Courseiva

AWS Certified DevOps Engineer Professional DOP-C02 (DOP-C02) — Questions 526–600

1298 questions total · 18pages · All types, answers revealed

Page 7

Page 8 of 18

Page 9
526
Multi-Selecteasy

A company wants to enable AWS CloudTrail to log all API calls across multiple accounts in AWS Organizations. The security team requires that logs be encrypted at rest and that any unauthorized deletion of log files be prevented. Which TWO actions should the security team take? (Choose TWO.)

Select 2 answers
A.Create a trail in the management account that applies to all accounts in the organization.
B.Enable default encryption with SSE-S3 on the S3 bucket where CloudTrail delivers logs.
C.Configure CloudTrail to send logs to Amazon CloudWatch Logs and enable encryption using an AWS KMS key.
D.Enable S3 Object Lock on the destination S3 bucket to prevent log file deletion.
E.Enable CloudTrail Insights to detect unusual API activity.
AnswersA, D

By creating an organization trail in the management account (using AWS Organizations), CloudTrail automatically logs API activity for all member accounts, including the management account itself, without needing to configure trails in each account. This centralizes governance and ensures the requirement of logging all API calls across the entire AWS environment is met, as organization trails deliver log files for every account to a single S3 bucket.

Why this answer

Enabling CloudTrail for all accounts in the organization ensures centralized logging. Option D is correct because S3 Object Lock prevents deletion of log files. Option B is incorrect because KMS with a customer managed key provides encryption, but the key must be created beforehand, not just enabled.

Option C is incorrect because CloudWatch Logs encryption uses KMS, not S3 SSE. Option E is incorrect because CloudTrail can be configured to log management events by default, and this is not about data events.

527
MCQhard

An organization runs a critical application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. The application requires that all traffic be encrypted in transit. The security team mandates the use of TLS 1.2 or higher and specific ciphers. What is the MOST efficient way to enforce this requirement?

A.Use a Network Load Balancer with TLS listeners and target groups.
B.Place a CloudFront distribution in front of the ALB and configure the origin protocol policy.
C.Install a self-signed certificate on each EC2 instance and configure the web server.
D.Configure the ALB with a security policy that enforces TLS 1.2 and the required ciphers.
AnswerD

ALB security policies terminate TLS at the load balancer and enforce the minimum protocol version and cipher suite list, satisfying the TLS 1.2 requirement without modifying each EC2 instance. This centralises enforcement at the single ingress point.

Why this answer

The Application Load Balancer (ALB) supports predefined security policies that enforce TLS version and cipher requirements at the load balancer level, providing centralized control. Option D is correct because configuring the ALB with a security policy that mandates TLS 1.2 and specific ciphers meets the requirement efficiently without modifying individual instances. Option A is incorrect because a Network Load Balancer (NLB) with TLS listeners does not offer the same granular security policy options as ALB and is less efficient for this requirement.

Option B is incorrect because CloudFront is a CDN service; placing it in front of the ALB does not directly enforce TLS settings on the ALB itself and adds unnecessary complexity. Option C is incorrect because installing self-signed certificates on each EC2 instance is inefficient, not centralized, and does not enforce consistent TLS version and cipher requirements across all traffic.

528
MCQmedium

A DevOps team is troubleshooting a slow application. They enabled AWS X-Ray tracing and see that one of the downstream services has a high average response time. However, the traces show that the service itself is fast; the delay is in the network call from the upstream service. Which X-Ray feature should the team use to identify the root cause?

A.Examine the trace map to see the connection between services.
B.Add annotations to the traces for better filtering.
C.View the raw segments of the upstream service.
D.Adjust the sampling rules to capture more traces.
AnswerA

The AWS X-Ray trace map is the correct tool because it visualizes each service as a node and the connections between them as edges, with latency metrics for each edge. This directly reveals whether the identified slowness stems from network communication between services (for example, high I/O wait or retries) rather than from code execution inside a single service, allowing the DevOps team to pinpoint the exact segment of the request path that is underperforming.

Why this answer

The trace map in AWS X-Ray provides a visual representation of the service graph, showing the connections and latency between services. Since the delay is in the network call from the upstream service to the downstream service, the trace map can highlight the specific edge where the high latency occurs, allowing the team to pinpoint whether the issue is due to network congestion, DNS resolution, or a slow HTTP connection. This is the most direct way to identify the root cause of the inter-service communication delay.

Exam trap

The trap here is that candidates might focus on the downstream service's segment (Option C) thinking the delay is inside that service, when the trace map is specifically designed to reveal inter-service communication latency that is not captured by individual segment durations.

How to eliminate wrong answers

Option B is wrong because annotations are key-value pairs added to traces for custom metadata filtering, not for diagnosing network latency between services. Option C is wrong because viewing raw segments of the upstream service would show the service's own processing time and subsegments, but the delay is in the downstream network call, which is captured as a subsegment of the upstream service's trace; however, the trace map is more efficient for visualizing the edge-level latency. Option D is wrong because adjusting sampling rules increases the number of traces captured but does not help identify the root cause of an existing latency issue in the network call.

529
MCQmedium

A company uses EC2 instances in an Auto Scaling group behind an ALB. The DevOps team receives alerts that the CPU utilization on the instances is consistently above 90% during peak hours. The Auto Scaling group is configured with a simple scaling policy that adds one instance when CPU exceeds 80% and removes one when below 30%. However, during sudden traffic spikes, the scaling policy reacts too slowly, causing performance degradation. The team wants to improve the scaling responsiveness without over-provisioning. What should the team do?

A.Increase the cooldown period for the simple scaling policy to allow more time for metrics to stabilize.
B.Replace the simple scaling policy with a step scaling policy that adds multiple instances when CPU exceeds 80%.
C.Create a scheduled scaling action to add instances before peak hours based on historical data.
D.Replace the simple scaling policy with a target tracking scaling policy based on average CPU utilization with a target value of 70%.
AnswerD

A target tracking scaling policy with a target value of 70% average CPU utilization proactively adds instances before utilization reaches 80% and continuously adjusts to maintain the target, providing fast response to spikes without over-provisioning.

Why this answer

A target tracking scaling policy automatically adjusts the size of the Auto Scaling group to keep the average CPU utilization close to the target value (70%). This provides a proactive and responsive scaling mechanism for sudden traffic spikes without manual intervention. Option A is incorrect because increasing the cooldown period would delay scaling actions, worsening the response time.

Option B is incorrect because although a step scaling policy can add multiple instances at once, it requires manual configuration of thresholds and step adjustments, and it may not adapt as smoothly to varying spikes as target tracking. Option C is incorrect because scheduled scaling only addresses predictable traffic patterns, not sudden, unpredictable spikes.

530
Multi-Selecteasy

A company wants to design a highly available and fault-tolerant architecture for a stateless web application on AWS. Which TWO actions should they take? (Choose two.)

Select 2 answers
A.Use a single large EC2 instance to simplify management
B.Deploy multiple Application Load Balancers in each AZ
C.Launch EC2 instances in at least two Availability Zones
D.Use an RDS Multi-AZ deployment for the web server fleet
E.Use an Auto Scaling group to replace failed instances automatically
AnswersC, E

Launching EC2 instances in at least two Availability Zones is the foundational principle for highly available web server fleets. Availability Zones are physically separate data centers with independent power, cooling, and networking, so a failure in one AZ does not affect the other. Combined with a load balancer that spans those same AZs, traffic automatically continues to be served by healthy instances if one AZ loses capacity. This design eliminates the single-AZ dependency and is a core requirement for fault-tolerant compute tiers.

Why this answer

To achieve high availability and fault tolerance for a stateless web application, you should deploy EC2 instances in at least two Availability Zones (C) to eliminate a single point of failure, and use an Auto Scaling group (E) to automatically replace failed instances and maintain desired capacity. Option A is incorrect because a single large instance is a single point of failure and does not provide fault tolerance. Option B is incorrect because multiple Application Load Balancers per AZ are unnecessary; a single ALB can route traffic across multiple AZs.

Option D is incorrect because RDS Multi-AZ is a database feature, not for the web server fleet.

531
MCQeasy

A company uses AWS Systems Manager to manage a fleet of EC2 instances. They need to run a script on all instances that have a specific tag 'Environment:Development'. Which Systems Manager capability should be used?

A.Inventory
B.Patch Manager
C.Run Command
D.State Manager
AnswerC

Run Command is the correct choice because it provides secure, on-demand remote execution of scripts and commands across EC2 instances, targeting tagged instances through AWS resource groups or tag key-value pairs. It uses SSM documents to define the script and the SSM Agent to execute it, with results streamed back to the console or S3. This directly matches the requirement to run a script on a fleet selected by tags.

Why this answer

Run Command is the correct capability because it allows you to remotely and securely execute scripts or commands on targeted EC2 instances using AWS Systems Manager. You can target instances by specifying tags, such as 'Environment:Development', and Run Command will execute the script on all matching instances without requiring SSH or RDP access.

Exam trap

The trap here is confusing Run Command with State Manager, as both can execute scripts, but State Manager is for recurring, state-enforcement tasks (using associations), not for immediate, tag-based ad-hoc execution.

How to eliminate wrong answers

Option A is wrong because Inventory is used to collect metadata and configuration data from instances (e.g., installed applications, network configuration), not to execute scripts. Option B is wrong because Patch Manager is designed to automate the process of patching operating systems and applications, not for running arbitrary scripts. Option D is wrong because State Manager is used to define and maintain consistent state configurations (e.g., ensuring a specific software is installed) on a schedule, not for ad-hoc or on-demand script execution.

532
MCQmedium

A DevOps engineer runs the command above to retrieve CPU utilization for an EC2 instance, but gets no data points. The instance is running and has basic monitoring enabled. What is the most likely reason?

A.The dimension name should be 'InstanceId' with a different case.
B.The instance has basic monitoring disabled.
C.The period of 300 seconds is less than the minimum supported period.
D.The IAM user executing the command lacks 'cloudwatch:GetMetricStatistics' permission.
AnswerD

The IAM user must have the cloudwatch:GetMetricStatistics permission to call the CloudWatch API and retrieve metric statistics. If the IAM policy attached to the user does not explicitly allow this action, the request is denied and no CPUUtilization data points are returned. Since the namespace, metric name, dimensions, and period are all valid, the most plausible reason for the lack of data is that the IAM permission is missing.

Why this answer

The command likely fails because the IAM user executing it does not have the 'cloudwatch:GetMetricStatistics' permission. Basic monitoring publishes CPUUtilization metrics every 5 minutes (300 seconds), so a period of 300 seconds is valid. The dimension name 'InstanceId' is correct as shown.

Option A is wrong because the dimension name is case-sensitive and 'InstanceId' is correct. Option B is wrong because basic monitoring is enabled by default and publishes CPUUtilization. Option C is wrong because 300 seconds equals the default 5-minute interval, which is the minimum supported period for basic monitoring.

533
MCQmedium

An organization uses AWS Elastic Beanstalk to deploy a web application. They need to ensure that configuration changes (e.g., environment variables, instance types) are version-controlled and can be rolled back. Which approach meets these requirements?

A.Use AWS Systems Manager Parameter Store to store configuration values.
B.Create a custom script that uses the Elastic Beanstalk API to apply configuration and store the script in a Git repository.
C.Use Elastic Beanstalk saved configurations to capture environment settings and store the configuration files in a version control system.
D.Manually record all configuration changes in a spreadsheet.
AnswerC

Elastic Beanstalk saved configurations capture environment option settings into a JSON or YAML template that can be downloaded and committed to version control. These templates can be applied to new or existing environments with a direct API/CLI call, enabling repeatable deployment and rollback to a known good state. Because the configuration file is just a file in your repository, you get code review, history, and drift detection naturally.

Why this answer

Elastic Beanstalk saved configurations allow you to capture the complete environment settings (including environment variables, instance types, and other configuration options) as a YAML or JSON file. By storing these configuration files in a version control system (e.g., Git), you achieve version-controlled configuration that can be applied to recreate or roll back an environment to a known state using the `eb config` command or the AWS Management Console.

Exam trap

The trap here is that candidates often confuse storing individual parameters (Parameter Store) with capturing the entire environment configuration, or they overcomplicate the solution with custom scripts when Elastic Beanstalk provides a built-in, versionable saved configuration feature that directly meets the requirement.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Parameter Store is a service for storing individual parameter values (e.g., database passwords, API keys) and does not capture the full Elastic Beanstalk environment configuration (such as instance type, scaling settings, or environment links) nor does it provide a mechanism to roll back an entire environment to a previous state. Option B is wrong because creating a custom script that uses the Elastic Beanstalk API to apply configuration and storing it in Git is an ad-hoc, error-prone approach that does not leverage Elastic Beanstalk's native saved configuration feature, which already provides a standardized, versionable format for environment settings. Option D is wrong because manually recording changes in a spreadsheet is not automated, not version-controlled in a meaningful way, and does not provide any mechanism to programmatically apply or roll back configuration changes.

534
Multi-Selectmedium

A company is using AWS CloudFormation to manage its infrastructure. The DevOps team wants to implement drift detection to identify resources that have been modified outside of CloudFormation. Which TWO of the following are correct statements about CloudFormation drift detection?

Select 2 answers
A.Drift detection is automatically performed every time the stack is updated.
B.Drift detection can be performed on nested stacks independently.
C.Drift detection automatically reverts any changes to the original template.
D.Drift detection can detect changes to resources such as security groups.
E.Drift detection can be performed on a stack at any time.
AnswersD, E

Security groups are among the resource types for which CloudFormation compares the live configuration—such as ingress rules, egress rules, and group name/description—against the template. If someone adds or removes a rule out-of-band, drift detection marks the security group as MODIFIED. This makes drift detection useful for catching unauthorized network-level changes to your VPC infrastructure.

Why this answer

Drift detection can detect changes to resources such as security groups because CloudFormation supports drift detection for a wide range of AWS resources, including EC2 security groups. When drift detection is performed, CloudFormation compares the current configuration of each supported resource in the stack with the expected configuration defined in the stack template. If a security group rule is added or removed outside of CloudFormation (e.g., via the AWS Console or CLI), drift detection will report that resource as drifted.

Exam trap

The trap here is that candidates often assume drift detection is automatic or can fix drift, but AWS explicitly requires manual initiation and only provides detection, not remediation.

535
MCQmedium

A company runs a stateful application on EC2 instances. They want to distribute traffic evenly and maintain session stickiness. Which AWS service should they use?

A.Network Load Balancer
B.Application Load Balancer with sticky sessions
C.Amazon Route 53 weighted routing policy
D.Amazon CloudFront with origin failover
AnswerB

An Application Load Balancer with sticky sessions is the correct solution because it operates at Layer 7 and can inspect HTTP/HTTPS traffic. ALB uses either the AWSALB cookie with a configurable duration or an application-controlled cookie to send all requests from the same client session to the same EC2 instance. This preserves in-memory session state, which is exactly what a stateful application requires.

Why this answer

An Application Load Balancer with sticky sessions (session affinity) distributes HTTP/HTTPS traffic across targets while binding a client to the same target for the duration of a session via a cookie. This satisfies both even distribution and session persistence for a stateful application.

Exam trap

DOP-C02 often tests whether candidates know that only ALB provides cookie-based sticky sessions; picking NLB because it is 'high performance' ignores the session-affinity requirement.

How to eliminate wrong answers

Option A is wrong because Network Load Balancer operates at Layer 4 and, while it supports source-IP affinity, it does not offer cookie-based sticky sessions and is not ideal for HTTP-layer session state. Option C is wrong because Route 53 weighted routing distributes DNS answers across endpoints but provides no session stickiness and is not a load balancer. Option D is wrong because CloudFront with origin failover is a CDN feature for content delivery and origin redundancy, not session-aware load balancing across EC2 targets.

536
MCQmedium

A company uses AWS CloudTrail to log all API calls. During an incident investigation, a security engineer needs to identify who deleted an S3 bucket named 'critical-data' two days ago. Which approach will provide the necessary information?

A.Use AWS CloudTrail LookupEvents API to search for DeleteBucket events.
B.Check the AWS Management Console activity history.
C.Review the S3 access logs for the bucket.
D.Search CloudWatch Logs for 'DeleteBucket' events.
AnswerA

The AWS CloudTrail LookupEvents API is the correct method because it directly queries CloudTrail's event history, which records all control plane API calls such as DeleteBucket. You can use the LookupAttributes parameter with AttributeKey=EventName and AttributeValue=DeleteBucket, filtering by time range if needed. This returns the full event record, including the IAM user or role, source IP, and timestamp, for any deletion within the last 90 days. It is the native, low-latency mechanism for exactly this forensic search.

