Courseiva

CCNA Configuration Management and IaC Questions

75 of 215 questions · Page 2/3 · Configuration Management and IaC · Answers revealed

76
MCQhard

An organization uses AWS Elastic Beanstalk for application deployments. They want to implement immutable updates to minimize downtime and ensure that if the new environment fails health checks, the old environment remains intact. Which deployment policy should they choose?

A.Traffic splitting.
B.Immutable update.
C.All at once.
D.Rolling update based on health.
AnswerB

Immutable update deploys the new application version to a completely new set of instances (or a fully separate environment) that runs alongside the old fleet. It waits for all new instances to pass health checks before shifting traffic to them, and if any fail, the old environment remains untouched, enabling an immediate, zero-impact rollback. This provides the strongest availability and isolation, making it the safest deployment policy.

Why this answer

Immutable updates in AWS Elastic Beanstalk launch a completely new environment with the new application version. If the new environment fails health checks, Elastic Beanstalk automatically terminates it, leaving the original environment untouched. This ensures zero downtime and a safe rollback, which matches the requirement to keep the old environment intact if health checks fail.

Exam trap

The trap here is that candidates confuse 'immutable update' with 'traffic splitting' because both involve a new environment, but traffic splitting does not automatically terminate the new environment on health check failure—it requires manual intervention or additional automation to roll back.

How to eliminate wrong answers

Option A is wrong because traffic splitting gradually shifts a percentage of traffic to a new environment, but if health checks fail, the old environment is not guaranteed to remain intact—the new environment may still be partially serving traffic and the rollback is not fully automated. Option C is wrong because all-at-once deploys replace all instances simultaneously, causing downtime and leaving no fallback environment if health checks fail. Option D is wrong because rolling update based on health replaces instances in batches and can terminate unhealthy instances in the old environment, potentially disrupting the original environment before the new one is fully verified.

77
MCQmedium

A company uses AWS Elastic Beanstalk to deploy a web application. The environment is running behind an Application Load Balancer. The DevOps team notices that during deployments, the new application version fails health checks and the deployment rolls back. The team wants to reduce deployment time while maintaining safety. Which configuration change should the engineer recommend?

A.Increase the number of EC2 instances in the environment.
B.Use the all-at-once deployment policy.
C.Change the deployment policy to immutable.
D.Increase the rolling update batch size to 100%.
AnswerC

Changing the deployment policy to immutable launches a fully new Auto Scaling group with the new application version while the old group continues serving traffic. Once the new instances pass health checks, Elastic Beanstalk swaps the environment's capacity to the new group, providing both safety and minimal downtime. This is the correct choice because it verifies the deployment before cutting over, unlike rolling or all-at-once strategies that update existing instances in place.

Why this answer

The immutable deployment policy in AWS Elastic Beanstalk creates a new Auto Scaling group with fresh instances running the new application version, performs health checks, and only then swaps the environment's target group to route traffic to the new fleet. This avoids the rolling update's problem of health check failures on existing instances (which trigger a rollback) and ensures the entire new environment is validated before any traffic is shifted. While immutable deployments can take longer than a successful rolling update because they provision a full new fleet, they reduce overall deployment time in this scenario by preventing repeated failed deployments and rollbacks, and they maintain safety by not exposing partially updated instances.

Exam trap

The trap is assuming that increasing batch size or instance count accelerates a rolling update, but the real issue is failed health checks during the rolling update causing rollbacks. Immutable deployments bypass this by launching and validating a completely new set of instances before switching traffic, rather than relying on modifications to the existing fleet.

How to eliminate wrong answers

Option A is wrong because increasing the number of EC2 instances does not change the deployment mechanism; it only adds capacity, which does not prevent health check failures during a rolling update or reduce deployment time. Option B is wrong because the all-at-once deployment policy deploys the new version to all instances simultaneously, which would cause immediate health check failures on all instances and a full rollback, increasing downtime and not reducing deployment time safely. Option D is wrong because increasing the rolling update batch size to 100% is effectively the same as all-at-once, which would cause all instances to be updated at once, leading to health check failures and a full rollback, not a safe or faster deployment.

78
MCQhard

A team manages a large fleet of EC2 instances using AWS Systems Manager. They want to enforce a consistent configuration across all instances, including installed software packages, firewall rules, and user accounts. The team also needs to audit configuration changes and remediate drift automatically. Which AWS service should the team use?

A.AWS OpsWorks for Chef Automate
B.AWS Systems Manager State Manager
C.AWS Systems Manager Run Command
D.AWS Config
AnswerB

AWS Systems Manager State Manager is the correct choice because it lets you define a desired configuration state (such as specific software packages, user accounts, or agent settings) and automatically apply and maintain that state on your EC2 fleet. It uses associations that run on a schedule, detect drift from the defined state, and reapply the configuration whenever needed. Unlike ad-hoc tools, State Manager continuously enforces the desired state across instances with built-in rate controls and error handling, making it ideal for managing large fleets.

Why this answer

AWS Systems Manager State Manager is the correct choice because it is designed to enforce a consistent configuration across EC2 instances by defining and applying desired state configurations (DSCs). It can manage software packages, firewall rules, and user accounts, and it automatically remediates drift by re-applying the desired state on a schedule. This directly meets the requirement for configuration enforcement, auditing, and automated drift remediation.

Exam trap

The trap here is confusing AWS Config (which only audits and detects drift) with State Manager (which enforces and remediates drift), leading candidates to choose Config because they focus on the auditing requirement without realizing it lacks enforcement capabilities.

How to eliminate wrong answers

Option A is wrong because AWS OpsWorks for Chef Automate is a configuration management service that uses Chef cookbooks, but it requires managing a Chef server and does not natively integrate with Systems Manager for drift remediation or auditing without additional setup. Option C is wrong because AWS Systems Manager Run Command is designed for ad-hoc, one-time command execution across instances, not for enforcing ongoing desired state configurations or automatically remediating drift. Option D is wrong because AWS Config is a service for auditing resource configurations and tracking changes, but it does not enforce configurations or remediate drift; it only detects non-compliance and can trigger remediation actions via other services like Systems Manager Automation.

79
Multi-Selecteasy

A company is designing a CI/CD pipeline using AWS CodePipeline, CodeBuild, and CodeDeploy. They need to ensure that the pipeline can deploy to multiple environments (dev, test, prod) with manual approval gates. Which TWO actions should they take? (Choose TWO.)

Select 2 answers
A.Create separate stages in the pipeline for dev, test, and prod
B.Configure a single pipeline with multiple branches in the source stage
C.Use CodeDeploy deployment groups to represent each environment
D.Add a manual approval stage before each environment deployment
E.Use CodeBuild batch builds to manage environment promotion
AnswersA, D

Separate stages in CodePipeline provide a sequential execution model where each stage contains a set of actions that deploy or test an environment. By defining dev, test, and prod as distinct stages, you enforce an ordered promotion flow, allow artifacts to progress only after each stage succeeds, and can insert approval actions between them. This is the fundamental way to model environment promotion in CodePipeline.

Why this answer

AWS CodePipeline allows you to define separate stages for each environment (dev, test, prod) within a single pipeline. This enables sequential or parallel deployments with clear separation of concerns, and each stage can have its own actions, such as deployment to a specific CodeDeploy application or environment. Option D is correct because you can add a manual approval action as a stage gate before each environment deployment, ensuring that a human reviewer must explicitly approve the promotion before the pipeline proceeds to the next environment.

Exam trap

The trap here is that candidates often confuse CodeDeploy deployment groups with environment stages, thinking that a single deployment group can represent an entire environment, when in fact deployment groups are compute targets within an environment and do not provide the stage-level orchestration or manual approval gates that CodePipeline stages offer.

80
MCQmedium

An organization uses OpsWorks to manage application stacks. They notice that custom cookbooks are not being executed during the lifecycle events. What is the most likely cause?

A.The layer's IAM role does not have permissions to execute the cookbook
B.The custom cookbook repository URL is misconfigured or inaccessible
C.The cookbook is not configured with CodeDeploy
D.The cookbook uses a Chef version that is not supported by OpsWorks
AnswerB

OpsWorks Stacks downloads custom cookbooks from the source repository during the setup phase and then runs the recipes defined for each lifecycle event. If the repository URL is malformed, points to a private repo with invalid credentials, or the endpoint is unreachable, the agent cannot retrieve the cookbook and therefore cannot execute any recipes. The failure may appear as 'non-execution' because the instance comes online but nothing from the cookbook is applied, and the error is only visible if you inspect the OpsWorks agent logs or stack activity.

Why this answer

Custom cookbooks in AWS OpsWorks are fetched from a repository (e.g., Git, S3, HTTP) during lifecycle events. If the repository URL is misconfigured (e.g., wrong branch, invalid path) or inaccessible (e.g., private repo without proper SSH keys or S3 bucket permissions), OpsWorks cannot retrieve the cookbooks, causing them to not execute. This is the most common cause of cookbook execution failures.

Exam trap

The trap here is that candidates often confuse IAM permissions with repository access, assuming the layer's IAM role controls cookbook retrieval, when in fact OpsWorks uses separate SSH keys or S3 bucket policies for repository access.

How to eliminate wrong answers

Option A is wrong because the layer's IAM role is used for AWS API calls (e.g., EC2, CloudWatch), not for executing Chef cookbooks; cookbook execution is handled by the Chef client locally. Option C is wrong because CodeDeploy is a separate AWS service for application deployments and is not involved in OpsWorks Chef cookbook execution; OpsWorks uses its own lifecycle event system. Option D is wrong because OpsWorks supports Chef 11.10, 12, and 12.2; if a cookbook uses an unsupported version, the error would occur during Chef run, not silently skip execution, and OpsWorks would log a version mismatch error.

81
MCQeasy

A DevOps engineer is using AWS CodeBuild to build a container image and push it to Amazon ECR. The buildspec.yml file includes a post_build phase that runs `docker push`. The build fails with an error indicating that the Docker daemon is not available. The CodeBuild project uses the `aws/codebuild/standard:5.0` image and has privileged mode disabled. Which action should the engineer take to resolve the issue?

A.Enable privileged mode in the CodeBuild project configuration.
B.Add a pre_build phase to start the Docker daemon manually using `sudo service docker start`.
C.Use the `docker buildx` command instead of `docker build` to avoid needing privileged mode.
D.Switch to a custom build image that includes Docker pre-installed and configured.
AnswerA

Docker requires privileged mode to run inside a container. AWS CodeBuild projects must have privileged mode enabled to build Docker images. Enabling it allows the Docker daemon to run, resolving the error. This is a common configuration for building container images in CodeBuild and is the minimal change needed to fix the issue.

Why this answer

Docker requires privileged mode in CodeBuild to run the Docker daemon. Enabling privileged mode in the project configuration allows Docker commands to execute, resolving the error. Other options do not address the underlying permission issue and would not allow Docker to run.

Exam trap

The trap here is assuming that Docker can run in CodeBuild without privileged mode, leading to attempts to start the daemon manually or change images.

82
MCQeasy

A company uses AWS CodeDeploy to deploy applications to an Auto Scaling group. The deployment fails because the new version of the application crashes the instances. The DevOps engineer needs the Auto Scaling group to automatically replace the unhealthy instances with the previous working version. Which deployment configuration should the engineer use?

A.In-place deployment with a deployment group that has a failure threshold of 0.
B.Blue/Green deployment with a load balancer to switch traffic only after health checks pass.
C.Canary deployment that shifts 10% of traffic to the new version, then 100% after 10 minutes.
D.Linear deployment that shifts 10% of traffic every 10 minutes.
AnswerB

Blue/Green deployment creates a completely separate green environment and reroutes traffic only after the new instances pass health checks. The load balancer is the key component: it keeps traffic anchored to the blue environment until the green is verified healthy, and if health checks fail, you simply do not cut over or you can switch back to blue instantly. This gives an automatic, low-risk rollback path because the original environment remains intact and available. Thus, it satisfies the need to revert to the original version when issues are detected.

Why this answer

A blue/green deployment with a load balancer health check ensures that the new (green) instances are validated before any traffic is routed to them. If the new version crashes, the health checks fail, the load balancer keeps traffic on the old (blue) instances, and the Auto Scaling group can automatically terminate the unhealthy green instances and replace them with the previous working version by reverting to the original launch configuration or template.

Exam trap

The trap here is that candidates often confuse deployment strategies (in-place, canary, linear) with rollback mechanisms, assuming that any traffic-shifting method automatically replaces unhealthy instances with the previous version, when in fact only blue/green deployments inherently isolate the new environment and allow a clean revert without affecting the old instances.

How to eliminate wrong answers

Option A is wrong because an in-place deployment with a failure threshold of 0 means the deployment will stop as soon as any single instance fails, but it does not automatically replace unhealthy instances with the previous working version; it simply halts the deployment, leaving the failed instances in place. Option C is wrong because a canary deployment shifts a small percentage of traffic to the new version and then fully shifts after a time window, but if the new version crashes instances, the canary instances become unhealthy and the deployment may still proceed to full rollout if the health check grace period expires, failing to automatically revert to the previous version. Option D is wrong because a linear deployment incrementally shifts traffic in steps, but like the canary, it does not inherently replace crashed instances with the previous working version; it only controls traffic shifting, not instance recovery or rollback.

83
MCQmedium

A DevOps engineer is designing a configuration management solution for a fleet of EC2 instances. The instances are ephemeral and frequently replaced by an Auto Scaling group. The engineer needs to ensure that newly launched instances are automatically configured with the latest software packages and settings. Which AWS service should be used?

A.AWS CodeDeploy
B.AWS OpsWorks Stacks
C.AWS CloudFormation
D.AWS Systems Manager State Manager
AnswerD

AWS Systems Manager State Manager is the correct choice because it enforces desired configuration on managed instances through associations. An association defines a set of actions, such as running a custom SSM document or a Chef recipe, and State Manager executes it according to a schedule to ensure the instance remains compliant. If an instance drifts from the desired state, the next scheduled execution brings it back, providing continuous configuration management for both EC2 and hybrid instances.

Why this answer

AWS Systems Manager State Manager is the correct choice because it provides a configuration management solution that ensures EC2 instances maintain a desired state. It uses associations to define the software packages, settings, and policies that should be applied to instances, and it automatically applies these configurations to newly launched instances, including those in an Auto Scaling group, without requiring custom scripts or manual intervention.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager State Manager with AWS CodeDeploy or AWS CloudFormation, mistakenly thinking that deployment or provisioning tools also handle ongoing configuration management, but State Manager is specifically designed for maintaining desired state on running instances.

How to eliminate wrong answers

Option A is wrong because AWS CodeDeploy is a deployment service for automating application code deployments, not a configuration management tool for maintaining desired state across ephemeral instances. Option B is wrong because AWS OpsWorks Stacks uses Chef or Puppet for configuration management but requires a persistent stack and agent management, making it less suitable for ephemeral instances that are frequently replaced by Auto Scaling groups. Option C is wrong because AWS CloudFormation is an Infrastructure as Code (IaC) service for provisioning and managing AWS resources, not for ongoing configuration management of software packages and settings on running instances.

84
MCQmedium

A company uses AWS CloudFormation to manage its infrastructure. The DevOps team wants to ensure that stack updates do not accidentally delete critical resources like a database. Which CloudFormation stack policy should they apply to protect the database resource?

A.Create a stack policy that denies delete actions on the logical resource ID of the database.
B.Apply an IAM policy that denies cloudformation:DeleteStack on the database.
C.Use an S3 bucket policy to deny deletion of the database snapshot.
D.Enable termination protection on the CloudFormation stack.
AnswerA

A stack policy is a JSON document attached to a CloudFormation stack that controls which update, replacement, or deletion actions are allowed on the stack's resources. By writing a statement that denies the Delete action on the logical resource ID of the database (e.g., the AWS::RDS::DBInstance resource), CloudFormation will refuse to remove or replace that resource during any stack update. This protects the database from being deleted as a side effect of an update, while still permitting other modifications to proceed.

Why this answer

A CloudFormation stack policy allows you to define resource-level permissions that prevent specific resources (identified by their logical resource ID) from being updated or deleted during a stack update. By creating a policy that denies delete actions on the database's logical resource ID, the DevOps team ensures that even if the template or parameters change, the database resource cannot be accidentally removed.

Exam trap

The trap here is that candidates confuse termination protection (which prevents stack deletion) with resource-level protection during updates, leading them to choose option D instead of understanding that stack policies are needed for granular resource safeguards.

How to eliminate wrong answers

Option B is wrong because an IAM policy denying cloudformation:DeleteStack would block the entire stack deletion, not protect individual resources like a database during an update; it does not prevent resource-level deletion within an update. Option C is wrong because an S3 bucket policy controls access to S3 buckets and objects, not CloudFormation resources; database snapshots are not managed by S3 bucket policies in this context. Option D is wrong because termination protection only prevents the entire stack from being deleted, not individual resources from being replaced or removed during a stack update.

85
MCQeasy

A company uses AWS Systems Manager to manage a fleet of EC2 instances. They need to run a script on all instances that have a specific tag 'Environment:Development'. Which Systems Manager capability should be used?

