Courseiva

AWS Certified DevOps Engineer Professional DOP-C02 (DOP-C02) — Questions 151–225

1298 questions total · 18pages · All types, answers revealed

Page 2

Page 3 of 18

Page 4
151
MCQhard

A company runs a critical application on Amazon RDS for PostgreSQL. The database experiences periodic slowdowns. The team wants to monitor the number of active connections and the query execution time. Which approach is most cost-effective?

A.Install the CloudWatch agent on the RDS instance to collect custom metrics.
B.Use the RDS console to view the 'DatabaseConnections' and 'QueryExecutionTime' metrics.
C.Enable Performance Insights and set up CloudWatch alarms on the 'DBLoad' metric.
D.Enable Enhanced Monitoring and publish metrics to CloudWatch, then create alarms on relevant metrics.
AnswerC

Performance Insights exposes the DBLoad metric, which represents the average number of active sessions and directly reflects query execution workload, and it can be streamed to CloudWatch for alarm creation. Per-query execution time is visible through the top SQL dashboard, allowing you to correlate load spikes with specific queries. The basic retention is included with RDS at no additional cost, making this a cost-effective and fully managed solution for monitoring query performance.

Why this answer

Performance Insights provides detailed query execution time metrics, enabling monitoring of query performance. It also includes the 'DBLoad' metric which reflects database load from active connections and queries. Combined with CloudWatch alarms, this approach is cost-effective as Performance Insights is included with RDS at no additional cost for up to 7 days of retention (longer retention has a fee).

Options A and B are invalid because the CloudWatch agent cannot be installed on RDS instances, and 'QueryExecutionTime' is not a standard CloudWatch metric for RDS. Option D is less suitable for the specific requirement of query execution time; Enhanced Monitoring provides OS-level metrics like processes and memory but does not track query-level execution time.

Exam trap

Candidates often assume Enhanced Monitoring is the most cost-effective because it is free, but it lacks query-level performance data. The key is that Performance Insights tracks execution time natively and is included at no extra cost for the first 7 days, making it the correct choice for this requirement.

How to eliminate wrong answers

Option A is wrong because the CloudWatch agent cannot be installed on an RDS instance; RDS is a managed service and does not allow direct OS access or agent installation. Option B is wrong because 'QueryExecutionTime' is not a standard metric available in the RDS console; the console provides 'DatabaseConnections' but not query execution time. Option C is wrong because Performance Insights focuses on database load (DBLoad) and query performance analysis, but it does not directly expose the number of active connections as a metric for CloudWatch alarms; additionally, enabling Performance Insights incurs extra costs beyond the basic RDS pricing.

152
MCQhard

A company is using AWS CloudFormation to deploy infrastructure. The security team wants to ensure that any changes to IAM roles must be reviewed and approved by a security engineer before deployment. The DevOps engineer needs to implement a gating mechanism. Which approach should the engineer use?

A.Use AWS Config to detect changes to IAM roles and trigger a Lambda function that reverts the change.
B.Apply a service control policy that denies iam:CreateRole and iam:UpdateAssumeRolePolicy across the organization.
C.Add a condition to the IAM policy that requires MFA for any CloudFormation action.
D.Create a CodePipeline that deploys CloudFormation stacks and include a manual approval step for changes that modify IAM resources.
AnswerD

A CodePipeline that deploys CloudFormation stacks can include a manual approval stage, which acts as a preventive control that pauses the pipeline before the stack update executes. The pipeline can detect when a change set modifies IAM resources—for example, by comparing the template or reviewing the change set—and conditionally require an approval step. This ensures a second person reviews the IAM changes before they are applied, satisfying the separation-of-duties requirement. Manual approval is a standard AWS pattern for production governance and is far more effective than post-hoc detection or MFA alone.

Why this answer

AWS CodePipeline can include a manual approval step before deploying CloudFormation stacks, allowing the security engineer to review and approve any changes to IAM roles. Option A is incorrect because AWS Config only detects changes after they occur; it cannot prevent deployment. Option B is incorrect because a service control policy would deny all IAM role creation across the organization, which is too restrictive and not a gating mechanism.

Option C is incorrect because requiring MFA for CloudFormation actions does not specifically gate changes to IAM resources.

153
Multi-Selectmedium

Which THREE are components of the AWS Shared Responsibility Model? (Choose THREE.)

Select 3 answers
A.AWS is responsible for patching customer applications on EC2
B.Customers are responsible for managing IAM users and permissions
C.AWS is responsible for managing customer IAM roles
D.Customers are responsible for securing their data in the cloud
E.AWS is responsible for the security of the cloud infrastructure
AnswersB, D, E

IAM is a customer-controlled service: customers define users, groups, roles, policies, and permission boundaries, and they are accountable for the identity and access management decisions they implement. AWS provides the IAM service itself and keeps its control plane available, but it does not create, modify, or assume customer identities or make authorization decisions on the customer's behalf. Correctly scoping least-privilege IAM policies, enabling multi-factor authentication, and rotating credentials are customer responsibilities that directly impact the security of everything deployed in the account.

Why this answer

Option B is correct because under the AWS Shared Responsibility Model, identity and access management — including creating, managing, and rotating IAM users, groups, roles, and policies — is a customer responsibility in the cloud. Option D is correct because customers are always responsible for the security and classification of their own data, including encryption choices and access controls, regardless of which AWS service is used. Option E is correct because AWS is responsible for security OF the cloud, meaning the physical facilities, hardware, networking, and foundational services that underpin the AWS global infrastructure.

Option A is incorrect because patching guest operating systems and customer applications on EC2 is the customer's responsibility, not AWS's. Option C is incorrect because managing customer IAM roles is a customer task; AWS only provides and secures the IAM service itself.

Exam trap

DOP-C02 often tests the Shared Responsibility Model; candidates may incorrectly assume AWS manages IAM roles or patches customer applications, but those are customer responsibilities.

154
Multi-Selectmedium

A company uses AWS CodePipeline to automate deployments. The pipeline consists of Source, Build, and Deploy stages. The Build stage uses CodeBuild, and the Deploy stage uses CodeDeploy. Recently, the pipeline failed at the Deploy stage with an error: 'The deployment group does not exist'. Which TWO actions should the team take to resolve this issue?

Select 2 answers
A.Verify that the deployment group name specified in the pipeline's Deploy stage matches the actual deployment group name in CodeDeploy.
B.Confirm that the pipeline and the CodeDeploy deployment group are in the same AWS Region.
C.Increase the timeout for the Deploy stage to allow more time for the deployment group to be created.
D.Ensure that the CodeBuild project has permissions to access the CodeDeploy deployment group.
E.Check that the CodeDeploy application exists in the same AWS account as the pipeline.
AnswersA, B

The `Deploy` stage action stores a literal `DeploymentGroupName` string that must exactly match the name of an existing deployment group in the target CodeDeploy application. This string is case-sensitive and cannot include trailing spaces or a mangled formatted name. When CodeDeploy receives the pipeline's `CreateDeployment` API call, it validates the deployment group against the application in the region; if no exact match exists, it returns the 'Deployment group not found' error. To resolve it, open the pipeline's Deploy stage action and compare the `DeploymentGroupName` value to the deployment group name shown in the CodeDeploy console.

Why this answer

The error 'The deployment group does not exist' directly indicates a mismatch between the deployment group name specified in the CodePipeline Deploy stage configuration and the actual deployment group name defined in CodeDeploy. The pipeline's Deploy stage action references a deployment group by name; if that name does not match an existing group in CodeDeploy, the deployment fails. Verifying and correcting this name resolves the issue.

Exam trap

The trap here is that candidates often confuse the deployment group name with the CodeDeploy application name, or assume that the pipeline will automatically create the deployment group, leading them to choose irrelevant options like increasing timeout or checking CodeBuild permissions.

155
MCQmedium

Refer to the exhibit. An administrator wants to be notified when any EC2 instance is launched in the account. Which combination of services would provide the most efficient and cost-effective solution?

A.Enable detailed billing reports and create a cost anomaly detection monitor.
B.Use AWS Config rules to detect non-compliant instances and trigger an SNS notification.
C.Create an Amazon EventBridge rule that matches RunInstances events from CloudTrail and sends to an SNS topic.
D.Set up a CloudWatch alarm on the RunInstances metric in the EC2 namespace.
AnswerC

An EventBridge rule can match event patterns against CloudTrail records, for example source 'aws.ec2', detail-type 'AWS API Call via CloudTrail', and eventName 'RunInstances'. When a matching API call occurs, EventBridge invokes an SNS topic in near real time, and the event payload contains instance IDs, user identity, request parameters, and response elements. This is the native AWS event-driven pattern for reacting to EC2 API activity.

Why this answer

The most efficient and cost-effective solution is to create an Amazon EventBridge rule that matches RunInstances events from CloudTrail and sends notifications to an SNS topic. EventBridge provides near real-time event processing with minimal overhead, and CloudTrail captures EC2 instance launch events. This avoids the need for continuous polling or additional services.

Exam trap

DOP-C02 often tests the confusion between CloudWatch metrics and CloudTrail events, and candidates may incorrectly assume CloudWatch has a RunInstances metric.

How to eliminate wrong answers

Option A is wrong because detailed billing reports and cost anomaly detection are for cost monitoring, not for real-time instance launch notifications. Option B is wrong because AWS Config rules evaluate compliance periodically, not in real-time, and may incur additional costs. Option D is wrong because CloudWatch does not have a RunInstances metric in the EC2 namespace; such events are not metrics but API calls logged by CloudTrail.

156
MCQmedium

A company is using AWS Lambda functions for data processing. The operations team needs to monitor the number of invocations, duration, and error counts for each function. They also want to set alarms when the error rate exceeds 5% in a 5-minute period. Which combination of AWS services should the team use to achieve this with minimal effort?

A.Use AWS CloudTrail to log Lambda invocations and configure CloudWatch alarms on the log events.
B.Enable Lambda Insights to collect detailed metrics and use CloudWatch dashboards to monitor error rates.
C.Stream Lambda logs to CloudWatch Logs and use CloudWatch Logs Insights to query error rates, then create alarms.
D.Use CloudWatch metrics published by Lambda and create a CloudWatch alarm on the ErrorCount metric with a math expression to calculate error rate.
AnswerD

Lambda automatically emits a set of standard metrics to CloudWatch, including 'Invocations', 'Errors', and 'ErrorCount' (via enhanced metrics if enabled), so you can directly build an error-rate expression without additional setup. The correct approach is to use a CloudWatch math expression, such as 'm1/m2*100' where m1 is ErrorCount and m2 is Invocations, and then create an alarm on that expression to alert when the error rate exceeds a threshold. This leverages the native, low-latency monitoring pipeline and avoids the overhead of log-based or third-party tooling, making it the simplest and most operationally sound solution.

Why this answer

Lambda automatically publishes metrics to CloudWatch, including Invocations, Duration, and Errors. To monitor error rate, you can create a CloudWatch alarm using a math expression that calculates the error rate from the ErrorCount and Invocations metrics. This approach requires minimal effort because it leverages built-in metrics and CloudWatch's native alarm capabilities.

Exam trap

DOP-C02 often tests the distinction between metrics and logs; candidates may choose log-based solutions, but the exam favors using built-in CloudWatch metrics and math expressions for minimal effort and real-time monitoring.

How to eliminate wrong answers

Option A is wrong because CloudTrail logs API calls, not Lambda invocations, and does not provide metrics for duration or error counts. Option B is wrong because Lambda Insights provides enhanced metrics but requires additional setup and is not necessary for basic error rate monitoring. Option C is wrong because streaming logs to CloudWatch Logs and using Logs Insights to query error rates is more complex and does not directly create alarms; it would require custom metric filters and alarms.

157
MCQmedium

An S3 bucket has the above bucket policy. What is the net effect on GetObject requests?

A.All anonymous users can read objects
B.All requests are denied
C.Only requests from IP range 192.0.2.0/24 are allowed
D.Only authenticated users can read objects
AnswerC

The net effective policy is that only clients with source IP addresses in 192.0.2.0/24 are permitted to read objects. The Allow statement grants s3:GetObject to Principal "*", but the Deny statement with NotIpAddress of that range blocks all other source IPs; because explicit deny overrides allow, the condition on the deny becomes the controlling factor. This creates a whitelist: any request not coming from 192.0.2.0/24, even an authenticated AWS identity, is denied, while any request from that range, including anonymous users, is allowed.

Why this answer

The bucket policy grants s3:GetObject to everyone (Principal "*") but wraps it in a Condition restricting the source to the 192.0.2.0/24 CIDR via aws:SourceIp. Because the Allow statement is conditional, only requests originating from that IP range satisfy the policy and are permitted; all other requests are implicitly denied since S3 is deny-by-default. The net effect is that GetObject succeeds only for callers inside 192.0.2.0/24.

Exam trap

The trap is reading Principal "*" and jumping to 'public access' or 'all denied' without noticing the Condition block — DOP-C02 frequently tests whether you evaluate the entire policy statement, including conditions, before deciding the net effect.

How to eliminate wrong answers

Option A is wrong because the Principal "*" is not unconditional — the aws:SourceIp condition narrows the grant, so anonymous users outside the CIDR are denied. Option B is wrong because the policy contains an explicit Allow that is satisfied for in-range requests, so not all requests are denied. Option D is wrong because the policy does not reference authentication or IAM principals at all; it is an IP-based condition, and an anonymous caller from inside 192.0.2.0/24 would actually be allowed.

158
MCQhard

An AWS account owner (Account A) owns an S3 bucket named my-bucket. The bucket policy shown in the exhibit is attached to the bucket. A user from Account B attempts to upload an object to the bucket without specifying the x-amz-acl header. What will happen?

A.The upload fails because the bucket policy requires the object ACL to be set, but the default ACL allows the upload anyway.
B.The upload succeeds because the bucket policy does not explicitly deny the request.
C.The upload succeeds because the bucket policy allows s3:PutObject for any principal.
D.The upload fails because the bucket policy requires the x-amz-acl header to be set to bucket-owner-full-control.
AnswerD

The bucket policy uses a condition key such as s3:x-amz-acl with a value of bucket-owner-full-control, making that header a mandatory requirement for any successful s3:PutObject call. When the requester omits the x-amz-acl header, the condition evaluates to false, so the allow statement cannot grant the action. With no other applicable allow, the request is implicitly denied and the upload fails. This design ensures the bucket owner can later manage or delete the object by forcing ownership transfer via the canned ACL.

Why this answer

The condition requires the x-amz-acl header to be set to bucket-owner-full-control. If the header is not specified, the condition fails, and the request is denied. Option A is wrong because the condition is not met.

Option B is wrong because the policy does not grant permission without the header. Option C is wrong because the bucket policy evaluates before the object ACL.

159
MCQmedium

A DevOps engineer created the IAM policy shown in the exhibit and attached it to a user. The user tries to upload an object to my-bucket without specifying the ACL. Why does the upload fail?

A.The Effect should be Deny for this policy to work
B.The resource ARN is incorrect; it should be arn:aws:s3:::my-bucket
C.The user does not have permission to list the bucket
D.The policy condition requires the ACL to be bucket-owner-full-control, but the user did not specify it
AnswerD

Correct — the policy's Condition uses StringEquals to require the s3:x-amz-acl value of bucket-owner-full-control on every PutObject request. When the user's PutObject request does not specify that exact ACL (either omits the x-amz-acl header or sets it to another value), the condition evaluates false. IAM authorization is deny-by-default: without an explicitly matching allow statement, the request is implicitly denied, producing the denied message. The user must include x-amz-acl: bucket-owner-full-control, or the policy must be adjusted if that enforcement is not desired.

Why this answer

The policy condition requires the ACL to be 'bucket-owner-full-control'. If the user does not specify an ACL, the default is usually 'private', which does not satisfy the condition. Therefore the action is denied.

The resource ARN is correct. The action is allowed. The condition specifies StringEquals, which is correct for comparison.

160
MCQhard

An IAM policy is attached to a user who needs to create a CloudFormation stack that provisions an EC2 instance and an S3 bucket. The user receives an 'Access Denied' error when running the 'aws cloudformation create-stack' command. Which additional permission is required?

A.ec2:RunInstances and s3:CreateBucket
B.s3:PutObject
C.cloudformation:DescribeStacks
D.iam:PassRole
AnswerA

CloudFormation assumes the IAM permissions of the calling user when provisioning resources from a template. To launch an EC2 instance, ec2:RunInstances is required, and to create an S3 bucket, s3:CreateBucket is required, because those are the specific API calls CloudFormation makes on your behalf. Without these actions, stack creation will fail even if other permissions are present.

Why this answer

To successfully create a CloudFormation stack that provisions an EC2 instance and an S3 bucket, the IAM user must have permissions for the actions that CloudFormation will perform on their behalf. Specifically, ec2:RunInstances and s3:CreateBucket are required in addition to cloudformation:CreateStack. The 'Access Denied' error occurs because the user lacks these resource-level permissions.

Notably, the DeletionPolicy attribute (e.g., Retain) only controls behavior when resources are deleted, not during stack creation or updates; it does not affect the permissions required for provisioning.

Exam trap

The trap here is that candidates assume the cloudformation:CreateStack permission alone suffices, but the DOP-C02 exam tests the understanding that CloudFormation acts as a proxy, requiring the caller to have permissions for every resource it provisions.