Why this answer

CloudTrail records management events such as DeleteBucket, and the LookupEvents API allows programmatic search of the last 90 days of event history by event name, so it can identify who deleted the bucket two days ago. This is the intended mechanism for API-level auditing. The other options either lack the event detail, cover only data-plane access, or require prior configuration that is not guaranteed.

Exam trap

DOP-C02 often tests the boundary between CloudTrail management events and S3 access logs, so candidates pick S3 access logs because the resource is an S3 bucket, missing that bucket deletion is a management event captured by CloudTrail.

How to eliminate wrong answers

Option B is wrong because the AWS Management Console activity history only shows actions taken by the current user in the console and does not provide a full account-wide audit trail with identity details. Option C is wrong because S3 access logs record data-plane requests to objects and buckets, not the DeleteBucket management API call or the caller identity in the same way CloudTrail does. Option D is wrong because CloudWatch Logs only contains CloudTrail events if a trail was configured to deliver them there, and even then the LookupEvents API is the direct, reliable way to query event history.

537
MCQeasy

A company uses AWS CodeCommit for source control. Developers frequently push large binary files, causing the repository size to exceed the recommended limit. What is the most efficient way to manage this situation?

A.Increase the repository size limit in CodeCommit settings.
B.Use Git LFS (Large File Storage) and configure it to store binaries in S3.
C.Periodically run a script to remove large files from the commit history.
D.Use S3 directly for storing binaries and reference them in code.
AnswerB

Git LFS solves the binary bloat problem by replacing each large file in the repository with a tiny text pointer, while the actual file content is stored in a separate, scalable LFS store—in this case, an S3 bucket you configure. During checkout, the Git LFS client retrieves the real file from S3 transparently, so developers see the full content without the repository itself growing. This keeps CodeCommit clones fast, avoids the 10 GB limit, and integrates smoothly with existing Git branching and merging workflows.

Why this answer

Git LFS (Large File Storage) replaces large binary files in the repository with lightweight text pointers, while the actual binary content is stored in an external storage backend such as Amazon S3. This keeps the CodeCommit repository small and within recommended limits, and developers continue to use standard Git commands without performance degradation.

Exam trap

The trap here is that candidates assume increasing a service limit is always possible (Option A), but AWS CodeCommit enforces a hard 10 GB repository limit that cannot be raised, making Git LFS the only scalable solution.

How to eliminate wrong answers

Option A is wrong because CodeCommit does not allow increasing the repository size limit beyond the default 10 GB; the limit is a hard service quota and cannot be adjusted. Option C is wrong because periodically rewriting Git history to remove large files is disruptive, forces all developers to rebase or re-clone, and does not prevent future large file pushes. Option D is wrong because storing binaries directly in S3 and referencing them in code breaks the developer workflow—developers must manually manage S3 uploads and versioning, losing the seamless integration and version control that Git LFS provides.

538
Multi-Selectmedium

A DevOps engineer is designing a monitoring solution for a serverless application using AWS Lambda, Amazon API Gateway, and Amazon DynamoDB. The team needs to monitor for errors and latency. Which TWO actions should the engineer take to implement comprehensive monitoring? (Choose TWO.)

Select 2 answers
A.Enable DynamoDB Accelerator (DAX) to reduce latency.
B.Enable detailed billing metrics for cost analysis.
C.Configure CloudWatch Logs for DynamoDB.
D.Enable AWS X-Ray tracing on API Gateway and Lambda.
E.Set up CloudWatch Alarms on Lambda error count and API Gateway 5XX count.
AnswersD, E

AWS X-Ray traces requests end-to-end from API Gateway to Lambda and downstream services like DynamoDB, capturing segments, sub-segments, and annotations that reveal where latency is consumed and which component is returning errors. By enabling X-Ray on API Gateway and Lambda, the DevOps engineer can inspect trace timelines, service maps, and error rates per operation to pinpoint performance bottlenecks and failed invocations. This provides correlated, request-level observability that CloudWatch aggregate metrics alone cannot offer, making it a correct component of a comprehensive monitoring solution.

Why this answer

AWS X-Ray provides end-to-end tracing for requests as they travel through API Gateway, Lambda, and DynamoDB, enabling the team to identify latency bottlenecks and errors across the entire serverless application. This is essential for comprehensive monitoring of distributed applications, as it captures detailed timing and error data for each component.

Exam trap

The trap here is that candidates may confuse performance optimization tools (like DAX) or cost monitoring (like billing metrics) with actual monitoring solutions, or assume that DynamoDB has native CloudWatch Logs support, when in fact it only emits metrics and requires X-Ray or CloudTrail for detailed request tracing.

539
MCQmedium

A company's security policy requires that all data stored in Amazon S3 must be encrypted at rest using server-side encryption with customer-managed keys (SSE-KMS). When uploading an object via the AWS CLI, which parameter must be included to enforce this?

A.--kms-key-id <key-id>
B.--sse AES256
C.--encryption aws:kms
D.--server-side-encryption aws:kms
AnswerD

This is the S3 CLI parameter that explicitly requests server-side encryption with AWS KMS (SSE-KMS). Setting the value to `aws:kms` instructs S3 to use a customer master key (CMK) for encrypting the object at rest. When combined with `--kms-key-id`, it allows specifying a particular KMS key, but the presence of `--server-side-encryption aws:kms` alone satisfies the encryption requirement.

Why this answer

The correct parameter to enforce server-side encryption with AWS KMS (SSE-KMS) when uploading an object via the AWS CLI is --server-side-encryption aws:kms, which corresponds to option D. Option A is incorrect because --kms-key-id only specifies the key ID but does not enable encryption by itself; it must be combined with --server-side-encryption aws:kms. Option B is incorrect because --sse AES256 is not a valid AWS CLI parameter; the correct parameter for SSE-S3 is --server-side-encryption AES256.

Option C is incorrect because --encryption is not a valid AWS CLI parameter for server-side encryption.

540
Multi-Selectmedium

A DevOps engineer is responsible for securing a containerized application running on Amazon ECS with the Fargate launch type. The application needs to access an Amazon RDS database and an Amazon S3 bucket. The security team requires that credentials are not hardcoded and that access is least privilege. Which two actions should the engineer take to meet these requirements? (Choose two.)

Select 2 answers
A.Store the database credentials in AWS Secrets Manager and grant the ECS task role permission to retrieve them.
B.Configure the ECS task definition to use environment variables for the database password.
C.Use AWS Systems Manager Parameter Store to store the database credentials as plaintext strings.
D.Create an IAM user with programmatic access and embed the access keys in the container image.
E.Attach an IAM role to the ECS task that grants access to the S3 bucket and Secrets Manager secret.
AnswersA, E

Secrets Manager securely stores and rotates credentials. By granting the ECS task role permission to retrieve the secret, the application can fetch credentials at runtime without hardcoding them. This aligns with least privilege and eliminates static credentials in code or environment variables.

Why this answer

The secure approach is to use an IAM task role for AWS service access and AWS Secrets Manager for database credentials. The task role provides temporary credentials for S3 and Secrets Manager, while Secrets Manager securely stores and can rotate the database password. This combination avoids hardcoded credentials and supports least privilege.

Exam trap

The trap here is thinking that environment variables or Parameter Store plaintext are acceptable for secrets, when they lack encryption and rotation, and that an IAM user with embedded keys is safe when it is actually a major security risk.

541
MCQeasy

A company wants to centrally manage and apply policies across multiple AWS accounts in an AWS Organization. Which service should be used to define and enforce compliance rules?

A.AWS Organizations Service Control Policies (SCPs)
B.AWS Config rules
C.AWS CloudTrail
D.IAM policies
AnswerA

SCPs centrally govern the maximum available permissions for every IAM principal in all accounts within an AWS Organizations hierarchy. They act as guardrails that filter which actions a principal or root user can perform, regardless of any IAM policies that grant broader access, enabling cross-account policy enforcement.

Why this answer

AWS Organizations Service Control Policies (SCPs) are the correct choice because they centrally manage permissions across all accounts in an AWS Organization by defining maximum allowable permissions. SCPs act as a guardrail, restricting what member accounts can do, even if IAM policies within those accounts grant broader access. This makes SCPs the ideal service for enforcing compliance rules at the organization level.

Exam trap

The trap here is that candidates often confuse AWS Config rules (which detect non-compliance) with SCPs (which enforce compliance), leading them to choose Config instead of SCPs for policy enforcement.

How to eliminate wrong answers

Option B is wrong because AWS Config rules evaluate resource configurations for compliance against desired states, but they do not enforce or prevent actions; they only detect and report non-compliance. Option C is wrong because AWS CloudTrail records API activity for auditing and governance, but it cannot define or enforce policies—it is a logging service. Option D is wrong because IAM policies are attached to users, groups, or roles within a single account and cannot centrally manage permissions across multiple accounts in an AWS Organization.

542
MCQhard

A DevOps engineer creates the CloudFormation template shown in the exhibit. When the stack is created, the EC2 instance is launched but the security group is not applied to the instance. What is the likely cause?

A.The security group resource is missing a VpcId property, so it is not created in the same VPC as the instance.
B.The instance does not have a SecurityGroup or SecurityGroupIds property referencing the security group.
C.The security group is created after the instance, so the instance cannot reference it.
D.The DependsOn clause should be removed because it causes a circular dependency.
AnswerB

The actual flaw is that the instance resource lacks a SecurityGroupIds or SecurityGroups property to reference the security group. DependsOn only ensures the security group is created first; it does not attach the group to the instance. Without an explicit reference in the instance properties, CloudFormation has no way to associate the security group, even though it exists and is available.

Why this answer

The CloudFormation template does not include a `SecurityGroup` or `SecurityGroupIds` property in the EC2 instance's `AWS::EC2::Instance` resource. Without this explicit reference, the instance launches with the default VPC security group, not the custom security group defined in the template. The security group resource is created successfully, but it is not attached to the instance.

Exam trap

The trap here is that candidates assume creating a security group resource in the template automatically applies it to the instance, but CloudFormation requires an explicit attachment via the instance's security group properties.

How to eliminate wrong answers

Option A is wrong because the security group resource (`AWS::EC2::SecurityGroup`) does not require a `VpcId` property if the template is deployed in a default VPC; even if missing, the security group is still created and can be referenced. Option C is wrong because CloudFormation automatically resolves dependencies based on resource references (e.g., `!Ref SecurityGroup`), and the security group is created before the instance if referenced, not after. Option D is wrong because a `DependsOn` clause does not cause a circular dependency here; it simply ensures the security group is created before the instance, which is valid and does not create a loop.

543
MCQhard

A company runs a critical web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application frequently experiences high latency during peak hours. The DevOps team needs to implement a solution that automatically adds capacity based on demand and reduces cost during off-peak hours. Which combination of AWS services should the team use?

A.Use an AWS Auto Scaling group with scheduled scaling policies that add instances during known peak hours and remove them during off-peak hours.
B.Implement Amazon Route 53 weighted routing policies to distribute traffic to multiple ALBs, each fronting a fixed set of EC2 instances.
C.Use an AWS Auto Scaling group with simple scaling policies based on CPU utilization and attach it to the ALB target group.
D.Use an AWS Auto Scaling group with target tracking scaling policies based on the ALB's request count per target, and attach it to the ALB target group.
AnswerD

This configuration uses the ALB's per-target request count as a scaling metric, so Auto Scaling continuously adjusts the EC2 fleet to keep that value near the chosen target. The ALB target group integration ensures newly launched instances are immediately registered to receive traffic, and the policy can scale both out and in based on real observed load. It is designed for variable workloads like critical web apps and responds faster and more accurately than scheduled or simple scaling policies.

Why this answer

Target tracking scaling policies allow the Auto Scaling group to automatically adjust capacity based on a specific metric, such as ALB request count per target, which directly reflects the load on each instance. This ensures that capacity is added during high latency periods and removed during off-peak hours, optimizing both performance and cost. The ALB target group integration ensures that new instances are automatically registered and start receiving traffic.

Exam trap

The trap here is that candidates often choose scheduled scaling (Option A) because it seems straightforward for known peak hours, but they overlook the requirement to handle unpredictable high latency during peak hours, which demands a dynamic, metric-based scaling solution like target tracking.

How to eliminate wrong answers

Option A is wrong because scheduled scaling policies only add or remove instances at predefined times, which cannot react to real-time demand fluctuations or unexpected traffic spikes, leading to either over-provisioning or under-provisioning. Option B is wrong because Route 53 weighted routing policies distribute traffic across multiple ALBs but do not dynamically scale the underlying EC2 instances; each fixed set of instances would still suffer from high latency during peak hours. Option C is wrong because simple scaling policies based on CPU utilization require manual configuration of thresholds and cooldown periods, which can cause slow reaction to sudden load changes and may not directly correlate with application latency as effectively as request count per target.

544
MCQhard

A CodeDeploy deployment group is configured as shown in the exhibit. During a deployment, the deployment fails because the instances are not found. What is the MOST likely reason?

A.The deployment configuration 'CodeDeployDefault.AllAtOnce' is not compatible with in-place deployments
B.The EC2 instances do not have the tag 'Environment' with value 'Production'
C.The service role ARN is incorrect and does not have the necessary permissions
D.The load balancer 'my-alb' is not registered with the instances
AnswerB

The deployment group's Amazon EC2 tag group is configured with key 'Environment' and value 'Production', and CodeDeploy identifies target instances solely by this tag filter. If no running instance carries both the exact key and value, CodeDeploy cannot discover any targets and the deployment fails with a 'No instances found' error before any other step executes. Therefore, the missing tag is the root cause of the failure.

Why this answer

The exhibit shows the deployment group is configured to match EC2 instances with the tag 'Environment' set to 'Production'. If the instances do not have this exact tag key-value pair, CodeDeploy cannot find them during the deployment, causing the failure. The error 'instances are not found' directly points to a tag mismatch, not to permissions or load balancer issues.

Exam trap

The trap here is that candidates often confuse 'instances not found' errors with permission or load balancer issues, but the error is a direct result of tag mismatch, which is the most common cause in CodeDeploy tag-based deployments.

How to eliminate wrong answers

Option A is wrong because 'CodeDeployDefault.AllAtOnce' is a valid deployment configuration that deploys to all instances simultaneously and is fully compatible with in-place deployments; the error is about instances not found, not about configuration incompatibility. Option C is wrong because an incorrect service role ARN or insufficient permissions would typically result in an 'access denied' or 'permission error', not an 'instances not found' error. Option D is wrong because the load balancer 'my-alb' not being registered with instances would cause health check or routing issues, but the deployment would still find the instances; the error specifically states instances are not found, indicating a tag or filter mismatch.

545
MCQhard

A company uses AWS CodeBuild to compile and test code. The buildspec.yaml includes a pre_build phase that runs 'aws ecr get-login-password --region us-east-1 | docker login --username AWS --password-stdin 123456789012.dkr.ecr.us-east-1.amazonaws.com'. The build fails with 'Error: Cannot connect to the Docker daemon'. What is the most likely cause?

A.The CodeBuild project does not have privileged mode enabled.
B.The region specified does not match the ECR repository region.
C.The Docker login command syntax is incorrect.
D.The AWS CLI is not installed in the CodeBuild environment.
AnswerA

In CodeBuild, Docker commands require access to a Docker daemon, but the default build environment runs as an unprivileged container without the necessary kernel capabilities (e.g., CAP_SYS_ADMIN) to start or use Docker. When privileged mode is not enabled, any Docker command such as `docker build` or `docker push` fails with permission errors or 'Cannot connect to the Docker daemon' because the daemon cannot run inside the container. Setting `PRIVILEGED_MODE=true` in the CodeBuild project environment (or via `PrivilegedMode: true` in infrastructure as code) is mandatory for Docker-based builds that need to build and push images to Amazon ECR.

Why this answer

The error 'Cannot connect to the Docker daemon' indicates that the Docker daemon is not running or inaccessible within the CodeBuild build environment. CodeBuild runs Docker commands inside a container that does not have a Docker daemon by default. To execute Docker commands (such as docker login or docker build), the CodeBuild project must be configured with privileged mode enabled, which grants the container elevated permissions to run its own Docker daemon.