A.Inventory
B.Patch Manager
C.Run Command
D.State Manager
AnswerC

Run Command is the correct choice because it provides secure, on-demand remote execution of scripts and commands across EC2 instances, targeting tagged instances through AWS resource groups or tag key-value pairs. It uses SSM documents to define the script and the SSM Agent to execute it, with results streamed back to the console or S3. This directly matches the requirement to run a script on a fleet selected by tags.

Why this answer

Run Command is the correct capability because it allows you to remotely and securely execute scripts or commands on targeted EC2 instances using AWS Systems Manager. You can target instances by specifying tags, such as 'Environment:Development', and Run Command will execute the script on all matching instances without requiring SSH or RDP access.

Exam trap

The trap here is confusing Run Command with State Manager, as both can execute scripts, but State Manager is for recurring, state-enforcement tasks (using associations), not for immediate, tag-based ad-hoc execution.

How to eliminate wrong answers

Option A is wrong because Inventory is used to collect metadata and configuration data from instances (e.g., installed applications, network configuration), not to execute scripts. Option B is wrong because Patch Manager is designed to automate the process of patching operating systems and applications, not for running arbitrary scripts. Option D is wrong because State Manager is used to define and maintain consistent state configurations (e.g., ensuring a specific software is installed) on a schedule, not for ad-hoc or on-demand script execution.

86
MCQmedium

An organization uses AWS Elastic Beanstalk to deploy a web application. They need to ensure that configuration changes (e.g., environment variables, instance types) are version-controlled and can be rolled back. Which approach meets these requirements?

A.Use AWS Systems Manager Parameter Store to store configuration values.
B.Create a custom script that uses the Elastic Beanstalk API to apply configuration and store the script in a Git repository.
C.Use Elastic Beanstalk saved configurations to capture environment settings and store the configuration files in a version control system.
D.Manually record all configuration changes in a spreadsheet.
AnswerC

Elastic Beanstalk saved configurations capture environment option settings into a JSON or YAML template that can be downloaded and committed to version control. These templates can be applied to new or existing environments with a direct API/CLI call, enabling repeatable deployment and rollback to a known good state. Because the configuration file is just a file in your repository, you get code review, history, and drift detection naturally.

Why this answer

Elastic Beanstalk saved configurations allow you to capture the complete environment settings (including environment variables, instance types, and other configuration options) as a YAML or JSON file. By storing these configuration files in a version control system (e.g., Git), you achieve version-controlled configuration that can be applied to recreate or roll back an environment to a known state using the `eb config` command or the AWS Management Console.

Exam trap

The trap here is that candidates often confuse storing individual parameters (Parameter Store) with capturing the entire environment configuration, or they overcomplicate the solution with custom scripts when Elastic Beanstalk provides a built-in, versionable saved configuration feature that directly meets the requirement.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Parameter Store is a service for storing individual parameter values (e.g., database passwords, API keys) and does not capture the full Elastic Beanstalk environment configuration (such as instance type, scaling settings, or environment links) nor does it provide a mechanism to roll back an entire environment to a previous state. Option B is wrong because creating a custom script that uses the Elastic Beanstalk API to apply configuration and storing it in Git is an ad-hoc, error-prone approach that does not leverage Elastic Beanstalk's native saved configuration feature, which already provides a standardized, versionable format for environment settings. Option D is wrong because manually recording changes in a spreadsheet is not automated, not version-controlled in a meaningful way, and does not provide any mechanism to programmatically apply or roll back configuration changes.

87
Multi-Selectmedium

A company is using AWS CloudFormation to manage its infrastructure. The DevOps team wants to implement drift detection to identify resources that have been modified outside of CloudFormation. Which TWO of the following are correct statements about CloudFormation drift detection?

Select 2 answers
A.Drift detection is automatically performed every time the stack is updated.
B.Drift detection can be performed on nested stacks independently.
C.Drift detection automatically reverts any changes to the original template.
D.Drift detection can detect changes to resources such as security groups.
E.Drift detection can be performed on a stack at any time.
AnswersD, E

Security groups are among the resource types for which CloudFormation compares the live configuration—such as ingress rules, egress rules, and group name/description—against the template. If someone adds or removes a rule out-of-band, drift detection marks the security group as MODIFIED. This makes drift detection useful for catching unauthorized network-level changes to your VPC infrastructure.

Why this answer

Drift detection can detect changes to resources such as security groups because CloudFormation supports drift detection for a wide range of AWS resources, including EC2 security groups. When drift detection is performed, CloudFormation compares the current configuration of each supported resource in the stack with the expected configuration defined in the stack template. If a security group rule is added or removed outside of CloudFormation (e.g., via the AWS Console or CLI), drift detection will report that resource as drifted.

Exam trap

The trap here is that candidates often assume drift detection is automatic or can fix drift, but AWS explicitly requires manual initiation and only provides detection, not remediation.

88
MCQhard

A DevOps engineer creates the CloudFormation template shown in the exhibit. When the stack is created, the EC2 instance is launched but the security group is not applied to the instance. What is the likely cause?

A.The security group resource is missing a VpcId property, so it is not created in the same VPC as the instance.
B.The instance does not have a SecurityGroup or SecurityGroupIds property referencing the security group.
C.The security group is created after the instance, so the instance cannot reference it.
D.The DependsOn clause should be removed because it causes a circular dependency.
AnswerB

The actual flaw is that the instance resource lacks a SecurityGroupIds or SecurityGroups property to reference the security group. DependsOn only ensures the security group is created first; it does not attach the group to the instance. Without an explicit reference in the instance properties, CloudFormation has no way to associate the security group, even though it exists and is available.

Why this answer

The CloudFormation template does not include a `SecurityGroup` or `SecurityGroupIds` property in the EC2 instance's `AWS::EC2::Instance` resource. Without this explicit reference, the instance launches with the default VPC security group, not the custom security group defined in the template. The security group resource is created successfully, but it is not attached to the instance.

Exam trap

The trap here is that candidates assume creating a security group resource in the template automatically applies it to the instance, but CloudFormation requires an explicit attachment via the instance's security group properties.

How to eliminate wrong answers

Option A is wrong because the security group resource (`AWS::EC2::SecurityGroup`) does not require a `VpcId` property if the template is deployed in a default VPC; even if missing, the security group is still created and can be referenced. Option C is wrong because CloudFormation automatically resolves dependencies based on resource references (e.g., `!Ref SecurityGroup`), and the security group is created before the instance if referenced, not after. Option D is wrong because a `DependsOn` clause does not cause a circular dependency here; it simply ensures the security group is created before the instance, which is valid and does not create a loop.

89
Multi-Selectmedium

A company uses AWS Elastic Beanstalk to manage its web application. The DevOps team wants to customize the Amazon EC2 instances launched by Elastic Beanstalk. Which two methods can they use to achieve this? (Choose TWO.)

Select 2 answers
A.Use .ebextensions configuration files in the application source bundle to install packages and run commands.
B.Use AWS OpsWorks to manage the instances instead of Elastic Beanstalk.
C.Create a custom AMI and specify it in the Elastic Beanstalk environment configuration.
D.Add user data to the Auto Scaling group launch configuration that Elastic Beanstalk creates.
E.Modify the CloudFormation template generated by Elastic Beanstalk directly.
AnswersA, C

Elastic Beanstalk automatically processes the .ebextensions directory inside your source bundle, passing any .config files (YAML/JSON) to the CreateStack operation as AWS::CloudFormation::Init metadata. The packages key lets you specify packages like yum, rpm, or gem, while the commands and container_commands keys execute shell commands at specific points in the deployment lifecycle. Because these run on every instance before the application is deployed, they give you a supported, idempotent way to install dependencies and tweak configuration without managing your own AMI. This is the most portable and preferred method for most customizations.

Why this answer

`.ebextensions` configuration files allow you to customize the EC2 instances launched by Elastic Beanstalk by installing packages, running commands, and configuring services during instance provisioning. These YAML or JSON files are placed in the `.ebextensions` folder of your application source bundle and are executed by the Elastic Beanstalk platform as part of the instance initialization process, providing a native and supported customization mechanism.

Exam trap

The trap here is that candidates often think they can directly modify the Auto Scaling group's launch configuration or the CloudFormation template, but Elastic Beanstalk treats these as managed resources and will revert any manual changes, making `.ebextensions` and custom AMIs the only supported customization methods.

90
MCQhard

A company uses Terraform to manage a multi-account AWS environment. The Terraform state files are stored in an S3 bucket with DynamoDB locking. Recently, a DevOps engineer ran 'terraform apply' from a CI/CD pipeline, and it failed with the error: 'Error acquiring the state lock. Lock ID: "abc123". Possible causes: Another process has the lock; or a previous process crashed.' The engineer checks DynamoDB and sees that the lock item exists but there is no active Terraform process. The engineer needs to proceed with the deployment urgently. What should the engineer do?

A.Use the 'terraform force-unlock' command with the lock ID to remove the lock.
B.Wait for the lock to expire automatically.
C.Delete the state file from S3 and recreate it from the last backup.
D.Manually delete the lock item from DynamoDB using the AWS Console.
AnswerA

Terraform's `force-unlock` command is the sanctioned recovery mechanism for a stale lock. Run `terraform force-unlock <LOCK_ID>` from the CLI using the lock ID printed in the error message (or found in the DynamoDB `LockID` item); this removes the lock item via a properly logged API call. It is safe only when you confirm no other `terraform` process is actively applying or planning against that state, because it overrides mutual exclusion.

Why this answer

The correct action is to use 'terraform force-unlock' with the lock ID to remove the stale lock. This command is specifically designed to safely release a lock when no active Terraform process holds it, allowing the deployment to proceed. It ensures the lock is removed in a controlled manner, preserving state integrity.

Exam trap

DOP-C02 often tests whether candidates know the safe, Terraform-native way to clear a stale lock versus dangerous manual deletion or state manipulation.

How to eliminate wrong answers

Option B is wrong because DynamoDB locks used by Terraform do not expire automatically; they persist until manually released or force-unlocked. Option C is wrong because deleting the state file would destroy the record of existing infrastructure, causing Terraform to lose track of resources and potentially recreate or orphan them. Option D is wrong because manually deleting the lock item from DynamoDB bypasses Terraform's lock management and can lead to race conditions or state corruption if another process is actually running.

91
MCQeasy

A developer wants to provision AWS resources using AWS Cloud Development Kit (CDK) and ensure that the infrastructure can be version-controlled and reviewed. Which practice should they follow?

A.Write the CDK app and deploy directly without synthesis to avoid extra steps.
B.Write the CDK app to generate Terraform configurations and store them in Git.
C.Write raw CloudFormation templates instead of CDK to simplify version control.
D.Write the CDK app in TypeScript, store it in a Git repository, and use CDK pipelines for deployment.
AnswerD

Storing an ordinary TypeScript CDK project in Git and using the `cdk pipelines` construct creates a self-mutating CI/CD pipeline that automatically builds, synthesizes, and deploys the app to one or more AWS environments. This approach lets you version the CDK source, review pull requests, run unit tests, and retain the full CloudFormation deployment model underneath. It is the recommended production pattern because pipeline updates are also managed through the same CDK code, giving you repeatable and auditable infrastructure delivery.

Why this answer

It follows the recommended practice of treating CDK application code as infrastructure source code, storing it in a version control system (Git), and using CDK Pipelines (a high-level construct that automatically synthesizes and deploys CloudFormation templates) to ensure repeatable, reviewed deployments. This approach enables infrastructure-as-code best practices: version history, peer review via pull requests, and automated deployment pipelines.

Exam trap

The trap here is that candidates may think CDK requires manual synthesis or that it can output Terraform, but the exam tests that CDK is a CloudFormation-only IaC tool that must be synthesized and version-controlled as code, not as raw templates.

How to eliminate wrong answers

Option A is wrong because deploying directly without synthesis bypasses the generation of CloudFormation templates, which are the deployable artifacts; CDK synthesis is a required step to produce the CloudFormation templates that AWS CloudFormation consumes, and skipping it would prevent deployment. Option B is wrong because CDK does not generate Terraform configurations; CDK synthesizes CloudFormation templates, not Terraform HCL, and mixing tools would introduce unnecessary complexity and break the native integration with AWS. Option C is wrong because writing raw CloudFormation templates instead of CDK would lose the benefits of CDK's higher-level abstractions, programming language features (e.g., loops, conditionals), and construct reuse, while version control is equally possible with CDK code; the question specifically asks about using CDK, so this option contradicts the premise.

92
MCQeasy

A DevOps team is implementing infrastructure as code using AWS CloudFormation. They need to ensure that the stack can be updated to modify a resource's property that requires replacement. Which CloudFormation stack policy should they use?

A.No stack policy, or a policy that allows updates to all resources.
B.A stack policy with an AllowAll statement.
C.A stack policy with a DenyAll statement.
D.A stack policy that explicitly denies updates to the resource.
AnswerA

With no stack policy, CloudFormation uses a default Allow policy that permits all update actions (Update:*) on every resource, so updates can proceed for any resource. Alternatively, an explicit stack policy with a statement containing Effect: Allow, Action: Update:*, Principal: *, and Resource: * has the same effect and also allows all resources to be updated. This matches the requirement to allow updates to all resources.

Why this answer

CloudFormation stack policies are designed to prevent accidental updates to critical resources, not to block updates that require replacement. By default, if no stack policy is applied, all resources can be updated, including those that require replacement. A policy that allows updates to all resources (or no policy) is necessary to permit a stack update that modifies a property requiring resource replacement, as the replacement process involves creating a new resource and deleting the old one, which is a valid update action.

Exam trap

The trap here is that candidates confuse stack policies with IAM policies or assume that any policy statement (like AllowAll) is valid, when in fact CloudFormation stack policies require specific Effect, Action, and Resource keys, and the default behavior (no policy) already allows all updates, including replacement.

How to eliminate wrong answers

Option B is wrong because an AllowAll statement is not a valid CloudFormation stack policy construct; stack policies use Effect, Action, and Resource statements, and an 'AllowAll' statement does not exist in the CloudFormation policy language. Option C is wrong because a DenyAll statement would block all update operations, including the replacement update, which is the opposite of what is needed. Option D is wrong because explicitly denying updates to the resource would prevent any modification, including replacement, making it impossible to perform the required stack update.

93
MCQmedium

A team uses AWS CodePipeline to orchestrate deployments. They want to integrate a manual approval step before deploying to production. Which action should they take?

A.Use an AWS Lambda function to send an approval request email and wait for HTTP response.
B.Add a manual approval action to the pipeline before the production deployment stage.
C.Add an Amazon CloudWatch Events rule to pause the pipeline before the production stage.
D.Add an Amazon SNS topic to the pipeline and require subscription confirmation.
AnswerB

Adding a manual approval action is the native and correct way to gate a production deployment in CodePipeline. The action is an Approval type stage step that pauses the pipeline execution until an authorized IAM principal explicitly clicks Approve or Reject in the console, or calls the appropriate AWS SDK/CLI commands. This provides a built-in, auditable human checkpoint with no additional infrastructure, and it can optionally send SNS or EventBridge notifications to reviewers.

Why this answer

AWS CodePipeline natively supports a manual approval action that can be added as a stage before the production deployment. This action pauses the pipeline and sends a notification (via Amazon SNS) to specified approvers, who can then approve or reject the deployment through the AWS Management Console, CLI, or API. No custom code or external services are required.

Exam trap

The trap here is that candidates may confuse the manual approval action's dependency on SNS with the idea that simply adding an SNS topic to the pipeline creates an approval step, when in fact the approval action must be explicitly added as a stage action.

How to eliminate wrong answers

Option A is wrong because using an AWS Lambda function to send an approval request email and wait for an HTTP response introduces unnecessary complexity and does not integrate with CodePipeline's built-in approval workflow; CodePipeline already provides a native manual approval action with SNS notifications. Option C is wrong because Amazon CloudWatch Events rules can trigger actions based on pipeline state changes but cannot pause a pipeline or add an approval step; pausing is a feature of the manual approval action itself. Option D is wrong because adding an Amazon SNS topic to the pipeline does not create an approval step; the SNS topic is used by the manual approval action to notify approvers, but simply adding a topic without the approval action does not pause the pipeline or require approval.

94
MCQhard

A company uses AWS OpsWorks for configuration management with Chef. They are migrating to AWS Systems Manager to reduce complexity. The operations team needs to run custom scripts on a fleet of EC2 instances on a schedule, with the ability to target instances based on tags. Which Systems Manager capability should the engineer use?

A.Patch Manager
B.Automation
C.State Manager
D.Run Command
AnswerC

AWS Systems Manager State Manager uses associations to define the state you want to maintain on your managed instances, including running custom scripts via Run Command documents or other SSM documents. Associations support a schedule using cron or rate expressions and can target instances by tags, resource groups, or individual instance IDs. This makes State Manager the ideal service for regularly executing a custom script on EC2 instances selected by tags. The association's schedule ensures the script runs automatically, and it provides compliance reporting on execution history.

Why this answer

State Manager is the correct choice because it is designed to define and maintain consistent configuration of EC2 instances and other AWS resources, including running custom scripts on a schedule. It supports targeting instances by tags and uses associations to enforce desired states at specified intervals, making it ideal for scheduled script execution across a tagged fleet.

Exam trap

The trap here is that candidates often confuse Run Command's on-demand execution with scheduled execution, overlooking that State Manager provides the built-in scheduling and tag-based targeting required for recurring tasks.

