Courseiva

AWS Certified SysOps Administrator Associate SOA-C02 (SOA-C02) — Questions 676–750

1169 questions total · 16pages · All types, answers revealed

Data quality score: 70/100 — Review before indexing

2 errors found across 75 questions. This page is set to noindex until issues are resolved.

Page 9

Page 10 of 16

Page 11
676
MCQhard

A company uses Amazon S3 to serve large files to users. The files are accessed frequently for the first 30 days after upload, then access drops significantly. The SysOps administrator wants to minimize storage costs while ensuring low-latency access for frequently accessed files and automatic optimization for changing access patterns. Which S3 storage class configuration should be used?

A.Use S3 Standard for 30 days, then transition to S3 Glacier Deep Archive.
B.Use S3 Intelligent-Tiering.
C.Use S3 Standard then transition to S3 Glacier Flexible Retrieval after 30 days.
D.Use S3 One Zone-IA for the first 30 days, then transition to S3 Standard-IA.
AnswerB

S3 Intelligent-Tiering is the correct choice because it automatically monitors access patterns at the object level and moves data between Frequent Access, Infrequent Access, and Archive Instant Access tiers without any retrieval fees or user action. This provides low-latency access for actively requested large files while silently reducing storage cost for objects that become cold. It is ideal for unknown, unpredictable, or changing access patterns because there is no static lifecycle rule to misjudge when data will be accessed again. A small monthly monitoring and automation fee per object applies, but it is typically negligible compared to the savings and avoids the risk of archive-tier retrieval delays.

Why this answer

S3 Intelligent-Tiering is the correct choice because it automatically moves objects between three access tiers (frequent, infrequent, and archive instant) based on changing access patterns, without any lifecycle rules or performance impact. This meets the requirement for low-latency access for frequently accessed files and automatic optimization, while minimizing storage costs as access drops after 30 days.

Exam trap

The trap here is that candidates often choose a lifecycle-based solution (like S3 Standard to Glacier) thinking it is automatic, but they overlook that lifecycle rules are static and do not adapt to changing access patterns, whereas S3 Intelligent-Tiering dynamically optimizes without manual intervention.

How to eliminate wrong answers

Option A is wrong because S3 Glacier Deep Archive has a retrieval time of 12-48 hours, which does not provide low-latency access for frequently accessed files, and it requires manual lifecycle rules rather than automatic optimization. Option C is wrong because S3 Glacier Flexible Retrieval has retrieval times of minutes to hours (typically 1-5 minutes for expedited, but with additional cost), which does not guarantee low-latency access, and it requires a lifecycle policy rather than automatic pattern adaptation. Option D is wrong because S3 One Zone-IA does not provide the durability of multiple Availability Zones and is not suitable for frequently accessed files due to retrieval costs, and transitioning to S3 Standard-IA after 30 days still requires manual lifecycle rules and does not automatically optimize for changing access patterns.

677
MCQmedium

A SysOps administrator manages IAM roles for Amazon EC2 instances. The administrator needs to identify permissions that have never been used in the last 90 days to right-size the policies. Which AWS feature should be used to achieve this?

A.AWS CloudTrail Insights
B.IAM Access Analyzer unused access analysis
C.IAM policy simulator
D.AWS Config managed rules
AnswerB

IAM Access Analyzer unused access analysis examines the service last accessed data for IAM roles and users to identify which actions, services, and resources have not been used within a specified timeframe (e.g., 90 or 180 days). This feature produces findings that directly highlight unused permissions, allowing SysOps administrators to update policies and enforce least privilege. It is the only option listed that provides the historical usage data needed to detect and remove unnecessary access.

Why this answer

IAM Access Analyzer unused access analysis is the correct AWS feature because it specifically analyzes IAM roles and policies to identify permissions that have not been used within a specified time frame (e.g., 90 days). It provides a report of unused actions, allowing the administrator to right-size policies by removing unnecessary permissions. This directly addresses the requirement to identify unused permissions for EC2 instance roles.

Exam trap

The trap here is that candidates may confuse IAM Access Analyzer unused access analysis with AWS CloudTrail Insights, but CloudTrail Insights focuses on anomalous activity patterns rather than a straightforward unused permissions report for policy right-sizing.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail Insights analyzes management and data events to detect unusual activity patterns, not to identify unused permissions over a specific period. Option C is wrong because the IAM policy simulator tests whether a given policy allows or denies specific actions for a user, role, or resource, but it does not analyze historical usage or identify unused permissions. Option D is wrong because AWS Config managed rules evaluate resource configurations against compliance rules, not historical permission usage.

678
MCQmedium

An administrator uses AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment fails with an error: "The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available for deployment, or some instances in your deployment group are experiencing problems." The deployment group has a minimum of 2 instances. What should the administrator check first?

A.The application revision's compatibility with the instance operating system.
B.The Auto Scaling group's health check settings.
C.The deployment group's deployment configuration settings.
D.The deployment logs on the individual EC2 instances.
AnswerD

CodeDeploy's error is generic, so instance-level detail is decisive. The CodeDeploy agent writes lifecycle event logs to /opt/codedeploy-agent/deployment-root on each EC2 instance, revealing the actual failure (hook script, permissions, or missing dependencies) behind the aggregate deployment-group message.

Why this answer

The error message indicates that too many individual instances failed deployment. The first step is to check the deployment logs on the individual EC2 instances to identify the specific failure reason, such as script errors, missing dependencies, or permissions issues. This provides the most direct insight into why instances are failing.

Exam trap

SOA-C02 often tests the tendency to jump to configuration settings, but the error message points to instance-level failures, so logs are the first check.

How to eliminate wrong answers

Option A is wrong because while OS compatibility could be a factor, it is not the first thing to check; logs will reveal if that is the issue. Option B is wrong because Auto Scaling health check settings affect instance replacement, not the deployment failure itself. Option C is wrong because deployment configuration settings control the rate of deployment and healthy instance thresholds, but the error already indicates too many instances failed, so the configuration is likely not the root cause.

679
Multi-Selecthard

A SysOps administrator is tasked with setting up a solution that automatically terminates EC2 instances that have been running for more than 24 hours. Which steps should the administrator take? (Select THREE.)

Select 3 answers
A.Configure an Auto Scaling group lifecycle hook to terminate instances after 24 hours.
B.Create a CloudWatch alarm on the InstanceAge metric and set it to trigger the Lambda function.
C.Tag each EC2 instance with its launch time (e.g., key: LaunchTime, value: timestamp).
D.Create an Amazon EventBridge rule that triggers the Lambda function on a schedule (e.g., every hour).
E.Create an AWS Lambda function that uses the EC2 API to terminate instances older than 24 hours.
AnswersC, D, E

Tagging each EC2 instance with its launch time (e.g., key: LaunchTime, value: timestamp) gives the Lambda function the necessary metadata to calculate the instance's age during each invocation. This tag can be read via the DescribeInstances API call, allowing the function to compare the stored timestamp with the current time and identify any instance older than 24 hours. It also makes the process stateless and independent of EC2's built-in attribute details, ensuring the solution works across instances in any state.

Why this answer

Tagging each EC2 instance with its launch time (e.g., key: LaunchTime, value: timestamp) provides a reliable, queryable metadata point that a Lambda function can use to calculate instance age. This approach avoids reliance on the EC2 instance's launch time attribute, which can be altered or unavailable in certain scenarios (e.g., stopped/started instances). The tag serves as a deterministic reference for the Lambda function to compare against the current time and decide termination.

Exam trap

The trap here is that candidates may confuse lifecycle hooks (which are for Auto Scaling events) with scheduled termination logic, or assume CloudWatch has a built-in 'InstanceAge' metric, when in fact no such metric exists and the correct approach requires a custom tagging and Lambda-based solution.

680
MCQeasy

A company wants to allow a developer to deploy applications using AWS CloudFormation but restrict the developer from creating or modifying IAM resources. Which IAM policy should be used?

A.Allow iam:*
B.Deny cloudformation:*
C.Allow cloudformation:* and deny iam:*
D.Allow cloudformation:* only
AnswerC

This combination correctly grants the developer the full CloudFormation API to create, update, and delete stacks needed for application deployment, while an explicit deny on iam:* overrides any other policy that might inadvertently allow IAM actions. Because an explicit deny always takes precedence over an allow, this ensures the developer cannot alter users, roles, or policies, even if they have attached policies from other sources. This strikes the right balance between enabling deployment workflows and enforcing least privilege.

Why this answer

The developer needs CloudFormation permissions to deploy stacks, but must be blocked from creating or modifying IAM roles, users, or policies. An explicit Deny on iam:* overrides any Allow, so combining Allow cloudformation:* with Deny iam:* enforces least privilege while still permitting stack operations. This is the standard pattern for preventing privilege escalation via CloudFormation, since stacks can otherwise create IAM roles with broad permissions.

Exam trap

SOA-C02 often tests the misconception that allowing cloudformation:* is safe — candidates forget that CloudFormation can create IAM resources, so an explicit Deny on iam:* is required to truly restrict IAM changes.

How to eliminate wrong answers

Option A is wrong because Allow iam:* grants the developer full IAM control, which is exactly what the requirement forbids and enables privilege escalation. Option B is wrong because Deny cloudformation:* blocks the very deployment capability the developer needs, defeating the purpose. Option D is wrong because Allow cloudformation:* alone still permits CloudFormation to create IAM resources (e.g., via AWS::IAM::Role in a template), so the restriction is not enforced.

681
MCQmedium

The finance team was surprised by a $12,000 spike in EC2 costs last month caused by a runaway Auto Scaling group. They want to receive an email alert within hours whenever any AWS service cost behaves unexpectedly, without manually setting fixed dollar thresholds for each service. Which AWS cost management feature provides this?

A.Enable Cost Anomaly Detection with an AWS services monitor and create an alert subscription to email the finance team when an anomaly is detected
B.Create an AWS Budget with a monthly EC2 cost threshold of $10,000 and an alert at 80 percent of the threshold
C.Enable AWS Cost Explorer and review the daily cost breakdown each morning to spot unexpected charges
D.Configure CloudWatch Billing alarms with a static threshold for each AWS service individually
AnswerA

Cost Anomaly Detection's ML model learns the historical spending pattern for each service. When EC2 (or any service) starts spending at an anomalous rate, the model detects it within hours. The alert subscription can notify via email or SNS with the anomaly amount, affected service, and percentage deviation. No manual threshold tuning is needed — the model self-calibrates.

Why this answer

Cost Anomaly Detection uses machine learning to model historical spending patterns for each AWS service and automatically detects unusual spikes without requiring manual thresholds. By creating an AWS services monitor and linking an alert subscription, the finance team receives email notifications within hours when any service deviates from its expected cost behavior, directly addressing the need for service-agnostic, threshold-free alerts.

Exam trap

The trap here is that candidates often confuse AWS Budgets or CloudWatch Billing alarms with anomaly detection, but those tools require manual static thresholds and do not automatically adapt to changing spending patterns across multiple services.

How to eliminate wrong answers

Option B is wrong because an AWS Budget with a fixed monthly EC2 cost threshold of $10,000 and an 80% alert requires manual threshold setting and only monitors EC2, not all services, and cannot detect unexpected behavior that stays under the threshold. Option C is wrong because manually reviewing AWS Cost Explorer daily is not an automated alerting mechanism and does not provide timely notification within hours of a spike. Option D is wrong because CloudWatch Billing alarms require configuring a static dollar threshold for each individual service, which is exactly what the finance team wants to avoid, and they do not adapt to changing spending patterns.

682
MCQmedium

Refer to the exhibit. An IAM policy is attached to an EC2 instance role. The application on the instance attempts to write logs to a log group named 'MyAppLogs' in CloudWatch Logs but fails. What is the likely cause?

A.The EC2 instance does not have an internet gateway to reach CloudWatch Logs.
B.The log group name in the policy does not match the application's log group.
C.The policy does not grant permission to create the log group because the resource for CreateLogGroup is specified as the log stream ARN.
D.The policy lacks permission for 'logs:DescribeLogGroups'.
AnswerC

This is correct because CloudWatch Logs IAM actions are tied to specific resource ARN types. The `logs:CreateLogGroup` action targets a log-group resource, so its Resource element must be the ARN of the log group itself (e.g., `arn:aws:logs:region:account:log-group:MyAppLogs`). By specifying a log-stream ARN, the IAM policy does not match the resource that the CreateLogGroup API call uses, so IAM denies the request. CreateLogStream and PutLogEvents, by contrast, correctly target log-stream ARNs, but that does not help create the log group.

Why this answer

The policy grants `logs:CreateLogGroup` but specifies the resource as the log stream ARN (`arn:aws:logs:us-east-1:123456789012:log-group:MyAppLogs:log-stream:*`). CloudWatch Logs requires the resource for `CreateLogGroup` to be the log group ARN (`arn:aws:logs:us-east-1:123456789012:log-group:*` or a specific log group name), not a log stream. Since the application is attempting to write logs to a log group that does not yet exist, the `CreateLogGroup` call fails due to the incorrect resource ARN, causing the overall write operation to fail.

Exam trap

The trap here is that candidates often overlook the resource ARN mismatch for `CreateLogGroup` and assume the failure is due to a missing permission or network issue, but the policy explicitly includes the action with an incorrectly scoped resource.

