Courseiva

AWS Certified DevOps Engineer Professional DOP-C02 (DOP-C02) — Questions 601–675

1298 questions total · 18pages · All types, answers revealed

Page 8

Page 9 of 18

Page 10
601
MCQmedium

A DevOps engineer is designing a CI/CD pipeline for a containerized application using AWS CodePipeline and Amazon ECS. The pipeline should build a Docker image, push it to Amazon ECR, and deploy it to an ECS service. Which deployment action should they use in the pipeline?

A.AWS Elastic Beanstalk deployment action.
B.AWS CodeBuild with a buildspec that runs aws ecs update-service.
C.Amazon ECS (Blue/Green) deployment provider with CodeDeploy.
D.AWS CloudFormation deployment action to update the ECS service.
AnswerC

Amazon ECS (Blue/Green) with CodeDeploy is the correct native deployment provider for ECS in CodePipeline. CodeDeploy's ECS compute platform orchestrates the creation of a green task set, shifts traffic from the blue target group to the green target group in either linear or canary increments, and performs post-traffic-shift validation hooks defined in an AppSpec file. It also supports automatic rollback if the deployment fails health checks, making it the ideal, fully integrated choice for ECS blue/green deployments in a pipeline.

Why this answer

Amazon ECS (Blue/Green) deployment provider with CodeDeploy is the native, fully managed deployment action in AWS CodePipeline for ECS services. It orchestrates traffic shifting, task set management, and rollback automatically using CodeDeploy's ECS blue/green deployment type, which is the recommended approach for containerized applications on ECS.

Exam trap

The trap here is that candidates often confuse the ECS (Blue/Green) deployment provider with a simple 'update-service' command, not realizing that CodePipeline requires a native deployment provider to support automated traffic shifting, rollback, and integration with CodeDeploy's lifecycle hooks.

How to eliminate wrong answers

Option A is wrong because AWS Elastic Beanstalk deployment action is designed for Elastic Beanstalk environments, not for ECS services; it cannot directly deploy to an ECS cluster or service. Option B is wrong because while CodeBuild can run aws ecs update-service, this approach bypasses CodePipeline's deployment tracking, rollback capabilities, and traffic shifting; it is a custom script, not a native deployment action. Option D is wrong because AWS CloudFormation deployment action updates CloudFormation stacks, not ECS services directly; it would require wrapping the ECS service update in a CloudFormation template, adding unnecessary complexity and losing the built-in deployment features of CodeDeploy.

602
MCQmedium

A DevOps engineer manages a fleet of EC2 instances in a private subnet. The instances must access an Amazon S3 bucket to read configuration files. The security team requires that all traffic to S3 be encrypted in transit and that the EC2 instances do not use the public internet. The engineer has already created an S3 gateway endpoint and attached it to the VPC route table. Which additional step should the engineer take to meet these requirements?

A.Modify the S3 bucket policy to deny requests where aws:SecureTransport is false.
B.Configure the EC2 instances to use an S3 interface endpoint instead of the gateway endpoint.
C.Attach an IAM role to the EC2 instances that allows s3:GetObject on the bucket.
D.Enable default encryption on the S3 bucket using AES-256.
AnswerA

Adding a bucket policy that denies requests when aws:SecureTransport is false enforces HTTPS for all access to the bucket. Combined with the gateway endpoint, traffic stays within the AWS network and is encrypted in transit. This directly meets both the encryption and private connectivity requirements.

Why this answer

The gateway endpoint provides private network routing, but encryption in transit must be enforced separately. A bucket policy that denies requests when aws:SecureTransport is false ensures that only HTTPS requests are allowed, satisfying the encryption requirement. IAM roles handle authorization, interface endpoints are an alternative connectivity method, and default encryption addresses data at rest, not in transit.

Exam trap

The trap here is assuming that a VPC gateway endpoint automatically encrypts traffic to S3, when it only provides private routing and still allows unencrypted HTTP requests unless a bucket policy enforces secure transport.

603
Multi-Selectmedium

A company wants to audit all changes to IAM policies in their AWS account. Which THREE services can be used to capture and alert on IAM policy changes? (Choose THREE.)

Select 3 answers
A.AWS Config
B.AWS CloudTrail
C.AWS Trusted Advisor
D.Amazon EventBridge
E.Amazon Inspector
AnswersA, B, D

AWS Config records configuration items for AWS::IAM::Policy and related resources, building a configuration history that shows exactly how IAM policy documents changed over time. It evaluates those configurations against custom or managed rules to detect noncompliant policies. This provides a persistent, queryable state timeline, which is the definitive way to audit all IAM policy changes after the fact.

Why this answer

AWS Config is correct because it continuously records resource configuration changes, including IAM policy changes, and can evaluate them against rules or configuration snapshots to detect and audit modifications. AWS CloudTrail is correct because it logs all API activity in the account, including IAM policy creation, modification, and deletion events (e.g., CreatePolicy, PutRolePolicy, AttachRolePolicy), providing the authoritative audit trail. Amazon EventBridge is correct because it can receive CloudTrail management events and match IAM policy change events via event patterns, then route them to targets such as SNS or Lambda for alerting.

AWS Trusted Advisor is not correct because it provides best-practice checks and recommendations, not a change audit or alerting mechanism for IAM policies. Amazon Inspector is not correct because it is a vulnerability management service that scans EC2 instances, container images, and Lambda functions, and does not capture IAM policy changes.

Exam trap

DOP-C02 often tests service-role confusion — candidates pick Inspector or Trusted Advisor for 'audit/alert' questions because they sound security-related, but only Config, CloudTrail, and EventBridge actually capture and act on IAM change events.

604
MCQhard

A company uses AWS CloudFormation to manage infrastructure. They want to deploy a stack that creates an Amazon RDS DB instance. The database password must be stored securely and rotated automatically. Which approach meets these requirements?

A.Hardcode the password in the CloudFormation template and use a NoEcho parameter.
B.Use AWS Key Management Service (KMS) to encrypt the password and pass it as a parameter.
C.Store the password in AWS Systems Manager Parameter Store and reference it using a dynamic reference.
D.Store the password in AWS Secrets Manager and enable automatic rotation. Reference the secret in the template using a dynamic reference.
AnswerD

AWS Secrets Manager offers native automatic rotation through a configured Lambda function, allowing the password to be rotated on a schedule independent of CloudFormation. Referencing the secret with a dynamic reference such as {{resolve:secretsmanager:MySecret:SecretString:password}} retrieves the current value at deployment time without embedding plaintext or ciphertext in the template. This combines secure storage, versioning, managed rotation, and clean CloudFormation integration, which makes it the correct choice.

Why this answer

AWS Secrets Manager provides built-in capabilities for automatic password rotation, which is a requirement. By storing the password in Secrets Manager and referencing it in the CloudFormation template using a dynamic reference (e.g., `{{resolve:secretsmanager:secret-id:SecretString:password}}`), the password is never exposed in the template or parameter logs, and rotation can be configured without updating the stack. This approach meets both security and automation requirements.

Exam trap

The trap here is that candidates confuse AWS Systems Manager Parameter Store with AWS Secrets Manager, assuming both support automatic rotation, but only Secrets Manager provides native rotation capabilities for RDS credentials.

How to eliminate wrong answers

Option A is wrong because hardcoding the password in the template, even with NoEcho, still exposes the password in the template source code and does not support automatic rotation. Option B is wrong because passing the password as a parameter, even if encrypted with KMS, does not enable automatic rotation and the plaintext value may be logged in AWS CloudTrail or parameter history. Option C is wrong because AWS Systems Manager Parameter Store does not support automatic rotation of secrets; it is a parameter store, not a secrets manager with rotation capabilities.

605
MCQmedium

A company uses AWS CodeBuild to compile and test code. The build takes 30 minutes, but the team wants to reduce build time by caching dependencies. Which approach should be used?

A.Remove unnecessary dependencies from the build specification.
B.Store dependencies in an S3 bucket and download them before each build.
C.Use AWS CodeArtifact to store dependencies and pull them during build.
D.Enable local caching in the build project configuration.
AnswerD

Enabling local caching in the CodeBuild project configuration is the officially supported way to reuse dependencies across builds. You set a cache type that includes LOCAL_CUSTOM (or use the combined LOCAL option in newer versions) and define a cache directory—for example, /root/.m2 for Maven or /root/.npm for npm—so CodeBuild saves that directory after one build and restores it at the start of the next. This avoids re-downloading or recompiling unchanged dependencies, significantly reducing build time while requiring no custom scripting or external services.

Why this answer

AWS CodeBuild's local caching feature allows you to cache intermediate build artifacts (such as dependencies) in a local directory on the build instance, which persists across builds for the same build project. This eliminates the need to re-download dependencies from external sources for every build, significantly reducing build time. The cache is stored in a Docker volume or S3 bucket, but the key benefit is that it is automatically managed by CodeBuild without manual download steps.

Exam trap

The trap here is that candidates may confuse caching with simply storing artifacts externally (like S3 or CodeArtifact) and fail to recognize that CodeBuild's local caching is the only option that eliminates the download overhead by persisting dependencies on the build instance itself.

How to eliminate wrong answers

Option A is wrong because removing unnecessary dependencies from the build specification is a good practice but does not address caching of existing dependencies; it reduces the total amount of dependencies but does not speed up the download of those that remain. Option B is wrong because storing dependencies in an S3 bucket and downloading them before each build still incurs network transfer time and does not leverage CodeBuild's built-in caching mechanism; it is a manual workaround that adds complexity and latency. Option C is wrong because AWS CodeArtifact is a managed artifact repository service for storing and retrieving packages, but it does not inherently cache dependencies on the build instance; using it still requires a download step during each build, which does not reduce build time as effectively as local caching.

606
MCQhard

A company uses AWS CloudFormation to manage a stack that includes an Auto Scaling group with a LaunchTemplate. The DevOps team wants to update the LaunchTemplate with a new AMI. The stack update fails with the error 'Launch template version does not exist'. What is the most likely cause?

A.The LaunchTemplate was recently modified and the new version is not yet available
B.The LaunchTemplate version specified in the template was deleted
C.The target group attachment is incorrect
D.The Auto Scaling group is using a different launch template
AnswerB

The most direct cause of a 'LaunchTemplate version not found' error during stack update or creation is that the exact version number specified in the CloudFormation template has been deleted. Launch template versions are immutable but can be manually deleted (except the default version) when no longer needed, and CloudFormation validates that the referenced version exists before provisioning resources. Once deleted, any stack operation referencing that version fails because the template is effectively trying to instantiate a non-existent configuration.

Why this answer

The error 'Launch template version does not exist' occurs when the CloudFormation template references a specific launch template version number that has been deleted. Launch template versions are immutable but can be deleted, and if the stack template or parameter references a deleted version, the stack update fails.

Exam trap

DOP-C02 often tests whether candidates understand that launch template versions are immutable and can be deleted, and that CloudFormation references to a deleted version cause this specific error — candidates may incorrectly blame propagation delays or target group issues.

How to eliminate wrong answers

Option A is wrong because launch template versions are available immediately upon creation — there is no propagation delay that would cause this error. Option C is wrong because an incorrect target group attachment would produce a different error (e.g., 'Target group not found' or 'Invalid target group'), not a launch template version error. Option D is wrong because the Auto Scaling group using a different launch template would not cause a 'version does not exist' error; it would simply use the other template, and CloudFormation would not fail with that message.

607
MCQeasy

A DevOps engineer is troubleshooting a slow-running Lambda function. The function processes messages from an SQS queue. Which CloudWatch metric should be examined first to determine if the function is experiencing throttling?

A.Invocations
B.ConcurrentExecutions
C.Duration
D.Throttles
AnswerD

The Throttles metric is the definitive CloudWatch counter for how many invocation requests Lambda rejected because the function had no available concurrency capacity. Each time Lambda receives a request while the function or account is over its concurrency limit, it increments Throttles and returns a 429 TooManyRequestsException, prompting SDK retries or event-source retry logic. For a slow-running function, elevated Throttles explains intermittent delays caused by client-side retries, making this the correct metric to inspect when troubleshooting such issues.

Why this answer

The Throttles metric directly indicates when Lambda is rejecting invocation requests due to concurrency limits being reached. Since the question asks specifically about throttling, this is the first metric to examine to confirm whether the function is being rate-limited by AWS.

Exam trap

The trap here is that candidates may confuse high ConcurrentExecutions with throttling, but throttling is a separate metric that directly counts rejected invocations, not the number of concurrent runs.

How to eliminate wrong answers

Option A is wrong because Invocations counts total function invocations, including successful ones, and does not indicate throttling events. Option B is wrong because ConcurrentExecutions shows the number of function instances running at a given time, but it does not directly measure throttling; high concurrency can lead to throttling but the metric itself is not the throttling indicator. Option C is wrong because Duration measures how long the function runs, which can be affected by throttling indirectly but is not a direct measure of throttling events.

608
MCQhard

A DevOps engineer manages a production environment with EC2 instances behind an Application Load Balancer (ALB). The application logs show intermittent 5xx errors from the ALB. The engineer needs to identify whether the errors originate from the targets or the ALB itself. Which CloudWatch metric should be examined to differentiate between these two sources?

A.TargetResponseTime
B.UnhealthyHostCount
C.HTTPCode_Target_5XX_Count
D.RequestCount
AnswerC

HTTPCode_Target_5XX_Count is the correct choice because it represents the number of HTTP responses with a 5xx status code that were returned by registered targets (e.g., EC2 instances) to the Application Load Balancer. This metric excludes 5xx errors generated by the ALB itself, such as 502 Bad Gateway or 503 Service Unavailable from the load balancer when no healthy targets exist. By checking this metric with a Sum statistic, the engineer can directly quantify application-level server errors and distinguish them from load-balancer-level failures.

Why this answer

HTTPCode_Target_5XX_Count, is the correct metric to identify 5xx errors originating from the targets (EC2 instances). The ALB has separate metrics for target errors (HTTPCode_Target_5XX_Count) and ALB errors (HTTPCode_ELB_5XX_Count). Option A (TargetResponseTime) measures latency, not error codes.

Option B (UnhealthyHostCount) counts unhealthy targets based on health checks, not specific HTTP errors. Option D (RequestCount) is total requests, not error codes.

609
Multi-Selecteasy

A DevOps engineer is setting up a CI/CD pipeline for a Python application using AWS CodePipeline. The pipeline includes a build stage with CodeBuild and a deploy stage that runs an AWS CLI command to update a Lambda function. Which THREE steps are necessary to ensure the pipeline can update the Lambda function? (Choose 3)

Select 3 answers
A.Store the AWS CLI command in the buildspec file or as a separate script in the source repository.
B.Grant the CodePipeline service role permission to pass the CodeBuild IAM role to CodeBuild.
C.Configure a CloudWatch Events rule to trigger the pipeline when the Lambda function is updated.
D.Create an IAM role for CodeBuild that includes permissions to invoke 'lambda:UpdateFunctionCode'.
E.Use AWS CodeDeploy instead of the AWS CLI to update the Lambda function.
AnswersA, B, D

The AWS CLI command that updates the Lambda function must be defined in the buildspec file or in a script committed to the source repository. CodeBuild executes the buildspec during the build phase, so placing the command there ensures it is run as part of the pipeline after the artifact is produced. Keeping it in source control also makes the deployment step reproducible, auditable, and versioned alongside the application code.

Why this answer

The AWS CLI command to update the Lambda function must be defined in the buildspec file or as a script in the source repository so that CodeBuild can execute it during the deploy stage. This ensures the pipeline has the exact command to run, and it becomes part of the version-controlled build specification.

Exam trap

The trap here is that candidates might think a CloudWatch Events trigger is needed to initiate the update, but the pipeline itself is the orchestrator; the real requirement is proper IAM permissions and command definition within the buildspec.

610
MCQmedium

Refer to the exhibit. A DevOps engineer sees the following error when trying to update a CloudFormation stack: 'Stack [arn:aws:cloudformation:us-west-2:123456789012:stack/MyStack/abc123] is in ROLLBACK_COMPLETE state and can not be updated.' What should the engineer do to proceed?

A.Run 'aws cloudformation continue-update-rollback' to finish the rollback and then update.
B.Modify the stack's template and try the update again.
C.Use the 'aws cloudformation resume-update' command to resume the update.
D.Delete the stack and create a new one with the updated template.
AnswerD

The `ROLLBACK_COMPLETE` state is terminal: the stack still exists in CloudFormation, but the failed create or update operation has rolled back, leaving no functional infrastructure from that attempt. CloudFormation will not accept `update-stack` or change-set execution from this state, so the only supported recovery path is to delete the stack and create a new one using the updated template. Recreating the stack provides a clean, deterministic provisioning pass and avoids inconsistent resource states.

Why this answer

When a CloudFormation stack reaches the ROLLBACK_COMPLETE state, it means the stack creation or update failed and the rollback has finished, leaving the stack in a terminal state. CloudFormation does not allow updates or rollback continuation on stacks in this state. The only supported action is to delete the stack and create a new one with the corrected template, as stated in the AWS documentation.