Without privileged mode, any attempt to interact with the Docker daemon will fail.

Exam trap

The trap here is that candidates may focus on the AWS CLI or ECR authentication syntax, missing that the fundamental issue is the Docker daemon not being available, which is a CodeBuild-specific configuration requirement for running Docker commands.

How to eliminate wrong answers

Option B is wrong because if the region did not match the ECR repository, the error would be an authentication or repository not found error (e.g., 'Error: Cannot locate repository'), not a Docker daemon connection error. Option C is wrong because the Docker login command syntax is correct: 'aws ecr get-login-password --region us-east-1 | docker login --username AWS --password-stdin 123456789012.dkr.ecr.us-east-1.amazonaws.com' is the standard AWS ECR authentication pattern. Option D is wrong because the AWS CLI is pre-installed in all CodeBuild managed images; if it were missing, the error would be 'aws: command not found', not a Docker daemon error.

546
MCQhard

A company uses AWS CodeCommit for source control and wants to enforce that all commits to the main branch are signed. The DevOps team has configured Git commit signing using GPG keys. However, some developers are able to push unsigned commits to main. What should the engineer do to enforce signed commits?

A.Set the 'requireSignedCommits' parameter in the repository configuration to 'true'.
B.Configure branch protection rules in IAM to deny push access to main unless the commit is signed.
C.Use an AWS CodeCommit trigger with an AWS Lambda function that validates commit signatures and rejects unsigned commits.
D.Create a repository policy that denies git push actions unless the condition 'codecommit:References' and 'codecommit:SourceIp' match.
AnswerC

CodeCommit triggers invoke a Lambda function asynchronously when a reference is updated, and that Lambda can inspect the pushed commit objects using the Git command line or the CodeCommit API to verify GPG signatures. Although the trigger fires after the push is initially accepted, the Lambda can delete or restore the branch reference to its previous commit via the UpdateRef API, effectively rejecting the unsigned commit and preserving repository integrity. This is the practical way to enforce signed commits because CodeCommit itself has no native, built-in signed-commit enforcement.

Why this answer

AWS CodeCommit does not natively support a 'require signed commits' setting like GitHub or GitLab. To enforce signed commits, you must use a CodeCommit trigger that invokes an AWS Lambda function to validate the GPG signature of each commit pushed to the main branch. The Lambda function can parse the commit object, verify the signature using the developer's public key, and reject the push by returning an error if the commit is unsigned or the signature is invalid.

Exam trap

The trap here is that candidates assume AWS CodeCommit has a built-in 'require signed commits' toggle like GitHub or GitLab, but AWS CodeCommit requires a custom serverless solution (Lambda trigger) to enforce this, and the exam tests your ability to recognize when native features are absent.

How to eliminate wrong answers

Option A is wrong because AWS CodeCommit does not have a 'requireSignedCommits' parameter in its repository configuration; this setting exists in GitHub, not in CodeCommit. Option B is wrong because IAM policies cannot inspect the content of a commit (such as whether it is signed) — IAM evaluates permissions based on the action and resource, not the commit payload. Option D is wrong because a repository policy with 'codecommit:References' and 'codecommit:SourceIp' conditions can restrict pushes based on branch reference or source IP address, but it cannot validate commit signatures.

547
MCQeasy

A development team wants to ensure that their application can continue serving traffic even if an entire AWS Availability Zone (AZ) becomes unavailable. The application runs on Amazon EC2 instances in an Auto Scaling group and uses an Application Load Balancer (ALB). Which configuration should the team implement to meet this requirement?

A.Configure the Auto Scaling group to launch EC2 instances across multiple AZs, and ensure the ALB is enabled for cross-zone load balancing.
B.Use a launch template with multiple instance types to ensure diversity across the fleet.
C.Use a single AZ but configure EC2 Auto Scaling to replace unhealthy instances automatically.
D.Launch all EC2 instances in the same AZ to minimize latency, and configure the Auto Scaling group to maintain a minimum of two instances.
AnswerA

By configuring the Auto Scaling group to span multiple Availability Zones and enabling cross-zone load balancing on the ALB, the application can survive an entire AZ failure. If one AZ becomes unavailable, the ALB routes traffic only to the remaining healthy targets, while the ASG automatically launches replacement instances in the other AZs to maintain capacity. Cross-zone load balancing ensures that traffic is distributed evenly across all instances, even when one AZ has fewer instances. This design provides both redundancy and optimal utilization.

Why this answer

Deploying EC2 instances across multiple Availability Zones (AZs) ensures that if one AZ fails, the remaining AZs continue to serve traffic. Enabling cross-zone load balancing on the ALB distributes incoming requests evenly across all healthy instances in all AZs, preventing traffic from being sent only to instances in the same AZ as the client. This architecture meets the requirement for high availability and fault tolerance at the AZ level.

Exam trap

The trap here is that candidates often confuse instance-level resilience (e.g., replacing unhealthy instances) with AZ-level resilience, or they think that multiple instances in a single AZ provide sufficient fault tolerance, ignoring the fact that an AZ failure takes down all instances in that AZ.

How to eliminate wrong answers

Option B is wrong because using multiple instance types in a launch template addresses instance diversity and spot instance interruption resilience, not AZ-level failure; it does not protect against an entire AZ becoming unavailable. Option C is wrong because using a single AZ means all instances are in one failure domain; even with automatic replacement, the application cannot serve traffic if that AZ fails, as the new instances would also be launched in the same unavailable AZ. Option D is wrong because launching all instances in the same AZ and maintaining a minimum of two instances does not provide AZ-level redundancy; if that AZ fails, all instances become unavailable, and the application cannot serve traffic.

548
MCQeasy

A DevOps engineer receives a CloudWatch alarm that the 'StatusCheckFailed' metric for an EC2 instance is in ALARM state. The instance is part of an Auto Scaling group. What should the engineer do first to restore service?

A.Update the Auto Scaling group's launch configuration
B.Wait for Auto Scaling to replace the instance
C.Manually terminate the instance
D.Reboot the instance
AnswerB

Auto Scaling is configured to use EC2 status checks for health, so it will detect the instance's failed status check and automatically terminate it, launching a new instance with the same launch configuration to maintain desired capacity. Waiting is the correct action because the replacement process is fully automated and requires no manual intervention. The new instance will be created once the unhealthy instance is marked as unhealthy, typically within a few minutes.

Why this answer

The Auto Scaling group automatically replaces unhealthy instances based on EC2 status checks. Options A, C, and D are incorrect: Updating the launch configuration does not fix existing instances; manually terminating is unnecessary as Auto Scaling handles it; and rebooting may not resolve underlying issues.

549
MCQeasy

A DevOps engineer is designing a resilient architecture for a serverless application using AWS Lambda, Amazon API Gateway, and Amazon DynamoDB. The application experiences occasional spikes in traffic that cause Lambda function throttling and increased error rates. What is the MOST effective way to improve resilience and reduce throttling?

A.Increase the Lambda function memory to the maximum allowed.
B.Enable DynamoDB auto scaling for the table to handle traffic spikes.
C.Set API Gateway throttling limits to match the expected peak traffic.
D.Reserve concurrency for the Lambda function to ensure it always has available capacity.
AnswerD

Reserved concurrency sets a hard upper limit on the number of simultaneous executions for a specific function and, more importantly, guarantees that this amount of capacity is reserved exclusively for that function from the account's total concurrency pool. This prevents other functions from exhausting the shared pool and ensures the critical function can always handle its peak load without being throttled. It also makes the function's behavior predictable during traffic spikes, because the reserved capacity is always available for that function's invocations.

Why this answer

The stem specifies that traffic spikes cause Lambda function throttling. Reserving concurrency for the Lambda function (Option D) guarantees a dedicated portion of the account-level concurrency limit, preventing other functions from exhausting capacity and directly mitigating throttling. Option B (DynamoDB auto scaling) would only help if the throttling were caused by DynamoDB capacity issues, but the stem makes no mention of database errors.

Option A (increasing memory) does not address concurrency limits, and Option C (API Gateway throttling) can limit incoming requests but does not guarantee that Lambda has capacity to process them.

Exam trap

The trap is to assume that downstream services like DynamoDB are the bottleneck causing Lambda throttling. However, the stem clearly states that traffic spikes directly cause Lambda throttling, indicating that the concurrency limit is the primary constraint.

How to eliminate wrong answers

Option A is wrong because increasing Lambda memory also increases CPU and network allocation, but it does not resolve throttling caused by DynamoDB capacity limits or Lambda concurrency limits; it only improves execution speed for compute-bound functions. Option C is wrong because setting API Gateway throttling limits to match expected peak traffic would cap requests at that level, rejecting legitimate traffic during spikes rather than improving resilience. Option D is wrong because reserving concurrency for the Lambda function guarantees a fixed number of concurrent executions, but if the DynamoDB table lacks sufficient capacity, those executions will still fail due to database throttling, and reserved concurrency can also waste capacity during low traffic.

550
MCQmedium

A DevOps engineer is troubleshooting an application that runs on Amazon EC2 instances behind an Application Load Balancer. Users report intermittent 503 errors. CloudWatch metrics for the ALB show an increase in 'HTTPCode_ELB_5XX_Count' but the backend 'HealthyHostCount' remains stable. Which action should the engineer take to identify the root cause?

A.Increase the size of the EC2 instances to handle more requests.
B.Enable detailed CloudWatch metrics on the EC2 instances to monitor CPU and memory.
C.Enable and review the ALB access logs stored in Amazon S3 to analyze the HTTP response codes and request patterns.
D.Increase the idle timeout setting on the ALB.
AnswerC

Enabling ALB access logs and storing them in Amazon S3 records every request with fields such as elb_status_code, target_status_code, request_processing_time, target_processing_time, and response_processing_time, as well as the exact request path and user agent. By querying these logs, you can identify the specific HTTP response codes (including the 503s), observe patterns by path or client, and determine whether the timeouts occur in the load balancer or at the target. This is the definitive diagnostic step to isolate the cause of intermittent 503s.

Why this answer

ALB access logs capture detailed information about each request, including HTTP status codes, request processing times, and target response times. By analyzing these logs in Amazon S3, the engineer can identify which specific requests are resulting in 503 errors, examine if there are patterns such as high latency or target unavailability, and determine the root cause. Option A is incorrect because increasing instance size does not address the intermittent 503 errors; if the instances are healthy (HealthyHostCount stable), the issue is likely not capacity but something else like configuration or request handling.

Option B is incorrect because detailed CloudWatch metrics on instances, while useful for performance, would not directly reveal why the ALB is returning 503 errors; the backend might be healthy but returning errors or timing out. Option D is incorrect because increasing the idle timeout would only help if requests are being dropped due to idle connections, but 503 errors typically indicate that the targets are not responding or are returning errors, not idle timeouts.

551
MCQeasy

A DevOps team wants to run unit tests in parallel across multiple build environments using AWS CodeBuild. Which build specification configuration allows this?

A.Use multiple build phases in the buildspec file.
B.Configure multiple artifacts in the buildspec.
C.Define a batch build with multiple builds.
D.Set environment variables to run multiple commands concurrently.
AnswerC

A batch build lets you define multiple builds that CodeBuild schedules on separate compute environments, running them concurrently up to the configured max batch size or parallelization limit. Each build in the batch can have its own buildspec override, environment variables, or input source, making it ideal for sharding unit tests across workers. This is the intended AWS mechanism for executing independent unit tests in parallel.

Why this answer

AWS CodeBuild supports batch builds, which allow you to define a build project that runs multiple builds in parallel. By specifying a batch configuration in your buildspec file (using the `batch` section), you can run unit tests across multiple build environments simultaneously, improving test execution speed and resource utilization.

Exam trap

The trap here is that candidates confuse sequential build phases with parallel execution, or assume that environment variables or multiple artifacts can achieve parallelism, when only the batch build feature in CodeBuild provides true parallel builds across multiple environments.

How to eliminate wrong answers

Option A is wrong because multiple build phases (e.g., install, pre_build, build, post_build) run sequentially within a single build, not in parallel across multiple environments. Option B is wrong because configuring multiple artifacts in the buildspec defines output files from a single build, not parallel execution across environments. Option D is wrong because setting environment variables to run multiple commands concurrently does not enable parallel builds across separate environments; it only runs commands sequentially within the same build container.

552
Multi-Selectmedium

A company uses AWS Elastic Beanstalk to manage its web application. The DevOps team wants to customize the Amazon EC2 instances launched by Elastic Beanstalk. Which two methods can they use to achieve this? (Choose TWO.)

Select 2 answers
A.Use .ebextensions configuration files in the application source bundle to install packages and run commands.
B.Use AWS OpsWorks to manage the instances instead of Elastic Beanstalk.
C.Create a custom AMI and specify it in the Elastic Beanstalk environment configuration.
D.Add user data to the Auto Scaling group launch configuration that Elastic Beanstalk creates.
E.Modify the CloudFormation template generated by Elastic Beanstalk directly.
AnswersA, C

Elastic Beanstalk automatically processes the .ebextensions directory inside your source bundle, passing any .config files (YAML/JSON) to the CreateStack operation as AWS::CloudFormation::Init metadata. The packages key lets you specify packages like yum, rpm, or gem, while the commands and container_commands keys execute shell commands at specific points in the deployment lifecycle. Because these run on every instance before the application is deployed, they give you a supported, idempotent way to install dependencies and tweak configuration without managing your own AMI. This is the most portable and preferred method for most customizations.

Why this answer

`.ebextensions` configuration files allow you to customize the EC2 instances launched by Elastic Beanstalk by installing packages, running commands, and configuring services during instance provisioning. These YAML or JSON files are placed in the `.ebextensions` folder of your application source bundle and are executed by the Elastic Beanstalk platform as part of the instance initialization process, providing a native and supported customization mechanism.

Exam trap

The trap here is that candidates often think they can directly modify the Auto Scaling group's launch configuration or the CloudFormation template, but Elastic Beanstalk treats these as managed resources and will revert any manual changes, making `.ebextensions` and custom AMIs the only supported customization methods.

553
Multi-Selectmedium

A company uses AWS CodePipeline for CI/CD. A recent pipeline execution failed at the 'Deploy' stage with the error 'Action execution failed: Access Denied'. The pipeline uses an IAM service role. Which THREE checks should the engineer perform to resolve this?

Select 3 answers
A.Check that CloudWatch Events rule is configured to trigger the pipeline.
B.Verify that the IAM service role has sufficient permissions to perform the deploy action on the target resource.
C.Ensure the artifact store S3 bucket has a bucket policy that allows the pipeline role to access it.
D.Enable S3 event notifications to trigger the pipeline on code changes.
E.Confirm that the service role's trust policy allows CodePipeline to assume the role.
AnswersB, C, E

CodePipeline executes deploy actions by assuming a dedicated IAM service role, and that role must contain an identity-based policy granting the required API permissions (e.g., codedeploy:CreateDeployment, ecs:UpdateService, or cloudformation:CreateStack) on the target resource. If a required permission is missing or explicitly denied, the deploy stage fails with an AccessDenied error even though every other pipeline configuration is correct. You should review the pipeline execution details to identify the specific denied action, then attach an appropriate managed or inline policy to the service role.

Why this answer

The 'Access Denied' error at the Deploy stage indicates a permissions issue. The correct checks are: B) Verify that the IAM service role has sufficient permissions for the deploy action on the target resource, as the role must have the necessary IAM policies to perform deployments. C) Ensure the artifact store S3 bucket has a bucket policy that allows the pipeline role to access it, because the pipeline needs to read artifacts from the bucket.

E) Confirm that the service role's trust policy allows CodePipeline to assume the role, since the trust policy must grant the `sts:AssumeRole` permission to the CodePipeline service. Option A is incorrect because CloudWatch Events rules trigger pipeline execution but are not related to the deploy stage's access denied error. Option D is incorrect because S3 event notifications trigger the pipeline on code changes, not resolve deployment failures.

554
MCQmedium

A DevOps engineer is troubleshooting a failed CodeBuild project. The build fails with an error: 'Access Denied: Unable to put object to S3.' The build project has an S3 bucket as the artifact store. What should the engineer do to resolve this issue?

