Courseiva

AWS Certified DevOps Engineer Professional DOP-C02 (DOP-C02) — Questions 76–150

1298 questions total · 18pages · All types, answers revealed

Page 1

Page 2 of 18

Page 3
76
MCQmedium

A DevOps team is designing a deployment pipeline for a microservices application on Amazon ECS using AWS CodePipeline. They want to implement a canary deployment strategy where a small percentage of traffic is routed to the new version before fully promoting it. Which AWS service or feature should they use to achieve this?

A.Amazon ECS Service Auto Scaling
B.AWS CodeDeploy with ECS blue/green deployment
C.Amazon Route 53 weighted routing
D.AWS App Mesh with traffic shifting
AnswerB

AWS CodeDeploy with ECS blue/green deployment is the native AWS service that performs canary traffic shifting for an ECS service. It creates a replacement task set from a new task definition, shifts traffic through load balancer target group weights (for example, 10 percent initially), waits a specified interval, and then shifts the remaining traffic after validation. It also supports lifecycle hooks, CloudWatch alarm rollback, and automatic cleanup of the old task set, making it the complete answer for a canary deployment.

Why this answer

AWS CodeDeploy with ECS blue/green deployment is the correct choice because it natively supports canary traffic shifting for Amazon ECS services. When integrated with AWS CodePipeline, CodeDeploy can route a small percentage of traffic (e.g., 10%) to the new task set, monitor it with CloudWatch alarms, and then automatically shift the remaining traffic after a specified interval. This is the only option that directly provides the canary deployment lifecycle within the ECS and CodePipeline context.

Exam trap

The trap here is that candidates often confuse Route 53 weighted routing (which operates at the DNS level and cannot shift traffic within a single ECS service) with the application-level traffic shifting needed for canary deployments, or they assume App Mesh is required when CodeDeploy already provides the native integration.

Why the other options are wrong

A

Auto Scaling adjusts the number of tasks, not traffic shifting between versions.

C

Route 53 can distribute traffic across multiple endpoints, but it's not the native way for ECS service deployments.

D

App Mesh provides traffic splitting, but ECS natively integrates with CodeDeploy for canary deployments.

77
MCQeasy

A company uses AWS Systems Manager to manage a fleet of EC2 instances. The operations team needs to run a script on all instances that are missing a specific security patch. Which Systems Manager capability should be used to accomplish this?

A.Automation
B.State Manager
C.Run Command
D.Patch Manager
AnswerC

Run Command allows you to execute an SSM Document once on a target instance or fleet, on demand. It does not provide a scheduling feature or persistent association, so after the script finishes, there is no mechanism to automatically re-run it to handle future drift or new missing patches. While you could use EventBridge or other schedulers to invoke Run Command, State Manager natively supports recurring associations and compliance tracking, making Run Command insufficient for ongoing, monitored remediation.

Why this answer

Run Command lets you execute an SSM document (including an arbitrary shell/PowerShell script) once, on demand, against a targeted fleet of instances -- exactly what's needed to run a one-time remediation script across all instances missing a specific patch. It returns per-instance output/status immediately so you can confirm the script ran successfully. State Manager, by contrast, is built for enforcing a recurring/continuous desired state via scheduled associations and compliance tracking; since the requirement here is a single ad hoc script execution with no mention of an ongoing schedule or compliance reporting, State Manager would be unnecessary overhead.

Exam trap

The trap is to confuse Run Command with State Manager. Run Command is for one-time, ad-hoc execution without state tracking, whereas State Manager enforces a desired state on a schedule or continuously. Since the question only asks to 'run a script' and does not mention ongoing compliance or a schedule, Run Command is the correct capability.

How to eliminate wrong answers

Option A is wrong because Automation is used for performing complex, multi-step workflows (e.g., AMI creation, instance recovery) and is not designed for ongoing state enforcement or running scripts on a fleet based on missing patches. Option C is wrong because Run Command executes scripts or commands on instances on-demand without any state tracking or enforcement; it does not check for missing patches or ensure compliance over time. Option D is wrong because Patch Manager is specifically for scanning and applying OS patches using predefined patch baselines, not for running custom scripts; it cannot execute arbitrary scripts to address a specific missing patch.

78
MCQeasy

A company uses AWS Elastic Beanstalk to deploy web applications. The DevOps team wants to implement a blue/green deployment strategy to minimize downtime. Which Elastic Beanstalk feature should be used?

A.Rolling update
B.Canary deployment
C.Environment URL swap
D.Immutable update
AnswerC

Swapping environment URLs is the canonical blue/green deployment mechanism in Elastic Beanstalk. You first provision a second environment (the 'green' one) with your new version, verify it, and then use 'Swap environment URLs' in the console or the SwapEnvironmentCNAMEs API to make the original environment's URL instantly point to the new environment. This switch is atomic at the DNS/CNAME level, providing zero downtime, and you can equally quickly swap back to the old environment to roll back. Unlike other deployment methods, this keeps two distinct environments with separate instance fleets and configurations, which is the essence of blue/green.

Why this answer

Elastic Beanstalk's environment URL swap feature enables blue/green deployment by routing traffic from the current (blue) environment to a new (green) environment via a simple DNS swap. This swap is instantaneous at the DNS level, resulting in zero downtime for users, as the green environment is fully tested before the swap occurs.

Exam trap

The trap here is that candidates confuse 'immutable update' with blue/green deployment, but immutable update still operates within a single environment and does not provide the independent, fully isolated environment that a true blue/green strategy requires.

How to eliminate wrong answers

Option A is wrong because rolling update deploys new application versions in batches across existing instances, which does not create a separate environment and can cause temporary downtime or reduced capacity. Option B is wrong because canary deployment is not a native Elastic Beanstalk feature; it requires external tools like AWS CodeDeploy or custom routing to shift a small percentage of traffic. Option D is wrong because immutable update launches a new set of instances in the same environment and then terminates the old ones, which still involves a brief traffic cutover within the same environment and does not provide a separate, fully independent environment for blue/green testing.

79
Multi-Selectmedium

Which THREE actions should a DevOps team take to ensure a CI/CD pipeline using AWS CodePipeline is secure? (Choose three.)

Select 3 answers
A.Require multi-factor authentication (MFA) for pipeline executions.
B.Use AWS KMS to encrypt artifacts in the pipeline.
C.Use AWS CodePipeline with a customer-managed S3 bucket for artifacts and restrict bucket access.
D.Enable pipeline-level IAM permissions to restrict who can modify the pipeline.
E.Enable AWS CloudTrail to log pipeline executions.
AnswersB, C, D

AWS KMS encryption for artifacts ensures that every source zip, build output, and deployment package stored in CodePipeline’s artifact bucket is encrypted with a customer-managed key using SSE-KMS (envelope encryption). This gives you granular control over who can decrypt artifacts via kms:Decrypt permissions on the key, and it provides a tamper-evident audit trail of key usage through AWS CloudTrail. Unlike default AWS-managed S3 encryption, a customer-managed KMS key lets you enforce key rotation, define cross-account access rules, and revoke access immediately in response to a threat, which directly protects sensitive artifacts at rest and during transit.

Why this answer

AWS CodePipeline can use AWS KMS customer-managed keys (CMKs) to encrypt artifacts stored in S3 or other supported stores. This ensures that pipeline artifacts are encrypted at rest and in transit, protecting sensitive data from unauthorized access. By default, CodePipeline uses an AWS-managed key, but using a customer-managed KMS key gives the team full control over encryption, key rotation, and access policies.

Exam trap

The trap here is that candidates often confuse logging (CloudTrail) with security controls, or assume MFA can be directly enforced on pipeline executions, when in fact the correct security measures involve encryption, access control on artifacts, and IAM permissions on the pipeline resource itself.

80
MCQmedium

A company uses AWS Elastic Beanstalk to deploy a web application. They want to ensure that configuration changes (e.g., environment variables, instance type) are version-controlled and can be rolled back. Which strategy should they use?

A.Use AWS CloudFormation to manage the Beanstalk environment outside of Beanstalk.
B.Use Elastic Beanstalk saved configurations to store environment settings.
C.Store configuration in a configuration file (e.g., .ebextensions) included with the application source code.
D.Manually change environment configuration using the Elastic Beanstalk console when needed.
AnswerC

Configuration files placed in the .ebextensions directory of your application source bundle are processed by Elastic Beanstalk during environment creation and every deployment, allowing you to define option settings, environment variables, packages, and custom resources declaratively. Because these files live in source control alongside your application code, every versioned build contains its exact configuration, so rolling back to a previous application version also restores the matching configuration automatically. This versioned, source-code-integrated approach is the recommended method for environment configuration.

Why this answer

Storing configuration in .ebextensions files (YAML/JSON) within the application source bundle allows version control of environment settings (e.g., environment variables, instance type) alongside the code. When the application is deployed or updated, Elastic Beanstalk applies these configuration files automatically, enabling consistent rollback by redeploying a previous source bundle version. This approach integrates configuration management with the application lifecycle, ensuring that changes are tracked and reversible.

Exam trap

The trap here is that candidates often confuse saved configurations (Option B) with version-controlled configurations, but saved configurations are not tied to application versions and cannot be rolled back automatically with a source code deployment.

How to eliminate wrong answers

Option A is wrong because using AWS CloudFormation to manage the Beanstalk environment outside of Beanstalk introduces an external management layer that can lead to drift and does not inherently version-control configuration changes within the application source code; it also requires manual synchronization. Option B is wrong because Elastic Beanstalk saved configurations store environment settings separately from the source code, are not automatically applied during deployment, and do not provide version-controlled rollback tied to application versions. Option D is wrong because manually changing environment configuration via the Elastic Beanstalk console is not version-controlled, cannot be rolled back programmatically, and violates infrastructure-as-code principles.

81
MCQhard

A team uses AWS CodePipeline with multiple stages: Source, Build, Test, and Deploy. The Test stage runs integration tests against a staging environment. Occasionally, the tests fail due to environment issues, not code issues. The team wants to automatically retry the Test stage up to two times if it fails, but not the Deploy stage. How can this be achieved?

A.Create a CloudWatch Events rule that triggers a Lambda function to retry the failed stage.
B.Configure the Retry setting in the Test stage's action configuration.
C.Enable the 'Retry on failure' option in the CodePipeline pipeline settings.
D.Use AWS Step Functions to orchestrate the pipeline and implement retries.
AnswerA

This is correct because CodePipeline emits Amazon CloudWatch Events/EventBridge events on stage state changes, including a 'FAILED' state for a stage. A rule can filter for `detail-type: 'CodePipeline Stage Execution State Change'` with `detail.state: 'FAILED'` and trigger a Lambda function that invokes the `RetryStageExecution` API, passing the `pipelineExecutionId` and `stageName` from the event. This automates the same retry a user would otherwise click, and can include backoff logic or retry counts within the Lambda handler.

Why this answer

The correct approach is to use Amazon EventBridge (formerly CloudWatch Events) to detect a stage failure in CodePipeline and trigger an AWS Lambda function that calls the RetryStageExecution API. This provides automatic retries without manual intervention. CodePipeline's built-in retry setting on a stage action is not automatic; it only allows manual retries via the console or API.

Option D (Step Functions) is a valid alternative but adds unnecessary complexity for this use case.

Exam trap

The trap is that candidates may mistakenly believe CodePipeline supports automatic per-stage retries through a built-in configuration, when in fact the retry setting only enables manual retries. Automatic retries require external services like EventBridge and Lambda.

How to eliminate wrong answers

Option A is wrong because creating a CloudWatch Events rule to trigger a Lambda function for retrying a failed stage is overly complex and not the native solution; CodePipeline already provides built-in retry capabilities at the stage level. Option C is wrong because there is no global 'Retry on failure' option in CodePipeline pipeline settings; retries must be configured per stage action, not pipeline-wide. Option D is wrong because using AWS Step Functions to orchestrate the pipeline and implement retries would add unnecessary complexity and cost, as CodePipeline natively supports stage-level retries without external orchestration.

82
MCQmedium

A company uses AWS CodeDeploy to deploy a web application to an Auto Scaling group of Amazon EC2 instances. The deployment fails with the error 'The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available for deployment, or some instances in your deployment group are experiencing problems.' The application is deployed to the instances using an in-place deployment. The instances are running Amazon Linux 2. What should the DevOps engineer check first?

A.Check the security group rules for the EC2 instances.
B.Check the application's port availability.
C.Verify that the AWS CodeDeploy agent is installed and running on each EC2 instance.
D.Verify that the IAM instance profile associated with the instances has the correct permissions.
AnswerC

In-place deployments depend on the CodeDeploy agent polling the service on each instance; if it is absent or stopped, lifecycle events never execute, triggering the too-many-instances-failed error. Verifying the agent on every Amazon Linux 2 instance is therefore the first diagnostic step.

Why this answer

The error message indicates that individual instances failed deployment, which is most commonly caused by the AWS CodeDeploy agent not running or not being installed on the EC2 instances. For an in-place deployment on Amazon Linux 2, the CodeDeploy agent must be installed and actively running to receive and execute deployment commands from the CodeDeploy service. If the agent is missing or stopped, the instance cannot participate in the deployment, leading to the 'too many individual instances failed' error.

Exam trap

The trap here is that candidates often jump to IAM permissions (Option D) as the first troubleshooting step, but the error message's reference to 'individual instances failed' directly points to the agent not running on the instances, which is a more immediate and common cause than permission issues.

How to eliminate wrong answers

Option A is wrong because security group rules control network traffic to/from the instances, but they do not affect the CodeDeploy agent's ability to communicate with the service or execute deployment scripts; the agent uses HTTPS outbound to the CodeDeploy endpoints, which is typically allowed by default. Option B is wrong because port availability relates to the application's ability to serve traffic after deployment, not to the deployment process itself; the error occurs during deployment, not after the application starts. Option D is wrong because while the IAM instance profile must have correct permissions for the agent to call CodeDeploy APIs, the error message specifically points to individual instance failures, which is more directly tied to the agent's presence and operational status; incorrect permissions would typically cause a different error (e.g., 'AccessDeniedException') rather than a generic instance failure.

83
Multi-Selecthard

A DevOps team is designing a CI/CD pipeline that deploys a web application on Amazon ECS. The application must be compliant with PCI DSS, which requires encryption of data at rest and in transit, and logging of all access. Which THREE actions should the team implement to meet these requirements? (Choose THREE.)

Select 3 answers
A.Enable AWS CloudTrail and Amazon ECS logs to capture all API calls and container logs.
B.Store database credentials in AWS Systems Manager Parameter Store.
C.Use VPC endpoints to access ECS and ECR APIs.
D.Enable ECS task definition encryption using AWS KMS for environment variables and sensitive data.
E.Configure an Application Load Balancer (ALB) with an HTTPS listener using an SSL/TLS certificate.
AnswersA, D, E

AWS CloudTrail records every API call made against the AWS account, including ECS, ECR, and other service actions, which is essential for auditing who did what and when. Amazon ECS logs, collected via the awslogs driver, capture container stdout/stderr for operational auditing and forensic analysis. Together they provide the necessary audit trail to verify compliance and detect unauthorized access or changes, directly addressing the requirement to capture all API calls and container logs.

Why this answer

AWS CloudTrail captures all API calls to the AWS environment, providing an audit trail of who accessed what and when, which is required for PCI DSS logging. Amazon ECS logs (via CloudWatch Logs or FireLens) capture container-level access and application logs, ensuring comprehensive logging of all access to the application and underlying infrastructure.

Exam trap

The trap here is that candidates often confuse security best practices (like storing secrets in Parameter Store or using VPC endpoints) with mandatory compliance actions for encryption and logging, leading them to select options that are helpful but not directly required by PCI DSS for the specific three actions.

84
MCQhard

An application running on an EC2 instance in a private subnet needs to access an S3 bucket. The instance has an IAM role with S3 access. However, the application is failing with timeout errors. The security group allows all outbound traffic, and the NACL allows outbound ephemeral ports. What is the most likely cause?

A.No VPC endpoint for S3
B.Missing route in the route table to an Internet Gateway
C.IAM role does not have correct trust policy
D.Missing HTTP proxy configuration
AnswerA

An EC2 instance in a private subnet has no route to the public internet unless a NAT device or VPC endpoint is provisioned. Since no VPC endpoint for S3 is listed as existing, traffic from the instance to S3 cannot traverse the AWS backbone via the private subnet. A gateway endpoint or interface endpoint for S3 is required to establish private connectivity without leaving the AWS network, making the absent endpoint the root cause of the failure.

Why this answer

A VPC endpoint for S3 (Gateway or Interface) is needed for private subnet access to S3 without NAT. Without a VPC endpoint, the EC2 instance in a private subnet cannot reach S3, resulting in timeout errors. The security group and NACL settings are permissive, so they are not the issue.

Option B is incorrect because the instance is in a private subnet; routing to an Internet Gateway is not necessary and would require a NAT device. Option C is incorrect because the IAM role has the necessary S3 permissions. Option D is incorrect because no HTTP proxy is required for S3 access.