How to eliminate wrong answers

Option A is wrong because EC2 instances can reach CloudWatch Logs via a VPC endpoint or NAT gateway; an internet gateway is not strictly required, and the question does not indicate any network connectivity issue. Option B is wrong because the exhibit shows the log group name in the policy is 'MyAppLogs', which matches the application's log group, so a mismatch is not the cause. Option D is wrong because `logs:DescribeLogGroups` is not required to write logs; the necessary permissions for writing are `CreateLogGroup`, `CreateLogStream`, and `PutLogEvents`, and the failure is specifically due to the `CreateLogGroup` resource misconfiguration.

683
MCQeasy

An organization wants to automate the creation of AWS resources using AWS CloudFormation. They need to ensure that certain resources, such as an Amazon S3 bucket, are not accidentally deleted when the stack is deleted. Which CloudFormation feature should they use?

A.DeletionPolicy attribute with value 'Retain'
B.DeletionPolicy attribute with value 'Protect'
C.DeletionPolicy attribute with value 'Delete'
D.Stack policy
AnswerA

The DeletionPolicy attribute with value Retain is the correct CloudFormation resource-level setting to preserve an S3 bucket when its stack is deleted. It instructs CloudFormation to skip deleting the underlying resource, so the bucket and all objects remain in the AWS account as an orphaned resource. This is designed exactly for the use case of retaining stateful data such as S3 buckets or DynamoDB tables after infrastructure teardown.

Why this answer

The DeletionPolicy attribute with value 'Retain' instructs AWS CloudFormation to preserve a resource when its stack is deleted. This is the correct feature to prevent accidental deletion of critical resources like an S3 bucket, as the bucket and its contents will remain in the account even after the stack is removed.

Exam trap

The trap here is that candidates confuse the DeletionPolicy attribute with a stack policy or incorrectly assume 'Protect' is a valid value, when in fact only 'Delete', 'Retain', and 'Snapshot' are permitted.

How to eliminate wrong answers

Option B is wrong because 'Protect' is not a valid value for the DeletionPolicy attribute; valid values are 'Delete', 'Retain', and 'Snapshot'. Option C is wrong because 'Delete' is the default behavior that deletes the resource when the stack is deleted, which is the opposite of what the organization wants. Option D is wrong because a stack policy controls updates to stack resources, not deletion behavior during stack deletion.

684
MCQmedium

An organization wants to ensure that all changes to an S3 bucket policy are logged and immediately trigger a notification to the security team. What is the most efficient way to achieve this?

A.Create a CloudWatch Events rule that matches PutBucketPolicy API call and triggers an SNS topic.
B.Create a CloudWatch Alarm that monitors the S3 bucket's policy.
C.Use AWS Config with a managed rule to detect policy changes.
D.Enable S3 event notifications on the bucket for 'PutBucketPolicy' events.
AnswerA

CloudWatch Events (now Amazon EventBridge) can match the PutBucketPolicy API call by using an event pattern that filters CloudTrail's AWS API Call events. When the bucket policy is modified, the rule triggers an SNS topic in near-real-time, enabling immediate notification. This approach requires CloudTrail to be enabled and configured to record management events, and it is the only option here that provides real-time, actionable alerts for policy changes.

Why this answer

CloudWatch Events (now Amazon EventBridge) can capture the PutBucketPolicy API call via a service-specific event pattern and route it to an SNS topic for immediate notification. This approach is the most efficient as it directly monitors the API call in real-time without polling or additional configuration, ensuring the security team is alerted the moment the policy changes.

Exam trap

The trap here is that candidates confuse S3 event notifications (which only cover object-level events) with CloudWatch Events (which can capture management API calls via CloudTrail), leading them to incorrectly select option D.

How to eliminate wrong answers

Option B is wrong because a CloudWatch Alarm monitors metric data (e.g., bucket size, request count) and cannot directly detect or react to S3 bucket policy changes; it lacks the ability to match specific API calls. Option C is wrong because AWS Config evaluates resource configurations against rules and can detect policy changes, but it operates on a periodic or configuration-change basis (typically minutes delay) and does not provide immediate, real-time notification via SNS. Option D is wrong because S3 event notifications support object-level events (e.g., s3:ObjectCreated, s3:ObjectRemoved) and not management API calls like PutBucketPolicy; S3 event notifications cannot be configured for bucket policy changes.

685
Multi-Selectmedium

A SysOps administrator is responsible for an Auto Scaling group that runs a critical application. The administrator wants to ensure that the application can recover from an AZ failure. Which THREE steps should the administrator take? (Choose three.)

Select 3 answers
A.Use EC2 instances in a single Availability Zone to reduce latency.
B.Place subnets in each Availability Zone used by the Auto Scaling group.
C.Configure the Auto Scaling group to launch instances in at least two Availability Zones.
D.Attach an Application Load Balancer that is enabled for multiple Availability Zones.
E.Use a single subnet in one Availability Zone to simplify network design.
AnswersB, C, D

An Auto Scaling group defines which subnets it can launch instances into, and each subnet maps to exactly one Availability Zone. To spread instances across multiple Availability Zones, you must explicitly configure the ASG to include subnets from each of those zones. Without a corresponding subnet in a given AZ, the group cannot place instances there, so omitting subnets limits the group's ability to recover from zone-level failures.

Why this answer

Placing subnets in each Availability Zone (AZ) used by the Auto Scaling group allows the group to launch EC2 instances in multiple AZs, which is essential for fault isolation. If one AZ fails, the Auto Scaling group can still launch and maintain instances in the other AZs, ensuring application availability. Without subnets in each AZ, the Auto Scaling group cannot distribute instances across AZs, defeating the purpose of high availability.

Exam trap

The trap here is that candidates often think using a single AZ simplifies management and reduces latency, but they overlook that this creates a critical single point of failure, which is unacceptable for a critical application requiring AZ failure recovery.

686
MCQhard

A SysOps administrator monitors a custom business metric published to Amazon CloudWatch. The metric exhibits irregular spikes that are not predictable. The administrator needs to be alerted when the metric deviates significantly from its normal pattern. Which CloudWatch feature should be used to set up the alarm with the least manual tuning?

A.CloudWatch Logs metric filter
B.CloudWatch Metric Math with standard deviation
C.CloudWatch Anomaly Detection
D.AWS CloudTrail Insights
AnswerC

CloudWatch Anomaly Detection applies machine learning algorithms to analyze a metric's historical behavior, including daily and weekly seasonality, and produces a dynamic baseline band with upper and lower thresholds. For a custom business metric with irregular patterns, these thresholds continually adapt as new data arrives, so you do not need to manually recalibrate for changing normal behavior. It emits an anomaly detection band that can be used in alarms to alert on deviations from expected values.

Why this answer

CloudWatch Anomaly Detection uses machine learning to automatically establish a baseline for a metric's normal pattern and create a band of expected values. When the metric deviates outside this band, it triggers an alarm without requiring manual threshold tuning, making it ideal for unpredictable, irregular spikes.

Exam trap

The trap here is that candidates often confuse CloudWatch Metric Math with standard deviation (Option B) as a way to detect anomalies, but it requires manual formula creation and does not automatically adapt to pattern changes, unlike Anomaly Detection which learns and adjusts the baseline over time.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs metric filters extract metrics from log data, not from custom business metrics published directly to CloudWatch, and they require manual threshold configuration. Option B is wrong because CloudWatch Metric Math with standard deviation requires manual calculation and setup of the standard deviation formula, and it does not automatically adapt to changing patterns over time. Option D is wrong because AWS CloudTrail Insights analyzes API activity for unusual patterns in AWS management events, not custom business metrics published to CloudWatch.

687
MCQhard

A company is using Amazon Route 53 for DNS and wants to route traffic to multiple endpoints based on the geographic location of the user. Which routing policy should the SysOps Administrator use?

A.Geolocation routing
B.Weighted routing
C.Failover routing
D.Latency routing
AnswerA

Geolocation routing is the correct choice because Route 53 uses the geographic location of the user's DNS resolver to determine which record to return. You can create records for continents, countries, or US states and even specify a default record for users in unmatched locations. This enables location-based routing, such as directing users to regional endpoints or enforcing regional restrictions. However, the location is inferred from the resolver's IP address, so it is approximate rather than exact.

Why this answer

Geolocation routing (Option A) is correct because it allows Route 53 to route traffic based on the geographic location of the DNS query's source IP address. This is ideal for scenarios where you need to direct users to specific endpoints based on their country, continent, or even US state, such as complying with data sovereignty laws or delivering localized content.

Exam trap

The trap here is that candidates often confuse geolocation routing with latency routing, assuming that lower latency correlates with geographic proximity, but latency routing uses actual network performance data, not geographic boundaries.

How to eliminate wrong answers

Option B (Weighted routing) is wrong because it distributes traffic across multiple endpoints based on assigned weights (e.g., 80% to one, 20% to another), not based on the user's geographic location. Option C (Failover routing) is wrong because it is designed for active-passive failover scenarios where traffic is routed to a primary endpoint unless it is unhealthy, then it fails over to a secondary endpoint; it does not consider user location. Option D (Latency routing) is wrong because it routes traffic to the endpoint with the lowest latency for the user, which is determined by network performance measurements, not by the user's geographic location.

688
MCQhard

Refer to the exhibit. A SysOps administrator needs to restore the database 'mydb' to the most recent restorable time shown. However, the administrator cannot restore to that time. What is the MOST likely reason?

A.The database engine does not support point-in-time recovery.
B.Automated backups are disabled (BackupRetentionPeriod is 0).
C.The backup window has already passed.
D.The database is not Multi-AZ.
AnswerB

With BackupRetentionPeriod set to 0, automated backups are completely disabled, meaning RDS never takes daily snapshots and does not retain transaction logs for PITR. Without any automated backup or retained log, there is no recovery point available to restore from, which directly explains why the restore fails. Manual snapshots could still be used if they were created separately, but the scenario indicates no usable backup exists for restoration.

Why this answer

Automated backups must be enabled with a BackupRetentionPeriod greater than 0 for point-in-time recovery (PITR) to be available. When BackupRetentionPeriod is set to 0, automated backups are disabled, and the database cannot be restored to any point in time within the retention window. The exhibit shows that the most recent restorable time is not available because no automated backups exist to support PITR.

Exam trap

The trap here is that candidates may assume the most recent restorable time is always available or confuse the backup window with the ability to perform PITR, when in fact the root cause is that automated backups are disabled entirely.

How to eliminate wrong answers

Option A is wrong because all supported RDS database engines (MySQL, PostgreSQL, Oracle, SQL Server, MariaDB, and Aurora) support point-in-time recovery when automated backups are enabled. Option C is wrong because the backup window defines when automated backups are taken, but it does not prevent restoring to the most recent restorable time; the most recent restorable time is determined by the last successful backup and transaction logs, not by whether the backup window has passed. Option D is wrong because Multi-AZ deployment is not a prerequisite for point-in-time recovery; PITR works on single-AZ instances as long as automated backups are enabled.

689
Multi-Selecteasy

A SysOps administrator needs to ensure that an Amazon S3 bucket is not publicly accessible. Which THREE actions should be taken to prevent public access?

Select 3 answers
A.Enable versioning on the bucket.
B.Delete the bucket policy if it exists.
C.Configure the bucket to block new public ACLs using S3 Object Ownership.
D.Review and remove any public ACLs on the bucket and objects.
E.Use the S3 Block Public Access feature at the bucket level.
AnswersC, D, E

Setting S3 Object Ownership to Bucket Owner Enforced disables Access Control Lists for the bucket, which prevents new ACLs—including those that would grant public access—from being created. With ACLs disabled, S3 ignores any ACL-based permissions, and all access is controlled exclusively by bucket policies and IAM policies. This is a preventive, proactive measure that stops future public ACL misconfigurations at the source.

Why this answer

Enabling S3 Object Ownership allows you to disable ACLs on the bucket, which prevents new public ACLs from being applied. This is a key step in ensuring that no objects can be made publicly accessible via ACLs, as ACLs are an older access control mechanism that can grant public read/write access.

Exam trap

The trap here is that candidates might think deleting the bucket policy (option B) is sufficient to prevent public access, but they overlook that public ACLs on objects can still grant public access, and that S3 Block Public Access provides a more comprehensive and enforceable control.

690
Multi-Selectmedium

Which TWO IAM policy conditions can be used to enforce multi-factor authentication (MFA) for API calls? (Choose two.)

Select 2 answers
A.aws:PrincipalType
B.aws:MultiFactorAuthPresent
C.aws:MultiFactorAuthAge
D.aws:TokenIssueTime
E.aws:SourceIp
AnswersB, C

aws:MultiFactorAuthPresent is a boolean condition key that returns true if the principal authenticated with multi-factor authentication, and false otherwise. It can be used with the Bool condition operator to require that MFA was used, for example, "Bool": {"aws:MultiFactorAuthPresent": "true"}. This is a straightforward way to enforce MFA but it only checks the presence, not the age, of the MFA authentication. One caveat is that this key is only meaningful for temporary credentials, so you must ensure callers use temporary sessions (e.g., via GetSessionToken) when applying this restriction.

Why this answer

Option B, aws:MultiFactorAuthPresent, is correct because this boolean condition key evaluates to true when the request is made with temporary credentials that were obtained through MFA, allowing a policy to explicitly deny or allow API calls based on whether MFA was used. Option C, aws:MultiFactorAuthAge, is correct because it checks the elapsed time (in seconds) since the MFA-authenticated session was established, enabling policies to require MFA to have occurred within a maximum age for API calls. Together these two conditions are the standard AWS mechanisms for enforcing MFA on API requests.

Option A, aws:PrincipalType, only distinguishes between account, user, role, or federated principal types and does not indicate MFA usage. Option D, aws:TokenIssueTime, reflects when temporary credentials were issued but does not by itself prove MFA was performed. Option E, aws:SourceIp, restricts requests by source IP address and is unrelated to MFA enforcement.

