Courseiva

CCNA Configuration Management and IaC Questions

65 of 215 questions · Page 3/3 · Configuration Management and IaC · Answers revealed

151
MCQmedium

An operations team manages a fleet of Amazon EC2 instances that require periodic software updates. They want to use AWS Systems Manager to apply patches automatically while ensuring that patches are tested before production deployment. Which approach meets these requirements?

A.Use AWS Systems Manager Automation to create a runbook that patches instances one by one.
B.Create a patch baseline and assign it to all instances; enable automatic approval for all patches.
C.Use AWS Systems Manager Run Command to manually run patch commands on test instances, then on production.
D.Use AWS Systems Manager Patch Manager with maintenance windows, and configure a patch baseline that approves patches after a test period.
AnswerD

Patch Manager automates the entire patching process by using a patch baseline to define which patches are approved, when they are approved (e.g., after a test period expressed in days), and how those rules are applied to tagged instance groups. Maintenance windows schedule when the patching runs on test and production fleets, ensuring production patches are installed only after the baseline's approval delay lets the test fleet validate them. This combination provides automation, a testing gate, and controlled rollout windows, which directly satisfies the requirement.

Why this answer

AWS Systems Manager Patch Manager, when combined with maintenance windows and a patch baseline configured with an approval delay after a test period, allows patches to be automatically applied to test instances first and then, after a defined waiting period, to production instances. This ensures patches are tested before production deployment without manual intervention, meeting the requirement for automated, staged patching.

Exam trap

The trap here is that candidates often confuse Run Command (a manual, ad-hoc tool) with Patch Manager (an automated, policy-driven service), or they assume that simply enabling automatic approval (Option B) is sufficient without considering the need for a testing delay.

How to eliminate wrong answers

Option A is wrong because using Automation to patch instances one by one does not inherently provide a test-before-production staging mechanism; it simply serializes patching without a defined approval delay. Option B is wrong because enabling automatic approval for all patches bypasses any testing period, applying patches to all instances immediately without validation. Option C is wrong because Run Command is a manual execution tool, not an automated solution, and it does not enforce a test period before production deployment.

152
MCQmedium

A DevOps team uses AWS OpsWorks for configuration management. They have a stack with a custom cookbook that installs and configures an application. After updating the cookbook on GitHub, they need to apply the changes to existing instances without creating new ones. What should the team do?

A.Clone the stack and assign the updated cookbook to the new stack.
B.Use the 'Execute Recipes' feature to run the updated custom recipe on the instances.
C.Update the layer's custom cookbook settings and then reboot the instances.
D.Update the stack's custom cookbook source and click 'Update Dependencies' on the stack.
AnswerB

The Execute Recipes feature in AWS OpsWorks Stacks allows you to run a specified recipe on selected instances immediately. This initiates an ad-hoc Chef run that pulls the latest cookbook from your configured source and executes the recipe's logic, directly applying the changes to the existing instances. It is the intended mechanism for manually applying cookbook updates without recreating or redeploying instances.

Why this answer

AWS OpsWorks provides the 'Execute Recipes' feature, which allows you to run a specific recipe from a cookbook on existing instances without requiring a stack update or instance replacement. This is the direct method to apply changes from an updated custom cookbook to running instances, as it triggers Chef to execute the specified recipe immediately on the selected instances.

Exam trap

The trap here is that candidates often confuse updating the cookbook source (which only stages the new code) with actually executing the recipes, leading them to choose Option D, which does not apply the changes to running instances.

How to eliminate wrong answers

Option A is wrong because cloning the stack creates a new set of instances, which does not apply changes to the existing instances and introduces unnecessary overhead. Option C is wrong because updating the layer's custom cookbook settings only changes the source for future instance provisioning or updates, and rebooting instances does not automatically run the updated recipes; it merely restarts the OS without executing Chef. Option D is wrong because updating the stack's custom cookbook source and clicking 'Update Dependencies' only refreshes the cookbook cache on the instances but does not automatically execute the updated recipes; a separate 'Execute Recipes' action is required to apply the changes.

153
MCQmedium

A DevOps engineer is creating a CloudFormation template that includes an AWS Lambda function. The function code is stored in an S3 bucket. The engineer wants to ensure that the Lambda function is updated whenever the code in S3 changes. What should the engineer do?

A.Use AWS CodeDeploy to deploy the Lambda function
B.Reference the S3 object version in the Lambda function's Code property to force an update when the version changes
C.Add a DependsOn clause to the Lambda function resource
D.Use AWS CodePipeline to automatically update the stack when the S3 object changes
AnswerB

In a CloudFormation template, the Lambda function's Code property, when referencing an S3 bucket, can include the S3ObjectVersion attribute. Because CloudFormation treats any template property change as a stack update trigger, explicitly specifying the object version creates a new template value whenever the zip file in S3 is modified. Without this version, CloudFormation compares only the bucket and key, both of which stay constant, so it considers the resource unrmodified and skips the Lambda update—even if the S3 object's contents were replaced. Adding the S3ObjectVersion forces a resource replacement or update, making it the simplest and most direct way to ensure the stack updates on code changes.

Why this answer

Referencing the S3 object version in the Lambda function's Code property (e.g., `S3ObjectVersion`) creates a dependency on that specific version. When the S3 object is updated, its version changes, which triggers CloudFormation to detect a change in the template and update the Lambda function during the next stack update. This ensures the function code is refreshed without manual intervention.

Exam trap

The trap here is that candidates assume any automation tool (CodePipeline or CodeDeploy) can replace the need for explicit version tracking, but CloudFormation requires a property change to trigger an update, and only referencing the S3 object version achieves that directly.

How to eliminate wrong answers

Option A is wrong because AWS CodeDeploy is a deployment service for managing traffic shifting and rollbacks, not a mechanism to detect S3 object changes and trigger CloudFormation updates. Option C is wrong because a DependsOn clause only controls resource creation order, not update triggers based on S3 object version changes. Option D is wrong because AWS CodePipeline can automate stack updates, but it requires an external trigger (e.g., S3 event notification or webhook) and does not inherently detect S3 object version changes to update the Lambda function directly.

154
MCQeasy

A DevOps engineer needs to manage the configuration of a large number of EC2 instances that are part of a cluster. The instances should have consistent software packages, services, and settings. The engineer wants to use a configuration management tool that integrates with AWS and supports a push-based model. Which service should be used?

A.AWS OpsWorks Stacks
B.AWS CodeCommit
C.AWS Systems Manager Run Command
D.AWS CloudFormation
AnswerC

AWS Systems Manager Run Command is a capability of AWS Systems Manager that lets you securely push commands to managed EC2 instances and on-premises machines without requiring SSH, RDP, or bastion hosts. The SSM Agent polls for commands, executes them, and can report status back, enabling admins to run scripts, install software, or change system settings across a fleet. Features such as tag-based targets, rate controls, and integration with IAM make it specifically designed for this kind of on-demand configuration activity.

Why this answer

AWS Systems Manager Run Command is the correct choice because it provides a push-based configuration management model that allows you to remotely and securely execute commands or scripts across a large fleet of EC2 instances without needing SSH access. It integrates natively with AWS, supports consistent software package installation and service management via SSM documents, and is ideal for maintaining configuration consistency in a cluster.

Exam trap

The trap here is that candidates confuse 'push-based' with agentless models or assume OpsWorks (which uses Chef/Chef push) is push-based, but OpsWorks Stacks primarily relies on pull-based Chef agents, whereas Systems Manager Run Command is the true push-based service for ad-hoc or scheduled configuration tasks.

How to eliminate wrong answers

Option A is wrong because AWS OpsWorks Stacks uses a pull-based model (Chef or Puppet agents on instances pull configuration from a central server) rather than a push-based model. Option B is wrong because AWS CodeCommit is a source control service for storing code and configuration files, not a configuration management tool for applying settings to EC2 instances. Option D is wrong because AWS CloudFormation is an Infrastructure as Code (IaC) service for provisioning and managing AWS resources declaratively, not for performing ongoing configuration management or push-based command execution on running instances.

155
MCQeasy

A company uses AWS CloudFormation to manage its infrastructure. The DevOps team needs to deploy a stack that includes a Lambda function and an S3 bucket. The Lambda function's code is stored in the S3 bucket. How can the team ensure that the Lambda function is created after the S3 bucket and the code is uploaded?

A.Upload the code to the S3 bucket before creating the stack.
B.Use the Fn::GetAtt intrinsic function to retrieve the bucket name.
C.Define the S3 bucket resource before the Lambda function resource in the template.
D.Use the DependsOn attribute on the Lambda function to depend on the S3 bucket.
AnswerD

The DependsOn attribute explicitly declares a dependency edge from the Lambda function back to the S3 bucket, forcing CloudFormation to wait until the bucket resource has reached CREATE_COMPLETE before it starts provisioning the Lambda function. This is the definitive way to guarantee creation order, especially when the function needs the bucket to exist for side effects such as populating an environment variable, writing to the bucket, or associating permissions, and no implicit dependency exists in the template. Unlike implicit references, DependsOn works even if the bucket is not directly referenced in any property of the Lambda function, making it the correct answer.

Why this answer

The DependsOn attribute explicitly instructs CloudFormation to create the S3 bucket before the Lambda function. Even though CloudFormation automatically determines resource dependencies for certain intrinsic functions, it does not infer dependencies based on code uploads. Using DependsOn ensures the bucket exists and the code is uploaded before the Lambda function is created, preventing a deployment failure when the Lambda references code that is not yet available.

Exam trap

The trap here is that candidates assume CloudFormation automatically orders resources based on template order or implicit references like Fn::GetAtt, but it does not infer dependencies from code uploads or resource definition order, so explicit DependsOn is required for non-attribute-based dependencies.

How to eliminate wrong answers

Option A is wrong because it requires manual intervention outside of the CloudFormation stack, breaking the principle of infrastructure as code and making the deployment non-repeatable and error-prone. Option B is wrong because Fn::GetAtt retrieves an attribute of a resource (e.g., the bucket ARN) but does not create a dependency that ensures the bucket is fully created and the code is uploaded before the Lambda function is created. Option C is wrong because the order of resource definitions in the template does not guarantee creation order; CloudFormation may create resources in parallel or in a different order unless explicit dependencies are defined.

156
MCQmedium

A company uses AWS CodePipeline with a multi-branch strategy. The pipeline deploys a Lambda function using CloudFormation. The DevOps engineer notices that when a new branch is created, the pipeline executes but the CloudFormation stack fails because the stack name already exists. What is the MOST efficient way to resolve this issue?

A.Modify the pipeline to use a dynamic stack name parameter, such as the branch name.
B.Hardcode a different stack name for each branch in the pipeline.
C.Delete the existing stack before each deployment.
D.Use the CloudFormation 'Override' parameter to reuse the same stack.
AnswerA

Using a dynamic stack name parameter, such as inserting the branch name into the stack name (e.g., `MyApp-${Branch}`), lets each branch deploy to a unique CloudFormation stack. This isolation prevents resource name collisions when multiple branches are deployed concurrently, supports per-branch rollback and lifecycle management, and eliminates the need to manually reconfigure the pipeline when a new branch is created.

Why this answer

Using a dynamic stack name parameter, such as the branch name, ensures each branch creates a unique CloudFormation stack. This avoids naming conflicts while allowing independent infrastructure per branch. In CodePipeline, you can pass the branch name as a variable (e.g., #{SourceVariables.BranchName}) to the CloudFormation deploy action, making the stack name unique without manual intervention.

Exam trap

The trap here is that candidates may think hardcoding stack names per branch (Option B) is acceptable, but they overlook the operational overhead and lack of automation; AWS expects you to use dynamic parameters to handle multi-branch pipelines efficiently.

How to eliminate wrong answers

Option B is wrong because hardcoding a different stack name for each branch is not scalable or maintainable; it requires manual updates every time a new branch is created, defeating the purpose of a multi-branch pipeline. Option C is wrong because deleting the existing stack before each deployment would destroy the production or main branch stack, causing downtime and loss of stateful resources; it also violates the principle of isolated environments per branch. Option D is wrong because CloudFormation does not have an 'Override' parameter to reuse the same stack; the stack name must be unique within an account and region, and reusing it would still cause a conflict if the stack already exists.

157
MCQeasy

A DevOps engineer is designing a CI/CD pipeline for a microservices application. The team wants to ensure that infrastructure changes are reviewed and approved before deployment. The code is stored in AWS CodeCommit, and the pipeline uses AWS CodePipeline and AWS CloudFormation. What is the BEST way to implement an approval process for infrastructure changes?

A.Use CodeCommit approval rules to require a pull request before any change is merged.
B.Configure IAM policies to require MFA before any CloudFormation stack update.
C.Use CodeBuild to run a script that sends an approval request via Amazon SNS and waits for a response.
D.Add a manual approval step in CodePipeline between the build and deploy stages.
AnswerD

A manual approval action in CodePipeline is a first-class, natively integrated gate that pauses the pipeline execution at a defined stage boundary (e.g., after build, before deploy). When the action runs, CodePipeline sends an SNS notification to the designated approver topic, and the execution remains in a Waiting state until an authorized user explicitly approves or rejects it via the console, CLI, or SDK. This is the intended AWS pattern for a human review gate because it is fully managed, has no custom polling logic, and automatically resumes the pipeline only upon approval — making it superior to any ad-hoc script or external approval mechanism.

Why this answer

A manual approval step in CodePipeline is the native, purpose-built mechanism for gating a pipeline stage on human review. CodePipeline pauses execution and sends an SNS notification to designated approvers; the pipeline resumes only after an approver acts in the console or via the API. This directly satisfies the requirement that infrastructure changes be reviewed and approved before CloudFormation deploys them, and it integrates cleanly with the existing CodeCommit/CodePipeline/CloudFormation toolchain.

Exam trap

DOP-C02 often tests the distinction between repository-level controls (CodeCommit approval rules, pull requests) and pipeline-level controls (manual approval actions), so candidates who conflate 'code review' with 'deployment approval' pick Option A.

How to eliminate wrong answers

Option A is wrong because CodeCommit approval rules govern pull-request merges in the repository, not the deployment of already-merged CloudFormation changes — a change can be approved and merged yet still be deployed without any pipeline-level gate. Option B is wrong because IAM MFA conditions authenticate the caller performing a stack update; they enforce identity strength, not a review-and-approve workflow, and cannot pause a pipeline for a human decision. Option C is wrong because a CodeBuild script that polls SNS for a response is a custom, brittle reimplementation of a feature CodePipeline already provides natively, adding complexity and failure modes without benefit.

158
MCQmedium

A DevOps engineer deploys the CloudFormation snippet shown in the exhibit. After the stack is deleted, the engineer checks for the S3 bucket. Which statement best describes the outcome?