85
Multi-Selecteasy

A DevOps engineer is setting up monitoring for an Amazon DynamoDB table that experiences high read traffic. They want to monitor the read capacity consumption and be alerted when the consumed read capacity exceeds 80% of the provisioned capacity for 5 consecutive minutes. Which TWO steps should they take? (Select TWO.)

Select 2 answers
A.Enable AWS CloudTrail to log DynamoDB read requests.
B.Set up an AWS Lambda function to monitor the DynamoDB ReadThrottleEvents metric.
C.Use CloudWatch to monitor the ConsumedReadCapacityUnits and ProvisionedReadCapacityUnits metrics.
D.Configure DynamoDB to stream all read events to CloudWatch Logs.
E.Create a CloudWatch alarm with a metric math expression that calculates (ConsumedReadCapacityUnits / ProvisionedReadCapacityUnits) and set the threshold to 0.8.
AnswersC, E

DynamoDB natively publishes ConsumedReadCapacityUnits and ProvisionedReadCapacityUnits to CloudWatch at a one-minute granularity. Monitoring these metrics directly gives you a continuous view of how much read capacity is being used relative to what the table has provisioned. This is the foundational data source for any read-capacity alarm or scaling policy, and it lets you detect capacity pressure before throttling begins.

Why this answer

CloudWatch directly exposes the ConsumedReadCapacityUnits and ProvisionedReadCapacityUnits metrics for DynamoDB, which are the exact metrics needed to calculate read capacity utilization. Monitoring these metrics allows the engineer to track how much of the provisioned capacity is being consumed over time, which is the foundation for setting up the desired alert.

Exam trap

The trap here is that candidates often confuse throttling metrics (like ReadThrottleEvents) with capacity utilization metrics, leading them to select Option B, which only detects throttling after it happens rather than providing a proactive alert based on capacity consumption.

86
MCQeasy

A DevOps engineer sets up a CloudWatch dashboard to monitor an application's performance. The application runs on EC2 instances in an Auto Scaling group. The engineer wants to display the average CPU utilization across all instances in the group. Which CloudWatch metric and statistic should be used?

A.CPUUtilization metric with the Sum statistic, filtered by Auto Scaling group.
B.CPUUtilization metric with the Average statistic, filtered by Auto Scaling group.
C.StatusCheckFailed metric with the Average statistic, filtered by Auto Scaling group.
D.NetworkOut metric with the Average statistic, filtered by Auto Scaling group.
AnswerB

The Average statistic applied to CPUUtilization with the AutoScalingGroupName dimension gives the mean CPU percentage across all instances in the group, which is exactly what the dashboard needs to assess overall load. CloudWatch computes this by taking the CPUUtilization data points from each instance and calculating the arithmetic mean over the selected period. This is the standard and CloudFormation-idiomatic approach for monitoring an Auto Scaling group's aggregate CPU usage, and it directly answers the requirement without mixing units or extrapolating to a nonsensical total.

Why this answer

To display the average CPU utilization across all instances in an Auto Scaling group, you should use the CPUUtilization metric with the Average statistic, filtered by the Auto Scaling group dimension. This aggregates the CPU utilization of all instances, providing a representative average.

Exam trap

DOP-C02 often tests the appropriate statistic for a given metric, and candidates may incorrectly choose Sum for utilization metrics, not realizing it produces a meaningless total.

How to eliminate wrong answers

Option A is wrong because the Sum statistic would add up CPU utilization percentages across instances, resulting in a meaningless total (e.g., 500% for 5 instances at 100%). Option C is wrong because StatusCheckFailed measures instance status checks, not CPU utilization, and is not the desired metric. Option D is wrong because NetworkOut measures network traffic, not CPU utilization.

87
MCQhard

A company uses AWS CloudFormation to deploy a multi-tier application. The template includes an Amazon RDS DB instance. The DevOps team wants to update the DB instance class without downtime. What should they do?

A.Use a CloudFormation stack update with a 'ReplaceOnDelete' deletion policy on the DB instance.
B.Create a new DB instance with the new class, update the application to point to the new endpoint, and delete the old instance.
C.Update the DBInstanceClass property in the CloudFormation template and set 'ApplyImmediately: true'.
D.Modify the DB instance class using an RDS blue/green deployment, then update the CloudFormation stack to match the new class.
AnswerD

RDS Blue/Green Deployments let you provision a staging 'green' environment that stays synchronized with the production 'blue' environment via logical replication, allowing you to change the DB instance class in the green environment with zero impact on production. After validation, you perform a switchover that flips the endpoint with minimal downtime and no data loss. Then you update the CloudFormation stack's DBInstanceClass property to match the new instance class, ensuring your infrastructure-as-code template reflects the actual state and preventing drift.

Why this answer

RDS blue/green deployments allow you to make changes (such as modifying the DB instance class) with minimal downtime by creating a staging environment that mirrors the production environment. After the change is applied and verified, the blue/green deployment switches traffic to the new environment, ensuring zero or near-zero downtime. Subsequently, updating the CloudFormation stack to match the new class keeps the infrastructure code in sync with the actual deployed resources.

Exam trap

The trap here is that candidates often assume 'ApplyImmediately: true' is a valid zero-downtime solution, but in reality it triggers an immediate reboot for instance class changes, causing downtime, whereas blue/green deployments are the correct AWS-native method for minimizing downtime during such modifications.

How to eliminate wrong answers

Option A is wrong because 'ReplaceOnDelete' is not a valid deletion policy attribute in CloudFormation; the correct attribute is 'DeletionPolicy' with values like 'Delete', 'Retain', or 'Snapshot', and it does not control replacement behavior for updates. Option B is wrong because manually creating a new DB instance, updating the application endpoint, and deleting the old instance introduces downtime during the endpoint switch and is error-prone, lacking the automated traffic cutover and synchronization provided by blue/green deployments. Option C is wrong because setting 'ApplyImmediately: true' on a DB instance class change causes an immediate reboot of the RDS instance, resulting in downtime; the 'ApplyImmediately' parameter does not avoid downtime for instance class modifications.

88
Multi-Selectmedium

A company wants to implement a CI/CD pipeline for an application that runs on Amazon ECS with Fargate. The pipeline should build a Docker image, push it to Amazon ECR, and deploy a new task definition to ECS. Which THREE AWS services are required to build this pipeline?

Select 3 answers
A.Amazon S3
B.AWS CodeDeploy
C.AWS CodePipeline
D.AWS CodeCommit
E.AWS CodeBuild
AnswersB, C, E

AWS CodeDeploy is the correct service for deploying the new task definition to Amazon ECS. It uses a blue/green deployment strategy when configured with the ECS deployment controller, allowing traffic to be shifted gradually from the old task set to the new one while monitoring health and supporting automatic rollbacks. CodeDeploy accepts a versioned task definition and an AppSpec file, making it the service that actually performs the deployment to ECS.

Why this answer

AWS CodeDeploy is required because it manages the deployment of the updated task definition to the ECS service, supporting strategies like blue/green and canary deployments. It integrates with AWS CodePipeline to orchestrate the deployment step, ensuring minimal downtime and rollback capabilities.

Exam trap

The trap here is that candidates often assume AWS CodeCommit is mandatory for source control in a CI/CD pipeline, but the pipeline can use any Git repository or S3 bucket as a source, making CodeCommit optional.

89
MCQhard

A company's security team notices that an IAM user has permissions to terminate EC2 instances but should only be allowed to stop them. The current policy allows ec2:TerminateInstances. What is the most secure way to prevent termination while allowing stop?

A.Use an SCP to deny ec2:TerminateInstances for the entire account.
B.Modify the existing policy to include ec2:StopInstances and remove ec2:TerminateInstances.
C.Add a Deny statement for ec2:TerminateInstances with a condition for the user's ARN.
D.Attach a separate managed policy that denies ec2:TerminateInstances to the user.
AnswerC

Placing an explicit Deny on ec2:TerminateInstances with a condition key like aws:PrincipalArn set to the user's ARN directly and narrowly blocks only that principal from terminating instances. This Deny overrides any Allow for the action, regardless of other policies, while leaving the user's ability to stop instances intact and preserving permissions for all other IAM principals.

Why this answer

The most secure because adding a Deny statement for ec2:TerminateInstances with a condition for the user's ARN explicitly blocks the termination action, regardless of any other policies that might allow it. Option A is wrong because an SCP affects the entire account, not just the user, and may be too broad. Option B is wrong because simply modifying the policy to include ec2:StopInstances and remove ec2:TerminateInstances does not prevent termination if the user has other policies that grant ec2:TerminateInstances.

Option D is wrong because attaching a separate Deny policy is effective but less direct and more complex than adding a Deny in the same policy.

90
MCQmedium

A company is building a serverless application using AWS Lambda, Amazon API Gateway, and Amazon DynamoDB. The application must be resilient to sudden spikes in traffic without manual intervention. Which combination of services should be used?

A.API Gateway with throttling, Lambda with reserved concurrency, and DynamoDB auto scaling.
B.API Gateway with usage plans, Lambda with provisioned concurrency, and DynamoDB on-demand.
C.API Gateway with WAF, Lambda with function URLs, and DynamoDB Accelerator (DAX).
D.API Gateway with caching, Lambda with no concurrency limits, and DynamoDB global tables.
AnswerA

This combination directly addresses a demand spike: API Gateway throttling imposes a maximum request rate per client or across the API, preventing a flood from reaching Lambda. Reserved concurrency allocates a guaranteed number of Lambda executions, insulating the function from account-level throttling and ensuring the spikes are absorbed within the reserved ceiling. DynamoDB auto scaling adjusts provisioned read/write capacity based on live utilization, so the database keeps pace without manual intervention.

Why this answer

It combines API Gateway throttling to absorb traffic spikes by queuing or rejecting excess requests, Lambda reserved concurrency to guarantee execution capacity for the function, and DynamoDB auto scaling to adjust read/write capacity based on demand. This triad ensures the application remains available and responsive under sudden load without manual intervention.

Exam trap

The trap here is that candidates confuse 'provisioned concurrency' (Option B) with 'reserved concurrency' (Option A), mistakenly believing pre-warming instances handles spikes, when in fact reserved concurrency guarantees capacity but does not reduce cold starts, and provisioned concurrency is for latency, not burst resilience.

How to eliminate wrong answers

Option B is wrong because Lambda provisioned concurrency is designed for low-latency cold starts, not for handling traffic spikes; it pre-warms a fixed number of instances, which can be overwhelmed if spikes exceed that count, and DynamoDB on-demand is suitable for unpredictable workloads but can incur higher costs and does not prevent throttling at the API or Lambda layer. Option C is wrong because AWS WAF provides web application firewall protection against exploits, not traffic spike resilience; Lambda function URLs are a direct invocation method without built-in throttling, and DynamoDB Accelerator (DAX) is an in-memory cache for read-heavy workloads, not a scaling mechanism for write spikes. Option D is wrong because API Gateway caching reduces backend load but does not throttle incoming requests; Lambda with no concurrency limits can lead to uncontrolled scaling and potential account-level throttling; DynamoDB global tables provide multi-region replication for disaster recovery, not automatic scaling under traffic spikes.

91
MCQmedium

A DevOps engineer is designing a CI/CD pipeline that deploys to production. The security team mandates that all code changes must be reviewed and signed off by two senior developers before deployment. How can this be enforced?

A.Use CloudWatch Events to trigger a manual approval step in CodePipeline.
B.Restrict push access to the production branch to only the two senior developers.
C.Use AWS Lambda to send a notification when a change is pushed.
D.Set up a pull request approval rule in CodeCommit requiring two approvals.
AnswerD

Setting up a pull request approval rule in CodeCommit requires at least two approvals from IAM principals (other than the commit author) before the pull request can be merged. This is a native CodeCommit feature that enforces the two-person review rule at the source, allowing the pipeline to deploy only code that has passed the mandated review process. The approval rule can also be associated with the repository's target branch (e.g., production) and automatically applies to all PRs targeting that branch, making it the correct control to meet the requirement.

Why this answer

CodeCommit's pull request approval rules allow you to require a specific number of approvals before a pull request can be merged. By configuring an approval rule template that requires two approvals from senior developers, you enforce the mandatory code review and sign-off before any change is merged into the production branch, which then triggers the CI/CD pipeline.

Exam trap

The trap here is that candidates often confuse deployment-stage approvals (like CodePipeline manual approval) with pre-merge code review approvals, failing to recognize that the security requirement must be enforced at the source code repository level before the pipeline even starts.

How to eliminate wrong answers

Option A is wrong because CloudWatch Events can trigger a manual approval step in CodePipeline, but this only enforces approval at the deployment stage, not the code review and sign-off requirement before the change is even merged into the production branch. Option B is wrong because restricting push access to only two senior developers does not enforce a mandatory two-person review process; a single developer could still push directly without any review. Option C is wrong because using Lambda to send a notification when a change is pushed does not enforce any approval or review requirement; it merely informs stakeholders without blocking the change.

92
Multi-Selectmedium

Which TWO best practices should be followed when configuring AWS CodeBuild projects to improve build performance and security? (Choose TWO.)

Select 2 answers
A.Run builds as the root user to avoid permission errors
B.Use the AWS managed policy 'AdministratorAccess' for the CodeBuild service role to avoid permission issues
C.Configure the build project to use a custom VPC to access resources like private Amazon RDS databases
D.Always use the 'latest' tag for the build environment image to ensure up-to-date software
E.Enable Amazon S3 cache to store dependencies and reuse them across builds
AnswersC, E

Configuring the build project to use a custom VPC is a best practice because it allows CodeBuild to securely access resources that are not publicly reachable, such as private Amazon RDS databases, internal load balancers, or AWS services via VPC endpoints. Without a VPC configuration, CodeBuild runs in AWS-managed compute and cannot resolve or connect to private IP addresses, forcing you to either expose those resources to the internet or use a NAT gateway with complex routing. By placing the build into a private subnet with proper security group rules, you can control both inbound and outbound traffic, ensuring the build only communicates with approved internal services and does not depend on the public internet.

Why this answer

Configuring a CodeBuild project to use a custom VPC allows it to access resources that are not publicly accessible, such as private Amazon RDS databases or internal services, which is essential for building applications that depend on those resources. This also enhances security by keeping traffic within the VPC and avoiding exposure to the public internet.

Exam trap

The trap here is that candidates may confuse 'improving performance' with 'simplifying configuration' and choose options like using the 'latest' tag or granting broad permissions, overlooking the security and determinism trade-offs.

93
Multi-Selectmedium

Which TWO actions should a DevOps engineer take to secure an AWS account root user? (Choose 2.)

Select 2 answers
A.Share the root user password with the team.
B.Create an IAM role for the root user.
C.Delete or disable the root user access keys.
D.Use the root user for daily administrative tasks.
E.Enable multi-factor authentication (MFA) for the root user.
AnswersC, E

Deleting or disabling root user access keys removes long-lived credentials that cannot be scoped by IAM policies and are frequently exposed through code commits or misconfigured tooling. Since the root user bypasses permission boundaries entirely, eliminating its programmatic keys satisfies the stem's requirement to secure the account's most privileged identity.

Why this answer

Option C is correct because deleting or disabling the root user's access keys eliminates a long-lived, highly privileged credential that could be used for programmatic access; AWS best practice is to have no access keys on the root user at all. Option E is correct because enabling MFA on the root user adds a second authentication factor, so a compromised password alone cannot be used to sign in to the account's most powerful identity. Options A, B, and D are not appropriate: sharing the root password violates least privilege and accountability, IAM roles cannot be created for or assumed by the root user (roles are for IAM principals), and using root for daily administrative tasks contradicts the practice of using scoped IAM users or roles for routine work.

Exam trap

DOP-C02 often tests the misconception that the root user can be secured by creating an IAM role or that it should be used for administrative tasks, when in fact the root user cannot assume roles and should be used only for a limited set of account-level operations.

94
MCQeasy

A company wants to centrally manage and audit access to AWS KMS keys across multiple accounts. Which AWS feature should be used?

A.AWS Config aggregated rules
B.Cross-account IAM roles
C.AWS CloudTrail with organization trail
D.AWS Organizations tag policies
AnswerC

An organization trail in AWS CloudTrail is created once in the management account of AWS Organizations and automatically delivers management events from every member account to a single central S3 bucket, with optional CloudWatch Logs delivery for real-time monitoring. This gives a centralized, near-complete audit record of who made API calls, the service called, source IP, and timestamp across all accounts, which directly satisfies both central management and audit requirements. Because the trail is organization-scoped, it captures activity for existing and future accounts, making it the native AWS solution for cross-account audit logging.

Why this answer

AWS CloudTrail with an organization trail can log all API calls, including KMS key usage, across multiple accounts in an AWS Organization. This provides centralized audit logging for KMS key access. Option A (AWS Config aggregated rules) can evaluate resource compliance but does not audit key usage.