A.Add s3:PutObject permission to the CodeBuild service role for the artifact bucket.
B.Enable server-side encryption on the artifact bucket.
C.Enable CloudWatch Logs for the build project.
D.Add s3:GetObject permission to the CodeBuild service role for the source bucket.
AnswerA

The CodeBuild service role is an IAM role that grants the build project permission to call AWS APIs. When CodeBuild uploads build artifacts to an S3 bucket, it must have the s3:PutObject action allowed on that artifact bucket. The failure occurs at the upload step because the role currently lacks write access; adding s3:PutObject to the role's policy for the artifact bucket's ARN resolves the AccessDenied error.

Why this answer

The error 'Access Denied: Unable to put object to S3' indicates the CodeBuild service role lacks s3:PutObject permission on the artifact bucket. CodeBuild assumes this role to upload build artifacts, so the fix is to attach an IAM policy granting s3:PutObject (and typically s3:GetBucketLocation, s3:ListBucket) for the artifact bucket to the CodeBuild service role.

Exam trap

DOP-C02 often tests the distinction between source bucket permissions (GetObject) and artifact bucket permissions (PutObject) — candidates confuse the two and apply the wrong S3 action.

How to eliminate wrong answers

Option B is wrong because enabling server-side encryption on the bucket does not grant write permissions — encryption is orthogonal to authorization, and the error is explicitly an access-denied issue. Option C is wrong because enabling CloudWatch Logs only improves logging visibility; it does not fix the underlying permission gap. Option D is wrong because s3:GetObject on the source bucket is for reading source code, not for writing artifacts — the error is about putting objects to the artifact store, not getting source objects.

555
MCQhard

A company uses Terraform to manage a multi-account AWS environment. The Terraform state files are stored in an S3 bucket with DynamoDB locking. Recently, a DevOps engineer ran 'terraform apply' from a CI/CD pipeline, and it failed with the error: 'Error acquiring the state lock. Lock ID: "abc123". Possible causes: Another process has the lock; or a previous process crashed.' The engineer checks DynamoDB and sees that the lock item exists but there is no active Terraform process. The engineer needs to proceed with the deployment urgently. What should the engineer do?

A.Use the 'terraform force-unlock' command with the lock ID to remove the lock.
B.Wait for the lock to expire automatically.
C.Delete the state file from S3 and recreate it from the last backup.
D.Manually delete the lock item from DynamoDB using the AWS Console.
AnswerA

Terraform's `force-unlock` command is the sanctioned recovery mechanism for a stale lock. Run `terraform force-unlock <LOCK_ID>` from the CLI using the lock ID printed in the error message (or found in the DynamoDB `LockID` item); this removes the lock item via a properly logged API call. It is safe only when you confirm no other `terraform` process is actively applying or planning against that state, because it overrides mutual exclusion.

Why this answer

The correct action is to use 'terraform force-unlock' with the lock ID to remove the stale lock. This command is specifically designed to safely release a lock when no active Terraform process holds it, allowing the deployment to proceed. It ensures the lock is removed in a controlled manner, preserving state integrity.

Exam trap

DOP-C02 often tests whether candidates know the safe, Terraform-native way to clear a stale lock versus dangerous manual deletion or state manipulation.

How to eliminate wrong answers

Option B is wrong because DynamoDB locks used by Terraform do not expire automatically; they persist until manually released or force-unlocked. Option C is wrong because deleting the state file would destroy the record of existing infrastructure, causing Terraform to lose track of resources and potentially recreate or orphan them. Option D is wrong because manually deleting the lock item from DynamoDB bypasses Terraform's lock management and can lead to race conditions or state corruption if another process is actually running.

556
MCQhard

A company runs an Auto Scaling group of EC2 instances that publish custom application metrics to CloudWatch using the PutMetricData API. During a traffic spike, the operations team reports that alarms based on these metrics did not trigger even though application error rates rose sharply. The metrics are published with a one-minute resolution. Which action should a DevOps engineer take to make the alarms respond reliably during spikes?

A.Change the alarm statistic to SampleCount and set the period to 60 seconds.
B.Configure the alarm to treat missing data as breaching and shorten the evaluation period.
C.Publish the custom metrics as high-resolution metrics and configure the alarm with a shorter evaluation period and M-out-of-N datapoints to alarm.
D.Increase the alarm's evaluation period to five minutes so more data points are averaged together.
AnswerC

High-resolution metrics allow one-second granularity, and combining a short evaluation period with M-out-of-N datapoints to alarm makes the alarm evaluate recent error data quickly. This directly addresses the delay and sparsity of custom metrics during rapid spikes, improving alarm responsiveness.

Why this answer

Custom metrics published at standard one-minute resolution can lag behind a fast spike, and a long evaluation window dilutes the signal. Publishing high-resolution metrics and configuring the alarm with a short evaluation period plus M-out-of-N datapoints to alarm lets the alarm react quickly to a genuine error-rate increase.

Exam trap

The trap here is responding to a missed alarm by widening the evaluation period, when that averaging actually makes the spike harder to detect.

557
MCQeasy

A DevOps engineer receives an alarm that an EC2 instance's CPU utilization has exceeded 90% for 5 minutes. The engineer needs to automatically recover the instance. Which AWS service should be used to configure automatic recovery?

A.Amazon CloudWatch Alarms
B.AWS Lambda
C.AWS Systems Manager Automation
D.EC2 Auto Scaling
AnswerA

Amazon CloudWatch Alarms are the native mechanism for EC2 AutoRecovery. By configuring an alarm on the System Status Check metric (StatusCheckFailed_System) with the 'recover' action, you let EC2 automatically restart the instance on new hardware while preserving its instance ID, private IP, Elastic IP, and instance store data. This is the direct, built-in solution that requires no custom code or additional orchestration.

Why this answer

Amazon CloudWatch Alarms can be configured to trigger an EC2 instance recovery action when a metric like CPU utilization exceeds a threshold (e.g., 90% for 5 minutes). The alarm sends a signal to the EC2 service, which automatically recovers the instance by stopping it and starting it on a new underlying host, preserving the instance ID, private IP, and Elastic IP. This is the native, built-in mechanism for automatic instance recovery without requiring additional compute or orchestration services.

Exam trap

The trap here is that candidates often confuse EC2 Auto Scaling (which replaces instances) with automatic recovery (which recovers the same instance), or they overcomplicate the solution by choosing Lambda or Systems Manager when a simple CloudWatch Alarm action is the correct and native AWS mechanism.

How to eliminate wrong answers

Option B is wrong because AWS Lambda is a serverless compute service that can execute custom code in response to events, but it is not the direct service used to configure automatic EC2 instance recovery; while Lambda could be used to script a recovery, it adds unnecessary complexity and latency compared to the native CloudWatch Alarm recovery action. Option C is wrong because AWS Systems Manager Automation provides runbooks for automated remediation and operational tasks, but it is not the primary service for configuring automatic EC2 instance recovery; it would require additional setup and is not the simplest or recommended approach. Option D is wrong because EC2 Auto Scaling is designed to manage the number of instances in an Auto Scaling group based on scaling policies, not to recover a specific impaired instance; it would terminate and replace the instance rather than recover it, which changes the instance ID and associated resources.

558
MCQmedium

A DevOps engineer is creating a CodePipeline service role. The above IAM policy is attached to the role. The pipeline fails when trying to download artifacts from the S3 bucket. What is the issue?

A.The Resource for S3 actions should be the bucket ARN, not the object ARN.
B.The policy is missing s3:ListBucket permission on the bucket.
C.The CodeDeploy actions require a specific resource ARN instead of '*'.
D.The Action list is missing s3:GetObjectVersion.
AnswerB

The policy is missing s3:ListBucket permission on the bucket. CodePipeline requires the ability to list the contents of the S3 artifact bucket in order to enumerate source objects, determine which artifacts are present, and trigger the pipeline correctly. s3:ListBucket is a bucket-level action, so its Resource must be the bucket ARN (arn:aws:s3:::bucket-name), not the object ARN. Without this permission, the pipeline will fail during the source stage with an access denied error, even though GetObject is present, because the service cannot discover which objects to fetch.

Why this answer

The pipeline fails because the IAM policy grants s3:GetObject on the object ARN but lacks s3:ListBucket on the bucket ARN. CodePipeline's S3 artifact download action first calls ListBucket to verify the bucket exists and the object key is accessible before performing the GetObject call. Without s3:ListBucket, the initial validation fails, causing the pipeline to error out even though GetObject is allowed.

Exam trap

The trap here is that candidates assume only s3:GetObject is needed for downloading artifacts, overlooking that CodePipeline's S3 action internally requires s3:ListBucket to resolve the object location before retrieval.

How to eliminate wrong answers

Option A is wrong because the Resource for S3 actions should be the object ARN (arn:aws:s3:::bucket-name/*) for GetObject, not the bucket ARN; using the bucket ARN would incorrectly grant access to the bucket itself rather than the objects. Option C is wrong because CodeDeploy actions can use '*' as the Resource ARN when the policy is attached to a service role that is scoped to a specific deployment group or application via the pipeline's configuration, and the issue here is S3 permissions, not CodeDeploy. Option D is wrong because s3:GetObjectVersion is only needed when retrieving a specific version of an object (e.g., versioned buckets), and the question does not indicate versioning is enabled; the missing permission is s3:ListBucket, not GetObjectVersion.

559
MCQeasy

A developer wants to provision AWS resources using AWS Cloud Development Kit (CDK) and ensure that the infrastructure can be version-controlled and reviewed. Which practice should they follow?

A.Write the CDK app and deploy directly without synthesis to avoid extra steps.
B.Write the CDK app to generate Terraform configurations and store them in Git.
C.Write raw CloudFormation templates instead of CDK to simplify version control.
D.Write the CDK app in TypeScript, store it in a Git repository, and use CDK pipelines for deployment.
AnswerD

Storing an ordinary TypeScript CDK project in Git and using the `cdk pipelines` construct creates a self-mutating CI/CD pipeline that automatically builds, synthesizes, and deploys the app to one or more AWS environments. This approach lets you version the CDK source, review pull requests, run unit tests, and retain the full CloudFormation deployment model underneath. It is the recommended production pattern because pipeline updates are also managed through the same CDK code, giving you repeatable and auditable infrastructure delivery.

Why this answer

It follows the recommended practice of treating CDK application code as infrastructure source code, storing it in a version control system (Git), and using CDK Pipelines (a high-level construct that automatically synthesizes and deploys CloudFormation templates) to ensure repeatable, reviewed deployments. This approach enables infrastructure-as-code best practices: version history, peer review via pull requests, and automated deployment pipelines.

Exam trap

The trap here is that candidates may think CDK requires manual synthesis or that it can output Terraform, but the exam tests that CDK is a CloudFormation-only IaC tool that must be synthesized and version-controlled as code, not as raw templates.

How to eliminate wrong answers

Option A is wrong because deploying directly without synthesis bypasses the generation of CloudFormation templates, which are the deployable artifacts; CDK synthesis is a required step to produce the CloudFormation templates that AWS CloudFormation consumes, and skipping it would prevent deployment. Option B is wrong because CDK does not generate Terraform configurations; CDK synthesizes CloudFormation templates, not Terraform HCL, and mixing tools would introduce unnecessary complexity and break the native integration with AWS. Option C is wrong because writing raw CloudFormation templates instead of CDK would lose the benefits of CDK's higher-level abstractions, programming language features (e.g., loops, conditionals), and construct reuse, while version control is equally possible with CDK code; the question specifically asks about using CDK, so this option contradicts the premise.

560
Multi-Selectmedium

A company is designing an incident response strategy for its Amazon EKS cluster. Which THREE steps should be taken to ensure rapid response to a compromised pod?

Select 3 answers
A.Delete the entire namespace to ensure all resources are removed.
B.Scale down the deployment to 0 replicas.
C.Delete the pod using kubectl delete pod.
D.Use kubectl exec to gather forensic data from the pod before termination.
E.Apply a Kubernetes NetworkPolicy to deny all ingress/egress traffic to the compromised pod.
AnswersC, D, E

Deleting the pod with `kubectl delete pod <name>` immediately sends a termination signal (SIGTERM) to the container, and after the grace period, a SIGKILL, removing the pod from the cluster and stopping the malicious process. This is the primary containment step to halt active compromise; however, if the pod is managed by a ReplicaSet or Deployment, the controller will replace it, so you must also update the workload definition or scale down to prevent recreation. It is a precise operation that affects only the compromised instance.

Why this answer

Deleting the pod with `kubectl delete pod` immediately terminates the compromised container, stopping any malicious activity. This is a rapid containment step that removes the pod from the cluster without affecting the broader deployment or namespace, allowing the incident response team to investigate and remediate without unnecessary disruption.

Exam trap

The trap here is that candidates may think scaling down the deployment (Option B) is the fastest containment action, but it actually triggers a reconciliation loop that can recreate the pod or delay termination, whereas `kubectl delete pod` is the most direct and immediate way to stop a compromised container.

561
MCQmedium

A company uses AWS CodeCommit as a Git repository and CodeBuild for continuous integration. The buildspec.yml file includes steps to run unit tests and package the application. The team wants to ensure that only code from the main branch is deployed to production. They have set up a CodePipeline that triggers on changes to any branch. The pipeline includes a build stage that runs CodeBuild, and then a deploy stage that deploys to production. The team noticed that code from feature branches is being deployed to production accidentally. The team wants to modify the pipeline to prevent this. What is the MOST effective solution?

A.Use IAM policies to restrict developers from pushing to the main branch.
B.In the CodePipeline source stage, configure the branch filter to only allow the main branch to trigger the pipeline.
C.Add a manual approval step before the deploy stage and require approval from a senior engineer.
D.Modify the CodeBuild project to only build the main branch by specifying the branch in the source configuration.
AnswerB

Configure the CodeCommit source action in the pipeline to specify 'main' as the Branch name; CodePipeline then only initiates an execution when a new commit is pushed to that exact branch. This branch filter is applied at the source stage before any build or deploy action runs, preventing resource consumption for non-main branches. It is the standard, supported mechanism for branch-scoped pipeline behavior in CodePipeline.

Why this answer

The most effective fix is to configure the CodePipeline source stage with a branch filter that only allows the main branch to trigger the pipeline. This prevents feature-branch commits from ever entering the pipeline, stopping the accidental production deployment at the source rather than downstream.

Exam trap

DOP-C02 often tests the confusion between fixing a problem at the source stage versus adding downstream gates — candidates pick manual approval or IAM restrictions when the cleanest fix is the pipeline source branch filter.

How to eliminate wrong answers

Option A is wrong because restricting developers from pushing to main does not prevent feature-branch code from triggering the pipeline — it addresses a different problem and doesn't stop the accidental deployment. Option C is wrong because a manual approval step adds a human gate but still allows feature-branch code to reach the deploy stage pending approval, which is not the most effective prevention. Option D is wrong because modifying the CodeBuild project's source configuration is a build-level workaround; the pipeline source stage is the correct control point, and CodeBuild branch filtering is less reliable than pipeline-level filtering.

562
MCQeasy

A DevOps team is designing a disaster recovery plan for an RDS MySQL database. The database must be recoverable with minimal data loss in case of a regional failure. Which solution provides the LOWEST Recovery Point Objective (RPO)?

A.Configure a Cross-Region Read Replica.
B.Take daily automated snapshots and copy them to another Region.
C.Use a Multi-AZ deployment with synchronous standby.
D.Use RDS Proxy to cache database writes.
AnswerA

A Cross-Region Read Replica uses Amazon RDS's asynchronous replication to continuously apply transactions from the primary DB instance to a replica in a different AWS Region. This typically achieves an RPO in the low seconds (usually 1–5 seconds) and a short RTO by promoting the replica to a standalone primary via the console or API. Because replication is ongoing, it minimizes data loss far more effectively than any interval-based snapshot strategy.

Why this answer

A Cross-Region Read Replica provides the lowest Recovery Point Objective (RPO) because it uses asynchronous replication to continuously replicate data changes from the primary region to a replica in another region. In the event of a regional failure, you can promote the replica to a standalone primary database, typically losing only a few seconds to minutes of data, depending on replication lag. This minimizes data loss compared to snapshot-based or batch replication methods.

Exam trap

The trap here is that candidates often confuse Multi-AZ deployments (which provide high availability within a region with zero RPO) with cross-region disaster recovery, mistakenly thinking synchronous replication across regions is possible, but AWS RDS does not support synchronous replication across regions, and Multi-AZ does not protect against regional outages.