A.The bucket is deleted because the stack deletion overrides the DeletionPolicy.
B.The bucket is retained (not deleted) after the stack deletion.
C.The stack deletion fails because the bucket has versioning enabled.
D.The bucket is deleted along with the stack because the DeletionPolicy is not supported for S3 buckets.
AnswerB

When a CloudFormation stack that contains an AWS::S3::Bucket with DeletionPolicy: Retain is deleted, the template's deletion intent is to leave that bucket in place. The bucket, including any objects and versions, remains in your AWS account and is no longer under CloudFormation's management. The stack itself shows DELETE_COMPLETE because CloudFormation treats the Retain policy as a successful completion of the resource deletion step, even though no physical deletion occurred.

Why this answer

S3 bucket versioning has no bearing on this stack's deletion mechanics since the bucket uses DeletionPolicy: Retain, so CloudFormation never attempts to delete the physical bucket. More generally, versioning is a bucket-level data-protection feature; it does not, by itself, cause a CloudFormation stack deletion to fail. However, note that CloudFormation does NOT automatically empty a bucket's object versions and delete markers before deleting it -- if DeletionPolicy were Delete (the default) and the bucket were non-empty (including having any object versions), the stack deletion would fail with a 'bucket not empty' error, requiring a custom resource or manual emptying first.

Because this stack uses Retain, the deletion action is never attempted, so the bucket -- and any versioned objects in it -- persists after the stack is deleted.

Exam trap

The trap here is that candidates assume stack deletion always removes all resources, overlooking that the DeletionPolicy attribute can explicitly override that behavior for supported resource types like S3 buckets.

How to eliminate wrong answers

Option A is wrong because the DeletionPolicy does not get overridden by stack deletion; instead, it is honored to retain the resource. Option C is wrong because enabling versioning on an S3 bucket does not prevent stack deletion or cause it to fail; the DeletionPolicy is the sole factor controlling retention. Option D is wrong because the DeletionPolicy is fully supported for S3 buckets; it is a valid attribute that CloudFormation respects for S3 resources.

159
MCQeasy

A DevOps team is using AWS CloudFormation to manage infrastructure. They need to ensure that stack updates are reviewed and approved by a senior engineer before being executed. Which feature should they implement?

A.Stack policies
B.Drift detection
C.Change sets
D.Stack sets
AnswerC

Change sets provide an itemized, read-only prediction of the exact modifications CloudFormation will apply to a stack when an updated template or parameter set is executed, listing each resource as being added, removed, or replaced without actually altering the stack. They are generated by calling CreateChangeSet, allowing the team to inspect the impact in a CI/CD pipeline and then explicitly execute the change set only after human approval. This makes change sets the correct mechanism for implementing a controlled pre-update review and approval workflow.

Why this answer

Change sets allow you to preview the proposed changes to a CloudFormation stack before executing them. This enables a senior engineer to review and approve the changes, ensuring that only validated updates are applied. Without change sets, updates would be applied immediately without a review step.

Exam trap

The trap here is that candidates may confuse change sets with stack policies, assuming both control updates, but stack policies only protect specific resources from modification, not the update approval process itself.

How to eliminate wrong answers

Option A is wrong because stack policies are used to prevent specific stack resources from being updated or deleted during a stack update, not to enforce a review-and-approval workflow. Option B is wrong because drift detection identifies whether a stack's actual resources have diverged from the template, but it does not control or review update execution. Option D is wrong because stack sets allow you to deploy stacks across multiple accounts and regions, but they do not provide a mechanism for reviewing and approving individual stack updates.

160
Multi-Selecthard

Which THREE actions should a DevOps engineer take to ensure that AWS CloudFormation stacks are securely managed? (Choose three.)

Select 3 answers
A.Set a DeletionPolicy on the stack to retain resources when the stack is deleted.
B.Use a service role with least privilege when creating the stack.
C.Use IAM policies to restrict CloudFormation actions to specific users and roles.
D.Define a StackSetPolicy to control permissions across accounts.
E.Apply a stack policy to prevent updates to sensitive resources during stack updates.
AnswersB, C, E

A service role is an IAM role that CloudFormation assumes to make API calls on your behalf when creating, updating, or deleting stacks. By specifying a service role with least privilege, you ensure CloudFormation only has the permissions required to provision the intended resources, limiting the impact if a resource definition is malicious or misconfigured. This also enables separation of duties because users can create stacks without holding direct resource permissions, and all actions are attributed to the service role.

Why this answer

Using a service role with least privilege ensures that CloudFormation operates with only the permissions necessary to create, update, and delete resources, rather than inheriting the user's broader permissions. This decouples the user's IAM permissions from the stack's runtime actions, reducing the risk of privilege escalation and unintended resource modifications.

Exam trap

The trap here is that candidates confuse DeletionPolicy (a resource retention setting) with a security control, or they invent a 'StackSetPolicy' option that sounds plausible but does not exist in AWS, leading them to select incorrect answers that seem security-related but are technically invalid.

161
MCQhard

A company uses CloudFormation to manage infrastructure. They have a nested stack that creates an Amazon RDS instance. When updating the parent stack, the RDS instance is unexpectedly replaced even though no changes were made to its properties. The engineer suspects a 'Drift' detection issue. What is the most likely reason for the replacement?

A.The RDS instance has drifted from the template definition.
B.The deletion policy is set to 'Retain'.
C.The logical ID of the RDS resource was changed in the nested stack template.
D.The stack policy prevents updates to the RDS instance.
AnswerC

CloudFormation identifies resources by logical ID; changing it makes the template treat the RDS instance as a new resource, so the old one is deleted and a replacement created. This replacement occurs regardless of unchanged properties, matching the stem's unexpected replacement with no property edits.

Why this answer

CloudFormation identifies resources by their logical ID within the template. When the logical ID of the RDS resource in the nested stack template is changed, CloudFormation treats it as a brand-new resource — it creates the new RDS instance and deletes the old one, resulting in an unexpected replacement even though the resource properties themselves are unchanged.

Exam trap

The trap here is conflating 'drift' with 'replacement' — candidates assume any unexpected change is drift, but drift detection is read-only and never causes a stack update to replace a resource; only template-level changes like a logical ID rename do.

How to eliminate wrong answers

Option A is wrong because drift detection only reports differences between actual resource state and the template; drift alone does not trigger a resource replacement during a stack update. Option B is wrong because a 'Retain' deletion policy only affects what happens to the resource when it is removed from the stack — it does not cause replacement during an update. Option D is wrong because a stack policy is an explicit deny/allow guard that would block the update entirely, not silently replace the resource.

162
MCQhard

A company uses AWS Elastic Beanstalk with a custom platform. They need to update the platform version to include a new security patch. Which approach should be used to create a new custom platform version?

A.Use the Elastic Beanstalk CLI to rebuild the platform with the new AMI.
B.Launch a new EC2 instance, apply the patch, and create an AMI, then update the platform version.
C.Modify the existing platform version's AMI ID using the Elastic Beanstalk console.
D.Create a new platform version using the aws elasticbeanstalk create-platform-version command with an updated platform definition file.
AnswerD

The correct procedure is to increment the version number in your platform definition file and then run the AWS CLI command `aws elasticbeanstalk create-platform-version`, which uploads the new packer template and associated configuration to build a fresh, immutable platform version. This new version can then be used as the `PlatformArn` in your environment's configuration, allowing the patched AMI to be deployed without affecting existing environments that reference the old version. This workflow is the documented way to apply changes to a custom platform.

Why this answer

AWS Elastic Beanstalk custom platforms are defined using a platform definition file (a YAML or JSON file that specifies the AMI, Chef recipes, and other configuration). To create a new platform version with an updated security patch, you must update this platform definition file (e.g., to reference a new base AMI with the patch) and then run the `aws elasticbeanstalk create-platform-version` CLI command. This command packages the definition file and uploads it to Elastic Beanstalk, which then builds and registers the new platform version.

The other options either bypass the custom platform framework or are not supported operations.

Exam trap

The trap here is that candidates assume they can directly modify an existing platform version or use manual EC2 operations, but Elastic Beanstalk custom platforms require a formal versioning process through the platform definition file and the `create-platform-version` API.

How to eliminate wrong answers

Option A is wrong because the Elastic Beanstalk CLI does not have a command to 'rebuild the platform with a new AMI'; the CLI is used for application management, not for modifying custom platform definitions. Option B is wrong because manually launching an EC2 instance, patching it, and creating an AMI does not integrate with Elastic Beanstalk's custom platform versioning system; you must use the platform definition file and the `create-platform-version` API to register a new version. Option C is wrong because the Elastic Beanstalk console does not allow you to modify the AMI ID of an existing platform version; platform versions are immutable once created.

163
Multi-Selectmedium

Which TWO actions should a DevOps engineer take to implement a GitFlow branching strategy for infrastructure as code using AWS CodeCommit and CodePipeline? (Choose two.)

Select 2 answers
A.Disable automatic triggers on the master branch to prevent accidental deployments.
B.Use CodeBuild to run unit tests on feature branches before merging.
C.Use a single pipeline that handles all branches.
D.Create separate pipelines for develop and master branches.
E.Configure CodePipeline to trigger on pull request creation.
AnswersB, D

Using CodeBuild to run unit tests on feature branches is correct because it provides fast, isolated feedback on each commit before the code is merged into develop. CodeBuild can be configured to respond to branch push or pull request webhooks, allowing tests to run without requiring a full CodePipeline execution. This validates code early in the development cycle, reducing the chance of integration problems and aligning with GitFlow's feature branch workflow.

Why this answer

Options B and D are correct. Option B: CodeBuild can run unit tests on feature branches before merging, ensuring code quality. Option D: Separate pipelines for develop and master branches allow different deployment behaviors (e.g., non-prod vs. prod).

Option A is wrong because disabling automatic triggers on the master branch would prevent automated deployments when changes are merged, which is contrary to GitFlow where master deployments are desired. Option C is wrong because a single pipeline for all branches reduces flexibility and can cause unintended deployments. Option E is wrong because CodePipeline does not natively support pull request triggers; use CodeBuild or other services for that.

164
MCQhard

A company uses AWS CloudFormation with a template that creates an Amazon RDS DB instance. The password for the master user is stored in AWS Secrets Manager. The CloudFormation stack creation fails with the error: 'Value of property MasterUserPassword must be of type String'. How should the DevOps engineer resolve this issue?

A.Use the Fn::ImportValue intrinsic function to import the secret value.
B.Use the Ref intrinsic function to reference the secret.
C.Use the dynamic reference '{{resolve:secretsmanager:MySecret:SecretString:password}}' in the CloudFormation template.
D.Use the Fn::GetAtt intrinsic function to retrieve the secret value from Secrets Manager.
AnswerC

This is the correct approach: a dynamic reference of the form {{resolve:secretsmanager:MySecret:SecretString:password}} instructs CloudFormation to call the GetSecretValue API during stack creation and extract the field named 'password' from the SecretString of 'MySecret'. The resolved value is then substituted directly into the supported resource property, and it never appears as a literal in the template or the saved stack template. This is the official mechanism for injecting Secrets Manager values into CloudFormation templates without using a custom resource.

Why this answer

CloudFormation supports dynamic references, which allow you to retrieve secret values from AWS Secrets Manager at stack creation time using the syntax `{{resolve:secretsmanager:secret-id:secret-string:json-key}}`. This resolves the password as a plaintext string directly in the template, satisfying the `MasterUserPassword` property's requirement for a String type. Other intrinsic functions like `Ref` or `Fn::GetAtt` return ARNs or metadata, not the secret value itself, and cannot be used directly for this purpose.

Exam trap

The trap here is that candidates often confuse intrinsic functions like `Ref` or `Fn::GetAtt` with the ability to retrieve secret values, not realizing that only dynamic references (the `{{resolve:...}}` syntax) can directly inject a secret string into a resource property that expects a plaintext value.

How to eliminate wrong answers

Option A is wrong because `Fn::ImportValue` is used to import exported cross-stack output values, not to retrieve secret values from Secrets Manager. Option B is wrong because `Ref` on an AWS::SecretsManager::Secret resource returns the secret ARN, not the secret string value, so it cannot provide the password as a string. Option D is wrong because `Fn::GetAtt` on a Secrets Manager secret returns attributes like the ARN or the generated password metadata, but not the plaintext secret value, and it does not resolve to a string that can be used directly in the `MasterUserPassword` property.

165
Multi-Selectmedium

A DevOps team is using AWS CodeBuild to run unit tests and package a Java application. They want to cache the Maven local repository (~/.m2) between builds to improve build times. Which TWO steps are necessary to enable caching in CodeBuild? (Select TWO.)

Select 2 answers
A.Set the MAVEN_OPTS environment variable to use a custom repository path.
B.Configure the buildspec to upload the Maven repository as a build artifact.
C.Enable 'Local cache' mode in the CodeBuild project.
D.Add a 'cache' section in the buildspec file specifying the paths to cache.
E.Create an S3 bucket to store the cache.
AnswersD, E

Adding a 'cache' section to the buildspec is the correct way to declare which paths CodeBuild should cache. You specify relative or absolute paths, such as /root/.m2, and CodeBuild saves the contents to a configurable S3 cache bucket after the build. On subsequent builds, CodeBuild restores those paths before the build starts, so dependency resolution skips re-downloading artifacts. This is the official mechanism for Maven dependency caching in CodeBuild.

Why this answer

To enable caching for the Maven local repository in AWS CodeBuild, two steps are required: (1) Add a `cache` section in the buildspec file specifying the paths to cache (e.g., ~/.m2) — this is option D. (2) Create an S3 bucket to store the cache and configure the CodeBuild project to use that bucket for caching — this is option E. Option A (setting MAVEN_OPTS) is not necessary because the default Maven repository path is already ~/.m2. Option B (uploading as a build artifact) is for saving output artifacts, not for caching.

Option C ('Local cache' mode) is a different feature used for Docker layer caching, not for Maven dependencies. Therefore, options D and E are correct.

166
MCQeasy

A company uses AWS OpsWorks for configuration management. The operations team needs to apply a configuration change to all instances in a layer without downtime. Which approach should they use?

A.Use a custom Chef recipe and run it on the layer using OpsWorks 'Run Command'.
B.Use an Auto Scaling lifecycle hook to apply the change during instance launch.
C.Clone the layer and update the clone with the new configuration, then switch traffic.
D.SSH into each instance and manually apply the change.
AnswerA

Use a custom Chef recipe and run it on the layer using OpsWorks 'Run Command' is correct because OpsWorks Stacks can execute a recipe on any currently online instance without waiting for a lifecycle event. This converges the specified layer's existing instances to the updated configuration immediately, and Chef's idempotent execution ensures only necessary changes are applied. You can target a single instance, a whole layer, or use custom Chef JSON to pass parameters.