How to eliminate wrong answers

Option B is wrong because s3:PutObject is used to upload objects to an existing S3 bucket, not to create the bucket itself; creating a bucket requires s3:CreateBucket. Option C is wrong because cloudformation:DescribeStacks is a read-only permission that allows viewing stack details, not creating resources; it does not grant the ability to provision EC2 or S3. Option D is wrong because iam:PassRole is used to pass an IAM role to a service (e.g., for EC2 instance profiles), but the question does not mention any role being passed in the template; the error stems from missing resource creation permissions, not role passing.

161
Multi-Selectmedium

A company is using Amazon CloudWatch to monitor its production environment. The operations team receives alerts for the same underlying issue from multiple alarms, causing alert fatigue. The team wants to reduce noise and consolidate alerts into actionable notifications. Which TWO steps should the team take? (Choose two.)

Select 2 answers
A.Configure the CloudWatch alarms to publish to an SNS topic, and use SNS subscription filter policies to route only critical notifications.
B.Use CloudWatch Evidently to run experiments and filter out false alarms.
C.Use CloudWatch composite alarms to combine multiple alarms into a single alarm that triggers only when certain conditions are met.
D.Use CloudWatch Logs Insights to query logs and create alarms based on the query results.
E.Use AWS Config rules to automatically suppress alarms that are not compliant.
AnswersA, C

Publishing CloudWatch alarms to an SNS topic and applying subscription filter policies is a valid approach because SNS supports content-based filtering on message attributes. When an alarm transitions to ALARM state, it publishes a message with attributes like `state` and `severity`; each subscriber can define filter policies that match only their desired subset (e.g., `state = ALARM` with high severity). This effectively routes critical notifications to the right team while suppressing non-critical messages at the subscription level, without altering the alarm logic itself.

Why this answer

You can configure CloudWatch alarms to publish to an SNS topic and use SNS subscription filter policies to route only critical notifications, thereby reducing noise. Option C is correct because CloudWatch composite alarms allow you to combine multiple alarms into a single alarm that triggers only when specific conditions (e.g., AND/OR logic) are met, consolidating alerts for the same underlying issue. Option B is incorrect because CloudWatch Evidently is used for running experiments and feature flags, not for alert consolidation.

Option D is incorrect because CloudWatch Logs Insights is a tool for querying log data, not for combining alarms. Option E is incorrect because AWS Config rules are designed to evaluate resource compliance, not to suppress alarms.

162
MCQhard

A company uses AWS CodePipeline with multiple stages: Source (Amazon S3), Build (AWS CodeBuild), and Deploy (AWS CodeDeploy). The build stage runs a series of tests, and if they pass, the pipeline proceeds to deploy. Recently, a developer committed a change that passed all tests but caused a production outage. The team wants to add an approval step before the deploy stage, but they also want to ensure that only changes from specific branches can be deployed. What is the MOST secure and maintainable way to enforce this?

A.Use a Lambda function in the pipeline to check the branch name and fail if not allowed.
B.Add a manual approval step in the pipeline and rely on the approver to verify the branch.
C.Create a separate pipeline for each allowed branch, with the approval step only in the production pipeline.
D.Tag the source artifacts with the branch name and use a condition in CodePipeline to allow only specific tags.
AnswerC

Creating a separate pipeline per allowed branch makes the pipeline definition itself the security boundary. Only branches that have an explicitly defined pipeline can ever proceed through the release stages, so committing to an unauthorized branch simply does not trigger a deployment even if the code is structurally valid. The production pipeline includes a manual approval step, and because that pipeline sources solely from an approved branch (e.g., main), the approval verifies the intended deployable artifact rather than attempting to check a branch name at runtime. This isolation prevents accidental or malicious deployment from unapproved branches without relying on inline validation or easily modified Lambda actions.

Why this answer

It enforces branch-based deployment at the pipeline level, ensuring that only changes from specific branches trigger the production pipeline with the approval step. This approach is secure and maintainable as it leverages AWS CodePipeline's native ability to trigger on branch events, avoiding custom logic or manual verification. By isolating production deployments to a dedicated pipeline, the team reduces the risk of unauthorized or untested code reaching production.

Exam trap

The trap here is that candidates often overestimate the flexibility of CodePipeline's built-in filtering or underestimate the security and maintainability benefits of using separate pipelines per branch, leading them to choose a custom Lambda solution (Option A) that introduces unnecessary complexity and risk.

How to eliminate wrong answers

Option A is wrong because using a Lambda function to check the branch name and fail the pipeline introduces custom code that must be maintained, tested, and secured, increasing complexity and potential failure points; it also fails the pipeline after the build stage, wasting resources. Option B is wrong because relying on a manual approver to verify the branch is error-prone and not automated, violating the principle of secure, maintainable enforcement; it depends on human diligence rather than system-level controls. Option D is wrong because CodePipeline does not support conditions that filter based on artifact tags; tagging source artifacts with branch names does not natively restrict pipeline execution, and such a condition would require custom logic, making it less secure and maintainable.

163
MCQeasy

A company uses AWS OpsWorks for configuration management. They need to automate the installation of a custom package on all instances in a layer. Which OpsWorks feature should they use?

A.AWS CodeDeploy AppSpec file
B.AWS CloudFormation custom resources
C.Custom Chef recipes associated with lifecycle events
D.AWS Systems Manager Run Command
AnswerC

Custom Chef recipes associated with lifecycle events are the correct mechanism for configuration management in AWS OpsWorks. OpsWorks defines five lifecycle events—Setup, Configure, Deploy, Undeploy, and Shutdown—and you can assign custom Chef recipes to run at each stage. For example, a Setup recipe can install packages and configure software, while a Deploy recipe can deploy application code. This is the native, fully integrated way to manage configurations in OpsWorks.

Why this answer

Custom Chef recipes associated with lifecycle events in AWS OpsWorks allow running Chef recipes automatically on instance lifecycle events such as Setup, Configure, Deploy, Undeploy, and Shutdown. This is the correct feature for automating package installation on all instances in a layer. Option A is incorrect because AWS CodeDeploy AppSpec file is used for CodeDeploy deployments, not OpsWorks.

Option B is incorrect because AWS CloudFormation custom resources are used to extend CloudFormation templates, not for OpsWorks automation. Option D is incorrect because AWS Systems Manager Run Command is a separate service for managing instances, not OpsWorks.

164
MCQhard

A DevOps engineer is troubleshooting an AWS Lambda function that processes messages from an Amazon SQS queue. The function is invoked successfully, but it frequently times out after 15 seconds. The function's CloudWatch Logs show that the timeout occurs while the function is making an HTTP request to an external API. The function's reserved concurrency is set to 5, and the SQS queue has a visibility timeout of 30 seconds. Which change would MOST effectively reduce the number of timeouts?

A.Increase the Lambda function's timeout to 30 seconds.
B.Increase the SQS queue's visibility timeout to 60 seconds.
C.Decrease the SQS batch size to 1.
D.Increase the Lambda function's reserved concurrency to 10.
AnswerA

The Lambda service enforces a configurable timeout that caps how long a single invocation can run, with a default of 3 seconds. If the function calls a downstream HTTP endpoint that is slower than the remaining execution time, the runtime terminates the invocation and returns a timeout error to the caller. Raising the timeout to 30 seconds grants the HTTP request enough time to return a response, directly resolving the symptom described in the troubleshooting scenario.

Why this answer

The function times out at 15 seconds while waiting on an external HTTP call, so the most direct fix is to raise the Lambda timeout to 30 seconds, giving the external API enough time to respond. The SQS visibility timeout (30s) already exceeds the current Lambda timeout, so it is not the bottleneck. Increasing the timeout is the change that most directly reduces the number of timeouts.

Exam trap

The trap is that candidates focus on SQS visibility timeout or concurrency, but the symptom (timeout during an HTTP call) points squarely at the Lambda execution timeout, which is the only setting that directly controls how long the function may run.

How to eliminate wrong answers

Option B is wrong because the visibility timeout (30s) is already greater than the Lambda timeout (15s), so extending it to 60s does not address the root cause — the function itself is being killed by Lambda, not by SQS redelivery. Option C is wrong because decreasing batch size to 1 reduces per-invocation work but does not change the fact that a single external HTTP call is exceeding 15 seconds. Option D is wrong because reserved concurrency controls how many concurrent invocations run, not how long each invocation may run — it would not prevent individual timeouts.

165
MCQeasy

A company uses AWS CodeBuild for CI/CD. The build project needs to access a private S3 bucket to download artifacts. What is the MOST secure way to grant access?

A.Embed the access keys in the buildspec.yml file.
B.Create an IAM role with read access to the bucket and attach it to the CodeBuild project.
C.Use an S3 bucket policy that grants public read access.
D.Store AWS access keys in CodeBuild environment variables.
AnswerB

An IAM role attached to the CodeBuild project supplies temporary credentials scoped to the required S3 read permissions, avoiding long-lived access keys stored in buildspec or environment variables. This satisfies least-privilege access to the private bucket.

Why this answer

Attaching an IAM role to the CodeBuild project allows CodeBuild to assume temporary credentials via the AWS STS service, eliminating the need to store any long-lived secrets. The role's policy can be scoped to only the specific S3 bucket and actions required, following least privilege. This is the AWS-recommended pattern for service-to-service authentication.

Exam trap

DOP-C02 often tests whether candidates confuse 'convenient' credential storage (env vars, buildspec) with 'secure' credential storage (IAM roles), so any answer that hardcodes or stores static keys is a distractor.

How to eliminate wrong answers

Option A is wrong because embedding access keys in buildspec.yml stores long-lived credentials in source control, where they can be leaked, committed to Git history, or exposed in build logs. Option C is wrong because granting public read access to a private bucket exposes the artifacts to anyone on the internet and violates least privilege. Option D is wrong because environment variables in CodeBuild are visible in the console and build logs, and static IAM user keys are long-lived and must be rotated manually.

166
MCQhard

A company is using AWS CodePipeline for CI/CD with CloudFormation as the deployment action. The pipeline fails intermittently with the error 'Rate exceeded' when creating or updating stacks. What is the most likely cause and solution?

A.The stack has a stack policy that prevents updates; modify the stack policy.
B.The IAM role used by CloudFormation does not have sufficient permissions; update the role policy.
C.The CloudFormation API rate limit is being hit; request a limit increase from AWS Support.
D.The pipeline is exceeding the CodePipeline execution frequency limit; reduce the number of pipeline executions.
AnswerC

The 'Rate exceeded' error is the exact textual representation of AWS API throttling, meaning the CloudFormation service is rejecting requests because the account's API request rate for that region has exceeded its allowed quota. This often occurs during CodePipeline deployments when multiple stages run large numbers of changeset creation, update, and describe calls concurrently, or when other automation is hammering the same CloudFormation API. The correct fix is to request a service quota increase for the CloudFormation API via Service Quotas or AWS Support, and also implement exponential backoff in the calling code to handle transient throttle responses while the increase is pending.

Why this answer

The 'Rate exceeded' error is a standard AWS API throttling error, indicating that CloudFormation API requests are being made faster than the account-level or region-level rate limit allows. CodePipeline can trigger multiple concurrent stack operations, especially during parallel stage executions or frequent commits, which can exceed the default CloudFormation API rate limit (e.g., 0.5 requests per second per account per region for CreateStack/UpdateStack). Requesting a limit increase from AWS Support is the correct solution to accommodate higher throughput.

Exam trap

The trap here is that candidates confuse API throttling errors with permission or policy issues, and they may incorrectly attribute the 'Rate exceeded' error to IAM roles or stack policies, rather than recognizing it as a classic AWS API rate limit error that requires a service quota increase.

How to eliminate wrong answers

Option A is wrong because a stack policy controls updates to stack resources (e.g., preventing modifications to specific resources), but it does not produce a 'Rate exceeded' error; it would produce an 'Update denied' or 'Stack policy violation' error. Option B is wrong because insufficient IAM permissions would result in an 'AccessDenied' or 'AuthorizationError', not a 'Rate exceeded' error; the error message explicitly indicates throttling, not authorization. Option D is wrong because CodePipeline execution frequency limits (e.g., 100 concurrent pipelines per account) are separate from CloudFormation API rate limits; exceeding pipeline frequency would cause pipeline execution failures, not CloudFormation-specific 'Rate exceeded' errors.

167
MCQmedium

A company uses AWS OpsWorks for Chef Automate. They have a stack that includes a PHP application layer. The application requires a custom PHP configuration file. The DevOps engineer creates a custom Chef cookbook with a recipe that deploys the configuration file. The recipe is assigned to the layer's Setup lifecycle event. The engineer notices that the configuration file is not being created on new instances when they are added to the layer. The cookbook is stored in a private S3 bucket. The engineer has verified that the cookbook is correctly associated with the stack. What should the engineer do to fix the issue?

A.Assign the recipe to the Configure lifecycle event instead of Setup
B.Verify that the recipe is included in the cookbook's default.rb file
C.Update the cookbook version to the latest
D.Ensure that the instance profile has permissions to read from the S3 bucket where the cookbook is stored
AnswerD

AWS OpsWorks for Chef Automate instances assume an IAM instance profile, and the chef-client uses those temporary credentials to fetch cookbooks and other artifacts from the configured S3 bucket. Without s3:GetObject (and often s3:ListBucket) permissions scoped to that bucket's path, the cookbook download fails, which prevents the recipe from executing. Granting the instance profile the necessary S3 read permissions directly resolves the issue, making this the correct remediation.

Why this answer

The issue is that the custom cookbook is stored in a private S3 bucket. For new instances to access the cookbook during the Setup lifecycle event, the instance must have the necessary IAM permissions to read from that S3 bucket. The instance profile attached to the OpsWorks stack's instances must include a policy that grants s3:GetObject for the cookbook's S3 bucket.

Without these permissions, the instance cannot download the cookbook, so the recipe never runs. Therefore, the engineer should ensure that the instance profile has permissions to read from the S3 bucket. Option A is incorrect because the Setup lifecycle event is appropriate for deploying configuration files when the instance is being set up; moving to Configure would run later and might not achieve the same result.

Option B is incorrect because the issue is not about the recipe being in default.rb; the cookbook is correctly associated, and the recipe is assigned to the layer lifecycle event directly, not necessarily via default.rb. Option C is incorrect because updating the cookbook version would not address the access permissions issue.

168
MCQhard

A company runs a stateful application on EC2 instances with instance store volumes. The application requires low-latency access to data. The operations team needs to ensure that instance failure does not result in data loss. Which solution is MOST resilient?

A.Use instance store volumes with RAID 1 across multiple instances.
B.Replicate data in real time to an EBS volume and take periodic snapshots.
C.Use larger instance types with more instance store capacity.
D.Create an AMI of the instance periodically to capture the data.
AnswerB

Replicating application data in real time to an Amazon EBS volume gives you a persistent, network-attached copy that survives the EC2 instance's lifecycle. EBS volumes are independently replicated within an Availability Zone, so they remain available if the instance is stopped or terminated. Taking periodic EBS snapshots copies the volume to Amazon S3, providing point-in-time recovery points that can be restored in the same or a different Availability Zone, which protects against both instance failure and EBS volume loss.

Why this answer

It combines the low-latency performance of instance store volumes with the durability of EBS snapshots. By replicating data in real time to an EBS volume, the application benefits from the instance store's speed while the EBS volume provides a persistent copy that survives instance failure. Periodic snapshots of the EBS volume add further resilience by enabling point-in-time recovery, ensuring data is not lost even if the instance or its instance store fails.

Exam trap

The trap here is that candidates assume instance store volumes are inherently durable because they are fast, overlooking that they are ephemeral and tied to the instance lifecycle, while the correct solution uses a hybrid approach to combine performance with persistence.

How to eliminate wrong answers

Option A is wrong because RAID 1 across multiple instances requires network-based replication, which introduces latency and complexity, and does not guarantee data durability if all instances fail simultaneously or if the instance store volumes themselves are ephemeral and tied to instance lifecycle. Option C is wrong because using larger instance types with more instance store capacity only increases storage size, not durability; instance store data is still lost on instance failure, reboot, or termination. Option D is wrong because creating an AMI periodically captures the entire instance state, but AMIs are not designed for real-time data replication; they are point-in-time snapshots that can lead to significant data loss between creation intervals and do not provide low-latency access to the latest data.

169
MCQhard

A company uses Terraform to manage AWS infrastructure. They have a state file stored in an S3 bucket with DynamoDB locking. After a failed 'terraform apply', the state file is locked. The DevOps engineer tries to run 'terraform plan' but gets an error: 'Error acquiring the state lock'. What should the engineer do to resolve this issue?

A.Manually delete the lock item from the DynamoDB table
B.Wait for the lock to expire automatically
C.Run 'terraform force-unlock' with the lock ID
D.Delete the state file from S3 and re-run terraform init
AnswerC

`terraform force-unlock <LOCK_ID>` is the designed recovery mechanism for stale or stuck locks, and it directly interacts with the backend's locking system to remove the lock item while preserving the integrity of the state file. This command requires the exact lock ID from the error message and is safe when the previous operation is truly no longer running; it is the recommended alternative to manual DynamoDB edits or destructive state file actions.