Exam trap

The trap here is that candidates confuse ROLLBACK_COMPLETE with ROLLBACK_IN_PROGRESS or UPDATE_ROLLBACK_FAILED, assuming they can resume or continue the rollback, but AWS explicitly prevents any operation on a stack in a terminal rollback state.

How to eliminate wrong answers

Option A is wrong because the 'continue-update-rollback' command is only valid for stacks in the UPDATE_ROLLBACK_FAILED or ROLLBACK_IN_PROGRESS states, not ROLLBACK_COMPLETE. Option B is wrong because modifying the template and retrying the update will still fail, as CloudFormation rejects any update attempt on a stack in ROLLBACK_COMPLETE state. Option C is wrong because there is no 'resume-update' command in the AWS CLI; the correct command for resuming an update is 'continue-update-rollback', which is not applicable here.

611
MCQhard

A company runs a web application on EC2 behind an Application Load Balancer (ALB). They want to protect against SQL injection and cross-site scripting (XSS) attacks. Which AWS service should they use?

A.Configure security groups to allow only HTTP/HTTPS traffic.
B.Configure network ACLs to block common attack patterns based on IP ranges.
C.Deploy AWS WAF in front of the ALB and create rules to block SQL injection and XSS.
D.Enable AWS Shield Advanced to protect the ALB.
AnswerC

AWS WAF is an application-layer firewall that can be associated with an Application Load Balancer and inspects each HTTP/HTTPS request for suspicious patterns. You can create custom rules and use AWS-managed rule groups such as AWSManagedRulesSQLiRuleSet and AWSManagedRulesCommonRuleSet to automatically block SQL injection, cross-site scripting, and other common web exploits. These rules evaluate request components like headers, query strings, body, and cookies, which is exactly what is needed to stop these attacks before they reach the EC2 instances.

Why this answer

AWS WAF is a web application firewall that integrates directly with Application Load Balancers to inspect HTTP/HTTPS requests for common attack patterns. It provides managed rule sets specifically designed to block SQL injection and cross-site scripting (XSS) attacks at the application layer, which is exactly what this scenario requires.

Exam trap

The trap here is that candidates often confuse network-layer controls (security groups, NACLs) or DDoS protection (Shield) with application-layer filtering, failing to recognize that only a web application firewall like AWS WAF can inspect HTTP payloads for injection attacks.

How to eliminate wrong answers

Option A is wrong because security groups operate at the network layer (Layer 3/4) and only filter traffic based on IP addresses, ports, and protocols; they cannot inspect application-layer payloads for SQL injection or XSS patterns. Option B is wrong because network ACLs are stateless packet filters that also operate at the network layer and cannot parse HTTP request bodies or query strings for malicious content; blocking IP ranges does not prevent application-layer attacks. Option D is wrong because AWS Shield Advanced provides DDoS protection against volumetric and state-exhaustion attacks at the network and transport layers, but it does not include the application-layer inspection capabilities needed to detect and block SQL injection or XSS.

612
Multi-Selecthard

Which THREE components are necessary to implement a secure VPC with a public subnet and a private subnet that hosts a database? (Choose THREE.)

Select 3 answers
A.AWS Site-to-Site VPN connection.
B.Internet Gateway attached to the VPC.
C.NAT Gateway in the public subnet.
D.VPC Peering connection to a central VPC.
E.Security group for the database allowing traffic only from the application tier.
AnswersB, C, E

An Internet Gateway (IGW) is a horizontally scaled, redundant VPC component that provides bidirectional communication between the VPC and the internet. It is attached to the VPC and serves as the target for the 0.0.0.0/0 route in public subnet route tables, enabling resources with public IPs to send and receive internet traffic. Additionally, the IGW is a prerequisite for a NAT Gateway, because the NAT Gateway itself resides in the public subnet and relies on the IGW for outbound internet forwarding. Without an IGW, neither public nor private instances could reach the internet.

Why this answer

Option B is correct because an Internet Gateway attached to the VPC is required to give the public subnet's resources (such as a bastion host or load balancer) inbound and outbound connectivity to the internet. Option C is correct because a NAT Gateway placed in the public subnet allows instances in the private subnet to initiate outbound traffic (for patching, updates, etc.) to the internet without being directly reachable from it. Option E is correct because a security group on the database that permits traffic only from the application tier enforces least-privilege, instance-level access control, which is essential for securing the database in the private subnet.

Option A is not required because a Site-to-Site VPN is for connecting on-premises networks to AWS, not for building public/private subnet architecture. Option D is not required because VPC peering connects separate VPCs and is unrelated to creating public and private subnets within a single VPC.

Exam trap

DOP-C02 often tests whether candidates include unnecessary components like VPN or peering, when the core requirements are IGW, NAT Gateway, and security group scoping.

613
MCQeasy

A DevOps engineer is tasked with setting up a centralized logging solution for a multi-account AWS environment. Which service should be used to aggregate logs from multiple accounts?

A.Amazon S3 with cross-region replication
B.AWS CloudTrail with organization trails
C.Amazon CloudWatch Logs with cross-account subscription
D.AWS Config with aggregated compliance rules
AnswerC

Amazon CloudWatch Logs cross-account subscriptions let you forward log events from multiple source accounts to a central destination (via a Kinesis Data Stream or Data Firehose) using subscription filters, enabling near-real-time aggregation of application logs. This is the correct pattern because it directly receives application log streams from existing CloudWatch Logs agents and routes them to a central account for storage and analysis.

Why this answer

Amazon CloudWatch Logs can aggregate logs across accounts using cross-account subscriptions with a central destination (e.g., Kinesis or Lambda). Option C is correct. Option A is incorrect because S3 is a storage service, not for real-time aggregation.

Option B is incorrect as CloudTrail is for API activity, not application logs. Option D is incorrect because AWS Config is for configuration compliance.

614
MCQhard

Refer to the exhibit. A CodeBuild project uses this buildspec.yml to build and push a Docker image to Amazon ECR. The build fails at the pre_build phase with the error 'Error: Cannot perform an interactive login from a non TTY device'. What is the MOST likely issue?

A.The AWS_DEFAULT_REGION environment variable is not set in CodeBuild.
B.The CodeBuild project's IAM role does not have permission to call ecr:GetAuthorizationToken.
C.The buildspec.yml is missing the 'docker login' command.
D.The Docker daemon is not running on the CodeBuild instance.
AnswerB

The build's `aws ecr get-login-password` command makes an ECR Authorization API call that requires the `ecr:GetAuthorizationToken` permission on the build project's service role. If that IAM policy is missing or doesn't allow the action, the CLI exits with an `AccessDeniedException` and no password is returned, causing the subsequent `docker login` to fail with invalid or empty credentials. This is the classic cause of ECR login failures in CodeBuild.

Why this answer

The error 'Cannot perform an interactive login from a non TTY device' occurs when the `docker login` command is invoked without receiving the password via stdin. In the buildspec, `aws ecr get-login-password` is used to retrieve the password and pipe it to `docker login`. If the CodeBuild project's IAM role lacks the `ecr:GetAuthorizationToken` permission, this command fails silently or returns an error, causing `docker login` to fall back to interactive mode.

Since CodeBuild runs in a non‑interactive environment, it throws the TTY error. Option B is correct because the missing permission prevents the password retrieval, leading to the login failure. Options A, C, and D do not directly cause this specific error.

615
MCQeasy

A company wants to ensure that all S3 buckets are encrypted at rest by default. Which S3 feature should be enabled at the bucket level to automatically encrypt new objects?

A.S3 Object Lock
B.Bucket policy with a Deny for unencrypted uploads
C.S3 Versioning
D.Default encryption
AnswerD

Default encryption is a bucket-level setting that automatically applies server-side encryption (SSE-S3 or SSE-KMS) to all new objects, even when the upload request does not include encryption headers. When enabled, every PUT that does not explicitly specify an encryption method is wrapped with the bucket's configured encryption, thereby ensuring new objects are encrypted at rest. Note that default encryption only affects objects uploaded after the setting is enabled; existing objects require rewriting or a copy operation to be encrypted. It is the only option that actively encrypts data without relying on client behavior.

Why this answer

S3 default encryption allows you to set a default encryption behavior for a bucket, so that all new objects are encrypted at rest automatically. Bucket policies can enforce encryption but do not automatically encrypt. Object lock is for retention.

Versioning is for object versions.

616
Multi-Selecthard

A company uses AWS CloudFormation StackSets to deploy resources across multiple accounts and regions. They need to ensure that updates to the stack set are rolled out in a controlled manner, with the ability to roll back if errors occur. Which THREE strategies should they implement? (Choose THREE.)

Select 3 answers
A.Use a canary deployment strategy by updating only a subset of accounts first
B.Set a failure tolerance to allow a certain number of stack operation failures before the overall operation fails
C.Pause stack instances manually if errors are detected
D.Configure region concurrency to control how many regions are updated at a time
E.Set the maximum concurrent accounts to control how many accounts are updated simultaneously
AnswersB, D, E

Failure tolerance specifies how many stack instance failures (as an absolute number or a percentage of total stack instances) are acceptable before the entire StackSet operation is considered failed. When this threshold is exceeded, StackSets automatically rolls back all successfully deployed stack instances, allowing you to absorb a limited number of transient errors without halting the whole deployment. This is the primary safety control for managing partial deployment success.

Why this answer

Option B is correct because StackSets support a failure tolerance parameter that defines how many stack instance operations may fail before the entire stack set operation is considered failed and rolled back, enabling controlled error handling. Option D is correct because region concurrency (MaximumConcurrentPercentage or a specific number of regions) lets you limit how many regions are updated in parallel, reducing blast radius and allowing controlled rollout across regions. Option E is correct because maximum concurrent accounts controls how many accounts within each region are updated simultaneously, which is the primary mechanism for throttling and controlling the pace of stack set updates.

Option A is not correct because CloudFormation StackSets do not provide a native canary deployment feature; controlled rollout is achieved through concurrency and failure tolerance settings rather than a built-in canary mode. Option C is not correct because manually pausing stack instances is not a supported StackSets control mechanism; rollback and failure handling are governed by failure tolerance and concurrency parameters, not manual pausing.

Exam trap

The trap here is that candidates often confuse the canary deployment concept (Option A) with StackSets' ability to target specific accounts or OUs, but StackSets does not natively support canary rollouts—you would need to implement that manually with separate stack sets or custom automation.

617
MCQmedium

A DevOps engineer is troubleshooting a CloudFormation stack that fails to create an EC2 instance with a custom AMI. The error message indicates that the AMI ID does not exist. The engineer is using a mapping in the template to select the AMI based on the region. However, the stack is being created in a region not covered by the mapping. What is the most efficient way to resolve this issue?

A.Retrieve the AMI ID dynamically using AWS Systems Manager Parameter Store and a dynamic reference in the template.
B.Create a new mapping entry for the region by updating the template.
C.Use AWS Systems Manager Run Command to find the correct AMI ID.
D.Hardcode the AMI ID in the template for the missing region.
AnswerA

Dynamic references resolve the AMI at deploy time from Parameter Store, so the template no longer depends on a static region mapping. This satisfies the region-agnostic constraint, letting the stack create successfully in any region without maintaining per-region map entries.

Why this answer

The most efficient way is to use AWS Systems Manager Parameter Store with a dynamic reference in the CloudFormation template. This allows the AMI ID to be resolved at deployment time based on the region, without hardcoding or maintaining mappings. Option B (creating a new mapping) is less efficient because it requires manual updates for each region.

Option C (Run Command) is not designed for parameter retrieval. Option D (hardcoding) is not scalable and error-prone.

618
MCQmedium

A DevOps team uses AWS CodePipeline to deploy a web application. The pipeline has a deploy stage that uses CodeDeploy to deploy to an Auto Scaling group. During deployment, the new instances fail health checks and the deployment rolls back. However, the rollback also fails because the old instances have been terminated. What should the team do to avoid this issue?

A.Increase the health check grace period in the Auto Scaling group.
B.Add a manual approval step before the deploy stage.
C.Configure the pipeline to deploy to a new Auto Scaling group each time.
D.Use a blue/green deployment strategy in CodeDeploy to keep the old instances running until the new ones pass health checks.
AnswerD

A blue/green deployment creates a fresh set of green instances beside the original blue instances, and traffic is shifted to the green fleet only after it successfully passes the configured health checks. If the green instances fail, CodeDeploy can keep the blue fleet available and immediately route traffic back to it, giving you a deterministic rollback path that does not require re-deploying the old revision. This directly solves the problem in the question, because the old instances remain running and intact until the new ones are proven healthy, making rollback both possible and rapid.

Why this answer

A blue/green deployment strategy in CodeDeploy keeps the old (blue) instances running while the new (green) instances are provisioned and validated, so if the new instances fail health checks, the deployment can roll back to the still-running old instances. This avoids the scenario where in-place deployment terminates old instances before new ones are confirmed healthy, leaving nothing to roll back to. Blue/green also supports traffic shifting controls like all-at-once, linear, or canary.

Exam trap

DOP-C02 often tests the misconception that increasing health check grace periods or adding approvals solves rollback failures, when the real fix is preserving old instances via blue/green deployment.

How to eliminate wrong answers

Option A is wrong because increasing the health check grace period only delays health check evaluation; it does not prevent old instances from being terminated during an in-place deployment, so rollback would still fail if the new instances never become healthy. Option B is wrong because a manual approval step adds a gate before deployment but does not change the deployment mechanics — once approved, the in-place deployment still terminates old instances, so rollback failure remains possible. Option C is wrong because deploying to a new Auto Scaling group each time is essentially what blue/green does, but configuring the pipeline to do this manually is not the standard CodeDeploy feature and does not by itself provide the traffic shifting and rollback guarantees of blue/green; the correct answer is to use CodeDeploy's blue/green capability.

619
MCQmedium

An organization manages multiple AWS accounts using AWS Organizations. They want to enforce that all Amazon S3 buckets across accounts have versioning enabled. Which approach is the most scalable and least error-prone?

A.Use AWS Config rules to detect buckets without versioning and send alerts.
B.Create an SCP that denies s3:PutBucketVersioning if versioning is not enabled.
C.Deploy a CloudFormation StackSet to all accounts with a template that enables versioning.
D.Manually enable versioning on each bucket after creation.
AnswerB

An SCP attached at the root or OU can deny s3:PutBucketVersioning unless the request's VersioningState header is exactly 'Enabled', using a condition such as s3:x-amz-versioning. Because SCPs are evaluated before any IAM policies, a user in a member account cannot bypass this restriction even if their IAM policy allows the action, and the API call fails before any state change occurs. This preventive control enforces the organization-wide requirement that every bucket remain versioned, making it the correct answer.

Why this answer

A Service Control Policy (SCP) in AWS Organizations can deny the `s3:PutBucketVersioning` action unless versioning is already enabled, effectively preventing the creation or modification of buckets without versioning. This approach is scalable as it applies to all accounts in the organization automatically and is least error-prone because it enforces the policy at the API level, blocking non-compliant actions before they occur.

Exam trap

The trap here is that candidates often choose AWS Config (Option A) because it is a common detective control, but they overlook that SCPs provide preventive enforcement at the organization level, which is more scalable and less error-prone for enforcing mandatory configurations across all accounts.

How to eliminate wrong answers

Option A is wrong because AWS Config rules can only detect and alert on non-compliant buckets after they are created, not prevent the action, making it reactive and error-prone. Option C is wrong because a CloudFormation StackSet can enable versioning on existing buckets but does not prevent future creation of buckets without versioning, and it requires ongoing maintenance to cover new buckets. Option D is wrong because manually enabling versioning is not scalable, is highly error-prone, and violates the principle of automation required for multi-account management.

620
MCQmedium

A company uses AWS Secrets Manager to store database credentials. The security team requires that secrets be automatically rotated every 30 days. Which rotation strategy should the engineer configure to meet this requirement with minimal operational overhead?

A.Manually rotate the secret every 30 days using the AWS CLI.
B.Store the secret in AWS Systems Manager Parameter Store with a SecureString parameter.
C.Enable automatic rotation using the pre-built Lambda rotation function for the database type.
D.Enable automatic rotation with a custom Lambda function.
AnswerC

Secrets Manager's pre-built Lambda rotation function (e.g., for Amazon RDS MySQL, PostgreSQL, Oracle, or SQL Server) is the correct choice because it provides a fully managed, automated rotation pattern that requires minimal configuration. When you enable rotation, Secrets Manager executes the Lambda on a configurable schedule (e.g., every 30 days), and the function updates the database password and the stored secret atomically using the Secrets Manager rotation sequence (createSecret, setSecret, testSecret, finishSecret). This ensures the secret and the database remain in sync with no temporary breakage and no custom code to write or maintain.