Why this answer

The correct approach is to use a custom Chef recipe and run it on the layer using OpsWorks 'Run Command'. This allows applying configuration changes to all instances in the layer without downtime, as OpsWorks executes the recipe on each instance without requiring instance recreation. Option B is incorrect because Auto Scaling lifecycle hooks are used to execute actions during instance launch or termination, not for runtime configuration updates.

Option C is incorrect because cloning a layer creates a new layer and does not apply changes to existing instances; switching traffic would involve additional steps and potential downtime. Option D is incorrect because manually SSHing into each instance is error-prone, not scalable, and violates best practices for configuration management.

167
MCQmedium

A DevOps engineer is using AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment fails with the error: 'The overall deployment failed because too many individual instances failed deployment'. The engineer checks the logs and finds that the application installation script exits with a non-zero exit code. What should the engineer do to troubleshoot?

A.Configure CloudWatch Logs to capture the script output
B.Increase the deployment's MinHealthyHosts percentage
C.Re-upload the application revision to S3
D.SSH into one of the failed instances and run the install script manually to identify the error
AnswerD

SSHing into a failed instance and manually running the install script is the most direct way to diagnose the failure, because you can reproduce the exact command and see the script's stderr, exit code, missing dependencies, permission errors, or incorrect path assumptions. CodeDeploy lifecycle scripts run under the instance's configured user environment, so executing the same script from the deployment archive directory (for example, /opt/codedeploy-agent/deployment-root/<deployment-id>/.../deployment-archive) exposes the root cause and lets you test a fix locally. This is the standard first step in troubleshooting a failed lifecycle hook.

Why this answer

The deployment failure is caused by the application installation script exiting with a non-zero exit code, which indicates a specific error in the script or its environment. SSHing into a failed instance and running the install script manually allows the engineer to see the exact error output, debug the script logic, and identify missing dependencies or configuration issues directly on the target host.

Exam trap

The trap here is that candidates may assume increasing MinHealthyHosts or re-uploading the revision will fix the issue, when in fact the problem is a script-level error that requires direct investigation on a failed instance.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs can capture script output only if the script is configured to write to a log file and the CloudWatch agent is installed and configured on the instances; it does not retroactively capture the error from a failed deployment. Option B is wrong because increasing MinHealthyHosts percentage would raise the threshold for healthy instances, making the deployment more strict and likely to fail faster, not help troubleshoot the script error. Option C is wrong because re-uploading the application revision to S3 does not address the root cause of the script failure; the revision is already present on the instances, and the error is in the execution, not in the upload.

168
MCQmedium

An organization uses AWS Systems Manager to manage a fleet of EC2 instances. They want to ensure that all instances have a specific software package installed. Which approach should they take?

A.Use OpsCenter to create an OpsItem for each instance.
B.Use Run Command to execute the installation on all instances.
C.Create a Patch Baseline that includes the package.
D.Create a State Manager association with a custom document that installs the package.
AnswerD

State Manager associations continuously enforce a desired configuration on managed nodes, so the custom document's install command runs on any instance lacking the package and re-applies if it drifts. This satisfies the requirement that all instances maintain the specific software package without manual intervention.

Why this answer

AWS Systems Manager State Manager is designed to maintain a consistent configuration state on managed instances. By creating an association with a custom document that installs the required software package, State Manager will apply and re-apply the configuration on a schedule or on instance registration, ensuring the package remains installed.

Exam trap

DOP-C02 often tests the distinction between one-time execution (Run Command) and persistent state enforcement (State Manager), so candidates pick Run Command when the requirement is ongoing compliance.

How to eliminate wrong answers

Option A is wrong because OpsCenter is for aggregating and managing operational issues (OpsItems), not for enforcing software installation. Option B is wrong because Run Command executes a one-time command on instances — it does not maintain state or re-apply if the package is removed. Option C is wrong because Patch Baselines define approved patches for Patch Manager, not arbitrary software packages.

169
MCQmedium

A DevOps engineer is creating a CloudFormation template to deploy a VPC with public and private subnets. The template uses the 'AWS::EC2::VPC' resource and two 'AWS::EC2::Subnet' resources. The engineer wants to ensure that the subnets are created in different Availability Zones. What is the best approach?

A.Use Fn::GetAZs function with Fn::Select to pick different AZs from the region's AZ list.
B.Use the CidrBlock property to define different AZs.
C.Use Fn::GetAZs function with a count of 2 to automatically assign different AZs.
D.Hardcode the Availability Zone names in the template.
AnswerA

Fn::GetAZs returns a list of all Availability Zones available in the current region, and Fn::Select chooses an element via its zero-based index. By combining them, you can assign the first AZ to one subnet (Fn::Select [0, Fn::GetAZs ""]) and the second AZ to another (Fn::Select [1, Fn::GetAZs ""]), ensuring two distinct AZs without hardcoding region-specific names. This approach remains valid even as the region's AZ list changes and keeps the template portable across regions.

Why this answer

Fn::GetAZs returns a list of all Availability Zones in the region, and Fn::Select allows you to pick specific indices from that list, ensuring each subnet is assigned a different AZ. This approach is dynamic and region-agnostic, so the template works across regions without hardcoding AZ names. It also avoids the risk of using the same AZ for both subnets, which would violate the requirement for high availability.

Exam trap

The trap here is that candidates confuse the CidrBlock property with AZ assignment, or assume Fn::GetAZs can directly return multiple AZs without using Fn::Select, leading them to pick option B or C.

How to eliminate wrong answers

Option B is wrong because the CidrBlock property defines the IP address range for the subnet, not the Availability Zone; AZ assignment is controlled by the AvailabilityZone property. Option C is wrong because Fn::GetAZs does not accept a count parameter; it returns a list of all AZs, and you must use Fn::Select or Fn::Split to pick individual AZs. Option D is wrong because hardcoding AZ names makes the template region-specific and brittle; if the template is deployed in a region with different AZ names, it will fail, and it also prevents the template from adapting to regions with fewer AZs.

170
MCQeasy

A company wants to use AWS OpsWorks for configuration management of their EC2 instances. They need to ensure that the instances are automatically configured with the latest security patches upon boot. Which OpsWorks feature should they use?

A.Create a custom Chef recipe that installs security patches and assign it to the setup lifecycle event.
B.Configure the instances to run a user data script that updates packages.
C.Use AWS Systems Manager Patch Manager with an OpsWorks lifecycle event.
D.Use a CloudFormation template to apply patches during stack creation.
AnswerA

Custom Chef recipes are the native configuration-management mechanism in AWS OpsWorks. Assigning a recipe that invokes the platform package manager (e.g., `apt-get update` and `apt-get upgrade -y` or `yum update -y`) to the setup lifecycle event ensures it runs on every instance immediately after boot, before any application deployment. The setup event runs only once at instance launch, making it the correct hook for initial patch application, and OpsWorks propagates any recipe changes when instances are updated or started.

Why this answer

AWS OpsWorks uses Chef recipes to manage instance configuration. By creating a custom Chef recipe that installs the latest security patches and assigning it to the 'setup' lifecycle event, the recipe runs automatically on every new instance boot, ensuring patches are applied before the instance enters service. This is the native OpsWorks mechanism for configuration management during instance provisioning.

Exam trap

The trap here is that candidates may confuse OpsWorks's native Chef lifecycle events with external tools like Systems Manager or user data scripts, failing to recognize that OpsWorks is designed to use Chef recipes for configuration management, not external patch management services.

How to eliminate wrong answers

Option B is wrong because user data scripts run at boot but are not integrated with OpsWorks lifecycle events, so they cannot leverage OpsWorks's configuration management workflow or be managed centrally via Chef. Option C is wrong because AWS Systems Manager Patch Manager is a separate service that does not integrate directly with OpsWorks lifecycle events; OpsWorks does not have a built-in event hook for Patch Manager. Option D is wrong because CloudFormation templates are used for infrastructure provisioning, not for ongoing configuration management within OpsWorks; applying patches during stack creation does not ensure automatic patching on subsequent boots.

171
Multi-Selecthard

A company uses AWS CloudFormation to manage infrastructure. They have a stack that includes a VPC, subnets, and EC2 instances. They want to update the AMI ID of an EC2 instance without causing downtime. Which TWO approaches meet this requirement?

Select 2 answers
A.Use CloudFormation stack update with 'UpdatePolicy' set to 'AutoScalingRollingUpdate' and 'MinInstancesInService' set to 0.
B.Delete the stack and recreate it with the new AMI.
C.Use a CloudFormation update with a rolling update policy on the Auto Scaling group.
D.Create a custom resource backed by a Lambda function that updates the instance using AWS Systems Manager.
E.Deploy the instances across multiple Availability Zones and update each zone separately.
AnswersC, D

Configuring an UpdatePolicy with AutoScalingRollingUpdate on the AWS::AutoScaling::AutoScalingGroup resource is the native CloudFormation way to replace instances with a new AMI while maintaining availability. CloudFormation automatically batches instance replacements by terminating old instances and launching new ones that use the updated launch template or configuration, with MinInstancesInService and MaxBatchSize controlling how many instances remain available. This integrates cleanly with the stack update workflow and is the recommended pattern for AMI rollouts in CloudFormation-managed Auto Scaling groups.

Why this answer

Option C is correct because attaching an AutoScalingRollingUpdate policy to the Auto Scaling group resource lets CloudFormation replace instances in batches, keeping a configurable number of instances in service (MinInstancesInService) so the AMI change is applied without downtime. Option D is correct because a custom resource backed by a Lambda function can orchestrate an in-place or rolling update via AWS Systems Manager (for example, SSM Run Command or Automation), allowing the AMI to be changed while maintaining availability. Option A is not correct because setting MinInstancesInService to 0 allows all instances to be taken out of service simultaneously, which causes downtime.

Option B is not correct because deleting and recreating the stack destroys the existing resources, causing downtime and data loss. Option E is not correct because spreading instances across Availability Zones does not by itself update the AMI or guarantee zero-downtime replacement.

Exam trap

The trap here is that candidates often confuse the 'AutoScalingRollingUpdate' policy with a generic EC2 instance update, not realizing it only applies to Auto Scaling groups, and they may incorrectly assume that setting 'MinInstancesInService' to 0 is acceptable for zero-downtime updates.

172
MCQeasy

A developer is writing an AWS CloudFormation template to create an Amazon S3 bucket. The bucket name must be unique across all AWS accounts. Which property should the developer use to ensure the name is unique?

A.Use the DeletionPolicy attribute to retain the bucket.
B.Set the BucketName property to a unique value using a parameter.
C.Use the UpdateReplacePolicy attribute to control replacement.
D.Omit the BucketName property so CloudFormation generates a unique name.
AnswerD

When the BucketName property is omitted from an S3 bucket resource, CloudFormation automatically generates a globally unique name by combining the stack name with a random suffix (e.g., my-stack-s3bucket-1a2b3c4d5e6f). This generated name guarantees uniqueness across all AWS accounts and regions, because the random component virtually eliminates collision risk. CloudFormation then exposes this generated name through the Ref function and the resource's physical ID, allowing other resources to reference it without ever needing to know the exact value beforehand. This is the simplest and most reliable way to avoid bucket-name conflicts without manual input.

Why this answer

Omit the BucketName property so CloudFormation generates a unique name. Amazon S3 bucket names must be globally unique across all AWS accounts. If you specify a custom BucketName, you must ensure its uniqueness yourself, which is error-prone.

By omitting BucketName, CloudFormation automatically generates a unique name that includes a random suffix, guaranteeing global uniqueness. Option A (DeletionPolicy) controls what happens when the stack is deleted, not naming. Option B (setting BucketName to a unique value via parameter) still requires manual uniqueness and is not a property that ensures uniqueness automatically.

Option C (UpdateReplacePolicy) controls replacement behavior on updates, not naming. Therefore, omitting BucketName is the simplest way to ensure a unique name.

173
MCQeasy

A developer wants to use AWS CloudFormation to create an Amazon RDS DB instance. The template includes a DB instance resource. Which property is required for the DB instance to be created successfully?

A.DBInstanceClass and Engine
B.AllocatedStorage
C.DBInstanceIdentifier
D.MasterUsername and MasterUserPassword
AnswerA

In CloudFormation's AWS::RDS::DBInstance resource, DBInstanceClass and Engine are mandatory properties for every instance. DBInstanceClass defines the instance's compute and memory capacity, while Engine specifies the database engine (e.g., mysql, postgres). Without these, the resource automatically fails validation because CloudFormation can't provision a database without a compute class and an engine type. This makes this pair the correct answer for the property required universally.

Why this answer

In AWS CloudFormation, when creating an Amazon RDS DB instance using the AWS::RDS::DBInstance resource, the only truly required properties are DBInstanceClass (the compute and memory capacity) and Engine (the database engine, e.g., MySQL, PostgreSQL). These two properties are mandatory in the CloudFormation resource specification; without them, the template will fail validation. All other properties, such as AllocatedStorage, DBInstanceIdentifier, MasterUsername, and MasterUserPassword, have default behaviors or can be omitted under certain conditions (e.g., AllocatedStorage defaults to 20 GB for some engines, and MasterUsername/MasterUserPassword are not required if you use a snapshot or a source DB instance).

Exam trap

The trap here is that candidates often assume MasterUsername and MasterUserPassword are always required because they are mandatory in the AWS Management Console wizard, but CloudFormation allows omitting them when the DB instance is created from a snapshot or as a read replica, making DBInstanceClass and Engine the only universally required properties.

How to eliminate wrong answers

Option B is wrong because AllocatedStorage is not required; CloudFormation will use a default value (typically 20 GB) if not specified, and the DB instance can still be created successfully. Option C is wrong because DBInstanceIdentifier is optional; if omitted, CloudFormation automatically generates a unique identifier for the DB instance. Option D is wrong because MasterUsername and MasterUserPassword are not required when creating a DB instance from a snapshot or when specifying a source DB instance identifier; they are only required for a fresh, empty DB instance creation.

174
MCQhard

Refer to the exhibit. An IAM policy is attached to a group. A user in the group tries to stop an EC2 instance in us-east-1. What will happen?

A.The action is denied because the policy does not explicitly allow stopping an instance that is running.
B.The action is denied because the Deny statement is ambiguous and could apply to StopInstances.
C.The action is allowed only if the instance is in a stopped state.
D.The action is allowed because StopInstances is explicitly allowed and not denied.
AnswerD

The IAM policy includes an explicit Allow for ec2:StopInstances, and no explicit Deny statement covers StopInstances. Under IAM evaluation logic, an explicit Allow overrides the default implicit Deny, and since no explicit Deny applies, the request is permitted. Therefore, the user can stop the instance regardless of its running state.