How to eliminate wrong answers

Option B is wrong because daily automated snapshots have an RPO of up to 24 hours, as they are taken only once per day, and copying them to another region adds additional latency, resulting in significantly higher potential data loss. Option C is wrong because a Multi-AZ deployment with synchronous standby provides high availability within a single region but does not protect against a regional failure; it offers zero RPO within the region but cannot recover data if the entire region goes down. Option D is wrong because RDS Proxy caches database writes to improve connection pooling and reduce failover time, but it does not replicate data to another region or provide any disaster recovery capability; it does not reduce RPO for regional failures.

563
MCQeasy

A development team uses AWS CodeBuild to run unit tests on every commit to the develop branch. The tests take a long time because they download dependencies each time. What should the team do to reduce build time?

A.Enable the local cache feature in CodeBuild.
B.Store dependencies in Amazon Elastic File System (EFS) and mount it during builds.
C.Increase the compute type of the build environment.
D.Use multiple builds in parallel for the same commit.
AnswerA

Enabling the local cache feature in CodeBuild stores resolved dependencies (e.g., Maven, pip, npm packages) in a local directory or an S3-backed bucket between builds. On subsequent builds, CodeBuild restores this cache instantly, eliminating the need to re-download and re-resolve packages. This directly reduces the network I/O bottleneck that dominates unit-test build time, especially for frequently executed builds, and is the correct way to speed up dependency-heavy pipelines.

Why this answer

Enabling the local cache feature in CodeBuild allows the build environment to cache dependencies, such as Maven or npm packages, in a local directory that persists across builds. This avoids re-downloading unchanged dependencies on every commit, significantly reducing build time. The cache can be stored in an S3 bucket or locally on the build instance, and is automatically restored at the start of each build.

Exam trap

The trap here is that candidates often confuse caching with storage solutions like EFS or with scaling compute resources, failing to recognize that the core issue is repetitive network-bound dependency downloads, which only a cache mechanism can mitigate.

How to eliminate wrong answers

Option B is wrong because mounting an Amazon EFS filesystem adds network latency and does not inherently cache dependencies; it would still require downloading dependencies to the EFS volume initially, and the mount overhead can increase build time. Option C is wrong because increasing the compute type (e.g., more vCPUs or memory) does not reduce the time spent downloading dependencies; it only speeds up CPU-bound or memory-bound tasks, not network I/O. Option D is wrong because running multiple builds in parallel for the same commit does not reduce the time for a single build; it would run redundant tests and waste resources without addressing the dependency download bottleneck.

564
Multi-Selectmedium

A company runs a critical application on EC2 instances behind an Application Load Balancer (ALB) in an Auto Scaling group. The team wants to automate the response to an instance failure. Which THREE steps should be taken to ensure automatic recovery and notification?

Select 3 answers
A.Create a CloudWatch alarm to terminate the instance
B.Configure Auto Scaling to replace unhealthy instances
C.Configure the ALB health check to mark instances as unhealthy
D.Set up Amazon SNS notifications for Auto Scaling events
E.Create a scaling policy based on CPU utilization
AnswersB, C, D

Auto Scaling can be configured with an appropriate health check type (EC2 status checks or ELB/ALB health checks) and a termination policy to automatically detect and replace unhealthy instances. This ensures that the ASG maintains the desired instance count by terminating the unhealthy instance and launching a new one, providing a self-healing architecture for the critical application.

Why this answer

Configuring the Auto Scaling group to replace unhealthy instances ensures that when an instance fails health checks, Auto Scaling automatically terminates it and launches a new instance to maintain the desired capacity. This is the core mechanism for automated recovery in an Auto Scaling group, as it directly responds to instance failure without manual intervention.

Exam trap

The trap here is that candidates often confuse CloudWatch alarms (Option A) for instance recovery, but CloudWatch alarms are for monitoring and triggering actions like scaling policies or SNS notifications, not for directly replacing failed instances in an Auto Scaling group.

565
MCQhard

A Lambda function is unable to write logs to CloudWatch Logs. The IAM policy attached to the function's execution role is shown above. What is the issue?

A.The resource ARN is incorrect; it should include the log stream name.
B.The region in the ARN does not match the Lambda function's region.
C.The action should be 'logs:PutLogEvents' but the resource is too restrictive.
D.The policy is missing the 'logs:CreateLogGroup' and 'logs:CreateLogStream' actions.
AnswerD

Lambda's execution role needs `logs:CreateLogGroup` and `logs:CreateLogStream` before `logs:PutLogEvents` can succeed, since the log group and stream must exist first. Without these actions, the function cannot create its destination, so writes fail regardless of the PutLogEvents permission. This satisfies the stem's requirement for the missing write-enabling actions.

Why this answer

The IAM policy attached to the Lambda execution role is missing the logs:CreateLogGroup and logs:CreateLogStream actions. Without these, Lambda cannot create the log group or log stream, and thus cannot write logs to CloudWatch Logs. The logs:PutLogEvents action alone is insufficient because the log group and stream must exist first.

Exam trap

The trap is focusing on the logs:PutLogEvents action and its resource ARN, while overlooking the prerequisite actions needed to create the log group and stream.

How to eliminate wrong answers

Option A is wrong because the resource ARN for logs:PutLogEvents typically includes the log group and log stream, but the issue is not the ARN format; it's the missing actions. Option B is wrong because the region in the ARN is likely correct; the problem is not a region mismatch. Option C is wrong because while logs:PutLogEvents is necessary, the resource being too restrictive is not the primary issue; the missing CreateLogGroup and CreateLogStream actions prevent any logging.

566
MCQeasy

A DevOps engineer needs to allow an AWS Lambda function to write logs to Amazon CloudWatch Logs. What should the engineer do?

A.Attach an IAM role to the Lambda function's instance profile.
B.Attach an IAM policy to the Lambda execution role that allows logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents.
C.Generate an access key for the Lambda function and configure the function to use it.
D.Create a resource-based policy on the CloudWatch Logs log group that allows the Lambda function to write.
AnswerB

The execution role is the IAM identity that the Lambda service assumes on the function's behalf, and you must attach an identity-based policy with logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents. Without these actions, CloudWatch Logs will reject the function's log writes, causing request failures and missing log streams. This is the standard, least-privilege pattern for granting Lambda access to CloudWatch Logs in the same account.

Why this answer

Lambda functions assume an IAM execution role, and permissions to write to CloudWatch Logs must be granted via an IAM policy attached to that role. The policy needs logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents to allow the function to create the log group (if absent), create a log stream, and put log events. This is the standard, least-privilege way to grant Lambda logging permissions.

Exam trap

DOP-C02 often tests the misconception that Lambda uses instance profiles like EC2, or that resource-based policies on log groups can grant write access — both are wrong; permissions must come from the execution role.

How to eliminate wrong answers

Option A is wrong because Lambda does not use EC2 instance profiles — instance profiles are an EC2 construct for attaching roles to instances, not functions. Option C is wrong because embedding long-term access keys in a Lambda function is an anti-pattern that violates AWS security best practices and rotation requirements. Option D is wrong because CloudWatch Logs log groups do not support resource-based policies that grant write access to Lambda; access must come from the caller's identity-based policy on the execution role.

567
MCQmedium

A company runs a high-traffic e-commerce application on EC2 instances in an Auto Scaling group behind an ALB. The application uses an in-memory cache on the EC2 instances. During a recent deployment, the Auto Scaling group terminated an instance that had active user sessions, causing users to lose their cart data and leading to a poor customer experience. The company wants to prevent this in future deployments. They need a solution that allows existing sessions to complete before instance termination, without manual intervention. Which solution should they use?

A.Increase the Auto Scaling group's cooldown period and health check grace period.
B.Enable connection draining on the ALB target group and increase the deregistration delay.
C.Implement an Auto Scaling lifecycle hook that puts the instance in a 'terminating:wait' state, and have a script on the instance that signals completion after draining sessions.
D.Change the health check type to ELB and mark instances unhealthy before deployment.
AnswerC

A lifecycle hook pauses the Auto Scaling termination process by moving the instance into the 'terminating:wait' state, giving you a configurable period to perform custom actions before the instance is finally terminated. An in-instance script or agent can monitor and gracefully drain active user sessions, commit any required state, and then call complete-lifecycle-action with the appropriate lifecycle hook token to signal that termination may proceed. This is the only option that actually holds the termination process itself and coordinates with application-level work rather than merely affecting network connections or scaling timers.

Why this answer

An Auto Scaling lifecycle hook puts the instance into a 'terminating:wait' state when the ASG decides to terminate it, pausing the termination process. A script on the instance can then drain active sessions (e.g., finish processing requests, flush cart data to a persistent store) and call CompleteLifecycleAction to signal completion, after which the ASG proceeds with termination. This is the only option that provides a programmable, instance-level mechanism to gracefully complete sessions before termination without manual intervention.

Exam trap

DOP-C02 often tests the misconception that ALB connection draining alone handles graceful instance termination — candidates forget that connection draining only covers in-flight requests, not in-memory application state or session persistence.

How to eliminate wrong answers

Option A is wrong because cooldown periods and health check grace periods control scaling timing and health check behavior, not graceful session draining during termination — they do not pause termination to let sessions finish. Option B is wrong because ALB connection draining (deregistration delay) only handles in-flight HTTP requests at the load balancer level; it does not address in-memory session state on the instance or allow the application to persist cart data before the instance is terminated. Option D is wrong because changing health check type to ELB and manually marking instances unhealthy is a manual, error-prone process that does not provide a programmable completion signal and does not guarantee session draining.

568
MCQmedium

A DevOps engineer needs to monitor the number of messages in an Amazon SQS queue and trigger an auto scaling action when the queue depth exceeds a threshold. Which combination of services should be used?

A.Amazon CloudWatch Logs and Amazon EC2 Auto Scaling
B.Amazon CloudWatch and Amazon EC2 Auto Scaling
C.Amazon EventBridge and Amazon EC2 Auto Scaling
D.Amazon SQS and AWS Lambda
AnswerB

Amazon CloudWatch natively ingests the `ApproximateNumberOfMessagesVisible` metric that SQS publishes every minute, making queue depth directly measurable. A CloudWatch alarm that transitions to ALARM state based on this metric can be attached to a scaling policy in EC2 Auto Scaling (for step or simple scaling), or you can use a target tracking policy with a custom metric. This is the standard, supported mechanism for scaling compute resources based on queue backlog.

Why this answer

Amazon SQS automatically publishes queue metrics (such as ApproximateNumberOfMessagesVisible) to Amazon CloudWatch. CloudWatch alarms can monitor these metrics and trigger scaling policies on an EC2 Auto Scaling group when the threshold is breached. This is the standard, native integration for queue-depth-based auto scaling.

Exam trap

DOP-C02 often tests the misconception that EventBridge can directly monitor SQS queue depth and trigger scaling, but EventBridge is for event routing, not metric-based alarms; CloudWatch is the correct service for metric monitoring and alarms.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs is for storing and analyzing log data, not for monitoring SQS metrics or triggering scaling actions. Option C is wrong because EventBridge is used for event-driven architectures and routing events, but it does not natively monitor SQS queue depth metrics or directly trigger EC2 Auto Scaling policies. Option D is wrong because SQS alone does not provide monitoring or scaling capabilities, and Lambda is a compute service that could process messages but does not directly trigger EC2 Auto Scaling actions based on queue depth.

569
MCQeasy

A DevOps team is implementing infrastructure as code using AWS CloudFormation. They need to ensure that the stack can be updated to modify a resource's property that requires replacement. Which CloudFormation stack policy should they use?

A.No stack policy, or a policy that allows updates to all resources.
B.A stack policy with an AllowAll statement.
C.A stack policy with a DenyAll statement.
D.A stack policy that explicitly denies updates to the resource.
AnswerA

With no stack policy, CloudFormation uses a default Allow policy that permits all update actions (Update:*) on every resource, so updates can proceed for any resource. Alternatively, an explicit stack policy with a statement containing Effect: Allow, Action: Update:*, Principal: *, and Resource: * has the same effect and also allows all resources to be updated. This matches the requirement to allow updates to all resources.

Why this answer

CloudFormation stack policies are designed to prevent accidental updates to critical resources, not to block updates that require replacement. By default, if no stack policy is applied, all resources can be updated, including those that require replacement. A policy that allows updates to all resources (or no policy) is necessary to permit a stack update that modifies a property requiring resource replacement, as the replacement process involves creating a new resource and deleting the old one, which is a valid update action.

Exam trap

The trap here is that candidates confuse stack policies with IAM policies or assume that any policy statement (like AllowAll) is valid, when in fact CloudFormation stack policies require specific Effect, Action, and Resource keys, and the default behavior (no policy) already allows all updates, including replacement.

How to eliminate wrong answers

Option B is wrong because an AllowAll statement is not a valid CloudFormation stack policy construct; stack policies use Effect, Action, and Resource statements, and an 'AllowAll' statement does not exist in the CloudFormation policy language. Option C is wrong because a DenyAll statement would block all update operations, including the replacement update, which is the opposite of what is needed. Option D is wrong because explicitly denying updates to the resource would prevent any modification, including replacement, making it impossible to perform the required stack update.

570
MCQhard

Refer to the exhibit. A DevOps engineer runs this query to investigate a spike in errors. What is the most likely interpretation?

A.The error rate is increasing sharply in the last 15 minutes.
B.The error rate is decreasing over time.
C.The error rate is stable with no significant change.
D.The query is incorrectly filtering log streams.
AnswerA

The query results show a sharp upward spike in the error count in the most recent time bins, jumping from 1 to 12, which is a clear and significant acceleration in the error rate over the last 15 minutes. This trend is not random fluctuation; the consistent climb in the final bins indicates an emerging incident that requires immediate attention. The slope of the line in the visualization confirms the error rate is increasing, not just an isolated outlier.

Why this answer

The query counts ERROR messages per 5-minute bin for a specific log stream. The output shows a clear increasing trend from 1 to 12 errors over the last 20 minutes, indicating a recent escalation of errors.

571
Multi-Selecteasy

A company wants to protect its application from DDoS attacks. Which THREE AWS services should they use?

Select 3 answers
A.Amazon Inspector
B.AWS WAF
C.AWS Shield Advanced
D.Amazon CloudFront
E.Amazon GuardDuty
AnswersB, C, D

AWS WAF is a web application firewall that filters and monitors HTTP(S) requests using rules for IP reputation, geographic origin, URI patterns, SQL injection, and cross-site scripting. Its rate-based rules automatically block IPs that exceed configured request thresholds, making it effective against HTTP floods and the low-and-slow application-layer DDoS attacks that target web endpoints. WAF integrates with CloudFront, Application Load Balancer, and API Gateway, allowing it to enforce Web ACLs at the edge or origin.

Why this answer

AWS Shield Advanced, WAF, and CloudFront provide layered DDoS protection.

572
MCQeasy

An organization needs to audit all AWS API calls made in their account for compliance purposes. Which AWS service should they enable?

A.Amazon CloudWatch Logs
B.AWS Config
C.AWS CloudTrail
D.Amazon GuardDuty
AnswerC

AWS CloudTrail is the native AWS service that records every API call made in your account, including the identity of the caller, the time of the call, the source IP address, the request parameters, and the response elements. It captures management events for control-plane operations across AWS services, and can also log data events for S3 object-level activity and Lambda function invocations. CloudTrail delivers these logs to an S3 bucket (and optionally CloudWatch Logs) for long-term storage and analysis, making it the correct service for auditing all AWS API calls.

Why this answer

AWS CloudTrail records API activity for auditing and compliance. Option A (Amazon CloudWatch Logs) is incorrect as it is a log management service but does not record API calls. Option B (AWS Config) is incorrect because it tracks resource configuration changes, not API calls.

Option D (Amazon GuardDuty) is incorrect because it is a threat detection service, not a comprehensive API audit trail.

573
MCQeasy

A DevOps engineer is troubleshooting a Lambda function that times out after 3 seconds. The function makes an HTTP request to an external API. The function's timeout setting is 10 seconds. What is the most likely cause of the timeout?

A.The external API is throttling the request.
B.The HTTP client's timeout is set to a low value.
C.The Lambda function is not in a VPC.
D.The Lambda function's memory is insufficient.
AnswerB

The default inactivity timeout for many HTTP clients is exactly 3 seconds, so when the external API takes longer than that to respond, the client aborts with a timeout error before the Lambda function's own timeout limit is reached. Raising the client timeout (or configuring connection/read timeouts) to exceed the expected API response time directly resolves the issue. This matches the symptom precisely because every call that exceeds the threshold fails at the same 3-second mark.