Exam trap

The trap is assuming that any condition key containing 'Auth' or 'Token' enforces MFA; only aws:MultiFactorAuthPresent and aws:MultiFactorAuthAge are directly tied to MFA status.

691
MCQeasy

A SysOps administrator is responsible for an AWS account that hosts a development environment. The environment includes several EC2 instances that are used only during business hours (9 AM to 5 PM) on weekdays. The administrator wants to reduce costs by stopping the instances during off-hours. Which action should the administrator take to automate this process?

A.Manually stop the instances at 5 PM and start them at 9 AM each weekday.
B.Create an Auto Scaling group with a scheduled scaling action to set desired capacity to 0 during off-hours.
C.Set up a CloudWatch alarm that stops instances when CPU utilization is below 1% for 30 minutes.
D.Use the AWS Instance Scheduler to define a schedule that stops instances at 5 PM and starts them at 9 AM on weekdays.
AnswerD

The AWS Instance Scheduler is a reference solution that deploys AWS Lambda functions and Amazon DynamoDB tables via AWS CloudFormation to automatically issue EC2 StopInstances and StartInstances calls based on user-defined daily or weekly periods. It works by evaluating instance tags against stored schedules, supports time zones, and can handle large fleets across accounts and regions. Because it stops rather than terminates instances, EBS-backed volumes, private IP addresses, and instance IDs are preserved.

Why this answer

AWS Instance Scheduler is a solution that automates the starting and stopping of EC2 instances based on a schedule. It uses Lambda functions and DynamoDB to manage schedules, and it can be configured to stop instances at 5 PM and start them at 9 AM on weekdays, reducing costs during off-hours.

Exam trap

SOA-C02 often tests the difference between stopping and terminating instances, and candidates may incorrectly choose Auto Scaling groups for scheduled start/stop, not realizing that ASG terminates instances.

How to eliminate wrong answers

Option A is wrong because manual stopping is not automated and is error-prone. Option B is wrong because Auto Scaling groups are for dynamic scaling based on demand, not for scheduled start/stop of existing instances; setting desired capacity to 0 would terminate instances, not stop them, and would not preserve instance state. Option C is wrong because CloudWatch alarms based on CPU utilization are for reactive scaling, not scheduled start/stop, and stopping instances based on low CPU could disrupt business hours if utilization is low.

692
MCQeasy

A SysOps administrator needs to route traffic to multiple AWS regions for a global application with low latency. Which AWS service should be used?

A.Amazon CloudFront
B.Amazon Route 53 with latency routing policy
C.Application Load Balancer
D.AWS Global Accelerator
AnswerB

Amazon Route 53's latency routing policy evaluates the measured latency between the user's DNS resolver and each AWS region where you have a resource, then returns the IP address for the region with the lowest latency. This enables multi-region active-active architectures by using DNS to direct each user request to the most responsive endpoint. For a sysops administrator needing to route traffic to multiple AWS regions, this is the correct service because it explicitly performs latency-based regional routing.

Why this answer

Amazon Route 53 with a latency routing policy directs traffic to the AWS region that provides the lowest latency for each user, based on measurements of network round-trip time. This is the correct choice for routing traffic to multiple regions to minimize latency for a global application.

Exam trap

The trap here is that candidates often confuse AWS Global Accelerator with latency-based routing, but Global Accelerator optimizes traffic over the AWS backbone from the edge, not by selecting the lowest-latency region based on DNS queries.

How to eliminate wrong answers

Option A is wrong because Amazon CloudFront is a content delivery network (CDN) that caches content at edge locations, not a service that routes traffic to multiple AWS regions based on latency. Option C is wrong because an Application Load Balancer distributes traffic within a single AWS region and cannot route traffic across multiple regions. Option D is wrong because AWS Global Accelerator uses Anycast IPs to route traffic to the nearest edge location, but it does not use latency-based routing to select the optimal AWS region; it relies on static IP addresses and the AWS global network.

693
MCQmedium

A company uses AWS CloudFormation to manage infrastructure. The SysOps administrator needs to update a stack that contains a critical database. The update may require a replacement of the database resource. The administrator wants to review the changes before they are applied. What is the BEST way to achieve this?

A.Use the AWS CloudFormation update-stack command with the --no-fail-on-empty-changeset flag.
B.Apply a stack policy that prevents replacement of the database resource.
C.Use the AWS CloudFormation create-change-set command and then review the changes before executing.
D.Use the AWS CloudFormation detect-stack-drift command to check for differences.
AnswerC

The create-change-set command constructs a change set that describes the modifications CloudFormation would make to the stack if the updated template were applied, without actually changing any resources. You can then use describe-change-set or the CloudFormation console to review every resource action (Add, Modify, Remove) including property details and whether a replacement will occur, before you decide to call execute-change-set. This two-phase approach is specifically designed to give you a safe, non-destructive preview of the update, which is exactly what the question requires.

Why this answer

Creating a change set allows you to review all changes, including replacements, before executing them. Option A is incorrect because the '--no-fail-on-empty-changeset' flag does not provide a review. Option B is incorrect because a stack policy can protect resources but does not allow reviewing changes.

Option D is incorrect because the drift detection feature detects drift, not planned changes.

694
MCQeasy

A company has an S3 bucket that stores critical financial data. The bucket versioning is enabled. A SysOps administrator needs to ensure that data can be recovered after accidental deletion by users. What is the MOST effective way to protect against accidental deletion?

A.Configure a lifecycle policy to transition objects to Glacier after 30 days.
B.Apply a bucket policy that denies s3:DeleteObject for all users.
C.Replicate objects to another S3 bucket in a different AWS Region.
D.Enable MFA Delete on the S3 bucket.
AnswerD

MFA Delete, when enabled on a versioned S3 bucket, requires the bucket owner to present the root credential plus a valid MFA code for two operations: changing the bucket's versioning state and permanently deleting object versions. An ordinary DeleteObject request without a version ID only creates a delete marker, while any attempt to hard-delete a specific version without the MFA token fails. This prevents an authorized but careless user from irretrievably removing critical financial data.

Why this answer

MFA Delete adds an additional authentication factor (a hardware or virtual MFA device) that must be provided to permanently delete an object version or to change the versioning state of the bucket. This makes accidental or malicious deletion significantly harder because a compromised access key alone is insufficient. It is the most effective control specifically designed to protect versioned S3 data from deletion.

Exam trap

SOA-C02 often tests the misconception that bucket policies or cross-region replication prevent accidental deletion, when in fact only MFA Delete (or Object Lock) provides a strong, version-level deletion protection mechanism for versioned buckets.

How to eliminate wrong answers

Option A is wrong because a lifecycle policy transitions objects to Glacier for cost optimization; it does not prevent deletion and may even delete objects if configured with expiration actions. Option B is wrong because a bucket policy denying s3:DeleteObject can be modified or removed by an administrator with sufficient permissions, and it does not protect against accidental deletion by users who have policy-editing rights; it also does not address version deletion. Option C is wrong because cross-region replication provides durability and disaster recovery but does not prevent deletion in the source bucket — if an object is deleted in the source, replication can propagate the deletion to the destination depending on configuration.

695
MCQmedium

Refer to the exhibit. A SysOps administrator creates an IAM policy to allow an EC2 instance to upload objects to an S3 bucket. However, the instance is unable to upload objects. What is the MOST likely reason?

A.The S3 bucket has server-side encryption enabled.
B.The policy does not include s3:GetObject permission.
C.The bucket policy denies all access.
D.The IAM role is not attached to the EC2 instance.
AnswerD

An EC2 instance can only use IAM permissions if an instance profile containing a role is attached at launch time or later. Without an attached role, the instance has no AWS credentials to sign API requests, so any S3 operation (including upload) fails with an error such as 'Unable to locate credentials' or an access denied error because the request is not authenticated with an authorized IAM identity. The role must be attached to the EC2 instance and the instance must have the necessary permissions in its trust and permissions policies. This is the root cause of the upload failure.

Why this answer

The IAM role must be attached to the EC2 instance as an instance profile for the instance to assume the role and obtain temporary credentials. Without this attachment, the instance has no valid AWS credentials to sign API requests, so the s3:PutObject action will fail regardless of the permissions defined in the role's policy.

Exam trap

The trap here is that candidates often assume the IAM policy alone is sufficient, forgetting that the EC2 instance must have a mechanism (the instance profile) to assume the role and obtain credentials.

How to eliminate wrong answers

Option A is wrong because server-side encryption (SSE) does not inherently block uploads; the instance can still upload objects if it has the correct permissions and the bucket policy does not explicitly deny access. Option B is wrong because the policy only needs s3:PutObject to upload objects; s3:GetObject is required for reading, not writing. Option C is wrong because the question states the policy allows uploads, and a bucket policy that denies all access would be an explicit deny, but the most likely reason given the scenario is the missing attachment of the IAM role to the instance.

696
MCQhard

A company has a multi-account AWS environment using AWS Organizations. The SysOps Administrator needs to deploy a standardized set of baseline resources (VPC, subnets, security groups, and an S3 bucket for logs) into each new member account as soon as the account is created. The administrator wants to automate this process using AWS CloudFormation and ensure that the baseline resources are deployed without manual intervention. The organization uses AWS CloudTrail and AWS Config for governance. What solution should the administrator implement?

A.Use AWS CloudFormation StackSets with automatic deployment to accounts in the organization.
B.Create an AWS Config rule that triggers an AWS Lambda function to deploy the baseline resources when a new account is created.
C.Store the CloudFormation template in Amazon S3 and use S3 event notifications to trigger a Lambda function that deploys the stack into the new account.
D.Use AWS Service Catalog to create a portfolio with the baseline products and grant access to the organization.
AnswerA

AWS CloudFormation StackSets with automatic deployment is the native, service-integrated method for account baselining. When a new account is added to an AWS Organization, StackSets with service-managed permissions automatically creates stack instances in that account, using the organization's trusted access to deploy the baseline template. This eliminates the need for custom event-driven orchestration and ensures consistent governance across the entire organization.

Why this answer

AWS CloudFormation StackSets with automatic deployment is purpose-built for this scenario: it deploys a single template across multiple accounts in an AWS Organization and can automatically push the stack to new member accounts as they are added. The 'automatic deployment' setting enables StackSets to target the entire OU or organization, so new accounts inherit the baseline resources without manual intervention. This directly satisfies the requirement to deploy VPC, subnets, security groups, and an S3 log bucket into each new account automatically.

Exam trap

SOA-C02 often tests the difference between reactive compliance tools (AWS Config, Trusted Advisor) and proactive provisioning tools (StackSets, Service Catalog); candidates wrongly pick Config or Lambda-based automation when the question asks for automatic deployment to new accounts.

How to eliminate wrong answers

Option B is wrong because AWS Config rules are for evaluating resource compliance, not for provisioning resources; triggering a Lambda from a Config rule is a reactive, custom-coded workaround that does not natively handle new account creation events. Option C is wrong because S3 event notifications only fire on object-level events within a bucket and have no awareness of new AWS account creation, so the Lambda would never be triggered by account creation. Option D is wrong because AWS Service Catalog requires end users to manually launch products from a portfolio; it does not automatically deploy resources into newly created accounts.

697
MCQmedium

A company has deployed a web application across multiple AWS regions and wants to use Amazon Route 53 to direct users to the region with the lowest latency. Which routing policy should the SysOps administrator use?

A.Latency routing policy
B.Geolocation routing policy
C.Geoproximity routing policy
D.Weighted routing policy
AnswerA

The latency routing policy selects the AWS region that gives the requesting user the lowest network latency by comparing real-time latency measurements from the client's DNS resolver to each configured regional endpoint. It is the only policy among these that makes a routing decision based on actual network path performance rather than a static geographic or weighting rule, so it matches the requirement to route users to the fastest-performing region for the web application.

Why this answer

Latency routing policy is correct because it directs user traffic to the AWS region that provides the lowest network latency for the end user. Route 53 measures latency between the user's DNS resolver and each region's edge location, then responds with the IP of the region that has the lowest latency. This is ideal for multi-region deployments where the goal is to minimize response time.

Exam trap

The trap here is that candidates confuse 'geolocation' (based on user's physical location) with 'latency' (based on actual network performance), assuming that the closest geographic region always has the lowest latency, which is not true due to network routing and peering differences.

How to eliminate wrong answers

Option B is wrong because geolocation routing policy routes traffic based on the geographic location of the user (e.g., country or continent), not on real-time network latency, so it cannot guarantee the lowest latency. Option C is wrong because geoproximity routing policy routes traffic based on the physical distance between the user and the resource, optionally using a bias value, but it does not measure actual network latency. Option D is wrong because weighted routing policy distributes traffic across resources based on assigned weights (e.g., 80% to one region, 20% to another), which is used for load balancing or testing, not for latency optimization.

698
MCQeasy

A company uses AWS OpsWorks for configuration management. The SysOps administrator needs to deploy a new application version to a stack. What is the recommended way to update the application on the instances?

A.Create a new CloudFormation stack to replace the OpsWorks stack.
B.Update the custom cookbook and run the 'deploy' recipe on the stack.
C.Use the OpsWorks built-in 'deploy' command on each instance.
D.SSH into each instance and manually update the application files.
AnswerB

Updating the custom cookbook source (e.g., S3, Git, or HTTP) on the OpsWorks stack and then running the 'deploy' lifecycle recipe is the correct and intended method for rolling out application changes. The deploy recipe triggers a stack-wide command that executes your custom Chef recipes on all online instances in the selected layer or stack, following the defined deployment lifecycle (before_deploy, deploy, after_deploy). This ensures all instances receive the same application update in a coordinated, automated fashion, and because OpsWorks uses Chef, the recipe can handle dependencies, configuration templates, and service restarts consistently across the fleet.