Why this answer

The policy explicitly allows ec2:StopInstances for all resources, and there is no explicit deny for StopInstances. The Deny only applies to TerminateInstances. Option A is incorrect because StopInstances is allowed.

Option B is incorrect because the Deny is not ambiguous. Option C is incorrect because there is no condition key about instance state.

175
MCQmedium

A DevOps team is using AWS CodePipeline to automate deployments. The pipeline has a source stage (CodeCommit), a build stage (CodeBuild), and a deploy stage (CodeDeploy). The team wants to add a manual approval step before the deploy stage to ensure that only authorized personnel can approve production deployments. Which action should be taken to implement this requirement?

A.Add an AWS Lambda function as a transition action between the build and deploy stages that sends an email to the approver and waits for a response.
B.Create a CodeDeploy deployment group with a manual approval step in the deployment configuration.
C.Configure an Amazon SNS topic to send an approval request email to the approver, and use a Lambda function to resume the pipeline upon approval.
D.Add a manual approval action to the pipeline between the build and deploy stages, and configure the SNS topic to notify the approvers.
AnswerD

Adding a manual approval action between the build and deploy stages creates a required gate that pauses pipeline execution, satisfying the constraint that only authorised personnel can approve production deployments. Configuring the SNS topic enables the pipeline to send email or SMS notifications to the designated approvers, ensuring they are alerted to review and approve the change before CodeDeploy proceeds.

Why this answer

AWS CodePipeline natively supports a manual approval action that can be inserted as a stage between build and deploy. This action pauses the pipeline and sends a notification via an SNS topic to the configured approvers. The pipeline only resumes when an authorized user clicks the 'Approve' button in the CodePipeline console or API, ensuring that only authorized personnel can approve production deployments.

Exam trap

The trap here is that candidates often confuse CodeDeploy's deployment configuration options (like traffic shifting or validation hooks) with pipeline-level approval actions, or they assume a custom Lambda function can replace the native approval action, missing the fact that CodePipeline provides a fully managed, auditable approval workflow.

How to eliminate wrong answers

Option A is wrong because AWS Lambda cannot act as a transition action in CodePipeline; transitions are automatic and cannot be replaced by custom functions. Option B is wrong because CodeDeploy deployment groups do not have a manual approval step in their deployment configuration; manual approvals are a pipeline-level feature, not a CodeDeploy feature. Option C is wrong because while an SNS topic can send approval emails, using a Lambda function to resume the pipeline bypasses the built-in approval workflow and security controls of CodePipeline, and the pipeline would not properly wait for the approval response.

176
Matchingmedium

Match each AWS service to its primary function in a DevOps pipeline.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Continuous delivery service for release pipelines

Fully managed continuous integration build service

Automates code deployments to any instance

Unified user interface for managing software development activities

Fully managed source control service hosting Git repositories

Why these pairings

In a DevOps pipeline, AWS CodeCommit provides source control, CodeBuild compiles and tests code, CodeDeploy automates deployments, and CodePipeline orchestrates the entire CI/CD process. Common confusions include mixing up the roles of CodeCommit and CodeDeploy or CodeCommit and CodeBuild.

177
MCQmedium

A CloudFormation template includes the following resource: MySecurityGroup: Type: AWS::EC2::SecurityGroup Properties: GroupDescription: My security group SecurityGroupIngress: - IpProtocol: tcp FromPort: 443 ToPort: 443 CidrIp: 0.0.0.0/0 MyInstance: Type: AWS::EC2::Instance Properties: ImageId: ami-0abcdef1234567890 InstanceType: t2.micro SecurityGroupIds: !Ref MySecurityGroup The stack creation fails with the error shown. What is the cause?

A.The SecurityGroupIds property must be a list, but !Ref returns a single value.
B.The SecurityGroupIds property must be a list of security group names, not IDs.
C.The security group ingress rule is invalid because it allows all traffic.
D.The ImageId is missing, so the security group validation fails first.
AnswerA

The `SecurityGroupIds` property of an EC2 instance is typed as a list of security group IDs. When you use `!Ref` on a security group resource, CloudFormation resolves it to the security group's physical ID as a single string, not an array. Because the property requires a `List<AWS::EC2::SecurityGroup::Id>`, passing a bare `!Ref` causes a type-validation failure. To fix it, you must wrap the reference in a list literal, e.g., `SecurityGroupIds: [!Ref MySecurityGroup]`, or use `Fn::Split` if composing from a string.

Why this answer

The error occurs because the `SecurityGroupIds` property expects a list of security group IDs, but the `!Ref` intrinsic function returns a single security group ID (a string), not a list. In CloudFormation, `!Ref` for a security group returns its ID as a scalar value, so wrapping it in a list (e.g., `[!Ref MySecurityGroup]`) is required to satisfy the `List<String>` type constraint.

Exam trap

The trap here is that candidates assume `!Ref` automatically returns a list when the property expects one, but CloudFormation does not coerce scalar values into lists; you must explicitly provide a list literal.

How to eliminate wrong answers

Option A is correct because `SecurityGroupIds` requires a list, and `!Ref` returns a single value. Option B is wrong because `SecurityGroupIds` expects security group IDs, not names; the `SecurityGroups` property (deprecated) expects names, but `SecurityGroupIds` explicitly requires IDs. Option C is wrong because the ingress rule allowing TCP 443 from 0.0.0.0/0 is valid; it permits HTTPS traffic from anywhere, which is a common and allowed configuration.

Option D is wrong because the `ImageId` is provided (ami-0abcdef1234567890), and even if it were missing, CloudFormation would fail with a different error (e.g., 'ImageId is required'), not a security group validation error.

178
MCQmedium

A company is using AWS Elastic Beanstalk with a custom platform. They need to install a third-party agent on all instances. The agent requires a configuration file that contains sensitive credentials. How should the DevOps engineer provide the configuration file to the agent?

A.Use instance user data to write the configuration file during instance launch.
B.Embed the configuration file in the application source code and deploy it with the application.
C.Use .ebextensions configuration files to download the configuration from a secure S3 bucket using an IAM instance role.
D.Use AWS Systems Manager Run Command to distribute the configuration file after instances are launched.
AnswerC

.ebextensions files are processed by Elastic Beanstalk during environment creation and every instance deployment, allowing you to use a container command to copy the configuration from a private S3 bucket. Using an IAM instance role with a least-privilege policy scoped to that bucket keeps credentials out of code, and the configuration can be updated independently of the application.

Why this answer

Ebextensions configuration files allow you to run custom commands and scripts during instance provisioning, and by combining this with an IAM instance role that grants read access to a secure S3 bucket, you can securely download the sensitive configuration file without embedding credentials in the source code or user data. This approach follows AWS best practices for handling secrets by avoiding hard-coded credentials and leveraging IAM roles for temporary, scoped access.

Exam trap

The trap here is that candidates often choose Option A (user data) because it seems like a simple provisioning step, but they overlook that user data is not encrypted and is visible in the EC2 console, making it unsuitable for secrets, whereas .ebextensions with S3 and IAM roles provide a secure, auditable method that aligns with the AWS shared responsibility model.

How to eliminate wrong answers

Option A is wrong because instance user data is stored in plain text and can be viewed by anyone with access to the EC2 console or instance metadata, making it insecure for sensitive credentials. Option B is wrong because embedding the configuration file in the application source code exposes the credentials in version control systems and deployment artifacts, violating security best practices. Option D is wrong because AWS Systems Manager Run Command is an operational tool for ad-hoc or scheduled tasks, not a provisioning mechanism; it would introduce a race condition if the agent starts before the configuration is delivered, and it does not integrate with the Elastic Beanstalk lifecycle hooks to ensure the file is present at boot.

179
MCQhard

A DevOps engineer is troubleshooting an AWS CloudFormation stack that failed to create. The error message indicates that a resource 'AWS::Lambda::Function' timed out while being created. The Lambda function code is packaged as a ZIP file in Amazon S3. What is the most likely cause?

A.The Lambda function has a very short timeout (e.g., 3 seconds) configured in the function properties.
B.The Lambda function's execution role does not have permission to download the ZIP file from S3.
C.The Lambda deployment package is very large, causing the S3 download to exceed the resource creation timeout.
D.The CloudFormation service role does not have permissions to create Lambda functions.
AnswerC

If the ZIP file is exceptionally large (approaching Lambda's 50 MB compressed limit), the time CloudFormation takes to download it from S3 and create the Lambda resource can exceed the stack resource creation timeout. This manifests as a 'Resource creation timed out' error in the stack event, even though the function is valid. In contrast, a small package deploys quickly regardless of the Lambda function's configured timeout or role permissions.

Why this answer

AWS CloudFormation has a default timeout for creating resources, and if the Lambda deployment package is very large, downloading it from S3 can exceed that timeout. Option A is incorrect because the Lambda function's timeout setting (e.g., 3 seconds) applies to function execution, not to the creation process; the creation timeout is controlled by CloudFormation. Option B is incorrect because if the execution role lacks permissions to download the ZIP file, it would result in an access denied error, not a timeout.

Option D is incorrect because the CloudFormation service role permissions affect stack operations broadly, but they do not directly cause a resource-specific timeout; the timeout here is due to package size.

180
MCQeasy

A DevOps engineer wants to ensure that all EC2 instances launched in an AWS account automatically have a specific set of tags applied for cost allocation. Which AWS service should they use to enforce this?

A.AWS Service Catalog
B.AWS Config
C.Amazon EC2 Auto Scaling
D.AWS CloudFormation
AnswerB

AWS Config is the correct choice because it provides a continuous, account-wide compliance evaluation of resource configurations. You can use the managed AWS Config rule 'required-tags' (or a custom Lambda-backed rule) to check that every EC2 instance has the mandatory tags, and the rule can be paired with an auto-remediation action, such as an SSM Automation document, to automatically add missing tags. Since AWS Config records every EC2 instance as a configuration item and re-evaluates on configuration changes, it can both detect and enforce tag compliance for all existing and newly launched instances, regardless of how they were created.

Why this answer

AWS Config is correct because it can enforce tagging rules through managed rules like `required-tags` or custom AWS Config rules using AWS Lambda. When an EC2 instance is launched without the required tags, AWS Config can evaluate the resource against the rule and trigger remediation actions (e.g., via AWS Systems Manager Automation) to automatically apply the tags or flag non-compliance. This ensures consistent cost allocation tagging across all instances without manual intervention.

Exam trap

The trap here is that candidates confuse AWS Config's evaluation and remediation capabilities with the tagging features of EC2 Auto Scaling or CloudFormation, mistakenly thinking those services can enforce tags on all instances account-wide, when they only apply to resources they directly manage.

How to eliminate wrong answers

Option A is wrong because AWS Service Catalog is used to create and manage a catalog of approved IT services (e.g., pre-configured EC2 instances), but it does not enforce tagging on instances launched outside its portfolio or retroactively. Option C is wrong because Amazon EC2 Auto Scaling can apply tags to instances it launches via launch templates or configurations, but it cannot enforce tags on instances launched directly via the EC2 console, API, or other services. Option D is wrong because AWS CloudFormation can apply tags to resources it creates, but it cannot enforce tagging on resources created outside of a CloudFormation stack, such as manually launched EC2 instances.

181
MCQmedium

A DevOps engineer uses AWS Secrets Manager to rotate database credentials. The rotation fails because the Lambda function used for rotation does not have network access to the database. The database is in a private VPC. How should the engineer fix this?

A.Configure the Lambda function to be VPC-enabled and place it in the same subnet as the database.
B.Assign a public IP address to the database and update the security group to allow access from the Lambda function.
C.Set up a VPC Peering connection between the Lambda service and the VPC.
D.Add a NAT Gateway to the VPC to allow Lambda to reach the database.
AnswerA

Correct. Enabling VPC integration for the Lambda function makes AWS attach a Hyperplane Elastic Network Interface directly inside your chosen subnets, so the function can communicate with the database over private IP addresses without crossing the internet. Placing the Lambda ENI in the same subnets (or at least with a valid local route to the DB subnet) lets traffic flow entirely within the VPC. You must still allow the Lambda ENI's security group in the database's security group inbound rule, and the subnets must have proper routing; this preserves the database's private posture, which is the key requirement for Secrets Manager rotation.

Why this answer

The Lambda rotation function must reach the private database, so it needs to run inside the VPC with network access to the database's subnet and security group. Configuring the Lambda function to be VPC-enabled and placing it in the same subnet (or a subnet with routing to the database) allows it to resolve and connect to the private RDS/DB endpoint, fixing the rotation failure.

Exam trap

DOP-C02 often tests the misconception that Lambda can reach private VPC resources without being VPC-enabled, or that NAT/peering solves internal connectivity — candidates must remember Lambda needs explicit VPC attachment plus correct routing and security groups.

How to eliminate wrong answers

Option B is wrong because assigning a public IP to the database exposes it to the internet and violates security best practices; the database should remain private, and the Lambda should reach it internally. Option C is wrong because VPC peering is between two VPCs, not between the Lambda service and a VPC — Lambda is made VPC-aware by attaching it to subnets, not by peering. Option D is wrong because a NAT Gateway allows private subnets to reach the internet (outbound), not to reach a database inside the same VPC; the Lambda already needs to be in the VPC to reach the DB, and NAT does not solve that.

182
Multi-Selectmedium

A company uses AWS CodeCommit as a source repository and AWS CodeBuild for building artifacts. The DevOps team wants to ensure that all commits to the main branch trigger a build. Which steps should be taken? (Choose THREE.)

Select 3 answers
A.Configure the CodeBuild project to use the CodeCommit repository as the source and specify the main branch
B.Configure a webhook in the CodeCommit repository to notify CodeBuild
C.Create a CloudWatch Events rule that listens for CodeCommit repository state changes on the main branch
D.Set the CodeBuild project's trigger to use the CloudWatch Events rule
E.Use AWS CodeDeploy to trigger the build on commits
AnswersA, C, D

The CodeBuild project must be explicitly configured to use the CodeCommit repository as its source and to specify the main branch as the source version. This ensures the build fetches the latest code from that branch whenever a build is initiated, whether manually or via an event. Without this configuration, CodeBuild would have no source to use, so this is a prerequisite that makes the other correct answers functional.

Why this answer

Configuring the CodeBuild project to use the CodeCommit repository as the source and specifying the main branch ensures that CodeBuild knows which repository and branch to monitor for changes. This is the foundational step that links the source code to the build project, enabling automated builds when commits are pushed to the main branch.