Why this answer

AWS Secrets Manager supports automatic rotation using pre-built Lambda rotation functions tailored to specific database types (e.g., Amazon RDS MySQL, PostgreSQL, Aurora). Enabling this built-in rotation with a 30-day schedule meets the requirement with minimal operational overhead because AWS manages the Lambda function, rotation logic, and secret update. This is the standard, lowest-effort approach for database credential rotation.

Exam trap

DOP-C02 often tests the trade-off between pre-built and custom rotation — candidates may over-engineer by choosing a custom Lambda when the pre-built function already supports the database type with minimal overhead.

How to eliminate wrong answers

Option A is wrong because manual rotation via CLI is error-prone, does not scale, and introduces significant operational overhead — the opposite of the requirement. Option B is wrong because Systems Manager Parameter Store with SecureString does not natively support automatic rotation of database credentials; it stores parameters but lacks built-in rotation for RDS-style secrets. Option D is wrong because a custom Lambda function requires the engineer to write, test, and maintain rotation logic, increasing operational overhead compared to the pre-built function.

621
MCQhard

A DevOps engineer updates an ECS service via CloudFormation. The stack update fails with the message 'Resource update cancelled'. The engineer notices that the ECS service's desired count was temporarily reduced during the update. What is the most likely cause of the failure?

A.The ECS service's minimum healthy percent was set to 100, causing the desired count reduction to zero to be rejected.
B.The ECS service's target group had an unhealthy instance that prevented the deregistration.
C.The ECS service deployment circuit breaker was triggered due to a timeout.
D.The ECS service did not have the required IAM role to call ecs:UpdateService.
AnswerA

During a rolling update, CloudFormation temporarily sets the ECS service's desired count to zero to force a clean replacement of all tasks. If the service's minimumHealthyPercent is set to 100%, ECS cannot scale the current running tasks below 100% of the desired count, so the service scheduler rejects the desired count reduction and the CloudFormation update is cancelled. This is a common misconfiguration when engineers expect zero-downtime but inadvertently block the scale-in step.

Why this answer

The error 'Resource update cancelled' occurs because CloudFormation detected that the ECS service update was not progressing as expected. When the minimum healthy percent is set to 100, the deployment process cannot reduce the desired count to zero (or below the current running count) without violating the requirement that 100% of the tasks remain healthy. This causes the update to be cancelled as CloudFormation waits indefinitely for the deployment to complete, eventually timing out and rolling back.

Exam trap

The trap here is that candidates often confuse the 'Resource update cancelled' error with a permissions or circuit breaker issue, but the key clue is the temporary reduction in desired count, which directly points to a minimum healthy percent constraint that prevents the service from scaling down to zero.

How to eliminate wrong answers

Option B is wrong because an unhealthy instance in the target group would cause health check failures and potential deployment issues, but it would not directly cause a 'Resource update cancelled' error with a temporary desired count reduction; the error message specifically points to a deployment configuration issue, not a target group health issue. Option C is wrong because the deployment circuit breaker is a feature that rolls back a deployment when it detects a failure (e.g., tasks failing to start), but it would not cause the desired count to be temporarily reduced; the circuit breaker triggers after a deployment failure, not as a cause of the count reduction. Option D is wrong because a missing IAM role for ecs:UpdateService would result in an authorization error (e.g., 'AccessDenied') during the update, not a 'Resource update cancelled' error with a temporary desired count reduction; the update would fail immediately with a permissions error, not after a partial state change.

622
MCQhard

A DevOps team is configuring an Auto Scaling group for a web application behind an Application Load Balancer. The team wants to automatically replace instances that fail the health check. Which scaling policy should be used?

A.Target tracking scaling policy
B.Default health check replacement
C.Step scaling policy
D.Manual scaling
AnswerB

When the Auto Scaling group is configured with EC2 health checks or an attached Elastic Load Balancer's health checks, it automatically detects instances that become unhealthy. The default health check replacement behavior marks the failing instance as unhealthy, terminates it, and launches a replacement instance to restore desired capacity, all without manual intervention. This is the underlying mechanism that keeps the web tier healthy, making it the correct choice for replacing faulty instances.

Why this answer

The correct approach is not a scaling policy but the Auto Scaling group's built-in health check replacement functionality. When the Auto Scaling group is configured with ELB health checks, it automatically terminates and replaces instances that the Application Load Balancer marks unhealthy. No scaling policy is required for this behavior.

Exam trap

The trap is confusing scaling policies (which adjust capacity based on load metrics) with the automatic health check replacement, which is a default feature of Auto Scaling groups. Scaling policies are not involved in replacing unhealthy instances.

How to eliminate wrong answers

Option A is wrong because a target tracking scaling policy adjusts the desired capacity based on a metric (like CPU utilization or request count) to maintain a target value, not to replace individual failed instances. Option C is wrong because a step scaling policy adjusts capacity based on alarm breaches with defined step adjustments, which is designed for proactive scaling based on load changes, not for reactive replacement of unhealthy instances. Option D is wrong because manual scaling requires human intervention to adjust capacity and does not automatically replace failed instances, defeating the purpose of automated health check replacement.

623
MCQmedium

A company uses AWS CodePipeline with a source stage from GitHub (via CodeStar Connections). The pipeline has a build stage using AWS CodeBuild and a deploy stage using AWS CodeDeploy. The team wants to ensure that a new pipeline execution starts automatically whenever a pull request is merged into the main branch. Which configuration change should be made to meet this requirement?

A.Enable the 'Poll for source changes' option on the source action and set the poll interval to 1 minute.
B.Create an Amazon EventBridge rule that monitors GitHub pull request merge events and invokes the pipeline via a Lambda function.
C.Add a manual approval action before the source stage that triggers the pipeline when a pull request is merged.
D.Configure the CodeStar Connection to use a webhook that triggers the pipeline on push events to the main branch.
AnswerD

CodeStar Connections automatically create webhooks for GitHub repositories. When a push event occurs on the configured branch (e.g., main), the webhook triggers the pipeline. Merging a pull request results in a push to the main branch, so the pipeline starts. This is the intended and supported integration for GitHub sources in CodePipeline.

Why this answer

For GitHub sources, CodePipeline uses CodeStar Connections, which create webhooks. When a pull request is merged, a push event to the target branch occurs, and the webhook automatically starts the pipeline. This is the native, recommended method.

Polling is not supported for connections, and custom EventBridge rules or manual approvals do not provide automatic triggering.

Exam trap

The trap here is assuming that polling or manual approvals are required to detect merges, when CodeStar Connections already provide webhook-based automatic triggering.

624
Multi-Selecthard

A DevOps team needs to enforce that all S3 buckets in an AWS account are encrypted at rest. Which THREE steps should be taken to achieve this? (Choose THREE.)

Select 3 answers
A.Configure AWS Config rules to detect buckets without encryption
B.Use an S3 bucket policy to deny PutObject requests that do not include encryption headers
C.Enable S3 server access logging
D.Enable default encryption on each S3 bucket
E.Enable S3 Transfer Acceleration
AnswersA, B, D

AWS Config's managed rule s3-bucket-server-side-encryption-enabled detects buckets where default encryption is disabled and continuously evaluates the account's infrastructure. When a noncompliant bucket is found, Config can trigger a remediation action, such as an AutoRemediate SSM document that enables default encryption, turning detection into corrective enforcement. This is a control-plane enforcement of encryption at the bucket level, rather than preventing unencrypted object writes.

Why this answer

Option A is correct because AWS Config managed rules such as s3-bucket-server-side-encryption-enabled continuously evaluate buckets and flag any that lack default encryption, giving the team the detection and compliance visibility needed to enforce encryption at rest. Option B is correct because an S3 bucket policy with a Deny effect on s3:PutObject when the request lacks the s3:x-amz-server-side-encryption condition (or aws:SecureTransport-style encryption conditions) blocks unencrypted uploads, actively enforcing encryption for objects written to the bucket. Option D is correct because enabling default encryption (SSE-S3/AES-256 or SSE-KMS) on each bucket ensures all objects are encrypted at rest automatically, even if clients do not specify encryption headers.

Option C is not correct because S3 server access logging only records request details for auditing; it does not detect or enforce encryption. Option E is not correct because S3 Transfer Acceleration only speeds up uploads over long distances using edge locations and has no bearing on encryption at rest.

Exam trap

The trap is selecting tangential S3 features (access logging, Transfer Acceleration) that sound security- or performance-related but do not enforce or detect encryption at rest.

625
Multi-Selectmedium

A company needs to audit all changes to IAM policies in their AWS account. Which services can be used to track and log these changes? (Select TWO.)

Select 2 answers
A.Amazon S3
B.Amazon CloudWatch Logs
C.AWS Config
D.AWS CloudTrail
E.Amazon GuardDuty
AnswersC, D

AWS Config is purpose-built for recording and evaluating configuration changes to AWS resources, including IAM policies. It continuously records the configuration state of IAM users, roles, groups, and their attached or inline policies, and maintains a configuration history with a timeline for each resource. You can query the configuration timeline to see what the policy document looked like before and after each change, making it the ideal service for auditing all changes to IAM policies.

Why this answer

AWS CloudTrail logs API calls, including IAM policy changes. AWS Config can track configuration changes to IAM resources. CloudWatch Logs stores logs but does not track changes itself.

GuardDuty is for threat detection. S3 is storage.

626
MCQhard

A company needs to enforce that all EC2 instances launched in an AWS account use a specific Amazon Machine Image (AMI) that is approved by the security team. Which combination of services should be used?

A.AWS Organizations SCP and AWS CloudTrail
B.AWS Config rule to check AMI ID and AWS Systems Manager Automation to remediate non-compliant instances
C.AWS Lambda and Amazon SNS
D.AWS CloudTrail and Amazon CloudWatch Events
AnswerB

AWS Config evaluates launched instances against a managed rule such as approved-ami-by-id, which checks whether the instance’s AMI ID is in an allowed list. When an instance is non-compliant, Config can automatically invoke an AWS Systems Manager Automation document (for example, to stop or terminate the instance), providing a self-healing enforcement loop. This is the recommended pattern for reactive enforcement where the desired AMI cannot be blocked at the API level by IAM or SCP policies.

Why this answer

AWS Config can evaluate whether EC2 instances use the approved AMI ID by creating a custom rule or using a managed rule, and AWS Systems Manager Automation can automatically remediate non-compliant instances (e.g., stop, terminate, or notify). This combination enforces the policy and provides automated remediation, which is the most effective way to ensure compliance.

Exam trap

DOP-C02 often tests the misconception that SCPs can enforce resource properties like AMI IDs, but SCPs only control API permissions, not resource configurations.

How to eliminate wrong answers

Option A is wrong because AWS Organizations SCPs cannot enforce AMI IDs; SCPs control API actions, not resource properties, and CloudTrail only logs API calls without enforcement. Option C is wrong because AWS Lambda and Amazon SNS can be used for custom enforcement but require significant custom code and do not provide built-in compliance evaluation; they are not a complete solution. Option D is wrong because CloudTrail and CloudWatch Events can detect and react to EC2 launches but do not enforce AMI usage; they are event-driven and reactive, not preventive or detective with remediation.

627
MCQhard

A company experiences a security incident where an unauthorized user accessed an S3 bucket containing sensitive data. The DevOps team needs to identify the source IP address and user agent of the request. Which AWS service provides this information?

A.VPC Flow Logs
B.Amazon S3 server access logs
C.AWS CloudTrail
D.Amazon CloudWatch Logs
AnswerB

Amazon S3 server access logs provide detailed records for every request, including source IP address, user agent, requester, operation, and HTTP status. This is the correct service to identify the source IP and user agent of the unauthorized request.

Why this answer

Amazon S3 server access logs record detailed information about every request made to a bucket, including the requester's IP address, user agent, request time, and operation. This is the only AWS service in the list that captures the source IP and user agent for S3 object-level requests. CloudTrail records API management events but does not log data-plane GET/PUT requests by default.

Exam trap

DOP-C02 often tests the distinction between CloudTrail (API/management events) and S3 server access logs (data-plane request details including IP and user agent) — candidates frequently assume CloudTrail captures everything.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture IP traffic metadata at the ENI/subnet level (source/dest IP, ports, bytes) but not HTTP user agents or S3 request details. Option C is wrong because CloudTrail logs S3 management events (e.g., PutBucketPolicy) and, only if data events are explicitly enabled, object-level operations — but even then it does not capture user agent strings. Option D is wrong because CloudWatch Logs is a log aggregation service, not a source of S3 request metadata; it only contains what you route to it.

628
MCQeasy

A DevOps engineer is managing the lifecycle of a CloudFormation stack. The engineer needs to update a stack that contains an Auto Scaling group. The update requires a replacement of the Auto Scaling group. What will happen to the existing instances during the update?

A.The existing instances will be terminated after the new Auto Scaling group is created
B.The stack update will fail because Auto Scaling groups cannot be replaced
C.The existing instances will remain running and be associated with the new Auto Scaling group
D.The instances will be updated in-place by terminating and recreating each instance one by one
AnswerA

During a CloudFormation stack update that forces replacement, the Auto Scaling group is recreated with a new physical resource ID. CloudFormation first creates the replacement group and only after it is successfully provisioned does it delete the original group, which terminates the old group's instances. This create-before-delete behavior preserves capacity during the update window.

Why this answer

When a CloudFormation stack update requires replacement of an Auto Scaling group (e.g., due to a change in the `LaunchConfigurationName` or `LaunchTemplate` property), CloudFormation creates the new Auto Scaling group first, then terminates the old instances after the new group is fully operational. This ensures minimal downtime because the new group begins serving traffic before the old one is torn down.

Exam trap

The trap here is that candidates assume CloudFormation performs in-place updates (Option D) or that replacement always fails (Option B), but the service explicitly supports create-before-destroy replacement for Auto Scaling groups.

How to eliminate wrong answers

Option B is wrong because CloudFormation supports replacing Auto Scaling groups during stack updates when the resource requires replacement; it does not fail. Option C is wrong because existing instances cannot be reassigned to a new Auto Scaling group—each instance is tied to a specific Auto Scaling group via its lifecycle hooks and launch configuration. Option D is wrong because CloudFormation does not perform in-place updates on Auto Scaling groups; it uses a create-before-destroy strategy, terminating the old group only after the new one is created.

629
MCQhard

A company is using AWS CodeCommit with multiple repositories. Developers are required to create pull requests for all changes, and the pull request must be associated with a JIRA issue key (e.g., PROJ-123) in the commit message. A DevOps engineer needs to enforce this policy automatically. Which approach meets the requirement with minimal operational overhead?

A.Store JIRA keys in an S3 bucket and configure a CloudWatch Events rule to check commits
B.Create a CodeCommit trigger that invokes an AWS Lambda function to validate the pull request description and reject if missing JIRA key
C.Use AWS CodeBuild to run a validation script during the build phase
D.Require developers to install a pre-commit hook script locally
AnswerB

A CodeCommit trigger can be configured for pull-request events such as pullRequestCreated or pullRequestSourceBranchUpdated, invoking a Lambda function asynchronously. The Lambda parses the pull request description with a regex for a JIRA key such as [A-Z]+-[0-9]+, and if the key is missing it calls the CodeCommit API UpdatePullRequestStatus with status CLOSED to reject the PR and posts a comment explaining the failure. Because the logic runs in AWS managed services on every qualifying pull request event, enforcement is centralized and cannot be bypassed by individual developers.

Why this answer

CodeCommit triggers can invoke an AWS Lambda function on pull request events (e.g., created or updated). The Lambda function can parse the pull request description or commit messages for a JIRA key pattern (e.g., regex `[A-Z]+-\d+`) and, if missing, automatically reject the pull request by updating its status or adding a comment. This serverless approach enforces the policy without requiring any changes to developer workflows or additional infrastructure, minimizing operational overhead.

Exam trap

The trap here is that candidates may choose Option C (CodeBuild) because they assume build-time validation is sufficient, but they overlook that CodeBuild runs after the pull request is merged, not before, making it ineffective for pre-merge enforcement.

How to eliminate wrong answers

Option A is wrong because storing JIRA keys in an S3 bucket and using a CloudWatch Events rule to check commits is overly complex and indirect; CloudWatch Events cannot directly inspect commit messages within a repository, and this approach would require custom polling logic and lack native integration with pull request lifecycle events. Option C is wrong because AWS CodeBuild runs during the build phase, which occurs after a pull request is merged or a commit is pushed, so it cannot reject a pull request before it is accepted; it would only catch violations post-merge, failing the policy requirement to enforce before changes are merged. Option D is wrong because requiring developers to install a pre-commit hook locally is not enforceable centrally; developers can bypass or omit the hook, leading to inconsistent policy application and increased operational overhead for maintenance and updates.

630
MCQeasy

A company needs to ensure that all API calls made to AWS are encrypted in transit. Which of the following is the correct way to enforce this?