Why this answer

AWS OpsWorks uses recipes and custom cookbooks to manage application deployment. To deploy a new version, the SysOps administrator should update the custom cookbook with the new application code or configuration and then run the 'deploy' recipe on the stack. This triggers the deployment process on all instances automatically.

Option A is incorrect because creating a new CloudFormation stack is not the recommended approach for updating an existing OpsWorks stack; CloudFormation is a different service for infrastructure as code. Option C is incorrect because the OpsWorks built-in 'deploy' command is meant for straightforward deployments and may not support custom cookbooks or complex application logic. Option D is incorrect because manually SSH-ing into each instance is not scalable and defeats the purpose of automation.

699
MCQmedium

A company uses AWS Organizations with multiple accounts. The SysOps administrator needs to centralize the monitoring of all API calls made in any account for security analysis. The solution must collect logs from all accounts, both existing and future, and deliver them to a centralized S3 bucket in the management account. Which AWS service should the administrator use?

A.AWS Config aggregator
B.Amazon CloudWatch Logs with cross-account subscription
C.AWS CloudTrail organization trail
D.Amazon Detective
AnswerC

An organization trail is created in the management account and, when the 'Enable for all accounts in my organization' option is selected, automatically captures API activity for every account in AWS Organizations, including accounts that join later. The event logs are delivered to a single S3 bucket designated by the management account, making it a centralized, scalable solution. This native integration eliminates the need to configure CloudTrail per member account.

Why this answer

AWS CloudTrail organization trails allow you to log all API calls across all accounts in an AWS Organization from a single management account. When you create an organization trail, it automatically applies to all existing and future accounts, delivering logs to a centralized S3 bucket in the management account without requiring per-account configuration.

Exam trap

The trap here is that candidates confuse AWS Config aggregator (which centralizes configuration data) with CloudTrail (which centralizes API call logs), or assume cross-account CloudWatch Logs subscriptions are the simpler solution, missing the automatic future-account coverage of an organization trail.

How to eliminate wrong answers

Option A is wrong because AWS Config aggregator collects configuration snapshots and compliance data, not API call logs; it is designed for resource inventory and rule evaluation, not security analysis of API activity. Option B is wrong because Amazon CloudWatch Logs with cross-account subscription requires manual setup for each account and does not automatically include future accounts; it also does not natively capture all API calls (CloudTrail is the service for API logging). Option D is wrong because Amazon Detective analyzes and visualizes security data from existing logs (like VPC Flow Logs and CloudTrail), but it does not collect or centralize API call logs itself; it relies on other services to deliver the data.

700
MCQhard

A company has a VPC with a public subnet and a private subnet. An EC2 instance in the private subnet needs to download patches from the internet. The company has a NAT gateway in the public subnet. Which of the following route table configurations is required for the private subnet to enable internet access through the NAT gateway?

A.Add a route to 0.0.0.0/0 pointing to the internet gateway in the private subnet route table
B.Add a route to 0.0.0.0/0 pointing to the NAT gateway in the private subnet route table
C.Add a route to 0.0.0.0/0 pointing to the NAT gateway in the public subnet route table
D.Add a route to the NAT gateway's private IP in the private subnet route table
AnswerB

By associating the private subnet's route table with a default route targeted at the NAT gateway, all outbound IPv4 traffic is forwarded to the NAT gateway in the public subnet, which then translates the source address and forwards the traffic to the internet gateway. This lets private instances initiate outbound connections while keeping them unaddressable from the internet, and unsolicited inbound traffic is blocked because the NAT gateway only allows responses to established outbound flows.

Why this answer

A private subnet route table must have a default route (0.0.0.0/0) pointing to the NAT gateway's elastic network interface (ENI) to forward outbound internet traffic from private instances through the NAT gateway. The NAT gateway, residing in the public subnet, then uses its own route table with a route to the internet gateway (IGW) to reach the internet. Without this route, traffic from the private subnet would have no path to the internet.

Exam trap

The trap here is that candidates often confuse the route table that needs modification, thinking the public subnet route table must be updated, when in fact it is the private subnet route table that requires the default route pointing to the NAT gateway.

How to eliminate wrong answers

Option A is wrong because adding a route to 0.0.0.0/0 pointing to the internet gateway in the private subnet route table would attempt to send traffic directly to the IGW, but the IGW requires a public IP or Elastic IP on the source instance; private instances lack public IPs, so traffic would be dropped. Option C is wrong because the public subnet route table already has a route to the IGW for 0.0.0.0/0; adding a route to the NAT gateway there would not help private instances, as the private subnet route table is the one that controls outbound traffic from the private subnet. Option D is wrong because adding a route to the NAT gateway's private IP in the private subnet route table would only allow traffic destined specifically to that IP, not general internet traffic; a default route (0.0.0.0/0) is required to forward all outbound traffic to the NAT gateway.

701
Multi-Selectmedium

A SysOps administrator is designing a highly available web application across multiple AWS regions. The application uses an Application Load Balancer in each region. Which TWO services can be used to route traffic to the closest regional load balancer based on latency?

Select 2 answers
A.AWS Global Accelerator
B.Amazon Route 53 geoproximity routing
C.Amazon Route 53 weighted routing
D.Amazon Route 53 latency-based routing
E.Amazon CloudFront with origin groups
AnswersA, D

AWS Global Accelerator routes traffic over the AWS global network to the endpoint with the lowest latency, using anycast IP addresses that direct users to the nearest edge location. This satisfies the requirement to reach the closest regional Application Load Balancer, unlike DNS-based routing which depends on resolver caching and TTL behaviour.

Why this answer

Option A (AWS Global Accelerator) is correct because it uses the AWS global network and anycast IP addresses to route user traffic to the optimal regional endpoint based on latency and health, and it can front Application Load Balancers in multiple regions. Option D (Amazon Route 53 latency-based routing) is correct because it returns the regional record whose AWS Region has the lowest measured latency to the requesting resolver, directing users to the closest regional ALB. Option B (geoproximity routing) routes based on geographic location and optional bias, not measured network latency, so it does not meet the stated requirement.

Option C (weighted routing) distributes traffic by assigned proportions regardless of latency, so it is not latency-based. Option E (CloudFront with origin groups) is for origin failover within a distribution and does not route to the closest regional load balancer by latency.

Exam trap

SOA-C02 often tests the distinction between latency-based routing and geoproximity routing — candidates may pick geoproximity thinking it means 'closest,' but it is geographic, not latency-based, and does not measure actual network performance.

702
MCQeasy

A company wants to distribute content globally with low latency and high transfer speeds. The content is stored in S3 buckets in multiple regions. Which AWS service should be used to accelerate content delivery?

A.Amazon Route 53
B.Amazon CloudFront
C.AWS Global Accelerator
D.S3 Transfer Acceleration
AnswerB

Amazon CloudFront is a content delivery network (CDN) that caches copies of content at edge locations worldwide, so users receive data from a nearby point of presence instead of the origin server. This reduces round-trip latency and offloads the origin, providing fast, consistent distribution. It integrates with S3, EC2, and custom origins, and supports features like SSL termination, geo-restriction, and Lambda@Edge for edge processing.

Why this answer

Amazon CloudFront is AWS's content delivery network (CDN), designed to cache and serve content from edge locations worldwide with low latency and high transfer speeds. It integrates natively with S3 origins across regions and can use origin groups or multiple origins for failover. This directly matches the requirement to accelerate global content delivery.

Exam trap

SOA-C02 often tests the confusion between CloudFront (CDN for caching HTTP content) and Global Accelerator (network-layer acceleration for TCP/UDP), and candidates frequently pick Global Accelerator because both claim to improve global performance.

How to eliminate wrong answers

Option A is wrong because Route 53 is a DNS service that routes users to endpoints based on latency, geolocation, or failover, but it does not cache content or accelerate transfer speeds at the edge. Option C is wrong because AWS Global Accelerator improves performance for TCP/UDP traffic using the AWS global network and anycast IPs, but it is not a content caching CDN and is better suited to non-HTTP workloads or dynamic applications. Option D is wrong because S3 Transfer Acceleration speeds up uploads and downloads to a single S3 bucket using edge locations, but it does not distribute cached content globally or serve as a CDN.

703
MCQmedium

An organization uses AWS OpsWorks to manage a stack of application servers. The stack uses a custom cookbook that is stored in a private GitHub repository. When deploying new instances, the cookbook download fails. What should the administrator do to resolve this?

A.Upload the cookbook to Amazon S3 and reference the S3 URL
B.Make the GitHub repository public
C.Configure an SSH key in the OpsWorks stack to access the private repository
D.Store the GitHub credentials in the OpsWorks stack settings
AnswerC

Configuring an SSH key in the OpsWorks stack is the correct method because OpsWorks natively supports private Git repositories by letting you supply a private SSH key in the Repository SSH Key field for custom cookbooks. You add the matching public key as a deploy key on the GitHub repository with read-only access, and OpsWorks uses that key to authenticate when it downloads or updates cookbooks on your instances. This keeps the repository private and avoids storing plaintext credentials, while also allowing Chef to automatically pull the latest cookbook revisions during stack updates and instance setup.

Why this answer

AWS OpsWorks needs credentials to clone a cookbook from a private GitHub repository. The correct approach is to configure an SSH key (deploy key) in the OpsWorks stack settings so that the instance can authenticate to GitHub during the cookbook download. This allows OpsWorks to securely access the private repository without exposing credentials in the cookbook or making the repository public.

Exam trap

SOA-C02 often tests the misconception that storing credentials in stack settings or making repositories public is acceptable, when the correct and secure method is configuring an SSH deploy key.

How to eliminate wrong answers

Option A is wrong because uploading the cookbook to Amazon S3 changes the source repository and does not address the underlying authentication issue with private GitHub repositories; it also bypasses the intended workflow. Option B is wrong because making the repository public is a security risk and violates the principle of least privilege, and it is not a recommended solution for private code. Option D is wrong because storing GitHub credentials in OpsWorks stack settings is not the supported mechanism; OpsWorks expects an SSH key for private repository access, and storing plaintext credentials is insecure.

704
MCQmedium

A company hosts a web application on EC2 instances behind an Application Load Balancer (ALB). The application experiences variable traffic patterns with occasional spikes. The current setup uses On-Demand instances in an Auto Scaling group with a simple scaling policy based on average CPU utilization. The team wants to optimize cost while ensuring that the application can handle spikes in traffic. What should the team do to reduce cost?

A.Switch to a target tracking scaling policy based on request count per target.
B.Implement scheduled scaling to add capacity during known peak hours.
C.Configure the Auto Scaling group to use a mixed instances policy with Spot Instances for a portion of the capacity and On-Demand for the remainder.
D.Purchase Reserved Instances for the minimum expected capacity to get a discount.
AnswerC

A mixed instances policy lets an Auto Scaling group launch both Spot and On-Demand Instances, with the ability to define a percentage split (e.g., 50% On-Demand and 50% Spot) across multiple instance types. Spot Instances can be 60–90% cheaper than On-Demand, so running a portion of the spike capacity on Spot delivers significant cost savings. The On-Demand portion maintains a stable baseline, while the Spot portion absorbs burst capacity; if Spot capacity is reclaimed, the group can optionally fall back to On-Demand, preserving availability and making this the most cost-effective, resilient choice for variable traffic.

Why this answer

A mixed instances policy lets the Auto Scaling group blend Spot Instances (up to ~90% cheaper than On-Demand) for the stateless, interruption-tolerant portion of the web tier with On-Demand instances as a stable baseline. This directly reduces compute cost while the ASG still scales out to absorb traffic spikes, and Spot capacity pools across multiple instance types/AZs improve availability. It is the only option that changes the pricing model of the existing capacity rather than just the scaling trigger.

Exam trap

SOA-C02 often tests the difference between changing the scaling policy (which affects responsiveness) and changing the purchasing model (which affects cost) — candidates pick the scaling option when the question explicitly asks for cost reduction.

How to eliminate wrong answers

Option A is wrong because switching to a target tracking policy based on request count per target only changes the scaling metric — it does not reduce the hourly price of the instances, so cost is not optimized. Option B is wrong because scheduled scaling assumes predictable peak hours, but the scenario explicitly states variable traffic with occasional spikes, so scheduled actions would either over-provision or miss spikes. Option D is wrong because Reserved Instances require a 1- or 3-year commitment for a steady baseline; with variable traffic and spikes, RIs would be underutilized during troughs and still require On-Demand/Spot for the peaks, so it does not address the spike-handling requirement.

705
MCQmedium

Refer to the exhibit. A SysOps administrator is troubleshooting a CloudFront distribution that serves content from an S3 bucket. Users are receiving 'Access Denied' errors when trying to access objects. The exhibit shows the distribution configuration. What is the most likely cause?

A.The S3 bucket policy does not grant read access to CloudFront.
B.The distribution is not enabled.
C.The CloudFront distribution is not using an Origin Access Identity (OAI) to authenticate with the S3 bucket.
D.The viewer protocol policy is set to 'redirect-to-https', but users are using HTTP.
AnswerC

This is the correct diagnosis: for a private S3 bucket, CloudFront must use an Origin Access Identity to authenticate its requests. Without an OAI, CloudFront does not sign the origin request with a recognized AWS identity, so S3 treats it as anonymous and denies access. The fix involves creating an OAI, associating it with the distribution's S3 origin, and updating the bucket policy to allow that OAI the `s3:GetObject` permission.