Why this answer

Terraform uses DynamoDB to implement state locking, and after a failed apply, the lock entry remains in the table. The `terraform force-unlock` command with the specific lock ID (obtained from the error message or via `terraform lock` commands) is the designed mechanism to manually release a stuck lock without corrupting the state file. This approach preserves the existing state and avoids data loss.

Exam trap

The trap here is that candidates assume DynamoDB locks have a TTL or that manual deletion is safe, but AWS DynamoDB does not enforce TTL on lock items by default, and Terraform's locking protocol requires the lock ID to be explicitly provided to prevent accidental release of another process's lock.

How to eliminate wrong answers

Option A is wrong because manually deleting the lock item from the DynamoDB table bypasses Terraform's safety checks and can lead to state corruption if the lock was legitimately held by another process; it also does not provide the lock ID validation that Terraform requires. Option B is wrong because DynamoDB locks do not have a built-in expiry mechanism; they persist until explicitly released, so waiting will not resolve the issue. Option D is wrong because deleting the state file from S3 destroys the entire infrastructure state, causing Terraform to lose track of all managed resources, and re-running `terraform init` would create a blank state, leading to potential resource duplication or deletion.

170
Multi-Selecteasy

Which TWO are best practices for securing an Amazon RDS database? (Choose 2)

Select 2 answers
A.Enable public accessibility for easy management.
B.Use a single Availability Zone to reduce complexity.
C.Launch the RDS instance in a private subnet.
D.Enable encryption at rest using AWS KMS.
E.Grant direct IAM user access to the database.
AnswersC, D

Launching the RDS instance in a private subnet that has no route to an internet gateway prevents any direct inbound connection from the public internet, including attempts to exploit database vulnerabilities. Only resources inside the VPC, such as application servers in private subnets or a bastion host, can reach the database, and those connections can be further restricted by security groups and NACLs. This is a core network security control that reduces the attack surface and is a mandatory requirement for many compliance frameworks.

Why this answer

Option C is correct because launching the RDS instance in a private subnet removes it from the public internet, so only resources inside the VPC (or connected via VPN/Direct Connect or a bastion) can reach the database endpoint, which is a core network-isolation best practice. Option D is correct because enabling encryption at rest with AWS KMS protects stored data, automated backups, read replicas, and snapshots, satisfying compliance and data-protection requirements. Option A is wrong because public accessibility exposes the database to internet-based attacks and is not recommended; management should be done via private networking or a bastion.

Option B is wrong because a Single-AZ deployment creates a single point of failure and does not improve security; Multi-AZ is preferred for availability. Option E is wrong because granting direct IAM user access to the database bypasses proper database authentication and least-privilege controls; IAM should be used for AWS API access, not direct DB logins.

Exam trap

DOP-C02 often tests the misconception that public accessibility or single-AZ simplifies management — candidates pick convenience options that violate the shared responsibility model's security and availability best practices.

171
MCQmedium

A DevOps engineer is setting up an AWS CodePipeline for a serverless application. The source code is in AWS CodeCommit, and the build and deploy stages use AWS CodeBuild and AWS CloudFormation respectively. The engineer wants to ensure that the pipeline automatically creates a new stack for each feature branch and deletes the stack when the branch is deleted. Which combination of actions should the engineer take to achieve this with minimal operational overhead?

A.Configure the pipeline to trigger on all branches and use a single CloudFormation stack with a parameter that includes the branch name.
B.Use AWS CodePipeline with a source action that triggers on all branches, and configure the build stage to pass the branch name to CloudFormation, creating a stack per branch with a naming convention, and use a cleanup Lambda triggered by CodeCommit branch deletion events.
C.Create a separate pipeline for each branch using AWS CloudFormation templates and AWS Lambda to manage stack creation and deletion.
D.Configure CodePipeline to use a single stage that deploys to AWS Elastic Beanstalk environments named after each branch, and rely on Elastic Beanstalk's environment lifecycle policies to delete environments when branches are deleted.
AnswerB

This approach leverages CodePipeline's ability to trigger on all branches and dynamically create CloudFormation stacks per branch using the branch name as part of the stack name. A Lambda function triggered by CodeCommit branch deletion events can delete the corresponding stack. This automates stack lifecycle management with minimal overhead, as the pipeline and Lambda handle creation and deletion. It provides isolation and scalability across branches.

Why this answer

To automatically create and delete CloudFormation stacks per feature branch, the engineer should use CodePipeline's branch-based triggering and pass the branch name to CloudFormation to create uniquely named stacks. A Lambda function triggered by CodeCommit branch deletion events can then delete the corresponding stack. This leverages native AWS services for automation, minimizing operational overhead.

The other options either use inappropriate services, lack automation, or do not provide isolation.

Exam trap

The trap here is assuming that a single stack with a branch parameter or manual pipelines can handle multiple branches efficiently, when in fact isolation and automated cleanup require per-branch stacks and event-driven deletion.

172
MCQeasy

A development team uses AWS CodeBuild to compile a Java application and run unit tests. The build takes 30 minutes, but the team wants to reduce build time. The codebase has not changed significantly, and dependencies are stable. Which action would be MOST effective in reducing build time?

A.Configure CodeBuild to cache dependencies in an Amazon S3 bucket.
B.Move the build process to a local developer machine to avoid CodeBuild overhead.
C.Reduce the number of unit tests executed in the build phase.
D.Increase the compute type of the build environment to a larger instance.
AnswerA

Configure CodeBuild with cache.type set to S3 and specify an S3 bucket as cache.location, then declare the Java dependency directory (e.g., /root/.m2 for Maven) in the buildspec cache.paths. This creates a persistent, shared cache that is uploaded at the end of each build and downloaded at the start of the next, so dependencies are fetched from S3 instead of being downloaded one-by-one from public repositories on every run. By keying the cache appropriately (e.g., including a hash of the buildspec or source), you retain a valid cache while invalidating it when dependencies or build parameters change.

Why this answer

Caching dependencies in an Amazon S3 bucket allows CodeBuild to reuse previously downloaded Maven/Gradle dependencies across builds, eliminating the need to re-download them each time. Since the codebase and dependencies are stable, this directly reduces the build time by avoiding repeated network transfers of large artifact repositories.

Exam trap

The trap here is that candidates assume a larger compute instance always speeds up builds, overlooking that network-bound operations like dependency downloads are not significantly improved by CPU or memory upgrades.

How to eliminate wrong answers

Option B is wrong because moving the build to a local developer machine sacrifices consistency, scalability, and auditability, and does not address the core issue of dependency download overhead in CodeBuild. Option C is wrong because reducing unit tests compromises code quality and test coverage, and the question states the team wants to reduce build time without changing the codebase significantly — removing tests is not a valid optimization. Option D is wrong because increasing the compute type primarily accelerates CPU-bound tasks (compilation), but the bottleneck here is likely network-bound dependency downloads; a larger instance does not reduce the time spent downloading unchanged dependencies.

173
MCQeasy

A company is using Amazon RDS for MySQL with Multi-AZ deployment. During a recent failover, the application experienced a brief downtime because the DNS cache on the application servers still pointed to the old primary. How can a DevOps engineer minimize this downtime?

A.Use an RDS Proxy to manage connections and reduce DNS dependency.
B.Configure the application to use the Multi-AZ endpoint instead of the primary endpoint.
C.Configure application servers to use a hardcoded IP address instead of the RDS endpoint.
D.Increase the TTL on the RDS DNS record.
AnswerA

RDS Proxy sits between your application and the database, exposing a fixed writer endpoint that masks the underlying instance DNS changes. When a Multi-AZ failover occurs, RDS Proxy automatically redirects existing connections to the new primary, which eliminates the delay caused by clients waiting for DNS TTL to expire. It also pools and reuses database connections, reducing connection-related errors during failover and lowering CPU/memory pressure on the database. This is exactly why it reduces DNS dependency and delivers failover times typically under one second.

Why this answer

RDS Proxy acts as a connection broker that maintains persistent connections to the database and abstracts the underlying DNS changes during failover. When a failover occurs, RDS Proxy automatically reconnects to the new primary without requiring the application to resolve a new DNS record, thereby eliminating the downtime caused by stale DNS caches. This reduces the application's dependency on DNS resolution and provides faster failover recovery.

Exam trap

The trap here is that candidates often think increasing TTL or using a different endpoint will help, but the real issue is DNS cache staleness, which RDS Proxy bypasses entirely by managing connections at the proxy layer.

How to eliminate wrong answers

Option B is wrong because there is no such thing as a 'Multi-AZ endpoint' in RDS; the Multi-AZ feature uses a single DNS endpoint (the primary) that is automatically updated after failover, so using a different endpoint does not solve the DNS caching issue. Option C is wrong because hardcoding an IP address is highly discouraged — RDS instances can change IP addresses after failover or maintenance, leading to permanent connectivity loss. Option D is wrong because increasing the TTL on the RDS DNS record would actually make the DNS cache stale for longer, increasing downtime instead of minimizing it.

174
MCQmedium

A DevOps engineer manages a CI/CD pipeline that builds Docker images and pushes them to Amazon ECR. The security team requires that every image be scanned for known vulnerabilities before deployment, and that the pipeline fail if any critical severity findings are detected. The engineer enables scan on push for the repository. Which additional step must be added to the pipeline to meet the requirement?

A.Use AWS Config to evaluate the ECR image scan results and trigger an AWS Lambda function that stops the pipeline.
B.Configure the ECR repository to block pushes of images that contain critical vulnerabilities.
C.Use the ECR DescribeImageScanFindings API to retrieve the scan results and fail the pipeline if any finding has a severity of CRITICAL.
D.Enable Amazon Inspector and configure it to fail the CodePipeline stage when critical findings are detected.
AnswerC

Enabling scan on push only initiates the scan; the pipeline must actively retrieve the results. Calling DescribeImageScanFindings returns the severity counts and individual findings, allowing the pipeline to evaluate them and fail when CRITICAL findings exist. This directly satisfies the requirement to block deployment based on critical vulnerabilities.

Why this answer

ECR scan on push generates vulnerability findings but does not enforce any action. To gate the pipeline, the engineer must call DescribeImageScanFindings after the push and evaluate the severity counts. If any CRITICAL finding exists, the pipeline should fail.

This is the standard pattern for integrating ECR image scanning into a CI/CD workflow and meets the security team's requirement.

Exam trap

The trap here is assuming that enabling scan on push automatically blocks vulnerable images from being pushed or deployed, when it only produces findings that must be evaluated separately.

175
MCQeasy

A company wants to receive real-time notifications when their Auto Scaling group launches or terminates EC2 instances. Which AWS service should they use?

A.Amazon CloudWatch alarm on the GroupTotalInstances metric.
B.AWS Config rules to detect changes in Auto Scaling groups.
C.AWS CloudTrail to monitor Auto Scaling API calls.
D.Amazon SNS notifications from the Auto Scaling group.
AnswerD

Auto Scaling groups have a built-in notification feature that publishes messages to an SNS topic on lifecycle events like ec2-instance-launch and ec2-instance-terminate. This provides immediate, event-driven delivery of the instance ID, the Auto Scaling group name, and the event type to all subscribers (email, SMS, Lambda, HTTP endpoints). It is the simplest native way to receive real-time notifications for the exact scaling actions the company cares about.

Why this answer

Auto Scaling groups natively support lifecycle hooks and notification configurations that publish events (EC2 Instance-launch, EC2 Instance-terminate, EC2 Instance-launch-lifecycle-action, etc.) directly to an Amazon SNS topic. This is the built-in, real-time mechanism designed specifically for launch/terminate notifications, requiring no polling or metric evaluation.

Exam trap

The trap here is confusing CloudWatch alarms (threshold-based, aggregate metrics) with native ASG lifecycle notifications (event-based, per-instance) — candidates often pick CloudWatch because it 'feels' like the monitoring answer.

How to eliminate wrong answers

Option A is wrong because a CloudWatch alarm on GroupTotalInstances only fires when the aggregate count crosses a threshold — it cannot notify on individual instance launch/terminate events and is not real-time per-instance. Option B is wrong because AWS Config rules evaluate resource configuration compliance over time (typically minutes), not real-time lifecycle events, and would require custom rules to detect scaling activity. Option C is wrong because CloudTrail logs Auto Scaling API calls for auditing, but it is not a real-time push notification service — you would need to build EventBridge/CloudWatch Logs filters on top of it.

176
Multi-Selecthard

Which THREE actions are best practices for managing secrets in AWS CloudFormation templates? (Choose three.)

Select 3 answers
A.Use AWS CloudFormation parameters with the NoEcho property set to true.
B.Use AWS Systems Manager Parameter Store secure string parameters with dynamic references.
C.Use AWS Secrets Manager dynamic references to retrieve secrets at deployment time.
D.Encrypt the CloudFormation template file with AWS KMS.
E.Store secrets as plaintext in the template parameters.
AnswersA, B, C

Using the NoEcho property on a CloudFormation parameter is a valid best practice because it masks the parameter's value from the AWS Management Console, API responses, and stack outputs, preventing casual exposure during template operations. However, it does not encrypt the value or prevent the resource that receives the parameter from exposing it, so it should be combined with external secret stores. NoEcho is appropriate when a secret must be passed as a stack parameter, but the secret itself should never be embedded in the template or committed to version control.

Why this answer

Setting the NoEcho property to true on a CloudFormation parameter prevents the parameter value from being returned in API calls or displayed in the console, which is a basic mechanism for masking secrets. However, this alone does not encrypt the value at rest or in transit, and the value is still passed as plaintext in the template, so it is considered a best practice only when combined with other secure methods like dynamic references.

Exam trap

The trap here is that candidates often think encrypting the template file (Option D) is sufficient for secret protection, but they overlook that secrets remain exposed during stack operations unless dynamic references or NoEcho are used.

177
MCQhard

A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that no member account can disable AWS CloudTrail or delete CloudTrail logs. What is the most effective way to enforce this control?

A.Require all accounts to use the same CloudTrail trail.
B.Apply a Service Control Policy that denies cloudtrail:DeleteTrail and cloudtrail:StopLogging.
C.Create an IAM policy in each account that denies cloudtrail:DeleteTrail.
D.Configure CloudTrail to log to an S3 bucket in a centralized logging account and deny access to the bucket from member accounts.
AnswerB

A Service Control Policy (SCP) applied at the organization root or an organizational unit is the correct mechanism because it acts as a permission boundary that all IAM principals—including the account root user—cannot override. By explicitly denying cloudtrail:DeleteTrail and cloudtrail:StopLogging, the SCP ensures that even a full account administrator cannot disable the trail or stop event delivery. Since member account admins lack permission to modify or detach SCPs, this provides an immutable, centralized control that persists regardless of individual account settings.

Why this answer

A Service Control Policy (SCP) applied at the organization or OU level is the most effective way to prevent member accounts from disabling CloudTrail or deleting logs because SCPs are enforced by AWS Organizations and cannot be overridden by account-level IAM policies, including root user actions. Denying cloudtrail:DeleteTrail and cloudtrail:StopLogging at the SCP level creates a hard guardrail across all accounts in scope. This is the canonical AWS Organizations security control pattern.

Exam trap

DOP-C02 often tests the difference between 'configuration' controls (same trail, central bucket) and 'enforcement' controls (SCP deny) — candidates pick the central S3 bucket because it sounds like a security best practice, missing that it does not block the StopLogging API call.

How to eliminate wrong answers

Option A is wrong because requiring all accounts to use the same trail does not prevent anyone from stopping or deleting it — it only standardizes configuration, not enforcement. Option C is wrong because an IAM policy in each account can be modified or deleted by account administrators (or root), so it is not a durable guardrail; it also requires per-account maintenance and can be bypassed. Option D is wrong because centralizing logs in an S3 bucket protects log retention but does not stop a member account from calling StopLogging or DeleteTrail on its own trail — the control must block the API call itself.

178
MCQmedium

A company uses Amazon RDS Multi-AZ for disaster recovery. The primary DB instance in us-east-1a fails. What happens next?

A.The standby DB instance in us-east-1b is promoted automatically and the CNAME record is updated
B.The administrator must manually promote the standby instance
C.The primary instance is automatically rebuilt in the same AZ
D.A read replica in us-east-1b is automatically promoted to primary
AnswerA

RDS Multi-AZ maintains a synchronous standby in a different Availability Zone, so when the primary in us-east-1a fails, the standby in us-east-1b is promoted automatically and the DB instance's CNAME endpoint is repointed to it. This satisfies the stem's automatic failover requirement without manual intervention.

Why this answer

RDS Multi-AZ maintains a synchronous standby replica in a different AZ and performs automatic failover by promoting the standby and updating the DB instance's DNS CNAME to point to the new primary. The failover is triggered by the primary's failure and typically completes in 60–120 seconds, with no manual intervention required. Applications using the endpoint hostname reconnect transparently once DNS TTL expires.

Exam trap

DOP-C02 often tests whether candidates confuse Multi-AZ (synchronous standby, automatic failover, HA) with read replicas (asynchronous, manual promotion, read scaling), causing them to pick the read-replica promotion answer.

How to eliminate wrong answers

Option B is wrong because Multi-AZ failover is automatic — manual promotion is the behavior of a read replica promotion (which is a separate feature), not Multi-AZ. Option C is wrong because RDS does not rebuild the primary in the same AZ during failover; it promotes the standby in the other AZ to preserve availability. Option D is wrong because read replicas are not part of the Multi-AZ failover mechanism — they are asynchronous, separately managed, and require manual promotion; Multi-AZ uses a synchronous standby, not a read replica.