Option B (Cross-account IAM roles) allows access but not centralized auditing. Option D (AWS Organizations tag policies) manage tags, not auditing. Therefore, option C is correct.

95
MCQmedium

A company runs a serverless application using AWS Lambda, Amazon API Gateway, and Amazon DynamoDB. The application is used by thousands of users. Recently, the operations team noticed an increase in 5xx errors from API Gateway. The team has enabled CloudWatch Logs for the Lambda functions and API Gateway. They see the errors are sporadic and not correlated with high traffic. The Lambda function's error count in CloudWatch is also increasing. The team wants to identify the specific requests that are failing and understand the error details. Which solution should the team implement?

A.Use CloudWatch Logs Insights to query the Lambda logs for ERROR messages and correlate with API Gateway logs
B.Enable VPC Flow Logs for the Lambda function's VPC to capture network traffic
C.Enable AWS X-Ray active tracing on the Lambda functions and API Gateway to capture detailed request traces and error details
D.Enable AWS CloudTrail to log API Gateway API calls and analyze the logs
AnswerC

AWS X-Ray active tracing on both API Gateway and the Lambda functions provides end-to-end request tracing that captures every segment and subsegment — including Lambda invocation details, function execution time, HTTP status codes, exceptions, and downstream AWS service calls — allowing you to pinpoint the exact component that caused the error. When active tracing is enabled, API Gateway sends trace headers to Lambda, and Lambda automatically records the function's execution, with error details visible in the X-Ray console under the service map and trace list. This lets you filter traces by HTTP 5xx status or Lambda ERROR, drill into the affected trace to see the precise failing segment, and inspect the exception stack trace or error message, directly answering where and why the API request failed. X-Ray is purpose-built for distributed serverless applications, making it the most efficient and comprehensive option for this diagnostic task.

Why this answer

AWS X-Ray active tracing on Lambda and API Gateway captures end-to-end request traces, including downstream calls to DynamoDB, latency breakdowns, and exception details for each failing invocation. Because the errors are sporadic and not traffic-correlated, X-Ray's per-request trace view is the fastest way to pinpoint which specific requests fail and why. CloudWatch Logs alone would require manual correlation across services and lacks the trace context X-Ray provides.

Exam trap

DOP-C02 often tests the confusion between control-plane logging (CloudTrail), network logging (VPC Flow Logs), and request-level tracing (X-Ray), tempting candidates to pick CloudTrail or Flow Logs when the question asks for per-request error detail.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs Insights can query Lambda logs, but it cannot natively correlate a specific API Gateway request with its downstream Lambda and DynamoDB calls; the team would have to stitch together request IDs manually and still lack trace-level timing and error propagation detail. Option B is wrong because VPC Flow Logs capture IP-level network metadata (source/dest, ports, accept/reject), not application errors or Lambda exceptions, so they cannot explain 5xx responses. Option D is wrong because CloudTrail logs control-plane API calls (e.g., who changed a configuration), not data-plane request execution or Lambda runtime errors, so it will not reveal failing user requests.

96
MCQeasy

A company uses Amazon CloudWatch Logs to store application logs from EC2 instances. The security team requires that logs be retained for 5 years for compliance. Which action should be taken to meet this requirement cost-effectively?

A.Export the logs to Amazon S3 and use S3 Glacier Deep Archive for long-term storage.
B.Set a log retention policy of 5 years on the CloudWatch Logs log groups.
C.Disable log retention and let CloudWatch Logs keep the logs indefinitely.
D.Use AWS CloudTrail to store the logs for 5 years.
AnswerA

Exporting application logs from CloudWatch Logs to Amazon S3 and applying a lifecycle policy that transitions objects to S3 Glacier Deep Archive is the most cost-efficient way to meet a 5-year retention requirement. CloudWatch Logs storage costs roughly $0.03 per GB-month, while Glacier Deep Archive costs about $0.00099 per GB-month — a savings of nearly 97%. This makes sense for rarely accessed logs where the 12-hour retrieval time of Glacier Deep Archive is acceptable for compliance audits.

Why this answer

Exporting logs to Amazon S3 and using lifecycle policies to transition them to S3 Glacier Deep Archive is the most cost-effective way to retain logs for 5 years. S3 provides low-cost storage, and Glacier Deep Archive offers the lowest storage cost for long-term archival, making it ideal for compliance requirements. In contrast, retaining logs in CloudWatch Logs beyond a short period is more expensive due to higher storage costs.

Option B is incorrect because setting a 5-year retention policy in CloudWatch Logs incurs significant costs compared to exporting to S3. Option C is incorrect because disabling retention causes logs to expire after 90 days, not indefinite. Option D is incorrect because AWS CloudTrail captures API activity, not application logs.

97
MCQmedium

A company runs a critical web application on AWS using an Application Load Balancer (ALB) in front of an Auto Scaling group of EC2 instances. The application experiences periodic traffic spikes. To handle these spikes, the company wants to use a combination of proactive scaling based on a predictable schedule and reactive scaling based on CPU utilization. What is the MOST resilient scaling strategy?

A.Use a scheduled scaling policy for the predictable spikes and a step scaling policy for CPU utilization.
B.Use predictive scaling based on historical traffic patterns.
C.Use manual scaling by increasing the desired capacity before expected spikes.
D.Use a target tracking scaling policy based on average CPU utilization.
AnswerA

Scheduled scaling pre-provisions instances at fixed times, aligning capacity with known upcoming demand, while a step scaling policy reacts to actual CPU utilization through CloudWatch alarms with defined adjustment steps (e.g., add 2 instances when CPU exceeds 80%, add 1 when it exceeds 70%). This combination ensures both proactive readiness for predictable traffic spikes and rapid reactive response to any deviation, giving the highest resilience for mixed traffic patterns.

Why this answer

It combines scheduled scaling for predictable traffic spikes with step scaling for reactive adjustments based on CPU utilization, providing both proactive and reactive resilience. Scheduled scaling adjusts capacity in advance of known events, while step scaling allows for larger, more aggressive adjustments when CPU utilization exceeds thresholds, avoiding the slower, linear response of target tracking. This dual approach ensures the application can handle spikes without over-provisioning or under-provisioning.

Exam trap

The trap here is that candidates often assume predictive scaling (Option B) is the best for all predictable patterns, but it fails for non-recurring or sudden spikes, and they overlook that target tracking (Option D) cannot proactively add capacity before a spike begins.

How to eliminate wrong answers

Option B is wrong because predictive scaling relies on historical traffic patterns and may not accurately predict sudden, non-recurring spikes, leading to under-provisioning during critical events. Option C is wrong because manual scaling requires human intervention, which is not resilient for periodic spikes that occur outside business hours or without warning, and it lacks automation for reactive scaling. Option D is wrong because target tracking scaling only adjusts capacity to maintain a specific CPU utilization target, which can be too slow to respond to rapid spikes and does not allow for proactive scaling based on a schedule.

98
MCQmedium

Refer to the exhibit. The DevOps engineer runs the commands and sees the output. What is the most likely issue with the instance?

A.The underlying hardware is having issues (system status check failed).
B.The instance is healthy and no issues exist.
C.The instance is stopped.
D.The instance has a failed status check due to OS-level issues.
AnswerA

The correct interpretation is that the system status check has failed, which indicates an AWS infrastructure-level problem with the physical host running the instance. This includes issues such as a failing disk, network connectivity loss, or hardware component degradation. Even though the instance is running and its instance status check may pass, the impaired system status means the underlying hardware is compromised and AWS may need to repair or replace the host, often requiring a stop/start or recovery action.

Why this answer

The SystemStatus is 'impaired', indicating a problem with the underlying physical host (system status check failed). The InstanceStatus is 'ok', so the OS is functioning normally. Option B is incorrect because the system status check shows impairment, so there is an issue.

Option C is incorrect because the instance is running, not stopped. Option D is incorrect because the impairment is at the system level, not the OS level.

99
MCQhard

A large enterprise uses a multi-account AWS strategy with a centralized DevOps account. The DevOps account hosts an AWS CodePipeline that deploys a critical application to production account (111111111111) using AWS CodeDeploy. The pipeline has three stages: Source (CodeCommit), Build (CodeBuild), and Deploy (CodeDeploy). The deploy stage uses a cross-account role (arn:aws:iam::111111111111:role/CrossAccountDeployRole) to perform the deployment. The trust policy on that role allows the DevOps account's CodePipeline service role (arn:aws:iam::222222222222:role/CodePipelineServiceRole) to assume it. The pipeline has been working for months, but after a recent security audit, the security team tightened permissions. Now the deploy stage fails with the error: 'User: arn:aws:sts::222222222222:assumed-role/CodePipelineServiceRole/AWS-CodePipeline-xxx is not authorized to perform: codedeploy:CreateDeployment on resource: arn:aws:codedeploy:us-east-1:111111111111:deploymentgroup:MyApp/MyDG'. The DevOps team has verified that the CrossAccountDeployRole has a permissions policy that allows 'codedeploy:*' on all resources. The CodePipelineServiceRole has a permissions policy that allows 'sts:AssumeRole' on the CrossAccountDeployRole. What is the most likely cause and what action should be taken to resolve the issue?

A.Add 'sts:AssumeRole' to the permissions policy of CodePipelineServiceRole.
B.Create the deployment group in the production account again to reset permissions.
C.Check the permissions boundary on CrossAccountDeployRole and add a boundary that allows CodeDeploy actions.
D.Update the trust policy of CrossAccountDeployRole to include the DevOps account ID.
AnswerC

A permissions boundary on CrossAccountDeployRole acts as an additional filter on the role's effective permissions, and if it does not explicitly allow CodeDeploy actions, those actions are denied even when the role's permissions policy grants them. Because the effective permission is the intersection of the identity-based policy and the boundary, the boundary must include all required codedeploy:* or specific actions. Adding or updating the boundary to allow CodeDeploy actions is the correct way to restore authorization in this cross-account deployment.

Why this answer

The error indicates that the assumed role (CrossAccountDeployRole) is not authorized to perform codedeploy:CreateDeployment, despite having a permissions policy that allows codedeploy:* on all resources. This typically occurs when a permissions boundary is attached to the role that restricts the effective permissions, overriding the permissions policy. Adding a permissions boundary that allows CodeDeploy actions resolves the issue by ensuring the role's effective permissions include the necessary CodeDeploy operations.

Exam trap

The trap here is that candidates often assume the error is due to missing sts:AssumeRole or trust policy misconfiguration, but the role was already assumed successfully (as shown by the assumed-role ARN in the error), so the real issue is a permissions boundary or service control policy limiting the role's effective permissions.

How to eliminate wrong answers

Option A is wrong because the CodePipelineServiceRole already has sts:AssumeRole in its permissions policy (as stated in the scenario), so adding it again would not resolve the issue. Option B is wrong because recreating the deployment group does not address the underlying permission restriction; the error is about authorization, not resource existence or configuration. Option D is wrong because the trust policy already allows the DevOps account's CodePipelineServiceRole to assume the role (the error shows the role was assumed successfully), so updating the trust policy is unnecessary.

100
Multi-Selectmedium

A company runs a critical application on Amazon ECS with Fargate launch type. During an incident, the DevOps engineer notices that tasks are failing with 'CannotPullContainerError: API error (500)'. Which TWO steps should the engineer take to resolve this issue?

Select 2 answers
A.Attach an EBS volume to the Fargate task for caching.
B.Check that the ECS service role has the required permissions.
C.Ensure that the ECR repository policy allows the task execution role to pull images.
D.Increase the task memory to accommodate the image pull.
E.Verify that the task execution IAM role has the necessary permissions to pull from Amazon ECR.
AnswersC, E

Amazon ECR uses both identity-based policies (attached to the principal, typically the task execution role) and resource-based policies (attached to the repository) to control access. If the repository policy does not explicitly grant the task execution role permission to perform actions like ecr:BatchGetImage and ecr:GetDownloadUrlForLayer, the pull will be denied even if the role's IAM policy allows those actions. The default repository policy is restrictive, and an overly narrow or misconfigured repository policy will cause a 'CannotPullContainerError' during task startup. Therefore, verifying that the ECR repository policy includes an Allow statement for the task execution role is a critical step.

Why this answer

Options C and E are correct. When a Fargate task fails with 'CannotPullContainerError: API error (500)', it typically indicates an issue with pulling the container image from Amazon ECR. The task execution IAM role (E) must have the necessary permissions (ecr:GetDownloadUrlForLayer, ecr:BatchGetImage, ecr:BatchCheckLayerAvailability) to pull images from ECR.

Additionally, if the image resides in a private ECR repository, the repository policy (C) must allow the task execution role to perform those actions. Option A is wrong because Fargate does not support attaching EBS volumes; it stores image layers ephemerally. Option B is incorrect because the ECS service role is used for load balancer integration, not for pulling images.

Option D is incorrect because increasing task memory does not fix image pull errors; memory affects running tasks, not the pull process.

101
MCQmedium

An organization uses AWS CodePipeline with multiple stages: Source, Build, Test, and Deploy. The Test stage runs integration tests in CodeBuild. Recently, the pipeline failed because the Test stage took longer than expected, causing a pipeline execution timeout. The pipeline has a default timeout of 7 days. What is the MOST efficient way to set a maximum execution time for the Test stage without affecting other stages?

A.Create an AWS Lambda function that stops the pipeline if the Test stage exceeds 1 hour.
B.Set the pipeline execution timeout to 1 hour in the pipeline settings.
C.Use Amazon CloudWatch Events to detect when the Test stage runs for more than 1 hour and then stop the pipeline.
D.Modify the CodeBuild project's build timeout (e.g., 1 hour) in the buildspec or project configuration.
AnswerD

In the CodeBuild project configuration (or in the buildspec's timeout-in-minutes field), you can set a build timeout that applies specifically to the build used by the Test stage. When the build exceeds the configured timeout, CodeBuild automatically stops the build and the pipeline transitions to Failed, giving a proactive, stage-scoped limit without affecting the Deploy stage. This is the recommended way to prevent a test job from hanging indefinitely because the timeout is enforced by CodeBuild's execution manager.

Why this answer

The CodeBuild project's build timeout setting directly controls the maximum duration a build can run before it is stopped. By setting this timeout to 1 hour in the CodeBuild project configuration or buildspec, the Test stage will automatically fail if it exceeds that limit, without affecting the pipeline's overall timeout or other stages. This is the most efficient and targeted approach, as it leverages a native CodeBuild feature rather than adding external monitoring or changing pipeline-wide settings.

Exam trap

The trap here is that candidates may confuse the pipeline-level execution timeout with stage-level or action-level timeouts, assuming that adjusting the pipeline timeout is the correct way to limit a specific stage, when in fact CodeBuild's own timeout is the precise and efficient mechanism for controlling build duration.

How to eliminate wrong answers

Option A is wrong because creating an AWS Lambda function to stop the pipeline adds unnecessary complexity, cost, and maintenance overhead; it is not the most efficient solution when a native CodeBuild timeout exists. Option B is wrong because setting the pipeline execution timeout to 1 hour applies to the entire pipeline, not just the Test stage, which would cause the entire pipeline to fail if any stage (e.g., Source, Build, or Deploy) takes longer than 1 hour, even if they are functioning correctly. Option C is wrong because using Amazon CloudWatch Events to detect a long-running Test stage and stop the pipeline introduces additional latency, complexity, and potential race conditions; it is less efficient than directly configuring the CodeBuild project's timeout.

102
MCQhard

A DevOps engineer needs to ensure that an S3 bucket policy enforces encryption in transit for all access. Which policy statement should be added?

A.{"Effect":"Deny","Condition":{"StringEquals":{"aws:SecureTransport":"true"}}}
B.{"Effect":"Allow","Condition":{"Bool":{"aws:SecureTransport":"false"}}}
C.{"Effect":"Allow","Condition":{"Bool":{"aws:SecureTransport":"true"}}}
D.{"Effect":"Deny","Condition":{"Bool":{"aws:SecureTransport":"false"}}}
AnswerD

This is the correct pattern: it explicitly denies any request where aws:SecureTransport equals false, meaning only HTTPS connections are permitted. An explicit deny overrides all other allow outcomes, so this robustly enforces TLS regardless of any other policies. The condition uses Bool, which is proper for boolean keys like aws:SecureTransport.

Why this answer

To enforce encryption in transit, the S3 bucket policy must deny requests that are not using SSL/TLS. The condition key aws:SecureTransport is a boolean that is true when the request uses HTTPS and false when it uses HTTP. Therefore, a Deny statement with a condition that aws:SecureTransport is false blocks all unencrypted (HTTP) access, effectively enforcing encryption in transit.

Exam trap

DOP-C02 often tests whether candidates confuse the boolean logic of aws:SecureTransport, leading them to select an Allow statement or a Deny with the wrong boolean value, instead of the correct Deny with false.