Why this answer

The exhibit shows that the Origin Access Identity (OAI) field is empty, meaning CloudFront is not using an OAI to authenticate with the S3 bucket. Without an OAI, CloudFront relies on the bucket being publicly accessible, but by default S3 buckets are private. Therefore, CloudFront cannot access the objects, resulting in 'Access Denied' errors.

Option A is not evident from the exhibit; the bucket policy is not shown. Option B is incorrect because the distribution status is 'Enabled' in the exhibit. Option D is incorrect because the viewer protocol policy 'Redirect HTTP to HTTPS' would redirect users, not cause Access Denied.

706
Multi-Selectmedium

A company runs a stateless web application on EC2 instances in an Auto Scaling group. To improve reliability during a traffic spike, which THREE actions should the SysOps administrator take? (Choose three.)

Select 3 answers
A.Configure a target tracking scaling policy based on average CPU utilization.
B.Enable detailed monitoring for EC2 instances.
C.Use a larger instance type to handle more traffic per instance.
D.Configure the Auto Scaling group to launch instances in multiple Availability Zones.
E.Place the instances behind an Application Load Balancer with health checks.
AnswersA, D, E

A target tracking scaling policy automatically adjusts the Auto Scaling group's desired capacity based on a CloudWatch metric, such as average CPU utilization, to keep the metric close to a specified target value. For a stateless web app with varying traffic, this provides true elasticity, scaling out to handle spikes and scaling in when demand falls, without manual intervention. Because it directly maps load to capacity, it is the most effective single choice among the listed options.

Why this answer

A target tracking scaling policy based on average CPU utilization allows the Auto Scaling group to automatically adjust the number of EC2 instances in response to traffic spikes. This policy maintains the target metric (e.g., 50% CPU) by adding or removing instances, ensuring the application remains responsive without manual intervention. It is a key mechanism for improving reliability under variable load.

Exam trap

The trap here is that candidates often confuse detailed monitoring (which only improves metric granularity) with a direct reliability improvement, or they mistakenly believe that scaling up (larger instances) is equivalent to scaling out (more instances) for fault tolerance.

707
MCQmedium

A SysOps administrator is deploying a new version of an application using AWS CodeDeploy with an in-place deployment configuration. The deployment group consists of EC2 instances behind an Application Load Balancer. The administrator wants to ensure that traffic is gradually shifted to the new version. Which CodeDeploy feature should be used?

A.Use a canary deployment instead of in-place.
B.Define a BeforeInstall hook to deregister instances.
C.Use a linear deployment configuration.
D.Configure the load balancer deregistration delay and re-registration in the deployment group.
AnswerD

Configuring the deregistration delay on the load balancer target group and enabling CodeDeploy's load balancer integration ensures that CodeDeploy automatically deregisters each instance, waits for in-flight requests to complete (based on the deregistration delay), performs the deployment, and then re-registers the instance. This built-in integration is the recommended way to avoid downtime during in-place deployments. CodeDeploy also waits for the instance to pass health checks before marking the deployment successful. This configuration is set in the deployment group's load balancer section.

Why this answer

Configuring the load balancer deregistration delay and re-registration in the deployment group allows CodeDeploy to control how instances are gradually removed from and added back to the ALB target group. This enables a controlled traffic shift during an in-place deployment by waiting for in-flight requests to complete (via deregistration delay) before rerouting traffic to the new version, and then re-registering instances after the new application is healthy.

Exam trap

The trap here is that candidates often confuse the deployment configuration (e.g., linear, canary) with traffic shifting mechanics, not realizing that in-place deployments require explicit load balancer settings to gradually shift traffic, whereas blue/green deployments handle traffic shifting natively via the load balancer.

How to eliminate wrong answers

Option A is wrong because using a canary deployment would change the deployment type from in-place to blue/green, which is not what the question specifies; the requirement is to gradually shift traffic within an in-place deployment. Option B is wrong because defining a BeforeInstall hook to deregister instances is a manual, script-based approach that does not leverage CodeDeploy's built-in traffic shifting controls and can lead to race conditions or incomplete traffic draining. Option C is wrong because a linear deployment configuration controls the rate at which instances are updated (e.g., percentage per interval), but it does not inherently manage traffic shifting through the load balancer; traffic shifting requires explicit integration with the ALB's deregistration and re-registration settings.

708
MCQmedium

A company is using Amazon RDS for MySQL. The SysOps administrator needs to monitor the number of database connections and set an alarm when connections exceed 80% of the maximum. Which CloudWatch metric and alarm threshold should be used?

A.Metric: DBConnections; Threshold: 80
B.Metric: DatabaseConnections; Threshold: 80
C.Metric: FreeableMemory; Threshold: 20%
D.Metric: DatabaseConnections; Threshold: 0.8 * max_connections (using a math expression)
AnswerD

The correct alarm should use the `DatabaseConnections` metric in a metric math expression that compares current connections to 80% of the `max_connections` value. Because `max_connections` is not emitted as a standard RDS CloudWatch metric, you can publish it as a custom metric (updated by a script that reads the DB parameter group) and create an expression like `m1 > 0.8 * m2` to compute the threshold dynamically. This approach self-adjusts if the instance class or parameter group is changed, avoiding the false positives and negatives that come with hard-coded thresholds while targeting the exact `DatabaseConnections` metric that tracks session count.

Why this answer

Amazon RDS for MySQL does not expose a direct 'DatabaseConnections' metric that represents the current connection count relative to the maximum. Instead, you must use the 'DatabaseConnections' CloudWatch metric (which reports the number of client connections) and create a CloudWatch math expression to compare it against the RDS instance's 'max_connections' parameter (e.g., 0.8 * max_connections). This allows you to set an alarm that triggers when connections exceed 80% of the configured maximum, which is the accurate way to monitor connection utilization.

Exam trap

The trap here is that candidates assume a static threshold like 80 is sufficient, but the exam tests whether you understand that 'DatabaseConnections' must be compared against the dynamic 'max_connections' value using a math expression to accurately detect 80% utilization.

How to eliminate wrong answers

Option A is wrong because 'DBConnections' is not a valid CloudWatch metric name for RDS; the correct metric is 'DatabaseConnections'. Option B is wrong because while 'DatabaseConnections' is the correct metric name, setting a static threshold of 80 is meaningless—80 connections could be far below or above 80% of max_connections depending on the instance size and configuration. Option C is wrong because 'FreeableMemory' measures available memory, not database connections, and a threshold of 20% is unrelated to connection utilization; it monitors memory pressure, not connection limits.

709
MCQhard

A company runs a critical stateful web application on Amazon EC2 instances in a single AWS region. The application stores user session data in an Amazon ElastiCache for Redis cluster. The SysOps administrator must design a disaster recovery (DR) strategy that can survive a complete regional outage with a Recovery Point Objective (RPO) of 15 minutes and a Recovery Time Objective (RTO) of 1 hour. The application must be able to redirect users to the DR region with minimal manual effort. Which combination of actions meets these requirements?

A.Use Amazon Route 53 with weighted routing to distribute traffic between the two regions. Use a global DynamoDB table for session data, and launch EC2 instances in the DR region only when a failure is detected using AWS CloudFormation StackSets.
B.Create a read replica of the ElastiCache Redis cluster in the DR region using the native cross-region replication feature. Use Route 53 with failover routing to point to the DR region ALB when the primary health check fails. Pre-configure EC2 instances in an Auto Scaling group in the DR region.
C.Use an Amazon CloudFront distribution with multiple origins (primary and DR). Enable session stickiness at the CloudFront level. Use EC2 instances in both regions behind separate ALBs. No special data replication is needed because sessions are stored in Redis.
D.Use EC2 instances with an Auto Scaling group in both regions. Schedule a Lambda function to take snapshots of the Redis cluster every 15 minutes and copy them to the DR region. Use Route 53 latency routing to direct users to the nearest region.
AnswerB

Global Datastore for Redis provides cross-Region replication with low RPO. Pre-configured Auto Scaling groups in the DR region ensure that compute capacity is ready. Route 53 failover routing automatically redirects traffic when the primary ALB health check fails. This combination meets the RPO and RTO requirements with minimal manual effort.

Why this answer

ElastiCache for Redis supports cross-region replication via a read replica in the DR region, which can keep session data synchronized with minimal lag, meeting the 15-minute RPO. Route 53 failover routing with health checks on the primary region's ALB automatically redirects traffic to the pre-configured DR region EC2 instances and ALB, achieving the 1-hour RTO with minimal manual effort. Pre-configuring the DR region with an Auto Scaling group ensures compute capacity is ready, while the read replica provides the required data availability.

Exam trap

The trap here is that candidates may assume snapshot-based replication (Option D) is sufficient for a 15-minute RPO, but they overlook the inherent latency and potential data loss from periodic snapshots, and that latency routing (Option D) does not provide health-based failover, while weighted routing (Option A) lacks automatic failover capability.

How to eliminate wrong answers

Option A is wrong because weighted routing does not automatically fail over during a regional outage; it distributes traffic based on weights, not health, and using a global DynamoDB table for session data is unnecessary since the application uses ElastiCache for Redis, not DynamoDB. Option C is wrong because CloudFront does not natively support session stickiness based on ElastiCache session data, and without cross-region replication of Redis, the DR region would have no session data, violating the RPO. Option D is wrong because scheduling snapshots every 15 minutes and copying them to the DR region cannot guarantee an RPO of 15 minutes due to snapshot timing and transfer delays, and latency routing does not provide automatic failover during a regional outage; it routes based on latency, not health.

710
Multi-Selecthard

An organization uses Amazon CloudWatch Synthetics canaries to monitor its web application endpoints. A SysOps administrator needs to be alerted when a canary run fails. Which THREE steps are required to set up this alerting?

Select 3 answers
A.Create a custom CloudWatch metric for canary failures.
B.Configure a CloudWatch alarm on the canary's `SuccessPercent` metric.
C.Create a canary in CloudWatch Synthetics.
D.Configure the alarm to send a notification to an SNS topic.
E.Enable detailed monitoring on the canary.
AnswersB, C, D

SuccessPercent is a native CloudWatch Synthetics metric that represents the percentage of successful canary runs during a given period. Configuring a CloudWatch alarm on this metric, with a threshold such as a drop below 99 percent, directly triggers an ALARM state when reliability degrades. This approach uses the existing metric stream, so no custom code or additional metrics are required, and it supports standard alarm features like evaluation periods and actions.

Why this answer

CloudWatch Synthetics canaries automatically publish a `SuccessPercent` metric to CloudWatch. By configuring a CloudWatch alarm on this metric (e.g., when `SuccessPercent` drops below 100), the administrator can trigger an alert whenever a canary run fails. This is the standard method for monitoring canary health without needing custom metrics.

Exam trap

The trap here is that candidates assume they must create a custom metric (Option A) or enable detailed monitoring (Option E) because they confuse Synthetics canaries with EC2 detailed monitoring, when in fact the built-in `SuccessPercent` metric is sufficient and automatically available.

711
MCQmedium

A company runs a stateless web application on Amazon EC2 instances in an Auto Scaling group across two Availability Zones. The SysOps administrator needs to ensure that the application can tolerate a failure of an entire Availability Zone. Which configuration is required?

A.Use an Application Load Balancer (ALB) that spans both Availability Zones with health checks enabled.
B.Enable termination protection on all Amazon EC2 instances.
C.Place the Amazon EC2 instances in a cluster placement group.
D.Associate an Elastic IP address with the primary instance.
AnswerA

An Application Load Balancer (ALB) is a regional service that spans all Availability Zones (AZs) in its subnet configuration and actively sends health-check requests to each registered target. When an EC2 instance or an entire AZ fails health checks, the ALB automatically stops routing new traffic to that target and continues serving requests from healthy instances in other AZs. Coupled with an Auto Scaling group that spans multiple AZs, this design provides both elasticity and zone-failure tolerance, because the ALB constantly updates its target membership based on instance health and scaling events.

Why this answer

An Application Load Balancer (ALB) that spans both Availability Zones with health checks enabled distributes incoming traffic across EC2 instances in multiple AZs. If an entire AZ fails, the ALB automatically routes traffic only to healthy instances in the remaining AZ, ensuring the stateless web application remains available. Health checks detect instance or AZ failure and remove unhealthy targets from the load balancer's target group, which is essential for fault tolerance.

Exam trap

The trap here is that candidates often confuse high availability with data durability or instance protection, leading them to choose termination protection or Elastic IPs, when the core requirement is automatic traffic rerouting across AZs, which only a load balancer with health checks can provide.

How to eliminate wrong answers

Option B is wrong because termination protection prevents accidental deletion of an instance but does not provide any resilience against an Availability Zone failure; it does not reroute traffic or maintain application availability. Option C is wrong because a cluster placement group is designed for low-latency, high-throughput networking within a single AZ; it actually increases the risk of simultaneous failure if that AZ goes down, as all instances are in the same AZ. Option D is wrong because associating an Elastic IP with the primary instance only provides a static public IP, which does not survive an AZ failure and does not offer automatic failover or load balancing across AZs.

712
Multi-Selectmedium

Which TWO actions should a SysOps administrator take to set up centralized logging from multiple Amazon EC2 instances running Amazon Linux 2 to Amazon CloudWatch Logs?