Exam trap

The trap here is that candidates confuse CodeCommit's lack of native webhook support with other Git providers, leading them to select Option B, or they mistakenly think CodeDeploy can trigger builds instead of deployments.

183
MCQhard

An organization uses AWS CloudFormation StackSets to deploy resources across multiple accounts. They notice that a stack instance in one account is in a 'FAILED' status because of a permissions issue. After fixing the permissions, what is the most efficient way to retry the stack instance operation?

A.Manually create the stack in the failed account using the same template.
B.Use the 'Update stack instances' operation for the failed target account.
C.Update the entire stack set to retry all stack instances.
D.Delete the stack instance from the stack set and add it again.
AnswerB

The 'Update stack instances' operation is the correct remediation because it targets only the specific stack instance that failed inside the target account/region. CloudFormation StackSets treats a failed stack instance as an operation that can be retried without affecting other stack instances or the stack set definition. This operation re-invokes the deployment logic for that single instance, allowing transient issues such as permission timeouts or resource contention to resolve while preserving the centralized management model.

Why this answer

StackSets allow you to update stack instances individually; you can retry the specific failed instance without affecting others. Option A is wrong because updating the entire stack set would affect all accounts, which is inefficient. Option C is wrong because deleting and recreating the stack instance is disruptive.

Option D is wrong because manual stack creation outside StackSets defeats the purpose.

184
MCQhard

A company uses AWS CloudFormation StackSets to deploy a VPC across multiple AWS accounts in AWS Organizations. The StackSet is created with self-managed permissions. The deployment fails in some accounts with the error: 'Insufficient IAM permissions to create resources'. What is the most likely cause of this failure?

A.The StackSet does not support deploying to more than one account
B.The execution IAM role is not created in the target accounts
C.The administrator account does not have a service-linked role for StackSets
D.The target accounts have reached their resource service quotas
AnswerB

With self-managed permissions, StackSets assumes an execution role that must exist in each target account with sufficient permissions. Absent that role, resource creation fails with insufficient IAM permissions, satisfying the stem's error condition rather than an organisational or service-managed role issue.

Why this answer

With self-managed permissions in AWS CloudFormation StackSets, the administrator account does not automatically create the necessary IAM roles in target accounts. The execution IAM role must be manually created in each target account to grant StackSets the permissions required to create resources. The error 'Insufficient IAM permissions to create resources' directly indicates that this execution role is missing or lacks the required policies.

Exam trap

The trap here is that candidates often confuse self-managed and service-managed permissions, assuming that StackSets automatically handle IAM roles in target accounts, when in fact self-managed requires manual role creation in each target account.

How to eliminate wrong answers

Option A is wrong because StackSets are specifically designed to deploy stacks across multiple accounts and regions, so deploying to more than one account is a core feature, not a limitation. Option C is wrong because service-linked roles are not required for StackSets with self-managed permissions; they are used with service-managed permissions when StackSets integrates with AWS Organizations. Option D is wrong because resource service quotas would produce a different error message (e.g., 'Resource limit exceeded'), not an IAM permissions error.

185
Multi-Selectmedium

A DevOps engineer is designing an AWS CloudFormation template to deploy a three-tier web application. The application must be highly available across multiple Availability Zones. The engineer needs to ensure that the database layer uses a Multi-AZ deployment. Which TWO options should the engineer implement to meet these requirements? (Choose TWO.)

Select 2 answers
A.Define a separate 'AWS::RDS::DBSubnetGroup' resource with subnets from at least two Availability Zones.
B.Deploy the database with multiple read replicas in different Availability Zones.
C.Select a database engine that supports Multi-AZ deployments.
D.Configure the database to use a DB subnet group with subnets in a single Availability Zone.
E.Set the 'MultiAZ' property of the 'AWS::RDS::DBInstance' resource to 'true'.
AnswersC, E

Multi-AZ availability is not universally available across all RDS database engines; for example, Microsoft SQL Server supports Multi-AZ only on Enterprise or Standard editions (and not on Express/Web), while Oracle requires Enterprise Edition. If an engine/edition lacks Multi-AZ support, setting MultiAZ=true in CloudFormation will fail validation or be ignored. Therefore, confirming engine support is a necessary prerequisite before enabling Multi-AZ in the template.

Why this answer

Not all AWS RDS database engines support Multi-AZ deployments; for example, Amazon Aurora uses a different high-availability mechanism (cluster volume) and does not use the standard Multi-AZ feature. The engineer must verify that the chosen engine (e.g., MySQL, PostgreSQL, Oracle, SQL Server) explicitly supports Multi-AZ to enable synchronous standby replication across Availability Zones. Option E is correct because setting the 'MultiAZ' property to 'true' on the 'AWS::RDS::DBInstance' resource directly instructs CloudFormation to provision a primary DB instance in one AZ and a standby in another AZ, with automatic failover.

Exam trap

The trap here is that candidates often assume any database engine can be made Multi-AZ by simply setting the flag, but the exam tests the knowledge that engines like Aurora have a different architecture and require a cluster-based approach, not the standard MultiAZ property.

186
MCQeasy

A company uses AWS CodeBuild to run unit tests and package a Java application. The build environment needs to have a specific version of Java installed that is not available in the standard build images. The team wants to minimize build time. How should the engineer configure the build environment?

A.Use AWS Lambda to run the tests and package the application.
B.Use a standard build image and include a pre-build command to install the required Java version.
C.Use a custom build image that already includes the required Java version, stored in Amazon ECR.
D.Use the pre-build phase to download and install Java from an S3 bucket.
AnswerC

A custom build image with the required Java version already installed, stored in Amazon ECR, is the correct architecture because CodeBuild can be configured to pull that image at build time. Baking the JDK, build tool, and dependency caches into Docker layers means the runtime is available immediately, eliminating per-build installation overhead and making versioning deterministic. This approach is the intended pattern for non-standard language versions.

Why this answer

Using a custom build image stored in Amazon ECR allows the team to pre-install the exact Java version required, eliminating the need for runtime installation. This minimizes build time by avoiding the overhead of downloading and installing software during every build, while still providing a consistent, reproducible environment.

Exam trap

The trap here is that candidates may think installing software during the build (options B or D) is acceptable, but the question explicitly requires minimizing build time, making a pre-built custom image the only optimal choice.

How to eliminate wrong answers

Option A is wrong because AWS Lambda is a serverless compute service designed for short-running, event-driven functions, not for running unit tests and packaging a Java application that may require a full build environment and longer execution times. Option B is wrong because installing a specific Java version via a pre-build command adds significant time to every build, contradicting the goal to minimize build time. Option D is wrong because downloading and installing Java from an S3 bucket during the pre-build phase also introduces unnecessary runtime overhead and latency, increasing build duration compared to using a pre-built custom image.

187
MCQhard

A company has a multi-account AWS environment using AWS Organizations. The DevOps team wants to enforce a policy that prevents creating S3 buckets with public read access. They plan to use AWS CloudFormation StackSets to deploy a stack across all accounts. What is the BEST way to enforce this policy?

A.Use AWS CloudFormation Guard to validate templates before deployment and reject those with public access.
B.Create an IAM policy that denies s3:PutBucketAcl and attach it to all IAM users.
C.Create a service control policy (SCP) in the root organizational unit that denies the s3:PutBucketPublicAccessBlock action.
D.Create an S3 bucket policy in each account that denies public read access.
AnswerC

An SCP attached to the root OU acts as an organization-wide permission guardrail, denying s3:PutPublicAccessBlock for every principal in all member accounts, regardless of IAM policies or account-level configurations. Since this action is a prerequisite for making a bucket publicly accessible through the console or API, explicitly denying it prevents bucket owners from disabling the public-access block that keeps objects private. This preventive control is the only option here that applies consistently across the entire AWS organization.

Why this answer

A service control policy (SCP) applied at the root organizational unit in AWS Organizations can centrally deny the s3:PutBucketPublicAccessBlock action across all accounts, effectively preventing any user or role from disabling the bucket-level public access block settings. This approach works even if an IAM principal has full administrative permissions, as SCPs act as a guardrail that cannot be overridden by account-level policies. It enforces the policy at the organization level without requiring per-account configuration or modifying individual IAM users.

Exam trap

The trap here is that candidates often confuse SCPs with IAM policies or resource-based policies, assuming that an SCP can only restrict IAM users and not API actions like s3:PutBucketPublicAccessBlock, or they mistakenly think that denying s3:PutBucketAcl is sufficient to prevent public read access when in reality bucket policies are a more common vector for granting public access.

How to eliminate wrong answers

Option A is wrong because AWS CloudFormation Guard is a policy-as-code validation tool that can reject templates before deployment, but it only applies to the account where the StackSet is deployed and does not prevent manual creation of S3 buckets via the console, CLI, or SDK in other accounts; it also cannot enforce the policy retroactively. Option B is wrong because attaching an IAM policy that denies s3:PutBucketAcl to all IAM users does not prevent public read access via bucket policies (which use s3:PutBucketPolicy) or via the S3 Block Public Access settings; it also fails to cover roles, service-linked roles, or root user actions. Option D is wrong because creating an S3 bucket policy in each account that denies public read access only applies to existing buckets and does not prevent the creation of new buckets with public read access; it also requires manual deployment and maintenance in every account, which is not scalable or centrally enforceable.

188
Multi-Selectmedium

A company uses AWS CloudFormation to manage infrastructure. They have a stack that creates an Amazon RDS DB instance and an EC2 instance that connects to it. The DB instance has a deletion policy of 'Retain'. The stack fails to delete because the DB instance is retained and still exists. Which TWO actions would allow the stack to be deleted successfully? (Select TWO.)

Select 2 answers
A.Use the AWS CLI to force delete the stack with the --force option.
B.Manually delete the DB instance using the RDS console.
C.Disable termination protection on the EC2 instance.
D.Change the deletion policy of the DB instance to 'Delete' and then update the stack before deleting.
E.Modify the DB instance to allow deletion by setting DeletionProtection to false.
AnswersB, D

Manually deleting the RDS DB instance from the RDS console removes the physical database object from the account, circumventing CloudFormation's inability to delete it automatically. This is a valid operational workaround when the stack is stuck in DELETE_FAILED because the DB instance is protected by RDS deletion protection or has a DeletionPolicy of Retain. Once the resource is gone, a subsequent stack delete operation will succeed because CloudFormation no longer attempts to delete that DB instance.

Why this answer

Manually deleting the retained DB instance removes the resource that is blocking the stack deletion. CloudFormation cannot delete a stack that contains a resource with a 'Retain' deletion policy until that resource is manually removed, as the stack expects the resource to no longer exist for the deletion to complete.

Exam trap

The trap here is that candidates often confuse 'Retain' deletion policy with 'DeletionProtection' or assume that termination protection on EC2 instances is relevant, when in fact the core issue is that the retained resource must be either manually removed or its policy changed to allow CloudFormation to delete it.

189
MCQmedium

A CloudFormation stack update failed with the error shown. What is the most likely cause?

A.The instance type t2.micro is not available in the region.
B.The IAM role used by CloudFormation lacks ec2:RunInstances permissions.
C.The AMI ID specified in the template is incorrect or has been deregistered.
D.The stack name does not match the existing stack.
AnswerC

This option is correct because the CloudFormation error explicitly states that the imageId is invalid, which is the EC2 API's validation response for an AMI ID that is malformed, deregistered, or not present in the account/region. During a stack update, CloudFormation passes the AMI ID from the template to the EC2 RunInstances API, and EC2 rejects it with an error like 'InvalidAMIID.NotFound' or 'InvalidAMIID.Malformed', causing the stack update to roll back. This commonly happens when a template references a hard-coded AMI that was deregistered or copied from a different region.

Why this answer

The error message indicates that CloudFormation cannot find the specified AMI. This typically occurs when the AMI ID is incorrect, has been deregistered, or is not available in the region where the stack is being deployed. CloudFormation validates the AMI ID during stack creation or update, and if the AMI does not exist or is inaccessible, the operation fails with a 'Resource creation cancelled' error.

Exam trap

The trap here is that candidates may confuse a missing AMI error with an IAM permissions error, but the specific error message about 'AMI' not being found directly points to the AMI ID being invalid or unavailable, not to a lack of permissions.

How to eliminate wrong answers

Option A is wrong because if the instance type t2.micro were unavailable in the region, the error would specifically mention that the instance type is not supported, not that the AMI cannot be found. Option B is wrong because if the IAM role lacked ec2:RunInstances permissions, the error would indicate an authorization failure (e.g., 'You are not authorized to perform this operation'), not a missing AMI. Option D is wrong because a stack name mismatch would cause a different error, such as 'Stack with id [name] does not exist', and would not trigger a resource creation failure during an update.

190
MCQhard

A company uses AWS CodeDeploy for application deployments. They want to ensure that if a deployment fails, the system automatically rolls back to the previous version. Which configuration should they set?

A.Define a 'Failure' lifecycle event hook that calls a Lambda function to revert the deployment.
B.Configure the deployment group to enable automatic rollback when a deployment fails.
C.Set the 'auto-rollback' property in the CodeDeploy deployment group to 'true'.
D.Use a CloudFormation stack with a rollback configuration.
AnswerB

This is correct because CodeDeploy deployment groups support automatic rollback for trigger events such as DEPLOYMENT_FAILURE, DEPLOYMENT_STOP_REQUEST, and ALARM_ACTIVE. When any of these events occurs, CodeDeploy automatically initiates a new deployment of the last known-good revision to the same deployment group, with no custom code required. This native mechanism is the standard and recommended way to recover from a failed deployment while preserving deployment-group settings such as traffic routing and alarm monitoring.

Why this answer

AWS CodeDeploy provides a built-in automatic rollback feature that can be configured at the deployment group level. When enabled, CodeDeploy automatically reverts the deployment to the last known successful version if the deployment fails or reaches a specified alarm threshold, without requiring custom scripting or external orchestration.

Exam trap

The trap here is that candidates confuse lifecycle event hooks with rollback mechanisms, or assume a simple boolean property like 'auto-rollback' exists, when in reality the configuration requires a structured 'autoRollbackConfiguration' object with an enabled flag and specific event triggers.

How to eliminate wrong answers

Option A is wrong because CodeDeploy lifecycle event hooks (such as ApplicationStop, BeforeInstall, etc.) are used to run custom scripts or Lambda functions during deployment phases, not to trigger rollbacks; rollback is a deployment group configuration, not a lifecycle event. Option C is wrong because there is no 'auto-rollback' property in the CodeDeploy deployment group; the correct property is 'autoRollbackConfiguration' with an 'enabled' flag and 'events' list (e.g., DEPLOYMENT_FAILURE). Option D is wrong because CloudFormation stack rollback is unrelated to CodeDeploy application deployments; it handles infrastructure provisioning rollbacks, not application version rollbacks managed by CodeDeploy.