A.Use an IAM policy with a condition that denies access unless the request uses HTTPS.
B.Configure security groups to allow only HTTPS traffic.
C.Use AWS Key Management Service (KMS) to create a key and require encryption.
D.Enable AWS CloudTrail to log all API calls.
AnswerA

An IAM policy is evaluated for every AWS API request, and the global condition key `aws:SecureTransport` returns `false` when the request was not sent over TLS/HTTPS. By attaching a policy that explicitly denies access when `aws:SecureTransport` is `false`, you enforce that all API calls must use HTTPS at the authorization layer. This is the correct, service-agnostic mechanism because IAM conditions apply uniformly to any supported AWS service, making it impossible to bypass via a non-HTTPS client.

Why this answer

All AWS API endpoints support HTTPS (TLS) by default. To enforce that all API calls are encrypted in transit, you can use an IAM policy with a condition that denies access unless the request uses HTTPS. Specifically, you can use the `aws:SecureTransport` condition key to require encrypted connections.

Option A is correct. Option B is incorrect because security groups control network traffic at the instance level but do not enforce encryption for API calls. Option C is incorrect because AWS KMS is used for managing encryption keys, not for enforcing HTTPS.

Option D is incorrect because AWS CloudTrail logs API activity but does not enforce encryption.

631
MCQhard

A company has a serverless application using AWS Lambda functions that process messages from an Amazon SQS queue. The Lambda function sometimes fails due to transient errors. The company wants to ensure that failed messages are retried and eventually processed or sent to a dead-letter queue after 3 retries. What is the correct configuration?

A.Set the Lambda function's retry policy to Maximum retries: 3 and configure a DLQ on the Lambda function.
B.Set the Lambda function's DLQ to an SQS queue and configure the event source mapping to use that DLQ after 3 retries.
C.Configure the SQS queue's redrive policy with maxReceiveCount: 3 and a dead-letter queue.
D.Create an AWS Step Functions workflow that polls the SQS queue, processes messages, and retries failures up to 3 times before moving to a DLQ.
AnswerC

This is the correct pattern because SQS itself owns the retry and dead-letter behavior when Lambda consumes from a queue. A redrive policy with maxReceiveCount: 3 instructs SQS to allow a message to be received up to three times; if the Lambda function fails to process it each time, SQS automatically moves the message to the configured dead-letter queue. This is a native, serverless-friendly mechanism that avoids unnecessary compute and precisely matches the requirement for '3 retries before a DLQ'.

Why this answer

For Lambda functions that poll an SQS queue, the retry behavior and dead-letter queue are configured on the SQS queue itself using a redrive policy. The redrive policy specifies the maxReceiveCount (e.g., 3) and the ARN of the dead-letter queue. After a message is received the specified number of times without being deleted, SQS moves it to the DLQ.

This is the correct way to handle retries and DLQ for SQS-triggered Lambda.

Exam trap

The trap is assuming Lambda's retry settings apply to SQS-triggered invocations; candidates often confuse asynchronous invocation retries with poll-based event source mapping retries, leading them to pick Lambda DLQ options instead of SQS redrive policy.

How to eliminate wrong answers

Option A is wrong because Lambda's own retry policy (Maximum retries) applies to asynchronous invocations, not to poll-based event source mappings like SQS. Option B is wrong because the Lambda function's DLQ is for asynchronous invocations, and the event source mapping does not have a DLQ configuration; the DLQ must be on the SQS queue. Option D is wrong because using Step Functions adds unnecessary complexity and does not leverage the native SQS redrive policy; it is not the simplest or correct configuration for this requirement.

632
MCQhard

A DevOps engineer is configuring CloudWatch Logs for a Lambda function that processes streaming data from Kinesis. The function sometimes fails due to memory exhaustion. The engineer wants to ensure that logs from the function are shipped to CloudWatch Logs even when the function fails. Which configuration should be used?

A.Configure a Kinesis Agent on the Lambda execution environment to stream logs to CloudWatch Logs
B.Install the CloudWatch Logs agent on the Lambda function to continuously send logs
C.Enable detailed CloudWatch metrics for the Lambda function
D.Ensure the Lambda function writes logs to stdout or stderr; CloudWatch Logs will automatically capture them
AnswerD

Correct. The Lambda runtime (for both the AWS-provided runtimes and custom runtimes that use the Runtime API) intercepts all output written to stdout and stderr and automatically streams it to CloudWatch Logs under the log group /aws/lambda/<function-name>. This happens regardless of whether the function completes successfully or crashes, so logging to stdout/stderr is the standard, documented way to generate logs. Each invocation gets a unique log stream, and the exact log line format can include request IDs if you also log the Lambda context object, but the capture itself requires no extra configuration beyond the Lambda service execution role's CloudWatch Logs permissions.

Why this answer

Lambda functions automatically send all output written to stdout (via print or console.log) and stderr to CloudWatch Logs, regardless of whether the function succeeds or fails. This is a built-in behavior of the Lambda runtime, so no additional agents or configuration are needed to capture logs from a failed invocation due to memory exhaustion.

Exam trap

The trap here is that candidates may overthink the solution and assume a separate agent or service is required for log shipping in failure scenarios, when in fact Lambda’s native stdout/stderr capture works automatically and reliably even on invocation failure.

How to eliminate wrong answers

Option A is wrong because a Kinesis Agent is designed to run on EC2 instances or on-premises servers to send data to Kinesis, not to stream logs from a Lambda execution environment; Lambda does not support installing or running external agents. Option B is wrong because the CloudWatch Logs agent is intended for EC2 instances or on-premises servers, and cannot be installed inside a Lambda function’s ephemeral execution environment. Option C is wrong because enabling detailed CloudWatch metrics provides performance metrics (e.g., duration, invocations, errors) but does not capture or ship log output from the function.

633
MCQeasy

A company has a security policy requiring that all IAM users use multi-factor authentication (MFA) to access the AWS Management Console. The DevOps engineer needs to enforce this policy. What is the simplest way to achieve this?

A.Use Amazon Cognito to require MFA for console access.
B.Create an IAM policy that denies all actions unless MFA is present, and attach it to all IAM users or groups.
C.Enable MFA delete on the root account.
D.Enable MFA on the S3 bucket policy.
AnswerB

Create an IAM policy that uses the 'aws:MultiFactorAuthPresent' condition key to deny actions when MFA is not present, for example: 'Condition': {'Bool': {'aws:MultiFactorAuthPresent': 'false'}}. Attach this policy to all IAM users or groups so that any API call made without MFA is rejected, while requests made with MFA succeed. This enforces MFA globally across all AWS services for the attached identities. Be sure to grant users permission to manage their own MFA devices beforehand to avoid lockout.

Why this answer

The simplest enforcement is an IAM policy that denies all actions unless the request is made with MFA, attached to users or groups. This uses the aws:MultiFactorAuthPresent condition key in a Deny statement, which blocks console and API access for users who have not authenticated with MFA. It is a native IAM mechanism requiring no additional services.

Exam trap

DOP-C02 often tests the difference between IAM policy conditions and service-specific features, tricking candidates into picking Cognito or S3 MFA Delete when the question is about IAM user console MFA enforcement.

How to eliminate wrong answers

Option A is wrong because Amazon Cognito is an identity service for customer-facing applications, not for enforcing MFA on IAM user console access. Option C is wrong because MFA Delete on the root account is an S3 bucket-level feature that protects object versions from deletion, not a console access control. Option D is wrong because S3 bucket policies govern access to S3 resources, not IAM user console authentication, and cannot enforce MFA at the console login level.

634
MCQhard

A company uses AWS CloudFormation to deploy infrastructure. The stack creation fails with the error: 'Resource handler returned message: 'The security group does not exist in VPC'.' The template references a security group by name. What is the MOST likely cause?

A.The security group name is misspelled or uses incorrect case
B.The IAM role used for CloudFormation does not have permissions to describe security groups
C.The stack is being created in a Region where the security group does not exist
D.The template uses a parameter that resolves to the default VPC security group
AnswerA

Security group names in EC2 are case-sensitive, and CloudFormation's lookup by name uses an exact, literal string match against the security groups within the specified VPC. If you reference a group by name and the template contains a typo, wrong case, or an unintended trailing space, the API returns no matching group, which CloudFormation reports as a 'security group not found' error. This is the most frequent root cause in practice because names like 'web-SG' and 'web-sg' are considered distinct, and the error message often appears immediately after a small edit or a manual copy-paste from a different source.

Why this answer

The error 'Resource handler returned message: The security group does not exist in VPC' occurs when CloudFormation cannot find a security group with the specified name in the target VPC. The most likely cause is a misspelling or case sensitivity issue (Option A), as CloudFormation matches security group names exactly. While region scoping (Option C) can also cause a similar error, the combination of a name-based reference and the specific error wording points to a name mismatch as the most common issue.

IAM permission errors (Option B) would typically return an authorization error, not a 'does not exist' error. Option D is incorrect because a default VPC security group exists and would not cause this error unless it is missing, which is unlikely.

Exam trap

Candidates often overlook that security group name resolution is case-sensitive and exact. While region scoping can cause a similar error, the most frequent cause is a typo or case mismatch in the security group name referenced in the template.

How to eliminate wrong answers

Option B is wrong because the error message specifically indicates the security group does not exist in the VPC, not a permissions issue; an IAM permissions error would produce a different message such as 'AccessDenied' or 'Unauthorized operation'. Option D is wrong because referencing a parameter that resolves to the default VPC security group would not cause this error; the default security group exists in every VPC and would be found, so the error would not occur unless the VPC itself is missing or the parameter value is invalid.

635
Multi-Selecthard

A company uses AWS CodePipeline to deploy a critical application. The pipeline has a manual approval step before deployment. Which TWO actions should be taken to improve security and auditability? (Choose two.)

Select 2 answers
A.Enable AWS CloudTrail to log all approval actions.
B.Remove the approval step and rely on post-deployment monitoring.
C.Integrate with AWS IAM to require multi-factor authentication (MFA) for approvers.
D.Replace the manual approval with an automated approval based on test results.
E.Use a shared IAM user for all approvers to simplify management.
AnswersA, C

Enabling AWS CloudTrail records the PutApprovalResult API calls made through CodePipeline when an approver clicks Approve or Reject. CloudTrail logs the IAM principal or federated user identity, the timestamp, the source IP address, and the decision, providing an immutable audit trail that satisfies compliance and forensic needs. This is the correct answer because the company's explicit requirement is to know who approved the deployment and when.

Why this answer

Enabling AWS CloudTrail to log all approval actions provides a detailed, immutable audit trail of who approved or rejected a pipeline stage, when it happened, and from which IP address. This is essential for compliance and forensic analysis, as CloudTrail captures the `Approval` API calls made by CodePipeline, including the `approve` and `reject` actions, along with the IAM user or role identity. Without CloudTrail, there is no native logging of manual approval events, making it impossible to prove accountability.

Exam trap

The trap here is that candidates often think automated approvals (Option D) are always more secure, but the question specifically asks for improving security and auditability of a manual approval step, and removing human oversight actually reduces security for critical deployments.

636
MCQeasy

A company uses AWS CloudFormation to manage its infrastructure. The operations team needs to update a stack that includes an RDS database. The update requires changing the DB instance class, which will cause a replacement of the database. The team wants to minimize downtime and ensure that data is not lost. Which CloudFormation stack update policy should they use?

A.Set the CreationPolicy attribute on the database resource.
B.Configure a Stack Policy to protect the database resource.
C.Set the UpdatePolicy to AutoScalingRollingUpdate.
D.Set the UpdatePolicy to AutoScalingReplacingUpdate with WillReplace set to true.
AnswerD

AutoScalingReplacingUpdate is only supported for AWS::AutoScaling::AutoScalingGroup and cannot be applied to an AWS::RDS::DBInstance resource.

Why this answer

The UpdatePolicy attribute with AutoScalingReplacingUpdate is only supported for AWS::AutoScaling::AutoScalingGroup resources, not for AWS::RDS::DBInstance. Therefore, option D is incorrect. Options A and C are also invalid (CreationPolicy is for signal-based creation, and AutoScalingRollingUpdate is for rolling updates on Auto Scaling groups).

Option B, Stack Policy, can protect resources from being updated but does not control how a replacement occurs to minimize downtime or prevent data loss. Thus, none of the provided options are correct for ensuring minimal downtime and data safety during an RDS instance class change that requires replacement.

Exam trap

Candidates might assume that AutoScalingReplacingUpdate can be applied to any resource supporting replacement, but CloudFormation limits UpdatePolicy to specific resources like Auto Scaling groups, ElastiCache replication groups, and Elasticsearch domains. RDS DB instances do not support UpdatePolicy.

How to eliminate wrong answers

Option A is wrong because the `CreationPolicy` attribute controls how CloudFormation waits for signals (e.g., from cfn-init) before marking a resource as created; it does not affect update behavior or minimize downtime during a replacement. Option B is wrong because a Stack Policy is used to prevent accidental updates or deletions of specific resources by denying update/delete actions, but it does not control the order or method of updates to minimize downtime. Option C is wrong because `AutoScalingRollingUpdate` is designed for Auto Scaling groups to update instances in batches, not for RDS instances; applying it to an RDS resource would have no effect and would not handle the replacement of a database.

637
Multi-Selectmedium

Which TWO approaches can be used to automate the creation of an AWS CloudFormation stack that includes IAM resources? (Select TWO.)

Select 2 answers
A.Store the CloudFormation template in an Amazon S3 bucket and use the 'aws cloudformation deploy' command.
B.Set the 'CAPABILITY_NAMED_IAM' capability when calling the CreateStack API.
C.Attach the AWS managed policy 'IAMFullAccess' to the IAM user or role executing the stack creation.
D.Use an AWS Lambda function to call the CreateStack API with the capabilities parameter set to 'CAPABILITY_IAM'.
E.Use the AWS CLI command 'aws cloudformation create-stack' with the '--capabilities CAPABILITY_IAM' parameter.
AnswersD, E

An AWS Lambda function can programmatically call the CreateStack API and include 'CAPABILITY_IAM' in the Capabilities list, satisfying CloudFormation's acknowledgement requirement. This is a valid automation method because the Lambda handler can pass the parameter directly in the SDK request, and the function can be triggered by various events. The Lambda execution role must have permission to create stacks and the necessary IAM resources.

Why this answer

When a CloudFormation stack includes IAM resources, you must explicitly acknowledge that the stack may create IAM entities. An AWS Lambda function calling the CreateStack API with the `capabilities` parameter set to `CAPABILITY_IAM` satisfies this requirement. Option E is correct because the AWS CLI `create-stack` command with the `--capabilities CAPABILITY_IAM` parameter also provides the required acknowledgment, allowing the stack to be created successfully.

Exam trap

The trap here is that candidates often confuse IAM permissions (like `IAMFullAccess`) with the CloudFormation capability acknowledgment, thinking that having the right IAM policy alone is sufficient to create IAM resources in a stack, when in fact the `CAPABILITY_IAM` or `CAPABILITY_NAMED_IAM` flag must be explicitly set in the API call.

638
MCQmedium

A company uses AWS CodePipeline with a multi-branch strategy. Developers push to feature branches, which should trigger a pipeline that runs unit tests and then deploys to a staging environment. However, the pipeline only triggers on the main branch. What should be done to enable pipeline execution for feature branches?

A.Change the source provider from Amazon S3 to AWS CodeCommit.
B.Increase the polling frequency in the source stage to detect new branches.
C.Create a separate pipeline for each feature branch.
D.Update the source stage to use 'Webhook' as the change detection method and specify a branch pattern.
AnswerD

Configuring the source stage to use Webhook change detection with a branch pattern, such as refs/heads/feature/*, makes the pipeline automatically respond to pushes on matching feature branches. This allows a single pipeline to serve multiple branches by filtering events based on the branch reference, without manual per-branch pipelines. The webhook sends an event to CodePipeline only when the push matches the pattern, enabling efficient and dynamic multi-branch execution.

Why this answer

AWS CodePipeline can use a webhook (e.g., from GitHub or CodeCommit) to detect changes on any branch. By configuring the source stage with 'Webhook' as the change detection method and specifying a branch pattern (e.g., 'feature/*'), the pipeline will automatically trigger on pushes to matching feature branches, not just the main branch.

Exam trap

The trap here is that candidates often assume polling or changing the source provider will automatically detect new branches, but AWS CodePipeline's polling only monitors the configured branch reference (e.g., 'refs/heads/main'), not all branches, and changing the source provider does not alter this behavior.

How to eliminate wrong answers

Option A is wrong because changing the source provider from Amazon S3 to AWS CodeCommit does not inherently enable multi-branch triggering; both providers require proper change detection configuration (e.g., webhook or polling) to trigger on non-default branches. Option B is wrong because increasing polling frequency only affects how often CodePipeline checks for changes on the configured branch (typically main), but it does not enable detection of new branches or trigger on branches other than the one specified in the source stage. Option C is wrong because creating a separate pipeline for each feature branch is unnecessary and violates the multi-branch strategy; a single pipeline with a webhook and branch pattern can handle all feature branches dynamically.