Select 2 answers
A.Attach an IAM role to each EC2 instance that includes permission for logs:PutLogEvents.
B.Create an S3 bucket and configure the EC2 instances to write logs directly to the bucket.
C.Install and configure the unified CloudWatch agent on each EC2 instance.
D.Create a VPC endpoint for CloudWatch Logs to allow private connectivity.
E.Export the logs from CloudWatch Logs to an Amazon S3 bucket for long-term retention.
AnswersA, C

Attaching an instance profile IAM role with logs:PutLogEvents is essential because the CloudWatch agent requires AWS credentials to authenticate and authorize its log writes; without this role, the agent will fail CloudWatch Logs API calls such as CreateLogStream and PutLogEvents. The role is scoped to the EC2 instance via the instance profile, eliminating the need to embed static keys in the AMI or on the instance. This is the foundational security prerequisite for any log collection, and it should also include permissions for DescribeLogStreams and CreateLogGroup if you want the agent to manage those resources automatically.

Why this answer

The EC2 instances need an IAM role with the logs:PutLogEvents permission to authenticate and authorize log delivery to CloudWatch Logs. Without this permission, the CloudWatch agent cannot send log data to the log stream, resulting in authorization failures.

Exam trap

The trap here is that candidates often confuse the unified CloudWatch agent with the older CloudWatch Logs agent or think that a VPC endpoint is required for any logging setup, when in fact the two mandatory actions are attaching an IAM role with the correct permissions and installing/configuring the unified CloudWatch agent.

713
Multi-Selecthard

A SysOps administrator is setting up a CloudWatch dashboard to monitor an application. The application runs on an Auto Scaling group of EC2 instances behind an Application Load Balancer. The administrator wants to track the number of healthy hosts and the request count per target group. Which two metrics should be used? (Choose TWO.)

Select 2 answers
A.HealthyHostCount (per TargetGroup)
B.RequestCount (per ALB)
C.ActiveConnectionCount
D.RequestCount (per TargetGroup)
E.HealthyHostCount (per ALB)
AnswersA, D

HealthyHostCount with the TargetGroup dimension reports the number of targets (EC2 instances, IP addresses, or Lambda functions) that pass the configured health checks for that specific target group. This provides direct, per-service visibility into backend capacity and is the correct metric for a dashboard focused on target-group health because the TargetGroup dimension precisely isolates the health of one group.

Why this answer

`HealthyHostCount` (per TargetGroup) is a CloudWatch metric that reports the number of healthy EC2 instances in a specific target group, which directly indicates the health of the backend fleet. Option D is correct because `RequestCount` (per TargetGroup) tracks the number of requests routed to that target group, allowing the administrator to correlate traffic load with host health. Together, these two metrics provide the exact visibility needed for an Auto Scaling group behind an ALB.

Exam trap

The trap here is that candidates confuse ALB-level metrics (like `RequestCount` per ALB or `ActiveConnectionCount`) with target-group-level metrics, or assume `HealthyHostCount` exists at the ALB level, when in fact it is only available per target group.

714
MCQmedium

A company is running a web application on EC2 instances in an Auto Scaling group behind an Application Load Balancer. The application stores session data on the local instance storage. Users are experiencing session loss during scaling events. What should a SysOps administrator do to maintain session persistence?

A.Move session data to an ElastiCache for Redis cluster.
B.Increase the EC2 instance size to reduce the frequency of scaling events.
C.Attach an Amazon EBS volume to each instance and store session data there.
D.Enable sticky sessions on the Application Load Balancer.
AnswerA

Moving session state to ElastiCache for Redis decouples user session data from the ephemeral lifecycle of EC2 instances. Because Redis is a centralized, network-accessible store, any instance in the Auto Scaling group can read and write the same session data, and the data survives instance termination or replacement (especially with Redis persistence/AOF). This enables the Application Load Balancer to route requests to any healthy instance, eliminating the single point of failure tied to local storage.

Why this answer

Session data stored on local instance storage is ephemeral and lost when instances are terminated or replaced during scaling events. Moving session data to ElastiCache for Redis provides a centralized, durable, and low-latency session store that persists independently of EC2 instance lifecycles, ensuring session continuity across scaling operations.

Exam trap

The trap here is that candidates often confuse sticky sessions (which maintain request routing) with session persistence (which maintains session data), leading them to choose option D without realizing that sticky sessions do not protect against data loss when the target instance is terminated.

How to eliminate wrong answers

Option B is wrong because increasing instance size does not eliminate session loss; it only reduces the frequency of scaling events but does not address the fundamental issue of ephemeral storage being lost on instance termination. Option C is wrong because attaching an EBS volume to each instance still ties session data to individual instances; if an instance is terminated during scale-in, the EBS volume is detached and the session data is lost unless the volume is manually reattached, which is not automated and defeats the purpose of Auto Scaling. Option D is wrong because sticky sessions (session affinity) only route subsequent requests from the same user to the same instance, but they do not preserve session data if that instance is terminated; the session data on local storage is still lost when the instance is replaced.

715
MCQhard

A SysOps administrator is troubleshooting a cost overrun in an AWS account. The cost explorer shows that data transfer costs have significantly increased. The architecture includes an Application Load Balancer (ALB) internet-facing, EC2 instances in private subnets, and an S3 bucket for static assets. Which action will MOST effectively reduce data transfer costs?

A.Enable Amazon CloudFront to cache static assets and reduce direct requests to the ALB.
B.Implement a VPC Gateway Endpoint for S3 so that traffic from EC2 to S3 stays within the AWS network.
C.Replace the NAT Gateway with a NAT instance to reduce hourly charges.
D.Change the ALB to internal (private) and use AWS Direct Connect for user access.
AnswerB

VPC Gateway Endpoints for S3 are horizontally scaled, redundant VPC components that require no additional cost—they are free to use and carry no hourly or per-GB charges. When added to the route table, traffic destined for S3 is directed via prefix lists to stay inside the AWS network, bypassing the NAT Gateway for both data transfer and NAT processing fees. This directly cuts the most common source of S3-related cost overruns from EC2 instances in private subnets.

Why this answer

Implementing a VPC Gateway Endpoint for S3 allows EC2 instances in private subnets to access S3 without traversing the NAT Gateway or internet, eliminating data transfer costs associated with NAT Gateway data processing and internet egress. This is the most effective cost reduction because S3 traffic is often a major contributor to data transfer charges in such architectures.

Exam trap

The trap is focusing on NAT Gateway hourly charges or CloudFront caching while overlooking that S3 data transfer through NAT Gateway incurs data processing and egress costs; SOA-C02 often tests whether candidates know that Gateway Endpoints for S3 are free and eliminate those costs.

How to eliminate wrong answers

Option A is wrong because while CloudFront can reduce direct requests to the ALB and cache static assets, it does not address the data transfer costs between EC2 and S3, which are likely the primary driver; CloudFront also introduces its own data transfer costs. Option C is wrong because replacing a NAT Gateway with a NAT instance reduces hourly charges but does not eliminate the data transfer costs for S3 traffic, and NAT instances have lower throughput and require management. Option D is wrong because changing the ALB to internal and using Direct Connect would disrupt user access and does not address the EC2-to-S3 data transfer costs; Direct Connect also has its own costs.

716
Multi-Selectmedium

Match each AWS service with its primary security compliance function. (Drag each service to its correct function.) (Choose 4.)

Select 4 answers
A.AWS CloudTrail -> Detect unauthorized API calls
B.AWS Config -> Monitor resource configuration changes
C.Amazon GuardDuty -> Identify malicious activity
D.Amazon Macie -> Discover sensitive data in S3
AnswersA, B, C, D

AWS CloudTrail is the compliance service that records every API action made in an AWS account, capturing the identity, time, source IP, and request parameters for each call. This complete audit trail enables security teams to detect unauthorized or anomalous API activity, such as a user attempting to access resources without permission or a compromised credential generating unusual calls. It is the first place to investigate security incidents and prove compliance for regulatory audits, making it correctly matched to 'Detect unauthorized API calls'.

Why this answer

AWS CloudTrail is the service that records API activity in your AWS account, including both management and data events. By enabling CloudTrail, you can detect unauthorized API calls by analyzing the recorded events for actions that were not initiated by authorized users or services, such as an IAM user making a call from an unexpected IP address or using an unknown user agent.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail with AWS Config, thinking both are for monitoring configuration changes, but CloudTrail focuses on API activity logging while Config tracks resource configuration state changes.

How to eliminate wrong answers

Option A is correct because AWS CloudTrail specifically logs API calls and is used to detect unauthorized activity. Option B is correct because AWS Config continuously monitors and records changes to AWS resource configurations, enabling compliance auditing. Option C is correct because Amazon GuardDuty uses machine learning and threat intelligence to identify malicious activity such as unusual API calls or compromised instances.

Option D is correct because Amazon Macie uses machine learning and pattern matching to discover and protect sensitive data, such as personally identifiable information (PII), stored in Amazon S3 buckets.

717
MCQhard

A company uses Amazon S3 for static website hosting. The website serves thousands of users globally, and the company wants to reduce latency and lower data transfer costs. Which solution should the SysOps administrator implement?

A.Set up Amazon CloudFront as a content delivery network (CDN) in front of the S3 bucket.
B.Use S3 Intelligent-Tiering storage class.
C.Enable cross-region replication and serve from multiple buckets.
D.Enable S3 Transfer Acceleration on the bucket.
AnswerA

CloudFront caches the S3 static content at global edge locations, so users are served from nearby points of presence rather than the bucket's Region. This reduces latency and cuts data transfer costs by lowering origin fetches, satisfying both stated goals.

Why this answer

Amazon CloudFront is a global content delivery network (CDN) that caches static content at edge locations closer to users, reducing latency and lowering data transfer costs by minimizing direct requests to the S3 origin. By serving cached objects from edge locations, CloudFront also reduces the amount of data transferred from S3, which can significantly decrease S3 data transfer egress charges.

Exam trap

The trap here is that candidates confuse S3 Transfer Acceleration (which speeds up uploads) with a CDN solution for download performance, or they think cross-region replication alone solves latency without considering the need for a global caching layer.

How to eliminate wrong answers

Option B is wrong because S3 Intelligent-Tiering optimizes storage costs by moving objects between access tiers based on usage patterns, but it does not reduce latency or data transfer costs for global users. Option C is wrong because cross-region replication creates copies in multiple regions, but users still access a single bucket directly unless a routing mechanism like Route 53 latency-based routing is added, and it increases storage costs without providing edge caching benefits. Option D is wrong because S3 Transfer Acceleration uses AWS edge locations to speed up uploads to S3 over long distances, but it does not cache content for downloads or reduce latency for end users retrieving static website content.

718
MCQmedium

A company is using CloudWatch Logs to centralize logs from multiple EC2 instances. The operations team notices that some log entries are missing from CloudWatch Logs. The CloudWatch agent is installed and running on all instances. What is the most likely cause?

A.The CloudWatch agent is not configured to send logs to the correct log group.
B.The CloudWatch agent is sending logs to a different AWS Region.
C.The log group has been encrypted with a KMS key that the agent does not have access to.
D.The IAM role attached to the EC2 instance does not have the 'logs:PutLogEvents' permission.
AnswerD

The CloudWatch agent runs under the EC2 instance's attached IAM role, and each PutLogEvents API call requires the logs:PutLogEvents permission to be explicitly allowed in that role's policy. Without this permission, the API returns an AccessDeniedException, and the agent's own log file (typically in /var/log/aws/amazon-cloudwatch-agent/) will record the failure while the logs silently stop appearing in CloudWatch. This is the most common root cause when the agent is running and configured correctly but no new log events arrive.

Why this answer

The most likely cause is that the IAM role attached to the EC2 instance lacks the 'logs:PutLogEvents' permission. Without this permission, the CloudWatch agent can authenticate and connect to CloudWatch Logs but cannot actually write log data to the log stream, resulting in missing entries. The agent may appear to be running and healthy, but API calls to PutLogEvents will fail silently or log errors, leading to gaps in the centralized logs.

Exam trap

The trap here is that candidates assume the agent's installation and running status guarantee log delivery, but the missing permission causes silent failures that are easy to overlook, especially when the agent reports no obvious errors.

How to eliminate wrong answers

Option A is wrong because if the agent were configured to send logs to the wrong log group, log entries would still appear in CloudWatch Logs, just in a different log group; the issue is missing entries entirely, not misrouting. Option B is wrong because sending logs to a different AWS Region would still result in log entries appearing in that region's CloudWatch Logs, not missing entries; the agent's configuration specifies the region, and logs would be visible elsewhere. Option C is wrong because KMS encryption on the log group does not block the agent from writing logs; the agent uses the same IAM permissions to decrypt the KMS key (if needed) and write logs, and missing logs are not caused by encryption access issues unless the agent explicitly fails to write due to a KMS permission error, which is less common than missing PutLogEvents.

719
MCQeasy

An application is running on an EC2 instance and is experiencing intermittent connection timeouts. The SysOps administrator wants to capture network traffic to analyze the issue. Which AWS service should be used?

A.CloudWatch Logs
B.AWS CloudTrail
C.AWS Config
D.VPC Flow Logs
AnswerD

VPC Flow Logs is a feature of Amazon VPC that captures metadata about IP traffic going to and from network interfaces in a VPC, including the ENI attached to the EC2 instance. Each flow log record includes fields such as source/destination IP, port, protocol, packet/byte counts, and whether the traffic was accepted or rejected by security groups/network ACLs. This makes it the correct service for diagnosing connectivity issues, analyzing traffic patterns, or investigating security incidents, as it directly provides network traffic metadata at the flow level.