191
MCQmedium

A DevOps team uses Elastic Beanstalk to deploy a web application. They want to configure environment variables without modifying the application code. Where should they define these variables?

A.As environment properties in the Elastic Beanstalk environment
B.In the EC2 User Data script
C.In the instance metadata
D.In the application code
AnswerA

Elastic Beanstalk's native Environment Properties are key-value pairs defined at the environment level and injected directly into the operating system as environment variables on each EC2 instance, or as container environment variables for ECS-based platforms. This allows platform-managed settings to be consumed by your application with no extra code, and they are automatically updated on configuration changes without requiring a new deployment. They also support encrypted values when set through the AWS CLI or saved configurations with KMS, making them the standard, service-supported approach.

Why this answer

Elastic Beanstalk environment properties are key-value pairs defined in the environment configuration that are injected as environment variables into the application's runtime. They allow configuration changes without modifying application code, and can be set via the console, CLI, or .ebextensions. This is the standard mechanism for externalizing configuration in Elastic Beanstalk.

Exam trap

DOP-C02 often tests whether candidates confuse EC2 User Data (bootstrapping) or instance metadata (instance info) with Elastic Beanstalk environment properties, which are the correct mechanism for externalized app configuration.

How to eliminate wrong answers

Option B is wrong because EC2 User Data scripts run at instance launch for bootstrapping and are not the Elastic Beanstalk mechanism for runtime environment variables; they are also harder to manage and not environment-specific in the Beanstalk sense. Option C is wrong because instance metadata provides information about the EC2 instance (e.g., instance ID, IAM role credentials), not application configuration variables. Option D is wrong because defining variables in application code defeats the purpose of externalized configuration and requires code changes and redeployment.

192
MCQeasy

A DevOps engineer is using AWS CloudFormation to deploy a stack that includes a VPC with public and private subnets. The engineer wants to ensure that the public subnets automatically get a public IP address assigned to instances launched in them. Which property should be set?

A.EnableDnsSupport on the VPC
B.MapPublicIpOnLaunch on the subnet
C.EnableDnsHostnames on the VPC
D.AssociatePublicIpAddress on the instance
AnswerB

MapPublicIpOnLaunch is a subnet-level attribute that, when set to true, automatically assigns a public IPv4 address to every instance's primary network interface upon launch. This is the correct control for achieving subnet-wide public IP assignment, as it directly applies at the subnet boundary and affects all instances regardless of individual launch configuration. Changing this attribute is the standard CloudFormation approach to provision instances in a public subnet with reachable IP addresses.

Why this answer

The `MapPublicIpOnLaunch` property on an AWS CloudFormation `AWS::EC2::Subnet` resource controls whether instances launched in that subnet automatically receive a public IP address. Setting this property to `true` ensures that any EC2 instance launched in the public subnet gets a public IPv4 address from the subnet's CIDR range, which is essential for internet-facing resources in a VPC.

Exam trap

The trap here is that candidates often confuse VPC-level DNS settings (`EnableDnsSupport` and `EnableDnsHostnames`) with subnet-level public IP assignment, or they mistakenly think the instance-level `AssociatePublicIpAddress` is the only way to control public IP assignment, ignoring the subnet-level auto-assign feature.

How to eliminate wrong answers

Option A is wrong because `EnableDnsSupport` on the VPC controls whether DNS resolution is supported for the VPC (i.e., the VPC's DNS server responds to queries), not whether instances get public IP addresses. Option C is wrong because `EnableDnsHostnames` on the VPC determines whether instances in the VPC are assigned DNS hostnames (e.g., ec2-xxx.compute-1.amazonaws.com), but it does not assign public IP addresses. Option D is wrong because `AssociatePublicIpAddress` is a property of an EC2 instance (e.g., in `AWS::EC2::Instance` or launch configuration), not a subnet-level setting; while it can override the subnet's behavior, the question asks for the property that ensures public IPs are assigned automatically at the subnet level.

193
MCQmedium

A DevOps engineer is using AWS CloudFormation to deploy a serverless application that includes AWS Lambda functions, Amazon API Gateway, and Amazon DynamoDB tables. The engineer wants to ensure that the DynamoDB tables are retained if the stack is deleted, but the Lambda functions and API Gateway should be deleted. Which CloudFormation resource attribute should the engineer use on the DynamoDB tables?

A.UpdateReplacePolicy: Retain
B.DeletionPolicy: Snapshot
C.DeletionPolicy: Retain
D.UpdatePolicy: Retain
AnswerC

The DeletionPolicy attribute with Retain ensures that the DynamoDB table is preserved when the stack is deleted. This is the correct way to keep the table and its data. Other resources without this policy will be deleted as usual, matching the requirement.

Why this answer

The DeletionPolicy attribute with Retain ensures that the DynamoDB table is not deleted when the stack is deleted. This is the correct attribute to use. Other attributes like UpdateReplacePolicy and UpdatePolicy control different lifecycle events and do not apply to stack deletion.

Exam trap

The trap here is confusing DeletionPolicy with UpdateReplacePolicy, which handles resource replacement during updates rather than stack deletion.

194
MCQhard

An organization uses AWS CloudFormation to manage infrastructure. They have a stack that creates an Amazon S3 bucket with a bucket policy that restricts access to a specific IAM role. During a recent security audit, it was discovered that the bucket policy was modified manually via the AWS Management Console, and the change was not reflected in the CloudFormation template. The security team wants to detect and remediate such drift automatically. Which combination of steps should be taken to achieve this?

A.Use AWS CloudTrail to monitor PutBucketPolicy events and send alerts to the security team via Amazon SNS.
B.Create an AWS Config rule to check if the bucket policy matches the desired policy, and use an AWS Lambda function to automatically correct any noncompliant buckets.
C.Configure S3 event notifications to invoke an AWS Lambda function whenever the bucket policy is modified.
D.Enable drift detection on the CloudFormation stack and use Amazon EventBridge to trigger an AWS Lambda function that restores the original bucket policy when drift is detected.
AnswerD

Drift detection compares the live S3 bucket policy against the CloudFormation template and reports resource drift. An EventBridge rule listens for CloudFormation drift-detection status-change events and invokes Lambda, which re-applies the original bucket policy or triggers a stack update to restore the resource. This closes the loop between detecting drift and automatically remediating it.

Why this answer

It directly addresses the requirement to both detect and automatically remediate drift in a CloudFormation-managed S3 bucket policy. CloudFormation drift detection identifies manual changes to the bucket policy, and Amazon EventBridge can trigger an AWS Lambda function that uses the CloudFormation UpdateStack API to restore the original policy from the template, ensuring the infrastructure remains in sync with the IaC definition.

Exam trap

The trap here is that candidates often confuse S3 event notifications (which are for object-level events) with control plane operations like PutBucketPolicy, leading them to choose Option C, or they assume AWS Config alone can remediate drift without understanding that Config does not automatically correct CloudFormation stack resources.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail monitoring of PutBucketPolicy events only provides detection via alerts; it does not include any automated remediation to restore the original policy. Option B is wrong because an AWS Config rule can detect noncompliant bucket policies, but the suggested Lambda function would need to directly modify the S3 bucket policy, which would create a new drift event and not correct the CloudFormation stack itself, leaving the template out of sync. Option C is wrong because S3 event notifications are triggered by object-level events (e.g., PUT, POST) on the bucket, not by changes to the bucket policy; PutBucketPolicy is a control plane API call, not an S3 event notification trigger.

195
MCQhard

A DevOps team is using this IAM policy to allow a CI/CD pipeline to launch EC2 instances and retrieve parameters. However, the pipeline is failing with an 'AccessDenied' error when trying to create an instance. The pipeline uses a role with this policy attached. What is the most likely cause?

A.The condition StringEquals on InstanceType is incorrectly formatted.
B.The pipeline does not have permission to call ssm:GetParameter because the resource is not specified.
C.The policy does not grant permissions on additional resources required for RunInstances, such as images and network interfaces.
D.The policy must include a 'Resource' for the 'ec2:DescribeInstances' action to be valid.
AnswerC

RunInstances requires permissions on dependent resources beyond the instance itself: AMIs, network interfaces, volumes, key pairs and subnets. The policy grants only the instance action, so EC2 authorisation fails when it evaluates those referenced resources, producing AccessDenied. This satisfies the stem's constraint that the pipeline role lacks the necessary dependent-resource permissions.

Why this answer

The IAM policy likely only grants permissions on the 'ec2:RunInstances' action for the EC2 instance resource (arn:aws:ec2:region:account:instance/*), but creating an EC2 instance also requires permissions on other resources such as Amazon Machine Images (AMI), security groups, network interfaces, subnets, etc. Without explicit permissions on these additional resources, the RunInstances call fails with AccessDenied. Option A is incorrect because the condition syntax does not cause an AccessDenied; it would simply not match if poorly formatted.

Option B is incorrect because the ssm:GetParameter action is allowed by the policy if it includes a resource specification, but the failure is on RunInstances, not SSM. Option D is incorrect because DescribeInstances does not require a Resource specification in the policy; the policy syntax is valid.

196
Multi-Selectmedium

A DevOps engineer is creating an AWS Elastic Beanstalk environment and needs to ensure that configuration changes are tracked and can be reverted. Which THREE steps should the engineer take to achieve this? (Choose THREE.)

Select 3 answers
A.Enable configuration drift detection using AWS Config.
B.Use Elastic Beanstalk lifecycle policies to automatically retain old configurations.
C.Store configuration templates in the Elastic Beanstalk console, which automatically keeps version history.
D.Enable enhanced health reporting and detailed CloudWatch metrics.
E.Save configuration versions as saved configurations in Elastic Beanstalk.
AnswersA, D, E

AWS Config can be enabled to record configuration changes to Elastic Beanstalk environments and their underlying AWS resources (such as EC2 instances, security groups, and load balancers). By authoring or using managed Config rules, you can compare the actual environment settings to the desired baseline and receive SNS notifications or trigger SSM remediation when drift is detected. This provides a continuous, auditable change history and alerts you to unauthorised or accidental configuration modifications, allowing you to restore the correct settings quickly.

Why this answer

AWS Config can be used to track configuration changes to Elastic Beanstalk resources (e.g., the underlying EC2 instances, security groups, and load balancers) by recording configuration items and detecting drift from the desired state. This allows the DevOps engineer to audit changes and revert to a compliant configuration if needed.

Exam trap

The trap here is confusing lifecycle policies (which manage application versions) with configuration versioning, and assuming the console automatically retains configuration history when in fact you must explicitly save configurations as versions.

197
MCQhard

A company is using AWS Elastic Beanstalk with a custom platform. The platform is based on Amazon Linux 2 and includes a pre-installed application. The DevOps team needs to inject environment-specific configuration files into the EC2 instances during deployment. Which approach should be used?

A.Use AWS CloudFormation to update the environment with new configuration
B.Use .ebextensions configuration files in the application source bundle
C.Use EC2 user-data scripts to download configuration from S3
D.Store configuration in AWS Systems Manager Parameter Store and retrieve it in the application
AnswerB

Files placed in the .ebextensions directory of your application source bundle are processed automatically by Elastic Beanstalk during each deployment lifecycle. A .config file in this directory can use the 'files' key to write configuration content directly to absolute paths on the instance, and it can also run commands or container_commands in sequence with deployment events. Because these configuration files are part of the versioned source bundle, they are associated with a specific application version and are re-applied consistently whenever that version is deployed, making this the correct way to inject a configuration file into each instance during deployment.

Why this answer

Ebextensions configuration files are the native mechanism in Elastic Beanstalk to inject environment-specific configuration into EC2 instances during deployment. These YAML or JSON files, placed in the .ebextensions directory of the application source bundle, are processed by the Elastic Beanstalk platform engine to execute commands, create files, or modify configuration before the application starts, ensuring the custom platform receives the necessary environment-specific settings.

Exam trap

The trap here is that candidates often confuse runtime parameter retrieval (Option D) with deployment-time file injection, or assume that user-data scripts (Option C) are sufficient for ongoing deployments, failing to recognize that Elastic Beanstalk's .ebextensions are specifically designed for this purpose and integrate seamlessly with the platform's lifecycle.

How to eliminate wrong answers

Option A is wrong because AWS CloudFormation is used to manage the Elastic Beanstalk environment's infrastructure (e.g., resources like load balancers or scaling policies), not to inject configuration files into individual EC2 instances during deployment; it operates at the infrastructure layer, not the instance configuration layer. Option C is wrong because EC2 user-data scripts run only once at instance launch and are not integrated with Elastic Beanstalk's deployment lifecycle hooks, making them unreliable for injecting configuration during updates or rolling deployments where instances are reused. Option D is wrong because while Systems Manager Parameter Store can store configuration values, it requires the application code to explicitly retrieve them at runtime, which does not satisfy the requirement to inject configuration files into the EC2 instances during deployment; the question specifies injecting files, not runtime parameter access.

198
Multi-Selecteasy

A DevOps team wants to manage EC2 instance configurations using AWS Systems Manager. Which THREE capabilities of Systems Manager can be used to ensure instances are in a desired state? (Choose THREE.)

Select 3 answers
A.Run Command
B.OpsCenter
C.Parameter Store
D.Patch Manager
E.State Manager
AnswersA, D, E

Run Command is a Systems Manager capability that lets you execute shell scripts or PowerShell commands on one or more EC2 instances via the SSM Agent, without the need for SSH/RDP or opening inbound ports. By invoking documents like AWS-RunShellScript or AWS-RunPowerShellScript, you can directly enforce configuration settings, install software, or remediate configuration drift on demand. It supports rate control, error thresholds, and IAM-based permission scoping, making it a direct and flexible mechanism for enforcing instance configuration.

Why this answer

Run Command (A) is correct because it allows you to remotely and securely execute scripts or commands across EC2 instances without needing SSH or RDP, using an SSM document (SSM Document) that defines the desired configuration actions. This capability directly enforces a desired state by running idempotent scripts on demand or on a schedule.

Exam trap

The trap here is confusing Parameter Store (a data store) with a configuration management tool, or thinking OpsCenter (an operations dashboard) can enforce state, when only Run Command, State Manager, and Patch Manager directly execute actions to achieve and maintain a desired configuration.

199
MCQhard

A DevOps team manages a multi-account AWS environment using AWS Organizations. They need to enforce a mandatory tag (e.g., 'CostCenter') on all resources created across accounts. Which combination of services should be used to automatically remediate non-compliant resources?