How to eliminate wrong answers

Option A is wrong because it uses StringEquals with 'true' and a Deny effect, which would deny all HTTPS requests, the opposite of the intended enforcement. Option B is wrong because it uses Allow with a condition that aws:SecureTransport is false, which would explicitly allow unencrypted requests, violating the requirement. Option C is wrong because it uses Allow with a condition that aws:SecureTransport is true, which allows HTTPS but does not deny HTTP; an explicit deny is needed to block unencrypted access.

103
MCQmedium

A company runs a serverless application using AWS Lambda, Amazon API Gateway, and Amazon DynamoDB. The application processes financial transactions. The DevOps team needs to monitor for duplicate transactions that could occur due to retries. The team wants to set up an alert when the number of duplicate transaction attempts exceeds 10 in a 5-minute window. The application logs each transaction attempt with a unique transaction ID to CloudWatch Logs. What is the most efficient way to achieve this?

A.Create a CloudWatch Logs metric filter that counts log events containing 'DuplicateTransaction' and set an alarm on the metric with a threshold of 10.
B.Use DynamoDB Streams to trigger a Lambda function that counts duplicates and publishes metrics.
C.Stream the CloudWatch Logs to Amazon Kinesis Data Analytics and use SQL queries to detect duplicates.
D.Modify the Lambda function to publish a custom metric to CloudWatch for each duplicate transaction, then set an alarm.
AnswerA

CloudWatch Logs metric filters evaluate log events in real time against a filter pattern and can emit a custom metric that increments for every matching event, here 'DuplicateTransaction'. This avoids changing the Lambda function or introducing additional services, and it leverages the transaction logs already being written to CloudWatch. A CloudWatch alarm can then monitor that metric over a 5-minute period and trigger when the count exceeds 10, providing an accurate and low-cost detection mechanism.

Why this answer

CloudWatch Logs metric filters can scan log events for specific terms like 'DuplicateTransaction' and convert matches into a custom metric. You can then create a CloudWatch alarm on that metric with a threshold of 10 over a 5-minute period. This requires no code changes, no additional services, and is the most efficient and native solution for monitoring log-based patterns.

Exam trap

DOP-C02 often tests the misconception that you need to modify application code or use additional services to monitor log patterns, when native CloudWatch Logs metric filters and alarms are sufficient and more efficient.

How to eliminate wrong answers

Option B is wrong because DynamoDB Streams capture item-level changes, not duplicate transaction attempts; duplicates are logged in CloudWatch Logs, not necessarily reflected as separate DynamoDB writes, and this adds unnecessary Lambda and Streams complexity. Option C is wrong because Kinesis Data Analytics is for real-time stream processing with SQL, which is overkill for simple counting and requires streaming logs to Kinesis, adding cost and latency. Option D is wrong because modifying the Lambda function to publish custom metrics requires code changes and deployment, and it still needs an alarm; it's less efficient than using existing logs with a metric filter.

104
MCQmedium

A company is using AWS Secrets Manager to store database credentials for a multi-tier application. The application runs on EC2 instances in an Auto Scaling group. The DevOps engineer has configured the instances to retrieve the secret at boot time using a script that calls the AWS CLI. Recently, the security team discovered that the secret was exposed in the instance's user data logs. The engineer needs to implement a more secure method to access the secret without storing it in user data. The application code can be modified. The environment uses IAM roles for EC2. Which solution best meets the security requirements?

A.Store the secret in a configuration file on the EC2 instance and encrypt the file system.
B.Store the secret in AWS Systems Manager Parameter Store and retrieve it via the AWS CLI at boot time.
C.Modify the application code to use the AWS SDK to retrieve the secret from Secrets Manager using the instance's IAM role.
D.Use a KMS key to encrypt the secret and store the encrypted value in user data.
AnswerC

Using the AWS SDK inside the application to retrieve the secret from Secrets Manager is the correct pattern because the secret is fetched at runtime, encrypted in transit, and never written to user data, environment variables, or disk. The EC2 instance profile's IAM role gives the SDK temporary, automatically rotated credentials, so no hard-coded access keys or CLI scripts are required. This approach leverages Secrets Manager's built-in rotation, CloudTrail auditing, and fine-grained IAM policies that can limit which secrets a given instance role can read, and it lets the SDK cache the secret to minimize latency while still respecting rotation.

Why this answer

The most secure and operationally sound approach is to have the application retrieve the secret at runtime using the AWS SDK, authenticating via the EC2 instance profile (IAM role). This eliminates any need to embed the secret in user data, config files, or environment variables, and it leverages Secrets Manager's native rotation, versioning, and audit trail. Because the environment already uses IAM roles for EC2, no additional credential management is required.

Exam trap

DOP-C02 often tests the misconception that 'encrypting' a secret in user data makes it safe — candidates forget that user data is readable via the EC2 API and IMDS, so ciphertext plus accessible decryption is still a leak.

How to eliminate wrong answers

Option A is wrong because storing the secret in a config file — even on an encrypted filesystem — still leaves the plaintext secret on disk and in any backups or snapshots, and it does not address rotation or access auditing. Option B is wrong because retrieving from Parameter Store via the AWS CLI at boot time still requires the secret value to be handled by a script, and if that script or its output is logged (as in the original incident), the secret can leak again; Parameter Store also lacks Secrets Manager's native rotation for RDS credentials. Option D is wrong because encrypting the secret with KMS and storing the ciphertext in user data still exposes the ciphertext to anyone who can read user data, and the instance must decrypt it — the decryption key or role permissions become the weak link, and user data is visible in the console and API.

105
MCQmedium

A DevOps engineer needs a centralized view of operational metrics and logs for applications running in three AWS Regions. The security team requires that the data be queryable together, that access be governed by existing IAM roles, and that no data be copied into a separate third-party account. Which approach should the engineer use?

A.Create an Amazon CloudWatch cross-account, cross-Region observability configuration in a central monitoring account and share the source accounts' metrics and log groups with it.
B.Use AWS CloudFormation StackSets to deploy identical CloudWatch dashboards and alarms into every Region and account, and have operators switch roles to view each one.
C.Enable AWS Config in all Regions and accounts and use the AWS Config advanced query feature to search metrics and logs.
D.Configure each application to write metrics and logs to an Amazon Kinesis Data Firehose delivery stream that lands data in a central Amazon S3 bucket, then query with Amazon Athena.
AnswerA

CloudWatch cross-account observability supports linking source accounts and Regions to a monitoring account, letting users query metrics, logs, and traces from one place while data stays in the source accounts. IAM roles control who can view the shared data, satisfying governance without copying data to a third party.

Why this answer

CloudWatch cross-account observability links source accounts and Regions to a monitoring account, enabling a single query experience for metrics, logs, and traces while data remains in place. IAM roles govern access, meeting the governance constraint. Data pipelines to S3, StackSet dashboards, and AWS Config do not provide the same in-place, unified query capability.

Exam trap

The trap here is assuming observability data must be copied to a central account, when CloudWatch can share it in place through a monitoring account link.

106
MCQhard

A company uses AWS CloudFormation to deploy infrastructure across multiple accounts. They want to reuse a set of resource definitions for a standard VPC configuration. Which approach minimizes duplication and maintains centralized control?

A.Create a CloudFormation module for the VPC resources and reference it in each stack.
B.Define the VPC resources in a CloudFormation macro and call the macro from each stack.
C.Publish the VPC template in AWS Service Catalog and have each account provision from it.
D.Use nested stacks by creating a separate template for the VPC and including it in each account's stack.
AnswerA

CloudFormation modules encapsulate a group of resources—such as a VPC with subnets, route tables, and gateways—so they can be referenced as a single reusable component in multiple stacks. Modules support parameters, outputs, and semantic versions, enabling centralized management and consistent configuration across accounts and regions without duplicating resource definitions. When a module is included in a stack, its resources become part of that stack's resource graph, so you can access their outputs directly in the same template, simplifying stack-level operations like changes and rollbacks.

Why this answer

CloudFormation modules allow you to encapsulate a set of resource definitions into a reusable component that can be referenced across multiple stacks. This approach minimizes duplication because the module is defined once in a central registry (e.g., the CloudFormation public or private module registry) and each stack simply includes a `Module` declaration. It also maintains centralized control because updates to the module are automatically propagated to all stacks that reference it, without requiring manual template copying or stack updates.

Exam trap

The trap here is that candidates often confuse CloudFormation macros with modules, thinking macros can encapsulate reusable resources, but macros only transform template code at deploy time and do not provide a reusable resource definition mechanism.

How to eliminate wrong answers

Option B is wrong because CloudFormation macros are designed for template preprocessing (e.g., transforming JSON/YAML at deploy time), not for encapsulating reusable resource definitions; they cannot be used to define and share a standard set of resources like a VPC. Option C is wrong because AWS Service Catalog is a governance tool for provisioning pre-approved products, but it does not inherently minimize duplication or maintain centralized control over the IaC template itself—each account still deploys a separate copy of the template, and updates require re-provisioning or version management. Option D is wrong because nested stacks require the child template to be stored in an S3 bucket and referenced by URL; while this allows reuse, it does not provide centralized version control or automatic propagation of updates to all consuming stacks, and it introduces additional complexity in managing S3 permissions and template versioning.

107
MCQeasy

A DevOps engineer is configuring AWS Config rules to detect non-compliant security groups. The rule should trigger if any security group allows inbound SSH (port 22) from 0.0.0.0/0. Which AWS managed Config rule should be used?

A.vpc-sg-open-only-to-authorized-ports
B.ec2-security-group-attached-to-eni
C.restricted-ssh
D.incoming-ssh-disabled
AnswerC

The managed rule restricted-ssh directly evaluates security group rules for inbound TCP port 22 and determines if any rule allows access from 0.0.0.0/0 or ::/0. When the rule finds an IPv4 or IPv6 inbound rule that permits SSH from all IP addresses, it marks the security group as noncompliant; this is exactly the condition a DevOps engineer would target to detect publicly exposed SSH.

Why this answer

'restricted-ssh' is the managed rule that checks for SSH access from 0.0.0.0/0. Option A is wrong because 'vpc-sg-open-only-to-authorized-ports' is not specific to SSH. Option B is wrong because 'ec2-security-group-attached-to-eni' checks attachment, not rules.

Option D is wrong because 'incoming-ssh-disabled' is not a managed rule.

108
MCQmedium

An IAM policy attached to a user is shown in the exhibit. The user reports that they are unable to delete an object in the 'example-bucket' bucket. What is the reason for this?

A.The resource ARN does not match the bucket name
B.The explicit Deny statement overrides the Allow
C.The user does not have permissions to perform s3:DeleteObject
D.The policy has a syntax error
AnswerB

This is the correct explanation. AWS IAM policy evaluation is based on a strict rule: an explicit deny from any applicable policy always overrides any allow, regardless of statement order or the number of allows. Even though the policy contains an Allow that includes `s3:DeleteObject` on the specified bucket and objects, the explicit Deny for the same action takes precedence, resulting in the user being denied. This is fundamental to AWS's default-deny model and is non-negotiable.

Why this answer

An explicit Deny overrides any Allow. The Deny action s3:DeleteObject explicitly denies the delete, even though the Allow all s3 actions includes delete. Option A is wrong because the resource ARN matches.

Option C is wrong because the policy allows all s3 actions, but the Deny blocks delete. Option D is wrong because the policy is valid.

109
MCQmedium

A company is using Amazon RDS for MySQL with Multi-AZ deployment. The database experiences a failover due to an availability zone outage. After the failover, the application team reports that the database endpoint is not resolving to the new primary. What is the most likely reason?

A.The RDS CNAME record was not updated by AWS after the failover.
B.The application is using the read replica endpoint instead of the primary endpoint.
C.The application is using a Route 53 health check that failed and redirected traffic away from the endpoint.
D.The application is using a cached DNS resolution that points to the old primary.
AnswerD

This is correct. After an RDS Multi-AZ failover, the RDS-managed DNS CNAME is updated to point to the new primary instance's underlying IP address. However, if the application's DNS resolver (or the application itself) has cached the old IP address from before the failover, it will continue to try to connect to the old primary instance until the cache expires (based on the DNS TTL, which is typically 30–60 seconds for RDS). A long TTL or a resolver that ignores TTL can keep the stale IP in effect, causing errors (e.g., 'Communications link failure') even though the new primary is healthy.

Why this answer

After an RDS Multi-AZ failover, the DNS CNAME record for the DB instance is updated to point to the new primary in the standby AZ. However, if the application or its DNS resolver has cached the previous DNS resolution, it will continue to use the old IP address, which is no longer reachable. This is a common issue that can be resolved by reducing the TTL on the DNS record or implementing retry logic with DNS re-resolution in the application.

Exam trap

The trap here is that candidates may assume AWS automatically handles DNS propagation instantly or that the CNAME record is not updated, but the real issue is client-side DNS caching, which is a common operational oversight in failover scenarios.

How to eliminate wrong answers

Option A is wrong because AWS automatically updates the RDS CNAME record to point to the new primary after a failover; it is not a manual process. Option B is wrong because the read replica endpoint is a separate endpoint used for read-only traffic; using it would not cause the primary endpoint to fail to resolve, and the application team reported the database endpoint is not resolving, not that it is resolving to the wrong instance. Option C is wrong because Route 53 health checks are not used for RDS DNS resolution; RDS uses its own internal DNS system with CNAME records, and Route 53 health checks are typically used for custom domain names pointing to RDS, not for the default RDS endpoint.

110
MCQmedium

A DevOps team uses AWS CodePipeline to deploy a web application. The pipeline has a manual approval step. During an incident, the deployment is stuck at the approval step because the approver is on leave. The team needs to unblock the pipeline quickly. What is the BEST action to take?

A.Update the pipeline definition to remove the manual approval step temporarily.
B.Use the CodePipeline console to approve the action directly as a different user.
C.Disable the transition to the approval stage and manually run the remaining stages.
D.Retry the action in the approval stage from the CodePipeline console.
AnswerB

The CodePipeline console provides Approve and Reject buttons for any pending manual approval action to any IAM user or role with the codepipeline:ApproveStage permission. The approval is bound to the action and its configured IAM permissions, not to the specific person who originally triggered it, so another authorized user can approve the action and immediately unblock the current pipeline execution without any code or pipeline definition changes.

Why this answer

In AWS CodePipeline, a manual approval action can be approved by any IAM user with the appropriate permissions, not just the designated approver. Using the console to approve as a different user is the quickest way to unblock the pipeline without modifying the pipeline structure. This action is immediate and preserves the pipeline's integrity.

Exam trap

The trap is thinking that only the designated approver can approve, when in fact any authorized IAM user can do so, making option B the fastest resolution.

How to eliminate wrong answers

Option A is wrong because updating the pipeline definition to remove the approval step is a configuration change that requires a pipeline update, which can take time and may have unintended consequences; it's not the best immediate action. Option C is wrong because disabling the transition to the approval stage would skip the stage entirely, potentially bypassing necessary checks, and manually running remaining stages is not a standard feature. Option D is wrong because retrying the action will not bypass the approval; it will simply re-trigger the same approval requirement.

111
MCQhard

A company uses AWS CloudTrail to log API calls. An IAM user's credentials are compromised, and the attacker launches multiple EC2 instances in regions that are not typically used. The security team wants to receive near-real-time notifications of any API calls from this user. What is the MOST effective solution?

A.Create an AWS Config rule that checks for EC2 instances in unauthorized regions
B.Configure CloudTrail to deliver logs to an S3 bucket and enable S3 event notifications to SQS
C.Create a CloudTrail trail that delivers to CloudWatch Logs, then set up a CloudWatch Events rule to invoke a Lambda function that sends an SNS notification
D.Use CloudWatch Logs Insights to query CloudTrail logs every 5 minutes and send results via email
AnswerC

This is the correct near-real-time solution. By delivering CloudTrail events to CloudWatch Logs, events are streamed continuously rather than waiting for S3 log file delivery. A CloudWatch Events (EventBridge) rule can match the specific API call from CloudTrail—filtering on the IAM user, event name, or region—and invoke a Lambda function, which publishes an SNS notification. This end-to-end path operates in seconds, giving you immediate alerting on unauthorized API calls.

Why this answer

The most effective solution for near-real-time notifications of specific API calls is to deliver CloudTrail logs to CloudWatch Logs and create a CloudWatch Events (now EventBridge) rule that triggers a Lambda function to send an SNS notification. This provides immediate alerting based on specific API calls, such as RunInstances, from a particular user.

Exam trap

The trap is choosing AWS Config or S3 event notifications, which are not real-time for API calls. Candidates must remember that CloudWatch Events with CloudTrail integration is the standard for real-time API monitoring.

How to eliminate wrong answers

Option A is wrong because AWS Config rules evaluate resource configurations periodically and are not designed for near-real-time API call notifications. Option B is wrong because S3 event notifications are triggered when objects are created, not when specific API calls occur, and there is inherent latency in log delivery to S3. Option D is wrong because CloudWatch Logs Insights queries are run on demand or on a schedule, and a 5-minute interval is not near-real-time; also, sending results via email is not automated alerting.