179
MCQhard

An organization uses AWS CodePipeline with multiple stages: Source, Build, Deploy to Test, Deploy to Prod. They want to implement a canary deployment strategy for the production deployment. Which approach should they use?

A.Use a Lambda function in CodePipeline to manually adjust weights in Route53.
B.Use CodeDeploy with a canary deployment configuration in the Deploy to Prod stage.
C.Use an Elastic Load Balancer to gradually shift traffic using weighted target groups.
D.Use CloudFormation with a canary update policy in the Deploy to Prod stage.
AnswerB

CodeDeploy is the AWS-native service designed for controlled software rollouts, and its canary deployment configuration is fully supported as a CodePipeline deploy action. For example, a configuration like Canary10Percent5Minutes shifts 10% of traffic to the new task set or instance fleet, waits five minutes, then shifts the remaining 90%, while monitoring health via lifecycle hooks. Because CodeDeploy owns the traffic-shifting logic, it automatically detects failures, stops the deployment, and can roll back to the previous version. This directly satisfies the requirement for a built-in canary strategy in the Deploy to Prod stage with no custom scripting.

Why this answer

AWS CodePipeline integrates natively with CodeDeploy, which supports canary deployments by shifting a percentage of traffic to the new revision over a specified time interval (e.g., 10% every 5 minutes). Using CodeDeploy with a canary configuration in the Deploy to Prod stage directly implements the desired canary strategy within the pipeline, leveraging CodeDeploy's built-in traffic shifting and health monitoring.

Exam trap

The trap here is that candidates often confuse traffic routing mechanisms (like ELB weighted target groups) with deployment strategies (like CodeDeploy canary), failing to recognize that CodeDeploy provides the orchestration, lifecycle hooks, and automated rollback that a true canary deployment requires.

How to eliminate wrong answers

Option A is wrong because manually adjusting weights in Route53 via a Lambda function is not a native CodePipeline integration for canary deployments; it requires custom scripting, lacks automated rollback capabilities, and does not leverage CodeDeploy's deployment lifecycle hooks. Option C is wrong because an Elastic Load Balancer with weighted target groups can shift traffic, but it does not provide the deployment orchestration, health checks, or rollback features that CodeDeploy offers; it is a lower-level traffic routing mechanism, not a deployment strategy. Option D is wrong because CloudFormation's canary update policy (UpdatePolicy with AutoScalingRollingUpdate) is for rolling updates to Auto Scaling groups, not for canary traffic shifting in a CodePipeline deployment; it does not support percentage-based traffic shifting to a new application version.

180
Multi-Selecthard

A company is using AWS Lambda to process sensitive data. The security team requires that the Lambda function only be invoked from within a specific VPC and that the function's environment variables be encrypted at rest. Which TWO actions should the DevOps engineer take to meet these requirements?

Select 2 answers
A.Enable AWS KMS encryption for the Lambda function's environment variables using a customer-managed key.
B.Enable encryption for CloudWatch Logs using a KMS key.
C.Configure the Lambda function to be VPC-enabled and set up a VPC endpoint for Lambda.
D.Assign an IAM execution role with permissions to access a KMS key.
E.Attach a resource-based policy to the Lambda function that denies invoke unless the request comes from the VPC.
AnswersA, C

Enabling AWS KMS encryption for the Lambda function's environment variables with a customer-managed key directly protects the sensitive values at rest. When you configure this, Lambda uses the selected customer master key to encrypt the environment-variable payload before storing it as part of the function configuration. This replaces the default aws/lambda managed key, giving you independent control, rotation, and audit trails through CloudTrail for encryption and decryption operations.

Why this answer

Using a customer-managed KMS key to encrypt the Lambda function's environment variables satisfies the encryption at rest requirement. Option C is correct because configuring the Lambda function to be VPC-enabled and setting up a VPC endpoint for Lambda restricts invocation to within the specific VPC. Option B is incorrect because encrypting CloudWatch Logs does not encrypt the Lambda environment variables.

Option D is incorrect because assigning an IAM execution role with KMS permissions is necessary but not sufficient; the encryption is enabled by configuring KMS on the function. Option E is incorrect because resource-based policies cannot restrict invocation to VPC origin alone; VPC configuration and endpoints are required.

181
MCQmedium

A team uses AWS CodePipeline to deploy a microservices application. The pipeline has a deploy action that uses AWS CloudFormation. The CloudFormation template creates an Amazon ECS service. The deployment fails because the ECS service cannot be updated. What is the most likely cause?

A.The CloudFormation stack already exists and is in a previous failed state.
B.The ECS service is in a steady state and cannot be modified.
C.The CodePipeline deploy action is configured with the wrong action type.
D.The IAM role used by CloudFormation does not have permission to update ECS services.
AnswerA

The CloudFormation stack referenced by the CodePipeline deploy action already exists and remains in a failed state (e.g., ROLLBACK_COMPLETE, UPDATE_ROLLBACK_COMPLETE, or CREATE_FAILED). CloudFormation refuses to perform an update on a stack that has not successfully reached a stable state (CREATE_COMPLETE or UPDATE_COMPLETE), so the deploy action fails immediately. A failed stack must be deleted (if resource policy allows) or updated/remediated using a change set to move it back to a stable, updatable state before CodePipeline can retry.

Why this answer

When a CloudFormation stack update fails, the stack enters a ROLLBACK_COMPLETE or UPDATE_ROLLBACK_COMPLETE state. In this state, the stack is considered to be in a 'failed' state and cannot be updated again until it is either deleted or the stack is manually continued with a rollback. CodePipeline's CloudFormation deploy action will attempt to perform a stack update, but CloudFormation rejects the request because the existing stack is in a non-updatable state, causing the pipeline deployment to fail.

Exam trap

The trap here is that candidates often assume the error is due to missing IAM permissions or a misconfigured action type, but the real issue is CloudFormation's requirement that stacks be in a valid state before updates can proceed.

How to eliminate wrong answers

Option B is wrong because an ECS service in a steady state (e.g., ACTIVE) can be modified via CloudFormation updates; the error is not due to the service being immutable. Option C is wrong because the deploy action type (CloudFormation) is correct for deploying infrastructure; the failure is not related to a misconfigured action type. Option D is wrong because if the IAM role lacked permissions, the error would be an access denied or authorization failure, not a generic 'cannot be updated' error from CloudFormation.

182
MCQmedium

A company uses AWS CloudFormation to deploy a multi-tier application. The network team manages the VPC and subnets using a separate CloudFormation stack. The application team needs to reference the VPC ID and subnet IDs from the network stack. Which approach should the application team use to obtain these values?

A.Hardcode the VPC and subnet IDs in the application template.
B.Export the VPC ID and subnet IDs from the network stack using the 'Export' field and import them in the application stack using Fn::ImportValue.
C.Create the network stack as a nested stack inside the application stack.
D.Store the VPC and subnet IDs in AWS Systems Manager Parameter Store and retrieve them using dynamic references.
AnswerB

Exporting the VPC and subnet IDs from the network stack via the 'Export' field and importing them into the application stack with Fn::ImportValue establishes a native CloudFormation cross-stack reference within the same account and region. This creates an explicit dependency between the stacks, ensuring the network stack is created before the application stack and that the latest exported values are resolved at stack operation time. It avoids hardcoding by letting CloudFormation manage the wiring, and it supports updates and reuse across multiple dependent stacks. This is the intended, first-class mechanism for sharing outputs between independent CloudFormation stacks.

Why this answer

CloudFormation's Export and Fn::ImportValue mechanism allows cross-stack references without hardcoding or duplicating values. The network stack exports the VPC ID and subnet IDs using the Export field, and the application stack imports them via Fn::ImportValue, ensuring that changes in the network stack propagate automatically to dependent stacks.

Exam trap

The trap here is that candidates may confuse cross-stack references with nested stacks or parameter stores, but the exam specifically tests the Export/ImportValue pattern for decoupled stacks managed by different teams.

How to eliminate wrong answers

Option A is wrong because hardcoding VPC and subnet IDs creates brittle templates that break if the network stack is recreated or updated, violating infrastructure-as-code best practices. Option C is wrong because nesting the network stack inside the application stack would tightly couple the two teams' responsibilities, defeating the purpose of separate management and making it harder to update the network independently. Option D is wrong because while Systems Manager Parameter Store can store values, dynamic references in CloudFormation (e.g., '{{resolve:ssm:...}}') are resolved at stack creation time and do not automatically update when the parameter changes, unlike Fn::ImportValue which tracks the exported value across stacks.

183
MCQmedium

A company uses AWS CloudFormation to deploy infrastructure. The DevOps team wants to receive notifications when a stack creation fails due to a resource limit exceeded error. Which approach should be used?

A.Create an Amazon EventBridge rule that matches CloudFormation resource limit exceeded events and sends to SQS.
B.Configure an SNS topic as a notification option in the CloudFormation stack, and subscribe an email endpoint.
C.Use AWS Config to detect when a stack is in a failed state.
D.Enable CloudTrail and create a CloudWatch alarm on the CreateStack API call.
AnswerB

CloudFormation natively supports an SNS topic as a stack notification option: when you specify an SNS topic ARN in the stack's NotificationARNs property, CloudFormation publishes every stack event—such as CREATE_FAILED and ROLLBACK_COMPLETE—to that topic. Subscribing an email endpoint to the topic delivers these events in near real time, giving operations teams immediate insight into resource limit failures or any other stack error. This is the only answer that directly leverages CloudFormation's built-in notification channel without needing extra services to infer failure.

Why this answer

CloudFormation natively supports sending stack events (including creation failures) to an SNS topic. By configuring an SNS topic as a notification option in the stack creation request, the DevOps team can subscribe an email endpoint to receive real-time notifications when a resource limit exceeded error occurs, without needing additional services or custom logic.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing EventBridge or CloudTrail-based monitoring, missing the fact that CloudFormation has a built-in, straightforward SNS notification feature specifically designed for real-time stack event alerts.

How to eliminate wrong answers

Option A is wrong because Amazon EventBridge does not natively emit a specific 'resource limit exceeded' event from CloudFormation; CloudFormation events in EventBridge are generic stack-level events (e.g., CREATE_FAILED) and would require custom filtering and parsing to detect the specific error message, making it less direct than using SNS. Option C is wrong because AWS Config is designed for resource compliance and configuration tracking, not for real-time monitoring of CloudFormation stack creation failures; it cannot trigger notifications for transient stack events like resource limit exceeded errors. Option D is wrong because enabling CloudTrail and creating a CloudWatch alarm on the CreateStack API call would only detect that a CreateStack call was made, not whether the stack creation failed due to a resource limit exceeded error; the alarm would fire on every CreateStack call, not on failures, and would require additional log filtering and metric filters to isolate the specific error.

184
MCQeasy

A team uses AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment fails with the error: 'The overall deployment failed because too many individual instances failed deployment.' The instances are healthy and can connect to the CodeDeploy service. What is the most likely cause?

A.The Auto Scaling group launch configuration is incorrect.
B.The deployment group is not configured with the correct service role.
C.The appspec.yml file or lifecycle event scripts have errors.
D.The target revision is not accessible from the instances.
AnswerC

The appspec.yml file controls the order and content of lifecycle events such as ApplicationStop, BeforeInstall, and AfterInstall. If the file is malformed, references a nonexistent script, or a referenced hook script exits with a non-zero status, CodeDeploy treats that instance as failed and reports 'ScriptFailed' or 'InvalidLifecycleEventName'. Because the deployment reaches the script execution stage and then errors, the appspec definition and its scripts are the most direct cause.

Why this answer

The error 'too many individual instances failed deployment' indicates that the deployment failed on the instances themselves, not at the infrastructure level. Since the instances are healthy and can connect to CodeDeploy, the most likely cause is that the appspec.yml file or the lifecycle event scripts (e.g., hooks like BeforeInstall, AfterInstall) contain errors that cause the deployment to fail on each instance. This is a common issue when scripts have syntax errors, missing dependencies, or incorrect paths.

Exam trap

The trap here is that candidates often assume the error is due to network or permissions issues (like S3 access or IAM roles) because those are common causes, but the question explicitly states instances are healthy and can connect to CodeDeploy, shifting the root cause to the application-level scripts or configuration.

How to eliminate wrong answers

Option A is wrong because an incorrect Auto Scaling group launch configuration would typically prevent instances from launching or cause them to be unhealthy, but the question states instances are healthy and can connect to CodeDeploy, so the launch configuration is not the issue. Option B is wrong because if the deployment group were not configured with the correct service role, CodeDeploy would fail to perform actions on the instances (e.g., cannot read from S3 or call APIs), but the instances can connect to CodeDeploy, indicating the service role is correctly assigned. Option D is wrong because if the target revision were not accessible from the instances, CodeDeploy would report a specific error about failing to download the revision (e.g., S3 bucket permissions or network issues), but the instances are healthy and can connect, so accessibility is not the problem.

185
Multi-Selecthard

A company wants to monitor and detect anomalous API calls in their AWS account. Which THREE AWS services should they use together to achieve this?

Select 3 answers
A.AWS CloudTrail
B.Amazon Inspector
C.Amazon CloudWatch Logs
D.AWS Config
E.Amazon GuardDuty
AnswersA, C, E

AWS CloudTrail is the primary service that records all API activity in an AWS account, capturing the identity, time, source IP, and request parameters for every call. Enabling CloudTrail across all regions and using events to build a baseline of expected behavior lets security teams flag anomalies such as unusual IAM roles, foreign IP addresses, or credential changes. It is the foundational data source for API-level anomaly detection, and its Insights feature can automatically identify unusual API patterns like mass resource deletion or unusual access timing.

Why this answer

AWS CloudTrail is correct because it records all API calls made in the AWS account, providing the raw data needed to detect anomalous activity. By enabling CloudTrail on all regions and logging to a centralized S3 bucket, you capture the identity, source IP, and request parameters for every API call, which is essential for anomaly detection.

Exam trap

The trap here is that candidates often confuse AWS Config (which tracks resource configuration changes) with CloudTrail (which tracks API calls), or they think Amazon Inspector (a vulnerability scanner) can detect anomalous API behavior when it is designed for a completely different purpose.

186
Multi-Selectmedium

A company is using Amazon CloudWatch to monitor a production environment. The DevOps team wants to receive notifications when the CPU utilization of an EC2 instance exceeds 90% for 5 consecutive minutes. Which TWO steps should the team take to achieve this? (Choose TWO.)

Select 2 answers
A.Enable detailed monitoring on the EC2 instance to get 1-minute metrics.
B.Configure an Amazon SNS topic and subscribe the team's email address to it, then set the alarm to send notifications to the SNS topic.
C.Create a CloudWatch alarm on the CPUUtilization metric with a threshold of 90% and an evaluation period of 5 consecutive minutes.
D.Create a CloudWatch Logs metric filter to count CPU utilization errors.
E.Create a CloudWatch dashboard to visualize CPU utilization.
AnswersB, C

An Amazon SNS topic acts as the delivery channel for CloudWatch alarm actions. By creating a topic, subscribing the team's email address, and confirming the subscription, the alarm can publish messages to that topic whenever it transitions to the ALARM state. This is the standard method to send email notifications and is a required component for the team to be alerted. Without this, the alarm would only change state and not proactively reach the team.

Why this answer

Option B is correct because CloudWatch alarms cannot send email directly; they must publish to an Amazon SNS topic, and the team's email address must be subscribed to that topic so the notification is delivered. Option C is correct because the alarm must be defined on the EC2 CPUUtilization metric with a threshold of 90% and an evaluation period of 5 consecutive 1-minute datapoints (5 minutes) to match the requirement. Option A is not required because basic monitoring already provides CPUUtilization at 5-minute intervals, which is sufficient for a 5-minute evaluation period; detailed monitoring only changes the granularity to 1 minute.

Option D is incorrect because CloudWatch Logs metric filters operate on log events, not on the CPUUtilization metric. Option E is incorrect because a dashboard only visualizes metrics and does not generate notifications.

Exam trap

DOP-C02 often tests whether candidates overcomplicate the solution by enabling detailed monitoring unnecessarily — standard 5-minute metrics are sufficient for a 5-minute evaluation period.

187
MCQeasy

A company is using AWS CloudTrail to track API calls. They want to be notified immediately when an IAM user creates a new access key. Which combination of AWS services should be used?

A.Amazon CloudWatch Logs with a metric filter and alarm.
B.AWS Config with an AWS Lambda function.
C.Amazon CloudWatch Events (Amazon EventBridge) with an AWS Lambda function that sends an email via Amazon SES.
D.Amazon CloudWatch Events (Amazon EventBridge) with an Amazon SNS topic.
AnswerD

Amazon EventBridge is the native event router for CloudTrail API activity: CloudTrail automatically delivers every call to an event bus, and a rule with a JSON pattern can match the specific API (e.g., an unauthorized or sensitive call). The rule immediately invokes an Amazon SNS topic, which then fans out notifications via email, SMS, or other subscribers. This event-driven flow provides sub-second, real-time alerts with no polling, no custom code, and direct integration, making it the correct architecture.