639
MCQmedium

A DevOps engineer is troubleshooting a slow web application. The application runs on EC2 instances behind an ALB. The engineer notices that the ALB's TargetResponseTime metric shows high p99 values, but the CPU and memory on the EC2 instances are well below thresholds. What is the most likely cause?

A.The Auto Scaling group has too many instances, causing increased network overhead
B.The ALB is routing requests to instances in different Availability Zones, increasing latency
C.The application is waiting on a slow database query or external API call
D.The ALB idle timeout is set too low, causing connections to be dropped
AnswerC

Synchronous dependencies like database queries and external API calls are the classic cause of elevated application latency; the end-user response time becomes the sum of all blocking calls in the request path, and a single slow query (e.g., missing index, lock contention, or throttled API) holds up the entire page. This pattern usually shows as high response times with low CPU and network utilization on the application instances, because threads are parked waiting for the downstream I/O to complete. In an Auto Scaling environment, simply adding instances won't help while the database or API service remains the bottleneck.

Why this answer

High p99 TargetResponseTime on the ALB with low CPU and memory on the EC2 instances indicates that the bottleneck is not compute capacity but rather a dependency external to the application server. The application is likely waiting on a slow database query or external API call, which increases response time without consuming significant local CPU or memory. This is a classic symptom of an I/O-bound or network-bound dependency.

Exam trap

The trap here is that candidates often assume high response times must be caused by compute saturation (CPU/memory) or network issues, but the question deliberately shows low resource utilization to force you to consider external dependencies as the root cause.

How to eliminate wrong answers

Option A is wrong because having too many instances in the Auto Scaling group would reduce per-instance load and likely decrease response times, not increase them; network overhead from more instances is negligible compared to the ALB's connection management. Option B is wrong because ALB inherently routes requests to instances across Availability Zones with minimal latency overhead (typically <1 ms), and cross-AZ data transfer costs are not a significant factor in p99 response time. Option D is wrong because a low ALB idle timeout would cause connections to be dropped prematurely, resulting in client-side errors (e.g., 504 Gateway Timeout) rather than consistently high p99 response times; the metric would show timeouts, not slow completions.

640
Multi-Selectmedium

Which TWO actions are best practices when designing a CI/CD pipeline for a containerized application on Amazon ECS? (Choose two.)

Select 2 answers
A.Run a full integration test suite on every commit to the repository.
B.Separate the build stage from the deploy stage in the pipeline.
C.Build the Docker image in the deploy stage to ensure consistency.
D.Use a rolling update with a fixed number of tasks for deployment.
E.Use a blue/green deployment strategy for the ECS service.
AnswersB, E

Separating the build stage from the deploy stage ensures that a single immutable artifact—such as a Docker image or packaged JAR—is produced once and then promoted through environments (dev, staging, prod) without rebuilding. This eliminates configuration drift and makes the pipeline auditable, because the exact artifact tested can be deployed to production. It also enables independent validation and safe rollback: if a deployment fails, you can redeploy the previous artifact rather than re-running a build that may produce different output.

Why this answer

Separating the build stage from the deploy stage in a CI/CD pipeline for Amazon ECS ensures that the Docker image is built, tested, and validated independently before being promoted to production. This decoupling allows you to reuse the same immutable artifact across multiple environments (e.g., dev, staging, prod), reducing the risk of environment-specific build inconsistencies and enabling rollback to a known good image.

Exam trap

The trap here is that candidates often confuse 'rolling update' (a deployment configuration) with 'blue/green deployment' (a deployment strategy), and they may incorrectly select Option D because they think it provides the same safety guarantees as blue/green, but rolling updates with a fixed number of tasks lack the atomic traffic shift and instant rollback capabilities that blue/green offers.

641
Multi-Selecthard

A company is migrating to a microservices architecture on Amazon ECS with AWS Fargate. They want to automate the deployment process using AWS CodePipeline. The pipeline should build a Docker image, push it to Amazon ECR, and deploy the updated service to ECS. Which THREE components are required in the pipeline? (Choose 3.)

Select 3 answers
A.Deploy stage with AWS CodeDeploy to ECS.
B.Build stage with AWS CodeBuild to build the Docker image and push to ECR.
C.Manual approval stage.
D.Source stage with AWS CodeCommit or Amazon S3 as source.
E.Test stage with AWS CodeBuild to run unit tests.
AnswersA, B, D

The Deploy stage is mandatory because it uses AWS CodeDeploy's ECS deployment type to shift traffic from the old to the new task definition. CodeDeploy references an AppSpec file and the task definition produced during the Build stage, then updates the ECS service with either rolling updates or blue/green traffic shifting. Without this stage, the built and pushed container image would never be run as an active service in ECS.

Why this answer

AWS CodeDeploy is the native deployment service that integrates with Amazon ECS to perform blue/green deployments, rolling updates, and traffic shifting. In a CodePipeline, the Deploy stage uses CodeDeploy to orchestrate the ECS service update, ensuring zero-downtime deployments by managing task set creation and load balancer target group routing.

Exam trap

The trap here is that candidates often think a manual approval or test stage is mandatory for a production pipeline, but the DOP-C02 exam focuses on the minimal required components for a functional CI/CD pipeline, which are source, build, and deploy.

642
MCQeasy

A company uses AWS CodeBuild to run unit tests for a Python application. The buildspec.yml file specifies a build phase that runs 'pytest'. The team wants to ensure that the build fails if any test fails, and that test results are available in the CodeBuild console. Which change should they make to the buildspec.yml?

A.Modify the build phase to run 'pytest --junitxml=results.xml' and add an artifacts section to upload results.xml.
B.Add a 'reports' section to the buildspec.yml that specifies the test report group and the location of the test results file.
C.Add a post_build phase that checks the exit code of the build phase and fails the build if tests failed.
D.Set the 'fail-fast' option to true in the build phase to stop the build immediately if any test fails.
AnswerB

AWS CodeBuild supports test reporting through the 'reports' section in buildspec.yml. By specifying a report group and the path to the test results file (e.g., JUnit XML), CodeBuild can parse and display test results in the console. Additionally, if 'pytest' exits with a non-zero status on failure, the build fails automatically. This change provides visibility into test results and ensures failures are caught.

Why this answer

To make test results available in the CodeBuild console, the buildspec.yml must include a 'reports' section that specifies the report group and the location of the test results file. CodeBuild automatically fails the build if a command in the build phase returns a non-zero exit code, so 'pytest' failures will cause the build to fail. The 'reports' section integrates with CodeBuild's test reporting feature, providing detailed test outcomes.

The other options either describe non-existent features or do not provide the required reporting integration.

Exam trap

The trap here is confusing artifacts with test reports, or assuming that a separate post_build check is needed when the build already fails on non-zero exit codes.

643
MCQeasy

A DevOps team uses AWS CodePipeline to deploy a web application. They notice that the deployment stage fails intermittently due to a missing configuration file. Which troubleshooting step should they take first?

A.Switch to AWS CodeBuild for the deployment stage.
B.Review the build logs in AWS CodeBuild to identify the error.
C.Recreate the pipeline with the same configuration to see if the issue repeats.
D.Verify the deployment group settings in AWS CodeDeploy.
AnswerB

Reviewing the build logs in AWS CodeBuild directly surfaces the compile-time or test-time error that caused the pipeline action to fail. CodeBuild logs are stored in CloudWatch Logs (and optionally S3), showing the full output of each build phase, including command execution, environment setup, and the exact error message and exit code. This is the fastest, most authoritative way to identify the root cause of a build-phase failure.

Why this answer

The deployment stage fails intermittently due to a missing configuration file. The first troubleshooting step should be to review the build logs in AWS CodeBuild, because CodeBuild generates detailed logs that capture the exact error message, including file paths and missing configuration details. This allows the team to pinpoint the root cause without making unnecessary changes to the pipeline or deployment group settings.

Exam trap

The trap here is that candidates may jump to verifying CodeDeploy settings (Option D) because the failure occurs in the deployment stage, but the root cause is a missing configuration file that should have been produced or included earlier in the pipeline, making build logs the correct first diagnostic step.

How to eliminate wrong answers

Option A is wrong because switching to AWS CodeBuild for the deployment stage does not address the intermittent missing configuration file issue; it only changes the compute service, and the underlying configuration problem would persist. Option C is wrong because recreating the pipeline with the same configuration is a time-consuming and non-diagnostic step that does not provide any new information about why the configuration file is missing intermittently. Option D is wrong because verifying the deployment group settings in AWS CodeDeploy is relevant only if the failure is related to deployment targets or traffic routing, not to a missing configuration file that should be present in the build or source stage.

644
MCQeasy

An organization is using AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment fails because the target group is not configured correctly. Which CodeDeploy component is responsible for registering instances with the load balancer?

A.The CodeDeploy agent configuration
B.The deployment group configuration
C.The AppSpec file hooks section
D.The application revision bundle
AnswerB

The deployment group configuration holds the load balancer or target group settings for the deployment. During an in-place or blue/green deployment, CodeDeploy automatically registers healthy instances with the target group defined in this configuration, and deregisters them before traffic shifts. It is this centrally defined setting, not anything in the application files or on the instance, that governs elastic load balancing integration.

Why this answer

The deployment group configuration in AWS CodeDeploy specifies the target group or load balancer for the deployment. CodeDeploy automatically registers instances in the Auto Scaling group with the specified target group as part of the deployment process. The AppSpec file hooks section defines custom lifecycle event hooks for scripts, but instance registration is handled by the CodeDeploy service based on the deployment group settings, not by hooks.

Exam trap

Candidates often incorrectly attribute instance registration to the AppSpec hooks section because hooks can run custom scripts. However, registration with a load balancer is a built-in function of CodeDeploy that relies on the deployment group configuration, not on user-defined hooks.

How to eliminate wrong answers

Option A is wrong because the CodeDeploy agent configuration is a file on the instance that controls the agent's behavior (e.g., logging, proxy settings) and does not handle load balancer registration. Option B is wrong because the deployment group configuration does specify the target group and load balancer settings, but it is not a component that directly registers instances; it defines the target group ARN and the deregistration delay, while the actual registration is performed by CodeDeploy service based on that configuration. Option D is wrong because the application revision bundle contains the application files and the AppSpec file, but it does not directly handle load balancer registration; it is the source of the deployment artifacts.

645
MCQmedium

An organization uses AWS CodeDeploy for automated deployments to EC2 instances. The deployment is failing with the error 'The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available for deployment, or some instances in your deployment group are experiencing problems.' The deployment group has a minimum healthy hosts setting of 75%. The application has 4 instances. What is the MOST likely issue?

A.The AppSpec file references a script that does not exist.
B.The IAM instance profile does not have sufficient permissions.
C.The CodeDeploy agent is not installed on any of the instances.
D.The deployment failed on 2 instances, leaving only 2 healthy.
AnswerD

For a deployment to four instances, a minimum healthy hosts percentage of 75% requires that at least three instances remain available throughout the deployment. When two instances failed, the healthy count dropped to two (50%), which is below the required threshold, so CodeDeploy was forced to abort the deployment and mark it as failed. This is a classic example of the minimum healthy hosts guardrail catching a partial-failure scenario that other, fleet-wide issues would not produce.

Why this answer

With a minimum healthy hosts setting of 75% and 4 instances, at least 3 instances must remain healthy during deployment. If 2 instances fail, only 2 are healthy (50%), which falls below the 75% threshold, causing CodeDeploy to abort the deployment to prevent further impact. This error message directly corresponds to the healthy host count dropping below the configured minimum.

Exam trap

The trap here is that candidates may focus on individual instance failure causes (like missing scripts or permissions) instead of recognizing that the error message explicitly describes a fleet-wide healthy host count violation, making the math of 4 instances with 75% minimum the key diagnostic clue.

How to eliminate wrong answers

Option A is wrong because a missing script in the AppSpec file would cause individual instance failures, but the error message specifically indicates a fleet-wide healthy host count issue, not a script execution error. Option B is wrong because insufficient IAM instance profile permissions would prevent the CodeDeploy agent from pulling revisions or reporting status, typically resulting in a different error like 'AccessDenied' or agent timeout, not a healthy host threshold violation. Option C is wrong because if the CodeDeploy agent were not installed on any instances, the deployment would fail immediately with an 'agent not found' error for each instance, not the specific healthy host count error shown.

646
Multi-Selecthard

A company runs a critical application on Amazon ECS with Fargate. The application emits structured logs in JSON format. The DevOps team wants to monitor for specific error codes and receive near-real-time alerts. The team also needs to retain logs for 5 years for compliance. Which TWO steps should the team implement?

Select 2 answers
A.Create a CloudWatch Logs metric filter to count occurrences of specific error codes and create an alarm
B.Use Amazon Kinesis Data Analytics to analyze logs in real-time and send alerts
C.Enable AWS CloudTrail to log the application's API calls
D.Stream logs to Amazon S3 via Amazon Kinesis Data Firehose and use S3 event notifications to trigger alerts
E.Configure a CloudWatch Logs retention policy to keep logs for 5 years
AnswersA, E

A CloudWatch Logs metric filter continuously scans new log events as they arrive in the log group and increments a custom metric whenever a pattern such as 'ERROR' or a specific error code appears. This metric can then drive a CloudWatch alarm with an associated SNS topic, providing a near-real-time notification without building any separate ingestion pipeline. Metric filters are the native, low-latency mechanism for monitoring textual patterns in logs.

Why this answer

CloudWatch Logs metric filters can parse JSON-structured logs to count occurrences of specific error codes, and you can create a CloudWatch alarm on that metric to trigger near-real-time notifications via SNS. This is a native, low-latency solution for monitoring specific patterns in ECS Fargate logs without additional infrastructure.

Exam trap

The trap here is that candidates often confuse CloudTrail (which logs AWS API calls) with application-level logging, or they over-engineer the solution with Kinesis Data Analytics or Firehose when CloudWatch native features (metric filters and retention policies) are sufficient and more cost-effective for this use case.

647
Multi-Selectmedium

A DevOps engineer is designing a secure CI/CD pipeline. Which TWO of the following are best practices for securing secrets in the pipeline?

Select 2 answers
A.Use encrypted environment variables in CodeBuild.
B.Store secrets in a parameter file in the source repository.
C.Hardcode secrets in CloudFormation template parameters.
D.Use S3 bucket policies to restrict access to secret files.
E.Store secrets in AWS Secrets Manager and retrieve them during the build.
AnswersA, E

CodeBuild allows you to define environment variables that are encrypted at rest with a customer-managed or AWS-managed KMS key and are never stored in buildspec or source control. These values are decrypted automatically in the build container at runtime, so the build commands can use them without exposing plaintext in the pipeline artifacts. Because CodeBuild also supports referencing Systems Manager Parameter Store or Secrets Manager values as environment variables, this approach centralizes secret access while retaining per-environment changes.

Why this answer

Options A and E are correct. Option A: CodeBuild allows environment variables to be encrypted using AWS KMS, which is a secure way to handle secrets in the pipeline. Option E: AWS Secrets Manager is a dedicated service for securely storing and retrieving secrets, and integrating it with the pipeline ensures secrets are not exposed.

Option B is incorrect because storing secrets in a parameter file in the source repository exposes them to anyone with repository access, violating security best practices. Option C is incorrect because hardcoding secrets in CloudFormation template parameters can lead to exposure in logs or template outputs, and is not secure. Option D is incorrect because while S3 bucket policies can restrict access, they do not encrypt the secrets themselves, and S3 is not designed for managing secrets; AWS Secrets Manager or Parameter Store are better choices.

648
MCQhard

A company uses AWS CloudFormation to manage infrastructure. They need to implement a CI/CD pipeline that automatically updates CloudFormation stacks when changes are pushed to a CodeCommit repository. The pipeline must use change sets to review changes before execution. Which pipeline configuration meets these requirements?

A.Use a CloudFormation action in CodePipeline with action mode 'CREATE_UPDATE' and include a manual approval step before the action.
B.Use a CloudFormation action with action mode 'CHANGE_SET_REPLACEMENT' and then a separate action with mode 'CHANGE_SET_EXECUTE' after an approval step.
C.Use an AWS Lambda function to create a change set and trigger a manual approval via SNS.
D.Use a CloudFormation action with action mode 'CREATE_UPDATE' and set the 'Review' flag to true.
AnswerB

This is the correct approach for a review-before-execution pipeline. The CHANGE_SET_REPLACEMENT action creates a new change set (or replaces an existing one) that captures the exact resource-level differences between the current stack and the proposed template, but it does not apply any changes. A subsequent manual approval step then gates the pipeline, allowing a human reviewer to inspect the change set in the CloudFormation console or via CLI. Only after approval does the CHANGE_SET_EXECUTE action run, which applies the previously created change set, ensuring that no stack modification occurs without explicit review and approval.

Why this answer

CodePipeline's CloudFormation deployment action supports a 'CHANGE_SET_REPLACEMENT' mode that creates or replaces a change set without executing it, followed by a 'CHANGE_SET_EXECUTE' action that applies the change set after an approval step. This two-step approach allows teams to review infrastructure changes before they are applied, meeting the requirement to use change sets for review before execution.