112
Multi-Selectmedium

A company uses AWS CloudFormation to deploy infrastructure. They want to implement a change management process that requires approval before any stack update is executed. Which TWO approaches can achieve this? (Choose TWO.)

Select 2 answers
A.Use AWS CodePipeline with a manual approval stage before the CloudFormation deployment action.
B.Use CloudFormation StackSets with approval tokens.
C.Use CloudFormation Change Sets and require a separate user to execute them.
D.Use AWS Service Catalog to manage CloudFormation templates and require approval for product launches.
E.Implement a custom AWS Lambda function that checks a ticketing system before allowing the update to proceed.
AnswersA, E

CodePipeline's manual approval action is a first-class gate that pauses execution between stages; a configured principal (often a manager or lead) must explicitly approve via console, CLI, or API before the pipeline proceeds to the CloudFormation deployment stage. This enforces separation of duties, because the engineer who initiated the pipeline cannot be the sole approver unless policies allow it. It works natively with the pipeline state machine and keeps an audit trail of who approved and when.

Why this answer

AWS CodePipeline can include a manual approval action that pauses the pipeline until an authorized user approves the change, after which the CloudFormation deployment action executes the stack update. This enforces a formal approval gate before any infrastructure change is applied.

Exam trap

The trap here is that candidates often confuse Change Sets (which allow review but not approval enforcement) with a true approval workflow, or they incorrectly assume StackSets or Service Catalog can be repurposed for stack update approvals.

113
MCQmedium

Refer to the exhibit. After a deployment at 10:00, the error rate increases steadily. What is the MOST likely cause?

A.An external dependency became unavailable after the deployment.
B.A bug in the new release causes errors to accumulate over time.
C.The database connection limit was reached immediately after deployment.
D.The deployment triggered a scaling event that overloaded the application.
AnswerB

A bug in the new release that causes errors to accumulate over time fits the exhibit's steady upward slope perfectly. For example, a memory leak, unreleased file descriptor, or growing goroutine/thread count raises resource pressure with every additional request, so failure probability increases as a function of cumulative traffic. This pattern is distinct from an immediate fault because the defect is latent, and the error rate worsens as the application's internal state becomes progressively corrupted or exhausted.

Why this answer

A steadily increasing error rate that begins right after a deployment and grows over time is the signature of a bug in the new release that accumulates state — for example, a memory leak, connection leak, unbounded cache, or counter that eventually corrupts behavior. Because the errors ramp up gradually rather than spiking immediately, the cause is inside the deployed code, not an external dependency or a hard resource ceiling hit at t=0. This pattern points to the new release as the root cause.

Exam trap

The trap is confusing 'gradual increase over time' with 'external dependency failure' — candidates pick A because dependency outages are common, but the temporal shape (steady ramp vs. step change) is the discriminator the exam is testing.

How to eliminate wrong answers

Option A is wrong because an external dependency becoming unavailable typically causes an immediate step-change in errors, not a steady ramp starting at deployment. Option C is wrong because hitting a database connection limit produces a sudden, sharp error spike when the pool is exhausted, not a gradual increase over hours. Option D is wrong because a scaling event triggered by deployment would cause a one-time capacity adjustment, not a continuously rising error rate; and if scaling were the issue, errors would correlate with load, not with time since deploy.

114
Multi-Selecteasy

A team uses AWS CodeBuild to build a Node.js application. The buildspec.yml file is at the root of the repository. The build fails with 'Error: Cannot find module 'aws-sdk''. Which TWO actions could resolve the issue? (Choose TWO.)

Select 2 answers
A.Ensure 'aws-sdk' is listed in the 'dependencies' section of package.json.
B.Specify a different Node.js runtime version in the buildspec.
C.Add a 'pre_build' phase that runs 'npm test'.
D.Add a 'install' phase that runs 'npm install'.
E.Add a 'build' phase command to compile the code.
AnswersA, D

The 'aws-sdk' package is a runtime dependency, and CodeBuild's npm install phase installs only the modules declared in package.json. If it is missing from the 'dependencies' section, npm will not fetch it, so your Node.js code cannot require it regardless of the environment. Adding it there ensures it is installed with the default dependency installation step, and pinning a version avoids unexpected updates.

Why this answer

The 'aws-sdk' module must be declared in the 'dependencies' section of package.json for npm to install it during the build. Without this declaration, npm install will not download the module, causing the 'Cannot find module' error at runtime. Option D is correct because CodeBuild does not automatically run npm install; you must explicitly include an 'install' phase in buildspec.yml to execute 'npm install' and populate node_modules.

Exam trap

The trap here is that candidates assume CodeBuild automatically runs 'npm install' or that the 'aws-sdk' is always available in the build environment, when in fact both the dependency declaration and explicit install phase are required.

115
MCQeasy

A development team uses AWS CodeCommit for source control and wants to automatically run unit tests on every push to the main branch. Which AWS service should they use to trigger the tests?

A.AWS CodeBuild
B.Amazon CloudWatch Events
C.AWS CodePipeline
D.AWS CodeDeploy
AnswerC

AWS CodePipeline is the correct choice because it natively integrates with CodeCommit as a source action and automatically starts a pipeline execution on every push to the configured branch. It can then invoke test actions (e.g., CodeBuild or third-party test tools) in a defined stage, with options for parallel actions, approvals, and rollback—making it the standard CI/CD orchestrator for this use case.

Why this answer

AWS CodePipeline is the correct service because it provides a fully managed continuous delivery service that can be configured to automatically trigger a build action (such as running unit tests in AWS CodeBuild) whenever a change is pushed to a specified branch in AWS CodeCommit. This is achieved by setting the source stage to the CodeCommit repository and branch, and then adding a build stage that invokes CodeBuild to execute the tests, enabling an automated CI/CD workflow.

Exam trap

The trap here is that candidates often confuse AWS CodeBuild as a standalone trigger because it can run tests, but they overlook that CodeBuild lacks native event-driven triggers and requires an orchestrator like CodePipeline or EventBridge to automate the start on a repository push.

How to eliminate wrong answers

Option A is wrong because AWS CodeBuild is a build service that compiles source code and runs tests, but it does not have native event-driven triggers to automatically start on a CodeCommit push; it requires an external trigger like CodePipeline or Amazon EventBridge. Option B is wrong because Amazon CloudWatch Events (now part of Amazon EventBridge) can capture CodeCommit repository events (e.g., push to branch) but cannot directly run unit tests; it would need to invoke a target like AWS Lambda or CodeBuild, making it an indirect and less integrated solution compared to CodePipeline. Option D is wrong because AWS CodeDeploy is a deployment service that automates application deployments to compute services (e.g., EC2, Lambda) and does not include functionality to run unit tests or trigger builds from source code changes.

116
MCQmedium

A company uses AWS Elastic Beanstalk for deploying web applications. They want to automate deployments whenever a new commit is pushed to the master branch of their CodeCommit repository. Which AWS service should they use to trigger the deployment?

A.AWS CloudTrail
B.AWS OpsWorks
C.Amazon CloudWatch Events
D.AWS CodePipeline
AnswerD

AWS CodePipeline is a fully managed continuous delivery service that orchestrates the stages required to build, test, and deploy your application automatically. It includes a native CodeCommit source action that watches the repository for new commits and completes the deployment by invoking Elastic Beanstalk as a deployment provider, which creates and deploys a new application version to the environment. The service handles sequencing, failure handling, and manual approval gates without requiring custom glue code. Therefore, CodePipeline is the correct answer because it directly integrates the version control and deployment services in a single automated pipeline.

Why this answer

AWS CodePipeline is a fully managed continuous delivery service that can be configured to automatically trigger a deployment pipeline when a new commit is pushed to a CodeCommit repository's master branch. It integrates directly with CodeCommit as a source action and Elastic Beanstalk as a deployment provider, enabling end-to-end automation without custom scripting.

Exam trap

The trap here is that candidates confuse CloudWatch Events (EventBridge) as a direct trigger for Elastic Beanstalk deployments, but it lacks the built-in pipeline orchestration and artifact management that CodePipeline provides for CI/CD workflows.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail is an auditing service that records API calls for governance and compliance, not a service for triggering automated deployments. Option B is wrong because AWS OpsWorks is a configuration management service using Chef or Puppet, not designed for event-driven deployment triggers from CodeCommit. Option C is wrong because Amazon CloudWatch Events (now Amazon EventBridge) can detect CodeCommit events but requires a custom target (e.g., a Lambda function) to invoke Elastic Beanstalk; it does not natively orchestrate the deployment pipeline as CodePipeline does.

117
MCQeasy

An application running on AWS Lambda is experiencing increased error rates. The DevOps engineer needs to quickly identify the root cause. Which AWS service should the engineer use to analyze the logs and errors?

A.AWS X-Ray
B.AWS Trusted Advisor
C.AWS Config
D.AWS CloudTrail
AnswerA

AWS X-Ray traces requests through Lambda and downstream services, exposing latency, errors and their causal path. This gives the engineer the distributed tracing needed to pinpoint the root cause of increased error rates, which CloudWatch logs alone would require manual correlation to achieve.

Why this answer

AWS X-Ray is designed for distributed tracing and root-cause analysis of application errors, including Lambda functions. It captures traces, errors, and latency data across services, making it the right tool to quickly identify where failures originate in a Lambda-based application.

Exam trap

DOP-C02 often tests the distinction between observability services, so candidates pick CloudTrail or Config for application error analysis when those services only cover API auditing and configuration compliance, not runtime tracing.

How to eliminate wrong answers

Option B is wrong because AWS Trusted Advisor provides best-practice checks on cost, security, fault tolerance, and service limits — it does not analyze application logs or errors. Option C is wrong because AWS Config tracks resource configuration changes and compliance, not runtime application errors. Option D is wrong because AWS CloudTrail records API activity and audit events, not application-level error traces or performance data.

118
MCQmedium

A company uses Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The operations team notices that some instances are failing health checks but are not being terminated by Auto Scaling. What should be investigated to resolve this issue?

A.Confirm that the load balancer's health check target is pointing to the correct port and path on the instances.
B.Check the health check grace period setting in the Auto Scaling group. If it is too long, instances failing health checks may not be terminated quickly.
C.Ensure the instances are sending health check requests to the load balancer.
D.Verify that the security group for the instances allows inbound traffic from the load balancer on the health check port.
AnswerB

The health check grace period tells Auto Scaling how long to wait after an instance launches before it starts evaluating the instance's health status. If this value is set too high, an instance that is already failing health checks will continue running without being terminated because the elapsed time since launch has not yet exceeded the grace period. Extending the grace period can therefore leave unhealthy instances in service, which matches the described issue.

Why this answer

The health check grace period in an Auto Scaling group controls how long Auto Scaling waits before checking the health of a newly launched instance. If this grace period is set too long, instances that fail health checks before the grace period expires will not be terminated promptly, leading to the observed behavior where unhealthy instances remain in service even though they are failing health checks. The default grace period is 300 seconds, but if it is excessively long, it delays the termination of instances that fail health checks during that period.

Exam trap

The trap here is that candidates often confuse the health check grace period with the load balancer's health check settings, assuming that if health checks are failing, the issue must be with the health check configuration (Option A) rather than the Auto Scaling group's delay in acting on those failures.

How to eliminate wrong answers

Option A is wrong because the load balancer's health check target pointing to the correct port and path is essential for health checks to work, but the issue here is that instances are failing health checks and not being terminated, not that health checks are misconfigured. Option C is wrong because instances do not send health check requests to the load balancer; the load balancer sends health check requests to the instances, so this option describes a reverse and incorrect flow. Option D is wrong because while security group rules allowing inbound traffic from the load balancer on the health check port are necessary for health checks to succeed, the problem is that instances are failing health checks and not being terminated, not that health checks are failing due to blocked traffic.

119
MCQmedium

A company uses AWS Systems Manager Parameter Store to manage configuration data for its applications. The DevOps team wants to ensure that sensitive parameters, such as database passwords, are automatically rotated every 30 days. The parameters are currently stored as `SecureString` and are referenced by AWS Lambda functions. Which solution will meet these requirements with the LEAST development effort?

A.Store the parameters in AWS Key Management Service (KMS) encrypted S3 buckets and use S3 Lifecycle policies to rotate the encryption keys every 30 days.
B.Use AWS Secrets Manager to store the sensitive parameters and configure automatic rotation using a Lambda rotation function.
C.Create a custom AWS Lambda function that generates new passwords and updates the Parameter Store parameters on a schedule using Amazon EventBridge.
D.Use AWS Systems Manager Automation to run a document that rotates the parameters and updates the Lambda functions' environment variables.
AnswerB

AWS Secrets Manager natively supports automatic rotation of secrets using Lambda functions. It provides built-in rotation templates for databases like Amazon RDS, and you can schedule rotation every 30 days. This requires minimal development effort because the rotation logic is managed by Secrets Manager. The Lambda functions can retrieve secrets directly from Secrets Manager, and rotation is transparent. This is the most efficient solution.

Why this answer

AWS Secrets Manager is designed for secret rotation and integrates with Lambda for automatic rotation. It supports scheduled rotation, reducing development effort compared to custom solutions. Storing secrets in Secrets Manager and enabling rotation every 30 days meets the requirement efficiently, while Parameter Store would require custom rotation logic.

Exam trap

The trap here is assuming that Parameter Store SecureString parameters can be automatically rotated natively, when they cannot; rotation requires custom logic or migration to Secrets Manager.

120
MCQeasy

A DevOps team uses AWS CodeBuild to compile a Java application. The build environment is managed by AWS and runs on Linux. The team wants to speed up the build process by caching dependency directories across builds. Which configuration should the team use?

A.Configure the buildspec file to use Docker layer caching
B.Use the CodeBuild cache configuration to store the entire build output in a custom Docker image
C.Store dependencies in an Amazon S3 bucket and download them at the start of each build
D.Enable local caching in the CodeBuild project and specify the cache location as /root/.m2
AnswerD

Enabling local caching in the CodeBuild project and specifying /root/.m2 as the custom cache location precisely tells CodeBuild to preserve and restore the Maven local repository onto the same build agent across runs. This way, already-downloaded JARs are reused and Maven won't fetch them again, dramatically reducing build time. This is the documented approach for caching Maven dependencies with CodeBuild.

Why this answer

AWS CodeBuild supports local caching, which stores specified directories on the build host's local instance storage. By configuring the cache type as 'local' and specifying the cache location as `/root/.m2` (the default Maven local repository), the team can persist downloaded Maven dependencies across builds, significantly reducing build time by avoiding re-downloading dependencies.

Exam trap

The trap here is that candidates may confuse Docker layer caching (used for container image builds) with local caching for dependency directories, or assume that S3 caching is the only option, overlooking the simpler and faster local cache feature.

How to eliminate wrong answers

Option A is wrong because Docker layer caching is used for Docker builds (e.g., when using `docker build`), not for caching Maven dependencies in a Java build; it does not apply to the dependency directory caching scenario. Option B is wrong because storing the entire build output in a custom Docker image is not a caching mechanism for dependencies; it would create unnecessary image bloat and does not leverage CodeBuild's built-in cache configuration for local or S3 caching. Option C is wrong because manually downloading dependencies from S3 at the start of each build adds network latency and complexity, whereas CodeBuild's local caching provides faster, host-local storage without the overhead of S3 transfers.

121
MCQeasy

A DevOps engineer receives an alert that an Amazon S3 bucket has become publicly accessible. The engineer needs to identify who made the bucket public. Which AWS service should the engineer use to find the API call that changed the bucket policy?

A.Amazon CloudWatch Logs
B.AWS CloudTrail
C.AWS Config
D.Amazon GuardDuty
AnswerB

AWS CloudTrail is the correct answer because it provides a complete audit history of API activity across AWS, including actions performed on S3 buckets such as CreateBucket, PutBucketPolicy, and DeleteBucket. For every management event, CloudTrail captures the IAM user or role, the source IP address, the request parameters, and the response returned, enabling you to answer exactly who did what and when. CloudTrail can also be configured to log data events for object-level S3 operations (GetObject, PutObject) for deeper forensic analysis.

Why this answer

CloudTrail records all S3 API calls, including bucket policy changes. Option A is wrong because CloudWatch monitors metrics. Option C is wrong because Config records configuration changes but not the identity.

Option D is wrong because GuardDuty detects threats but doesn't log API calls.

122
Multi-Selecthard

A company is using AWS CodeBuild to compile and test code. The buildspec.yml file includes a pre_build phase that installs dependencies and a build phase that runs the compilation. The tests are run in the post_build phase. The team wants to improve the security of the build process by ensuring that sensitive information such as database passwords is not exposed in the build logs. Which TWO actions should the team take? (Choose two.)