Why this answer

To be notified immediately when an IAM user creates a new access key, the most efficient approach is to use Amazon CloudWatch Events (Amazon EventBridge) with an Amazon SNS topic. CloudTrail records the 'CreateAccessKey' API call as an event. An EventBridge rule can be configured to match this specific event pattern and send the event to an SNS topic, which can then send notifications via email, SMS, etc.

This provides real-time notification without additional services. Option A (CloudWatch Logs with metric filter and alarm) requires sending CloudTrail logs to CloudWatch Logs, which adds latency and complexity; it is not as direct as EventBridge. Option B (AWS Config with Lambda) is not designed for real-time event notification.

Option C (EventBridge with Lambda and SES) adds unnecessary Lambda processing since SNS can directly send email when subscribed to the topic.

188
MCQmedium

A company uses AWS CodePipeline to deploy a static website to an S3 bucket. The pipeline includes a source stage (S3), a build stage (CodeBuild) that minifies assets, and a deploy stage that copies files to the production S3 bucket. The deploy stage uses 's3 sync' command. After a recent deployment, some users report seeing old content. What is the MOST likely cause?

A.The website is served through Amazon CloudFront, and the CloudFront distribution cache was not invalidated after the deployment.
B.The S3 bucket policy blocks public read access, so users get a 403 error.
C.The IAM role for CodeBuild does not have permissions to write to the S3 bucket.
D.The deploy stage uses 's3 cp' instead of 's3 sync', so new files are not uploaded.
AnswerA

Although CodePipeline updates the S3 origin with the new static files, CloudFront edge locations continue to serve stale content until the cache TTL expires or an explicit invalidation is submitted. A CloudFront distribution does not automatically detect origin content changes; it caches objects based on the Cache-Control/Expires headers. Without creating an invalidation for '/*' (or for the changed paths) after the deployment, users will still see the previous version of the website, which matches the reported symptom. This is the only option that explains outdated content being served while the pipeline itself succeeds.

Why this answer

The most likely cause is that the static website is served through Amazon CloudFront, and the CloudFront distribution cache was not invalidated after the deployment. Even though the S3 bucket contents are updated via 's3 sync', CloudFront caches objects at edge locations based on TTL settings. Without a cache invalidation request, users continue to receive the old cached content until the TTL expires or the cache is manually cleared.

Exam trap

The trap here is that candidates may focus on S3 permissions or the sync command, overlooking the common real-world scenario where a CDN like CloudFront caches content and requires explicit invalidation after updates.

How to eliminate wrong answers

Option B is wrong because a bucket policy blocking public read access would result in a 403 Forbidden error, not users seeing old content. Option C is wrong because if the IAM role for CodeBuild lacked write permissions to the S3 bucket, the deployment would fail entirely, not partially serve old content. Option D is wrong because the question explicitly states the deploy stage uses 's3 sync', not 's3 cp', so this is a misreading of the scenario.

189
MCQmedium

A company uses AWS CodeCommit for source control. Developers frequently push large binary files (e.g., compiled JARs) to the repository, causing the repository size to grow rapidly and slowing down clone operations. The team wants to enforce a policy to reject pushes that contain files larger than 50 MB. Which approach should be used?

A.Configure a CodeCommit trigger that invokes an AWS Lambda function to validate file sizes and reject the push.
B.Set up an Amazon CloudWatch Events rule to monitor repository size and alert when it exceeds a threshold.
C.Create an IAM policy that denies the `codecommit:GitPush` action if the file size exceeds 50 MB.
D.Use a pre-receive hook in the repository to reject large files by generating an S3 pre-signed URL.
AnswerA

A CodeCommit trigger configured for push events can launch a Lambda function that inspects the incoming commits's metadata and calculates the size of each file. While native triggers are asynchronous, the Lambda can quickly delete the offending branch reference or tag, effectively rejecting the large-file push from a server-side governance perspective. This is the only option that applies custom validation logic that actually sees file content and can act to block the push, unlike IAM conditions, which cannot inspect Git payloads, or pre-receive hooks, which CodeCommit does not support.

Why this answer

AWS CodeCommit supports custom triggers that invoke AWS Lambda functions on repository events, including pushes. By configuring a trigger for the 'push' event, a Lambda function can inspect each file in the push payload, check its size against the 50 MB threshold, and programmatically reject the push by returning an error response. This approach enforces the policy at the repository level without requiring client-side changes.

Exam trap

The trap here is that candidates confuse CodeCommit triggers with Git hooks (like pre-receive hooks) or assume IAM policies can enforce content-based rules, when in fact IAM cannot inspect file contents and CodeCommit does not support server-side Git hooks.

How to eliminate wrong answers

Option B is wrong because Amazon CloudWatch Events can monitor repository metrics and send alerts, but it cannot actively reject a push; it only provides post-hoc notification after the push has already occurred. Option C is wrong because IAM policies evaluate permissions based on the principal, action, and resource, but they cannot inspect the content or size of files being pushed; the `codecommit:GitPush` action does not support condition keys for file size. Option D is wrong because CodeCommit does not support pre-receive hooks; that feature is specific to self-managed Git servers or AWS CodeCommit's hosted Git does not expose hook mechanisms like pre-receive scripts, and generating an S3 pre-signed URL is unrelated to rejecting pushes.

190
MCQeasy

A company runs a stateless web application on EC2 instances behind an Application Load Balancer. To improve resilience, which configuration should be used for the EC2 instances?

A.Use one EC2 instance with a larger instance type
B.Use a single, large EC2 instance in one Availability Zone
C.Use multiple EC2 instances in one Availability Zone with health checks disabled
D.Use multiple EC2 instances across two or more Availability Zones
AnswerD

Spreading instances across two or more Availability Zones ensures the application survives an AZ outage, since the Application Load Balancer routes to healthy targets in remaining zones. This directly satisfies the resilience requirement for the stateless workload.

Why this answer

D is correct because deploying multiple EC2 instances across two or more Availability Zones (AZs) ensures high availability and fault tolerance. If one AZ fails, the Application Load Balancer (ALB) automatically routes traffic to healthy instances in other AZs, maintaining service continuity. This aligns with the AWS Well-Architected Framework's resilience best practices for stateless applications.

Exam trap

The trap here is that candidates may think scaling vertically (larger instance) or using multiple instances in a single AZ is sufficient, but the DOP-C02 exam specifically tests the requirement for multi-AZ deployment to achieve resilience against AZ failures.

How to eliminate wrong answers

Option A is wrong because using a single, larger EC2 instance creates a single point of failure; if that instance fails, the entire application goes down. Option B is wrong because placing a single large instance in one AZ does not protect against AZ-level failures, such as power outages or network disruptions. Option C is wrong because using multiple instances in one AZ with health checks disabled means the ALB cannot detect and route away from failed instances, and a single AZ failure still takes down all instances.

191
MCQeasy

A DevOps engineer is troubleshooting a failed build in AWS CodeBuild. The build log shows: 'Error: Cannot find module 'lodash'.' The buildspec.yml file lists 'npm install' as a command. What is the most likely cause?

A.The npm install command is running before the source is downloaded.
B.The lodash package is not compatible with the Node.js version.
C.The package.json file is missing or does not include lodash.
D.The build environment does not have internet access to download packages.
AnswerC

`npm install` reads the `dependencies` and `devDependencies` fields in `package.json` and installs exactly the packages listed there. If lodash is not specified in that file, it will not be installed, and any subsequent `require('lodash')` or `import ... from 'lodash'` will throw `MODULE_NOT_FOUND`. A missing `package.json` would cause `npm install` to fail outright, but either way, the root cause is that lodash was not properly declared as a dependency.

Why this answer

The error 'Cannot find module 'lodash'' indicates that the lodash package is not installed. Since the buildspec includes 'npm install', the most likely cause is that the package.json file is missing or does not list lodash as a dependency. Without package.json or with incorrect dependencies, npm install will not install lodash, leading to the error.

192
MCQhard

A company is using AWS CodeDeploy to deploy a web application to an Auto Scaling group of Amazon EC2 instances. The deployment strategy is Blue/Green. After a successful deployment, the team notices that the new instances are receiving traffic but the application returns errors. The old instances are still serving traffic correctly. The team wants to roll back immediately. What should be done?

A.Stop the current deployment using the AWS CLI.
B.Manually update the Auto Scaling group to associate new instances with the old launch configuration.
C.Configure the deployment group to automatically roll back when a deployment fails, then manually trigger a rollback.
D.Redeploy the same application revision to the same Auto Scaling group.
AnswerC

The correct approach is to leverage CodeDeploy's rollback capability: configure the deployment group to automatically roll back on deployment failure (or on a CloudWatch alarm), which causes CodeDeploy to track the last known good revision. Triggering the rollback—either through the console's rollback action or by redeploying the previous successful revision—makes CodeDeploy deploy that good revision to the green fleet and shift traffic back to the original blue environment, restoring the known-good service. This is the only option that actively reverses the faulty deployment and restores live traffic, rather than merely affecting future instances or repeating the defect.

Why this answer

To roll back a CodeDeploy Blue/Green deployment, you should initiate a rollback deployment with the previous application revision. This can be done via the AWS CLI (`aws deploy create-deployment` with the old revision) or via the CodeDeploy console. Configuring automatic rollback on deployment failure is a separate setting and is not a prerequisite for manual rollback.

The explanation should be corrected to state that the rollback process creates a new replacement environment with the previous revision (or reuses the original if still available) and shifts traffic to it, not that automatic rollback must be configured first.

Exam trap

The trap is that candidates may think stopping a deployment or manually modifying Auto Scaling groups will revert traffic. However, the correct method is to use CodeDeploy's rollback feature for the deployment. Automatic rollback configuration is not required for manual rollback.

How to eliminate wrong answers

Option A is wrong because stopping a deployment in progress does not roll back the environment; it leaves the new instances in place and does not restore traffic to the old instances. Option B is wrong because you cannot manually associate instances with a different launch configuration in an Auto Scaling group; the launch configuration is immutable and applies only to new instances launched by the group, and the old instances are in a separate Auto Scaling group in a Blue/Green deployment. Option D is wrong because redeploying the same application revision will repeat the same failure; it does not revert to the previous working revision or restore the old instances.

193
MCQmedium

A company manages a large AWS CloudFormation template that defines a VPC, subnets, an Application Load Balancer, and an Auto Scaling group. The template has grown to over 2,000 lines and is difficult to maintain. The DevOps team wants to break the template into smaller, reusable components that can be versioned and shared across multiple teams. The components must be able to be included in other templates and must support parameters to customize values. Which CloudFormation feature should the team use?

A.CloudFormation nested stacks
B.CloudFormation modules
C.CloudFormation change sets
D.CloudFormation stack policies
AnswerB

CloudFormation modules are reusable building blocks that encapsulate resource definitions and can be included in templates via the AWS::CloudFormation::Module resource type. They support parameters and can be versioned and shared across teams, exactly matching the requirement. Modules simplify template maintenance by abstracting complexity and promoting consistency.

Why this answer

CloudFormation modules allow teams to package resource configurations into reusable, versioned components that can be included in multiple templates. They support parameters, enabling customization, and are ideal for breaking down monolithic templates. Unlike nested stacks, modules are lightweight and designed for sharing, making them the best fit for this scenario.

Exam trap

The trap here is confusing nested stacks with modules, because both enable reuse but nested stacks require deploying separate stacks and are not as easily shared across teams.

194
MCQhard

An organization uses AWS CodePipeline to deploy a web application to Amazon EC2 instances behind an Application Load Balancer. The deployment uses a CodeDeploy action with an in-place deployment configuration. After a recent deployment, some instances are running the old version while others are running the new version. What is the most likely cause?

A.The deployment group is associated with an Auto Scaling group that launched new instances during the deployment.
B.The deployment group was configured with the 'AllAtOnce' deployment configuration, and the deployment failed partway through.
C.A lifecycle hook is configured to pause the deployment until manual approval.
D.The deployment was configured to use a blue/green strategy, but the target group is misconfigured.
AnswerB

With the AllAtOnce deployment configuration, CodeDeploy targets every instance in the deployment group simultaneously, but if a failure occurs partway through, the deployment stops without rolling back unless you explicitly enabled automatic rollback. Instances that already received and ran the new revision keep it, while instances that were not yet updated remain on the old revision, yielding a mixed state across the fleet. This is exactly the situation that would leave some instances running the previous version and others running the new version.

Why this answer

B is correct because the 'AllAtOnce' deployment configuration instructs CodeDeploy to deploy to all instances simultaneously. If the deployment fails partway through, some instances may have received the new version while others remain on the old version, resulting in a mixed state. This is the most likely cause given the symptom of a split between old and new versions across instances.

Exam trap

The trap here is that candidates often assume a failed deployment would affect all instances equally, but they overlook that 'AllAtOnce' can leave a mixed state because CodeDeploy does not roll back instances that already received the new version when the deployment fails partway through.

How to eliminate wrong answers

Option A is wrong because if an Auto Scaling group launched new instances during the deployment, those new instances would typically be provisioned with the latest launch template or user data, not necessarily the old version; moreover, CodeDeploy would still attempt to deploy to them, and the inconsistency described is more directly explained by a partial failure. Option C is wrong because a lifecycle hook configured to pause the deployment until manual approval would halt the entire deployment process, not cause a partial rollout where some instances get the new version and others do not. Option D is wrong because a blue/green strategy would create a separate set of instances (the green environment) and shift traffic only after the new version is fully deployed and tested; a misconfigured target group might cause routing issues, but it would not result in a mix of old and new versions on the same set of instances.

195
MCQhard

A company runs a critical application on Amazon EKS. The DevOps team uses Prometheus for monitoring and Grafana for visualization. The team has set up a Prometheus server on an EC2 instance to scrape metrics from the EKS cluster. However, they are experiencing high memory usage on the Prometheus server, and some metrics are being dropped because of the retention period. The team wants to implement a scalable and managed monitoring solution that can store metrics for longer durations without the operational overhead of managing the Prometheus server. The team also wants to retain the ability to use PromQL queries and Grafana dashboards. What should the team do?

A.Use Amazon Managed Grafana to visualize metrics directly from the EKS cluster without a Prometheus server.
B.Migrate to Amazon Managed Service for Prometheus to ingest and store metrics, and use Amazon Managed Grafana for visualization.
C.Increase the EC2 instance size for the Prometheus server and extend the retention period.
D.Set up Amazon CloudWatch Container Insights to collect metrics from the EKS cluster and store them in CloudWatch Logs.
AnswerB

Amazon Managed Service for Prometheus is a scalable, fully managed service compatible with Prometheus query language (PromQL) and remote write. It eliminates the operational overhead of running Prometheus at scale, provides durable storage, and integrates with Amazon Managed Grafana for dashboards. This is the recommended AWS-native approach for long-term metrics retention on EKS.

Why this answer

Amazon Managed Service for Prometheus is a scalable, fully managed service that ingests and stores Prometheus metrics, supports PromQL queries, and integrates seamlessly with Amazon Managed Grafana. This eliminates the operational overhead of managing a Prometheus server while enabling longer retention and scaling. Option A is incorrect because Amazon Managed Grafana is a visualization tool only; it does not store metrics.

Option C is incorrect because increasing the EC2 instance size does not address the operational overhead or scalability issues; it only postpones the problem. Option D is incorrect because Amazon CloudWatch Container Insights does not support PromQL natively, and migrating to CloudWatch would require rewriting queries and dashboards, losing compatibility with existing Prometheus and Grafana setups.

196
MCQeasy

A company wants to ensure that its Amazon S3 bucket can withstand the loss of an entire AWS Availability Zone. Which configuration meets this requirement?

A.Use the S3 Standard storage class.
B.Configure cross-Region replication to another bucket.
C.Enable S3 Versioning on the bucket.
D.Use the S3 One Zone-IA storage class.
AnswerA

S3 Standard is the default storage class and is engineered to deliver 99.999999999% object durability and 99.99% availability by synchronously storing each object across a minimum of three Availability Zones (AZs) within the same AWS Region. When an AZ becomes unavailable, S3 automatically serves requests from the remaining copies, so the bucket stays accessible without manual intervention. Because the data exists in at least three independent AZs, a single AZ failure does not cause data loss or downtime, making it the appropriate choice for resilience against an AZ disruption.

Why this answer

S3 Standard storage class automatically replicates data across at least three Availability Zones within an AWS Region, ensuring resilience against the loss of an entire AZ. Option B is incorrect because cross-Region replication replicates data to a different AWS Region, which provides geographic resilience but not specifically AZ resilience within the same Region. Option C is incorrect because S3 Versioning helps protect against accidental deletion or overwrite by preserving previous versions, but it does not provide data replication across AZs.

Option D is incorrect because S3 One Zone-IA stores data in a single AZ, which would not withstand the loss of that AZ.

197
MCQeasy

A DevOps engineer is designing an AWS Lambda function that needs to read secrets from AWS Secrets Manager. What is the most secure way to provide the Lambda function access to the secret?

A.Assign an IAM execution role to the Lambda function with a policy that allows secretsmanager:GetSecretValue on the specific secret.
B.Store the secret in AWS Systems Manager Parameter Store and grant the Lambda function access to the parameter.
C.Encrypt the secret using AWS KMS and pass the encrypted value as an environment variable.
D.Store the secret in an environment variable in the Lambda function.
AnswerA

Attaching an IAM execution role with a least-privilege policy that allows secretsmanager:GetSecretValue on the specific secret ARN is the recommended pattern because it keeps the secret out of the function configuration and gives you native rotation, versioning, and CloudTrail audit events. If the secret is encrypted with a customer-managed KMS key, you must also grant kms:Decrypt on that key, but the default AWS-managed key used by Secrets Manager requires no additional KMS action. This lets the function call GetSecretValue at runtime and parse the returned JSON string without exposing the raw secret in environment variables or source code.