How to eliminate wrong answers

Option A is wrong because Patch Manager is specifically for automating OS patching (e.g., installing security updates), not for running arbitrary custom scripts on a schedule. Option B is wrong because Automation is used for performing predefined or custom workflows (e.g., AMI creation, instance remediation) but is typically invoked manually or via events, not designed for recurring scheduled script execution with tag-based targeting. Option D is wrong because Run Command allows you to run scripts or commands on instances on-demand or via EventBridge, but it lacks the native scheduling capability of State Manager; you would need to build a separate scheduling mechanism (e.g., using EventBridge rules) to achieve recurring execution, whereas State Manager provides built-in scheduling via associations.

95
Multi-Selecteasy

A company uses AWS CloudFormation to deploy a VPC with public and private subnets. They want to ensure that the VPC has internet access for the public subnets. Which THREE resources must be included in the template?

Select 3 answers
A.AWS::EC2::VPCEndpoint
B.AWS::EC2::Route (pointing to InternetGateway)
C.AWS::EC2::RouteTable
D.AWS::EC2::NatGateway
E.AWS::EC2::InternetGateway
AnswersB, C, E

An AWS::EC2::Route entry with destination 0.0.0.0/0 and target pointing to an InternetGateway is the precise mechanism that makes a public subnet public. This route directs all non-local traffic to the internet gateway, enabling instances with public IPs to reach outbound and receive inbound internet traffic. Without this specific route, the internet gateway exists but the subnet cannot use it, so creating the route is the decisive step.

Why this answer

An AWS::EC2::Route resource that points to an InternetGateway is required to direct traffic from the public subnet's route table to the internet. Without this route, instances in the public subnet cannot send or receive traffic from the internet, even if an Internet Gateway is attached to the VPC.

Exam trap

The trap here is that candidates often assume an Internet Gateway alone is sufficient for internet access, forgetting that a route in the route table pointing to the IGW is mandatory to make the connection functional.

96
MCQhard

A company uses AWS CloudFormation to manage infrastructure. The DevOps team wants to implement a change management process where all stack updates must be reviewed before execution. Which AWS feature should be used?

A.Drift detection
B.Change Sets
C.StackSets
D.Stack policies
AnswerB

A change set is a read-only summary of the modifications CloudFormation will perform if you execute it, including resource additions, removals, and replacements with details such as `Replacement` and `RequiresRecreation`. You create a change set, inspect its proposed actions—even using `--changeset` filtering or the console UI—and only then choose to execute it, which gives you a controlled, auditable review gate before any infrastructure is altered.

Why this answer

Change Sets allow you to preview how proposed changes to a CloudFormation stack will impact your running resources before you execute them. This enables a review-and-approval workflow, making it the correct choice for implementing a change management process where all stack updates must be reviewed before execution.

Exam trap

The trap here is that candidates often confuse drift detection (which detects post-update configuration drift) with the ability to preview proposed changes, or they mistakenly think stack policies can gate the update itself rather than just protecting specific resources during an update.

How to eliminate wrong answers

Option A is wrong because drift detection identifies whether a stack's actual resource configuration has diverged from its template, but it does not provide a mechanism to review or approve proposed updates before they are applied. Option C is wrong because StackSets are used to deploy stacks across multiple accounts and regions, not to preview or gate changes to a single stack. Option D is wrong because stack policies define which resources can be updated during a stack update, but they do not allow you to review the proposed changes before the update is executed.

97
Drag & Dropmedium

Drag and drop the steps to set up an AWS CodePipeline with a source stage from CodeCommit and a deploy stage to Elastic Beanstalk.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order is: first create the S3 bucket for artifacts, then create the CodeCommit repository and push code, then create the pipeline, then configure source, then configure deploy.

98
MCQmedium

A DevOps engineer is designing a CI/CD pipeline for a containerized application using AWS CodePipeline and Amazon ECS. The pipeline should build a Docker image, push it to Amazon ECR, and deploy it to an ECS service. Which deployment action should they use in the pipeline?

A.AWS Elastic Beanstalk deployment action.
B.AWS CodeBuild with a buildspec that runs aws ecs update-service.
C.Amazon ECS (Blue/Green) deployment provider with CodeDeploy.
D.AWS CloudFormation deployment action to update the ECS service.
AnswerC

Amazon ECS (Blue/Green) with CodeDeploy is the correct native deployment provider for ECS in CodePipeline. CodeDeploy's ECS compute platform orchestrates the creation of a green task set, shifts traffic from the blue target group to the green target group in either linear or canary increments, and performs post-traffic-shift validation hooks defined in an AppSpec file. It also supports automatic rollback if the deployment fails health checks, making it the ideal, fully integrated choice for ECS blue/green deployments in a pipeline.

Why this answer

Amazon ECS (Blue/Green) deployment provider with CodeDeploy is the native, fully managed deployment action in AWS CodePipeline for ECS services. It orchestrates traffic shifting, task set management, and rollback automatically using CodeDeploy's ECS blue/green deployment type, which is the recommended approach for containerized applications on ECS.

Exam trap

The trap here is that candidates often confuse the ECS (Blue/Green) deployment provider with a simple 'update-service' command, not realizing that CodePipeline requires a native deployment provider to support automated traffic shifting, rollback, and integration with CodeDeploy's lifecycle hooks.

How to eliminate wrong answers

Option A is wrong because AWS Elastic Beanstalk deployment action is designed for Elastic Beanstalk environments, not for ECS services; it cannot directly deploy to an ECS cluster or service. Option B is wrong because while CodeBuild can run aws ecs update-service, this approach bypasses CodePipeline's deployment tracking, rollback capabilities, and traffic shifting; it is a custom script, not a native deployment action. Option D is wrong because AWS CloudFormation deployment action updates CloudFormation stacks, not ECS services directly; it would require wrapping the ECS service update in a CloudFormation template, adding unnecessary complexity and losing the built-in deployment features of CodeDeploy.

99
MCQhard

A company uses AWS CloudFormation to manage a stack that includes an Auto Scaling group with a LaunchTemplate. The DevOps team wants to update the LaunchTemplate with a new AMI. The stack update fails with the error 'Launch template version does not exist'. What is the most likely cause?

A.The LaunchTemplate was recently modified and the new version is not yet available
B.The LaunchTemplate version specified in the template was deleted
C.The target group attachment is incorrect
D.The Auto Scaling group is using a different launch template
AnswerB

The most direct cause of a 'LaunchTemplate version not found' error during stack update or creation is that the exact version number specified in the CloudFormation template has been deleted. Launch template versions are immutable but can be manually deleted (except the default version) when no longer needed, and CloudFormation validates that the referenced version exists before provisioning resources. Once deleted, any stack operation referencing that version fails because the template is effectively trying to instantiate a non-existent configuration.

Why this answer

The error 'Launch template version does not exist' occurs when the CloudFormation template references a specific launch template version number that has been deleted. Launch template versions are immutable but can be deleted, and if the stack template or parameter references a deleted version, the stack update fails.

Exam trap

DOP-C02 often tests whether candidates understand that launch template versions are immutable and can be deleted, and that CloudFormation references to a deleted version cause this specific error — candidates may incorrectly blame propagation delays or target group issues.

How to eliminate wrong answers

Option A is wrong because launch template versions are available immediately upon creation — there is no propagation delay that would cause this error. Option C is wrong because an incorrect target group attachment would produce a different error (e.g., 'Target group not found' or 'Invalid target group'), not a launch template version error. Option D is wrong because the Auto Scaling group using a different launch template would not cause a 'version does not exist' error; it would simply use the other template, and CloudFormation would not fail with that message.

100
Multi-Selecthard

A company uses AWS CloudFormation StackSets to deploy resources across multiple accounts and regions. They need to ensure that updates to the stack set are rolled out in a controlled manner, with the ability to roll back if errors occur. Which THREE strategies should they implement? (Choose THREE.)

Select 3 answers
A.Use a canary deployment strategy by updating only a subset of accounts first
B.Set a failure tolerance to allow a certain number of stack operation failures before the overall operation fails
C.Pause stack instances manually if errors are detected
D.Configure region concurrency to control how many regions are updated at a time
E.Set the maximum concurrent accounts to control how many accounts are updated simultaneously
AnswersB, D, E

Failure tolerance specifies how many stack instance failures (as an absolute number or a percentage of total stack instances) are acceptable before the entire StackSet operation is considered failed. When this threshold is exceeded, StackSets automatically rolls back all successfully deployed stack instances, allowing you to absorb a limited number of transient errors without halting the whole deployment. This is the primary safety control for managing partial deployment success.

Why this answer

Option B is correct because StackSets support a failure tolerance parameter that defines how many stack instance operations may fail before the entire stack set operation is considered failed and rolled back, enabling controlled error handling. Option D is correct because region concurrency (MaximumConcurrentPercentage or a specific number of regions) lets you limit how many regions are updated in parallel, reducing blast radius and allowing controlled rollout across regions. Option E is correct because maximum concurrent accounts controls how many accounts within each region are updated simultaneously, which is the primary mechanism for throttling and controlling the pace of stack set updates.

Option A is not correct because CloudFormation StackSets do not provide a native canary deployment feature; controlled rollout is achieved through concurrency and failure tolerance settings rather than a built-in canary mode. Option C is not correct because manually pausing stack instances is not a supported StackSets control mechanism; rollback and failure handling are governed by failure tolerance and concurrency parameters, not manual pausing.

Exam trap

The trap here is that candidates often confuse the canary deployment concept (Option A) with StackSets' ability to target specific accounts or OUs, but StackSets does not natively support canary rollouts—you would need to implement that manually with separate stack sets or custom automation.

101
MCQmedium

A DevOps engineer is troubleshooting a CloudFormation stack that fails to create an EC2 instance with a custom AMI. The error message indicates that the AMI ID does not exist. The engineer is using a mapping in the template to select the AMI based on the region. However, the stack is being created in a region not covered by the mapping. What is the most efficient way to resolve this issue?

A.Retrieve the AMI ID dynamically using AWS Systems Manager Parameter Store and a dynamic reference in the template.
B.Create a new mapping entry for the region by updating the template.
C.Use AWS Systems Manager Run Command to find the correct AMI ID.
D.Hardcode the AMI ID in the template for the missing region.
AnswerA

Dynamic references resolve the AMI at deploy time from Parameter Store, so the template no longer depends on a static region mapping. This satisfies the region-agnostic constraint, letting the stack create successfully in any region without maintaining per-region map entries.

Why this answer

The most efficient way is to use AWS Systems Manager Parameter Store with a dynamic reference in the CloudFormation template. This allows the AMI ID to be resolved at deployment time based on the region, without hardcoding or maintaining mappings. Option B (creating a new mapping) is less efficient because it requires manual updates for each region.

Option C (Run Command) is not designed for parameter retrieval. Option D (hardcoding) is not scalable and error-prone.

102
MCQmedium

An organization manages multiple AWS accounts using AWS Organizations. They want to enforce that all Amazon S3 buckets across accounts have versioning enabled. Which approach is the most scalable and least error-prone?

A.Use AWS Config rules to detect buckets without versioning and send alerts.
B.Create an SCP that denies s3:PutBucketVersioning if versioning is not enabled.
C.Deploy a CloudFormation StackSet to all accounts with a template that enables versioning.
D.Manually enable versioning on each bucket after creation.
AnswerB

An SCP attached at the root or OU can deny s3:PutBucketVersioning unless the request's VersioningState header is exactly 'Enabled', using a condition such as s3:x-amz-versioning. Because SCPs are evaluated before any IAM policies, a user in a member account cannot bypass this restriction even if their IAM policy allows the action, and the API call fails before any state change occurs. This preventive control enforces the organization-wide requirement that every bucket remain versioned, making it the correct answer.

Why this answer

A Service Control Policy (SCP) in AWS Organizations can deny the `s3:PutBucketVersioning` action unless versioning is already enabled, effectively preventing the creation or modification of buckets without versioning. This approach is scalable as it applies to all accounts in the organization automatically and is least error-prone because it enforces the policy at the API level, blocking non-compliant actions before they occur.

Exam trap

The trap here is that candidates often choose AWS Config (Option A) because it is a common detective control, but they overlook that SCPs provide preventive enforcement at the organization level, which is more scalable and less error-prone for enforcing mandatory configurations across all accounts.

How to eliminate wrong answers

Option A is wrong because AWS Config rules can only detect and alert on non-compliant buckets after they are created, not prevent the action, making it reactive and error-prone. Option C is wrong because a CloudFormation StackSet can enable versioning on existing buckets but does not prevent future creation of buckets without versioning, and it requires ongoing maintenance to cover new buckets. Option D is wrong because manually enabling versioning is not scalable, is highly error-prone, and violates the principle of automation required for multi-account management.

103
MCQeasy

A DevOps engineer is managing the lifecycle of a CloudFormation stack. The engineer needs to update a stack that contains an Auto Scaling group. The update requires a replacement of the Auto Scaling group. What will happen to the existing instances during the update?

A.The existing instances will be terminated after the new Auto Scaling group is created
B.The stack update will fail because Auto Scaling groups cannot be replaced
C.The existing instances will remain running and be associated with the new Auto Scaling group
D.The instances will be updated in-place by terminating and recreating each instance one by one
AnswerA

During a CloudFormation stack update that forces replacement, the Auto Scaling group is recreated with a new physical resource ID. CloudFormation first creates the replacement group and only after it is successfully provisioned does it delete the original group, which terminates the old group's instances. This create-before-delete behavior preserves capacity during the update window.

Why this answer

When a CloudFormation stack update requires replacement of an Auto Scaling group (e.g., due to a change in the `LaunchConfigurationName` or `LaunchTemplate` property), CloudFormation creates the new Auto Scaling group first, then terminates the old instances after the new group is fully operational. This ensures minimal downtime because the new group begins serving traffic before the old one is torn down.

Exam trap

The trap here is that candidates assume CloudFormation performs in-place updates (Option D) or that replacement always fails (Option B), but the service explicitly supports create-before-destroy replacement for Auto Scaling groups.

How to eliminate wrong answers

Option B is wrong because CloudFormation supports replacing Auto Scaling groups during stack updates when the resource requires replacement; it does not fail. Option C is wrong because existing instances cannot be reassigned to a new Auto Scaling group—each instance is tied to a specific Auto Scaling group via its lifecycle hooks and launch configuration. Option D is wrong because CloudFormation does not perform in-place updates on Auto Scaling groups; it uses a create-before-destroy strategy, terminating the old group only after the new one is created.

104
MCQeasy

A company uses AWS CloudFormation to manage its infrastructure. The operations team needs to update a stack that includes an RDS database. The update requires changing the DB instance class, which will cause a replacement of the database. The team wants to minimize downtime and ensure that data is not lost. Which CloudFormation stack update policy should they use?

A.Set the CreationPolicy attribute on the database resource.
B.Configure a Stack Policy to protect the database resource.
C.Set the UpdatePolicy to AutoScalingRollingUpdate.
D.Set the UpdatePolicy to AutoScalingReplacingUpdate with WillReplace set to true.
AnswerD

AutoScalingReplacingUpdate is only supported for AWS::AutoScaling::AutoScalingGroup and cannot be applied to an AWS::RDS::DBInstance resource.

Why this answer

The UpdatePolicy attribute with AutoScalingReplacingUpdate is only supported for AWS::AutoScaling::AutoScalingGroup resources, not for AWS::RDS::DBInstance. Therefore, option D is incorrect. Options A and C are also invalid (CreationPolicy is for signal-based creation, and AutoScalingRollingUpdate is for rolling updates on Auto Scaling groups).

Option B, Stack Policy, can protect resources from being updated but does not control how a replacement occurs to minimize downtime or prevent data loss. Thus, none of the provided options are correct for ensuring minimal downtime and data safety during an RDS instance class change that requires replacement.

Exam trap

Candidates might assume that AutoScalingReplacingUpdate can be applied to any resource supporting replacement, but CloudFormation limits UpdatePolicy to specific resources like Auto Scaling groups, ElastiCache replication groups, and Elasticsearch domains. RDS DB instances do not support UpdatePolicy.

How to eliminate wrong answers

Option A is wrong because the `CreationPolicy` attribute controls how CloudFormation waits for signals (e.g., from cfn-init) before marking a resource as created; it does not affect update behavior or minimize downtime during a replacement. Option B is wrong because a Stack Policy is used to prevent accidental updates or deletions of specific resources by denying update/delete actions, but it does not control the order or method of updates to minimize downtime. Option C is wrong because `AutoScalingRollingUpdate` is designed for Auto Scaling groups to update instances in batches, not for RDS instances; applying it to an RDS resource would have no effect and would not handle the replacement of a database.

105
Multi-Selectmedium

Which TWO approaches can be used to automate the creation of an AWS CloudFormation stack that includes IAM resources? (Select TWO.)

Select 2 answers
A.Store the CloudFormation template in an Amazon S3 bucket and use the 'aws cloudformation deploy' command.
B.Set the 'CAPABILITY_NAMED_IAM' capability when calling the CreateStack API.
C.Attach the AWS managed policy 'IAMFullAccess' to the IAM user or role executing the stack creation.
D.Use an AWS Lambda function to call the CreateStack API with the capabilities parameter set to 'CAPABILITY_IAM'.
E.Use the AWS CLI command 'aws cloudformation create-stack' with the '--capabilities CAPABILITY_IAM' parameter.
AnswersD, E

An AWS Lambda function can programmatically call the CreateStack API and include 'CAPABILITY_IAM' in the Capabilities list, satisfying CloudFormation's acknowledgement requirement. This is a valid automation method because the Lambda handler can pass the parameter directly in the SDK request, and the function can be triggered by various events. The Lambda execution role must have permission to create stacks and the necessary IAM resources.