Select 2 answers
A.Use AWS Systems Manager Parameter Store to store the secrets and reference them in the buildspec using the 'parameter-store' field.
B.Use AWS Secrets Manager to store the secrets and reference them in the buildspec using the 'secrets-manager' field.
C.Restrict access to the build logs by using IAM policies to only allow specific users to view them.
D.Enable encryption at rest for the CodeBuild project's S3 logs.
E.Store the secrets as plain-text environment variables in the CodeBuild project.
AnswersA, B

AWS Systems Manager Parameter Store with the 'parameter-store' field in buildspec is correct because CodeBuild retrieves the SecureString value during build and injects it as an environment variable without ever displaying it in the build log. The value itself is encrypted with KMS and access is controlled by IAM, so this satisfies the requirement to keep secrets out of logs without additional steps.

Why this answer

Option A is correct because CodeBuild natively supports the 'parameter-store' field in buildspec.yml, which retrieves values from AWS Systems Manager Parameter Store at build time and injects them as environment variables without printing them in the logs; the build's service role needs ssm:GetParameters permissions. Option B is correct because CodeBuild also supports the 'secrets-manager' field, which fetches secrets from AWS Secrets Manager during the build and masks them in the logs, requiring secretsmanager:GetSecretValue permissions. Option C is not correct because restricting who can view logs does not prevent secrets from being written into the logs in the first place, so the exposure risk remains.

Option D is not correct because S3 encryption at rest protects stored log objects but does not stop secrets from appearing in plaintext within the logs. Option E is not correct because plain-text environment variables are visible in the CodeBuild console and can be echoed into build logs, directly exposing the sensitive values.

Exam trap

The trap here is that candidates often think restricting log access (Option C) or encrypting logs (Option D) is sufficient to protect secrets, but the core requirement is to prevent secrets from ever being written to logs in the first place.

123
MCQmedium

A development team uses AWS CodeCommit as a source repository for their AWS CodePipeline. They want to automatically trigger a pipeline execution when a new branch is created. Which solution should they implement?

A.Create an S3 event notification to invoke the pipeline when a branch is created.
B.Use Amazon CloudWatch Events to trigger the pipeline on a CodeCommit 'Reference Created' event.
C.Configure a webhook in CodePipeline to detect branch creation events.
D.Set up a polling mechanism in CodePipeline to check for new branches every minute.
AnswerB

Amazon CloudWatch Events (now Amazon EventBridge) natively captures CodeCommit API events, including a 'Reference Created' event when a branch or tag is created. You can configure a rule that matches the repository name and reference type 'branch', then target it to the CodePipeline pipeline for automatic execution. This is the recommended push-based integration because it is serverless, near-real-time, and does not require any external endpoint or polling.

Why this answer

AWS CodePipeline can be configured to start execution automatically when a new branch is created in CodeCommit by using Amazon CloudWatch Events (now part of Amazon EventBridge) to listen for the 'Reference Created' event type. This event is emitted by CodeCommit whenever a new Git reference (such as a branch or tag) is created, and it can directly target a CodePipeline pipeline as a rule target, triggering a new execution without any custom polling or webhook setup.

Exam trap

The trap here is that candidates often confuse webhooks (which are for external Git providers) with native AWS event-driven triggers, leading them to incorrectly select Option C, or they mistakenly think S3 notifications can be used for CodeCommit events (Option A) due to a general familiarity with S3 event-driven architectures.

How to eliminate wrong answers

Option A is wrong because S3 event notifications cannot be generated by CodeCommit branch creation events; S3 events are specific to object-level operations in an S3 bucket, not to Git repository actions. Option C is wrong because CodePipeline webhooks are designed to listen for external events from third-party providers like GitHub or Bitbucket, not for native AWS CodeCommit events, and CodeCommit does not support outgoing webhooks to CodePipeline. Option D is wrong because CodePipeline does not have a built-in polling mechanism to check for new branches; polling would require a custom solution (e.g., a Lambda function) and is not a native feature of CodePipeline.

124
MCQeasy

A company uses AWS CloudFormation to deploy infrastructure. The DevOps team wants to receive notifications when a stack fails to create or update. What is the MOST efficient way to achieve this?

A.Configure an SNS topic in the stack's notification options.
B.Create a custom resource in the stack that publishes to Amazon SNS.
C.Create a CloudWatch alarm on the StackStatus metric.
D.Use Amazon EventBridge to capture CloudFormation events and publish to SNS.
AnswerA

Configuring an SNS topic in the stack's notification options is the native CloudFormation mechanism for sending stack lifecycle events (e.g., CREATE_COMPLETE, UPDATE_FAILED, DELETE_IN_PROGRESS) to a pub/sub channel. You simply provide the topic ARN (up to five) when you create or update the stack, and CloudFormation publishes every stack event to it without requiring any Lambda code, custom resources, or additional infrastructure. This is the simplest and most direct way to get notified about stack changes.

Why this answer

AWS CloudFormation natively supports specifying Amazon SNS topic ARNs in the stack's notification options. When a stack operation (create, update, or delete) fails, CloudFormation automatically publishes a notification to the configured SNS topic without requiring any custom code, additional resources, or external event processing. This is the most efficient approach as it leverages built-in functionality with zero maintenance overhead.

Exam trap

The trap here is that candidates overthink the solution by choosing EventBridge or custom resources, missing the fact that CloudFormation has a built-in, one-step SNS notification feature that is both simpler and more reliable for failure alerts.

How to eliminate wrong answers

Option B is wrong because creating a custom resource in the stack to publish to SNS introduces unnecessary complexity, requires a Lambda function or other compute resource to handle the custom resource lifecycle, and does not reliably capture all stack failure scenarios (e.g., failures during stack creation before the custom resource is processed). Option C is wrong because CloudFormation does not emit a 'StackStatus' metric to CloudWatch; CloudWatch alarms cannot directly monitor CloudFormation stack status without custom metrics or log-based metrics, making this approach infeasible. Option D is wrong because while EventBridge can capture CloudFormation events (e.g., via AWS API calls or CloudTrail), this requires additional configuration, incurs EventBridge costs, and is less efficient than the native SNS notification option that requires no extra services or rules.

125
MCQmedium

The exhibit shows the output of the AWS CLI command 'batch-get-builds' for a CodeBuild build. The build failed. What is the most likely cause of the failure?

A.The source code has compilation errors.
B.The buildspec file is malformed.
C.The build project does not have sufficient memory.
D.The S3 bucket 'my-bucket' does not exist or the build project lacks permissions to access it.
AnswerD

CodeBuild reports a client error when it cannot retrieve source artefacts, and the build log shows an S3 access failure. Either the bucket 'my-bucket' is absent or the service role lacks s3:GetObject permission, so the build fails before compilation begins.

Why this answer

The `batch-get-builds` output shows a failure in the DOWNLOAD_SOURCE phase, with an error indicating that the build could not access the S3 bucket `my-bucket`. The error details, such as 'Access Denied' or 'NoSuchBucket', imply that the CodeBuild service role lacks the required `s3:GetObject` permission on the bucket, or the bucket does not exist. This is a common misconfiguration when the source code is stored in an S3 bucket and the build project is not properly configured to retrieve it.

Exam trap

The trap here is that candidates often assume a build failure is always due to code errors or buildspec issues, but the error message in the CLI output directly points to an S3 permission problem during the DOWNLOAD_SOURCE phase. Unlike artifact uploads which require s3:PutObject, source downloads require s3:GetObject, and candidates must distinguish between the two.

How to eliminate wrong answers

Option A is wrong because compilation errors would produce a different error message in the build logs, typically showing compiler output or exit code 1, not an S3 access-related error. Option B is wrong because a malformed buildspec file would cause a `BUILD_FAILURE` with a YAML parse error or 'Invalid buildspec' message, not an S3 permission error. Option C is wrong because insufficient memory would manifest as an out-of-memory (OOM) kill or a build timeout, not an S3 access denied error.

126
Multi-Selecteasy

A DevOps engineer needs to restrict access to an S3 bucket so that only users from a specific AWS account can read objects. Which TWO methods can achieve this?

Select 2 answers
A.Create an IAM role in the source account with read access to the bucket, and allow users in that account to assume the role.
B.Enable S3 Block Public Access on the bucket.
C.Generate pre-signed URLs for each object and distribute them only to users in the target account.
D.Write a bucket policy that uses the aws:SourceAccount condition to allow access only from the specific account.
E.Set a bucket ACL that grants read access to the target account's canonical ID.
AnswersA, D

Creating an IAM role in the source account with read access to the bucket, and allowing users in that account to assume the role, grants cross-account access by using the role as the principal identity. This approach leverages AWS STS trusts so the bucket policy can restrict the principal to the role's ARN, ensuring only users who assume that role can list and read objects. It avoids permanent cross-account credentials and gives you central control over who may assume the role.

Why this answer

An IAM role in the source account can be granted read access to the S3 bucket via a bucket policy that allows the role's ARN. Users in the source account assume this role, which temporarily provides them with the necessary permissions to read objects. This cross-account access pattern is secure and follows AWS best practices for delegating access across accounts.

Exam trap

The trap here is that candidates often confuse bucket ACLs (Option E) with bucket policies, thinking ACLs can restrict access to a specific account, but ACLs only grant access to the entire account (not individual users) and lack the condition keys needed for fine-grained control.

127
MCQhard

A company uses AWS CodePipeline with an Amazon S3 source action. The pipeline deploys to an Amazon ECS Fargate service. The engineer notices that the pipeline does not automatically start when a new object is uploaded to the S3 bucket. The S3 bucket versioning is enabled. What is the most likely cause?

A.The pipeline has manual approval required before the source stage
B.The S3 bucket does not have event notifications configured for the pipeline
C.S3 versioning is not enabled on the bucket
D.The ECS service is not configured for blue/green deployments
AnswerB

CodePipeline does not automatically poll an Amazon S3 source bucket for new objects unless the bucket has event notifications enabled to emit s3:ObjectCreated:* events to the pipeline. Without an Amazon CloudWatch Events rule or an S3 event notification configured to invoke the pipeline on object writes, the pipeline will only run manually or when explicitly started from the console, CLI, or SDK. This is the standard prerequisite for automatic triggering from an S3 source, and its absence explains why the pipeline remains idle after an upload.

Why this answer

AWS CodePipeline with an S3 source action does not automatically detect new object uploads unless the S3 bucket is configured with event notifications that trigger the pipeline. Without these notifications, the pipeline must be started manually or via a webhook. Since versioning is enabled, the issue is not related to versioning but to the missing event notification configuration.

Exam trap

The trap here is that candidates assume S3 versioning alone enables automatic pipeline triggers, but versioning only ensures object version tracking, not event-driven execution.

How to eliminate wrong answers

Option A is wrong because manual approval is a stage-level action that occurs after the source stage, not a condition that prevents the pipeline from starting; it would block execution but not the trigger itself. Option C is wrong because the question explicitly states that S3 bucket versioning is enabled, so this cannot be the cause. Option D is wrong because blue/green deployments are a deployment strategy for ECS, unrelated to how the pipeline is triggered by S3 events.

128
MCQhard

An organization uses AWS CloudFormation to manage infrastructure. During an incident, a stack update fails with 'UPDATE_ROLLBACK_FAILED' status. The engineer needs to bring the stack to a consistent state without losing data. What is the BEST approach?

A.Use the 'ContinueUpdateRollback' API to skip the resource that caused the failure.
B.Create a new stack from the same template and migrate resources.
C.Manually correct the resource configuration that caused the failure, then perform a stack update.
D.Delete the stack and then recreate it from the same template.
AnswerA

The `ContinueUpdateRollback` API is the designed recovery action when a CloudFormation stack is stuck in the `UPDATE_ROLLBACK_FAILED` state. By invoking it with the `ResourcesToSkip` parameter, you explicitly instruct CloudFormation to skip the specific resource that caused the rollback failure, allowing the stack to return to a stable `UPDATE_COMPLETE` state. This bypasses the problematic resource without requiring manual intervention. It is the recommended and least disruptive method to recover from a failed stack update.

Why this answer

The 'ContinueUpdateRollback' API is the best approach because it allows the stack to resume the rollback process, skipping the resource that caused the failure, and bringing the stack to a consistent 'UPDATE_ROLLBACK_COMPLETE' state without manual intervention or data loss. This API is specifically designed for the 'UPDATE_ROLLBACK_FAILED' status, enabling you to skip resources that cannot be rolled back (e.g., due to a non-reversible change) while preserving the rest of the stack's state.

Exam trap

The trap here is that candidates often choose manual correction (Option C) thinking they can fix the resource and retry the update, but they overlook that the stack is in a failed rollback state that blocks further updates until the rollback is resolved, making 'ContinueUpdateRollback' the only viable path to a consistent state without data loss.

How to eliminate wrong answers

Option B is wrong because creating a new stack from the same template and migrating resources is time-consuming, risks data loss during migration, and does not address the immediate need to recover the existing stack to a consistent state. Option C is wrong because manually correcting the resource configuration and then performing a stack update assumes the failure is fixable via a new update, but the stack is stuck in 'UPDATE_ROLLBACK_FAILED' and cannot accept further updates until the rollback is completed or continued; this approach may also lead to configuration drift and potential data loss. Option D is wrong because deleting the stack would destroy all resources, including any data stored in them (e.g., databases, EBS volumes), which violates the requirement to avoid data loss.

129
MCQhard

A company is building a global application that requires low-latency access to static content across multiple AWS Regions. The content changes infrequently. Which solution is MOST resilient and cost-effective?

A.Use Amazon S3 Transfer Acceleration
B.Set up a VPN to a single Region
C.Deploy EC2 instances in each Region with a global load balancer
D.Use Amazon CloudFront with an S3 bucket as origin
AnswerD

Amazon CloudFront with an S3 bucket as origin is the intended AWS solution for low-latency global delivery of static content. CloudFront caches objects at hundreds of edge locations, so users receive data from the nearest edge POP rather than the origin, drastically reducing latency. The S3 bucket provides durable, cost-effective storage, and CloudFront minimizes origin requests via cache hits, reducing cost. This combination also improves resilience by absorbing traffic spikes at the edge and supports features like SSL, geo-restriction, and signed URLs.

Why this answer

Amazon CloudFront with an S3 bucket as origin provides low-latency global content delivery by caching static content at edge locations worldwide. It is highly resilient because CloudFront automatically routes around failures, and cost-effective since it reduces load on origin and data transfer costs.

Exam trap

DOP-C02 often tests the difference between CDN (CloudFront) and other acceleration services like S3 Transfer Acceleration, causing candidates to choose the latter for global content delivery.

How to eliminate wrong answers

Option A is wrong because S3 Transfer Acceleration speeds up uploads to S3, not global content delivery to users. Option B is wrong because a VPN to a single Region does not provide low-latency access across multiple Regions and adds complexity. Option C is wrong because deploying EC2 instances in each Region with a global load balancer is more expensive and complex than using a CDN, and does not inherently cache content.

130
Multi-Selectmedium

Which TWO options are valid ways to trigger an AWS CodePipeline execution automatically? (Choose two.)

Select 2 answers
A.A scheduled CloudWatch Logs metric filter.
B.Completion of a CodeDeploy deployment.
C.Changes to a CodeCommit repository.
D.Manual approval action in the pipeline.
E.Upload of a new object to an S3 bucket.
AnswersC, E

CodePipeline can be configured to automatically start an execution when a push occurs to a branch (or tag) in a CodeCommit repository. The console sets up a CloudWatch Events rule that matches actions like reference creation or update, and the pipeline's source stage polls for that event; this is a built-in, first-class trigger mechanism for Git-based sources

Why this answer

AWS CodePipeline can automatically start a pipeline execution when a change is detected in a CodeCommit repository. This is achieved through CloudWatch Events that monitor the repository for specific events like push to a branch, and then trigger the pipeline. This integration allows for continuous delivery by automatically building and deploying code changes.

Exam trap

The trap here is confusing pipeline stage actions (like manual approval or deployment completion) with external event sources that automatically start the pipeline; candidates often think any pipeline activity can trigger itself, but only source changes from CodeCommit, S3, or third-party sources like GitHub (via webhooks) are valid automatic triggers.

131
MCQhard

A DevOps engineer is setting up an AWS CodeBuild project to build a Node.js application. The buildspec.yml file includes a pre_build phase that runs npm install and a build phase that runs npm run build. The build is failing with an error indicating that the 'node' command is not found. The CodeBuild project uses a standard Ubuntu image with the 'aws/codebuild/standard:5.0' image. What is the most likely cause of the failure?

A.The CodeBuild service role lacks permissions to download Node.js from the internet.
B.The build phase is using a different shell that does not have Node.js in its PATH.
C.The buildspec.yml file is missing a runtime-versions section specifying Node.js.
D.The pre_build phase must include a command to install Node.js manually using apt-get.
AnswerC

In CodeBuild standard images, the runtime-versions section in the buildspec.yml is required to install and set up the desired runtime, such as Node.js. Without it, the image may not have Node.js pre-installed or may not be in the PATH. The error indicates that the node command is not found, which is resolved by specifying the runtime version.