Why this answer

The most secure approach is to give the Lambda function an IAM execution role whose policy grants secretsmanager:GetSecretValue scoped to the specific secret's ARN. Lambda assumes this role at runtime, so no credentials are stored in code or configuration, and the secret value is retrieved dynamically, allowing rotation without redeployment. This follows least privilege and avoids hardcoding secrets.

Exam trap

DOP-C02 often tests the misconception that encrypting a secret and storing it in an environment variable is secure, when the correct pattern is runtime retrieval via an IAM execution role scoped to the specific secret.

How to eliminate wrong answers

Option B is wrong because Parameter Store (especially the standard tier) is not designed for secret rotation and lacks native rotation integration; while SecureString exists, Secrets Manager is the purpose-built service and the question specifies Secrets Manager. Option C is wrong because passing an encrypted value as an environment variable still exposes ciphertext in the function configuration and requires the function to hold KMS decrypt permissions and manage decryption logic — it also doesn't benefit from rotation. Option D is wrong because storing the secret in a plaintext environment variable exposes it in the Lambda console, CloudFormation templates, and logs, and requires redeployment to rotate — a clear security anti-pattern.

198
MCQhard

A company has a multi-account AWS environment using AWS Organizations. The security team has implemented a service control policy (SCP) that denies the creation of IAM users and roles with full admin access. The SCP is attached to all accounts. However, a DevOps engineer in a member account reports that they are able to create an IAM role with an administrator access policy attached. The engineer uses the AWS Management Console to create the role. The SCP is confirmed to be in place. What is the most likely reason the SCP is not preventing the role creation?

A.SCPs are not inherited by member accounts from the root.
B.The SCP is not attached to the member account's root organizational unit.
C.The engineer's IAM policy allows iam:CreateRole and overrides the SCP.
D.The SCP only denies iam:CreateUser, but the engineer is creating a role (iam:CreateRole).
AnswerD

The SCP only denies the iam:CreateUser action, which means it does not restrict the engineer's ability to create IAM roles. IAM role creation is governed by the iam:CreateRole permission, which is not covered by the SCP's deny statement. As a result, the engineer can create a new administrative role, attach a permissive policy to it, and assume that role to bypass the intended restrictions and achieve privilege escalation.

Why this answer

The SCP in question denies only the iam:CreateUser action, but the engineer is creating an IAM role, which requires the iam:CreateRole action. SCPs provide an explicit deny for actions they list; they do not block actions they do not list. Since the SCP does not deny iam:CreateRole, the engineer's IAM policy (which allows iam:CreateRole) is effective.

SCPs are inherited by member accounts and, when correctly attached, cannot be overridden by IAM policies; however, they only apply to the actions they explicitly specify.

Exam trap

Candidates often assume that an SCP denying creation of IAM users automatically covers roles, or that SCPs block all administrative actions. In this case, the SCP only prevents user creation, not role creation.

199
MCQhard

An incident response team is analyzing an IAM policy attached to a role used by a forensic tool. The tool needs to create snapshots of EBS volumes during an incident. However, when the tool runs from an IP address in the 203.0.113.0/24 range, the CreateSnapshot API call fails with an access denied error. What is the MOST likely cause?

A.The policy does not grant ec2:CreateSnapshot on specific resource ARNs, only on all resources.
B.The aws:ViaAWSService condition is set to false, but the tool is invoked by an AWS service such as Systems Manager, making the condition evaluate to true and denying access.
C.The Deny statement explicitly denies ec2:DeleteSnapshot, but the error is for CreateSnapshot, so it is unrelated.
D.The source IP address 203.0.113.0/24 is not included in the Condition block, so access is implicitly denied.
AnswerB

The aws:ViaAWSService global condition key is true when an AWS service, such as Systems Manager, makes the API call on the principal's behalf rather than the principal making a direct call. The policy's condition requires this key to be false, so when the tool is invoked via Systems Manager the actual value is true and the Allow statement does not match. With no other matching Allow, the request is implicitly denied, which is exactly the error observed.

Why this answer

The aws:ViaAWSService condition key evaluates to true when an API call is made by an AWS service on behalf of a principal. If the policy sets this condition to false, it denies any call that originates from an AWS service (e.g., Systems Manager Automation). In this scenario, the forensic tool is likely invoked by Systems Manager, causing the condition to evaluate to true and triggering the deny, even though the source IP is allowed.

This explains why CreateSnapshot fails with access denied despite the IP being in the allowed range.

Exam trap

The trap here is that candidates focus on the IP address condition and assume the error is due to an IP mismatch, overlooking the subtle aws:ViaAWSService condition that denies calls made through AWS services even when the source IP is allowed.

How to eliminate wrong answers

Option A is wrong because granting ec2:CreateSnapshot on all resources ("*") would not cause an access denied error; the error is due to a condition key, not resource ARN specificity. Option C is wrong because a deny on ec2:DeleteSnapshot is unrelated to the CreateSnapshot failure; IAM evaluates deny statements independently per action. Option D is wrong because the source IP 203.0.113.0/24 is included in the Condition block (as stated in the question), so implicit denial does not apply; the error is caused by the aws:ViaAWSService condition, not the IP condition.

200
Multi-Selectmedium

Which TWO options are valid approaches for managing configuration drift in an AWS environment? (Choose two.)

Select 2 answers
A.Use AWS Config rules to evaluate resource configurations against desired policies.
B.Use AWS CodePipeline to automatically redeploy infrastructure when changes are detected.
C.Use AWS Systems Manager Patch Manager to keep instances patched.
D.Use AWS CloudTrail to monitor API calls that modify resources.
E.Use AWS CloudFormation drift detection to identify resources that have been modified outside of CloudFormation.
AnswersA, E

AWS Config rules evaluate the recorded configuration of AWS resources against the desired policy logic you define in a rule. A rule can be AWS-managed (e.g., requiring S3 buckets to be encrypted) or custom (via Lambda), and it runs on a change-triggered or periodic schedule to identify noncompliant resources. When a resource deviates from the policy, AWS Config flags it as noncompliant and can trigger remediation actions, making it a continuous drift-detection and compliance-audit service.

Why this answer

AWS Config rules continuously evaluate your resource configurations against desired policies defined in managed or custom rules. When a resource configuration changes and violates a rule, AWS Config can trigger remediation actions or notify you, directly addressing configuration drift by detecting non-compliant resources in near real-time.

Exam trap

The trap here is that candidates confuse monitoring API calls (CloudTrail) with evaluating configurations against policies (AWS Config), or assume that redeploying via CodePipeline automatically corrects drift without a detection mechanism.

201
Multi-Selecthard

A DevOps team is investigating a performance issue where an application's response time spiked during a deployment. The deployment used AWS CodeDeploy to update an Auto Scaling group. Which THREE actions should the team take to identify the root cause? (Choose THREE.)

Select 3 answers
A.Review the CodeDeploy deployment logs for errors.
B.Examine application logs on the new EC2 instances launched during the deployment.
C.Review the CodeDeploy deployment group configuration.
D.Check AWS CloudTrail for any unauthorized API calls during the deployment.
E.Compare CloudWatch metrics for the Auto Scaling group before and after the deployment.
AnswersA, B, E

CodeDeploy deployment logs capture lifecycle event hook failures, invalid scripts, and resource timing issues during deployment (e.g., BeforeInstall/AfterInstall failures) that can leave instances in a degraded state causing performance hits. Any failed or aborted deployment step may cause new instances to be registered with incomplete configuration, leading to CPU/memory pressure or misrouted traffic. Scrutinizing these logs pinpoints whether the performance spike correlates with deployment execution timeouts, file overwrite errors, or instance registration failures.

Why this answer

CodeDeploy deployment logs contain detailed information about the deployment process, including any errors or failed steps that could impact performance. Option B is correct because application logs on the new EC2 instances can reveal errors, misconfigurations, or resource contention that may have caused the spike. Option E is correct because comparing CloudWatch metrics (e.g., CPU utilization, latency, request count) before and after the deployment helps pinpoint changes that correlate with the performance issue.

Option C is wrong because reviewing the deployment group configuration—which defines how deployments occur (e.g., traffic routing, instance selection)—is unlikely to directly identify the root cause of a performance spike; it is more relevant for deployment strategy issues. Option D is wrong because AWS CloudTrail records API calls for auditing and security, not application performance; unauthorized API calls are unlikely to cause a transient performance spike during deployment.

202
Multi-Selecthard

An e-commerce platform uses Amazon DynamoDB as its primary database. During a flash sale, the application experiences throttling errors. The operations team needs to implement a solution to handle sudden traffic spikes while keeping costs under control. Which TWO actions should the team take? (Choose two.)

Select 2 answers
A.Increase the read and write capacity units manually before the sale.
B.Switch from on-demand to provisioned capacity with auto scaling.
C.Implement DynamoDB Accelerator (DAX) to cache read-intensive data.
D.Use application-level retry logic with exponential backoff to handle throttling gracefully.
E.Enable DynamoDB Streams and replicate data to a read replica.
AnswersC, D

Implementing DynamoDB Accelerator (DAX) is correct because it puts a write-through, in-memory cache directly in front of your DynamoDB table. DAX intercepts repeated read requests—such as product details, pricing, or inventory views during a sale—and serves them in microseconds, dramatically reducing the read capacity units consumed by the table. This offloading lowers the chance of throttling your primary table while keeping latency low for read-heavy traffic.

Why this answer

DynamoDB Accelerator (DAX) is an in-memory cache that reduces read latency from milliseconds to microseconds, offloading read requests from the main DynamoDB table. During a flash sale, caching read-intensive data (e.g., product details) with DAX reduces the number of read capacity units consumed, helping to avoid throttling while keeping costs under control by not requiring a permanent increase in provisioned capacity.

Exam trap

The trap here is that candidates often confuse DynamoDB Streams with read replicas, or assume that provisioned capacity with auto scaling is always cost-effective for spikes, when in fact on-demand capacity is designed for unpredictable traffic and avoids the cold-start throttling risk of auto scaling.

203
MCQmedium

A DevOps team is troubleshooting a CloudFormation stack creation failure. The error message states: 'CREATE_FAILED: Resource handler returned message: "You have attempted to create more resources than the current AWS account limit"'. Which step should the team take to resolve this issue?

A.Delete the failed stack and recreate it with the same template.
B.Review the IAM permissions for the CloudFormation service role.
C.Modify the CloudFormation template to use a different resource type.
D.Check the current service limits for the resource type and request a limit increase from AWS Support.
AnswerD

When CloudFormation returns an error that an account limit has been reached, it means the AWS resource API rejected the creation request due to service quota exhaustion for that resource type in the current region. You should use the Service Quotas console or AWS Support to check the current limit and request an increase, then wait for approval before retrying the stack creation. This directly resolves the root cause without modifying the template or IAM role.

Why this answer

The error message explicitly indicates that the CloudFormation stack creation failed because the AWS account has reached a service limit for a specific resource type. Option D is correct because the team must first identify which resource type exceeded its limit (e.g., EC2 instances, VPCs, or IAM roles) by checking the AWS Service Quotas console or using the Trusted Advisor dashboard, then request a limit increase from AWS Support. Simply retrying the stack creation or modifying IAM permissions will not resolve a hard service quota violation.

Exam trap

The trap here is that candidates may confuse a service limit error with an IAM permissions issue or a template syntax error, leading them to choose options B or C instead of recognizing the need to check and increase AWS service quotas.

How to eliminate wrong answers

Option A is wrong because deleting and recreating the stack with the same template will not change the account-level service limit; the same resource count will be attempted, causing the same failure. Option B is wrong because IAM permissions control who can create resources, but the error is about exceeding a service quota, not about authorization—CloudFormation already had permission to attempt the creation. Option C is wrong because changing the resource type in the template does not address the underlying limit issue; the new resource type may have its own separate quota, but the error is about exceeding a limit for a specific resource type, not about the type itself being invalid.

204
Multi-Selectmedium

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer. The operations team wants to analyze application access logs and error rates. They need to identify the top IP addresses making requests, as well as the distribution of HTTP status codes over time. Which THREE steps should the team take to achieve this? (Select THREE.)

Select 3 answers
A.Enable access logs on the Application Load Balancer and store them in an Amazon S3 bucket.
B.Use Amazon CloudWatch Logs Insights to run queries on the access logs.
C.Enable AWS CloudTrail to log all API calls.
D.Enable VPC Flow Logs to capture IP traffic data.
E.Use Amazon CloudWatch Contributor Insights to analyze the top IP addresses.
AnswersA, B, E

Enabling access logs on the Application Load Balancer is the foundational step; it delivers a raw, per-request log file containing the client IP, request URI, User-Agent, and HTTP status code for every request handled by the ALB. These logs are written in gzip-compressed files to an S3 bucket you specify, and S3 provides durable, queryable storage. Without this first step, no HTTP-level transaction data exists in S3, making any subsequent log analysis or querying impossible. This is why enabling ALB access logs is the correct primary action.

Why this answer

Enabling access logs on the Application Load Balancer and storing them in an S3 bucket captures detailed HTTP request data, including client IPs, request paths, and HTTP status codes. This raw log data is essential for analyzing top IP addresses and status code distributions over time.

Exam trap

The trap here is confusing AWS CloudTrail (management plane logging) with application-level access logging, leading candidates to select CloudTrail instead of ALB access logs for HTTP request analysis.

205
MCQmedium

A company runs a containerized order-processing service on Amazon EKS. The DevOps team wants to detect when the service's CPU utilization exceeds 80% for 5 consecutive minutes and then automatically notify an on-call engineer. They also need to see both application logs and CPU metrics side-by-side in a single dashboard for troubleshooting. Which combination of AWS services should the team use to meet these requirements with the LEAST operational overhead?

A.AWS X-Ray with CloudWatch Logs Insights and CloudWatch alarms
B.Amazon CloudWatch Container Insights with CloudWatch alarms and CloudWatch dashboards
C.AWS CloudTrail with Amazon EventBridge rules and Amazon SNS topics
D.Amazon Managed Service for Prometheus with AWS Distro for OpenTelemetry and Grafana dashboards
AnswerB

Container Insights automatically collects CPU, memory, network, and log data from EKS nodes and pods without installing custom agents beyond the CloudWatch agent DaemonSet. CloudWatch alarms evaluate the CPUUtilization metric over 5-minute periods, and CloudWatch dashboards can display both metrics and log insights queries together, satisfying the monitoring and alerting needs with minimal operational effort.

Why this answer

Container Insights provides native EKS monitoring with automatic metric and log collection, and CloudWatch alarms and dashboards integrate directly to alert on CPU thresholds and visualize logs and metrics together. The other options either lack CPU metric collection or require substantial additional tooling and management, making them less suitable for a low-overhead solution.

Exam trap

The trap here is assuming that X-Ray or CloudTrail can provide CPU utilization metrics, when they are designed for tracing and auditing respectively.

206
MCQmedium

A company hosts a web application on EC2 instances behind an Application Load Balancer. The application stores sensitive user data in an S3 bucket. A Security Engineer needs to ensure that the EC2 instances can only access the specific S3 bucket and no other AWS services. Which solution meets these requirements?

A.Attach a bucket policy to the S3 bucket that allows access only from the ALB's security group.
B.Create an IAM role with a policy that grants s3:PutObject and s3:GetObject access to the specific bucket, and attach the role to the EC2 instances as an instance profile.
C.Configure a VPC endpoint for S3 and modify the route table to route S3 traffic through the endpoint.
D.Create a security group that allows outbound HTTPS traffic only to the S3 bucket's IP address range.
AnswerB

An instance profile supplies temporary AWS credentials to the EC2 instance via the instance metadata service, and the attached IAM role's policy can be scoped to the exact bucket and the required actions. This provides least-privilege access, ensuring the instances can read and write only that bucket without long-lived keys or additional service permissions. Because IAM policies explicitly identify the resource (the bucket ARN) and the actions, no other AWS service or bucket is accessible unless separately allowed.

Why this answer

Creating an IAM role with a policy that grants s3:PutObject and s3:GetObject access only to the specific S3 bucket, and attaching that role to the EC2 instances as an instance profile, ensures that the instances can only access that bucket. This method uses AWS Identity and Access Management (IAM) to restrict permissions per resource. Option A is incorrect because an S3 bucket policy restricting access to the ALB's security group cannot control what the instances themselves do; the instances can still access S3 directly if they have credentials.

Option C is incorrect because a VPC endpoint for S3 provides private connectivity but does not restrict which resources the instances can access; it only ensures traffic stays within the AWS network. Option D is incorrect because security groups cannot filter traffic based on S3 bucket names or policies; they only filter IP addresses and ports, and S3 uses HTTPS which is not restrictable by security group to a specific bucket.

207
MCQeasy

A DevOps engineer needs to automate the creation of a new AWS CodeCommit repository when a new project starts. The engineer wants to use infrastructure as code. Which service should be used?