Exam trap

The trap here is that candidates often assume a manual approval step combined with a 'CREATE_UPDATE' action is sufficient for review, but they miss that change sets are required to preview the actual changes before execution, and 'CREATE_UPDATE' does not generate a change set at all.

Why the other options are wrong

A

CREATE_UPDATE directly applies changes without creating a change set first.

C

This is more complex and not the native CodePipeline CloudFormation action.

D

There is no 'Review' flag; CloudFormation actions do not support reviewing before update in that mode.

649
MCQmedium

A company is designing a disaster recovery strategy for a critical application that requires a Recovery Time Objective (RTO) of 15 minutes and a Recovery Point Objective (RPO) of 1 hour. The application runs on EC2 with data stored in Amazon RDS Multi-AZ. Which approach meets these requirements?

A.Use a pilot light strategy with RDS cross-Region read replicas and automated backups
B.Use backup and restore with daily snapshots to another Region
C.Use a warm standby with a scaled-down production environment in another Region
D.Use a Multi-AZ deployment in the same Region for DR
AnswerA

A pilot light strategy keeps a minimal core, such as the RDS instance, running in the DR Region via a cross-Region read replica while other services remain off. The read replica provides continuous asynchronous replication, so a promotion on failover can complete in roughly 15 minutes, and automated backups in the DR Region give point-in-time restore support. Since the database is already warm and data is being copied, the worst-case data loss stays within the 1-hour RPO.

Why this answer

A pilot light strategy with RDS cross-Region read replicas and automated backups meets the RTO of 15 minutes and RPO of 1 hour. The cross-Region read replica provides near-synchronous replication with an RPO typically under 5 seconds, and automated backups enable point-in-time recovery within the 1-hour RPO. The pilot light approach allows rapid promotion of the replica to a primary instance, achieving the 15-minute RTO by keeping minimal core services running in the DR Region.

Exam trap

The trap here is that candidates often confuse Multi-AZ (high availability within a Region) with cross-Region disaster recovery, assuming Multi-AZ alone provides DR, but it does not protect against Region-wide outages.

How to eliminate wrong answers

Option B is wrong because daily snapshots to another Region result in an RPO of up to 24 hours, far exceeding the required 1-hour RPO, and restoring from snapshots takes longer than 15 minutes. Option C is wrong because a warm standby with a scaled-down production environment typically has an RTO of minutes but requires continuous replication and failover orchestration; while it could meet the RPO, it is over-engineered and more costly than necessary, and the question asks for an approach that meets requirements, not the most optimal. Option D is wrong because a Multi-AZ deployment in the same Region does not provide disaster recovery across Regions; it only protects against Availability Zone failures, not regional disasters, and thus fails to meet the DR requirement.

650
MCQmedium

A DevOps team uses AWS CodePipeline to automate deployments. The pipeline has a Deploy stage that uses AWS CloudFormation to create or update a stack. Recently, a stack update failed because the template referenced an AMI that was deprecated. The team wants to automatically roll back the stack to the last known good state if a deployment fails. What should they do?

A.Configure the CloudFormation deployment action in CodePipeline with 'ActionMode' set to 'CREATE_UPDATE' and check the 'Rollback on failure' option.
B.Use the CodePipeline console to enable 'Automatic rollback' for the Deploy stage.
C.Set the stack's 'DisableRollback' parameter to 'true' in the template.
D.Add a stack policy to the CloudFormation stack that denies updates to the AMI parameter.
AnswerA

In CodePipeline, the CloudFormation deployment action requires an explicit ActionMode such as CREATE_UPDATE to create a new stack or update an existing one. When 'Rollback on failure' is selected, CloudFormation automatically rolls back the stack to its last known good state if the deployment fails, restoring both resources and stack outputs. This is the correct mechanism because it leverages CloudFormation's native rollback capability within the pipeline execution, preserving the integrity of the deployed infrastructure.

Why this answer

The CloudFormation deployment action in CodePipeline supports a 'Rollback on failure' option when 'ActionMode' is set to 'CREATE_UPDATE'. When enabled, if the stack update fails, CloudFormation automatically rolls back the stack to the last known good state (the previously deployed stack). This directly addresses the team's requirement to revert to a stable state after a failed deployment due to a deprecated AMI.

Exam trap

The trap here is that candidates confuse the CloudFormation stack-level 'DisableRollback' parameter (which controls rollback during stack creation) with the CodePipeline action-level 'Rollback on failure' option, leading them to incorrectly select Option C.

How to eliminate wrong answers

Option B is wrong because CodePipeline does not have an 'Automatic rollback' toggle at the stage level; rollback behavior is configured within the CloudFormation action itself, not via a generic stage setting. Option C is wrong because setting 'DisableRollback' to 'true' actually prevents rollback on failure, which is the opposite of what the team wants. Option D is wrong because a stack policy controls permissions for stack updates (e.g., preventing updates to specific resources), but it does not trigger an automatic rollback after a failed deployment.

651
MCQmedium

A company uses AWS CloudFormation to manage its infrastructure. The DevOps team has a template that creates an Amazon RDS DB instance and an EC2 instance that runs a web application. The EC2 instance needs to connect to the RDS instance using the database endpoint and password. The team currently passes the endpoint and password as CloudFormation parameters, which are then stored in the EC2 instance's user data. However, security audit has flagged this as a security risk because the password is visible in the user data. The team wants to securely pass the database credentials to the EC2 instance without exposing them in the template or user data. The EC2 instance has an IAM role that allows it to read from AWS Secrets Manager. Which solution should the team implement?

A.Store the password in AWS Systems Manager Parameter Store as a SecureString and have the EC2 instance retrieve it using the AWS CLI.
B.Encrypt the user data using AWS KMS and decrypt it on the EC2 instance at boot time.
C.Store the password in AWS Secrets Manager, use a dynamic reference to pass it to the EC2 instance's IAM role, and have the application retrieve it from Secrets Manager at runtime.
D.Use CloudFormation's Fn::GetAtt to retrieve the password from the RDS instance and pass it to the EC2 instance via user data.
AnswerC

This is correct because the password is stored and rotated in AWS Secrets Manager, and the CloudFormation template only references the secret's ARN (e.g., via a dynamic reference) in the IAM role policy, enabling the EC2 instance to read it. No secret value ever enters the template, user data, or instance filesystem; the application retrieves the plaintext only when it calls Secrets Manager at runtime. Since the IAM role restricts access to only that secret and Secrets Manager supports automatic rotation, the approach satisfies security best practices.

Why this answer

By storing the password in AWS Secrets Manager and using a dynamic reference in CloudFormation, the password is never exposed in the template or user data. The EC2 instance retrieves the password from Secrets Manager at runtime using its IAM role. Option A is not the best because although Parameter Store can store SecureStrings, Secrets Manager is more secure and supports automatic rotation, and the instance already has permissions to read Secrets Manager.

Option B is risky because encrypting user data still exposes the password in the user data itself and adds key management complexity. Option D is wrong because Fn::GetAtt cannot retrieve the RDS master password, and even if it could, the password would still be passed via user data, which is insecure.

652
MCQhard

A DevOps engineer manages a CodePipeline with a CodeCommit source, a CodeBuild test stage, and a manual approval before a production deploy stage. Audit requires that only the specific commit that passed testing can be deployed, and that no new commits pushed to the branch between test and approval can reach production. What should the engineer configure to guarantee this?

A.Configure the source action to use a specific commit ID as the source revision and disable polling so the pipeline only runs for that commit.
B.Add a stage-level condition or gate that fails the pipeline if the source artifact revision differs from the revision recorded at test time.
C.Enable the pipeline's artifact bucket versioning and add a lifecycle rule that expires old artifact versions after 30 days.
D.Keep the same pipeline execution through approval so the approved execution deploys the artifact produced earlier in that same execution.
AnswerD

A single pipeline execution carries its own artifacts from source through deploy. If the approval is part of that execution, the deploy stage consumes the exact artifact built and tested earlier, so commits pushed after the test stage start a new execution that must itself pass testing and approval, leaving the original execution's artifact intact.

Why this answer

The requirement is that the tested artifact, not just the branch, is what reaches production. Within one CodePipeline execution, artifacts are immutable across stages, so approving and continuing that execution deploys the tested revision. A later push starts a separate execution that cannot bypass test and approval, which preserves the audit guarantee without custom comparison logic.

Exam trap

The trap here is treating the source branch as the unit of control, when the deploy stage actually consumes the artifact of the pipeline execution, not the latest branch state.

653
MCQhard

An organization uses AWS CodePipeline with multiple stages: Source, Build, Test, and Deploy. The Test stage runs integration tests that take 30 minutes. The team wants to speed up feedback without skipping tests. Which action should they take?

A.Use a larger build environment for the Test stage.
B.Configure parallel build actions in the Test stage to run tests concurrently.
C.Remove the Test stage and rely on post-deployment testing.
D.Move the Test stage to after deployment.
AnswerB

CodePipeline naturally executes independent actions within a stage in parallel unless you set explicit runOrder values or action dependencies. By configuring multiple build actions, each running a partitioned portion of the test suite (by module, service, or shard), the total test work is spread across concurrent CodeBuild projects. The stage completes when all parallel actions finish, so overall duration approaches the slowest shard's critical path rather than the sum of all tests, directly reducing feedback time.

Why this answer

Running integration tests in parallel within the Test stage reduces the total wall-clock time for the test suite, speeding up feedback without skipping any tests. AWS CodePipeline supports parallel actions within a stage, allowing multiple test suites to execute concurrently, which directly addresses the goal of faster feedback while maintaining test coverage.

Exam trap

The trap here is that candidates often assume 'larger build environment' (Option A) is the universal solution for slow tests, but the DOP-C02 exam tests understanding that parallelism is the correct approach when tests are independent and the goal is to reduce elapsed time without sacrificing coverage.

How to eliminate wrong answers

Option A is wrong because using a larger build environment (e.g., more CPU/memory) does not inherently speed up integration tests that are sequential; it only helps if the tests are CPU-bound or memory-bound, but the bottleneck here is the 30-minute duration, which parallelism addresses. Option C is wrong because removing the Test stage eliminates integration testing entirely, violating the requirement to not skip tests and increasing the risk of deploying faulty code. Option D is wrong because moving the Test stage after deployment defeats the purpose of pre-deployment validation, allowing defects to reach production before detection, which contradicts the goal of faster feedback and safe deployment.

654
MCQmedium

A DevOps engineer is troubleshooting a failed AWS CloudFormation stack update. The stack contains an AWS::Lambda::Function resource. The update failed with the error 'Resource creation cancelled' after a timeout. The engineer wants to view the logs from the Lambda function during the stack update to diagnose the issue. What should the engineer do?

A.Use AWS CodeBuild to build and test the function locally
B.Enable detailed CloudFormation logging in the stack template
C.Access the CloudWatch Logs log group for the Lambda function
D.Review the CloudFormation stack events in the AWS Management Console
AnswerC

AWS Lambda automatically writes all execution logs—including output from print() statements, exception stack traces, and custom log messages—to a dedicated CloudWatch Logs log group named /aws/lambda/<function-name>. When the stack update fails, the Lambda function's runtime error is recorded as a log event, which you can view in the CloudWatch Logs console to pinpoint the root cause. Be sure to check the log stream that matches the exact timestamp of the failed update, and remember that logs are retained based on the log group's retention policy.

Why this answer

AWS Lambda automatically sends function execution logs to Amazon CloudWatch Logs. When a Lambda function is invoked during a CloudFormation stack update (e.g., via a custom resource or a function that runs as part of the update), all stdout, stderr, and logging statements are captured in a log group named /aws/lambda/<function-name>. Accessing this log group allows the engineer to view detailed error messages, stack traces, or timeout-related output that caused the 'Resource creation cancelled' failure.

Exam trap

The trap here is that candidates often confuse CloudFormation stack events (which show resource-level status) with the actual application logs from the Lambda function, leading them to choose Option D instead of recognizing that CloudWatch Logs is the correct source for debugging function execution failures.

How to eliminate wrong answers

Option A is wrong because AWS CodeBuild is a continuous integration service used to build and test code, not to view historical logs from a Lambda function that ran during a CloudFormation stack update; it cannot access CloudWatch Logs retroactively. Option B is wrong because CloudFormation does not have a 'detailed logging' feature that captures Lambda function execution logs; CloudFormation logs only its own orchestration events (e.g., resource creation, update, deletion) in stack events, not the application-level logs from the Lambda function itself. Option D is wrong because reviewing CloudFormation stack events in the AWS Management Console shows only the status and reason for each resource operation (e.g., 'Resource creation cancelled'), but does not include the actual stdout/stderr output or application logs from the Lambda function.

655
MCQmedium

A DevOps engineer needs to implement a CI/CD pipeline that builds a Docker image, scans it for vulnerabilities, and deploys it to Amazon ECS. The scanning must be integrated into the pipeline before the image is pushed to Amazon ECR. Which approach meets these requirements?

A.Enable ECR 'Scan on Push' and configure CodePipeline to deploy only if the scan result is clean.
B.Use CodeBuild to run a vulnerability scanner on the Docker image, then push to ECR only if the scan passes.
C.Use AWS Lambda to scan the image after push and automatically roll back if vulnerabilities are found.
D.Use AWS Security Hub to scan images in ECR and block deployment.
AnswerB

Running a scanner such as Trivy or Anchore inside a CodeBuild stage before the Docker push enforces a shift-left security gate; if the scanner exits with a non-zero code on critical/high vulnerabilities, the build fails and the image never reaches ECR. This keeps the registry free of vulnerable images and ensures only approved artifacts are available for subsequent pipeline stages.

Why this answer

It uses CodeBuild to run a vulnerability scanner on the Docker image before pushing to ECR, ensuring that only images that pass the scan are stored and deployed. This satisfies the requirement to scan before the image is pushed to ECR, which is critical for preventing vulnerable images from entering the registry.

Exam trap

The trap here is that candidates often confuse 'Scan on Push' (post-push) with pre-push scanning, or assume that Security Hub can directly scan and block deployments, when in reality it is an aggregation and correlation service, not a scanning engine.

Why the other options are wrong

A

Scan on Push scans after the image is pushed, not before. The requirement is to scan before push.

C

This scans after push, not before.

D

Security Hub aggregates findings but does not scan images itself; it relies on other services.

656
MCQeasy

A DevOps engineer is setting up a CI/CD pipeline for a microservices architecture. The team uses AWS CodeCommit, CodeBuild, and CodeDeploy. The engineer needs to ensure that the pipeline can automatically roll back the deployment if the health checks fail after deployment. Which action should the engineer take?

A.Use AWS Lambda to monitor health checks and trigger a rollback via the CodeDeploy API.
B.Configure the deployment group to roll back when a CloudWatch alarm is triggered.
C.Set up the deployment group to use blue/green deployment with traffic shifting.
D.Configure the pipeline to have a manual approval step after deployment.
AnswerB

CodeDeploy deployment groups support a built-in automatic rollback option triggered by CloudWatch alarms. When you configure one or more alarms in the deployment group, CodeDeploy monitors them during the deployment (and during traffic shifting for blue/green) and, if any alarm enters the ALARM state, it automatically rolls back the deployment to the last known good revision. This is a native, first-class feature that tightly integrates with Amazon CloudWatch and requires no custom code or external services, making it the recommended and correct way to achieve automated rollback on detected failures.

Why this answer

CodeDeploy natively supports automatic rollbacks triggered by CloudWatch alarms. By configuring the deployment group to monitor a CloudWatch alarm (e.g., based on ELB health check metrics), CodeDeploy will automatically initiate a rollback to the last known good revision if the alarm enters the ALARM state, ensuring health check failures are handled without custom scripting.

Exam trap

The trap here is that candidates often assume custom automation (like Lambda) is required for rollback, overlooking CodeDeploy's built-in CloudWatch alarm integration, which is the simplest and most reliable method for automatic rollback on health check failure.

How to eliminate wrong answers

Option A is wrong because while AWS Lambda can monitor health checks and call the CodeDeploy API, this approach introduces unnecessary complexity and custom code; CodeDeploy already provides built-in automatic rollback via CloudWatch alarms, which is the recommended and simpler solution. Option C is wrong because blue/green deployment with traffic shifting is a deployment strategy, not a rollback mechanism; it does not automatically revert the deployment if health checks fail unless combined with a rollback configuration. Option D is wrong because a manual approval step after deployment only pauses the pipeline for human review; it does not automate the rollback process and relies on manual intervention, which contradicts the requirement for automatic rollback.

657
MCQmedium

A company uses AWS CloudFormation StackSets to deploy a common security group across multiple accounts in an AWS Organization. The security group must allow inbound traffic from the organization's central VPN CIDR range. The VPN CIDR range is stored in AWS Systems Manager Parameter Store. How should the engineer reference this parameter in the StackSet template to ensure the value is resolved at deployment time?