Why this answer

When a CloudFormation stack includes IAM resources, you must explicitly acknowledge that the stack may create IAM entities. An AWS Lambda function calling the CreateStack API with the `capabilities` parameter set to `CAPABILITY_IAM` satisfies this requirement. Option E is correct because the AWS CLI `create-stack` command with the `--capabilities CAPABILITY_IAM` parameter also provides the required acknowledgment, allowing the stack to be created successfully.

Exam trap

The trap here is that candidates often confuse IAM permissions (like `IAMFullAccess`) with the CloudFormation capability acknowledgment, thinking that having the right IAM policy alone is sufficient to create IAM resources in a stack, when in fact the `CAPABILITY_IAM` or `CAPABILITY_NAMED_IAM` flag must be explicitly set in the API call.

106
MCQeasy

A DevOps team uses AWS CodePipeline to deploy a web application. They notice that the deployment stage fails intermittently due to a missing configuration file. Which troubleshooting step should they take first?

A.Switch to AWS CodeBuild for the deployment stage.
B.Review the build logs in AWS CodeBuild to identify the error.
C.Recreate the pipeline with the same configuration to see if the issue repeats.
D.Verify the deployment group settings in AWS CodeDeploy.
AnswerB

Reviewing the build logs in AWS CodeBuild directly surfaces the compile-time or test-time error that caused the pipeline action to fail. CodeBuild logs are stored in CloudWatch Logs (and optionally S3), showing the full output of each build phase, including command execution, environment setup, and the exact error message and exit code. This is the fastest, most authoritative way to identify the root cause of a build-phase failure.

Why this answer

The deployment stage fails intermittently due to a missing configuration file. The first troubleshooting step should be to review the build logs in AWS CodeBuild, because CodeBuild generates detailed logs that capture the exact error message, including file paths and missing configuration details. This allows the team to pinpoint the root cause without making unnecessary changes to the pipeline or deployment group settings.

Exam trap

The trap here is that candidates may jump to verifying CodeDeploy settings (Option D) because the failure occurs in the deployment stage, but the root cause is a missing configuration file that should have been produced or included earlier in the pipeline, making build logs the correct first diagnostic step.

How to eliminate wrong answers

Option A is wrong because switching to AWS CodeBuild for the deployment stage does not address the intermittent missing configuration file issue; it only changes the compute service, and the underlying configuration problem would persist. Option C is wrong because recreating the pipeline with the same configuration is a time-consuming and non-diagnostic step that does not provide any new information about why the configuration file is missing intermittently. Option D is wrong because verifying the deployment group settings in AWS CodeDeploy is relevant only if the failure is related to deployment targets or traffic routing, not to a missing configuration file that should be present in the build or source stage.

107
MCQmedium

A DevOps team uses AWS CodePipeline to automate deployments. The pipeline has a Deploy stage that uses AWS CloudFormation to create or update a stack. Recently, a stack update failed because the template referenced an AMI that was deprecated. The team wants to automatically roll back the stack to the last known good state if a deployment fails. What should they do?

A.Configure the CloudFormation deployment action in CodePipeline with 'ActionMode' set to 'CREATE_UPDATE' and check the 'Rollback on failure' option.
B.Use the CodePipeline console to enable 'Automatic rollback' for the Deploy stage.
C.Set the stack's 'DisableRollback' parameter to 'true' in the template.
D.Add a stack policy to the CloudFormation stack that denies updates to the AMI parameter.
AnswerA

In CodePipeline, the CloudFormation deployment action requires an explicit ActionMode such as CREATE_UPDATE to create a new stack or update an existing one. When 'Rollback on failure' is selected, CloudFormation automatically rolls back the stack to its last known good state if the deployment fails, restoring both resources and stack outputs. This is the correct mechanism because it leverages CloudFormation's native rollback capability within the pipeline execution, preserving the integrity of the deployed infrastructure.

Why this answer

The CloudFormation deployment action in CodePipeline supports a 'Rollback on failure' option when 'ActionMode' is set to 'CREATE_UPDATE'. When enabled, if the stack update fails, CloudFormation automatically rolls back the stack to the last known good state (the previously deployed stack). This directly addresses the team's requirement to revert to a stable state after a failed deployment due to a deprecated AMI.

Exam trap

The trap here is that candidates confuse the CloudFormation stack-level 'DisableRollback' parameter (which controls rollback during stack creation) with the CodePipeline action-level 'Rollback on failure' option, leading them to incorrectly select Option C.

How to eliminate wrong answers

Option B is wrong because CodePipeline does not have an 'Automatic rollback' toggle at the stage level; rollback behavior is configured within the CloudFormation action itself, not via a generic stage setting. Option C is wrong because setting 'DisableRollback' to 'true' actually prevents rollback on failure, which is the opposite of what the team wants. Option D is wrong because a stack policy controls permissions for stack updates (e.g., preventing updates to specific resources), but it does not trigger an automatic rollback after a failed deployment.

108
MCQmedium

A company uses AWS CloudFormation to manage its infrastructure. The DevOps team has a template that creates an Amazon RDS DB instance and an EC2 instance that runs a web application. The EC2 instance needs to connect to the RDS instance using the database endpoint and password. The team currently passes the endpoint and password as CloudFormation parameters, which are then stored in the EC2 instance's user data. However, security audit has flagged this as a security risk because the password is visible in the user data. The team wants to securely pass the database credentials to the EC2 instance without exposing them in the template or user data. The EC2 instance has an IAM role that allows it to read from AWS Secrets Manager. Which solution should the team implement?

A.Store the password in AWS Systems Manager Parameter Store as a SecureString and have the EC2 instance retrieve it using the AWS CLI.
B.Encrypt the user data using AWS KMS and decrypt it on the EC2 instance at boot time.
C.Store the password in AWS Secrets Manager, use a dynamic reference to pass it to the EC2 instance's IAM role, and have the application retrieve it from Secrets Manager at runtime.
D.Use CloudFormation's Fn::GetAtt to retrieve the password from the RDS instance and pass it to the EC2 instance via user data.
AnswerC

This is correct because the password is stored and rotated in AWS Secrets Manager, and the CloudFormation template only references the secret's ARN (e.g., via a dynamic reference) in the IAM role policy, enabling the EC2 instance to read it. No secret value ever enters the template, user data, or instance filesystem; the application retrieves the plaintext only when it calls Secrets Manager at runtime. Since the IAM role restricts access to only that secret and Secrets Manager supports automatic rotation, the approach satisfies security best practices.

Why this answer

By storing the password in AWS Secrets Manager and using a dynamic reference in CloudFormation, the password is never exposed in the template or user data. The EC2 instance retrieves the password from Secrets Manager at runtime using its IAM role. Option A is not the best because although Parameter Store can store SecureStrings, Secrets Manager is more secure and supports automatic rotation, and the instance already has permissions to read Secrets Manager.

Option B is risky because encrypting user data still exposes the password in the user data itself and adds key management complexity. Option D is wrong because Fn::GetAtt cannot retrieve the RDS master password, and even if it could, the password would still be passed via user data, which is insecure.

109
MCQmedium

A company uses AWS CloudFormation StackSets to deploy a common security group across multiple accounts in an AWS Organization. The security group must allow inbound traffic from the organization's central VPN CIDR range. The VPN CIDR range is stored in AWS Systems Manager Parameter Store. How should the engineer reference this parameter in the StackSet template to ensure the value is resolved at deployment time?

A.Use Fn::ImportValue with an export from another stack that reads the parameter.
B.Use the dynamic reference '{{resolve:ssm:/org/vpn/cidr}}' in the template.
C.Use the Ref function on the parameter name as a CloudFormation parameter.
D.Use Fn::GetAtt to retrieve the parameter value from an AWS::SSM::Parameter resource.
AnswerB

The `{{resolve:ssm:/org/vpn/cidr}}` dynamic reference resolves the Parameter Store value at deployment time, satisfying the requirement that the CIDR is fetched when the StackSet instantiates stacks. Unlike hard-coded values or parameters passed manually, it retrieves the current stored value per account deployment, keeping the security group rule consistent with the central VPN range.

Why this answer

CloudFormation dynamic references ({{resolve:ssm:/org/vpn/cidr}}) allow you to retrieve the current value of an SSM Parameter Store parameter at stack deployment time, without needing to pass it as a parameter or create a separate resource. This ensures the security group rule always uses the latest VPN CIDR value stored in Parameter Store, even if the CIDR changes between deployments.

Exam trap

The trap here is that candidates often confuse dynamic references with CloudFormation parameters or intrinsic functions like Ref and Fn::GetAtt, not realizing that {{resolve:ssm:...}} is a special syntax that directly retrieves SSM parameter values without requiring a resource or parameter declaration.

How to eliminate wrong answers

Option A is wrong because Fn::ImportValue is used to import exported values from other stacks, not to resolve SSM parameters dynamically; it would require an intermediate stack that exports the parameter value, adding unnecessary complexity. Option C is wrong because using Ref on a parameter name would require the parameter value to be passed as a CloudFormation parameter input at stack creation, not resolved from SSM at deployment time. Option D is wrong because Fn::GetAtt retrieves attributes from a resource defined in the same template, but an AWS::SSM::Parameter resource would need to be created in the stack, which is not the intended pattern for referencing an existing parameter.

110
Multi-Selecthard

A DevOps team manages hundreds of EC2 instances using AWS Systems Manager State Manager. They need to ensure that a specific configuration (e.g., a custom firewall rule) is applied to all instances and remains enforced. Which THREE steps should they take? (Choose THREE.)

Select 3 answers
A.Ensure the instances have an IAM role that allows Systems Manager to perform actions.
B.Create a State Manager association using a custom document that defines the firewall rule.
C.Use AWS Config rules to detect non-compliance.
D.Use Run Command to execute the configuration once.
E.Set the association to apply the configuration on a schedule (e.g., every 30 minutes).
AnswersA, B, E

The SSM Agent running on each EC2 instance requires an IAM instance profile that grants Systems Manager API permissions, such as the AmazonSSMManagedInstanceCore managed policy. Without this role, the agent cannot register with the Systems Manager service or receive association requests, so any subsequent automation—including State Manager—will fail. This IAM prerequisite is non-negotiable and must be verified before creating associations or running documents.

Why this answer

AWS Systems Manager requires instances to have an IAM role that grants the necessary permissions (e.g., AmazonSSMManagedInstanceCore) for the SSM Agent to communicate with the Systems Manager service. Without this role, State Manager cannot apply or enforce any configuration, including custom firewall rules.

Exam trap

The trap here is that candidates often confuse AWS Config rules (which only detect drift) with State Manager associations (which both detect and automatically remediate drift), leading them to select Option C instead of Option E for enforcement.

111
MCQmedium

A company uses AWS CloudFormation to manage infrastructure. They have a production stack that creates an Auto Scaling group. They want to update the launch configuration to use a new Amazon Machine Image (AMI) ID without causing downtime. Which update policy should they set on the Auto Scaling group?

A.AutoScalingScheduledAction
B.AutoScalingReplacingUpdate
C.AutoScalingRollingUpdate
D.AutoScalingBatchUpdate
AnswerC

AutoScalingRollingUpdate replaces instances in batches, maintaining a minimum number of healthy instances throughout the update. This satisfies the no-downtime constraint by keeping the Auto Scaling group serving traffic while new AMI-based instances launch and old ones terminate, rather than replacing all instances simultaneously.

Why this answer

The AutoScalingRollingUpdate policy allows CloudFormation to update the Auto Scaling group's launch configuration by gradually replacing instances in batches, ensuring that a minimum number of instances remain in service throughout the update. This prevents downtime by terminating old instances and launching new ones with the updated AMI in a controlled, rolling fashion.

Exam trap

The trap here is that 'AutoScalingReplacingUpdate' is a valid CloudFormation update policy, but it replaces the entire Auto Scaling group at once, causing downtime. Candidates may mistakenly choose it thinking it's the only policy that updates launch configurations, but 'AutoScalingRollingUpdate' does so gradually, avoiding downtime.

How to eliminate wrong answers

Option A is wrong because AutoScalingScheduledAction is used to define time-based scaling actions (e.g., increase capacity at a specific time), not to manage rolling updates or replace launch configurations. Option B is wrong because AutoScalingReplacingUpdate is not a valid CloudFormation update policy; the correct term for a full replacement update is 'AutoScalingReplacingUpdate' does not exist—CloudFormation uses 'AutoScalingRollingUpdate' for rolling updates and 'AutoScalingScheduledAction' for scheduled actions. Option D is wrong because AutoScalingBatchUpdate is not a valid CloudFormation update policy; the service does not support a 'batch' update policy—rolling updates are the only native mechanism for gradual replacement.

112
MCQmedium

A DevOps engineer creates the IAM policy above for an instance role. The role is attached to an EC2 instance that runs an application. The application starts and stops EC2 instances and reads a database password from Systems Manager Parameter Store. However, the application fails to retrieve the parameter. What is the most likely cause?

A.The policy does not allow 'ssm:GetParameterHistory'.
B.The policy does not allow 'ec2:DescribeParameters'.
C.The parameter is a SecureString and the policy does not grant 'kms:Decrypt' permission for the KMS key.
D.The policy does not allow 'ssm:GetParameter' on the specific resource.
AnswerC

When a parameter is stored as a SecureString, its value is encrypted at rest using an AWS KMS key, either the default aws/ssm key or a customer-managed key. To retrieve the plaintext value via ssm:GetParameter, the caller must have kms:Decrypt permission on that specific KMS key, in addition to the ssm:GetParameter action on the parameter resource. The policy shown grants the SSM read action but omits kms:Decrypt, so even though the resource-level SSM permission is correct, the call fails with an AccessDeniedException.

Why this answer

The policy allows 'ssm:GetParameter' and 'ssm:GetParameters' on the specific parameter ARN. However, to retrieve a parameter, the action 'ssm:GetParameter' is sufficient, but the resource ARN must be correct. The given ARN includes the parameter name '/MyApp/DBPassword'.

If the application is using a different path or the parameter is encrypted, the policy might be insufficient. But the most common issue is that the parameter is a SecureString and the policy also needs 'kms:Decrypt' access to the KMS key. Option C is correct because the policy does not include KMS permissions.

Option A and B are less likely. Option D is incorrect because the actions are allowed.

113
MCQeasy

A company uses AWS OpsWorks for configuration management of a fleet of EC2 instances running a legacy application. The operations team needs to deploy a new version of the application across all instances without causing downtime. The application runs on each instance and requires a rolling update. Which approach should the team use?

A.Use AWS CodeDeploy to perform a blue/green deployment on the existing instances.
B.Create a new Auto Scaling group with the updated AMI and terminate old instances.
C.Manually update each instance by adding a new layer and reassigning instances.
D.Use the OpsWorks Deploy command to trigger a rolling update across the stack.
AnswerD

The OpsWorks Deploy command triggers the deploy lifecycle stage on the stack, running the deployment recipes that update application code and configuration on each registered instance. Because OpsWorks Stacks lets you configure the batch size and pause time, instances are updated one batch at a time while the remaining instances continue serving traffic, which minimizes downtime during the update. This is the native rolling-update mechanism for an OpsWorks-managed stack and directly addresses the requirement to update the existing fleet with minimal service interruption.

Why this answer

AWS OpsWorks provides a Deploy command that can perform rolling updates across instances in a stack. This command allows you to deploy application code or configuration changes in a controlled manner, updating instances in batches to avoid downtime. It is the native OpsWorks mechanism for rolling deployments, aligning with the requirement to update all instances without downtime.

Exam trap

The trap is confusing OpsWorks deployment methods with AWS CodeDeploy or Auto Scaling; candidates may think CodeDeploy is the default for rolling updates, but OpsWorks has its own Deploy command.

How to eliminate wrong answers

Option A is wrong because AWS CodeDeploy is a separate service and cannot directly perform blue/green deployments on existing OpsWorks instances without significant reconfiguration; OpsWorks has its own deployment methods. Option B is wrong because creating a new Auto Scaling group with a new AMI is not a rolling update and would require replacing instances, potentially causing downtime if not managed carefully; it also does not leverage OpsWorks. Option C is wrong because manually updating each instance by adding a layer and reassigning instances is error-prone, not automated, and does not guarantee a rolling update; it could cause downtime.

114
MCQeasy

A company uses AWS CodeBuild to compile and test code. The build process requires a specific version of a library that is not available in the default build environment. Which approach should be used to include this library in the build process?

A.Modify the buildspec file to include the library as a build artifact.
B.Store the compiled library in an Amazon S3 bucket and download it during the build process using the buildspec file.
C.Add an install command in the buildspec file to download and compile the library during each build.
D.Create a custom Docker image that includes the library and use it as the build environment in CodeBuild.
AnswerD

Creating a custom Docker image with the library preinstalled makes the library available at the very start of every build because CodeBuild runs build phases inside that image. Custom images let you pin the exact library version and all transitive runtime dependencies, ensuring reproducibility and eliminating repeated download/compile overhead. This is a best practice when the build consistently requires specialized binaries, libraries, or tools that are not present in CodeBuild's standard managed images.