A.AWS CloudFormation
B.AWS CodePipeline
C.AWS CodeStar
D.AWS CodeBuild
AnswerA

AWS CloudFormation is the correct choice because it is a declarative Infrastructure as Code (IaC) service that can directly model and provision AWS resources, including AWS CodeCommit repositories. You define a repository in a CloudFormation template using the AWS::CodeCommit::Repository resource type, specifying properties such as RepositoryName and Code, and CloudFormation will create, update, and delete the repository as part of stack lifecycle management, making it ideal for automating resource creation.

Why this answer

AWS CloudFormation is the correct service because it allows you to define and provision AWS infrastructure as code using templates. You can declare an AWS::CodeCommit::Repository resource in a CloudFormation template, which will automatically create the CodeCommit repository when the stack is created, enabling fully automated and repeatable infrastructure deployment.

Exam trap

The trap here is that candidates may confuse AWS CodeStar's project templates (which can include a CodeCommit repository) with the ability to define infrastructure as code, but CodeStar does not provide the same declarative, version-controlled infrastructure management that CloudFormation offers.

How to eliminate wrong answers

Option B (AWS CodePipeline) is wrong because it is a continuous delivery service for building, testing, and deploying code changes, not for provisioning infrastructure resources like a CodeCommit repository. Option C (AWS CodeStar) is wrong because it is a project management and collaboration service that provides a unified interface for CI/CD pipelines, but it does not directly create CodeCommit repositories via infrastructure as code templates. Option D (AWS CodeBuild) is wrong because it is a fully managed build service that compiles source code and runs tests, not a service for defining or creating infrastructure resources.

208
Multi-Selecthard

A company runs a critical application on AWS using Amazon EC2 instances in an Auto Scaling group, an Application Load Balancer (ALB), and an Amazon RDS for PostgreSQL Multi-AZ DB cluster. The application must maintain an RTO of 5 minutes and an RPO of 1 second for database transactions. The current setup meets these requirements, but the DevOps team wants to improve the resilience of the application tier to withstand a regional failure. Which THREE actions should be taken? (Choose three.)

Select 3 answers
A.Replace the RDS Multi-AZ cluster with Amazon Aurora Global Database to replicate data across regions.
B.Use an active-passive architecture with a second Auto Scaling group and ALB in another region.
C.Use Amazon EFS Replication to replicate application data across regions with a recovery point objective (RPO) of 1 second.
D.Extend the existing Auto Scaling group to launch instances in two regions by specifying a second region in the launch template.
E.Set up Amazon Route 53 with health checks and failover routing policy to direct traffic to the secondary region if the primary fails.
AnswersA, B, E

RDS Multi-AZ only synchronously replicates to a standby in the same Region, so it cannot protect against a regional outage. Amazon Aurora Global Database replicates data to up to five secondary Regions using storage-level replication, typically with an RPO of 1 second or less, while still providing a familiar MySQL/PostgreSQL-compatible endpoint. Promoting a secondary Region during failover is a fast, deliberate action that preserves the database's durability and availability in a disaster recovery scenario.

Why this answer

Amazon Aurora Global Database is the correct choice because it provides cross-region replication with a typical RPO of 1 second and RTO of 1 minute, meeting the stated requirements. Unlike standard RDS Multi-AZ, which is limited to a single region, Aurora Global Database replicates data asynchronously across multiple regions with minimal lag, ensuring the database tier can survive a regional failure while maintaining the required RPO of 1 second.

Exam trap

The trap here is that candidates often confuse Multi-AZ with cross-region disaster recovery, assuming Multi-AZ alone provides regional failover, when in fact it only protects against Availability Zone failures within a single region.

209
Multi-Selectmedium

A company is designing a disaster recovery (DR) strategy for a critical application that runs on EC2 instances with an RDS database. The DR site must be in a different AWS Region. The Recovery Point Objective (RPO) is 15 minutes, and Recovery Time Objective (RTO) is 1 hour. Which TWO actions should the company take to meet these objectives? (Choose TWO.)

Select 2 answers
A.Use AWS Backup to copy EC2 AMIs and RDS snapshots to the DR region every 15 minutes.
B.Use AWS CloudFormation to pre-provision resources in the DR region manually.
C.Configure Amazon Route 53 with health checks and failover routing to the DR region.
D.Create an RDS cross-Region read replica in the DR region.
E.Configure S3 cross-Region replication for application data stored in S3.
AnswersC, D

Amazon Route 53 health checks monitor the primary endpoint (e.g., an Application Load Balancer or an IP address) and automatically detect when it becomes unhealthy. With failover routing, Route 53 stops returning the primary resource's DNS answer and instead returns the DR region's endpoint, effectively steering user traffic within minutes. This directly supports the RTO by eliminating the need for manual DNS changes, and it works with any application architecture as long as the endpoint can be health-checked. However, Route 53 only handles traffic redirection—it does not replicate data or pre-warm compute, so it must be paired with a data replication strategy to also meet the RPO.

Why this answer

Options C and D are correct. D: Creating an RDS cross-Region read replica in the DR region allows the replica to be promoted to the primary database with minimal data loss, meeting the 15-minute RPO. C: Configuring Amazon Route 53 with health checks and failover routing enables automatic traffic redirection to the DR region within the 1-hour RTO.

Option A is wrong because copying AMIs and RDS snapshots every 15 minutes would require launching EC2 instances and restoring the database from snapshots, which can exceed the 1-hour RTO. Option B is wrong because manually pre-provisioning resources with CloudFormation does not provide the automated failover needed to meet the RTO. Option E is wrong because S3 cross-Region replication does not address the EC2 and RDS components of the application.

210
MCQmedium

A company uses AWS CloudFormation to manage infrastructure. The team wants to ensure that all stack updates are reviewed and approved before execution. Which mechanism should the team implement?

A.Create a stack policy that denies all updates unless approved.
B.Use AWS CloudFormation drift detection to identify changes before updating.
C.Enable termination protection on the stack to prevent accidental updates.
D.Use AWS CloudFormation change sets to review the proposed changes before executing the update.
AnswerD

A change set is a read-only summary of the exact modifications CloudFormation will make to the stack when you execute it, including resource type add/remove/replace and whether the change is dynamically applied or requires no interruption. You can create and inspect multiple change sets from different template versions without touching live infrastructure, then deliberately execute the approved one—only execution applies the update. This gives you the review-before-apply gate that the requirement asks for, as the change set is the proposed changes themselves rather than a policy or detection signal.

Why this answer

AWS CloudFormation change sets allow you to preview how proposed changes to a stack will be applied before you execute them. This includes a summary of additions, modifications, and deletions of resources, enabling you to review and approve the changes in a controlled manner. By generating a change set, the team can ensure that no update is executed without prior review and approval, meeting the requirement for a gated deployment process.

Exam trap

The trap here is that candidates confuse stack policies (which control resource-level permissions) with change sets (which provide a preview of changes), or they mistakenly think termination protection or drift detection can gate updates, when neither is designed for that purpose.

How to eliminate wrong answers

Option A is wrong because a stack policy controls permissions for stack resources (e.g., preventing updates to specific resources) but does not provide a review-and-approve workflow for the entire stack update; it cannot block the update itself. Option B is wrong because drift detection identifies whether the stack's actual resources have deviated from the template, but it does not preview or gate proposed updates; it is a detective, not a preventive, control. Option C is wrong because termination protection prevents accidental deletion of the entire stack, not updates; it has no effect on stack updates or change review.

211
MCQeasy

A company uses Amazon RDS for PostgreSQL and wants to monitor database performance metrics such as CPU utilization, memory, and disk I/O. Which AWS service should be used to set up custom dashboards and alarms for these metrics?

A.AWS X-Ray
B.Amazon VPC Flow Logs
C.AWS CloudTrail
D.Amazon CloudWatch
AnswerD

Amazon CloudWatch natively ingests Amazon RDS performance metrics—including CPU utilization, freeable memory, database connections, read/write IOPS, and replica lag—through the AWS/RDS metric namespace. These metrics are published automatically and can be visualized in CloudWatch dashboards or used to trigger alarms for proactive alerting and auto scaling actions. CloudWatch also supports publishing custom metrics and streaming RDS logs, making it the comprehensive monitoring service for RDS PostgreSQL.

Why this answer

Amazon CloudWatch (Option D) is the correct service for monitoring Amazon RDS performance metrics such as CPU utilization, memory, and disk I/O. CloudWatch provides built-in metrics for RDS, allows creation of custom dashboards to visualize these metrics, and supports setting alarms for proactive notifications. Option A (AWS X-Ray) is used for tracing and analyzing requests through applications, not for infrastructure metrics.

Option B (Amazon VPC Flow Logs) captures IP traffic information for network troubleshooting, not database performance. Option C (AWS CloudTrail) logs API calls for auditing, not performance monitoring. Therefore, CloudWatch is the appropriate choice for this use case.

212
MCQmedium

A company uses AWS CodeDeploy for application deployments to EC2 instances. The team recently noticed that deployments are failing because some instances do not have the CodeDeploy agent installed. Which configuration management approach should the team implement to ensure the CodeDeploy agent is installed and running on all instances before deployment?

A.Use an AWS Config rule to detect instances without the agent and trigger a Lambda function to install it.
B.Use the CodeDeploy deployment configuration to skip instances that do not have the agent.
C.Create a custom AMI with the CodeDeploy agent pre-installed, or use a user data script to install the agent at launch.
D.Configure the CodeDeploy deployment group to automatically install the agent on new instances.
AnswerC

Pre-installing the CodeDeploy agent in a custom AMI (or bootstrapping it via user-data at instance launch) ensures the agent is running before the instance ever joins a deployment group. Because the agent is already present, CodeDeploy's deployment workflow can immediately begin pulling the AppSpec file and application revision from Amazon S3 or GitHub without waiting for an installation step. This proactive approach also avoids the time-of-installation risk where a deployment starts before a scripted agent installation completes, and it minimizes the chance of an instance being skipped or failing due to a missing agent.

Why this answer

It ensures the CodeDeploy agent is present on every EC2 instance from the moment it is launched, either by baking the agent into a custom AMI or by installing it via a user data script. This approach aligns with immutable infrastructure and configuration management best practices, preventing deployment failures caused by missing agents. AWS CodeDeploy requires the agent to be installed and running on target instances before any deployment can proceed.

Exam trap

The trap here is that candidates may assume CodeDeploy can automatically install its own agent on instances (Option D), but AWS CodeDeploy has no such built-in capability; the agent must be provisioned independently through AMI, user data, or a configuration management tool like AWS Systems Manager or Chef.

How to eliminate wrong answers

Option A is wrong because AWS Config rules are reactive and can only detect non-compliance after an instance is launched, not proactively ensure the agent is installed before deployment; additionally, relying on a Lambda function to install the agent introduces latency and potential race conditions. Option B is wrong because CodeDeploy deployment configurations do not support skipping instances based on agent presence; if an instance lacks the agent, the deployment will fail for that instance, and the overall deployment may fail depending on the failure threshold. Option D is wrong because CodeDeploy deployment groups do not have a built-in feature to automatically install the agent on new instances; the agent must be installed separately via AMI, user data, or an external configuration management tool.

213
Multi-Selectmedium

A team wants to run a CodeBuild project that builds a container image and pushes it to Amazon ECR, but the build currently fails with an access denied error when calling ecr:InitiateLayerUpload. The CodeBuild project uses a service role and runs in a VPC. Which TWO actions should the engineer take to resolve the error while keeping the build functional? (Choose two.)

Select 2 answers
A.Set the CodeBuild project's privileged mode to true so the Docker daemon can authenticate to Amazon ECR.
B.Change the buildspec to use the AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY environment variables stored in plaintext.
C.Attach an IAM policy to the CodeBuild service role granting the required Amazon ECR push actions on the target repository.
D.Disable the CodeBuild service role and switch the project to use an IAM user's access keys for authentication.
E.If the build runs in a VPC, ensure a NAT gateway or VPC endpoint allows connectivity to Amazon ECR and its dependent services.
AnswersC, E

The access denied error indicates the build's AWS credentials lack permission for ECR push operations. Granting ecr:InitiateLayerUpload along with the related push actions such as ecr:PutImage and ecr:UploadLayerPart on the specific repository authorizes the docker push and directly resolves the failure.

Why this answer

The failure is an authorization and connectivity issue, not a Docker capability issue. Adding the required ECR push permissions to the CodeBuild service role authorizes the API calls, and ensuring the VPC can reach ECR endpoints allows the push to complete. Together these address both the permission and network dimensions of the error without introducing static credentials or unnecessary privileges.

Exam trap

The trap here is assuming privileged mode or static credentials fix an access denied error, when the error is about missing IAM permissions and, for VPC builds, missing network paths to ECR.

214
MCQmedium

A company runs a web application behind an Application Load Balancer (ALB) in a production AWS account. The DevOps team needs to analyze HTTP request patterns and identify the top IP addresses generating errors. They want to store the data cost-effectively for querying with SQL. Which solution meets these requirements?

A.Use CloudWatch Metrics to monitor error rates and top IPs via custom metrics.
B.Enable CloudWatch Logs for the ALB and use CloudWatch Logs Insights to query the logs.
C.Stream the ALB logs to Amazon Kinesis Data Analytics and use SQL applications.
D.Enable ALB access logs and store them in Amazon S3, then use Amazon Athena to query the logs with SQL.
AnswerD

Enabling ALB access logs to be delivered to Amazon S3 creates immutable, row-based log files that are ideal for large-scale retrospective analysis. Amazon Athena lets you run standard SQL directly on that S3 data using a serverless engine that charges only for the bytes scanned, and you can further optimize costs and performance by partitioning S3 objects by date or using compression. This combination is the industry-standard cost-effective approach when the goal is to perform flexible SQL queries over historical ALB logs without pre-provisioning infrastructure or paying for continuous ingestion.

Why this answer

ALB access logs provide detailed HTTP request data (including source IP, request URI, response code, etc.) and are stored in Amazon S3, which is cost-effective for long-term storage. Amazon Athena allows querying these logs directly with standard SQL without needing to load data into a database, meeting the requirement for SQL-based analysis of top IP addresses generating errors.

Exam trap

The trap here is that candidates often confuse CloudWatch Logs (which for ALB only contain error logs, not full request details) with ALB access logs (which are stored in S3 and contain all request data), leading them to choose Option B instead of D.

How to eliminate wrong answers

Option A is wrong because CloudWatch Metrics cannot capture individual HTTP request details like source IP addresses; custom metrics are aggregated and cannot be used to identify top IPs generating errors. Option B is wrong because CloudWatch Logs for ALB capture only error-level logs (e.g., 5xx responses) and do not include request-level details such as source IP; CloudWatch Logs Insights cannot query for top IP addresses from these logs. Option C is wrong because Kinesis Data Analytics is designed for real-time stream processing with SQL, but the requirement is to store data cost-effectively for querying, not real-time analysis; streaming logs to Kinesis incurs ongoing costs and is overkill for batch querying of historical patterns.

215
MCQeasy

A company wants to monitor the number of messages in an Amazon SQS queue and send an alert if the queue depth exceeds 1000 for more than 5 minutes. Which AWS service should be used to create the alarm?

A.Amazon EventBridge
B.Amazon CloudWatch Alarms
C.AWS X-Ray
D.Amazon CloudWatch Logs
AnswerB

Amazon CloudWatch Alarms are the correct choice because they continuously monitor a specified CloudWatch metric—such as ApproximateNumberOfMessagesVisible for an SQS queue—against a defined threshold over a configured period. When the metric crosses the threshold, the alarm changes state (OK, ALARM, or INSUFFICIENT_DATA) and can trigger an action like an SNS notification, EC2 Auto Scaling, or an arbitrary EC2 stop/terminate action. This provides the exact metric-threshold monitoring required.

Why this answer

Amazon CloudWatch Alarms is the correct service because it can monitor SQS queue metrics (such as ApproximateNumberOfMessagesVisible) and trigger an alarm when the metric exceeds a threshold (e.g., 1000) for a specified evaluation period (e.g., 5 minutes). CloudWatch Alarms directly integrate with SQS via the AWS/SQS namespace and support actions like sending notifications through Amazon SNS.

Exam trap

The trap here is that candidates may confuse EventBridge's ability to react to SQS metric changes (via CloudWatch metric streams) with the actual alarm evaluation logic, but EventBridge cannot perform threshold-based monitoring over a time window—only CloudWatch Alarms can.

How to eliminate wrong answers

Option A is wrong because Amazon EventBridge is a serverless event bus used for routing events between services (e.g., reacting to state changes), not for monitoring metric thresholds over time or creating alarms based on sustained conditions. Option C is wrong because AWS X-Ray is a distributed tracing service for analyzing and debugging application requests, not for monitoring queue depth or setting metric alarms. Option D is wrong because Amazon CloudWatch Logs is used for storing, monitoring, and querying log data, not for creating alarms on numeric metrics like SQS queue depth.

216
MCQeasy

A company wants to monitor CPU utilization of its EC2 instances and receive an alert when utilization exceeds 80% for 5 consecutive minutes. Which AWS service should be used to create this alarm?