Why this answer

CodeBuild standard images require the runtime-versions section in the buildspec.yml to install and configure the desired runtime, such as Node.js. Without it, the image may not have Node.js installed, leading to a 'command not found' error. Specifying runtime-versions ensures the correct version is available in the PATH for all phases.

Exam trap

The trap here is assuming that the standard image includes Node.js by default, when it actually requires explicit runtime version specification in the buildspec.

132
MCQhard

Refer to the exhibit. An IAM policy is attached to a user. A developer tries to upload an object to s3://my-bucket/confidential/report.pdf without specifying server-side encryption. What will happen?

A.The upload succeeds because the Allow statement grants PutObject.
B.The upload succeeds because the Deny condition uses a wrong condition key.
C.The upload fails because the Deny statement requires SSE-KMS.
D.The upload fails only if the object name matches the prefix.
AnswerC

An explicit Deny in the IAM policy overrides any Allow, and it is conditioned on the absence of SSE-KMS encryption headers. Because the request specifies no server-side encryption, the Deny matches and the upload is rejected.

Why this answer

The upload fails because the Deny statement in the IAM policy explicitly denies the s3:PutObject action unless the request includes the s3:x-amz-server-side-encryption header with a value of 'aws:kms'. When the developer does not specify server-side encryption, the condition is not met, so the Deny applies, causing the upload to fail. Option A is incorrect because the Allow statement does not override an explicit Deny.

Option B is incorrect because the condition key is correct; the failure is due to the missing encryption header. Option D is incorrect because the Deny is not based on the object name prefix; it applies to all objects in the bucket.

133
MCQmedium

Refer to the exhibit. A CloudFormation stack has been deployed. A developer wants to use the S3 bucket name in a subsequent AWS CLI command. Which command will correctly retrieve the bucket name?

A.aws s3 ls | grep my-stack
B.aws cloudformation describe-stack-resources --stack-name my-stack --logical-resource-id BucketName --query "StackResources[0].PhysicalResourceId" --output text
C.aws cloudformation describe-stacks --stack-name my-stack --query "Stacks[0].Outputs[?OutputKey=='BucketName'].OutputValue" --output text
D.aws cloudformation describe-stacks --stack-name my-stack --query "Stacks[0].Outputs[OutputKey='BucketName'].OutputValue" --output text
AnswerC

This command is correct because it uses `aws cloudformation describe-stacks` to retrieve the stack's metadata, then JMESPath `Stacks[0].Outputs[?OutputKey=='BucketName'].OutputValue` filters the outputs array for the output whose `OutputKey` exactly equals `BucketName` and extracts its `OutputValue`. The `--output text` renders the result as plain text (the actual bucket name). This directly matches the exhibit, which shows the stack's outputs, and is the intended way to programmatically retrieve a CloudFormation output value.

Why this answer

The developer can use the --query parameter with the describe-stacks command to extract the OutputValue for the specific OutputKey 'BucketName'. Option C uses the correct JMESPath syntax with the filter [?OutputKey=='BucketName'] to select the matching output and then retrieves its OutputValue. Option A attempts to list all S3 buckets and grep for 'my-stack', which is unreliable and not the intended method.

Option B uses describe-stack-resources but incorrectly assumes the bucket name is a physical resource ID when it is actually an output value. Option D uses incorrect JMESPath syntax (single bracket with equality) which is invalid.

134
MCQeasy

A company uses AWS Secrets Manager to store database credentials. The security team needs to automatically rotate the secrets every 30 days. Which action should be taken?

A.Enable automatic rotation on the secret and configure the rotation interval to 30 days
B.Manually rotate the secret every 30 days using the AWS Management Console
C.Store the secret in AWS Systems Manager Parameter Store and use a scheduled Lambda to update it
D.Use AWS KMS to rotate the secret by re-encrypting with a new key
AnswerA

Secrets Manager natively supports automatic rotation by invoking a configurable Lambda function that updates both the database credential and the secret value. Setting the rotation interval to 30 days on the secret ensures the database password is rotated without any manual intervention or custom infrastructure. The rotation Lambda must have permission to modify the database and call the UpdateSecret API, and the interval can be adjusted to meet compliance requirements.

Why this answer

AWS Secrets Manager supports automatic rotation of secrets using a Lambda rotation function. By enabling automatic rotation and setting the rotation interval to 30 days, the secret is rotated automatically without manual intervention. This meets the security team's requirement for automatic rotation every 30 days.

Exam trap

DOP-C02 often tests the confusion between secret rotation and KMS key rotation, tricking candidates into selecting KMS when the requirement is to rotate the secret value itself.

How to eliminate wrong answers

Option B is wrong because manual rotation does not meet the requirement for automatic rotation and is error-prone. Option C is wrong because Systems Manager Parameter Store does not natively support automatic rotation of secrets; it would require custom scripting and is not the recommended approach for database credentials. Option D is wrong because AWS KMS key rotation is for rotating the encryption key, not the secret value itself; it does not rotate the database credentials.

135
MCQmedium

A company is using AWS Systems Manager to manage configuration drift on EC2 instances. They want to automatically apply a baseline configuration to instances that have drifted from the desired state. Which Systems Manager capability should they use?

A.AWS Systems Manager Patch Manager
B.AWS Systems Manager Parameter Store
C.AWS Systems Manager Run Command
D.AWS Systems Manager State Manager
AnswerD

AWS Systems Manager State Manager creates associations that define a desired configuration state using SSM documents, and it automatically applies that state on a schedule or when an instance is launched. When a configured resource drifts from the desired state, State Manager detects and remediates it during the next association execution, and it provides compliance status for every managed instance. It is the correct service for ongoing, agent-managed configuration enforcement and drift correction.

Why this answer

AWS Systems Manager State Manager is the correct capability because it is specifically designed to define and maintain consistent configuration states for EC2 instances and other AWS resources. It uses associations to automatically apply a baseline configuration and remediate drift on a schedule or when triggered, ensuring instances remain in the desired state without manual intervention.

Exam trap

The trap here is that candidates often confuse Run Command with State Manager because both can execute commands, but Run Command is for one-time execution while State Manager is for ongoing, automated enforcement of a desired configuration state.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Patch Manager is focused solely on automating the patching of operating systems and applications, not on applying a full baseline configuration or remediating configuration drift. Option B is wrong because AWS Systems Manager Parameter Store is a secure hierarchical store for configuration data and secrets, but it does not have the ability to automatically apply configurations to instances or enforce desired states. Option C is wrong because AWS Systems Manager Run Command allows you to execute scripts or commands on instances remotely, but it is a one-time, ad-hoc execution tool and does not provide ongoing, automated drift detection or remediation.

136
MCQmedium

A company uses AWS CloudFormation StackSets to deploy a VPC with subnets across multiple accounts and regions. Recently, a new account was added to the organization, and the DevOps team wants to deploy the stack set to this new account without affecting existing stacks. The stack set has self-managed permissions. The engineer creates a new stack instance for the account and region, but the operation fails with an 'Access Denied' error when CloudFormation tries to create resources in the new account. The engineer has verified that the stack set's IAM roles exist in the new account. What is the most likely cause?

A.The stack set template contains a resource that is not supported in the target region.
B.The trust policy of the IAM role in the target account does not grant permissions to the administrator account.
C.The target account has reached a service limit for VPCs.
D.The IAM roles in the target account are not named correctly.
AnswerB

This is the correct cause because StackSets with self-managed permissions require the administrator account to assume an IAM execution role in each target account using the sts:AssumeRole API. The target account execution role must include a trust policy that explicitly grants the administrator account (or the StackSets administration role) permission to assume it. If that trust relationship is missing or misconfigured, the administrator account receives an AccessDenied response even though the role exists and the execution role's permissions policy may be correct. Therefore, verifying the role exists is not sufficient; you must verify its trust policy.

Why this answer

With self-managed permissions in CloudFormation StackSets, the administrator account assumes an IAM role in each target account to deploy stacks. The trust policy of that target-account role must explicitly grant sts:AssumeRole to the administrator account (or its role). If the trust policy does not list the administrator account, CloudFormation's attempt to assume the role fails with Access Denied, even though the role exists and has the right permissions policy.

Exam trap

DOP-C02 often tests the distinction between the permissions policy (what the role can do) and the trust policy (who can assume it) — candidates see the role exists and has permissions, and miss that the trust policy must name the administrator account.

How to eliminate wrong answers

Option A is wrong because an unsupported resource in the target region would produce a different error (e.g., 'Resource type not supported in region') during stack creation, not an Access Denied error when assuming the role. Option C is wrong because a VPC service limit would produce a limit-exceeded error (e.g., 'VpcLimitExceeded'), not Access Denied, and the scenario does not indicate the account is at its VPC limit. Option D is wrong because the scenario states the IAM roles exist in the new account; role naming is not the issue — the trust policy is what governs whether the administrator account can assume the role.

137
MCQmedium

A DevOps engineer executes the above CloudWatch Logs Insights query. What will the output contain?

A.The count of ERROR messages per 1-minute interval for the most recent 20 intervals
B.The count of ERROR messages per 5-minute interval for the most recent 20 intervals
C.The total count of ERROR messages in the log group
D.A list of the 20 most recent log entries that contain the word 'ERROR'
AnswerB

The query filters for events containing 'ERROR' and then performs stats count(*) by bin(5m), which aggregates the matching events into consecutive 5-minute time buckets. The results are ordered by bucket timestamp in descending order and limited to 20 rows, so the output is exactly the count of ERROR messages for each of the 20 most recent 5-minute intervals. The bin(5m) function and the LIMIT clause together determine the time span and number of rows returned.

Why this answer

The CloudWatch Logs Insights query uses 'stats count(*) by bin(5m)' which aggregates log events into 5-minute buckets, and 'limit 20' restricts the output to the 20 most recent buckets. Therefore the output is a count of ERROR messages per 5-minute interval for the most recent 20 intervals. The bin() function defines the time bucket size, and the limit applies to the number of result rows returned.

Exam trap

The trap is misreading the bin() interval or confusing 'limit 20' (which limits result rows/buckets) with limiting raw log entries — candidates often assume limit applies to individual log lines rather than aggregated output.

How to eliminate wrong answers

Option A is wrong because bin(5m) creates 5-minute buckets, not 1-minute buckets — a 1-minute interval would require bin(1m). Option C is wrong because the query groups results by time bucket rather than returning a single total; a total count would require removing the 'by bin()' clause. Option D is wrong because the query uses 'stats count(*)' which returns aggregated counts, not raw log entries — returning raw entries would require removing the stats command and using fields/display instead.

138
Multi-Selecthard

A company is using AWS Elastic Beanstalk with a custom platform. The DevOps team wants to automate the creation of a new platform version whenever changes are pushed to a Git repository. The pipeline should run tests, build the platform, and then update the Elastic Beanstalk environment to use the new platform version. Which services should be used together to achieve this? (Choose THREE.)

Select 3 answers
A.AWS CloudFormation
B.AWS CodeBuild
C.AWS CodePipeline
D.HashiCorp Packer (run in CodeBuild)
E.AWS CodeDeploy
AnswersB, C, D

AWS CodeBuild is a fully managed build service that can execute a custom build spec in a disposable compute environment. To create a custom Elastic Beanstalk platform, CodeBuild can run the Packer templates and platform hooks that produce the platform's AMI, making it the correct AWS service for the build itself. Its ephemeral environment, clean snapshots, and retryable builds make it well suited for repeatable platform builds.

Why this answer

AWS CodeBuild is correct because it can run the tests and build the custom platform artifact. In this scenario, CodeBuild executes the buildspec to compile code, run unit tests, and produce the platform version (e.g., an AMI or Packer image). It integrates directly with CodePipeline to receive source changes and pass artifacts downstream for environment updates.

Exam trap

The trap here is that candidates often confuse AWS CodeDeploy with Elastic Beanstalk platform updates, but CodeDeploy cannot create or manage custom platform versions; only CodeBuild with Packer can build the platform artifact, and CodePipeline orchestrates the full CI/CD pipeline.

139
MCQmedium

A DevOps engineer notices that an EC2 instance running a critical application is unresponsive. CloudWatch alarms for CPU utilization and memory usage did not trigger. The engineer checks the system logs and finds an 'Out of memory: Kill process' error. What is the MOST likely cause of the missed alarms?

A.The CloudWatch agent is not installed or configured to collect memory metrics.
B.The instance is using instance store volumes instead of EBS, which prevents metric collection.
C.The CloudWatch metrics retention period is set to 1 day, so old alarms were deleted.
D.The EC2 instance's root EBS volume is encrypted, blocking CloudWatch agent logs.
AnswerA

The CloudWatch agent is required to emit in-guest memory metrics. The default EC2 monitoring collects only hypervisor-level metrics such as CPU utilization, disk I/O, and network throughput; memory utilization is not visible from the hypervisor and must be reported by the agent inside the OS. If the agent is not installed or its configuration does not define memory as a collected metric, the MemoryUtilization metric will be absent, causing any alarm relying on it to remain in INSUFFICIENT_DATA and never trigger.

Why this answer

The 'Out of memory: Kill process' error indicates the OS OOM killer terminated a process due to memory exhaustion, but the CloudWatch memory alarm did not fire because the default CloudWatch metrics for EC2 do not include memory utilization. Memory metrics are only available if the CloudWatch agent is installed and configured to collect them via the mem_used_percent metric. Therefore, the most likely cause is that the agent was not installed or not configured for memory metrics.

Exam trap

The trap is assuming that all EC2 metrics are available by default — candidates forget that memory and disk space require the CloudWatch agent, and they may incorrectly blame storage type or encryption for the missing alarm.

How to eliminate wrong answers

Option B is wrong because instance store vs. EBS has no bearing on CloudWatch metric collection — the CloudWatch agent runs at the OS level and can collect metrics regardless of the underlying storage type. Option C is wrong because CloudWatch metric retention (e.g., 1-day for high-resolution) does not delete alarms; alarms persist and evaluate against available data points, and retention affects historical data, not alarm existence.

Option D is wrong because EBS encryption does not block CloudWatch agent logs or metrics — encryption at rest is transparent to the OS and the agent, and CloudWatch agent communicates over the network, not via the EBS volume directly.

140
Multi-Selectmedium

A DevOps team is designing a CI/CD pipeline for a microservices application that runs on Amazon ECS. They need to implement automated canary deployments. Which TWO AWS services would be essential for this implementation?

Select 2 answers
A.AWS CodeDeploy
B.AWS CloudFormation
C.AWS CodeBuild
D.Amazon CloudWatch
E.Amazon EC2 Auto Scaling
AnswersA, D

AWS CodeDeploy is the native AWS service for performing canary deployments on Amazon ECS. It shifts a specified percentage of production traffic to the new task set (e.g., 10% for 5 minutes) while the old version continues to serve the rest, then gradually increases the new version's traffic until 100%. CodeDeploy orchestrates the entire traffic-shifting process using the AppSpec file, target groups, and optional LifecycleEventHooks such as BeforeAllowTraffic and AfterAllowTraffic, making it the correct choice for a microservices CI/CD pipeline requiring canary releases.

Why this answer

AWS CodeDeploy is essential because it natively supports canary deployments for Amazon ECS through its ECS blue/green deployment type, allowing you to specify a canary traffic shift (e.g., 10% for 5 minutes) before full promotion. This enables automated, controlled rollouts with built-in rollback capabilities based on CloudWatch alarms.

Exam trap

The trap here is that candidates often confuse AWS CodeDeploy with AWS CloudFormation for deployment strategies, or mistakenly think EC2 Auto Scaling is needed for ECS canary deployments, when in fact CodeDeploy and CloudWatch are the essential pair for traffic shifting and monitoring.

141
MCQhard

A company runs a containerized application on Amazon ECS with Fargate launch type. The application experiences periodic spikes in response times. The CloudWatch metrics show high CPU and memory usage for the tasks during these spikes. What is the MOST effective approach to handle these spikes?

A.Use a larger Fargate task size to handle the spikes
B.Increase the CPU and memory limits for the ECS task definition
C.Set up a scheduled scaling action to add tasks during peak hours
D.Configure target tracking scaling policies for the ECS service using CPU or memory utilization
AnswerD

Configuring target tracking scaling policies for the ECS service lets AWS automatically scale the number of tasks in response to actual load, using CloudWatch metrics such as CPUUtilization or MemoryUtilization. The policy works by maintaining a specified target value (for example, 70% CPU) and triggers scale-out or scale-in based on aggregated utilization across the service. This is the recommended pattern for handling spikes in containerized workloads on ECS, as it provides reactive, horizontal scaling without manual intervention.

Why this answer

Target tracking scaling policies for Amazon ECS services using CPU or memory utilization are the most effective approach because they dynamically adjust the number of tasks in response to real-time demand, automatically adding capacity during spikes and removing it when load subsides. This aligns with the AWS Well-Architected Framework's principle of elasticity, ensuring the application scales out precisely when high CPU/memory usage is detected, without manual intervention or over-provisioning.