Why this answer

Creating a custom Docker image that includes the required library ensures the build environment is consistent, reproducible, and avoids repeated download/compile overhead. AWS CodeBuild supports custom Docker images via the `image` field in the buildspec file or the console, allowing you to specify a repository in Amazon ECR or Docker Hub. This approach aligns with infrastructure-as-code best practices by baking dependencies into the environment rather than managing them at build time.

Exam trap

The trap here is that candidates often choose Option B or C because they think 'download during build' is simpler, but they overlook the core DevOps principle of immutable build environments and the inefficiency of re-downloading or recompiling dependencies on every build run.

How to eliminate wrong answers

Option A is wrong because a build artifact is the output of a build process, not a mechanism to include external dependencies; modifying the buildspec to include a library as an artifact would not install it into the build environment. Option B is wrong because while downloading from S3 is possible, it introduces network latency, potential permission issues, and version management overhead; it is a workaround rather than a proper solution for a missing library. Option C is wrong because adding an install command to download and compile the library during each build is inefficient, increases build time, and risks build failures due to network issues or source unavailability; it also violates the principle of using a consistent, pre-configured environment.

115
MCQmedium

A DevOps team uses AWS Elastic Beanstalk to deploy a web application. They want to implement a blue/green deployment strategy to minimize downtime. Which configuration change should they make?

A.Create a new environment and perform a CNAME swap.
B.Set the deployment policy to 'All at once'.
C.Set the deployment policy to 'Rolling' with a batch size of 50%.
D.Set the deployment policy to 'Immutable'.
AnswerA

In a blue/green deployment, you provision a second Elastic Beanstalk environment (the green environment) with the new application version, run tests against it, and then use the Swap Environment URLs feature to atomically redirect the existing CNAME to the new environment. This avoids any downtime during the cutover and leaves the old (blue) environment intact for instant rollback if issues arise after the swap.

Why this answer

Blue/green deployment in AWS Elastic Beanstalk is achieved by creating a separate environment (the 'green' environment) with the new application version, then swapping the CNAME of the existing 'blue' environment to point to the green environment. This CNAME swap is instantaneous and does not require DNS propagation, minimizing downtime. Option A correctly describes this process.

Exam trap

The trap here is that candidates confuse 'Immutable' deployments with blue/green, but immutable still replaces instances in-place rather than performing a CNAME swap between two independent environments.

How to eliminate wrong answers

Option B is wrong because 'All at once' deploys the new version to all instances simultaneously, causing downtime during the deployment. Option C is wrong because 'Rolling' with a batch size of 50% updates instances in batches, which still results in reduced capacity and potential downtime during the transition. Option D is wrong because 'Immutable' deploys a new Auto Scaling group with the new version, but it does not perform a CNAME swap; it replaces the old instances after health checks, which can cause brief downtime and does not provide the instant cutover of blue/green.

116
Multi-Selecthard

A company uses AWS Elastic Beanstalk to deploy a web application. The application experiences high traffic during business hours and low traffic at night. The company wants to configure automatic scaling based on CPU utilization. Which THREE steps are required to achieve this? (Select THREE.)

Select 3 answers
A.Create a CloudWatch alarm that triggers a scaling policy.
B.Set the minimum and maximum number of instances for the auto scaling group.
C.Configure the load balancer health check interval.
D.Set the scale-up and scale-down cooldown periods.
E.Define a scaling trigger based on average CPU utilization.
AnswersB, D, E

Setting the minimum and maximum number of instances for the Auto Scaling group is an absolute prerequisite for any elastic scaling in Elastic Beanstalk. These values define the allowed capacity range that the Auto Scaling group can scale within, and without them the Auto Scaling group cannot adjust its size. Every scaling activity, whether scale-out or scale-in, must respect these boundaries, making this a mandatory configuration element.

Why this answer

Elastic Beanstalk uses Auto Scaling groups to manage the EC2 instances for the application. Setting the minimum and maximum number of instances defines the boundaries within which the Auto Scaling group can scale, ensuring the application can handle high traffic during business hours and scale down during low traffic at night.

Exam trap

The trap here is that candidates often think creating a CloudWatch alarm manually is required, but Elastic Beanstalk handles this automatically when you define the scaling trigger, making Option A an unnecessary step.

117
MCQhard

A DevOps engineer is troubleshooting an AWS CodeDeploy deployment that fails during the 'BeforeInstall' lifecycle event. The deployment group uses an in-place deployment to an Auto Scaling group. The engineer reviews the logs on the instance and sees that the 'BeforeInstall' script exits with code 1. The script is a shell script that compiles application code. What is the most likely cause of the failure?

A.The script exited with a non-zero exit code
B.The script is not included in the 'files' section of the appspec.yml
C.The script requires dependencies that are not installed on the instance
D.The script is not owned by the root user
AnswerA

CodeDeploy treats any non-zero exit code from a lifecycle event script as a definitive failure, regardless of the underlying cause. When the agent executes a script, it captures the process exit status; if it is not 0, the deployment immediately stops, marks the overall deployment as Failed, and runs any configured OnFailure hooks. This is the direct trigger for the failure, even if the script printed an error message before exiting.

Why this answer

In AWS CodeDeploy, lifecycle event scripts must exit with a status code of 0 to indicate success. Any non-zero exit code, including 1, is interpreted as a failure, causing the deployment to abort. Since the 'BeforeInstall' script exits with code 1, the deployment fails regardless of the script's intent or content.

Exam trap

The trap here is that candidates may overthink the cause (e.g., missing dependencies or file permissions) when the question explicitly states the script exits with code 1, which is the direct and most likely cause of failure in CodeDeploy's lifecycle event execution model.

How to eliminate wrong answers

Option B is wrong because the 'files' section of the appspec.yml specifies which files to copy to the instance, not which scripts to run; lifecycle hooks are defined in the 'hooks' section. Option C is wrong because while missing dependencies could cause a script to fail, the question explicitly states the script exits with code 1, which is a direct exit code failure, not a dependency error (which would typically produce a different error message or exit code). Option D is wrong because script ownership does not affect exit codes; CodeDeploy runs scripts as the root user by default, and a non-root owner would not cause a non-zero exit code unless the script itself checks ownership.

118
Multi-Selecteasy

Which TWO tools can be used to manage configuration drift detection for AWS resources? (Choose two.)

Select 2 answers
A.AWS Config
B.AWS Systems Manager Inventory
C.AWS Trusted Advisor
D.AWS CloudTrail
E.AWS CloudFormation Drift Detection
AnswersA, E

AWS Config is the correct service for managing configuration drift because it continuously records and evaluates the configuration of AWS resources against desired baseline rules. When a resource's configuration changes from the recorded baseline, AWS Config flags it as noncompliant, providing a precise, rule-driven mechanism to detect drift. You can define custom or managed rules that represent your desired state, and AWS Config will produce a detailed compliance history and configuration timeline for every tracked resource, enabling automated remediation via Systems Manager Automation or Lambda.

Why this answer

AWS Config continuously monitors and records AWS resource configurations and can detect changes against desired baselines, enabling drift detection through rules and compliance checks. AWS CloudFormation Drift Detection directly compares the current state of a stack's resources with the expected template-defined state to identify configuration drift. Both tools provide native mechanisms to detect when resources deviate from their intended configuration.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Inventory (which collects instance-level software inventory) with configuration drift detection, or they mistakenly think AWS CloudTrail's API logging is sufficient to detect drift, when in fact drift detection requires comparing current state to a desired baseline, not just recording changes.

119
MCQeasy

A company uses AWS Elastic Beanstalk to deploy a Java web application. The DevOps team wants to ensure that configuration changes are tracked and can be rolled back if needed. Which Elastic Beanstalk feature should they use?

A.Use AWS CodeCommit to store configuration files and version them.
B.Use AWS CodePipeline with a manual approval stage to track changes.
C.Use AWS CloudFormation change sets to review changes before deployment.
D.Use Elastic Beanstalk saved configurations to capture environment settings and restore them if needed.
AnswerD

Elastic Beanstalk saved configurations provide a native way to snapshot an environment's option settings, environment variables, and solution stack into a re-usable YAML file. You can save a known-good configuration using the console or `eb config save`, and later restore it to the same or a different environment to roll back any undesired changes. Because saved configurations are purpose-built for this scenario, they give you an auditable, restorable record of environment settings without requiring code deployments or external tools.

Why this answer

Elastic Beanstalk saved configurations allow you to capture the environment's configuration settings (e.g., instance type, environment variables, platform version) as a JSON file stored in S3. This enables you to restore or recreate an environment with the exact same settings, providing a straightforward rollback mechanism for configuration changes without relying on external tools or pipelines.

Exam trap

The trap here is that candidates often confuse configuration management with CI/CD pipeline tools, assuming that CodePipeline or CodeCommit can handle environment-specific rollbacks, when in fact Elastic Beanstalk's native saved configurations are the simplest and most direct mechanism for tracking and reverting environment settings.

How to eliminate wrong answers

Option A is wrong because AWS CodeCommit is a Git-based source control service for storing code and configuration files, but it does not natively integrate with Elastic Beanstalk to track or roll back environment-specific settings; it would require manual scripting to apply versions. Option B is wrong because AWS CodePipeline is a CI/CD service that orchestrates build, test, and deploy stages; while it can include a manual approval stage, it is designed for application deployment pipelines, not for tracking or rolling back Elastic Beanstalk environment configuration changes. Option C is wrong because AWS CloudFormation change sets are used to review changes to CloudFormation stacks before execution, but Elastic Beanstalk environments are not managed as CloudFormation stacks by default (unless using the CloudFormation-backed environment option), and change sets do not directly apply to Elastic Beanstalk's native configuration management.

120
MCQmedium

A company uses AWS CloudFormation to deploy a stack that includes an Amazon RDS DB instance. The database password is stored in AWS Secrets Manager. The CloudFormation template needs to reference the secret value dynamically during stack creation. How should the template retrieve the secret?

A.Use a CloudFormation mapping to store the secret ARN.
B.Use a dynamic reference with '{{resolve:secretsmanager:secret-id:secret-string}}' in the template.
C.Hardcode the password in the template as a literal string.
D.Use a CloudFormation parameter with a default value referencing the secret ARN.
AnswerB

The dynamic reference syntax {{resolve:secretsmanager:secret-id:secret-string}} is correct because CloudFormation resolves it to the actual secret value at stack creation or update time. The full syntax allows you to specify a JSON key, version stage, or version ID, giving you precise control over which secret value is injected into a resource property. CloudFormation calls GetSecretValue on your behalf, so the secret never appears in the template, change sets, or the rendered stack template. To use this, ensure the CloudFormation execution role has the secretsmanager:GetSecretValue permission for the target secret.

Why this answer

CloudFormation dynamic references using the 'resolve:secretsmanager' syntax allow the template to retrieve secret values from AWS Secrets Manager at stack creation time. Option B correctly uses this dynamic reference to pull the password securely. Option A (mapping) cannot retrieve secrets dynamically; it only stores static values.

Option C (hardcoding) is insecure and not dynamic. Option D (parameter with default ARN) does not retrieve the secret value; it only passes the ARN string, not the actual secret.

121
MCQhard

A team uses Terraform to manage AWS infrastructure. After a recent update, a state file shows that a security group rule was created, but the rule does not exist in AWS. Running 'terraform plan' shows no changes. What is the most likely cause?

A.The security group rule was imported into state but not defined in configuration.
B.The 'terraform refresh' command was not run before the plan.
C.There is a conflict between multiple Terraform workspaces.
D.The security group rule was added manually via the AWS console and is not managed by Terraform, causing state to be out of sync.
AnswerB

When a resource is deleted outside of Terraform, the state still contains the old resource until a refresh reconciles it with the live AWS inventory. Running terraform plan without a preceding terraform refresh — or with refresh explicitly disabled — lets Terraform compare configuration only against stale state, so it concludes the rule still exists and reports no changes. A manual deletion is exactly the kind of drift that refresh is designed to detect; skipping it hides the missing security group rule from the planner.

Why this answer

If a security group rule was deleted manually from AWS (e.g., via console or CLI), the state file still contains the resource. Without running 'terraform refresh', Terraform does not detect the deletion and assumes the state is accurate. Thus, 'terraform plan' shows no changes because it compares the current state (which still includes the rule) with the configuration (which likely does define it, otherwise plan would show a destroy).

If 'terraform refresh' had been run, the state would be updated to remove the rule, and then plan would show a creation. Option A is incorrect because if the rule were imported into state but not defined in configuration, plan would show a destroy. Option C is incorrect because workspace conflicts typically cause state isolation issues, not missing resources.

Option D is incorrect because adding a rule manually would create it, not cause it to be missing; the scenario states the rule does not exist in AWS.

122
MCQeasy

A company uses AWS OpsWorks for configuration management. They want to ensure that whenever a new instance is added to a layer, it automatically installs the latest security patches and joins a central logging system. What is the most efficient way to achieve this?

A.Schedule a cron job on each instance to check and apply patches daily.
B.Use Chef recipes in a custom OpsWorks layer's Setup lifecycle event.
C.Configure user data scripts in the launch configuration.
D.SSH into each instance and run the commands manually.
AnswerB

The Setup lifecycle event runs recipes when an instance is added to the layer, so security patches and logging-agent configuration apply automatically. This satisfies the requirement for automatic onboarding without manual intervention on each new instance.

Why this answer

AWS OpsWorks uses Chef recipes to automate configuration management. The Setup lifecycle event runs on every instance when it is added to a layer, making it the correct place to install security patches and configure the logging agent. This ensures consistency and automation without manual intervention, and it is the native OpsWorks mechanism for bootstrapping instances.

Exam trap

DOP-C02 often tests the difference between OpsWorks lifecycle events and EC2 user data — candidates may pick user data because it is familiar, but OpsWorks layers require Chef recipes in lifecycle events, not user data scripts.

How to eliminate wrong answers

Option A is wrong because a cron job is a manual, per-instance workaround that does not integrate with OpsWorks lifecycle management and may run at inconsistent times. Option C is wrong because user data scripts are for EC2 launch configurations, not OpsWorks layers; OpsWorks manages instances through Chef, and user data would bypass the layer's configuration management. Option D is wrong because manual SSH is not automated, not scalable, and violates the principle of infrastructure as code.

123
MCQeasy

A company uses AWS CloudFormation to manage its infrastructure. The DevOps team notices that stack updates sometimes fail because of resource conflicts. The team wants to prevent concurrent updates to the same stack. What should they do?

A.Use an AWS Organizations service control policy to restrict updates
B.Create an IAM policy that denies cloudformation:UpdateStack if a stack update is in progress
C.No action needed; CloudFormation already prevents concurrent stack updates
D.Enable CloudTrail to log all stack update attempts and manually review
AnswerC

No action is required because the CloudFormation service applies a mutual-exclusion lock to each stack: from the moment an UpdateStack call is accepted until the update, rollback, or clean-up finishes, any subsequent UpdateStack, DeleteStack, or ExecuteChangeSet operation on the same stack is rejected with a ValidationError such as 'Stack is currently in an update state'. This built-in serialization prevents concurrent modifications and preserves stack consistency without any downstream code, IAM policy, or auxiliary lock. Therefore, the design is already safe, and adding extra mechanisms is redundant.

Why this answer

AWS CloudFormation inherently prevents concurrent updates to the same stack. When an update operation is initiated, CloudFormation places a lock on the stack, rejecting any subsequent update requests until the current operation completes. This behavior is built into the service and requires no additional configuration, making option C correct.

Exam trap

The trap here is that candidates overthink the problem and assume they need to implement custom concurrency controls (like IAM policies or SCPs), when in fact CloudFormation already handles this natively, making the 'no action needed' answer the correct one.

How to eliminate wrong answers

Option A is wrong because AWS Organizations service control policies (SCPs) are used to centrally control permissions across accounts, not to prevent concurrent stack updates within a single account; they cannot enforce operation-level concurrency controls. Option B is wrong because IAM policies evaluate permissions at the time of the API call, but CloudFormation already rejects concurrent updates at the service level, so an IAM policy denying UpdateStack during an in-progress update is redundant and would require custom logic (e.g., using condition keys like cloudformation:StackStatus) that is not natively supported for this purpose. Option D is wrong because CloudTrail logs API calls for auditing but does not prevent concurrent updates; manual review after the fact does not address the real-time conflict.

124
MCQhard

A team uses AWS CloudFormation to manage a multi-tier application. They update the stack and receive this error: 'UPDATE_ROLLBACK_FAILED'. The stack is in a state where some resources were updated, then rollback failed. What is the best course of action?

A.Use the 'ContinueUpdateRollback' API or AWS Management Console to resume rollback, and fix any underlying issues.
B.Ignore the error and use the stack as-is.
C.Attempt to continue the update again.
D.Delete the stack and recreate it.
AnswerA

When an update fails and the automatic rollback is also unsuccessful, CloudFormation leaves the stack in the UPDATE_ROLLBACK_FAILED state. The ContinueUpdateRollback API or console action is the designed recovery mechanism; it retries the rollback of resources that failed, allowing you to skip resources with known issues and restore the stack to a usable state before fixing underlying problems and reattempting the update.