A.AWS CloudTrail
B.VPC Flow Logs
C.Amazon CloudWatch Alarms
D.AWS Config
AnswerC

Amazon CloudWatch Alarms are the correct service because they directly evaluate CloudWatch metrics, and CPUUtilization is a built-in metric emitted by EC2 instances. You can configure an alarm to transition to an ALARM state when the average CPU utilization exceeds a threshold, and then trigger actions like Auto Scaling, Amazon SNS notifications, or EC2 actions (reboot, stop, terminate). Alarm evaluation periods and statistic types (e.g., average, maximum) allow precise control over when an alarm fires, making it the natural choice for CPU monitoring.

Why this answer

Amazon CloudWatch Alarms is the correct service to monitor CPU utilization of EC2 instances and trigger an alert when the metric exceeds a threshold for a specified period. CloudWatch collects metrics from EC2 instances, and alarms can be configured to watch a metric over a time period and perform actions (e.g., send an SNS notification) when the threshold is breached. This directly matches the requirement.

Exam trap

DOP-C02 often tests the difference between monitoring, logging, and auditing services, and candidates may incorrectly choose CloudTrail or Config for performance monitoring.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail logs API activity, not performance metrics like CPU utilization. Option B is wrong because VPC Flow Logs capture IP traffic information, not instance performance metrics. Option D is wrong because AWS Config evaluates resource configurations against desired policies, not real-time performance metrics.

217
MCQhard

A company uses AWS Elastic Beanstalk for application deployments. They want to integrate infrastructure-as-code practices using AWS CloudFormation. Which approach allows them to manage the Elastic Beanstalk environment and underlying resources as part of a CloudFormation stack?

A.Use a custom resource backed by a Lambda function to create the Elastic Beanstalk environment.
B.Use the CloudFormation import feature to bring the existing Elastic Beanstalk environment into the stack.
C.Export the Elastic Beanstalk environment configuration as a CloudFormation template from the console.
D.Define the Elastic Beanstalk environment in the CloudFormation template using the AWS::ElasticBeanstalk::Environment resource.
AnswerD

The correct approach is to declare the Elastic Beanstalk environment directly in your CloudFormation template with the AWS::ElasticBeanstalk::Environment resource. This native resource supports properties such as ApplicationName, SolutionStackName or PlatformArn, OptionSettings, and Tags, allowing CloudFormation to create and manage the environment as part of the stack. It integrates cleanly with other stack resources and avoids custom code or workarounds.

Why this answer

CloudFormation natively supports Elastic Beanstalk through the AWS::ElasticBeanstalk::Environment and AWS::ElasticBeanstalk::Application resource types. Defining the environment in the template lets CloudFormation create, update, and delete the environment and its underlying resources (EC2, ASG, ELB, security groups) as part of the stack, giving full IaC lifecycle management.

Exam trap

DOP-C02 often tests whether candidates know that Elastic Beanstalk has first-class CloudFormation resource types — many assume a custom resource or import is needed because Beanstalk 'manages its own resources.'

How to eliminate wrong answers

Option A is wrong because a custom resource backed by Lambda is a workaround that only creates the environment imperatively — CloudFormation cannot track or manage the underlying resources, so drift and rollback are not handled. Option B is wrong because CloudFormation import only supports a limited set of resource types and cannot import an existing Elastic Beanstalk environment into a stack. Option C is wrong because the Elastic Beanstalk console does not export a CloudFormation template; that capability does not exist.

218
Multi-Selecteasy

Which THREE AWS services can be used as a source action in AWS CodePipeline? (Choose three.)

Select 3 answers
A.Amazon S3
B.Amazon DynamoDB
C.AWS CodeCommit
D.AWS CloudFormation
E.GitHub (via webhook)
AnswersA, C, E

Amazon S3 is a fully supported source action in AWS CodePipeline. You can store a single zip file or a set of files in an S3 bucket, and CodePipeline detects changes when the object version changes or via Amazon CloudWatch Events. The bucket must have versioning enabled so that each upload creates a new source artifact, which is then downloaded and extracted in the Source stage for subsequent build and deploy actions.

Why this answer

Amazon S3 is a supported source action in AWS CodePipeline because you can configure a pipeline to use an S3 bucket as a source location for your application code or artifacts. When you upload a new version of a file to the specified S3 bucket, CodePipeline can automatically detect the change (via Amazon CloudWatch Events or S3 event notifications) and start the pipeline execution. This is commonly used for deploying static websites or integrating with third-party CI/CD tools that output artifacts to S3.

Exam trap

The trap here is that candidates often confuse services that can be used as source actions (where code/artifacts originate) with services that can be used as deploy or test actions, leading them to incorrectly select CloudFormation (a deploy action) or DynamoDB (a database service) as source options.

219
MCQhard

A company is using AWS Organizations with multiple accounts. The security team wants to enforce that all S3 buckets have encryption enabled. They need a preventive control that applies to all current and future accounts. Which approach should they use?

A.Use a service control policy (SCP) in the Organizations root to deny PutBucketEncryption actions when encryption settings do not include AES256 or aws:kms.
B.Use AWS Config rules to detect unencrypted buckets and automatically apply encryption using a remediation action.
C.Enable AWS CloudTrail to log all S3 API calls and send alerts when non-compliant buckets are created.
D.Create an IAM policy in each account that denies PutBucketEncryption unless encryption is enabled.
AnswerA

A service control policy (SCP) attached at the Organizations root is a preventive guardrail that applies to every account in the organization, including accounts created later. By using the s3:x-amz-server-side-encryption condition key with values AES256 or aws:kms, you can deny any PutBucketEncryption call that attempts to use a different encryption type, such as SSE-C or no encryption. This works because SCPs filter permitted API actions before they reach IAM, and they cannot be overridden by account administrators, making them the correct way to enforce encryption settings organization-wide.

Why this answer

A service control policy (SCP) applied at the Organizations root can deny the creation or modification of S3 buckets that do not have encryption enabled, specifically requiring AES256 or aws:kms. This is a preventive control that applies to all current and future accounts in the organization, as SCPs are inherited by all accounts and cannot be overridden by IAM policies within those accounts.

Exam trap

The trap here is that candidates often confuse detective controls (like AWS Config or CloudTrail) with preventive controls (like SCPs), or assume that IAM policies applied per account are sufficient for organization-wide enforcement, failing to recognize that SCPs are the only mechanism that applies uniformly to all accounts, including future ones.

How to eliminate wrong answers

Option B is wrong because AWS Config rules are detective, not preventive; they can detect non-compliant buckets and trigger remediation, but they do not prevent the non-compliant action from occurring in the first place. Option C is wrong because CloudTrail is a logging service that records API calls after they happen; it cannot prevent the creation of unencrypted buckets, only alert on them. Option D is wrong because IAM policies are account-specific and must be manually applied to each account; they do not scale to future accounts automatically and can be overridden by account administrators with sufficient permissions.

220
Multi-Selectmedium

A company uses AWS CloudFormation to deploy infrastructure. They want to enforce mandatory tags on all resources created by CloudFormation. Which TWO approaches can achieve this? (Choose TWO.)

Select 2 answers
A.Use CloudFormation stack tags that propagate to all resources in the stack.
B.Create an AWS Config rule to automatically tag resources after creation.
C.Use an AWS Organizations service control policy (SCP) to deny creation of resources that are not tagged.
D.Add an IAM policy that denies cloudformation:CreateStack unless the template includes the required tags.
E.Enable AWS CloudTrail to log all API calls and monitor for untagged resources.
AnswersA, C

CloudFormation stack tags are specified on the stack and automatically propagated to every resource in the stack that supports tagging. Because CloudFormation applies these tags to resources during the CREATE or UPDATE operation, resources are born with the required tags, eliminating the need for a post-creation remediation step. This provides a native, preventive control that works without requiring any custom Lambda functions or additional configuration.

Why this answer

CloudFormation stack tags propagate to all resources that support tagging within the stack. When you specify tags at the stack level, CloudFormation automatically applies them to each resource it creates, ensuring mandatory tags are enforced without additional configuration.

Exam trap

The trap here is that candidates often confuse reactive detection (AWS Config) with proactive prevention (SCPs or stack tags), or mistakenly believe IAM policies can parse template content to enforce tagging rules.

221
MCQeasy

A DevOps engineer is designing a CI/CD pipeline for a serverless application using AWS Lambda and Amazon API Gateway. The team wants to automate deployment across multiple environments (dev, test, prod) with environment-specific configuration. Which approach should the engineer use?

A.Use the AWS Serverless Application Model (SAM) with CodePipeline, and pass environment parameters as CloudFormation parameter overrides.
B.Use CodeBuild to package the Lambda code and then use CloudFormation with parameters for each environment.
C.Use CodeDeploy with a deployment configuration that deploys to all environments sequentially.
D.Use CodePipeline with separate CodeBuild projects for each environment.
AnswerA

SAM is the only option that natively pairs with CodePipeline for serverless deployments: the pipeline can run `sam build` and `sam package` in a CodeBuild stage, then use a CloudFormation change set via the `CreateReplaceChangeSet` action. By specifying a `ParameterOverrides` JSON file (e.g., `stageName`, `environment`, `vpcConfig`) on that action, each environment (dev, test, prod) reuses the same pipeline definition yet receives its own configuration without duplicating stages or using manual scripts. SAM also generates the Lambda function, event sources, and permissions as a CloudFormation template, so environment-specific values propagate consistently through `AWS::Serverless::Function` properties and `!Ref` parameters.

Why this answer

AWS SAM is purpose-built for serverless applications and integrates natively with CodePipeline and CodeBuild. SAM templates are transformed into CloudFormation, so environment-specific values (memory, env vars, API stages) can be injected via CloudFormation parameter overrides at deploy time. This gives one template, many environments, with no custom scripting.

Exam trap

DOP-C02 often tests whether candidates confuse build orchestration (CodeBuild) with deployment orchestration (CodePipeline + CloudFormation/SAM), leading them to pick per-environment build projects instead of a single pipeline with parameter overrides.

How to eliminate wrong answers

Option B is wrong because CodeBuild only packages artifacts; it does not orchestrate multi-environment deployment or provide the SAM transform that simplifies Lambda/API Gateway resource definitions. Option C is wrong because CodeDeploy is for EC2/ECS/Lambda traffic shifting, not for sequential multi-environment pipeline orchestration, and it has no concept of environment parameters. Option D is wrong because separate CodeBuild projects per environment duplicate build logic and still lack a deployment mechanism that understands serverless resources or parameter overrides.

222
MCQhard

A company uses AWS CodePipeline to deploy a serverless application. The pipeline has a source stage (CodeCommit), a build stage (CodeBuild), and a deploy stage (CloudFormation). The deployment consistently fails because the Lambda function's IAM role is not created before the function. The team uses a single CloudFormation template. Which action should be taken to resolve this dependency issue?

A.Add a DependsOn attribute in the CloudFormation template to ensure the IAM role is created before the Lambda function.
B.Create the IAM role in a separate CodeBuild action before the deploy stage.
C.Add a wait condition in the CloudFormation template.
D.Separate the IAM role into a nested stack and reference it.
AnswerA

DependsOn is the correct CloudFormation mechanism to explicitly control resource creation order when there is no implicit dependency. Even though CloudFormation automatically creates a dependency when you use Ref or GetAtt in a resource property, there are cases where the Lambda function's IAM role ARN is substituted indirectly (e.g., via a parameter or a Fn::Sub in a string), so CloudFormation cannot infer the ordering. Adding DependsOn: IamRole to the Lambda function resource guarantees that the IAM role is fully created before the Lambda function is provisioned, preventing the deployment failure that occurs when Lambda tries to use a role that does not yet exist.

Why this answer

The CloudFormation template lacks an explicit dependency between the IAM role resource and the Lambda function resource. By adding a `DependsOn` attribute to the Lambda function resource, you ensure CloudFormation creates the IAM role first, resolving the deployment failure. This is the standard way to handle resource creation order within a single CloudFormation template.

Exam trap

The trap here is that candidates may assume CloudFormation automatically resolves all dependencies via intrinsic references, but when resources are referenced by name strings rather than logical IDs, explicit `DependsOn` is required to enforce creation order.

How to eliminate wrong answers

Option B is wrong because creating the IAM role in a separate CodeBuild action introduces unnecessary complexity and does not guarantee the role is available before the CloudFormation deploy stage; the role must exist in the same account and region before the template is applied. Option C is wrong because wait conditions are used to pause stack creation until an external signal is received, not to define resource dependencies within the same template. Option D is wrong because separating the IAM role into a nested stack does not inherently enforce creation order; you would still need a DependsOn or explicit reference to ensure the nested stack completes before the Lambda function is created.

223
MCQeasy

A company uses AWS Systems Manager Automation to patch EC2 instances. The automation document 'AWS-RunPatchBaseline' runs successfully but some instances are not patched because they are not managed by Systems Manager. What is the most likely reason?

A.The instances are running Windows Server 2012 or older.
B.The instances are in a VPC without internet access.
C.The instances do not have the AWS Systems Manager Agent (SSM Agent) installed and the required IAM role attached.
D.The automation document is not compatible with the instance's operating system.
AnswerC

The SSM Agent is the software component that executes Systems Manager requests on the instance, and the instance must also have an instance profile with IAM permissions to call Systems Manager APIs and download patch content. Without the agent or a role such as AmazonSSMManagedInstanceCore, the instance will not show up as a managed node and the automation cannot even target or initiate patching. This is the definitive prerequisite that is missing in this scenario.

Why this answer

Systems Manager Automation can only patch instances that are managed by Systems Manager. For an instance to be managed, it must have the SSM Agent installed and running, and it must have an IAM role that grants the necessary permissions (e.g., AmazonSSMManagedInstanceCore) to communicate with the Systems Manager service. Without these prerequisites, the instance is not registered as a managed node, so the automation document cannot target or patch it.

Exam trap

The trap here is that candidates may assume patching failures are due to network connectivity or OS compatibility, when the root cause is almost always the missing SSM Agent or missing IAM role that prevents the instance from being managed by Systems Manager.

How to eliminate wrong answers

Option A is wrong because Windows Server 2012 or older is still supported by Systems Manager Patch Manager as long as the SSM Agent is installed and the instance is managed; the OS version alone does not prevent management. Option B is wrong because instances in a VPC without internet access can still be managed by Systems Manager if they use a VPC endpoint (interface or gateway endpoint) for Systems Manager and Amazon S3, or if they use a proxy or NAT gateway; lack of internet access does not inherently block management. Option D is wrong because the 'AWS-RunPatchBaseline' document is compatible with both Windows and Amazon Linux operating systems; incompatibility is not the reason for instances being unmanaged.

224
MCQeasy

A company uses AWS CloudTrail to log all API calls across multiple accounts. The logs are stored in an S3 bucket in the management account. The security team wants to ensure that the logs are not tampered with and that any unauthorized modification is detected. The DevOps engineer has enabled CloudTrail log file integrity validation. The engineer also sets up an S3 lifecycle policy to transition logs to Glacier after 90 days. Additionally, the engineer enables S3 server access logging and sends the logs to a different bucket. A few months later, the security team suspects that some logs have been deleted. The engineer checks the CloudTrail digest files and finds that the latest digest file is missing. What is the most likely cause?

A.The S3 lifecycle policy transitions objects to Glacier after 90 days, causing the digest file to appear missing when listing the bucket without filtering by storage class.
B.The S3 bucket has default encryption enabled, causing the digest files to be unreadable.
C.The server access logging is writing access logs to the same bucket, causing overwrites.
D.The S3 bucket has Object Lock enabled, which prevents deletion of any objects.
AnswerA

While the scenario describes a transition to Glacier (not expiration), the lifecycle policy is still the cause: the digest file is moved to Glacier and becomes inaccessible, appearing missing. This is the most likely cause among the options.

Why this answer

CloudTrail log file integrity validation stores digest files in the same S3 bucket as the logs. The lifecycle policy transitions all objects, including digest files, to Glacier after 90 days. When objects are transitioned to Glacier, they remain in the bucket but are not readily accessible via standard S3 list operations unless you specifically request the Glacier storage class.

As a result, the latest digest file may appear missing, leading to the assumption that logs were deleted.

225
MCQmedium

An application running on AWS Lambda is experiencing cold starts. The team wants to monitor the cold start duration. What should they do?

A.Monitor the 'InitDuration' metric in CloudWatch for the Lambda function.
B.Use CloudWatch Logs Insights to query log groups for 'REPORT' lines and calculate duration.
C.Publish a custom metric from the Lambda code that measures initialization time.
D.Enable AWS X-Ray and trace the Lambda invocation to see cold start duration.
AnswerA

Monitoring the 'InitDuration' metric is the direct, built-in approach because CloudWatch automatically receives this metric for every Lambda invocation that experiences a cold start. This metric reports the time the runtime spends initializing the execution environment (downloading the code, starting the runtime, and running initialization code) before the handler is invoked. It requires no custom instrumentation or querying, making it the simplest and most authoritative source for cold start duration.

Why this answer

AWS Lambda automatically publishes the 'InitDuration' metric in CloudWatch for cold starts, which measures the time spent initializing the runtime and code. Option B is incorrect because while CloudWatch Logs Insights can query for 'REPORT' lines, it is more complex and unnecessary since the metric is already available. Option C is incorrect because publishing a custom metric from the Lambda code is redundant; the InitDuration metric is automatically provided.

Option D is incorrect because AWS X-Ray can trace cold starts, but the dedicated metric is simpler and directly available.

Page 2

Page 3 of 18

Page 4