Exam trap

The trap here is that candidates often confuse increasing task-level resources (CPU/memory limits) with horizontal scaling, or assume scheduled scaling is sufficient, failing to recognize that unpredictable spikes require reactive, metric-based auto scaling.

How to eliminate wrong answers

Option A is wrong because using a larger Fargate task size (e.g., increasing vCPU and memory) addresses the spike by over-provisioning resources for each task, which is cost-inefficient and does not scale the number of tasks; it may still hit limits if the spike exceeds the larger size. Option B is wrong because increasing CPU and memory limits in the task definition only raises the maximum resources a single task can use, but does not add more tasks to handle increased load; it can also lead to throttling if the underlying Fargate platform cannot allocate the requested resources. Option C is wrong because scheduled scaling actions are predictive, not reactive, and cannot adapt to unpredictable spikes; they may add tasks at the wrong times, leading to either insufficient capacity during unexpected spikes or wasted resources during off-peak periods.

142
MCQmedium

A DevOps engineer supports a microservice running on Amazon EKS. During an incident, pods in one node group are repeatedly evicted and the engineer sees node memory pressure conditions. The team wants future incidents to trigger automatic replacement of unhealthy nodes and alerting without manual intervention. Which combination should the engineer implement?

A.Deploy the AWS Node Termination Handler and configure a CloudWatch alarm on node memory metrics to page the team.
B.Configure the Cluster Autoscaler to add nodes when pods are pending and rely on the pod eviction events for alerting.
C.Increase the pod memory requests and limits so the kubelet stops evicting pods, and add a PodDisruptionBudget for alerting.
D.Use a managed node group with health checks enabled and configure the cluster to replace nodes that fail health checks, plus CloudWatch alarms on node conditions for alerting.
AnswerD

Managed node groups perform health checks and can automatically replace nodes that fail them, which addresses unhealthy nodes without manual action. Pairing that with CloudWatch alarms on node condition metrics provides the alerting path, satisfying both automatic replacement and notification requirements for future incidents.

Why this answer

The requirement is twofold: automatically replace unhealthy nodes and alert on node conditions. A managed node group with health checks enabled replaces nodes that fail health checks, and CloudWatch alarms on node condition metrics deliver the alerting. The other approaches either only scale on pending pods, only handle planned interruptions, or tune pod resources without addressing node-level failure.

Exam trap

The trap here is confusing Cluster Autoscaler or Node Termination Handler behavior with node health remediation, when neither automatically replaces a node that is failing due to memory pressure.

143
Multi-Selectmedium

A company is using Amazon CloudWatch Logs to collect logs from multiple applications. The DevOps team wants to create a metric filter to count the number of ERROR log entries and trigger an alarm when the count exceeds 10 in 5 minutes. Which TWO steps must the team take? (Choose TWO.)

Select 2 answers
A.Create a subscription filter to stream logs to Amazon Kinesis Data Firehose.
B.Create a metric filter on the log group that extracts ERROR count.
C.Create a CloudWatch alarm on the metric with the threshold of 10.
D.Set a log group retention policy to retain logs indefinitely.
E.Create a CloudWatch dashboard to visualize the ERROR count.
AnswersB, C

Creating a metric filter on the log group that extracts ERROR count is the first required action. A metric filter defines a pattern, such as the literal string 'ERROR', and evaluates each incoming log event against that pattern; every match increments a specified CloudWatch metric value. The filter can also output a custom value and unit, producing a metric that can be used for alarms and dashboards. This is the native CloudWatch Logs mechanism to translate unstructured log text into a numerical time-series metric.

Why this answer

Option B is correct because a CloudWatch Logs metric filter must be defined on the log group to parse log events and publish a custom metric that counts occurrences of the ERROR pattern; this is the mechanism that turns raw log data into a numeric CloudWatch metric. Option C is correct because once the metric exists, a CloudWatch alarm is created against that metric with a threshold of 10 and an evaluation period of 5 minutes so it can trigger when the count exceeds the limit. Option A is not needed because subscription filters stream logs to destinations like Kinesis Data Firehose for processing, not for creating metrics or alarms.

Option D is irrelevant because retention policy only controls how long log events are stored and does not affect metric filtering or alarming. Option E is unnecessary because a dashboard only visualizes metrics and does not create the metric or trigger the alarm.

Exam trap

DOP-C02 often tests whether candidates confuse the roles of metric filters, subscription filters, and dashboards — the trap is selecting subscription filters (for streaming) or dashboards (for visualization) when the requirement is specifically to count and alarm on log events.

144
MCQeasy

A company uses AWS CodePipeline with a GitHub source action. The pipeline triggers on changes to the master branch. However, the pipeline does not trigger when changes are pushed to the master branch. What is the MOST likely cause?

A.The pipeline uses a different branch name.
B.The GitHub repository is not in the same AWS region as the pipeline.
C.The webhook in GitHub is not properly configured or has been removed.
D.The pipeline does not have permission to access the GitHub repository.
AnswerC

Automatic triggering in CodePipeline with a GitHub source action depends on an active webhook that GitHub uses to notify the CodePipeline API whenever commits are pushed to the repository. If that webhook has been deleted, or if its payload URL or secret token no longer matches what CodePipeline expects, GitHub's push events will never reach CodePipeline and no new pipeline execution will be started. This is the classic cause of 'commits pushed but pipeline doesn't run,' and it is precisely why this is the correct answer.

Why this answer

The most likely cause is that the webhook in GitHub is not properly configured or has been removed. CodePipeline relies on a webhook to automatically detect changes in the GitHub repository. If the webhook is missing or misconfigured, the pipeline will not trigger on pushes.

Option A is incorrect because the pipeline uses the master branch as specified. Option B is incorrect because AWS regions are independent of GitHub; the webhook is not region-specific. Option D is incorrect because pipeline permissions are not required for the webhook to function; the webhook itself is the key mechanism for triggering.

145
MCQhard

A company runs a critical e-commerce application on AWS. The architecture includes an Application Load Balancer (ALB) in front of an Auto Scaling group of EC2 instances running a web server, and an Amazon RDS MySQL Multi-AZ database. The DevOps team has implemented CloudWatch dashboards to monitor key metrics. Recently, customers have reported that the website becomes unresponsive for a few minutes during peak traffic hours. The team reviews the CloudWatch metrics and observes that during the incidents, the ALB's 'TargetResponseTime' metric spikes, and the RDS 'ReadLatency' and 'WriteLatency' metrics also spike. However, the EC2 CPU utilization and memory usage remain normal. The ALB health check shows 'Healthy' for all targets. The team needs to identify the root cause. Which course of action should the team take?

A.Configure the ALB to add a second listener and distribute traffic across multiple target groups.
B.Review the ALB access logs to identify if there are any unusual request patterns causing the latency.
C.Enable Performance Insights on the RDS instance to analyze database performance and identify slow queries.
D.Increase the desired capacity of the Auto Scaling group to add more EC2 instances to handle the load.
AnswerC

Performance Insights for Amazon RDS is the direct diagnostic tool for database performance. It visualizes database load by wait states, SQL statements, and hosts, allowing you to quickly identify slow queries, lock waits, or I/O bottlenecks that are driving the ALB backend latency. This matches the scenario where application instances are healthy but the database is the constraint, making it the correct next step for root-cause analysis.

Why this answer

Option C is correct because the symptoms — spiking ALB TargetResponseTime alongside spiking RDS ReadLatency and WriteLatency, with normal EC2 CPU/memory and healthy targets — point to a database bottleneck, most likely slow or inefficient queries. Performance Insights is the AWS-native tool for identifying top SQL statements, wait events, and database load contributors, so it directly addresses the root cause. Adding instances or listeners would not help because the bottleneck is downstream at the database, not at the application tier.

Exam trap

The trap is chasing the loudest symptom — the ALB TargetResponseTime spike — and adding application-tier capacity, when the correlated RDS latency metrics reveal the database as the true bottleneck.

How to eliminate wrong answers

Option A is wrong because adding a second ALB listener and target group only changes traffic routing; it does nothing to reduce database latency, which is the actual bottleneck. Option B is wrong because ALB access logs show request-level patterns (URLs, status codes, latencies) but cannot reveal SQL-level causes inside RDS — they would confirm the symptom, not diagnose the root cause. Option D is wrong because EC2 CPU and memory are normal, so the application tier is not resource-constrained; adding instances would multiply concurrent database connections and could worsen the problem.

146
MCQmedium

A company runs a containerized application on Amazon ECS with Fargate launch type. The application is behind an Application Load Balancer (ALB). The operations team notices that the ALB's 5xx error rate increases periodically. The ECS service is configured with a target tracking scaling policy based on CPU utilization. The CloudWatch logs from the application show no errors. The health check on the ALB is configured to hit the /health endpoint. What is the MOST likely cause of the 5xx errors?

A.The ECS tasks are running on an underlying host that is being patched.
B.The health check endpoint is returning a 503 status due to a dependency failure.
C.The target tracking scaling policy is not responding quickly enough to traffic spikes.
D.The application is throwing exceptions that are not logged.
AnswerB

This is the correct explanation because the ALB health check probes the configured endpoint and expects a successful status code, and a 503 returned by that endpoint indicates the application's dependency (for example, a database or downstream API) is unavailable. When the health check receives 503 for all tasks, the ALB marks the targets unhealthy and stops routing traffic, ultimately returning HTTP 503 to clients. The symptom therefore matches the health check failure, not an application exception or scaling issue.

Why this answer

The ALB periodically reports 5xx errors because the health check endpoint /health is returning a 503 status code, likely due to a transient dependency failure. When the health check fails, the ALB considers the target unhealthy and returns a 503 (or 502) to clients. The application code itself logs no errors because the failure occurs in a downstream dependency that the health check probes, not in the main application logic.

Option A is incorrect because ECS with Fargate does not expose underlying host patching; the ALB would not detect such patching as 5xx errors. Option C is incorrect because a target tracking CPU scaling policy, even if slow, would not cause 5xx errors—it would affect performance but not directly trigger health check failures. Option D is incorrect because the application logs show no errors, ruling out unlogged exceptions as the source.

147
MCQhard

A company uses AWS Organizations with multiple accounts. The security team requires that all newly created S3 buckets in any account automatically have default encryption enabled and block public access. Which solution is MOST operationally efficient?

A.Use AWS CloudTrail to monitor bucket creation and trigger a Lambda function to apply settings
B.Apply a service control policy (SCP) that denies creation of buckets without encryption and public access block
C.Create a bucket policy on each existing bucket and rely on developers to apply it to new buckets
D.Use AWS Config rules to detect non-compliant buckets and send notifications
AnswerB

An SCP is a preventive, organization-wide control enforced by AWS Organizations before the action is authorized; it cannot be overridden by any IAM policy within the account. To deny non-compliant creation, you attach to the root/OU a policy that denies s3:CreateBucket with a StringNotEquals condition on s3:x-amz-server-side-encryption and a StringNotEquals condition on s3:x-amz-public-access-block, so only requests meeting both criteria succeed. This approach automatically covers every existing and future account and bucket without custom code or manual catch-up.

Why this answer

The most operationally efficient solution is to use an SCP in AWS Organizations that denies creation of S3 buckets without default encryption and public access block. This enforces the security requirements at the organization level, preventing non-compliant bucket creation across all accounts without additional automation. Option A relies on CloudTrail and Lambda, which is reactive and adds complexity.

Option C is manual and not scalable. Option D uses AWS Config to detect non-compliant buckets but requires additional remediation steps, making it less efficient than a preventive SCP.

148
MCQeasy

A development team uses AWS CodeBuild to compile a Java application. The build fails during the 'Install' phase with an error: 'Error: JAVA_HOME is not set'. How should the team fix this?

A.Set the environment variable 'JAVA_HOME' in the buildspec file's 'env' section.
B.Use the managed image 'aws/codebuild/standard:5.0' which has Java pre-installed.
C.Install Java in the pre_build phase using a command.
D.Use a custom Docker image that has Java pre-installed.
AnswerA

Setting JAVA_HOME in the buildspec's env section ensures the variable is exported into every build phase's shell before commands run. This resolves the 'invalid JAVA_HOME' error because Maven or Gradle translates this variable into the absolute path of the JDK installation, which is needed for compilation. It's the canonical fix and works regardless of which base image CodeBuild uses.

Why this answer

The error 'JAVA_HOME is not set' indicates that the build environment lacks the required environment variable pointing to the Java installation. In AWS CodeBuild, the buildspec file's 'env' section allows you to define environment variables, including 'JAVA_HOME', which can be set to the path of the Java runtime (e.g., '/usr/lib/jvm/java-11-openjdk-amd64'). This ensures the variable is available during the Install phase, resolving the error without altering the build image or adding installation steps.

Exam trap

The trap here is that candidates assume using a managed image with Java pre-installed automatically sets JAVA_HOME, but AWS CodeBuild images do not always export this variable by default, requiring explicit definition in the buildspec.

How to eliminate wrong answers

Option B is wrong because using a managed image like 'aws/codebuild/standard:5.0' does not guarantee that JAVA_HOME is set; while Java is pre-installed, the environment variable may not be defined by default, leading to the same error. Option C is wrong because installing Java in the pre_build phase is unnecessary if Java is already present, and it does not address the root cause—JAVA_HOME not being set; the variable must be explicitly defined. Option D is wrong because using a custom Docker image with Java pre-installed still requires setting JAVA_HOME in the buildspec or Dockerfile; otherwise, the variable may be missing, causing the same failure.

149
MCQmedium

An organization uses AWS Systems Manager Incident Manager for incident response. They have created a response plan with an engagement plan that pages the on-call engineer via SMS. The engineer acknowledges the incident but then does not take any further action. What is the BEST way to automate escalation?

A.Manually re-page the on-call engineer with a higher urgency.
B.Use Amazon CloudWatch Events to trigger a second SMS if the incident is not resolved within a time frame.
C.Create an AWS Lambda function that checks the incident status and pages the next responder if no action is taken.
D.Configure an escalation plan in the response plan that pages a secondary contact after a specified timeout.
AnswerD

An escalation plan is a first-class component of an AWS Systems Manager Incident Manager response plan. You define a total duration (e.g., 10 minutes) and add engagement targets such as individual contacts, chat channels, or a full on-call schedule; if the primary responder does not acknowledge the incident within that window, Incident Manager automatically pages the secondary/next-level contact using the configured contact channels (SMS, voice, mobile push). This is the intended solution because it is fully managed, idempotent, and does not require any custom code or additional AWS services. Escalation plans also support multiple levels, and you can set the engagement duration per target to progressively move up the chain until someone acknowledges.

Why this answer

Systems Manager Incident Manager supports escalation plans with timeouts and multiple engagement levels. Option A is wrong because manual re-paging does not provide automated escalation and requires human intervention. Option B is wrong because CloudWatch Events can trigger actions but is not the built-in escalation mechanism within Incident Manager; that capability is provided by escalation plans.

Option C is wrong because while a Lambda function could be used, it is not the best or simplest approach; Incident Manager natively supports escalation plans.

150
Multi-Selectmedium

A DevOps engineer is investigating a security incident where an EC2 instance was compromised. The engineer needs to collect forensic data without losing volatile information. Which TWO actions should the engineer take? (Choose two.)

Select 2 answers
A.Detach the EBS volumes and attach them to a forensic instance.
B.Retrieve the instance metadata from the console.
C.Create a snapshot of the attached EBS volumes.
D.Collect a memory dump from the instance before stopping it.
E.Terminate the instance immediately to prevent further access.
AnswersC, D

Creating a snapshot of the attached EBS volumes is a core forensic preservation technique because it captures the full disk state—including deleted file remnants, user-space artifacts, logs, and malware binaries—without stopping the instance. Unlike a live filesystem copy, an EBS snapshot is crash-consistent (or application-consistent with pre-freeze), providing a point-in-time image that can be analyzed on a separate forensic instance without risking further alteration of the original evidence. This must be done before any stop/termination, since those actions can change or destroy disk data.

Why this answer

Option C is correct because creating an EBS snapshot captures a point-in-time, crash-consistent copy of the attached volumes, preserving disk-based forensic evidence (file system, logs, malware artifacts) without altering the running instance. Option D is correct because volatile data such as RAM contents, running processes, network connections, and encryption keys exist only in memory and are lost once the instance is stopped or terminated, so a memory dump must be collected first. Option A is wrong because detaching EBS volumes from a running instance is not supported and would disrupt the live system before volatile data is captured.

Option B is wrong because instance metadata contains only configuration data (instance ID, AMI, IAM role, user data) and provides no forensic value for the compromise. Option E is wrong because terminating the instance destroys both volatile memory and the instance store, and may also delete EBS volumes depending on the DeleteOnTermination setting, irreversibly destroying evidence.

Exam trap

The trap is choosing actions that seem to preserve evidence (detaching volumes, terminating) but actually destroy volatile data or alter the scene; the exam tests knowledge of order of volatility and proper forensic sequence.

Page 1

Page 2 of 18

Page 3