Why this answer

The 'UPDATE_ROLLBACK_FAILED' state indicates that CloudFormation attempted to roll back a failed stack update but encountered an error during the rollback process. The correct action is to use the 'ContinueUpdateRollback' API (or the AWS Management Console equivalent) to resume the rollback after fixing the underlying issue that caused the rollback to fail, such as a resource dependency or permission problem. This allows CloudFormation to complete the rollback and return the stack to a known stable state, rather than leaving it in an inconsistent or partially updated condition.

Exam trap

The trap here is that candidates may think they can simply retry the update (Option C) or ignore the error (Option B), not realizing that CloudFormation's state machine requires a specific recovery action—'ContinueUpdateRollback'—to exit the 'UPDATE_ROLLBACK_FAILED' state before any further stack operations are allowed.

How to eliminate wrong answers

Option B is wrong because ignoring the error leaves the stack in an inconsistent 'UPDATE_ROLLBACK_FAILED' state, where some resources may have been updated and others not, leading to potential application instability or security risks. Option C is wrong because attempting to continue the update again is not possible; CloudFormation does not allow a new update operation on a stack in the 'UPDATE_ROLLBACK_FAILED' state—you must first resolve the rollback failure. Option D is wrong because deleting the stack and recreating it is an overly destructive approach that loses the existing stack's state and resources, and it does not address the root cause of the rollback failure; the 'ContinueUpdateRollback' API is the designed recovery mechanism.

125
MCQeasy

A DevOps engineer needs to create an IAM policy that allows a user to start and stop EC2 instances, but only for instances that have a specific tag 'Environment=Production'. The current policy allows all actions on all instances. Which modification must be made to enforce the tag-based restriction?

A.Add a Condition block: "Condition": {"StringEquals": {"aws:PrincipalTag/Environment": "Production"}}
B.Change the Action to "ec2:Describe*" and add a NotAction element.
C.Add a Condition block: "Condition": {"StringEquals": {"ec2:ResourceTag/Environment": "Production"}}
D.Add a Condition block: "Condition": {"StringEquals": {"aws:RequestTag/Environment": "Production"}}
AnswerC

This is correct because ec2:ResourceTag/Environment is the IAM condition key that checks the value of the Environment tag on the EC2 resource (instance, volume, etc.) that the request targets, and StringEquals ensures the tag must exactly equal "Production". By adding this Condition block to the policy statement, the allowed actions are only granted when the resource being acted upon carries that tag, effectively scoping permissions to Production instances. This is the standard pattern for tag-based, resource-level access control for EC2.

Why this answer

The `ec2:ResourceTag` condition key allows you to restrict actions based on the tags already attached to the EC2 instance. By using `StringEquals` with `ec2:ResourceTag/Environment` set to `Production`, the policy will only permit the `ec2:StartInstances` and `ec2:StopInstances` actions on instances that currently have that tag. This is the standard AWS mechanism for tag-based resource-level authorization in IAM policies.

Exam trap

The trap here is confusing `ec2:ResourceTag` (tag on the resource) with `aws:RequestTag` (tag in the API request) or `aws:PrincipalTag` (tag on the user), leading candidates to pick a condition key that does not evaluate the instance's existing tags.

How to eliminate wrong answers

Option A is wrong because `aws:PrincipalTag/Environment` checks the tag on the IAM user or role making the request, not the tag on the EC2 instance; this would allow any user with that principal tag to act on any instance, regardless of the instance's tags. Option B is wrong because changing the Action to `ec2:Describe*` would only permit read-only actions (like listing instances), not start/stop operations, and adding a `NotAction` element does not enforce tag-based restrictions—it inverts the action scope, which is irrelevant here. Option D is wrong because `aws:RequestTag/Environment` checks tags that are passed in the API request itself (e.g., when creating a resource), not the tags already present on an existing resource; this would not restrict start/stop actions on existing instances based on their current tags.

126
MCQhard

An organization uses AWS System Manager Patch Manager to patch EC2 instances. The patches are not being applied to some instances. The instances are running Amazon Linux 2 and have the SSM Agent installed. What is the MOST likely reason for the failure?

A.The instances do not have internet access to reach the Systems Manager endpoint.
B.The SSM Agent is out of date and needs to be updated.
C.The instances are missing the required IAM role for Systems Manager.
D.The instances are not running a supported operating system.
AnswerC

To allow the SSM Agent to call Systems Manager APIs, an instance must have an IAM instance profile with the AmazonSSMManagedInstanceCore managed policy. Without this role, the agent cannot authenticate, and the instance will not appear as a managed node in Patch Manager, so no patching can occur.

Why this answer

Instances must have an IAM role that grants Systems Manager permissions to manage patches. Without this role, the SSM Agent cannot communicate with the Systems Manager service, preventing patch application. Option A is incorrect because instances can use VPC endpoints (e.g., AWS PrivateLink) to reach Systems Manager without internet access.

Option B is incorrect: although an out-of-date SSM Agent can cause issues, the agent auto-updates by default, and the most common cause for patch failures is missing IAM permissions, not an outdated agent. Option D is incorrect because Amazon Linux 2 is a fully supported operating system for Patch Manager.

127
Multi-Selectmedium

A company is designing a CI/CD pipeline for a microservices architecture using AWS CodePipeline. They want to use infrastructure as code to manage the pipeline itself. Which TWO services can be used together to achieve this?

Select 2 answers
A.AWS Service Catalog
B.AWS CodePipeline
C.AWS CloudFormation
D.AWS CodeDeploy
E.AWS Elastic Beanstalk
AnswersB, C

CodePipeline is the orchestration service whose own pipeline definition can be declared as code, letting the team version and recreate the pipeline itself. It satisfies the requirement by acting as the managed resource that CloudFormation templates provision and update.

Why this answer

AWS CloudFormation [CORRECT] is the infrastructure-as-code service that lets you define and provision AWS resources, including the CodePipeline pipeline itself, in a declarative template so the pipeline is version-controlled and reproducible. AWS CodePipeline [CORRECT] is the CI/CD orchestration service that is being managed as code; CloudFormation supports an AWS::CodePipeline::Pipeline resource type, so the two services work together to define and run the pipeline from a template. AWS Service Catalog is a catalog of approved products for governed provisioning, not a way to author the pipeline as code, so it does not belong.

AWS CodeDeploy is a deployment service used as a pipeline action provider, not the IaC mechanism for managing the pipeline. AWS Elastic Beanstalk is a PaaS application-hosting service, not a pipeline-definition or IaC tool.

Exam trap

DOP-C02 often tests whether candidates confuse CodePipeline (the CI/CD service) with the IaC tool that defines it (CloudFormation), and whether they mistakenly pick CodeDeploy or Elastic Beanstalk as pipeline-definition tools.

128
MCQmedium

A DevOps engineer is using AWS CloudFormation to provision a VPC that includes public and private subnets, an Internet Gateway, and NAT Gateways. The engineer wants to ensure that the private subnets have outbound internet access through the NAT Gateways. After deploying the stack, the engineer notices that instances in the private subnets cannot reach the internet. The engineer verifies that the route tables for the private subnets have a route to the NAT Gateway. What is the most likely cause of the issue?

A.The NAT Gateway is not associated with an Elastic IP address.
B.The private subnets are missing an association with a network ACL that allows outbound traffic to the NAT Gateway.
C.The route in the private subnet's route table points to the NAT Gateway in the same Availability Zone, but the NAT Gateway is in a public subnet that lacks a route to the Internet Gateway.
D.The instances in the private subnets do not have a public IP address, so they cannot communicate with the NAT Gateway.
AnswerC

For a NAT Gateway to provide internet access, its public subnet must have a route to an Internet Gateway. If the public subnet's route table does not have a route to the Internet Gateway, the NAT Gateway cannot forward traffic to the internet. This is a common misconfiguration in CloudFormation templates.

Why this answer

A NAT Gateway must reside in a public subnet that has a route to an Internet Gateway. If the public subnet's route table lacks a route to the Internet Gateway, the NAT Gateway cannot route traffic to the internet. The engineer should verify that the public subnet's route table has a route to the Internet Gateway and that the NAT Gateway is correctly placed.

Exam trap

The trap here is assuming that as long as the private subnet route table points to the NAT Gateway, internet access works, without verifying that the NAT Gateway's own subnet has a route to the Internet Gateway.

129
MCQeasy

A company uses AWS OpsWorks to manage a set of EC2 instances. They need to ensure that a custom recipe runs on all instances during the 'Configure' lifecycle event. What is the correct way to achieve this?

A.Modify the stack's CloudFormation template to include the recipe.
B.Upload the recipe to a custom cookbook repository and assign it to the 'Configure' lifecycle event in the stack settings.
C.Add the recipe commands to the instance's user data script.
D.Use AWS CodeDeploy to trigger the recipe during the Configure event.
AnswerB

Upload the cookbook containing the recipe to a repository (S3, Git, or HTTP), then in the OpsWorks stack settings enable 'Use custom Chef cookbooks' and add the recipe name to the Configure lifecycle event. The OpsWorks agent then executes that recipe on every Configure event, which fires when any instance enters the online state or when instances are added to or removed from the stack. This is the documented, supported method for attaching custom configuration logic to OpsWorks lifecycle events.

Why this answer

In AWS OpsWorks, lifecycle events (such as Configure) are tied to layers, not individual instances. To run a custom recipe on all instances during the Configure event, you must upload the recipe to a custom cookbook repository (e.g., S3 or Git) and then assign that recipe to the Configure lifecycle event in the stack's layer settings. This ensures OpsWorks Chef runs the recipe on every instance in that layer whenever the Configure event fires (e.g., after scaling or instance state changes).

Exam trap

The trap here is that candidates confuse the one-time execution of user data scripts (Option C) with the recurring, event-driven nature of OpsWorks lifecycle events, or mistakenly think CloudFormation (Option A) or CodeDeploy (Option D) can directly manage OpsWorks recipe execution.

How to eliminate wrong answers

Option A is wrong because AWS OpsWorks does not use CloudFormation templates to define lifecycle recipes; OpsWorks uses Chef cookbooks and lifecycle event assignments within the stack/layer configuration. Option C is wrong because user data scripts run only once at instance boot, whereas the Configure lifecycle event fires repeatedly (e.g., on instance start, stop, or scaling), so a user data script cannot handle recurring Configure events. Option D is wrong because AWS CodeDeploy is a deployment service for application code, not a mechanism to trigger OpsWorks lifecycle events; it cannot directly invoke Chef recipes during the Configure event.

130
MCQhard

An organization manages multiple AWS accounts using AWS Organizations. They want to use AWS CloudFormation StackSets to deploy a standard VPC configuration across all accounts. However, some accounts require specific CIDR blocks that differ from the default. What is the most efficient way to handle this variation?

A.Create separate StackSets for each CIDR range and assign accounts accordingly.
B.Create a nested stack for each account that overrides the default parameters.
C.Use a single StackSet with parameters and pass account-specific parameter files via AWS CloudFormation parameter overrides in the StackSet instance.
D.Maintain separate templates per account with hardcoded CIDR blocks.
AnswerC

A single StackSet with a common template and per-account parameter overrides is the intended pattern for account-specific values like CIDR blocks. You can attach overrides to individual stack instances via CreateStackInstances or UpdateStackInstances, so each account receives the same standard security and network rules but with the exact CIDR range it needs, all through one API call. This approach centralizes updates and drift management—changing a rule once updates every account—while preserving per-account flexibility, and it integrates natively with Organizations' delegated administrator and automatic deployment for new accounts.

Why this answer

AWS CloudFormation StackSets support parameter overrides at the stack instance level, allowing you to deploy a single StackSet template across multiple accounts while specifying account-specific CIDR blocks without duplicating infrastructure. This approach minimizes management overhead by using one template and one StackSet, with parameter overrides applied per target account or organizational unit (OU) via the StackSet instance configuration.

Exam trap

The trap here is that candidates often confuse StackSet parameter overrides with nested stacks or separate templates, not realizing that StackSets natively support per-instance parameter values without requiring multiple StackSets or template duplication.

How to eliminate wrong answers

Option A is wrong because creating separate StackSets for each CIDR range defeats the purpose of using StackSets for centralized management, leading to operational complexity and increased maintenance burden. Option B is wrong because nested stacks are not designed to override parameters per account in a StackSet; they are used for modular template composition, not for passing account-specific values across multiple StackSet instances. Option D is wrong because maintaining separate templates per account with hardcoded CIDR blocks violates IaC best practices, introduces drift risk, and eliminates the reusability and consistency that StackSets provide.

131
MCQeasy

A DevOps engineer is using AWS OpsWorks for configuration management. They need to ensure that custom recipes are applied to all instances in a layer in a specific order. What should the engineer do?

A.Assign the recipes to the appropriate lifecycle events in the layer configuration.
B.Use AWS CloudFormation Init with cfn-init to order the scripts.
C.Include all recipes in a single wrapper recipe and use include_recipe with the desired order.
D.Add the recipes to the instance's user data script.
AnswerA

Assigning recipes to lifecycle events is the native OpsWorks Stacks mechanism for ordered configuration. Each layer exposes five lifecycle events (Setup, Configure, Deploy, Undeploy, Shutdown), and recipes attached to an event execute in the order listed within that event's configuration. This provides a predictable, sequential run across all instances in the layer, ensuring that prerequisites and dependencies are satisfied. Because OpsWorks orchestrates these events centrally, this is the only option that reliably enforces both per-instance ordering and layer-wide sequencing.

Why this answer

AWS OpsWorks uses lifecycle events (Setup, Configure, Deploy, Undeploy, Shutdown) to control when custom recipes run on instances within a layer. By assigning recipes to the appropriate lifecycle events in the layer configuration, the engineer ensures they execute in the defined order for that event across all instances in the layer, which is the native mechanism for ordering in OpsWorks.

Exam trap

The trap here is that candidates may confuse OpsWorks lifecycle events with Chef's include_recipe directive, assuming that ordering within a wrapper recipe is sufficient, when OpsWorks actually enforces order through lifecycle event assignments.

How to eliminate wrong answers

Option B is wrong because AWS CloudFormation Init with cfn-init is used for bootstrapping EC2 instances in CloudFormation stacks, not for managing recipe execution order within an OpsWorks layer, which is a separate configuration management service. Option C is wrong because while include_recipe can be used in Chef to include other recipes, placing all recipes in a single wrapper recipe does not inherently enforce a specific order across lifecycle events; OpsWorks relies on lifecycle event assignments to control execution sequence, not Chef's include_recipe order alone. Option D is wrong because user data scripts run only at instance launch and are not integrated with OpsWorks lifecycle events; they cannot manage the ordered execution of custom recipes across the instance's operational lifecycle.

132
MCQmedium

A DevOps team uses AWS CodeCommit and AWS CodePipeline for CI/CD. They need to ensure that sensitive configuration parameters such as database passwords are not stored in plaintext in the source code repository. Which solution meets these requirements with minimal operational overhead?

A.Store the parameters in a separate encrypted Git repository and use Git submodules.
B.Use AWS KMS to encrypt the parameters and include the encrypted blob in the source code.
C.Store the parameters in an S3 bucket with server-side encryption, and have the pipeline download them.
D.Use AWS Systems Manager Parameter Store with secure strings, and reference them in the pipeline using parameter-store action.
AnswerD

AWS Systems Manager Parameter Store with a SecureString parameter encrypts the secret under a KMS customer managed key and lets CodePipeline or CodeBuild retrieve it directly as an environment variable at build time, without the secret ever appearing in the source repository or build artifact. Because access is controlled via IAM, you can scope which pipelines see which secrets, and you can rely on Parameter Store’s native versioning to rotate values without triggering a pipeline rebuild.

Why this answer

AWS Systems Manager Parameter Store with secure strings provides a native, fully managed service for storing sensitive configuration data like database passwords. By using the parameter-store action in CodePipeline, the pipeline can retrieve the secure parameter at runtime without exposing it in the source code or requiring manual encryption/decryption logic, minimizing operational overhead.

Exam trap

The trap here is that candidates may think storing an encrypted blob in the repository (Option B) is acceptable because it is 'encrypted,' but the exam tests the principle that secrets should never be stored in the source code repository at all, even in encrypted form, due to key management and exposure risks.

How to eliminate wrong answers

Option A is wrong because maintaining a separate encrypted Git repository and using Git submodules adds significant complexity, does not natively integrate with CodePipeline, and still risks exposing sensitive data in the submodule reference or during cloning. Option B is wrong because including an encrypted blob in the source code requires manual key management and decryption logic in the pipeline, and the encrypted blob itself is still stored in the repository, which violates the principle of not storing secrets in the codebase. Option C is wrong because storing parameters in an S3 bucket with server-side encryption requires additional pipeline steps to download the file, manage bucket permissions, and handle potential race conditions or stale data, increasing operational overhead compared to a direct parameter store reference.

133
MCQmedium

A company uses AWS CloudFormation to deploy a web application across multiple AWS accounts using StackSets. The DevOps team notices that stack instance updates are failing in some accounts with the error: 'Insufficient IAM permissions to perform the action'. The team has already verified that the StackSet IAM role has the necessary permissions. What is the most likely cause of this issue?