Why this answer

The Lambda function times out after 3 seconds, which is most likely due to an HTTP client timeout explicitly set to a low value (e.g., 3 seconds) inside the function code. Even though the Lambda function's configured timeout is 10 seconds, the HTTP client's internal timeout fires first, causing the function to fail before the Lambda timeout is reached. This is the most likely cause because the symptom matches a client-side timeout rather than a server-side or infrastructure issue.

Exam trap

The trap here is that candidates assume the Lambda function's configured timeout (10 seconds) is the only timeout that matters, overlooking that application-level timeouts (like HTTP client timeouts) can fire independently and cause earlier failures.

How to eliminate wrong answers

Option A is wrong because external API throttling would typically return an HTTP 429 status code or cause a slower response, not a consistent 3-second timeout; the function would still wait for the response up to the Lambda timeout. Option C is wrong because not being in a VPC actually reduces network latency and complexity (Lambda uses the public internet by default), so it would not cause a timeout; VPC-related timeouts usually occur when the function is in a VPC without a NAT gateway or proper routing. Option D is wrong because insufficient memory would cause out-of-memory errors or slower execution, not a consistent 3-second timeout; memory affects CPU allocation but does not directly trigger a timeout at a specific second.

574
MCQmedium

A company uses Amazon RDS for MySQL. The database performance has degraded, and the engineer suspects that slow queries are the cause. Which service should be used to identify and analyze the slow queries?

A.Amazon RDS Performance Insights
B.Amazon CloudWatch Metrics
C.Amazon CloudWatch Logs
D.AWS X-Ray
AnswerA

Amazon RDS Performance Insights is the correct choice because it provides a database-focused dashboard that visualizes the DB Load metric in units of Average Active Sessions (AAS), directly correlating temporal load spikes with the specific SQL statements, waits, hosts, and users responsible. This enables you to drill down into individual slow queries and diagnose performance degradation without needing to manually parse slow query logs or instrument application code.

Why this answer

Amazon RDS Performance Insights is the correct service because it provides a database-specific performance schema that visualizes database load and identifies the exact SQL queries causing performance degradation. It integrates directly with RDS for MySQL, offering a dashboard that breaks down wait events, SQL text, and host-level metrics, making it the ideal tool for analyzing slow queries.

Exam trap

The trap here is that candidates may confuse CloudWatch Logs (which can store slow query logs) with a native analysis tool, overlooking that Performance Insights provides immediate, built-in visualization and query-level analysis without requiring custom log parsing.

How to eliminate wrong answers

Option B is wrong because Amazon CloudWatch Metrics provides aggregated performance metrics like CPU utilization and IOPS, but it does not capture individual SQL query text or detailed database wait event analysis needed to identify slow queries. Option C is wrong because Amazon CloudWatch Logs can store MySQL slow query logs if configured, but it requires manual setup and does not provide built-in visualization or analysis of query performance; it is a log storage service, not an analysis tool. Option D is wrong because AWS X-Ray is designed for tracing distributed application requests and debugging microservices, not for analyzing database query performance or slow SQL statements.

575
MCQmedium

An organization uses AWS CodePipeline with a multi-branch strategy. They want to run unit tests on every push to any branch, but only deploy to production on pushes to the 'main' branch. What is the most efficient way to achieve this?

A.Configure a single pipeline with a source action that triggers on all branches, then use a 'branch' condition on the deployment stage to only proceed if the branch is 'main'.
B.Use a single pipeline with a source action that triggers on all branches, and deploy to a test environment for all branches, then promote to production manually.
C.Create separate pipelines for each branch, each with its own test and deploy stages.
D.Use a single pipeline with a source action that only triggers on the 'main' branch, and run tests in a separate system.
AnswerA

This option uses a single CodePipeline execution triggered by all branch updates, and then applies a stage condition such as #{SourceVariables.BranchName} == 'main' on the deployment action. Test and build stages still run for every branch, but non-main branches are skipped at the deployment stage, so no production release occurs for feature branches. This minimizes pipeline infrastructure, reduces maintenance, and keeps the automation fully managed inside the pipeline.

Why this answer

AWS CodePipeline supports a single pipeline with a source action configured to trigger on all branches (e.g., using a webhook event filter for 'refs/heads/*'). You can then add a 'branch' condition on the deployment stage using a Lambda function or a manual approval action that checks the branch name, ensuring only pushes to 'main' proceed to production. This approach avoids duplicating pipelines while still running unit tests on every push.

Exam trap

The trap here is that candidates often think they need separate pipelines per branch (Option C) or a manual promotion step (Option B), but AWS CodePipeline supports branch filtering natively via webhook event patterns and custom conditions, making a single pipeline the most efficient choice.

How to eliminate wrong answers

Option B is wrong because it suggests deploying to a test environment for all branches and then manually promoting to production, which does not automatically restrict production deployment to only the 'main' branch and introduces unnecessary manual steps. Option C is wrong because creating separate pipelines for each branch is inefficient and harder to maintain, especially as the number of branches grows, and it violates the principle of using a single pipeline for multi-branch strategies. Option D is wrong because it runs tests in a separate system outside CodePipeline, which breaks the unified CI/CD workflow and does not leverage CodePipeline's built-in multi-branch triggering capabilities.

576
MCQhard

A company runs a critical microservices architecture on Amazon ECS with Fargate. They want to ensure that if a task fails, it is automatically restarted, and the service remains available across multiple Availability Zones. How should they configure the ECS service?

A.Place all tasks in the same Availability Zone to reduce latency
B.Run a standalone Fargate task and use a CloudWatch alarm to restart it
C.Use an EC2 launch type with a single instance to reduce complexity
D.Define an ECS service with a task definition, set desired count across multiple Availability Zones, and use Service Auto Scaling
AnswerD

An ECS service with a task definition and a multi-AZ placement strategy is the correct pattern because the service scheduler continuously maintains the desired count, automatically replacing tasks that fail, become unhealthy, or lose connectivity. Distributing tasks across multiple Availability Zones ensures the service remains available even if an entire AZ goes down, as the remaining AZs still host task copies. Service Auto Scaling independently adjusts the desired count based on CloudWatch metrics or target tracking, providing elasticity and capacity management without sacrificing the resilience built into the service model.

Why this answer

An ECS service configured with a task definition, desired count across multiple Availability Zones, and Service Auto Scaling ensures resilience. The ECS service scheduler automatically restarts failed tasks, and distributing tasks across AZs provides high availability. Option A is wrong because placing all tasks in a single AZ creates a single point of failure.

Option B is wrong because a standalone Fargate task does not have automatic restart; a CloudWatch alarm can restart it but lacks the built-in resilience of an ECS service. Option C is wrong because using a single EC2 instance is a single point of failure and does not provide multi-AZ resilience.

577
MCQmedium

A team uses AWS CodeDeploy to deploy a web application to an Auto Scaling group. The deployment fails with the error 'The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available, or some instances in your deployment group are experiencing problems.' The team checks the logs and finds that the application installation script fails on some instances due to missing dependencies. What is the BEST long-term solution?

A.Create a custom AMI that includes all dependencies and use it in the Auto Scaling group.
B.Use an Elastic Load Balancer health check to automatically replace failed instances.
C.Modify the CodeDeploy AppSpec file to run the installation script as root.
D.Implement a retry mechanism in the deployment script to install dependencies again.
AnswerA

Creating a custom Amazon Machine Image (AMI) that has all required runtime dependencies pre-installed and using it in the Auto Scaling group is the most robust fix. When instances launch from this golden AMI, the operating system and packages are already present, so the CodeDeploy deployment only needs to place and start the application code. This eliminates runtime failures caused by dependency installation errors and guarantees consistency across newly launched instances.

Why this answer

Creating a custom AMI that includes all dependencies ensures that every instance launched in the Auto Scaling group has the required software pre-installed. This eliminates the root cause of the deployment failure—missing dependencies—by baking them into the machine image, making deployments consistent and reliable. It is the best long-term solution because it avoids runtime dependency installation failures and reduces deployment time.

Exam trap

The trap here is that candidates often choose a retry mechanism or health check fix, thinking they can handle transient failures, but the question specifies 'missing dependencies'—a persistent issue that requires a proactive, image-based solution rather than reactive or permission-based fixes.

How to eliminate wrong answers

Option B is wrong because an Elastic Load Balancer health check only detects and replaces unhealthy instances after they fail, but it does not prevent the deployment failure caused by missing dependencies; it is a reactive measure, not a long-term fix. Option C is wrong because running the installation script as root does not resolve missing dependencies; it only changes the execution user, and dependency installation failures are typically due to missing packages, not permission issues. Option D is wrong because implementing a retry mechanism in the deployment script only retries the same failing dependency installation, which will continue to fail if the dependencies are not available in the instance's package repositories or are not properly configured; it does not address the underlying missing dependency problem.

578
MCQhard

A company has a multi-account AWS environment with separate accounts for development, staging, and production. They want to implement a CI/CD pipeline that deploys to each account sequentially after manual approvals. Which setup allows cross-account deployment with CodePipeline?

A.Create an IAM role in the target account with permissions for the pipeline service role to assume, and use that role in the deployment action.
B.Create separate pipelines in each account and trigger them via SNS from a master pipeline.
C.Use CodePipeline with cross-account actions by specifying the target account ID and region.
D.Use a single pipeline in the management account with different stages for each account.
AnswerA

Create an IAM role in the target account with a trust policy that allows the CodePipeline service role in the originating account to assume it via sts:AssumeRole. Then configure the deployment action (e.g., ECS, CloudFormation, S3) to use that role's ARN so the pipeline can perform resource operations in the target account without long-lived credentials. This follows least privilege and avoids hard-coding keys, and it is the canonical pattern documented by AWS for cross-account CodePipeline deployments.

Why this answer

CodePipeline supports cross-account deployments by having the pipeline service role in the source account assume an IAM role in the target account. This role must have a trust policy allowing the pipeline service role to assume it, and the deployment action (e.g., CloudFormation, CodeDeploy) references that target account role. This enables sequential deployment to development, staging, and production accounts with manual approval gates between stages.

Exam trap

The trap here is that candidates confuse CodePipeline's cross-account support with a simple account ID parameter, when in reality it requires explicit IAM role assumption and trust policy configuration.

How to eliminate wrong answers

Option B is wrong because it creates separate pipelines in each account, which defeats the purpose of a single CI/CD pipeline and introduces complexity in managing cross-account triggers via SNS; CodePipeline does not natively support triggering pipelines in other accounts via SNS without additional custom logic. Option C is wrong because CodePipeline does not support specifying a target account ID and region directly in a cross-account action; cross-account actions require an IAM role in the target account, not just an account ID. Option D is wrong because a single pipeline in the management account cannot deploy directly to resources in other accounts without assuming roles; the management account is not automatically trusted by member accounts for deployment actions.

579
MCQhard

A company runs a critical application on an Auto Scaling group of EC2 instances behind an Application Load Balancer (ALB). The DevOps team needs to implement a dashboard that shows real-time request latency, error rates, and the number of healthy hosts. Which AWS service should be used to create this dashboard?

A.Amazon QuickSight
B.AWS CloudTrail
C.AWS Config
D.Amazon CloudWatch Dashboards
AnswerD

Amazon CloudWatch Dashboards are the native solution for building customizable operational views that aggregate metrics from AWS services, including EC2 auto scaling groups, load balancers, and custom application metrics. They support real-time graphing with automatic refresh, can combine multiple metrics, alarms, and logs into a single pane of glass, and allow cross-account or cross-region aggregation. With built-in integration for Auto Scaling group metrics like average CPU utilization and healthy host counts, CloudWatch Dashboards are the appropriate choice for a critical application's real-time operational monitoring.

Why this answer

Amazon CloudWatch Dashboards is the correct choice because it provides real-time monitoring and visualization of metrics such as request latency, error rates, and healthy host counts directly from CloudWatch. These metrics are automatically emitted by the Application Load Balancer (e.g., TargetResponseTime, HTTPCode_ELB_5XX_Count, HealthyHostCount) and can be displayed on a customizable dashboard without additional data transformation or querying.

Exam trap

The trap here is that candidates may confuse Amazon QuickSight with CloudWatch Dashboards, assuming QuickSight is the go-to for any dashboarding need, but QuickSight is for business analytics and not designed for real-time infrastructure monitoring with sub-minute latency metrics.

How to eliminate wrong answers

Option A is wrong because Amazon QuickSight is a business intelligence service for interactive dashboards and ad-hoc analysis, not designed for real-time operational monitoring of live infrastructure metrics like ALB latency or healthy hosts. Option B is wrong because AWS CloudTrail records API activity and governance events, not real-time performance metrics or health status of EC2 instances behind a load balancer. Option C is wrong because AWS Config tracks resource configuration changes and compliance, not real-time operational metrics such as request latency or error rates.

580
Multi-Selecthard

A company runs a critical application on Amazon EKS. The operations team needs to monitor the health of the Kubernetes cluster and the applications running on it. Which THREE services can be used together to achieve comprehensive monitoring? (Choose THREE.)

Select 3 answers
A.AWS X-Ray
B.Amazon VPC Flow Logs
C.AWS CloudTrail
D.Amazon CloudWatch Container Insights
E.Amazon Managed Service for Prometheus
AnswersA, D, E

AWS X-Ray traces requests as they flow through a distributed application, providing end-to-end visibility into latencies, errors, and dependencies across microservices running on Amazon EKS. By instrumenting the application with the X-Ray SDK, you can identify the specific service or database call causing performance degradation. X-Ray's service graph and trace timelines reveal exactly where requests are spending time, making it the correct choice for troubleshooting application-level performance issues.

Why this answer

AWS X-Ray (A) is correct because it provides distributed tracing for applications running on EKS, letting the team follow requests across microservices and pinpoint latency or errors in the application layer. Amazon CloudWatch Container Insights (D) is correct because it collects and aggregates container-level metrics and logs (CPU, memory, disk, network) from EKS nodes and pods, giving cluster and workload health visibility. Amazon Managed Service for Prometheus (E) is correct because it is a Prometheus-compatible managed service that scrapes and stores Kubernetes metrics and supports alerting, complementing Container Insights for deeper, PromQL-based monitoring.

Amazon VPC Flow Logs (B) only captures IP traffic metadata at the network interface level and does not provide application or Kubernetes-level health insight. AWS CloudTrail (C) records AWS API activity for auditing and governance, not runtime health or performance monitoring of the cluster or its applications.

Exam trap

DOP-C02 often tests whether candidates confuse network/audit logging services (VPC Flow Logs, CloudTrail) with observability services that actually surface application and container health, causing them to pick the wrong 'monitoring' trio.

581
MCQmedium

A team uses AWS CodePipeline to orchestrate deployments. They want to integrate a manual approval step before deploying to production. Which action should they take?

A.Use an AWS Lambda function to send an approval request email and wait for HTTP response.
B.Add a manual approval action to the pipeline before the production deployment stage.
C.Add an Amazon CloudWatch Events rule to pause the pipeline before the production stage.
D.Add an Amazon SNS topic to the pipeline and require subscription confirmation.
AnswerB

Adding a manual approval action is the native and correct way to gate a production deployment in CodePipeline. The action is an Approval type stage step that pauses the pipeline execution until an authorized IAM principal explicitly clicks Approve or Reject in the console, or calls the appropriate AWS SDK/CLI commands. This provides a built-in, auditable human checkpoint with no additional infrastructure, and it can optionally send SNS or EventBridge notifications to reviewers.

Why this answer

AWS CodePipeline natively supports a manual approval action that can be added as a stage before the production deployment. This action pauses the pipeline and sends a notification (via Amazon SNS) to specified approvers, who can then approve or reject the deployment through the AWS Management Console, CLI, or API. No custom code or external services are required.

Exam trap

The trap here is that candidates may confuse the manual approval action's dependency on SNS with the idea that simply adding an SNS topic to the pipeline creates an approval step, when in fact the approval action must be explicitly added as a stage action.

How to eliminate wrong answers

Option A is wrong because using an AWS Lambda function to send an approval request email and wait for an HTTP response introduces unnecessary complexity and does not integrate with CodePipeline's built-in approval workflow; CodePipeline already provides a native manual approval action with SNS notifications. Option C is wrong because Amazon CloudWatch Events rules can trigger actions based on pipeline state changes but cannot pause a pipeline or add an approval step; pausing is a feature of the manual approval action itself. Option D is wrong because adding an Amazon SNS topic to the pipeline does not create an approval step; the SNS topic is used by the manual approval action to notify approvers, but simply adding a topic without the approval action does not pause the pipeline or require approval.