A.AWS Service Control Policies (SCPs) to deny creation of resources without the tag.
B.AWS CloudTrail to detect non-compliant resource creation and send notifications.
C.AWS Config rules with automatic remediation using AWS Systems Manager Automation or Lambda.
D.AWS Resource Groups & Tag Editor to manually add tags to non-compliant resources.
AnswerC

AWS Config rules continuously evaluate resource configurations, including tags, against your desired policy and can trigger automatic remediation when a resource is non-compliant. Remediation actions are implemented through AWS Systems Manager Automation runbooks, such as AWS-TagEC2Instance to add the required tag or AWS-StopEC2Instance to stop the resource, or through a custom Lambda function. This provides a fully automated, auditable corrective control that detects and fixes tag non-compliance at scale without manual intervention.

Why this answer

AWS Config rules continuously evaluate resource configurations against desired tag policies. When a resource is non-compliant, Config can trigger automatic remediation using AWS Systems Manager Automation documents or Lambda functions to add the required tag or stop/delete the resource. This combination provides detection and automated enforcement across all accounts in AWS Organizations.

Exam trap

DOP-C02 often tests the misconception that SCPs can enforce tagging, but SCPs only control permissions, not resource configuration.

How to eliminate wrong answers

Option A is wrong because SCPs only deny API actions; they cannot enforce tagging at resource creation time and do not remediate existing resources. Option B is wrong because CloudTrail only logs API activity and can send notifications, but it does not automatically remediate non-compliant resources. Option D is wrong because manual tagging via Resource Groups & Tag Editor is not automated and does not scale across accounts.

200
MCQmedium

A company uses AWS CloudFormation to deploy a multi-tier application. The template includes a parameter for the instance type of EC2 instances. The DevOps team wants to restrict the allowed values to a specific set of instance types. Which CloudFormation section should be used?

A.Outputs
B.Parameters with AllowedValues
C.Conditions
D.Mappings
AnswerB

Parameters with AllowedValues is the correct mechanism because it defines an input variable whose acceptable values are explicitly enumerated at template authoring time. When the stack is created or updated, CloudFormation validates any supplied value against that list and rejects the operation if the value is not present. This provides a controlled menu of environment-specific options (e.g., Dev, Staging, Prod) or instance types, ensuring the multi-tier app is deployed with a valid, pre-approved configuration.

Why this answer

The Parameters section in AWS CloudFormation allows you to define input values that can be supplied at stack creation or update time. By specifying an AllowedValues constraint on a parameter, you restrict the user to select only from a predefined list of instance types, which enforces compliance and prevents misconfiguration. This is the correct mechanism for limiting instance type choices in a CloudFormation template.

Exam trap

The trap here is that candidates may confuse Mappings (which are static lookups) with parameter constraints, thinking they can restrict input values via a mapping, but Mappings only retrieve pre-defined data and do not enforce input validation.

How to eliminate wrong answers

Option A is wrong because the Outputs section declares values that are returned after the stack is created, such as resource IDs or endpoints; it does not accept or restrict input values. Option C is wrong because Conditions control whether certain resources or properties are created based on logical expressions (e.g., environment type), but they cannot restrict the allowed values of a parameter. Option D is wrong because Mappings provide a static lookup table (e.g., mapping region to AMI ID) and are used to retrieve values based on keys, not to constrain user-supplied parameter inputs.

201
MCQmedium

A company uses AWS Elastic Beanstalk for a web application. The DevOps engineer needs to ensure that environment configuration changes (e.g., instance type, environment variables) are version-controlled and can be rolled back quickly. Which approach should they use?

A.Use Elastic Beanstalk saved configurations stored in source control.
B.Manually update the environment configuration through the Elastic Beanstalk console.
C.Use the AWS CLI to apply configuration changes from a script.
D.Use AWS CloudFormation to manage the Elastic Beanstalk environment.
AnswerA

Elastic Beanstalk saved configurations are YAML files that capture the environment's option settings, environment variables, and platform configuration. You can store these files in source control, which gives you versioned, auditable, and reproducible configuration snapshots. When you need to roll back a problematic change, you can apply an older saved configuration via the EB CLI or console, restoring the exact previous runtime settings without re-provisioning infrastructure.

Why this answer

Elastic Beanstalk saved configurations allow you to export environment settings (e.g., instance type, environment variables) as a YAML or JSON file that can be stored in a version control system like Git. This enables you to recreate environments with identical settings and roll back to a previous configuration by deploying an older saved configuration file, providing a version-controlled, auditable, and reversible change management process.

Exam trap

The trap here is that candidates often assume AWS CloudFormation is always the best choice for infrastructure version control, but the question specifically tests knowledge of Elastic Beanstalk's native saved configuration feature, which is simpler and more direct for environment-level configuration rollbacks without requiring a separate orchestration service.

How to eliminate wrong answers

Option B is wrong because manually updating the environment configuration through the Elastic Beanstalk console is not version-controlled, lacks auditability, and cannot be easily rolled back without manually re-entering previous settings. Option C is wrong because using the AWS CLI to apply configuration changes from a script, while automatable, does not inherently provide version control or a structured rollback mechanism unless the script itself is stored in source control and carefully managed; it lacks the built-in saved configuration abstraction that Elastic Beanstalk offers for environment-level settings. Option D is wrong because while AWS CloudFormation can manage Elastic Beanstalk environments, it introduces additional complexity and overhead for simple environment configuration changes, and the question specifically asks for an approach that uses Elastic Beanstalk's native capabilities for version-controlled configuration and quick rollback, which saved configurations directly address.

202
MCQhard

A company uses AWS CloudFormation to deploy a complex application that includes an Amazon RDS database. The database must be created with a specific master password that is stored in AWS Secrets Manager. The DevOps team wants to avoid hardcoding the password in the CloudFormation template. They need to reference the secret in the template so that the RDS instance uses the password from Secrets Manager. Which approach should they take?

A.Store the secret in an Amazon S3 bucket and use the `Fn::GetAtt` function to reference it in the RDS `MasterUserPassword` property.
B.Use the `resolve:ssm-secure` dynamic reference to retrieve the secret from Secrets Manager and pass it to the RDS `MasterUserPassword` property.
C.Use the `resolve:secretsmanager` dynamic reference to retrieve the secret value and assign it to the RDS `MasterUserPassword` property.
D.Create a custom CloudFormation resource using AWS Lambda that retrieves the secret from Secrets Manager and returns it to the template.
AnswerC

CloudFormation supports the `resolve:secretsmanager` dynamic reference to fetch secret values from AWS Secrets Manager during stack operations. This allows the RDS instance to use the secret without hardcoding it. The dynamic reference retrieves the secret at deployment time, and CloudFormation manages the value securely. This is the correct and secure approach for referencing Secrets Manager secrets in templates.

Why this answer

The `resolve:secretsmanager` dynamic reference allows CloudFormation to retrieve a secret from AWS Secrets Manager during stack operations. This enables secure injection of the secret into the RDS `MasterUserPassword` property without hardcoding. Other options either use the wrong service (Parameter Store) or introduce unnecessary complexity with custom resources or insecure storage.

Exam trap

The trap here is confusing the dynamic reference for Systems Manager Parameter Store (`resolve:ssm-secure`) with the one for Secrets Manager (`resolve:secretsmanager`).

203
MCQhard

Refer to the exhibit. A DevOps engineer is troubleshooting an issue where an IAM user is unable to stop an EC2 instance with the tag 'Environment: Development'. The attached IAM policy is shown. Which statement explains the failure?

A.The Deny statement condition incorrectly uses StringNotEquals, which denies all instances except those with the Production tag.
B.The Deny statement includes ec2:StopInstances implicitly because stop is a termination action.
C.The Allow statement only grants ec2:DescribeInstances, not start/stop.
D.The policy does not prevent stopping instances with the Development tag; the failure must be caused by another policy or service control policy.
AnswerC

The policy's only explicit Allow is ec2:DescribeInstances; because ec2:StopInstances is a separate action in the IAM action namespace, no permission is granted to perform a stop. When the user calls StopInstances, IAM finds no allow and defaults to an implicit deny, so the API request fails. The Deny statement on RunInstances does not counteract this, so the missing start/stop Allow is precisely the cause.

Why this answer

The IAM policy in the exhibit only grants ec2:DescribeInstances and explicitly denies ec2:RunInstances with a condition. It does not include an Allow for ec2:StopInstances. By default, IAM denies any action that is not explicitly allowed.

Therefore, the user lacks permission to stop instances, including the Development-tagged instance. Option C correctly identifies this as the reason for the failure. Option D is incorrect because the policy itself denies stop implicitly due to the missing Allow; it is not necessary to invoke another policy or SCP.

Exam trap

The trap here is that candidates misread the Deny statement's action (ec2:RunInstances) and condition (StringNotEquals) as applying to stopping instances, when in fact it only affects launching instances, leading them to incorrectly select Option A or B without noticing the action mismatch.

How to eliminate wrong answers

Option A is wrong because the Deny statement uses ec2:RunInstances, not ec2:StopInstances, and the StringNotEquals condition applies to launching instances, not stopping them; it does not deny stopping Development instances. Option B is wrong because the Deny statement explicitly lists ec2:RunInstances, and AWS IAM does not implicitly include ec2:StopInstances under termination actions; stop and terminate are separate actions. Option C is wrong because while the Allow statement only grants ec2:DescribeInstances, the question asks why the user cannot stop the instance; the lack of an explicit allow for ec2:StopInstances would cause a default implicit deny, but the policy itself does not prevent stopping—the failure must be from another policy or SCP, as the provided policy does not deny stop actions.

204
MCQhard

A company manages a fleet of EC2 instances using AWS Systems Manager State Manager. They have a State Manager association that ensures a specific software package is installed on all instances. Recently, they noticed that some instances are reporting the association as 'Success' even though the software is not installed. The association uses a custom document that runs a script to install the package. The engineer checks the association execution history and sees that the script exited with code 0 on those instances. What is the most likely cause?

A.The association is not targeting those instances.
B.The instances are not configured to send compliance data to Systems Manager.
C.The instances do not have the SSM Agent installed.
D.The script does not check the exit code of the installation command and always returns 0.
AnswerD

State Manager judges an association as successful based on the exit code returned by the script; if the script's last command always returns 0, or it explicitly ends with `exit 0`, then even a failed installation will be recorded as compliant. To correctly reflect failures, the script must inspect `$?` (or `$LASTEXITCODE` in PowerShell) after the installer and propagate a non-zero exit. Because this script ignores the installer's failure and exits 0, compliance shows Success despite the software not being installed.

Why this answer

The script likely does not check the exit code of the installation command and always returns 0, so State Manager reports success even when installation fails. Option A is incorrect because the association is running on those instances, as shown by execution history. Option B is incorrect because compliance data is being sent (the 'Success' status is reported).

Option C is incorrect because the association runs, indicating SSM Agent is installed.

205
MCQmedium

A company uses Terraform with an S3 backend to manage infrastructure. The DevOps engineer notices that after a colleague runs 'terraform apply' locally, the state file in S3 becomes corrupted and subsequent runs fail. What is the BEST way to prevent this issue?

A.Store the state file locally and commit it to version control.
B.Use DynamoDB for state locking and enable consistency checks.
C.Use S3 server-side encryption to protect the state file.
D.Enable S3 versioning on the state bucket to recover previous versions.
AnswerB

The DynamoDB lock table uses conditional writes to ensure that only one Terraform run can hold the state lock at a time, preventing two `apply` executions from simultaneously updating the same S3 object and causing corruption. Enabling consistency checks (for example, verifying the lock acquisition and using DynamoDB's strongly consistent reads) ensures that the state pulled before a plan or apply is the latest known-good version, so stale or partially written state is never used as the basis for changes.

Why this answer

Enabling DynamoDB for state locking prevents concurrent modifications that can corrupt the state file. When a user runs 'terraform apply', Terraform acquires a lock in DynamoDB, ensuring only one operation modifies the state at a time. Consistency checks (e.g., using DynamoDB's conditional writes) further validate that the state hasn't been tampered with, directly addressing the corruption issue.

Exam trap

The trap here is that candidates often confuse recovery mechanisms (like S3 versioning) with prevention mechanisms (like state locking), leading them to choose Option D even though it only mitigates damage after corruption occurs.

How to eliminate wrong answers

Option A is wrong because storing the state file locally and committing it to version control introduces risks of manual merge conflicts, stale state, and accidental exposure of sensitive data; it does not prevent corruption from concurrent applies. Option C is wrong because S3 server-side encryption protects data at rest but does not prevent concurrent writes or state corruption from race conditions. Option D is wrong because S3 versioning allows recovery of previous state versions after corruption, but it does not prevent the corruption from occurring in the first place.

206
MCQmedium

A company uses AWS CodePipeline to deploy a Node.js application to AWS Elastic Beanstalk. The pipeline includes a build stage using AWS CodeBuild. Developers notice that the deployed application occasionally crashes due to missing environment variables that were configured in the Elastic Beanstalk environment but not passed from CodeBuild. What is the MOST efficient way to ensure the environment variables are consistently applied?

A.Define environment variables in the source code using .ebextensions configuration files.
B.Update the environment variables manually in the Elastic Beanstalk console after each deployment.
C.Use the aws elasticbeanstalk update-environment CLI command after the pipeline completes.
D.Store environment variables in AWS Systems Manager Parameter Store and have the application retrieve them at runtime.
AnswerA

Commit the variables in a .ebextensions/*.config file (e.g., option_settings for namespace aws:elasticbeanstalk:application:environment). CodePipeline packages the entire source into the application version, and the Elastic Beanstalk deployment agent processes this file automatically, injecting the values into the Node.js process's environment. This makes environment configuration declarative, versioned, and reproducible for every pipeline run, eliminating manual or post-deployment steps.

Why this answer

Ebextensions configuration files allow you to define environment variables declaratively in the source code, ensuring they are consistently applied during every deployment via CodePipeline. This approach eliminates the dependency on runtime or manual steps, as the Elastic Beanstalk environment automatically reads these files during environment creation and updates. It integrates seamlessly with CodeBuild and CodePipeline, making it the most efficient and reliable method for maintaining environment variable consistency.

Exam trap

The trap here is that candidates often assume runtime parameter retrieval (e.g., from Parameter Store or Secrets Manager) is the best practice for all scenarios, but for environment variables required at process startup in Elastic Beanstalk, .ebextensions provide a more reliable and simpler solution that avoids application code changes and ensures variables are set before the application runs.

How to eliminate wrong answers

Option B is wrong because manually updating environment variables in the Elastic Beanstalk console after each deployment is error-prone, not scalable, and violates the principle of infrastructure as code, leading to configuration drift. Option C is wrong because using the aws elasticbeanstalk update-environment CLI command after the pipeline completes introduces an extra post-deployment step that can fail or be forgotten, and it does not tie the variables to the source code version, making rollbacks inconsistent. Option D is wrong because while Parameter Store can be used for runtime retrieval, it requires application code changes to fetch variables at startup, adds latency, and does not guarantee the variables are present during the Elastic Beanstalk environment initialization, potentially causing crashes before the application code runs.