A.The target accounts have reached the limit of 200 stacks per region.
B.The target accounts do not have the necessary trust policy to allow the StackSet IAM role to assume the execution role.
C.AWS Organizations has a service control policy (SCP) that denies the required action, but the StackSet IAM role has full admin permissions.
D.The StackSet name contains invalid characters that are not allowed in some accounts.
AnswerB

AWS CloudFormation StackSets require a trust relationship between the IAM role used to administer the StackSet (in the management account) and an execution role in each target account. If the execution role’s trust policy does not include the StackSet IAM role (or the appropriate account) as a trusted principal, the sts:AssumeRole call fails with an access-denied error. This trust policy is what authorizes the management account’s role to assume the target execution role, so its absence directly produces the reported failure.

Why this answer

StackSets require a trust relationship between the StackSet IAM role (in the management account) and an execution role in each target account. Even if the StackSet IAM role has full permissions, the target accounts must have a trust policy that allows the StackSet IAM role to assume the execution role. Without this trust policy, the assumption fails, resulting in the 'Insufficient IAM permissions' error.

Exam trap

The trap here is that candidates often assume the error is due to missing permissions on the StackSet IAM role itself, but the DOP-C02 exam tests the understanding that StackSets require a trust chain where the target account's execution role must explicitly trust the management account's StackSet IAM role.

How to eliminate wrong answers

Option A is wrong because the error message specifically mentions IAM permissions, not stack limits; reaching the 200-stack limit would produce a limit exceeded error, not an IAM permissions error. Option C is wrong because SCPs can deny actions even if the IAM role has full admin permissions, but the question states the team verified the StackSet IAM role has necessary permissions, and the error is about IAM permissions, not SCP denials; however, SCPs would cause a different error (e.g., 'Action denied by service control policy'), and the scenario points to a trust policy issue. Option D is wrong because StackSet names have character restrictions that are validated at creation time, not during updates, and invalid characters would cause a creation failure, not an update permission error.

134
MCQmedium

A DevOps engineer is using AWS Systems Manager Parameter Store to manage configuration data for a fleet of Amazon EC2 instances. The engineer needs to store a database password that must be encrypted at rest and audited for access. The password should be automatically rotated every 30 days. Which solution meets these requirements?

A.Store the password as a String parameter in Parameter Store and enable AWS CloudTrail logging.
B.Store the password as a SecureString parameter in Parameter Store with the default AWS managed KMS key.
C.Store the password in AWS Secrets Manager and configure automatic rotation using a Lambda rotation function.
D.Store the password in an encrypted Amazon S3 object and use S3 bucket policies to restrict access.
AnswerC

AWS Secrets Manager is designed for storing and rotating secrets. It supports automatic rotation via Lambda functions, and it integrates with AWS KMS for encryption and AWS CloudTrail for auditing. This solution meets all requirements: encryption at rest, auditing, and automatic 30-day rotation.

Why this answer

AWS Secrets Manager is purpose-built for managing secrets like database passwords. It encrypts secrets using KMS, logs access via CloudTrail, and supports automatic rotation through Lambda functions. Parameter Store SecureString parameters offer encryption but lack built-in rotation.

Therefore, Secrets Manager is the correct choice for meeting all requirements.

Exam trap

The trap here is assuming that Parameter Store SecureString parameters support automatic rotation, which they do not; rotation must be implemented manually.

135
MCQhard

An organization uses AWS OpsWorks for configuration management. They want to migrate to AWS Systems Manager to reduce costs and improve flexibility. Their current stack includes custom Chef recipes that manage package installations and service configurations. What is the MOST effective migration strategy?

A.Use AWS CloudFormation to recreate the entire infrastructure and manage configurations.
B.Use AWS CodeDeploy to replace OpsWorks and manage configurations.
C.Translate Chef recipes into Systems Manager State Manager associations and use Run Command for ad-hoc tasks.
D.Keep OpsWorks but integrate it with Systems Manager for hybrid management.
AnswerC

Systems Manager State Manager associations can enforce a desired state on EC2 instances by running SSM documents that are idempotent, similar to Chef's converge model, and can directly execute existing Chef recipes using the built-in AWS-ApplyChefRecipes document. Run Command complements this by providing on-demand, ad-hoc command execution without needing a managed node group or persistent agent configuration. Migrating to SSM removes OpsWorks per-node costs and creates a more flexible, hybrid-amenable control plane integrated with IAM and CloudWatch.

Why this answer

Systems Manager State Manager associations can enforce desired-state configuration (package installs, service states) on a schedule, directly replacing the convergent behavior of Chef recipes, while Run Command handles ad-hoc or one-off execution. This maps OpsWorks Chef functionality onto native Systems Manager capabilities without introducing new tooling.

Exam trap

DOP-C02 often tests whether candidates conflate provisioning (CloudFormation) or deployment (CodeDeploy) with configuration management; the trap is picking CloudFormation because it 'manages infrastructure' when the requirement is ongoing state enforcement.

How to eliminate wrong answers

Option A is wrong because CloudFormation is an infrastructure-as-code provisioning service; it does not perform ongoing configuration management or replace Chef's convergent recipe execution. Option B is wrong because CodeDeploy orchestrates application deployments to instances, not configuration drift remediation or package/service state management. Option D is wrong because keeping OpsWorks defeats the stated goal of migrating off it to reduce cost and improve flexibility.

136
Multi-Selectmedium

A DevOps team is designing a CI/CD pipeline for a microservices application deployed on Amazon ECS. The application uses multiple AWS services including RDS, ElastiCache, and SQS. Which TWO strategies should the team implement to ensure secure and auditable configuration management across environments?

Select 2 answers
A.Use AWS Secrets Manager to store and rotate database credentials.
B.Implement AWS Config rules to enforce tagging and compliance standards.
C.Store database credentials in a version-controlled configuration file.
D.Manually review configuration changes before deployment.
E.Grant developers direct S3 access to upload configuration files.
AnswersA, B

AWS Secrets Manager natively rotates RDS credentials via Lambda, satisfying the rotation requirement for database secrets. Unlike Parameter Store, it provides built-in rotation and cross-account replication, keeping credentials out of code and pipeline variables while CloudTrail logs every retrieval for auditability across environments.

Why this answer

Option A is correct because AWS Secrets Manager is purpose-built to store sensitive values such as RDS database credentials and can automatically rotate them on a schedule using Lambda rotation functions, keeping secrets out of code and configuration files across all environments. Option B is correct because AWS Config continuously records resource configurations and evaluates them against rules, enabling enforcement of tagging and compliance standards and providing an auditable history of configuration changes across the ECS, RDS, ElastiCache, and SQS resources. Option C is not appropriate because storing credentials in a version-controlled file exposes secrets in source control history and provides no rotation or access auditing.

Option D is not appropriate because manual review is error-prone, does not scale across environments, and provides no automated audit trail or enforcement. Option E is not appropriate because granting developers direct S3 access to upload configuration files bypasses least-privilege controls and lacks the auditing and secret-management capabilities required for secure configuration management.

Exam trap

DOP-C02 often tests whether candidates confuse 'auditable' with 'manual' — the trap is selecting manual review or version-controlled config files because they sound like governance, when the exam expects automated, least-privilege, auditable AWS-native services.

137
MCQhard

A company uses AWS CloudFormation to manage infrastructure. They have a template that creates an Amazon RDS DB instance. The template includes a 'DeletionPolicy' attribute set to 'Retain' on the DB instance resource. The DevOps team deletes the stack. Later, they notice that the DB instance still exists and is incurring costs. What is the MOST cost-effective way to remove the DB instance?

A.Create a new CloudFormation stack that includes the same DB instance but with a DeletionPolicy of 'Delete', then delete that stack.
B.Manually delete the DB instance using the AWS Management Console or AWS CLI.
C.Use the 'aws cloudformation delete-change-set' command to remove the resource.
D.Update the stack: change the DeletionPolicy to 'Delete' and then delete the stack again.
AnswerB

Because the original stack was deleted with a DeletionPolicy that did not delete the DB instance, the database was left as an unmanaged, orphaned resource outside CloudFormation. Manually deleting it through the AWS Management Console or with the aws rds delete-db-instance CLI command is the simplest and most cost-effective way to remove it, since no stack resources or templates remain to account for.

Why this answer

The DB instance was created with a DeletionPolicy of 'Retain', which explicitly instructs CloudFormation to preserve the resource when the stack is deleted. Once the stack is deleted, CloudFormation no longer manages the DB instance, so the only way to remove it and stop costs is to manually delete it via the AWS Management Console or AWS CLI. This is the most cost-effective approach as it directly addresses the orphaned resource without unnecessary overhead.

Exam trap

The trap here is that candidates assume CloudFormation can still manage or modify a resource after the stack is deleted, but once the stack is gone, CloudFormation has no control, and the only way to remove the resource is through direct manual deletion.

How to eliminate wrong answers

Option A is wrong because creating a new stack with the same DB instance is not possible—the DB instance already exists and has a unique identifier; CloudFormation would fail to create a duplicate resource, and even if it could, this approach adds complexity and cost without benefit. Option C is wrong because 'aws cloudformation delete-change-set' is used to delete a change set (a list of proposed changes to a stack), not to delete resources; it has no effect on existing resources like a DB instance. Option D is wrong because the stack has already been deleted, so there is no existing stack to update or delete again; CloudFormation cannot modify or delete resources it no longer manages.

138
MCQeasy

A company uses AWS CodeBuild to compile and test code. The buildspec.yml file includes commands that require access to a private S3 bucket. The DevOps engineer wants to securely provide AWS credentials to the build project. What is the recommended approach?

A.Use a service role for CodeBuild with appropriate permissions
B.Store the AWS access key ID and secret access key in the buildspec.yml file
C.Use an EC2 instance profile attached to the build environment
D.Pass the credentials as environment variables in the build project configuration
AnswerA

Using a service role for CodeBuild is the secure approach because CodeBuild assumes the role via the `codebuild.amazonaws.com` service principal to obtain temporary credentials for API calls such as pulling source from S3 or publishing artifacts. The role is configured with an IAM trust policy and a permissions policy that grants only the needed actions, adhering to least privilege. Temporary session credentials are automatically rotated and never written to disk, logs, or build scripts.

Why this answer

The recommended approach is to use a service role for CodeBuild with appropriate permissions. CodeBuild can assume an IAM role that grants the build project access to the private S3 bucket, eliminating the need to manage long-term credentials. This follows AWS best practices for secure credential management by using temporary, automatically rotated credentials via the AWS Security Token Service (STS).

Exam trap

The trap here is that candidates may confuse CodeBuild with EC2-based build environments and incorrectly assume an instance profile can be used, or they may think environment variables are a secure way to pass credentials, overlooking that the values must still be stored in the project configuration.

How to eliminate wrong answers

Option B is wrong because storing AWS access key ID and secret access key in the buildspec.yml file exposes long-term credentials in plaintext, which violates security best practices and risks credential leakage in version control. Option C is wrong because CodeBuild does not run on EC2 instances; it uses a managed, ephemeral build environment, so an EC2 instance profile cannot be attached to it. Option D is wrong because passing credentials as environment variables in the build project configuration still requires storing the secret values in the project, which is insecure and not recommended; instead, CodeBuild should assume a service role to obtain temporary credentials.

139
MCQhard

A company uses AWS CodePipeline to deploy a static website to an S3 bucket. The pipeline has a Source stage (GitHub), a Build stage (CodeBuild), and a Deploy stage (CodeDeploy). The deployment fails intermittently with the error: 'Bucket does not allow ACLs'. The S3 bucket is configured to use the 'bucket-owner-enforced' setting for Object Ownership. The team wants to resolve the failure while maintaining security best practices. What should the team do?

A.Update the CodeDeploy deployment action to use a bucket policy and disable ACLs.
B.Make the S3 bucket publicly accessible to allow CodeDeploy to write objects.
C.Add a step in CodeBuild to copy the artifacts to the S3 bucket using the AWS CLI.
D.Change the Object Ownership setting to 'ObjectWriter' to enable ACLs.
AnswerA

The CodePipeline S3 deployment action assumes an IAM role and, when ACLs are enabled, attempts to set a canned ACL on each object it uploads. If the bucket denies ACL operations because Object Ownership is set to BucketOwnerEnforced, deployment fails; disabling ACLs in the action and granting the deployment role permissions (s3:PutObject, s3:PutObjectAcl) via a bucket policy provides a robust, secure authorization model. This is the AWS-recommended approach because bucket policies are centrally managed and do not rely on per-object ACLs.

Why this answer

The error occurs because the S3 bucket uses the 'bucket-owner-enforced' Object Ownership setting, which disables ACLs. AWS CodeDeploy's default deployment action attempts to set ACLs on deployed objects, causing the failure. The correct solution is option A: configure the CodeDeploy deployment action to use a bucket policy instead of ACLs.

This resolves the error while maintaining security best practices by keeping ACLs disabled. Option B (making the bucket public) is insecure. Option C (adding a CodeBuild step) does not address the root cause.

Option D (changing Object Ownership to 'ObjectWriter') re-enables ACLs but is not recommended as it weakens ownership control and does not follow current best practices.

140
Multi-Selecteasy

Which TWO are benefits of using AWS CloudFormation for infrastructure as code? (Select TWO.)

Select 2 answers
A.Manages both AWS and on-premises resources.
B.Enables declarative infrastructure definition.
C.Automates resource provisioning and reduces manual error.
D.Provides a graphical interface for designing infrastructure.
E.Automatically optimizes resource costs.
AnswersB, C

CloudFormation lets users describe the desired end state of their infrastructure in a JSON or YAML template, and the service determines the exact provisioning sequence and dependency resolution. This declarative approach contrasts sharply with imperative scripting, where you specify step-by-step commands and ordering. As a result, templates become portable, reusable, and enable consistent environment replication, which is one of the core benefits of the service.

Why this answer

AWS CloudFormation uses a declarative approach to infrastructure as code, where you define the desired end state of your resources in a template (JSON or YAML), and CloudFormation handles the provisioning and configuration to achieve that state. This contrasts with imperative scripting, where you must specify every step. Declarative definitions reduce complexity and improve reliability by letting the service manage the orchestration.

Exam trap

The trap here is that candidates often confuse declarative infrastructure as code (CloudFormation) with imperative scripting (like AWS CLI scripts) or assume CloudFormation includes cost optimization features, when in fact it only provisions what you define without any cost analysis or optimization logic.

141
MCQeasy

A company uses AWS OpsWorks for configuration management of its EC2 instances. The DevOps team wants to apply a new security patch to all instances in a specific layer. What is the most efficient way to accomplish this?

A.Create a new OpsWorks stack with the patch and migrate instances to it.
B.SSH into each instance and run the patch command manually.
C.Update the layer's custom Chef recipe to include the patch and trigger a lifecycle event to execute the recipe on all instances.
D.Use AWS Systems Manager Run Command to run a patch command on each instance individually.
AnswerC

Updating the layer's custom Chef recipe to include the patch and triggering a lifecycle event is the correct, integrated approach. OpsWorks executes Chef recipes at well-defined lifecycle events (setup, configure, deploy, etc.), so attaching the patch logic to a recipe and invoking the event ensures consistent, automated application. This leverages the existing configuration management system, maintains versioned recipe code, and can be applied fleet-wide without manual intervention.

Why this answer

OpsWorks uses Chef to manage configuration, and updating the layer's custom Chef recipe to include the security patch allows you to trigger a lifecycle event (e.g., 'Setup' or 'Configure') that runs the recipe on all instances in that layer simultaneously. This approach is efficient, automated, and leverages OpsWorks' built-in configuration management without manual intervention or stack migration.

Exam trap

The trap here is that candidates may choose Option D (Systems Manager Run Command) because it is a valid patching tool, but they overlook that OpsWorks provides a more integrated and efficient layer-wide mechanism via Chef recipes and lifecycle events, which is the intended pattern for configuration management within OpsWorks.

How to eliminate wrong answers

Option A is wrong because creating a new OpsWorks stack and migrating instances is unnecessarily complex and disruptive; it does not leverage the existing layer's lifecycle events and would require re-associating instances, which is inefficient for a simple patch update. Option B is wrong because SSHing into each instance and manually running the patch command is not scalable, error-prone, and violates the principle of automated configuration management that OpsWorks is designed to provide. Option D is wrong because while AWS Systems Manager Run Command can patch instances, it treats each instance individually and does not integrate with OpsWorks layer-level lifecycle events; it would require separate targeting and lacks the Chef recipe-driven consistency that OpsWorks offers for layer-wide updates.

142
Multi-Selecthard

A DevOps team is designing a CI/CD pipeline for a microservices application using AWS CodePipeline. They want to incorporate infrastructure as code (IaC) using AWS CloudFormation. Which three practices should they follow to ensure reliable and repeatable deployments? (Choose THREE.)

Select 3 answers
A.Use the same CloudFormation template across all environments, with parameterization for environment-specific values.
B.Implement rollback triggers to automatically roll back failed stack updates.
C.Create a single monolithic template for all microservices to simplify management.
D.Skip change sets during stack updates to speed up the pipeline.
E.Use CloudFormation stack sets to deploy stacks across multiple accounts and regions consistently.
AnswersA, B, E

Parameterizing a single CloudFormation template enables a consistent infrastructure definition across dev, test, and prod, with environment-specific variables (e.g., instance types, VPC IDs, AMI IDs) passed via Parameters and Mappings. This avoids template drift and duplication, ensuring the same resource logic is tested and promoted. It also simplifies change management because a single template revision can be reused for multiple environments.