A.Use Fn::ImportValue with an export from another stack that reads the parameter.
B.Use the dynamic reference '{{resolve:ssm:/org/vpn/cidr}}' in the template.
C.Use the Ref function on the parameter name as a CloudFormation parameter.
D.Use Fn::GetAtt to retrieve the parameter value from an AWS::SSM::Parameter resource.
AnswerB

The `{{resolve:ssm:/org/vpn/cidr}}` dynamic reference resolves the Parameter Store value at deployment time, satisfying the requirement that the CIDR is fetched when the StackSet instantiates stacks. Unlike hard-coded values or parameters passed manually, it retrieves the current stored value per account deployment, keeping the security group rule consistent with the central VPN range.

Why this answer

CloudFormation dynamic references ({{resolve:ssm:/org/vpn/cidr}}) allow you to retrieve the current value of an SSM Parameter Store parameter at stack deployment time, without needing to pass it as a parameter or create a separate resource. This ensures the security group rule always uses the latest VPN CIDR value stored in Parameter Store, even if the CIDR changes between deployments.

Exam trap

The trap here is that candidates often confuse dynamic references with CloudFormation parameters or intrinsic functions like Ref and Fn::GetAtt, not realizing that {{resolve:ssm:...}} is a special syntax that directly retrieves SSM parameter values without requiring a resource or parameter declaration.

How to eliminate wrong answers

Option A is wrong because Fn::ImportValue is used to import exported values from other stacks, not to resolve SSM parameters dynamically; it would require an intermediate stack that exports the parameter value, adding unnecessary complexity. Option C is wrong because using Ref on a parameter name would require the parameter value to be passed as a CloudFormation parameter input at stack creation, not resolved from SSM at deployment time. Option D is wrong because Fn::GetAtt retrieves attributes from a resource defined in the same template, but an AWS::SSM::Parameter resource would need to be created in the stack, which is not the intended pattern for referencing an existing parameter.

658
MCQeasy

A developer wants to automate the creation of a new Amazon ECS service whenever a new Docker image is pushed to Amazon ECR. Which AWS service should be used to orchestrate this workflow?

A.Amazon EventBridge
B.AWS Step Functions
C.Amazon CloudWatch Logs
D.Amazon S3
AnswerA

Amazon EventBridge natively ingests ECR lifecycle events such as an image push or scan, publishing them as event objects. You can define a rule with an event pattern matching the aws.ecr source and ECR Image Action detail-type, then route that event to a Lambda function that calls the ECS CreateService or UpdateService API. This is the correct mechanism because it is event-driven and requires no polling or manual invocation.

Why this answer

Amazon EventBridge can capture ECR image push events (via the 'ECR Image Action' event type) and route them to a target such as an ECS service or a Lambda function that triggers an ECS service update or creation. This serverless event bus natively integrates with ECR and ECS, making it the simplest and most direct service to orchestrate the workflow without custom polling or additional orchestration logic.

Exam trap

The trap here is that candidates often confuse AWS Step Functions as the primary orchestrator for event-driven workflows, but EventBridge is the correct service for reacting to AWS service events like ECR pushes, while Step Functions is for coordinating multi-step processes after the event is received.

How to eliminate wrong answers

Option B (AWS Step Functions) is wrong because Step Functions is a workflow orchestration service that coordinates multiple AWS services, but it is not designed to directly react to ECR push events; you would still need an event source like EventBridge to trigger the Step Function. Option C (Amazon CloudWatch Logs) is wrong because CloudWatch Logs is a log storage and monitoring service, not an event-driven workflow trigger; it cannot initiate ECS service creation. Option D (Amazon S3) is wrong because S3 is an object storage service and does not natively capture ECR push events or trigger ECS service creation; it would require additional custom logic to poll or be notified.

659
Multi-Selecthard

A DevOps team manages hundreds of EC2 instances using AWS Systems Manager State Manager. They need to ensure that a specific configuration (e.g., a custom firewall rule) is applied to all instances and remains enforced. Which THREE steps should they take? (Choose THREE.)

Select 3 answers
A.Ensure the instances have an IAM role that allows Systems Manager to perform actions.
B.Create a State Manager association using a custom document that defines the firewall rule.
C.Use AWS Config rules to detect non-compliance.
D.Use Run Command to execute the configuration once.
E.Set the association to apply the configuration on a schedule (e.g., every 30 minutes).
AnswersA, B, E

The SSM Agent running on each EC2 instance requires an IAM instance profile that grants Systems Manager API permissions, such as the AmazonSSMManagedInstanceCore managed policy. Without this role, the agent cannot register with the Systems Manager service or receive association requests, so any subsequent automation—including State Manager—will fail. This IAM prerequisite is non-negotiable and must be verified before creating associations or running documents.

Why this answer

AWS Systems Manager requires instances to have an IAM role that grants the necessary permissions (e.g., AmazonSSMManagedInstanceCore) for the SSM Agent to communicate with the Systems Manager service. Without this role, State Manager cannot apply or enforce any configuration, including custom firewall rules.

Exam trap

The trap here is that candidates often confuse AWS Config rules (which only detect drift) with State Manager associations (which both detect and automatically remediate drift), leading them to select Option C instead of Option E for enforcement.

660
Multi-Selectmedium

A company uses AWS CodeBuild to build and test a Node.js application. The buildspec.yml currently runs npm install and npm test. They want to also run a security scan using a third-party tool. Which THREE steps are required to integrate the security scan into the CodeBuild build?

Select 3 answers
A.Ensure the build fails if the scanner finds vulnerabilities by checking the exit code.
B.Create a new 'security' phase in the buildspec.yml.
C.Add a command to run the security scanner in the build phase.
D.Add a command to install the security scanning tool in the pre_build or build phase.
E.Upload the security scanner configuration to an S3 bucket and reference it in the buildspec.
AnswersA, C, D

CodeBuild evaluates each buildspec command's exit code; if the security scanner returns a non-zero exit status when vulnerabilities are found, the build phase will immediately fail. To guarantee this, invoke the scanner as the final command in the build phase or wrap its output so that any findings are translated into a non-zero exit code. Without this explicit exit-code enforcement, a scanner that always exits 0 would allow the pipeline to pass despite critical security findings.

Why this answer

CodeBuild phases (install, pre_build, build, post_build) run shell commands sequentially, and a non-zero exit code from any command causes the build to fail. By checking the exit code of the security scanner (e.g., via `$?` or relying on the tool's default exit behavior), the build will stop and report failure if vulnerabilities are found, enforcing a security gate. This is the standard mechanism to integrate third-party tools without custom scripting.

Exam trap

The trap here is that candidates think they need to create a custom phase (Option B) to run a security scan, but CodeBuild's fixed phases are sufficient—simply add the scanner command to the existing build phase after the test step.

661
MCQhard

Refer to the exhibit. The deployment succeeded but the application fails. What is the MOST likely cause?

A.The CodePipeline deployment action uses the wrong cluster.
B.The new task definition has a misconfigured database connection string or security group.
C.The ECS service is not registered with a target group.
D.The database is not available in the same Availability Zone.
AnswerB

A database connection timeout to the database IP address strongly indicates the new task definition is passing an invalid connection string or is associated with a security group that blocks the database port. The application container is starting and attempting to open a TCP connection, but the destination either rejects or silently drops it — exactly what a bad host, port, or restrictive inbound rule produces. This is an application-level configuration defect in the task definition that does not prevent the task from launching, which is why the deployment can still be marked successful.

Why this answer

The most common cause of a deployment succeeding but the application failing is a misconfiguration in the new task definition, such as an incorrect database connection string or a security group that does not allow traffic to the database. CodePipeline can successfully deploy the new task definition to ECS, but if the application cannot connect to its backend services due to these configuration errors, the application will fail at runtime. This aligns with the scenario where the deployment pipeline reports success but the application itself is non-functional.

Exam trap

The trap here is that candidates often assume a successful deployment means the application is fully functional, but AWS separates the deployment of infrastructure (task definition, service update) from the application's runtime dependencies, so a misconfigured connection string or security group can cause application failure post-deployment.

How to eliminate wrong answers

Option A is wrong because if the CodePipeline deployment action used the wrong cluster, the deployment would likely fail or the task would not run on the intended cluster, but the question states the deployment succeeded, so the cluster must be correct. Option C is wrong because if the ECS service were not registered with a target group, the deployment would still succeed (the task would run), but the service would not receive traffic from the load balancer; however, the question does not mention a load balancer or traffic routing issue, and the application failure is more likely due to a backend connectivity problem. Option D is wrong because database availability in the same Availability Zone is not a strict requirement for ECS tasks; ECS tasks can connect to databases across AZs as long as network connectivity and security group rules allow it, and the failure is more likely due to misconfigured connection strings or security groups.

662
Multi-Selecteasy

A company is using AWS KMS to encrypt data. Which TWO statements about AWS KMS key rotation are correct? (Choose TWO.)

Select 2 answers
A.Customer managed keys can be configured for automatic rotation
B.Keys imported into KMS support automatic rotation
C.Automatic rotation is enabled by default for customer managed keys
D.Automatic rotation can be disabled for AWS managed keys
E.AWS managed keys are automatically rotated every year
AnswersA, E

Customer managed keys can be configured for automatic rotation. Enabling this setting causes AWS KMS to automatically generate new key material for the CMK every 365 days, while retaining the previous material for decryption of existing ciphertext. You must explicitly opt in to this feature; it is not the default behavior.

Why this answer

Option A is correct because AWS KMS allows you to enable automatic rotation on customer managed keys, rotating the backing key material every year (365 days) while keeping the same key ID and ARN. Option E is correct because AWS managed keys are automatically rotated every year by AWS, with no configuration required or possible on the customer's part. Option B is incorrect because imported key material (keys with origin EXTERNAL) cannot be automatically rotated by KMS; you must manually rotate by re-importing new material.

Option C is incorrect because automatic rotation is opt-in for customer managed keys and is not enabled by default. Option D is incorrect because you cannot enable or disable rotation for AWS managed keys; AWS controls their rotation lifecycle entirely.

Exam trap

DOP-C02 often tests the distinction between customer managed keys (rotation configurable, off by default) and AWS managed keys (rotation mandatory every year, not configurable) — candidates frequently assume all KMS keys behave identically or that imported keys can auto-rotate.

663
MCQmedium

A DevOps engineer ran the above command and saw this output. What is the MOST likely cause of the stack creation failure?

A.The key pair specified in the launch template does not exist.
B.The IAM role does not have permission to create the Auto Scaling group.
C.The AMI ID specified in the launch template is not available in this Region.
D.The launch template name specified in the CloudFormation template is incorrect or does not exist.
AnswerD

When you reference a launch template by name in an Auto Scaling group's LaunchTemplateSpecification, CloudFormation and the Auto Scaling API require that the launch template already exists in the same account and Region. If the name is misspelled, or the launch template was created under a different account/Region or never created, the API returns an error indicating the launch template parameter is invalid or not found. The error message in the output is consistent with this cause, as it specifically flags the launch template name reference, not the AMI, key pair, or IAM permissions.

Why this answer

The error message indicates that the launch template name specified in the CloudFormation template does not match any existing launch template in the account and Region. CloudFormation resolves the launch template name at stack creation time; if the name is incorrect or the template does not exist, the Auto Scaling group creation fails with a validation error. This is the most direct cause because the launch template name is a required parameter that must reference a pre-existing resource.

Exam trap

The trap here is that candidates confuse launch template validation errors with instance-level errors (like missing AMI or key pair), but CloudFormation validates the launch template name at the Auto Scaling group resource level before any EC2 instances are launched.

How to eliminate wrong answers

Option A is wrong because a missing key pair would cause an EC2 instance launch failure, not a stack creation failure at the Auto Scaling group level; the error message would reference 'InvalidKeyPair.NotFound' or similar. Option B is wrong because an IAM role lacking permissions to create an Auto Scaling group would produce an 'AccessDenied' or authorization error, not a validation error about a missing launch template. Option C is wrong because an unavailable AMI ID would cause an instance launch failure with an 'InvalidAMIID.NotFound' error, not a stack creation failure related to the launch template name.

664
MCQeasy

A company is building a multi-tier web application on AWS. The web tier runs on EC2 instances behind an ALB. The application tier runs on EC2 instances that are not publicly accessible. The database tier runs on RDS MySQL. Which design provides the HIGHEST level of resilience for the database tier?

A.Deploy a single RDS DB instance in one Availability Zone.
B.Deploy an RDS DB instance with a cross-region read replica.
C.Deploy an RDS DB instance with a read replica in the same region.
D.Deploy an RDS DB instance in a Multi-AZ configuration.
AnswerD

Deploying an RDS DB instance in a Multi-AZ configuration creates a synchronous standby in a different Availability Zone and enables automatic failover. RDS monitors the primary instance and, if a failure is detected, automatically switches the endpoint to the standby, typically in 60–120 seconds. This is the standard RDS pattern for high availability within a single region.

Why this answer

Multi-AZ RDS automatically provisions and maintains a synchronous standby replica in a different Availability Zone. If the primary DB instance fails, RDS automatically fails over to the standby, providing high availability with minimal downtime. This design ensures the database tier remains resilient against AZ-level failures without manual intervention.

Exam trap

The trap here is that candidates often confuse read replicas (which are for read scaling and disaster recovery) with Multi-AZ deployments (which are for high availability and automatic failover), leading them to choose a read replica option for resilience.

How to eliminate wrong answers

Option A is wrong because a single RDS DB instance in one Availability Zone is a single point of failure; any AZ outage or instance failure will cause database downtime. Option B is wrong because a cross-region read replica provides disaster recovery and read scaling, but it is asynchronous and does not support automatic failover for high availability; it requires manual promotion to become the primary. Option C is wrong because a read replica in the same region is designed for offloading read traffic, not for automatic failover; it is asynchronous and cannot be used as a synchronous standby for high availability.

665
Multi-Selecthard

A company runs a containerized application on Amazon EKS. The application must be highly available across multiple Availability Zones and must automatically recover from node failures. Which THREE steps should be taken?

Select 3 answers
A.Use Pod Disruption Budgets to ensure a minimum number of pods are available during voluntary disruptions.
B.Configure the Cluster Autoscaler to add nodes when pods are unschedulable.
C.Deploy worker nodes across multiple Availability Zones.
D.Deploy worker nodes in a single Availability Zone to reduce cross-AZ data transfer costs.
E.Use a single large instance type for all worker nodes to simplify management.
AnswersA, B, C

Pod Disruption Budgets (PDBs) constrain voluntary disruptions such as node drains during cluster upgrades, node-group updates, or Cluster Autoscaler scale-in by specifying minAvailable or maxUnavailable for a pod selector. During a voluntary disruption, the Kubernetes eviction API rejects requests that would cause the number of available pods to fall below the budget. PDBs do not protect against involuntary failures like an EC2 instance crash, so they are a complement, not a substitute, for multi-AZ node deployment.

Why this answer

Pod Disruption Budgets (PDBs) are correct because they allow you to specify the minimum number of pods that must remain available during voluntary disruptions, such as node drains or cluster upgrades. This ensures that the application maintains high availability even when Kubernetes performs planned maintenance, preventing all replicas from being taken down simultaneously.

Exam trap

The trap here is that candidates often think deploying in a single AZ or using a single instance type simplifies management and reduces costs, but the DOP-C02 exam specifically tests the principle of designing for failure across multiple AZs and instance diversity to achieve true high availability.

666
Multi-Selecthard

Which THREE services can be used to protect a VPC from malicious traffic? (Choose 3.)

Select 3 answers
A.Network ACLs
B.Security Groups
C.AWS Shield
D.Amazon Route 53 Resolver
E.AWS Network Firewall
AnswersA, B, E

Network ACLs are a stateless firewall layer operating at the subnet boundary, inspecting traffic entering and leaving each subnet. Rules are evaluated in numeric order, and because they are stateless, you must explicitly allow both inbound and outbound traffic, including return traffic. By default, a custom Network ACL denies all traffic until you add allow rules, while the default NACL permits all traffic. This makes NACLs ideal for subnet-level deny lists and for enforcing broad boundaries, but they lack the stateful awareness of security groups.

Why this answer

Network ACLs (NACLs) are stateless, subnet-level firewalls that filter traffic based on rules evaluating source/destination IP, protocol, and port. They provide an additional layer of defense by explicitly allowing or denying inbound and outbound traffic at the subnet boundary, making them a correct choice for protecting a VPC from malicious traffic.

Exam trap

The trap here is that candidates often confuse AWS Shield (a DDoS protection service) with a VPC-level firewall, not realizing it operates at the edge/global layer and does not filter traffic within the VPC itself.

667
MCQmedium

A company uses an Auto Scaling group with a dynamic scaling policy based on the average CPU utilization of the instances. During an incident, the DevOps team notices that the Auto Scaling group is not launching new instances quickly enough to handle a traffic spike. What is a possible cause for the slow scaling response?