582
MCQhard

A company uses AWS OpsWorks for configuration management with Chef. They are migrating to AWS Systems Manager to reduce complexity. The operations team needs to run custom scripts on a fleet of EC2 instances on a schedule, with the ability to target instances based on tags. Which Systems Manager capability should the engineer use?

A.Patch Manager
B.Automation
C.State Manager
D.Run Command
AnswerC

AWS Systems Manager State Manager uses associations to define the state you want to maintain on your managed instances, including running custom scripts via Run Command documents or other SSM documents. Associations support a schedule using cron or rate expressions and can target instances by tags, resource groups, or individual instance IDs. This makes State Manager the ideal service for regularly executing a custom script on EC2 instances selected by tags. The association's schedule ensures the script runs automatically, and it provides compliance reporting on execution history.

Why this answer

State Manager is the correct choice because it is designed to define and maintain consistent configuration of EC2 instances and other AWS resources, including running custom scripts on a schedule. It supports targeting instances by tags and uses associations to enforce desired states at specified intervals, making it ideal for scheduled script execution across a tagged fleet.

Exam trap

The trap here is that candidates often confuse Run Command's on-demand execution with scheduled execution, overlooking that State Manager provides the built-in scheduling and tag-based targeting required for recurring tasks.

How to eliminate wrong answers

Option A is wrong because Patch Manager is specifically for automating OS patching (e.g., installing security updates), not for running arbitrary custom scripts on a schedule. Option B is wrong because Automation is used for performing predefined or custom workflows (e.g., AMI creation, instance remediation) but is typically invoked manually or via events, not designed for recurring scheduled script execution with tag-based targeting. Option D is wrong because Run Command allows you to run scripts or commands on instances on-demand or via EventBridge, but it lacks the native scheduling capability of State Manager; you would need to build a separate scheduling mechanism (e.g., using EventBridge rules) to achieve recurring execution, whereas State Manager provides built-in scheduling via associations.

583
Multi-Selectmedium

Which of the following are valid strategies for implementing continuous integration in AWS? (Choose two.)

Select 2 answers
A.Configure AWS CodeBuild to automatically run tests when a pull request is created in CodeCommit.
B.Set up AWS CodeDeploy to trigger a build every time a commit is pushed to a repository.
C.Use AWS CodePipeline with a source stage that polls CodeCommit for changes and triggers a build stage.
D.Use AWS CloudFormation to create a stack that runs tests every time a new commit is pushed.
AnswersA, C

Using AWS CodeBuild with CodeCommit as a source, you can configure pull request filters so a test build starts automatically when a PR is created, before the branch is merged. The buildspec can run unit tests and integration tests against the PR source revision, then post status back to CodeCommit. This event-driven behavior is a canonical continuous integration practice because it validates every proposed change quickly without waiting for a scheduled pipeline.

Why this answer

AWS CodeBuild can be configured to automatically run tests when a pull request is created in CodeCommit using a webhook or event rule. This enables continuous integration by validating code changes before merging, ensuring that only tested code is integrated into the main branch.

Exam trap

The trap here is confusing deployment services (CodeDeploy) and infrastructure provisioning (CloudFormation) with CI build triggers, leading candidates to select options that sound plausible but lack the specific capability to initiate a build or run tests.

Why the other options are wrong

B

CodeDeploy is for deployment, not building or testing.

D

CloudFormation is for infrastructure as code, not for running tests.

584
Multi-Selecteasy

A company uses AWS CloudFormation to deploy a VPC with public and private subnets. They want to ensure that the VPC has internet access for the public subnets. Which THREE resources must be included in the template?

Select 3 answers
A.AWS::EC2::VPCEndpoint
B.AWS::EC2::Route (pointing to InternetGateway)
C.AWS::EC2::RouteTable
D.AWS::EC2::NatGateway
E.AWS::EC2::InternetGateway
AnswersB, C, E

An AWS::EC2::Route entry with destination 0.0.0.0/0 and target pointing to an InternetGateway is the precise mechanism that makes a public subnet public. This route directs all non-local traffic to the internet gateway, enabling instances with public IPs to reach outbound and receive inbound internet traffic. Without this specific route, the internet gateway exists but the subnet cannot use it, so creating the route is the decisive step.

Why this answer

An AWS::EC2::Route resource that points to an InternetGateway is required to direct traffic from the public subnet's route table to the internet. Without this route, instances in the public subnet cannot send or receive traffic from the internet, even if an Internet Gateway is attached to the VPC.

Exam trap

The trap here is that candidates often assume an Internet Gateway alone is sufficient for internet access, forgetting that a route in the route table pointing to the IGW is mandatory to make the connection functional.

585
MCQeasy

A company uses AWS CodeBuild to build a Docker image and push it to Amazon ECR. The buildspec.yml includes a 'post_build' phase command to tag the image. The build fails with 'unauthorized: authentication required'. What must be done to resolve this?

A.Add 'ecr:InitiateLayerUpload' and 'ecr:CompleteLayerUpload' permissions to the CodeBuild service role.
B.Use the 'docker login' command with AWS CLI in the build phase.
C.Install the AWS CLI in the CodeBuild build environment.
D.Create a new IAM user with ECR permissions and store the keys in CodeBuild environment variables.
AnswerA

The AWS CodeBuild service role is the IAM identity that supplies temporary credentials to the build container. Pushing a Docker image to Amazon ECR requires calling the ECR API operations InitiateLayerUpload, UploadLayerPart, CompleteLayerUpload, and PutImage, so the role must explicitly allow those actions. Without these permissions, even a successfully authenticated docker login will fail when the push actually attempts to upload the image layers. Granting the policy to the service role is the secure, minimal-change fix.

Why this answer

The error 'unauthorized: authentication required' indicates that CodeBuild's IAM role lacks the necessary permissions to push the Docker image to Amazon ECR. The correct resolution is to add the specific ECR permissions 'ecr:InitiateLayerUpload' and 'ecr:CompleteLayerUpload' to the CodeBuild service role, as these are required for the Docker push operation to upload image layers. Without these permissions, the ECR API rejects the push even if other permissions like 'ecr:GetAuthorizationToken' are present.

Exam trap

The trap here is that candidates often assume the 'unauthorized' error is due to missing 'ecr:GetAuthorizationToken' or a need to run 'docker login', but the real issue is the absence of specific layer upload permissions required for the push operation.

How to eliminate wrong answers

Option B is wrong because 'docker login' with AWS CLI is not needed in CodeBuild; CodeBuild automatically authenticates to ECR using the instance's IAM role when the AWS CLI is configured, and manual login is redundant and can cause conflicts. Option C is wrong because the AWS CLI is already pre-installed in CodeBuild's standard build environments (e.g., Amazon Linux 2), so installing it again does not resolve the missing IAM permissions. Option D is wrong because creating a new IAM user and storing keys in environment variables is an anti-pattern; it introduces long-term credentials that must be rotated and violates the principle of least privilege, whereas the correct approach is to grant the necessary permissions directly to the CodeBuild service role.

586
MCQhard

A company uses AWS CloudFormation to manage infrastructure. The DevOps team wants to implement a change management process where all stack updates must be reviewed before execution. Which AWS feature should be used?

A.Drift detection
B.Change Sets
C.StackSets
D.Stack policies
AnswerB

A change set is a read-only summary of the modifications CloudFormation will perform if you execute it, including resource additions, removals, and replacements with details such as `Replacement` and `RequiresRecreation`. You create a change set, inspect its proposed actions—even using `--changeset` filtering or the console UI—and only then choose to execute it, which gives you a controlled, auditable review gate before any infrastructure is altered.

Why this answer

Change Sets allow you to preview how proposed changes to a CloudFormation stack will impact your running resources before you execute them. This enables a review-and-approval workflow, making it the correct choice for implementing a change management process where all stack updates must be reviewed before execution.

Exam trap

The trap here is that candidates often confuse drift detection (which detects post-update configuration drift) with the ability to preview proposed changes, or they mistakenly think stack policies can gate the update itself rather than just protecting specific resources during an update.

How to eliminate wrong answers

Option A is wrong because drift detection identifies whether a stack's actual resource configuration has diverged from its template, but it does not provide a mechanism to review or approve proposed updates before they are applied. Option C is wrong because StackSets are used to deploy stacks across multiple accounts and regions, not to preview or gate changes to a single stack. Option D is wrong because stack policies define which resources can be updated during a stack update, but they do not allow you to review the proposed changes before the update is executed.

587
Multi-Selectmedium

A DevOps team is investigating a security incident where an unauthorized user accessed an S3 bucket. The team needs to determine what actions were taken by the user. Which TWO AWS services should be used together to investigate? (Choose TWO.)

Select 2 answers
A.S3 server access logs
B.Amazon CloudWatch metrics
C.AWS Config
D.AWS CloudTrail
E.Amazon GuardDuty
AnswersA, D

S3 server access logs record every request made to a bucket, capturing the authenticated identity, timestamp, source IP and operation performed. This directly satisfies the requirement to determine which actions the unauthorised user took, since the logs detail the specific REST operations against the bucket.

Why this answer

S3 server access logs (A) are correct because they record detailed, object-level requests made against a bucket, including the requester, bucket name, request time, action (such as REST.GET.OBJECT or REST.PUT.OBJECT), response status, and error code, which lets the team see exactly what operations the unauthorized user performed on the objects. AWS CloudTrail (D) is correct because it captures S3 data events (GetObject, PutObject, DeleteObject) and management events (such as PutBucketPolicy) as API activity with the identity of the caller, source IP address, and timestamp, providing the who-did-what audit trail needed to attribute the actions. Used together, CloudTrail identifies the principal and API calls while S3 server access logs provide the granular request-level detail for the bucket.

Amazon CloudWatch metrics (B) only provides aggregate performance and usage statistics, not per-request identity or action detail, so it cannot show what the user did. AWS Config (C) tracks resource configuration changes and compliance over time, not individual object access actions. Amazon GuardDuty (E) is a threat-detection service that generates findings about suspicious activity but does not provide the raw request-level or API-level audit records required to reconstruct the user's actions.

588
Multi-Selecthard

A company is experiencing a DDoS attack on its application hosted on AWS. The application uses an Application Load Balancer (ALB) with an Auto Scaling group of EC2 instances. The security team needs to mitigate the attack with minimal latency impact on legitimate users. Which THREE actions should the team take? (Choose THREE.)

Select 3 answers
A.Disable cross-zone load balancing on the ALB to limit the number of instances receiving traffic.
B.Enable AWS Shield Advanced on the ALB.
C.Enable connection draining (deregistration delay) on the ALB target group.
D.Configure the Auto Scaling group to scale based on the NetworkIn metric to handle the increased traffic.
E.Configure AWS WAF on the ALB to block requests based on source IP reputation or rate-based rules.
AnswersB, C, E

Shield Advanced provides always-on detection and inline mitigation at the AWS edge, absorbing large volumetric DDoS attacks before they reach the ALB. It also includes DDoS cost protection and 24/7 access to the DDoS Response Team (DRT), who can analyze attack patterns and apply mitigations directly. Enabling it on the ALB is a fundamental step for comprehensive DDoS protection.

Why this answer

AWS Shield Advanced provides enhanced DDoS mitigation for ALBs, including access to the DDoS Response Team (DRT) and financial protection against scaling costs. It operates at the network and transport layers with minimal latency, as it inspects traffic inline without introducing significant processing delay. This makes it a critical first line of defense for high-availability applications under attack.

Exam trap

The trap here is confusing scaling-based absorption (Option D) with actual mitigation, leading candidates to think handling more traffic automatically defends against DDoS, when in reality it only increases cost and resource exhaustion without blocking the attack source.

589
MCQmedium

A company stores its application source in an AWS CodeCommit repository. The security team requires that all code changes be reviewed and approved by at least one other developer before being merged into the `main` branch. A DevOps engineer needs to enforce this policy and prevent direct pushes to `main`. Which combination of actions should the engineer take?

A.Configure an Amazon EventBridge rule that triggers an AWS Lambda function to revert any direct push to `main` and send a notification.
B.Enable branch protection on `main` in the CodeCommit console and configure an approval rule that requires one approver.
C.Use AWS CodePipeline to automatically reject any commit to `main` that does not have an approved pull request, and notify the security team.
D.Create an IAM policy that denies `codecommit:GitPush` to the `main` branch for all developers, and require pull requests via a repository approval rule template.
AnswerD

IAM policies can restrict Git push operations to specific branches using the `codecommit:References` condition key. Denying `codecommit:GitPush` to `refs/heads/main` prevents direct pushes. Additionally, approval rule templates enforce pull request approvals. Together, they meet both requirements: no direct pushes and mandatory review.

Why this answer

To prevent direct pushes to a specific branch in CodeCommit, an IAM policy must deny the `codecommit:GitPush` action for that branch reference. This is done using the `codecommit:References` condition key. To require approvals before merging, an approval rule template can be applied to the repository, mandating a minimum number of approvals.

Together, these native features enforce both aspects of the security policy without custom code.

Exam trap

The trap here is assuming CodeCommit has a branch protection toggle like other Git services, when it actually relies on IAM policies for push restrictions.

590
MCQmedium

A development team uses AWS CodeCommit and AWS CodePipeline for CI/CD. They notice that a pipeline execution failed due to a code review rejection in the 'Approve' stage. The pipeline is configured with a manual approval action. What is the most likely cause of the failure?

A.The IAM role for the pipeline does not have permission to invoke the approval action.
B.The CodeCommit repository has a branch policy that prevents direct commits.
C.An authorized user logged in to the CodePipeline console and rejected the approval request.
D.The pipeline is not configured with a CloudWatch Events rule to trigger the approval.
AnswerC

When a manual approval action is reached, an authorized IAM user sees a Review button in the CodePipeline console and can choose Approve or Reject. Selecting Reject transitions the pipeline execution to a failed state with a status of 'Rejected', and any reviewer comment is recorded in the execution history. This is the only mechanism that directly causes a rejection.

Why this answer

A manual approval action in CodePipeline explicitly requires a human reviewer to approve or reject the pipeline execution. If the pipeline failed due to a 'code review rejection,' the most direct cause is that an authorized user logged into the CodePipeline console and clicked the 'Reject' button on the approval request. This is the only mechanism by which a manual approval action can result in a rejection.

Exam trap

The trap here is that candidates may confuse the manual approval action with automated checks or permissions issues, overlooking that the only way a manual approval action results in a rejection is through explicit human action in the console or API.

How to eliminate wrong answers

Option A is wrong because the IAM role for the pipeline does not need permission to 'invoke' the approval action; the approval action is manual and relies on user authentication, not pipeline role permissions. Option B is wrong because a CodeCommit branch policy that prevents direct commits would block pushes to the repository, but it does not affect the manual approval stage in CodePipeline, which occurs after the source and build stages. Option D is wrong because CloudWatch Events rules are used to trigger pipeline executions automatically (e.g., on source changes), but they are not required for the manual approval action to function; the approval stage is triggered by the pipeline execution itself.

591
MCQmedium

A company uses AWS CodeCommit for source control. Developers work on feature branches and create pull requests to merge into the 'develop' branch. The company wants to enforce that all commits to the 'develop' branch are signed. Which AWS service or feature should be used to enforce this policy?

A.Use Amazon CloudWatch Events to trigger a Lambda function that verifies commit signatures and reverts unsigned commits.
B.Create an approval rule template in CodeCommit that requires commits to be signed and associate it with the 'develop' branch.
C.Use AWS Key Management Service (KMS) to create a signing key and require developers to use it.
D.Configure an IAM policy that denies 'git push' unless the commit is signed.
AnswerB

Incorrect. Approval rule templates only require approvals from specified users; they do not verify commit signatures or enforce signing.

Why this answer

AWS CodeCommit natively supports enforcing signed commits. You can create an approval rule template with the 'Require commit signing' condition and associate it with the 'develop' branch. This ensures that any commit to the branch must be signed with a valid GPG key, and unsigned commits are rejected.

Option A is incorrect because using CloudWatch Events and Lambda to revert unsigned commits is not a native enforcement mechanism and is unnecessary. Option C is incorrect because KMS is not used for Git commit signing. Option D is incorrect because IAM policies cannot inspect commit signatures.