Why this answer

VPC Flow Logs capture IP traffic information for network interfaces in a VPC, including accepted and rejected connection attempts. This allows the SysOps administrator to analyze the source/destination IPs, ports, protocols, and whether the traffic was allowed or denied, which is essential for diagnosing intermittent connection timeouts.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (which capture network traffic metadata) with CloudWatch Logs (which capture application/system logs) or CloudTrail (which captures API activity), leading them to choose a logging service that cannot diagnose network-level issues.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs is a service for storing, monitoring, and accessing log files from AWS resources (e.g., application logs, system logs), but it does not capture raw network traffic or packet-level data. Option B is wrong because AWS CloudTrail records API calls and user activity for auditing and governance, not network traffic flows. Option C is wrong because AWS Config evaluates resource configurations against desired policies and tracks configuration changes, but it does not capture or analyze network traffic.

720
Multi-Selectmedium

A SysOps administrator is investigating a security incident where an unauthorized user accessed an S3 bucket. Which TWO AWS services can the administrator use to collect and analyze the relevant logs?

Select 2 answers
A.AWS WAF logs
B.Amazon VPC Flow Logs
C.AWS CloudTrail
D.Amazon Route 53 resolver logs
E.Amazon S3 server access logs
AnswersC, E

AWS CloudTrail is the correct answer because it can be configured to capture S3 data events — object-level API calls such as GetObject, PutObject, and DeleteObject — in addition to management events like CreateBucket. Each event record includes the IAM user or role that made the request, the source IP address, the request parameters, and the response, providing a complete audit trail for incident investigation. Data events are not enabled by default on a trail, so the administrator must explicitly enable them for the target bucket to ensure such logs are captured.

Why this answer

AWS CloudTrail is correct because it records API calls made to S3, including who made the request, the source IP address, and the time of the action. This allows the administrator to trace the unauthorized access to a specific IAM user or role and identify the exact API operations performed, such as GetObject or PutObject.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs with S3 access logs, thinking network-level logs can capture S3 API calls, but VPC Flow Logs only show IP traffic metadata and not the application-level S3 operations.

721
MCQhard

A company has a VPC with public and private subnets across three Availability Zones. The public subnets host NAT Gateways, and the private subnets host EC2 instances that need to access the internet. The SysOps administrator notices that EC2 instances in one private subnet cannot reach the internet, while others can. What is the MOST likely cause?

A.The EC2 instances have a secondary private IP address that is not registered.
B.The NAT Gateway is not in a public subnet.
C.The network ACL for the private subnet blocks outbound traffic.
D.The route table for the private subnet does not have a default route to the NAT Gateway.
AnswerD

The private subnet's route table must contain a default route (0.0.0.0/0) that targets the NAT Gateway for all outbound internet traffic. Without this route, packets destined for the internet have no next hop and are dropped, even though the NAT Gateway itself is correctly placed and functional. This configuration is per-subnet, which explains why only the affected private subnet lacks internet access while other subnets work normally.

Why this answer

The most likely cause is that the route table associated with the private subnet does not have a default route (0.0.0.0/0) pointing to the NAT Gateway. Without this route, traffic destined for the internet has no path and fails. Option A is incorrect because secondary private IP addresses do not affect internet access.

Option B is incorrect because NAT Gateways must be in a public subnet (not private) to have internet access. Option C is incorrect because network ACLs are stateless and would affect all instances equally, not just those in one subnet.

722
MCQhard

A company runs a critical application on AWS Lambda functions. The functions are invoked by an API Gateway endpoint. The SysOps administrator needs to ensure that the application continues to work if an entire AWS Region becomes unavailable. What should the administrator do?

A.Use AWS Global Accelerator to route traffic to the closest Region.
B.Configure Lambda functions with provisioned concurrency in multiple Regions.
C.Use Lambda@Edge to run the functions at edge locations.
D.Deploy the same API Gateway and Lambda setup in a second Region and use Route 53 with failover routing.
AnswerD

Deploying an identical API Gateway and Lambda setup in a second Region and using Route 53 failover routing with health checks on the primary endpoint provides an active-passive disaster recovery pattern. When the health check fails, Route 53 automatically returns the secondary Region's IP address, directing clients to the standby stack. This approach ensures cross-Region availability and is the standard solution for making a Lambda-based critical application resilient to an entire Region outage.

Why this answer

Deploying the same API Gateway and Lambda setup in a second AWS Region and using Route 53 with failover routing creates an active-passive disaster recovery architecture. Route 53 health checks monitor the primary Region's endpoint, and if it becomes unhealthy (e.g., due to a regional outage), DNS failover automatically routes traffic to the secondary Region, ensuring continuous operation of the application.

Exam trap

The trap here is that candidates often confuse high-availability features like Global Accelerator or provisioned concurrency with true disaster recovery across Regions, failing to recognize that only Route 53 failover routing provides the DNS-level traffic redirection needed when an entire Region becomes unavailable.

How to eliminate wrong answers

Option A is wrong because AWS Global Accelerator improves performance and availability by routing traffic to the closest healthy endpoint within a single Region or across multiple Regions, but it does not provide automatic failover to a completely separate Region if the entire primary Region becomes unavailable; it relies on existing endpoints in the same Region. Option B is wrong because configuring Lambda functions with provisioned concurrency in multiple Regions initializes the functions to reduce cold starts, but it does not include the necessary API Gateway endpoints or DNS-based routing to redirect traffic if the primary Region fails. Option C is wrong because Lambda@Edge runs functions at CloudFront edge locations, which are designed for lightweight request/response modifications and cannot host the full application logic or API Gateway integration required for this critical application; it also does not provide regional failover.

723
MCQhard

An EC2 instance runs a database on a 2 TB EBS gp3 volume. After a corruption event, the team must restore from a snapshot. When they detach the corrupted volume, attach a new volume restored from the snapshot, and start the database, performance is 10 to 20 times lower than normal for the first two hours. What causes this behavior, and what feature eliminates it?

A.Enable Fast Snapshot Restore (FSR) on the snapshot in the target Availability Zone before creating the replacement volume
B.Use a Provisioned IOPS (io2) volume type instead of gp3 to get higher IOPS during initialization
C.Run a full dd or fio pre-warm pass over the volume after attaching it but before starting the database
D.Increase the EBS volume size to 4 TB when restoring from the snapshot to get double the throughput baseline
AnswerA

FSR fully initializes the volume's block index immediately upon creation. The first I/O to any block is served from EBS at full throughput rather than waiting for lazy initialization from S3. For a 2 TB database volume where I/O latency determines restore time, FSR eliminates the 2-hour performance degradation period entirely.

Why this answer

When you create an EBS volume from a snapshot, the volume's data blocks are lazily loaded from Amazon S3 on first access. This causes high latency and low IOPS until all blocks are fetched. Fast Snapshot Restore (FSR) pre-initializes the volume in a specific Availability Zone, eliminating the need for lazy loading and providing full performance immediately.

Exam trap

The trap here is that candidates assume performance issues are due to volume type (gp3 vs io2) or size, rather than recognizing the fundamental lazy-load initialization behavior of EBS snapshots and the specific feature (FSR) designed to mitigate it.

How to eliminate wrong answers

Option B is wrong because Provisioned IOPS (io2) volumes do not eliminate the lazy-load initialization penalty; they only provide consistent IOPS after the volume is fully initialized, but the initial access still suffers from the same on-demand fetch from S3. Option C is wrong because running dd or fio pre-warms the volume manually, but this is a workaround, not a feature that eliminates the behavior, and it still requires the same time-consuming initialization process. Option D is wrong because increasing the volume size to 4 TB does not change the lazy-load behavior; it only increases the baseline throughput for the volume after initialization, but the initial performance degradation remains until all blocks are loaded.

724
MCQhard

A company runs a critical web application on EC2 instances behind an Application Load Balancer (ALB). The SysOps administrator needs to be notified if the ALB's error rate exceeds 5% for 5 consecutive minutes. Which solution meets this requirement with the least operational overhead?

A.Enable VPC Flow Logs and analyze them with Amazon Athena to detect error rates.
B.Use a CloudWatch alarm on the ALB's 'HTTPCode_ELB_5XX_Count' metric with a math expression to calculate error rate.
C.Enable CloudTrail for the ALB and create a metric filter for 5xx errors.
D.Use AWS Config rules to monitor the ALB configuration and trigger a notification on changes.
AnswerB

The ALB emits the CloudWatch metric HTTPCode_ELB_5XX_Count, which counts the number of 5xx HTTP response codes generated by the load balancer itself (e.g., 502, 503, 504) for each target group and LoadBalancer dimension. By creating a metric math expression that divides this metric by the RequestCount metric (or a sliding window sum of both), you can calculate a 5xx error rate in real time. A CloudWatch alarm can be attached directly to that expression, evaluating at a chosen period (e.g., 5 minutes) and triggering an SNS notification when the calculated rate crosses a threshold, providing operational monitoring that is immediate and built into the ALB service.

Why this answer

CloudWatch can directly monitor the ALB's 'HTTPCode_ELB_5XX_Count' metric and combine it with the 'RequestCount' metric using a math expression to calculate the error rate as a percentage. This approach requires no additional logging or external services, and a CloudWatch alarm can be configured to trigger an SNS notification when the error rate exceeds 5% for 5 consecutive minutes, minimizing operational overhead.

Exam trap

The trap here is that candidates may confuse CloudTrail (which logs API activity) with CloudWatch metrics (which track performance data), or assume VPC Flow Logs can provide HTTP-level error codes when they only capture network-layer information.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network-level traffic metadata (IP addresses, ports, protocols) and do not include HTTP status codes, making them unsuitable for detecting application-layer 5xx errors; analyzing them with Athena adds unnecessary complexity and cost. Option C is wrong because CloudTrail records API calls to the ALB (e.g., configuration changes) and does not capture HTTP response codes from client requests; metric filters on CloudTrail logs cannot extract 5xx error rates from traffic. Option D is wrong because AWS Config rules evaluate resource configuration compliance (e.g., security group settings, deletion protection) and cannot monitor real-time traffic metrics like error rates; they are designed for drift detection, not performance monitoring.

725
MCQeasy

A company requires that all access to the AWS Management Console be protected by multi-factor authentication (MFA). The SysOps administrator has enabled an IAM policy that denies all actions if the user does not authenticate with MFA. However, some users report they cannot list their own MFA devices. What is the MOST likely cause?

A.The policy denies the iam:ListMFADevices action without an MFA-authenticated session
B.The policy is applied to the root user only
C.Users are not using MFA-enabled access keys
D.The policy is not applied in the us-east-1 region
AnswerA

The Deny clause for iam:ListMFADevices when the session lacks an MFA-authenticated condition blocks the AWS Management Console from displaying a user's existing MFA devices and prevents the self-service MFA enrollment flow from working. Because iam:ListMFADevices is one of the first API calls the console makes when a user attempts to manage or set up MFA, this Deny effectively locks out any user who has not yet enrolled MFA, making it impossible to satisfy the MFA requirement. A correctly designed MFA enforcement policy must explicitly allow iam:ListMFADevices (along with iam:CreateVirtualMFADevice and iam:EnableMFADevice) without requiring MFA, allowing users to bootstrap their first device.

Why this answer

The IAM policy that denies all actions unless the user is authenticated with MFA will also block the iam:ListMFADevices action because that API call is made without an MFA-authenticated session. When a user tries to list their own MFA devices, they have not yet passed the MFA challenge, so the session is not MFA-authenticated, and the deny policy applies. This creates a catch-22: the user cannot list their devices to manage MFA because listing requires MFA, but they need to list devices to set up MFA.

Exam trap

The trap here is that candidates assume the deny policy only applies to sensitive actions like modifying resources, but they overlook that even benign read actions like listing MFA devices are blocked because the policy uses a blanket Deny for all actions when MFA is not present, creating a circular dependency.

How to eliminate wrong answers

Option B is wrong because the root user is not the only user affected; the policy is applied to all IAM users via a deny-all policy, and the issue is about IAM users, not the root user. Option C is wrong because access keys are not used for console access; the issue is about the AWS Management Console, which uses a session, not access keys, and MFA enforcement for console access is separate from access key MFA. Option D is wrong because IAM policies are global and not region-specific; they apply across all regions, including us-east-1, and there is no regional restriction for IAM actions.

726
MCQhard

A company has an S3 bucket that stores sensitive customer data. The security team requires that all objects in the bucket be encrypted at rest using AWS KMS. An administrator notices that some objects are not encrypted. What is the MOST efficient way to enforce encryption for future uploads?

A.Use an SCP to require KMS encryption for all S3 actions.
B.Use AWS Config to detect unencrypted objects and automatically encrypt them.
C.Add a bucket policy that denies s3:PutObject unless the request includes the x-amz-server-side-encryption header set to aws:kms.
D.Enable S3 default encryption on the bucket with KMS.
AnswerC

An S3 bucket policy can deny s3:PutObject unless the request includes the x-amz-server-side-encryption header set to aws:kms, using a condition block with StringNotEqualsIfExists (or an equivalent combination of conditions). Because the bucket policy is evaluated synchronously before the write is committed, any upload that lacks the header or specifies a different encryption type is immediately rejected with an Access Denied error. This makes it a true preventive control: it enforces server-side encryption with KMS on every PUT, regardless of what IAM permissions the caller holds. This is the correct solution when sensitive data must never be stored unencrypted or with non-KMS encryption.

Why this answer

Adding a bucket policy that denies s3:PutObject unless the request includes the x-amz-server-side-encryption header set to aws:kms is the most efficient way to enforce encryption for future uploads. This policy prevents any upload without proper encryption. Option A is incorrect because SCPs (Service Control Policies) limit IAM permissions but do not directly enforce encryption on S3 objects.