207
MCQmedium

A company uses AWS CloudFormation to manage its infrastructure. The DevOps team wants to ensure that critical resources, such as an RDS database, are not accidentally deleted when a stack is updated or deleted. Which CloudFormation feature should be used to prevent this?

A.DeletionPolicy attribute with Retain
B.Stack policy
C.Termination protection
D.DependsOn attribute
AnswerA

DeletionPolicy: Retain on a resource instructs AWS CloudFormation to preserve that physical resource when the stack is deleted. Without it, DeleteStack removes every resource in the template; with Retain, the resource is simply left in place and becomes orphaned, allowing you to keep critical data such as databases or S3 buckets. This is the standard way to prevent accidental data loss during stack deletion.

Why this answer

The DeletionPolicy attribute with the Retain value is the correct choice because it explicitly instructs CloudFormation to preserve the physical resource (e.g., an RDS database) when its corresponding logical resource is deleted from the stack template during an update or when the entire stack is deleted. This prevents accidental deletion of critical stateful resources by ensuring the resource remains in the AWS account even after the stack operation completes.

Exam trap

The trap here is that candidates confuse termination protection (an EC2-specific feature) with CloudFormation's DeletionPolicy, or mistakenly think a stack policy can prevent deletion during a full stack deletion, when it only restricts update operations.

How to eliminate wrong answers

Option B is wrong because a stack policy is an IAM-like resource-level policy that controls which stack resources can be updated or deleted during a stack update, but it does not prevent deletion when the entire stack is deleted; it only restricts update/delete actions during an update operation. Option C is wrong because termination protection is an EC2 instance-level feature that prevents accidental termination of an EC2 instance, not a CloudFormation feature and not applicable to RDS databases. Option D is wrong because the DependsOn attribute only specifies resource creation order within a stack template; it has no effect on preventing deletion of resources during stack updates or deletions.

208
Multi-Selectmedium

Which TWO approaches can be used to manage configuration files (e.g., application.properties) across multiple AWS accounts and regions using AWS Systems Manager? (Select TWO.)

Select 2 answers
A.Use AWS AppConfig to create, manage, and deploy application configurations across accounts and regions.
B.Use AWS OpsWorks for Chef Automate to store configuration data in Chef data bags.
C.Store configuration files in AWS Secrets Manager and retrieve them using the Secrets Manager API.
D.Store configuration parameters in AWS Systems Manager Parameter Store and reference them from applications using the AWS SDK.
E.Use AWS Systems Manager Run Command to push configuration files to EC2 instances on demand.
AnswersA, D

AWS AppConfig is the correct choice because it is purpose-built for managing application configuration independently of code deployments. It supports creating and maintaining configurations in a central store, validating them with format or semantic checks, and rolling them out gradually across accounts and regions using deployment strategies. Unlike the other options, AppConfig also provides built-in monitoring, automatic rollback, and the ability to retrieve configuration at runtime, making it an enterprise-grade configuration management service.

Why this answer

AWS AppConfig is a feature of AWS Systems Manager that allows you to create, manage, and deploy application configurations across accounts and regions. It supports staged rollouts, validation, and monitoring, making it suitable for managing configuration files like application.properties in multi-account, multi-region environments.

Exam trap

The trap here is that candidates often confuse AWS Secrets Manager with Parameter Store for configuration management, or assume Run Command is suitable for configuration deployment, when in fact AppConfig and Parameter Store are the correct Systems Manager services for managing and deploying configuration files across multiple accounts and regions.

209
MCQeasy

A company uses AWS Elastic Beanstalk to deploy a web application. The operations team wants to ensure that the environment's configuration (e.g., instance type, scaling limits) is version-controlled and reproducible. Which practice should they adopt?

A.Manually recreate the environment from the Elastic Beanstalk console when needed.
B.Use the Elastic Beanstalk saved configuration feature to download a configuration file and store it in version control.
C.Use AWS CloudFormation to define the environment and store the template in a Git repository.
D.Document the configuration in a wiki and apply it manually through the AWS Management Console.
AnswerB

The Elastic Beanstalk saved configuration feature exports the current environment's settings into a YAML file via `eb config save`, which can be downloaded and committed to version control. This file captures the complete environment configuration—platform, instance type, environment variables, scaling limits, health-check settings, and other option settings—without including transient data like application versions. Storing this file in Git enables you to recreate the same environment later with `eb config put`, apply it across regions or accounts, and revert to older configurations through normal version-control history.

Why this answer

Elastic Beanstalk's saved configuration feature allows you to download the environment's configuration as a YAML or JSON file, which can be stored in version control and used to recreate identical environments. This directly addresses the need for version-controlled, reproducible environment configuration without requiring additional infrastructure-as-code tools.

Exam trap

The trap here is that candidates may overthink and choose CloudFormation (Option C) because it is a powerful IaC tool, but the question specifically asks for a practice within Elastic Beanstalk's own features to version-control its configuration, not to replace the deployment service entirely.

How to eliminate wrong answers

Option A is wrong because manually recreating an environment from the console is error-prone, not version-controlled, and violates the principle of reproducibility. Option C is wrong because while AWS CloudFormation can define Elastic Beanstalk environments, the question specifically asks for a practice within Elastic Beanstalk's native capabilities; using CloudFormation adds unnecessary complexity and is not the recommended practice for version-controlling Elastic Beanstalk environment configuration. Option D is wrong because documenting configuration in a wiki and applying it manually is not version-controlled, is prone to human error, and does not enable automated or reproducible deployments.

210
Multi-Selecthard

Which THREE actions should be taken to ensure that an AWS CloudFormation stack update does not cause downtime for a production application that runs on an Auto Scaling group behind an Application Load Balancer? (Select THREE.)

Select 3 answers
A.Configure an 'UpdateWaitCondition' in the CloudFormation template to pause the stack update until a healthy signal is received from the new instances.
B.Add a custom resource that triggers an AWS Lambda function to take a snapshot of the database before the update.
C.Ensure that the Auto Scaling group spans at least three Availability Zones to distribute instances.
D.Set the Auto Scaling group's UpdatePolicy to 'AutoScalingRollingUpdate' with a 'BatchSize' of 1 and 'MinInstancesInService' equal to the desired capacity.
E.Define a lifecycle hook for the Auto Scaling group that delays instance termination until the new instance is fully registered and healthy with the load balancer.
AnswersA, D, E

An UpdateWaitCondition (typically implemented as a WaitCondition resource or UpdatePolicy with WaitOnSignals) makes CloudFormation pause the stack update until each new instance sends a success signal, usually via cfn-signal after it has passed health checks and is ready to serve traffic. This ensures that CloudFormation does not complete the update and potentially remove old resources until the new capacity is confirmed operational, directly preventing application downtime during the replacement process.

Why this answer

An 'UpdateWaitCondition' in a CloudFormation template can pause the stack update until a healthy signal is received from the new instances. This ensures that the update proceeds only after the new instances have passed health checks, preventing premature traffic routing and potential downtime.

Exam trap

The trap here is that candidates may confuse general high-availability practices (like multi-AZ distribution) with specific update-time actions that prevent downtime, or they may think database snapshots are relevant to instance-level availability during a stack update.

211
Matchingmedium

Match each AWS Config rule to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Checks that resources have specified tags

Ensures EBS volumes are encrypted

Prevents public read access on S3 buckets

Verifies CloudTrail is enabled

Checks for IAM policies granting full admin access

Why these pairings

The correct matches are: s3-bucket-public-read-prohibited with S3 public read check, restricted-ssh with SSH access check, iam-user-no-policies-check with no attached policies, and cloud-trail-cloud-watch-logs-enabled with CloudWatch integration. Common confusions include swapping definitions between different rule types.

212
MCQmedium

A DevOps engineer is troubleshooting a failed AWS CloudFormation stack creation. The stack creates an EC2 instance with a user data script that runs a configuration management tool. The instance launches successfully, but the user data script fails. How can the engineer retrieve the user data execution logs to debug the issue?

A.Use AWS CloudTrail to view the user data execution events.
B.Use AWS Systems Manager Run Command to retrieve the logs remotely.
C.Check the CloudWatch Logs group for the instance.
D.Access the instance via EC2 Instance Connect and check /var/log/cloud-init-output.log.
AnswerD

EC2 Instance Connect opens a temporary SSH session through the AWS Console, giving you direct interactive access to the running instance. Once connected, you can read /var/log/cloud-init-output.log, which captures the output of cloud-init including your user-data script, so any error or traceback from the script will be visible there. It is an effective diagnostic because it accesses the primary log source without requiring pre-installed agents or external log forwarding.

Why this answer

The user data script output is logged by cloud-init to /var/log/cloud-init-output.log on the EC2 instance. By using EC2 Instance Connect to access the instance, the engineer can directly read this log file to see the full execution output, including any error messages from the configuration management tool.

Exam trap

The trap here is that candidates assume CloudTrail or CloudWatch Logs automatically capture user data execution logs, but those services require explicit configuration and do not capture the script's output by default.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API calls (e.g., RunInstances) but does not capture the execution output of user data scripts inside the instance. Option B is wrong because AWS Systems Manager Run Command requires the SSM Agent to be installed and the instance to have an IAM role with appropriate permissions; it is not a default method for retrieving user data logs, and the user data script may fail before SSM Agent is fully operational. Option C is wrong because user data script logs are not automatically sent to CloudWatch Logs unless the instance is explicitly configured with the CloudWatch Logs agent and the user data script writes to the agent.

213
MCQeasy

A DevOps engineer is implementing AWS Config rules to enforce tagging standards on resources. The rule should trigger a remediation action via AWS Systems Manager Automation to apply the correct tags if a resource is non-compliant. What is the correct way to set up this remediation?

A.Use the AWS Config rule's remediation action to run an AWS Systems Manager Automation document.
B.Configure the AWS Config rule to send events to AWS CodePipeline to trigger a pipeline that fixes the tags.
C.Configure a CloudWatch Events rule to detect non-compliant resources and invoke a Lambda function that applies tags.
D.Use an SNS topic to notify administrators when a resource is non-compliant.
AnswerA

AWS Config rules natively support an automated remediation feature that links a non-compliant rule evaluation to an AWS Systems Manager Automation document. This is the intended, first-party mechanism: the Automation document can run pre-built or custom steps (e.g., AWS-TagResource) to fix tag violations, and Config can automatically apply remediation to affected resources. Because it is built into the Config service itself, it avoids the need to wire separate event routing or manual workflows, making it the most direct and operationally efficient option.

Why this answer

AWS Config rules can directly associate a remediation action using an AWS Systems Manager Automation document. When a resource is evaluated as non-compliant, Config can automatically invoke the specified SSM Automation document to apply the correct tags, without requiring intermediate services. This is the native, supported mechanism for auto-remediation of non-compliant resources.

Exam trap

The trap here is that candidates may over-engineer a solution with Lambda or CloudWatch Events, not realizing that AWS Config has a built-in, one-click remediation action that directly invokes SSM Automation documents, making it the simplest and most correct approach.

How to eliminate wrong answers

Option B is wrong because AWS Config does not natively integrate with AWS CodePipeline for remediation; CodePipeline is a CI/CD service, not designed for real-time tag enforcement. Option C is wrong because while a CloudWatch Events rule can detect non-compliant resources and invoke a Lambda function, this is an indirect, custom approach that duplicates the built-in remediation capability of AWS Config, and the question specifically asks for the correct way to set up remediation using AWS Config's native feature. Option D is wrong because an SNS topic only notifies administrators; it does not perform any automated remediation action, which the question requires.

214
Multi-Selectmedium

Which THREE are valid AWS Systems Manager capabilities for configuration management? (Select THREE.)

Select 3 answers
A.Run Command
B.OpsCenter
C.Parameter Store
D.Patch Manager
E.State Manager
AnswersA, D, E

Run Command is a valid Systems Manager capability because it lets you execute operational commands and scripts on EC2 instances and on-premises machines via the SSM agent, without opening inbound ports like SSH or RDP. It supports ad-hoc execution across targets defined by tags, resource groups, or individual instance IDs, with features like rate control, error thresholds, and integration with EventBridge for automation.

Why this answer

Run Command enables you to manage configuration by remotely executing commands on instances. Patch Manager automates the process of patching managed instances. State Manager helps you define and maintain the desired state of your instances.

OpsCenter (B) is an operational data hub for viewing and resolving operational issues, not primarily for configuration management. Parameter Store (C) provides secure storage for configuration data and secrets, but it is a supporting service rather than a configuration management capability itself.

215
Multi-Selectmedium

A company uses AWS CloudFormation to manage a production environment with multiple stacks. The DevOps team needs to implement a change management process that requires approval for any changes to the production stack. Which approaches meet this requirement? (Choose TWO.)

Select 2 answers
A.Create an IAM policy that allows only read-only access to the production stack and a separate role with write access.
B.Require that all stack updates be performed through a change set that is reviewed and executed by a separate role.
C.Use AWS CodePipeline with a manual approval step before executing a CloudFormation change set.
D.Use AWS Config rules to detect unapproved changes and automatically revert them.
E.Use an SCP to deny all CloudFormation actions except from a specific CI/CD role.
AnswersB, C

Change sets preview exactly which resources CloudFormation will add, modify or delete, so a separate role can review that diff before execution. This enforces approval at the stack level, satisfying the change management requirement without altering the template itself.

Why this answer

Option B is correct because CloudFormation change sets let you preview exactly what modifications an update will make to the production stack, and gating the actual execution behind a separate role enforces a review-and-approve step before any changes are applied. Option C is correct because AWS CodePipeline supports a manual approval action that pauses the pipeline, allowing a designated approver to review the change set before the pipeline proceeds to execute it against the production stack. Option A is not correct because read-only versus write IAM policies only control who can modify stacks; they do not build a review/approval workflow into the change process.

Option D is not correct because AWS Config rules detect and can remediate noncompliant resources after the fact, but they do not provide a pre-change approval gate for CloudFormation stack updates. Option E is not correct because an SCP restricting CloudFormation actions to a CI/CD role limits who can make changes but does not itself require human review or approval of those changes.

Exam trap

The trap here is that candidates often think IAM policies alone can enforce an approval workflow, but IAM only controls who can perform actions, not the sequence or review of those actions; change sets and CodePipeline approval steps are the correct mechanisms for enforcing a change management process.

← PreviousPage 3 of 3 · 215 questions total

Ready to test yourself?

Try a timed practice session using only Configuration Management and IaC questions.