Exam trap

The trap is that candidates may think CodeCommit lacks native support for signed commits and resort to a custom Lambda-based solution. In reality, CodeCommit approval rule templates can enforce commit signing directly.

How to eliminate wrong answers

Option A is wrong because CloudWatch Events and Lambda can react to events but cannot enforce a policy at the git push level; reverting unsigned commits after they are pushed is reactive and violates the requirement to enforce signing. Option C is wrong because AWS KMS provides signing keys but does not enforce commit signing policies in CodeCommit; developers could still push unsigned commits. Option D is wrong because IAM policies cannot inspect the content of a git push (such as whether a commit is signed); they only control API-level permissions, not commit metadata.

592
MCQeasy

A DevOps engineer is investigating why an Amazon ECS service is not scaling out as expected. The service has a target tracking scaling policy based on average CPU utilization. The CloudWatch alarm shows that CPU utilization has exceeded the target for several minutes, but no scaling activity has occurred. What is the most likely cause?

A.The ECS service is configured with a minimum healthy percent that prevents scaling out.
B.The ECS service does not have an IAM role that allows it to call CloudWatch.
C.The CloudWatch alarm is configured with a period that is too long.
D.The scaling policy has a cooldown period that is still in effect from a previous scaling activity.
AnswerD

A cooldown period is a duration after a scaling activity during which the scaling policy cannot trigger another action, even if the CloudWatch alarm remains in breach. In Application Auto Scaling, this prevents rapid oscillation and lets the newly added tasks take effect. If a previous scale-out or scale-in occurred recently, the outstanding cooldown will block the new scaling request, which exactly matches the symptom of the alarm being breached but no scaling activity occurring.

Why this answer

Target tracking scaling policies in Amazon ECS have a cooldown period (default 300 seconds) that prevents the policy from initiating additional scaling activities immediately after a previous scaling action. If a recent scaling activity occurred, the cooldown period would still be in effect, causing the policy to ignore the alarm even though CPU utilization has exceeded the target. This is the most likely reason no scaling activity is observed despite the alarm being triggered.

Exam trap

The trap here is that candidates often overlook the cooldown period and instead blame IAM permissions or alarm configuration, but the cooldown is a deliberate stabilization mechanism that directly explains why scaling is not occurring despite the alarm being active.

How to eliminate wrong answers

Option A is wrong because the minimum healthy percent parameter controls the minimum percentage of tasks that must remain healthy during deployments or scaling activities, but it does not prevent scaling out; it only affects how many tasks can be stopped or started at once. Option B is wrong because the ECS service does not need an IAM role to call CloudWatch; the scaling policy uses the service-linked role AWSServiceRoleForApplicationAutoScaling, which already has permissions to read CloudWatch alarms and metrics. Option C is wrong because a long CloudWatch alarm period would delay the alarm transition to ALARM state, but the question states the alarm has already exceeded the target for several minutes, meaning the period is not the issue.

593
MCQmedium

A company uses an AWS Elastic Load Balancer (ELB) to distribute traffic to EC2 instances. During an incident, some users report slow response times. The DevOps engineer suspects that one instance is unhealthy but the health check is not detecting it. What should the engineer do to improve health check accuracy?

A.Increase the health check interval to reduce load on instances
B.Configure a health check that checks a specific application endpoint
C.Decrease the health check unhealthy threshold to 2
D.Set the health check path to the root document ('/')
AnswerB

Configuring a health check against a specific application endpoint, such as /healthz or /api/v1/status, makes the ELB perform a deep health check that exercises your application's critical request path, including framework routing, connections to dependent services, and session or cache state. This directly addresses the scenario where an instance accepts TCP or HTTP requests but is not truly ready to serve application traffic. By returning a non-200 status only when application dependencies or internal state are degraded, the ELB can accurately detect the unhealthy instance and stop sending it traffic.

Why this answer

A health check that targets a specific application endpoint (e.g., /health or /api/status) validates that the application is actually functioning, not just that the instance responds on a port. This catches unhealthy instances that still accept TCP connections but fail to serve requests, which is exactly the scenario described. The other options either weaken detection or do not improve accuracy.

Exam trap

DOP-C02 often tests the difference between port-level and application-level health checks — candidates pick '/' or threshold tweaks because they sound like fixes, but only a specific application endpoint validates true health.

How to eliminate wrong answers

Option A is wrong because increasing the interval slows detection of failures, making the problem worse rather than improving accuracy. Option C is wrong because lowering the unhealthy threshold to 2 makes the check more aggressive but does not make it more accurate — it can cause false positives without validating application health. Option D is wrong because checking '/' only confirms the web server responds; it does not verify application-level health and may return 200 even when the app is degraded.

594
Drag & Dropmedium

Drag and drop the steps to set up an AWS CodePipeline with a source stage from CodeCommit and a deploy stage to Elastic Beanstalk.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order is: first create the S3 bucket for artifacts, then create the CodeCommit repository and push code, then create the pipeline, then configure source, then configure deploy.

595
Multi-Selectmedium

A company uses AWS CodePipeline for CI/CD. The security team requires that all code changes be scanned for secrets before deployment. The pipeline consists of a source stage (CodeCommit), a build stage (CodeBuild), and a deploy stage (CodeDeploy). The security team wants to automatically scan for secrets and block the pipeline if any secrets are found. Which THREE actions should the team take? (Choose THREE.)

Select 3 answers
A.Add a scanning action in the deploy stage to scan after deployment.
B.Configure the build project to fail the build if the scanning tool returns a non-zero exit code.
C.Add a scanning action in the build stage using a custom action or a third-party action from AWS Marketplace.
D.Configure an S3 bucket policy to deny access if secrets are detected.
E.Grant the CodeBuild service role permissions to retrieve the scanning tool from an S3 bucket.
AnswersB, C, E

CodeBuild treats any command that returns a non-zero exit code as a failed build, which immediately stops the pipeline and prevents the artifact from being promoted to the deploy stage. When a secret-scanning tool detects an issue, it exits with a non-zero code; configuring the build project to treat that as fatal ensures the pipeline is blocked before deployment. This is often implemented in the buildspec by running the scanner as the final command or using build phases with explicit failure handling.

Why this answer

Option B is correct because CodeBuild treats a non-zero exit code from a build command as a build failure, which stops the pipeline before the deploy stage and thereby blocks deployment when secrets are detected. Option C is correct because the build stage is the appropriate place to run a secret-scanning tool, and CodePipeline supports invoking it either as a custom action or via a pre-built third-party action from AWS Marketplace integrated into the build stage. Option E is correct because CodeBuild needs its service role to have the necessary permissions (for example, s3:GetObject on the specific bucket/object) to download the scanning tool or its dependencies from Amazon S3 during the build.

Option A is not appropriate because scanning after deployment is too late—secrets would already be exposed in the deployed environment, and CodeDeploy does not natively support a scanning action that blocks based on findings. Option D is incorrect because an S3 bucket policy cannot detect secrets in code and is unrelated to blocking a CodePipeline deployment based on scan results.

Exam trap

DOP-C02 often tests the misconception that scanning can happen in the deploy stage or that S3 bucket policies can detect secrets — the correct pattern is to scan in the build stage and fail the build on detection.

596
MCQeasy

A DevOps engineer is designing a CI/CD pipeline that deploys code to an EC2 instance. The engineer needs to securely store and retrieve database credentials used by the application. Which AWS service should be used?

A.Amazon S3 with server-side encryption
B.AWS Systems Manager Parameter Store
C.AWS Secrets Manager
D.AWS Key Management Service (KMS)
AnswerC

AWS Secrets Manager stores database credentials encrypted and supports automatic rotation, so the pipeline retrieves them at deploy time via IAM-scoped API calls instead of embedding them in code or instance user data, meeting the secure storage and retrieval requirement.

Why this answer

AWS Secrets Manager is designed to securely store, retrieve, and rotate secrets such as database credentials. It provides fine-grained access control, encryption at rest, and automatic rotation, making it ideal for CI/CD pipelines that need to access database credentials securely.

Exam trap

DOP-C02 often tests the distinction between Secrets Manager and Parameter Store. Candidates might choose Parameter Store because it's cheaper, but the question emphasizes secure storage and retrieval of database credentials, where Secrets Manager's rotation and management features are key.

How to eliminate wrong answers

Option A is wrong because Amazon S3 with server-side encryption is for storing objects, not managing secrets; it lacks automatic rotation and fine-grained access policies for secrets. Option B is wrong because AWS Systems Manager Parameter Store can store secrets, but it does not provide automatic rotation and is less feature-rich for secret management compared to Secrets Manager. Option D is wrong because AWS KMS is a key management service for encryption keys, not for storing and retrieving application secrets like database credentials.

597
MCQhard

A company uses AWS CloudFormation to deploy a multi-tier application. During an update, the stack fails and rolls back. The rollback also fails, leaving the stack in UPDATE_ROLLBACK_FAILED state. The operations team needs to resolve this with minimal disruption. What is the MOST efficient approach?

A.Use the 'ContinueUpdateRollback' API or AWS Management Console to retry the rollback.
B.Manually modify the resources to match the previous stack state.
C.Delete the stack and recreate it from the original template.
D.Execute a change set to update the stack to the desired configuration.
AnswerA

The Correct answer: The `ContinueUpdateRollback` API or the AWS Management Console action is specifically designed for stacks stuck in `UPDATE_ROLLBACK_FAILED`. It resumes the rollback from the point where it failed, skips resources that were already successfully rolled back, and can optionally skip resources you explicitly specify. This recovers the stack to its last known good state with minimal disruption, and it is the only built-in mechanism that directly resolves this status.

Why this answer

When a CloudFormation stack is stuck in UPDATE_ROLLBACK_FAILED, the supported recovery path is to call ContinueUpdateRollback (via API, CLI, or console) to resume the rollback, optionally skipping specific resources that are blocking it. This preserves the stack and its resources with minimal disruption.

Exam trap

DOP-C02 often tests whether candidates know that ContinueUpdateRollback is the only supported way out of UPDATE_ROLLBACK_FAILED — deleting the stack or running a change set sounds reasonable but is either destructive or blocked.

How to eliminate wrong answers

Option B is wrong because manually modifying resources to match the previous state does not update CloudFormation's internal state and can cause drift or further failures; it is not a supported recovery mechanism. Option C is wrong because deleting and recreating the stack destroys all resources and causes significant disruption, violating the 'minimal disruption' requirement. Option D is wrong because a change set cannot be executed while the stack is in UPDATE_ROLLBACK_FAILED — CloudFormation rejects updates until the rollback is resolved.

598
MCQhard

A company has a microservices architecture with 50 services running on Amazon ECS. The DevOps team wants to collect and analyze logs from all services centrally. They need to query logs across services and set up alerts for error patterns. Which solution is the most scalable and cost-effective?

A.Use AWS CloudTrail to capture all log events and store them in an S3 bucket for analysis
B.Deploy an Amazon Elasticsearch cluster and configure the ECS Fargate agent to send logs directly to Elasticsearch
C.Use the awslogs driver to send logs to Amazon CloudWatch Logs and use CloudWatch Logs Insights for querying and metric filters for alerts
D.Send logs to Amazon S3 and use Amazon Athena for querying, with scheduled queries for alerts
AnswerC

The awslogs driver natively ships ECS container logs to CloudWatch Logs, where Logs Insights queries across all 50 services and metric filters trigger alerts on error patterns. This satisfies centralised querying and alerting without managing extra infrastructure.

Why this answer

Using the awslogs driver to ship ECS container logs to Amazon CloudWatch Logs is the most scalable and cost-effective native solution. CloudWatch Logs Insights provides a query language for searching across log groups, and metric filters can trigger CloudWatch alarms on error patterns. This requires no cluster management, scales automatically with log volume, and integrates natively with ECS task definitions via the logConfiguration block.

Exam trap

DOP-C02 often tests whether candidates default to self-managed Elasticsearch or S3+Athena for log analytics when the native, lower-overhead CloudWatch Logs solution is the intended answer — the trap is over-engineering.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail captures API activity and management events, not application logs from ECS containers — it cannot collect microservice application output. Option B is wrong because deploying and managing a self-hosted Amazon Elasticsearch (now OpenSearch) cluster adds significant operational overhead and cost, and sending logs directly from Fargate tasks bypasses the managed ingestion path, making it less scalable and more expensive than CloudWatch Logs. Option D is wrong because sending logs to S3 and querying with Athena introduces latency (Athena is not real-time), requires schema/partition management, and lacks native alerting — scheduled queries are a poor substitute for CloudWatch metric filters and alarms.

599
MCQhard

A company deploys the above CloudFormation stack. They want to enforce HTTPS for all requests to the S3 bucket. After deployment, users are still able to make HTTP requests. What is the problem?

A.The condition key 'aws:SecureTransport' is misspelled; it should be 'aws:SecureTransport' with a capital 'T'
B.The bucket is not versioned, so the policy does not apply to object versions
C.The policy uses Deny, but an Allow policy from another statement overrides it
D.The Deny statement's Resource specifies only the objects, not the bucket itself
AnswerD

The Resource does not include the bucket ARN, so bucket-level operations like ListBucket are not denied.

Why this answer

The Deny statement in the bucket policy uses `arn:aws:s3:::example-bucket/*` as the Resource, which applies only to objects within the bucket, not to the bucket itself. To enforce HTTPS for all requests, including those to the bucket endpoint (e.g., `GET /` or `PUT /`), the Resource must also include the bucket ARN without the `/*` suffix. Without it, HTTP requests targeting the bucket itself (such as listing objects or configuring website hosting) are not denied, allowing HTTP access to bypass the policy.

Exam trap

The trap here is that candidates assume a Deny statement on `/*` covers all requests, but they overlook that the bucket ARN itself must be explicitly included to enforce HTTPS on bucket-level operations, not just object operations.

How to eliminate wrong answers

Option A is wrong because `aws:SecureTransport` is correctly spelled with a capital 'S' and capital 'T' — the condition key is case-sensitive and must be exactly `aws:SecureTransport`. Option B is wrong because versioning is irrelevant to enforcing HTTPS; bucket policies apply to all object versions regardless of versioning status, and the Deny statement would still apply to `/*` resources. Option C is wrong because an explicit Deny in a bucket policy always overrides any Allow, regardless of other statements, per IAM policy evaluation logic (Deny is evaluated first and is definitive).

600
MCQhard

A company uses AWS CodeBuild to run integration tests. The tests require access to an RDS database in a private subnet. CodeBuild runs in a VPC but the build times out waiting for the database connection. What is the MOST likely cause?

A.CodeBuild cannot access resources in a private subnet unless it uses a NAT gateway.
B.The CodeBuild service role does not have rds:Connect permission.
C.The CodeBuild project's security group outbound rules do not allow traffic to the RDS security group on port 3306 (or appropriate port).
D.The RDS instance is in a different subnet CIDR than CodeBuild's subnet.
AnswerC

Correct: When CodeBuild is attached to a VPC, the build container uses an elastic network interface with the project's security group. The outbound rules on that security group must explicitly allow TCP traffic to the RDS security group on the database port (e.g., 3306 for MySQL or 5432 for PostgreSQL). If the outbound rule is missing, the packets are silently dropped, causing a timeout even though the RDS inbound rule and IAM role are correct. Since security groups are stateful, the response path is automatically allowed once the inbound rule on RDS accepts the request, but the initial outbound allowance is still required.

Why this answer

CodeBuild's security group outbound rules must explicitly allow traffic to the RDS security group on the database port (e.g., 3306 for MySQL). Even though CodeBuild runs in a VPC, if the outbound rules are too restrictive, the build agent cannot establish a TCP connection to the RDS instance, causing a timeout. The security group acts as a virtual firewall for the CodeBuild ENI, and without a matching outbound rule, packets are dropped.

Exam trap

The trap here is that candidates often assume IAM permissions (like rds:Connect) control network access, but RDS network access is governed solely by security groups and VPC routing, not IAM.

How to eliminate wrong answers

Option A is wrong because CodeBuild can access resources in a private subnet directly when it is launched in the same VPC; a NAT gateway is only needed for outbound internet access, not for VPC-internal traffic. Option B is wrong because IAM permissions like rds:Connect do not exist; RDS access is controlled by security group rules and database credentials, not IAM actions for network connectivity. Option D is wrong because subnets with different CIDRs can still communicate within the same VPC via the VPC router, as long as route tables and security groups permit the traffic.

Page 7

Page 8 of 18

Page 9