A.The cooldown period is set too high.
B.The health check grace period is set too low.
C.The minimum group size is set too low.
D.The launch template has a long warm-up time.
AnswerA

The cooldown period is a deliberate delay after a scaling activity before the group can launch or terminate additional instances. If set too high, it suppresses subsequent scaling actions for an extended time, so the group cannot keep pace with rapidly increasing demand. For a dynamic scaling policy, this directly prevents the Auto Scaling group from adding instances promptly, making scaling appear slow. Thus, an excessively high cooldown is a valid cause of the described problem.

Why this answer

A high cooldown period prevents the Auto Scaling group from launching additional instances immediately after a scaling activity, even if the CPU utilization remains high. During a traffic spike, if the cooldown is set too high, the group waits before responding to further scaling triggers, resulting in slow scale-out. Reducing the cooldown period allows the group to react more quickly to sustained high demand.

Exam trap

DOP-C02 often tests the confusion between cooldown (which throttles scaling actions) and health check grace period (which delays health checks) — candidates may pick the grace period thinking it affects scaling speed.

How to eliminate wrong answers

Option B is wrong because the health check grace period is the time ASG waits before checking the health of a newly launched instance; setting it too low would cause premature termination, not slow scaling. Option C is wrong because the minimum group size determines the baseline number of instances, not the speed of scaling out — a low minimum does not slow down the launch of new instances. Option D is wrong because the launch template does not have a 'warm-up time' parameter; while instance boot time can affect readiness, the question asks about the scaling response, and the cooldown is the direct throttle on scaling actions.

668
MCQhard

A company runs a critical application on Amazon ECS with Fargate launch type. The application uses an Application Load Balancer (ALB) in front. During a load test, the team notices a sudden increase in 5xx errors from the ALB, and some tasks become unhealthy. The task logs show occasional 'OutOfMemoryError' exceptions. The task definition currently has 512 CPU units and 1024 MiB memory. What should the team do to mitigate the issue while maintaining a cost-effective approach?

A.Increase the task definition CPU to 1024 units and memory to 2048 MiB.
B.Increase the task definition memory to 2048 MiB while keeping CPU at 512 units.
C.Configure the ECS service to use a rolling update with a longer health check grace period.
D.Decrease the task definition memory to 512 MiB to force garbage collection more frequently.
AnswerB

Raising the task memory to 2048 MiB while keeping CPU at 512 units is the minimal change that removes the hard memory limit causing the container's OOM kill. ECS enforces task memory as a cgroup limit, so the kernel terminates the process once the container's resident memory reaches that configured cap. This directly provides the application runtime sufficient headroom, uses the valid Fargate 0.5 vCPU / 2 GiB combination, and avoids wasting spend on CPU that was never the bottleneck.

Why this answer

The application is experiencing OutOfMemoryError, indicating the current 1024 MiB memory allocation is insufficient. Increasing memory to 2048 MiB while keeping CPU at 512 units directly resolves the memory constraint without unnecessary CPU cost. ECS Fargate allows independent scaling of CPU and memory within valid combinations, and this change maintains a cost-effective approach by only increasing the resource that is actually constrained.

Exam trap

The trap here is that candidates may assume both CPU and memory must be increased together (Option A) or that a deployment strategy change (Option C) can mitigate resource exhaustion, when in fact the root cause is a memory limit that must be raised independently.

How to eliminate wrong answers

Option A is wrong because it increases both CPU and memory, which is unnecessary and more costly; the issue is memory, not CPU, and the extra CPU units would not resolve OutOfMemoryError. Option C is wrong because a rolling update with a longer health check grace period does not address the root cause of memory exhaustion; it only delays health check failures without fixing the underlying resource shortage. Option D is wrong because decreasing memory to 512 MiB would exacerbate the OutOfMemoryError, causing more frequent failures and task crashes, not improving garbage collection behavior.

669
MCQhard

A company is using Amazon CloudWatch Synthetics canaries to monitor its web application endpoints. The canaries are deployed in multiple AWS regions. The team wants to aggregate the canary results into a single dashboard in the US East (N. Virginia) region. What is the MOST efficient way to achieve this?

A.Replicate the canaries to US East (N. Virginia) and run them from there.
B.Create a cross-region CloudWatch dashboard and add metrics from each region using metric math.
C.Set up a Lambda function in each region to push canary results to a central S3 bucket, then create a dashboard from S3.
D.Create a CloudWatch Logs Insights query across all regions and visualize results.
AnswerB

CloudWatch dashboards are not region-bound artifacts: each widget can explicitly specify a different source region, and metric math can combine those cross-region metrics within a single expression, for example summing SuccessPercent or averaging Duration across all canary regions. This natively aggregates the existing Synthetics metrics without duplicating canaries, running Lambda functions, or parsing logs. It is the intended, low-operational-overhead mechanism for a consolidated cross-region view and requires no custom infrastructure.

Why this answer

CloudWatch cross-region dashboards allow you to aggregate metrics from multiple regions into a single dashboard without data movement. By using metric math, you can reference metric IDs from different regions directly in the dashboard widget, enabling real-time aggregation of Synthetics canary success/failure rates and latency metrics from all regions into a unified view in US East (N. Virginia).

This approach avoids unnecessary data replication, reduces latency, and minimizes operational overhead.

Exam trap

The trap here is that candidates may assume cross-region aggregation requires data movement (e.g., to S3 or Lambda) or that CloudWatch dashboards are region-scoped, but AWS actually supports cross-region dashboards natively, making option B the most efficient and direct solution.

How to eliminate wrong answers

Option A is wrong because replicating canaries to US East (N. Virginia) would only monitor endpoints from that single region, losing the geographic distribution and failing to aggregate results from the original regions. Option C is wrong because pushing canary results to an S3 bucket and then creating a dashboard from S3 introduces unnecessary complexity, latency, and potential data staleness; CloudWatch Synthetics already stores metrics and logs in CloudWatch, so a cross-region dashboard is more direct and efficient.

Option D is wrong because CloudWatch Logs Insights queries cannot span multiple regions; they are scoped to a single region and log group, making cross-region aggregation impossible without additional tooling.

670
MCQmedium

A company is using AWS CloudFormation to deploy infrastructure. They want to receive notifications when a stack operation fails, including the specific resource that caused the failure. Which approach should they use?

A.Create a CloudWatch alarm on the 'StackFailure' metric.
B.Configure an SNS topic as a notification option in the CloudFormation stack and subscribe to receive stack events.
C.Create an AWS Lambda function that polls the CloudFormation DescribeStackEvents API every minute and sends an email on failure.
D.Enable AWS CloudTrail to log CloudFormation API calls and configure an SNS notification on the trail.
AnswerB

Configuring an SNS topic as a stack notification option delivers every CloudFormation stack event, including ResourceStatusReason for the specific resource that failed, satisfying the requirement to identify the failing resource. Subscribing an email or Lambda endpoint to that topic then surfaces the failure notification automatically.

Why this answer

CloudFormation allows you to specify an SNS topic ARN as a notification option when creating or updating a stack. When a stack operation fails, CloudFormation publishes a notification to that SNS topic, and the notification includes the logical resource ID and the status reason for the failure. This provides real-time, event-driven notifications without requiring polling or additional services.

Exam trap

The trap here is that candidates may confuse CloudWatch metrics or CloudTrail with CloudFormation's native notification capability, assuming that failure events are exposed as metrics or logs rather than through SNS topic subscriptions.

How to eliminate wrong answers

Option A is wrong because CloudFormation does not emit a 'StackFailure' metric to CloudWatch; CloudFormation publishes stack events to SNS topics, not CloudWatch metrics. Option C is wrong because polling the DescribeStackEvents API every minute introduces latency, unnecessary cost, and complexity compared to the native SNS notification mechanism; it also violates the principle of event-driven architecture. Option D is wrong because AWS CloudTrail logs API calls for auditing, but it does not provide real-time notifications on stack operation failures; configuring SNS on a trail only delivers log file delivery notifications, not stack failure events.

671
MCQhard

A company runs a critical application on Amazon ECS with the Fargate launch type. The application is deployed across three Availability Zones. Each service has its own Application Load Balancer. The company wants to implement a blue/green deployment strategy to reduce risk. They currently use AWS CodeDeploy for ECS deployments. During a recent deployment, the company noticed that the new version (green) was not receiving any traffic even after passing all health checks. The CodeDeploy configuration uses a 'Linear10PercentEvery3Minutes' traffic shifting configuration. What is the most likely reason that the green tasks are not receiving traffic?

A.The CodeDeploy deployment group is not associated with the correct ECS service.
B.The green target group's health check is misconfigured, causing CodeDeploy to consider the green tasks unhealthy and not route traffic.
C.The blue target group is still set as the production target group in the load balancer listener.
D.The green tasks are in a different VPC than the load balancer.
AnswerB

In CodeDeploy's ECS blue/green deployment, the green target group's health checks are the gating mechanism for traffic shifting. If the health check path, port, or interval is misconfigured, the green tasks are marked unhealthy even though the containerized application is running normally, so CodeDeploy never receives the signal that the green fleet is ready. As a result, the listener remains pointed at the blue target group, and the deployment times out waiting for a healthy green target.

Why this answer

The green target group's health check is misconfigured, causing CodeDeploy to consider the green tasks unhealthy. With a 'Linear10PercentEvery3Minutes' traffic shifting configuration, CodeDeploy gradually shifts traffic in 10% increments every 3 minutes, but only if the green target group passes health checks. If the health check fails, CodeDeploy stops traffic shifting, leaving the green tasks with zero traffic despite the tasks themselves being healthy.

Exam trap

The trap here is that candidates assume health checks passing on the ECS tasks means traffic will automatically route, but CodeDeploy relies on the target group's health check configuration, not the task's health status, to determine when to shift traffic.

How to eliminate wrong answers

Option A is wrong because if the CodeDeploy deployment group were not associated with the correct ECS service, the deployment would fail entirely or target the wrong service, but the green tasks would still be created and potentially receive traffic if health checks passed. Option C is wrong because CodeDeploy automatically updates the load balancer listener rules to point to the green target group during the traffic shifting process; the blue target group being set as production is the initial state, but CodeDeploy changes it as traffic shifts. Option D is wrong because ECS Fargate tasks and the load balancer must be in the same VPC for the service to function; if they were in different VPCs, the service would not register targets or pass health checks at all, not just fail to receive traffic after health checks pass.

672
MCQmedium

A company uses AWS CloudFormation to manage infrastructure. They have a production stack that creates an Auto Scaling group. They want to update the launch configuration to use a new Amazon Machine Image (AMI) ID without causing downtime. Which update policy should they set on the Auto Scaling group?

A.AutoScalingScheduledAction
B.AutoScalingReplacingUpdate
C.AutoScalingRollingUpdate
D.AutoScalingBatchUpdate
AnswerC

AutoScalingRollingUpdate replaces instances in batches, maintaining a minimum number of healthy instances throughout the update. This satisfies the no-downtime constraint by keeping the Auto Scaling group serving traffic while new AMI-based instances launch and old ones terminate, rather than replacing all instances simultaneously.

Why this answer

The AutoScalingRollingUpdate policy allows CloudFormation to update the Auto Scaling group's launch configuration by gradually replacing instances in batches, ensuring that a minimum number of instances remain in service throughout the update. This prevents downtime by terminating old instances and launching new ones with the updated AMI in a controlled, rolling fashion.

Exam trap

The trap here is that 'AutoScalingReplacingUpdate' is a valid CloudFormation update policy, but it replaces the entire Auto Scaling group at once, causing downtime. Candidates may mistakenly choose it thinking it's the only policy that updates launch configurations, but 'AutoScalingRollingUpdate' does so gradually, avoiding downtime.

How to eliminate wrong answers

Option A is wrong because AutoScalingScheduledAction is used to define time-based scaling actions (e.g., increase capacity at a specific time), not to manage rolling updates or replace launch configurations. Option B is wrong because AutoScalingReplacingUpdate is not a valid CloudFormation update policy; the correct term for a full replacement update is 'AutoScalingReplacingUpdate' does not exist—CloudFormation uses 'AutoScalingRollingUpdate' for rolling updates and 'AutoScalingScheduledAction' for scheduled actions. Option D is wrong because AutoScalingBatchUpdate is not a valid CloudFormation update policy; the service does not support a 'batch' update policy—rolling updates are the only native mechanism for gradual replacement.

673
Multi-Selecteasy

A company is designing a highly available architecture for a web application using AWS. Which TWO of the following design principles should be applied? (Select TWO.)

Select 2 answers
A.Run all resources in a single Availability Zone to reduce complexity
B.Store session data on EC2 instances to improve performance
C.Deploy resources across multiple Availability Zones
D.Use loosely coupled components, such as queues and asynchronous processing
E.Use tightly coupled components to reduce latency
AnswersC, D

Deploying across multiple Availability Zones (AZs) is the primary AWS design pattern for high availability because each AZ is an independent failure domain with separate power, cooling, and networking. By placing resources (e.g., application servers behind an Application Load Balancer, and a Multi-AZ database) in at least two AZs, the workload can continue serving traffic if one AZ suffers an outage, as the load balancer automatically routes requests only to healthy instances in the remaining AZs. This approach directly satisfies the requirement for fault tolerance, and when combined with Auto Scaling, it also provides capacity to absorb increased load in the surviving AZs.

Why this answer

Correct answers: C and D. Deploying resources across multiple Availability Zones (C) ensures high availability by tolerating an AZ failure. Using loosely coupled components like queues (D) improves resilience by decoupling components, preventing cascading failures and allowing independent scaling.

Option A is wrong because running in a single AZ creates a single point of failure. Option B is wrong because storing session data on EC2 instances is not recommended for high availability; session data should be stored externally (e.g., ElastiCache or DynamoDB). Option E is wrong because tightly coupled components increase dependency and reduce fault tolerance.

674
MCQmedium

A DevOps engineer creates the IAM policy above for an instance role. The role is attached to an EC2 instance that runs an application. The application starts and stops EC2 instances and reads a database password from Systems Manager Parameter Store. However, the application fails to retrieve the parameter. What is the most likely cause?

A.The policy does not allow 'ssm:GetParameterHistory'.
B.The policy does not allow 'ec2:DescribeParameters'.
C.The parameter is a SecureString and the policy does not grant 'kms:Decrypt' permission for the KMS key.
D.The policy does not allow 'ssm:GetParameter' on the specific resource.
AnswerC

When a parameter is stored as a SecureString, its value is encrypted at rest using an AWS KMS key, either the default aws/ssm key or a customer-managed key. To retrieve the plaintext value via ssm:GetParameter, the caller must have kms:Decrypt permission on that specific KMS key, in addition to the ssm:GetParameter action on the parameter resource. The policy shown grants the SSM read action but omits kms:Decrypt, so even though the resource-level SSM permission is correct, the call fails with an AccessDeniedException.

Why this answer

The policy allows 'ssm:GetParameter' and 'ssm:GetParameters' on the specific parameter ARN. However, to retrieve a parameter, the action 'ssm:GetParameter' is sufficient, but the resource ARN must be correct. The given ARN includes the parameter name '/MyApp/DBPassword'.

If the application is using a different path or the parameter is encrypted, the policy might be insufficient. But the most common issue is that the parameter is a SecureString and the policy also needs 'kms:Decrypt' access to the KMS key. Option C is correct because the policy does not include KMS permissions.

Option A and B are less likely. Option D is incorrect because the actions are allowed.

675
MCQmedium

A company uses AWS Elastic Beanstalk for its web application. After a deployment, the environment health changes to 'Severe' and the application becomes unresponsive. The DevOps team needs to quickly revert to the previous working version. What is the FASTEST way to achieve this?

A.Use the Elastic Beanstalk console to deploy the previous application version.
B.Swap environment URLs with a different environment that runs the previous version.
C.Terminate the environment and create a new one with the previous version.
D.Redeploy the same application version to the environment.
AnswerA

Redeploying the previous application version through the Elastic Beanstalk console triggers a fresh environment update that restores the last known-good build, directly reversing the faulty deployment. This is faster than rebuilding the environment or manually patching instances, satisfying the requirement to quickly revert to the previous working version.

Why this answer

Deploying the previous application version through the Elastic Beanstalk console is the fastest rollback because Beanstalk retains prior application versions and can redeploy one directly to the same environment, restoring the working state without rebuilding infrastructure. This is the standard, quickest recovery path.

Exam trap

DOP-C02 often tests the difference between a fast in-place rollback (redeploy previous version) and a blue/green swap, tempting candidates to pick URL swap even when no second environment exists.

How to eliminate wrong answers

Option B is wrong because swapping environment URLs requires a separate environment already running the previous version; if one doesn't exist, this is slower and more complex than a direct redeploy. Option C is wrong because terminating and recreating an environment is slow and disruptive, losing configuration and taking minutes to provision. Option D is wrong because redeploying the same broken version does nothing to fix the issue and would leave the environment unhealthy.

Page 8

Page 9 of 18

Page 10