Why this answer

Using a single CloudFormation template across all environments with parameterization ensures consistency and reduces drift. Environment-specific values (e.g., instance sizes, subnet IDs) are passed as parameters, so the same template logic applies to dev, test, and prod, making deployments repeatable and auditable.

Exam trap

The trap here is that candidates might think monolithic templates simplify management (Option C) or that skipping change sets speeds up pipelines (Option D), but both compromise reliability and repeatability, which are core to IaC best practices in the DOP-C02 exam.

143
MCQeasy

A company uses AWS CodeCommit to store its infrastructure as code templates. The DevOps team wants to automatically validate CloudFormation templates before merging changes to the main branch. Which service should be used to implement this validation?

A.AWS CodeBuild
B.AWS CodeDeploy
C.AWS CodePipeline
D.AWS CodeStar
AnswerA

AWS CodeBuild is a fully managed continuous integration service that can execute arbitrary build and validation commands. In the context of CodeCommit, you can attach an approval rule to a pull request that invokes a CodeBuild project, so that the pull request is not mergable until the validation (e.g., running cfn-lint, terraform validate, or a shell script that checks CloudFormation templates) completes successfully and the build status is reported back to the pull request. This makes CodeBuild the correct service for automatically validating infrastructure-as-code changes as part of the pull request workflow.

Why this answer

AWS CodeBuild is the correct service because it can be configured as a pre-merge check in a pull request workflow. By integrating CodeBuild with CodeCommit, the DevOps team can automatically run a build project that validates CloudFormation templates (e.g., using `aws cloudformation validate-template` or `cfn-lint`) before the merge is allowed. This provides a serverless, automated validation step without requiring a full pipeline or deployment.

Exam trap

The trap here is that candidates often confuse CodePipeline's orchestration capabilities with the need for a simple pre-merge validation, overlooking that CodeBuild can be directly triggered by CodeCommit pull request events without a full pipeline.

How to eliminate wrong answers

Option B (AWS CodeDeploy) is wrong because CodeDeploy is designed for deploying application code to compute services (EC2, Lambda, ECS) and does not provide a mechanism to validate CloudFormation templates before merging. Option C (AWS CodePipeline) is wrong because CodePipeline orchestrates continuous delivery workflows but does not natively trigger on pull request events in CodeCommit; it requires manual setup with webhooks and is overkill for a simple pre-merge validation. Option D (AWS CodeStar) is wrong because CodeStar is a project management and collaboration dashboard that simplifies setting up CI/CD pipelines, but it does not itself perform template validation or enforce pre-merge checks.

144
MCQmedium

A DevOps engineer is designing a configuration management strategy for a fleet of EC2 instances running Amazon Linux 2. The instances must be bootstrapped with custom software and continuously managed to ensure desired state compliance. Which combination of services should the engineer use?

A.AWS CloudFormation for bootstrapping and Amazon CloudWatch Events to enforce desired state
B.AWS OpsWorks for Chef Automate for configuration management and AWS CodeDeploy for deployments
C.AWS Systems Manager State Manager for desired state configuration and AWS Systems Manager Run Command for initial bootstrapping
D.AWS Config for configuration management and Amazon CloudWatch Events for remediation
AnswerC

AWS Systems Manager State Manager uses associations to define and continuously enforce a desired configuration state, automatically reapplying or remediating drift for managed instances. AWS Systems Manager Run Command can execute one-time bootstrap scripts on instances via the SSM Agent, enabling initial setup like installing packages or joining domains. Because both services share the same agent and console, this combination provides a unified, serverless approach to bootstrap and ongoing configuration management.

Why this answer

AWS Systems Manager State Manager provides a policy-driven mechanism to define and maintain desired state configuration for EC2 instances, while AWS Systems Manager Run Command enables ad-hoc or initial bootstrapping by executing scripts or commands (e.g., installing custom software) without requiring SSH. Together, they cover both the initial setup and ongoing compliance enforcement for Amazon Linux 2 instances, aligning with the requirement for continuous management.

Exam trap

The trap here is that candidates often confuse AWS Config (a compliance auditing service) with a configuration management tool, or assume CloudWatch Events can enforce state, when in fact Systems Manager State Manager is the native AWS service for desired state configuration.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Events (now Amazon EventBridge) is an event bus service for routing events, not a tool for enforcing desired state; it cannot apply or remediate configuration drift on EC2 instances. Option B is wrong because AWS OpsWorks for Chef Automate is a managed Chef server, but it is not the recommended approach for Amazon Linux 2 instances that are better served by native AWS Systems Manager capabilities, and AWS CodeDeploy handles application deployments, not configuration management or desired state enforcement. Option D is wrong because AWS Config is a service for evaluating resource compliance against rules and recording configuration history, but it does not perform remediation actions itself; while it can trigger remediation via Systems Manager Automation, it is not a configuration management tool for bootstrapping or continuous desired state enforcement.

145
MCQmedium

A DevOps engineer attempted to create a CloudFormation stack and it failed. The engineer runs the 'describe-stack-events' command and sees the output above. What is the most likely cause of the failure?

A.The EC2 key pair 'myKeyPair' does not exist in the region where the stack is being created.
B.The AMI ID specified in the template is not available in the region.
C.The CloudFormation template has a syntax error in the EC2 instance definition.
D.The security group specified for the EC2 instance does not exist.
AnswerA

CloudFormation validates the `KeyName` property by calling the EC2 API in the stack's target region. If `myKeyPair` has not been created in that exact region, EC2 returns an `InvalidKeyName` error and stack creation fails before any resources are provisioned. Key pairs are region-scoped, so an existing key in another region does not satisfy this validation.

Why this answer

The 'describe-stack-events' output shows a 'CREATE_FAILED' event for the EC2 instance resource with the status reason indicating that the key pair 'myKeyPair' was not found. CloudFormation validates the existence of the specified EC2 key pair in the target region at creation time; if the key pair does not exist, the stack creation fails immediately. This is a common validation error when the key pair name is misspelled, belongs to a different region, or has not been created beforehand.

Exam trap

The trap here is that candidates may confuse a missing key pair with other common EC2 launch failures like AMI unavailability or security group issues, but the specific error message in the stack events directly points to the key pair name as the root cause.

How to eliminate wrong answers

Option B is wrong because if the AMI ID were not available in the region, CloudFormation would fail with a specific error message like 'AMI ID does not exist' or 'AMI not found', not a key pair error. Option C is wrong because a syntax error in the template would cause a validation error before any resource creation attempts, typically reported as 'Template validation error' or 'Template format error', not a resource-specific failure. Option D is wrong because a missing security group would produce an error referencing the security group ID or name, such as 'Security group does not exist', not a key pair error.

146
MCQmedium

A company uses AWS CodeCommit and CodePipeline. The pipeline triggers on commits to the main branch. The DevOps engineer wants to add a stage that runs unit tests in a build environment. After the tests pass, the pipeline should deploy to a staging environment. If the tests fail, the pipeline should stop and notify the team. Which AWS service should be used to implement this workflow?

A.AWS CodeBuild
B.AWS CodeStar
C.AWS Lambda
D.AWS CodeDeploy
AnswerA

AWS CodeBuild is the correct choice because it is a fully managed build and test service that integrates natively as a build action within CodePipeline. You can define unit tests in a buildspec file that execute during the build stage; if any test command returns a non-zero exit code, CodeBuild marks the action as failed, which immediately halts the pipeline and prevents the deployment stage from running. This makes CodeBuild the standard, purpose-built mechanism for implementing a test gate that can conditionally stop a pipeline. It also produces build artifacts and detailed logs, enabling seamless handoff to later deployment stages when tests pass.

Why this answer

AWS CodeBuild is the correct service because it can be integrated directly into a CodePipeline as a build action that runs unit tests in a managed build environment. When tests fail, CodeBuild can be configured to exit with a non-zero status, which causes CodePipeline to stop the execution and optionally trigger notifications via Amazon SNS or CloudWatch Events. This matches the requirement for a build stage that runs tests and conditionally proceeds or halts the pipeline.

Exam trap

The trap here is that candidates may confuse CodeBuild with CodeDeploy, thinking that deployment services also handle testing, or they may assume CodeStar is a build service when it is actually a project management layer that does not execute code.

How to eliminate wrong answers

Option B is wrong because AWS CodeStar is a project management and collaboration service that provides a unified dashboard for CI/CD, but it does not itself execute build or test commands; it orchestrates underlying services like CodeBuild and CodePipeline. Option C is wrong because AWS Lambda is a serverless compute service for running code in response to events, but it is not designed to run unit tests as a build stage within a CodePipeline; it lacks the built-in build environment, caching, and test reporting capabilities of CodeBuild. Option D is wrong because AWS CodeDeploy is a deployment service that automates application deployments to compute services like EC2 or Lambda, but it does not run unit tests or provide a build environment; it is used after tests pass to deploy to staging.

147
MCQeasy

A company is using AWS OpsWorks for configuration management of their application stack. The stack includes a PHP application layer and a MySQL database layer. The DevOps team wants to automate the deployment of a new PHP version across all instances in the PHP layer. The team has created a custom Chef recipe that updates PHP. They want to run this recipe on all instances in the PHP layer in a rolling update fashion to avoid downtime. Which OpsWorks feature should they use?

A.Use the OpsWorks 'Run Command' feature to execute the recipe on the PHP layer with rolling update settings.
B.Create a custom Chef cookbook and enable automatic updates in OpsWorks.
C.Add the recipe to the Setup lifecycle event for the PHP layer.
D.Modify the PHP layer's lifecycle configuration to include the recipe in the Configure event.
AnswerA

The 'Run Command' feature in AWS OpsWorks, also known as Execute Recipes, is designed to run Chef recipes on-demand against existing instances or layers without requiring a full lifecycle event. You can target the PHP layer and configure rolling update settings such as batch size and wait time between batches, minimizing downtime across the fleet. This is the correct choice because it directly addresses the need to apply a recipe to currently running PHP instances immediately, not at some future provisioning or event-triggered moment.

Why this answer

Option A is correct because AWS OpsWorks Stacks provides a 'Run Command' feature that lets you execute a specific Chef recipe on a chosen layer, and it supports rolling updates so instances are updated in batches rather than all at once. This is the designed mechanism for on-demand execution of a recipe across a layer without redeploying the entire stack. Rolling updates minimize downtime by updating instances in configurable batch sizes while keeping the rest of the layer serving traffic.

Exam trap

The trap is assuming that adding a recipe to a lifecycle event (Setup or Configure) will update running instances — lifecycle events only fire at specific instance lifecycle moments, not on demand, so they cannot perform a rolling update of an existing fleet.

How to eliminate wrong answers

Option B is wrong because 'automatic updates' in OpsWorks refers to updating the Chef agent/OS packages, not executing a custom recipe on demand; it does not provide rolling execution of a user recipe. Option C is wrong because the Setup lifecycle event runs only once when an instance is first booted, so adding the recipe there would not update already-running instances. Option D is wrong because the Configure event runs on every instance during setup and configuration changes, not as an on-demand rolling deployment mechanism, and it would not give the team control over batch size or timing.

148
MCQmedium

A team uses CloudFormation to deploy a multi-container Docker environment on Amazon ECS. They need to pass environment variables to the containers from Parameter Store. How should they reference these values in the CloudFormation template?

A.Using the 'Ref' function with the parameter name
B.Using the 'Fn::ParamStore' intrinsic function
C.Using 'Fn::GetAtt' on the Parameter Store resource
D.Using the 'resolve:ssm' dynamic reference
AnswerD

The correct method is to use a dynamic reference, which CloudFormation resolves during stack create or update operations. For SSM Parameter Store, you write {{resolve:ssm:parameter-name:version}} (or without a version) to inject the parameter's value directly into your template properties. This approach works for both plaintext and, with resolve:ssm-secure, SecureString parameters, enabling secure, service-managed retrieval without hardcoding secrets.

Why this answer

CloudFormation supports dynamic references using the 'resolve:ssm' prefix to retrieve values from AWS Systems Manager Parameter Store at stack creation or update time. This allows environment variables in an ECS task definition to be populated directly from Parameter Store without hardcoding secrets or using custom Lambda-backed custom resources.

Exam trap

The trap here is that candidates may confuse CloudFormation's 'Ref' function with the ability to fetch SSM parameter values, or invent a non-existent function like 'Fn::ParamStore', instead of recognizing the dedicated 'resolve:ssm' dynamic reference syntax.

How to eliminate wrong answers

Option A is wrong because the 'Ref' function returns the logical ID of a resource or the value of a parameter, not the actual value stored in Parameter Store; it cannot resolve SSM parameter values. Option B is wrong because 'Fn::ParamStore' is not a valid CloudFormation intrinsic function; AWS CloudFormation does not provide such a function. Option C is wrong because 'Fn::GetAtt' retrieves attributes from CloudFormation resources, and Parameter Store is not a CloudFormation resource type that can be referenced with 'GetAtt'; it requires a dynamic reference or a custom resource.

149
MCQeasy

A DevOps engineer needs to manage configuration files across a fleet of Amazon EC2 instances running Amazon Linux. The configuration files must be updated whenever they change in an S3 bucket. Which AWS service is most suitable for this task?

A.AWS OpsWorks for Chef Automate
B.AWS Systems Manager State Manager
C.AWS CloudFormation
D.AWS Config
AnswerB

AWS Systems Manager State Manager is the correct choice because it creates State Manager associations that run SSM documents on a schedule to enforce and update configuration files across your managed instances. You can specify the exact content and location of files using SSM documents like AWS-RunShellScript or AWS-ApplyAnsibleModules, and the association will ensure that state stays consistent, remediating drift automatically. It supports targeting by tags, integration with Parameter Store for values, and granular rate controls, making it a native, agent-based configuration management service.

Why this answer

AWS Systems Manager State Manager is the most suitable service because it provides a configuration management solution that can automatically apply and maintain the desired state of EC2 instances. It can be configured to run associations on a schedule or in response to events, such as changes to an S3 bucket, using an AWS Lambda trigger or EventBridge rule to invoke the association. This ensures that configuration files are updated whenever they change in the S3 bucket, without requiring manual intervention or a full configuration management platform.

Exam trap

The trap here is that candidates often confuse AWS Config (which only audits and records configuration changes) with Systems Manager State Manager (which actively enforces and applies desired configurations), leading them to select AWS Config as the answer.

How to eliminate wrong answers

Option A is wrong because AWS OpsWorks for Chef Automate is a managed Chef server that requires Chef cookbooks and a Chef client agent, which is overkill for simple file synchronization and does not natively integrate with S3 bucket events for automatic updates. Option C is wrong because AWS CloudFormation is an Infrastructure as Code (IaC) service used to provision and manage AWS resources, not to manage runtime configuration files on running instances; it would require custom resources or additional automation to react to S3 changes. Option D is wrong because AWS Config is a service for evaluating resource compliance against rules and recording configuration history, not for actively pushing or updating configuration files on EC2 instances.

150
MCQhard

A company uses AWS CodePipeline to automate deployments. The pipeline has a source stage (CodeCommit), a build stage (CodeBuild), and a deploy stage (CodeDeploy). The DevOps engineer notices that the pipeline fails intermittently during the deploy stage with the error: 'The deployment failed because the deployment group does not exist'. What is the most likely cause?

A.The deployment group was deleted or renamed after the pipeline was configured
B.The Auto Scaling group associated with the deployment group has insufficient capacity
C.The CodePipeline service role does not have permission to call CodeDeploy
D.The CodeDeploy application name in the pipeline is misspelled
AnswerA

When a pipeline's deploy action references a CodeDeploy deployment group, CodeDeploy resolves that group by name and deployment group ID at execution time. If the group was deleted or renamed after pipeline configuration, the deploy action fails with a DeploymentGroupDoesNotExist or similar error when CodeDeploy attempts the deployment. The pipeline configuration itself stores the name, not a live reference, so the failure occurs at run time, not when the pipeline is edited. This is the classic cause when the error explicitly indicates the deployment group cannot be found.

Why this answer

The intermittent 'deployment group does not exist' error indicates that the deployment group referenced in the CodePipeline deploy stage configuration is missing at the time of execution. This most commonly occurs when the deployment group has been deleted or renamed after the pipeline was initially configured, causing the pipeline to reference a non-existent resource. Since the error is intermittent, it suggests the deployment group may be deleted and recreated or renamed during certain operations, rather than a permanent misconfiguration.

Exam trap

The trap here is that candidates often assume permission or naming errors cause consistent failures, but the intermittent nature of the error points to a resource lifecycle issue—specifically, the deployment group being deleted or renamed after pipeline configuration.

How to eliminate wrong answers

Option B is wrong because insufficient Auto Scaling group capacity would cause a different error, such as 'InsufficientCapacityException' or 'InstanceLimitExceeded', not 'deployment group does not exist'. Option C is wrong because a missing permission for the CodePipeline service role to call CodeDeploy would result in an 'AccessDeniedException' error, not a 'deployment group does not exist' error. Option D is wrong because a misspelled CodeDeploy application name would cause a consistent failure every time the pipeline runs, not an intermittent error, and the error message would reference the application name, not the deployment group.

← PreviousPage 2 of 3 · 215 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Configuration Management and IaC questions.