Option B is incorrect because AWS Config can detect unencrypted objects but does not automatically encrypt them; it is a reactive measure. Option D is incorrect because S3 default encryption can be overridden by the client specifying a different encryption header in the upload request.

727
MCQmedium

A company runs a production application on Amazon EC2 instances in an Auto Scaling group across two Availability Zones. The application uses an Amazon RDS Multi-AZ DB instance. The SysOps administrator wants to test the application's behavior during an Availability Zone failure of the database. Which action should the administrator take to simulate a failure with minimal impact on production?

A.Reboot the DB instance with the 'Reboot with failover' option
B.Modify the DB instance to be a single-AZ deployment
C.Delete the standby replica in the other Availability Zone
D.Stop the DB instance
AnswerA

Choosing 'Reboot with failover' instructs Amazon RDS to perform a graceful, forced failover from the primary to the standby replica in the other Availability Zone. This simulates an AZ outage or primary instance failure, letting you validate that your application reconnects and continues operating after RDS promotes the standby and updates the DNS endpoint. The reboot causes only a short interruption while the failover completes, making it the correct way to test resilience without manual infrastructure changes.

Why this answer

Rebooting the RDS Multi-AZ DB instance with the 'Reboot with failover' option forces a synchronous failover to the standby replica in the other Availability Zone. This simulates an AZ failure of the primary database with minimal impact because the application's Auto Scaling group spans two AZs and the RDS Multi-AZ deployment provides automatic failover, so the application should experience only a brief interruption during the DNS change to the new primary.

Exam trap

The trap here is that candidates may think stopping or deleting the standby replica simulates an AZ failure, but those actions either cause a full outage or permanently remove redundancy, whereas 'Reboot with failover' is the only option that triggers a controlled failover with minimal production impact.

How to eliminate wrong answers

Option B is wrong because modifying the DB instance to be a single-AZ deployment permanently removes the standby replica and changes the architecture, which does not simulate a transient AZ failure and has a greater impact on production. Option C is wrong because deleting the standby replica in the other AZ is a destructive action that removes high availability entirely, and it does not simulate a failover event; it also requires manual intervention to recreate the standby. Option D is wrong because stopping the DB instance halts the database completely, causing a full outage rather than a controlled failover, and it does not test the application's behavior during an AZ failure of the database.

728
MCQeasy

A company's security policy requires that all IAM user passwords must be at least 12 characters long. The SysOps administrator needs to enforce this requirement across the AWS account. Which action should the administrator take?

A.Create an AWS Config rule to check password length and auto-remediate.
B.Update the IAM account password policy to require a minimum length of 12 characters.
C.Enable AWS CloudTrail to monitor for password changes and alert the administrator.
D.Attach a service control policy (SCP) that denies IAM user creation if the password is less than 12 characters.
AnswerB

The IAM account password policy is the native, preventative control that enforces password requirements at the account level for all IAM users. When you set a minimum length of 12 characters, IAM rejects any password creation or change that does not meet this threshold, ensuring compliance before the password is ever stored. This is the intended mechanism that directly satisfies the security policy requirement.

Why this answer

The IAM account password policy is the native AWS mechanism for enforcing password requirements across all IAM users in an account. By updating this policy to require a minimum length of 12 characters, the administrator ensures that any new or changed password must comply, and existing passwords are not affected until the next change. This is a direct, account-wide setting that requires no additional services or custom logic.

Exam trap

The trap here is that candidates confuse AWS Config (which can detect but not enforce password length at creation time) with the IAM password policy (which is the correct, built-in enforcement mechanism), or they mistakenly think SCPs can inspect password content when they only control API actions at a high level.

How to eliminate wrong answers

Option A is wrong because AWS Config rules can detect noncompliant passwords but cannot directly enforce password length at the point of creation or change; auto-remediation would require a custom Lambda function to modify the password policy, which is unnecessary when the native IAM password policy already exists. Option C is wrong because CloudTrail logs API calls but does not enforce password requirements; it only provides auditing after the fact, which does not prevent users from setting short passwords. Option D is wrong because service control policies (SCPs) apply to AWS Organizations and can restrict IAM user creation actions, but they cannot evaluate or enforce password length at the time of password creation or change; SCPs operate at the API level and lack the granularity to inspect password content.

729
MCQmedium

A company is using AWS CloudTrail to log API activity in their account. The security team needs to be alerted when an IAM user creates a new access key. Which solution meets this requirement with the least operational overhead?

A.Enable CloudTrail email notifications for management events.
B.Configure the IAM user's permissions to require MFA for access key creation.
C.Create an Amazon EventBridge rule that matches the CreateAccessKey event and targets an SNS topic.
D.Write a Lambda function that periodically scans CloudTrail logs in S3 and sends alerts.
AnswerC

EventBridge can ingest CloudTrail API calls as events, and a rule with an event pattern filtering for the 'CreateAccessKey' API call from the IAM service will trigger in real time. The rule's target can be an SNS topic, which then sends notifications (e.g., email, SMS) to subscribers, providing immediate alerting. This is the standard serverless pattern for reacting to AWS API activity because it is real-time, scalable, and requires no polling or log parsing.

Why this answer

Amazon EventBridge can directly match the `CreateAccessKey` API call from CloudTrail and trigger an SNS topic to send an alert in real time, requiring no custom code or polling. This provides the least operational overhead by using a fully managed, event-driven rule.

Exam trap

The trap here is that candidates may think CloudTrail itself can send email alerts (Option A) or that a security control like MFA (Option B) satisfies the alerting requirement, but neither provides the real-time notification specified in the question.

How to eliminate wrong answers

Option A is wrong because CloudTrail does not support email notifications for management events; it can only deliver log files to S3 or CloudWatch Logs, and email alerts require an additional service like SNS. Option B is wrong because requiring MFA for access key creation is a security control that prevents unauthorized creation but does not generate alerts when a key is created. Option D is wrong because writing a Lambda function to periodically scan CloudTrail logs in S3 introduces unnecessary complexity, latency, and operational overhead compared to a real-time EventBridge rule.

730
MCQeasy

A SysOps administrator wants to deploy a serverless application using AWS Lambda functions, Amazon API Gateway, and Amazon DynamoDB. The deployment must be automated and repeatable. Which AWS service should the administrator use to define and manage this infrastructure as code?

A.AWS CodeDeploy
B.AWS OpsWorks
C.AWS Elastic Beanstalk
D.AWS CloudFormation with the AWS Serverless Application Model (SAM)
AnswerD

AWS CloudFormation with the AWS Serverless Application Model (SAM) is the definitive infrastructure-as-code approach for serverless applications. SAM is an open-source framework that extends CloudFormation with simplified syntax to define serverless resources like Lambda functions, API Gateway APIs, and DynamoDB tables in a template, then transforms them into full CloudFormation stacks. It also provides local testing via the SAM CLI, supports automatic IAM role generation, and enables deployment through CodeDeploy for safer Lambda traffic shifting, making it purpose-built for serverless. By using SAM, a SysOps administrator can version, review, and reliably replicate the entire serverless application in a repeatable, auditable way.

Why this answer

AWS CloudFormation with the AWS Serverless Application Model (SAM) is the correct choice for defining and managing serverless infrastructure as code, as SAM extends CloudFormation with shorthand syntax for Lambda, API Gateway, and DynamoDB. Option A is wrong because AWS CodeDeploy automates code deployment to running instances, not infrastructure provisioning. Option B is wrong because AWS OpsWorks manages Chef/Puppet-based application stacks.

Option C is wrong because AWS Elastic Beanstalk is designed for deploying web applications on EC2, not serverless architectures.

731
MCQhard

A company uses AWS OpsWorks to manage a stack of EC2 instances running a web application. They recently migrated to AWS Elastic Beanstalk for easier deployments. However, after the migration, some users report that the application is responding slowly during peak hours. The Elastic Beanstalk environment is configured with a load balancer and auto scaling based on average CPU utilization. What should the SysOps Administrator do to troubleshoot the performance issue?

A.Manually scale the environment to add more instances.
B.Revert to the OpsWorks stack configuration.
C.Review the CloudWatch metrics and logs for the Elastic Beanstalk environment.
D.Increase the instance size in the environment configuration.
AnswerC

CloudWatch metrics track CPU, memory, network, and request latency, while Elastic Beanstalk aggregates application and web server logs that can expose 5xx errors, stack traces, or slow queries. Reviewing these data sources together reveals whether the performance issue is due to a bottleneck, a recent deployment, or a resource limitation, allowing you to make a data-driven adjustment. This is the correct first step before any scaling action to ensure the actual root cause is addressed.

Why this answer

Reviewing CloudWatch metrics and logs from the Elastic Beanstalk environment can identify if the auto scaling policy is not aggressive enough or if there are other bottlenecks. Option A is wrong because manually scaling the environment is a reactive measure that does not help identify the root cause of the performance issue. Option B is wrong because reverting to the OpsWorks stack would be a step backward and does not address the current environment's performance problem.

Option D is wrong because increasing instance size without analysis may be inefficient and not resolve the underlying issue.

732
MCQmedium

A SysOps administrator needs to audit all changes to security groups in an AWS account. Which AWS service should be used to capture these changes?

A.VPC Flow Logs
B.AWS CloudTrail
C.CloudWatch Logs
D.AWS Config
AnswerB

AWS CloudTrail is the service designed to provide a complete audit trail of API activity in your account. It records every management event, including calls like AuthorizeSecurityGroupIngress, RevokeSecurityGroupIngress, and CreateSecurityGroup, along with the identity of the caller, the source IP, timestamp, and request parameters. This gives you the definitive answer to the SysOps administrator's need to audit all changes to security groups and other resources.

Why this answer

AWS CloudTrail is the correct service because it records API calls made to the AWS environment, including all CreateSecurityGroup, AuthorizeSecurityGroupIngress, RevokeSecurityGroupEgress, and DeleteSecurityGroup API actions. By enabling CloudTrail trail logging, the SysOps administrator can capture a complete audit trail of who made changes, when, and from which source IP, which is essential for security group change auditing.

Exam trap

The trap here is that candidates often confuse AWS Config (which tracks configuration state changes) with CloudTrail (which tracks API call provenance), leading them to choose Config for auditing changes when only CloudTrail provides the identity and source of the change.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) at the network interface level, not API-level changes to security group configurations. Option C is wrong because CloudWatch Logs is a service for storing, monitoring, and accessing log files from various sources (e.g., application logs, system logs), but it does not natively capture AWS API calls; it can only store CloudTrail logs if they are streamed to it, but it is not the primary service for capturing the changes. Option D is wrong because AWS Config evaluates resource configurations against desired rules and tracks configuration changes over time, but it does not capture the API caller identity or the source of the change; it records the state of the security group after the change, not the who and how of the API call.

733
MCQhard

A company uses AWS CloudTrail to log all API calls. The security team requires that all logs be encrypted at rest and stored in an S3 bucket that blocks public access. The SysOps administrator configures the bucket with default encryption (SSE-S3) and a bucket policy that denies all actions unless the request includes the x-amz-server-side-encryption header with value AES256. However, CloudTrail delivery fails. What is the MOST likely cause?

A.The bucket policy requires the x-amz-server-side-encryption header, but CloudTrail does not include this header
B.CloudTrail does not support SSE-S3 encryption
C.The bucket policy does not grant CloudTrail the s3:PutObject permission
D.The bucket has default encryption enabled, which conflicts with CloudTrail's encryption
AnswerA

CloudTrail delivers log files to S3 with SSE-S3 encryption applied automatically, but its PutObject requests do not include an x-amz-server-side-encryption header. The bucket policy in this scenario uses a condition that requires that exact header on all writes (e.g., s3:x-amz-server-side-encryption equals AES256). Because CloudTrail omits the header, the condition evaluates to false and the bucket policy denies the request, so log delivery fails even though the object would have been encrypted server-side.

Why this answer

CloudTrail does not include the x-amz-server-side-encryption header when delivering log files to S3. The bucket policy requires this header for all PutObject requests, so CloudTrail's PUT requests are denied, causing delivery to fail. SSE-S3 encryption is applied automatically by S3 when default encryption is enabled, but the policy condition overrides that by requiring the header explicitly.

Exam trap

The trap here is that candidates assume default encryption automatically satisfies encryption requirements, but bucket policy conditions are evaluated before S3 applies default encryption, so the missing header still causes a denial.

How to eliminate wrong answers

Option B is wrong because CloudTrail fully supports SSE-S3 encryption; it can deliver logs to buckets with default SSE-S3 encryption as long as the bucket policy does not block it. Option C is wrong because the bucket policy does not explicitly deny s3:PutObject permission; it denies actions unless the required header is present, which is a condition-based denial, not a missing permission. Option D is wrong because default encryption does not conflict with CloudTrail's encryption; CloudTrail does not set its own encryption headers, so S3 applies default encryption automatically, but the policy condition still blocks the request due to the missing header.

734
MCQmedium

A company uses AWS Organizations to manage multiple AWS accounts. The security team requires that all Amazon S3 buckets in every account be encrypted at rest using AWS KMS customer managed keys. The SysOps administrator needs to enforce this requirement centrally without requiring changes in each account individually. Which approach should the administrator use?

A.Create an IAM policy in each account that denies creation of unencrypted S3 buckets
B.Configure an S3 bucket policy on each bucket to require encryption
C.Create a service control policy (SCP) in the management account that denies creation of S3 buckets without KMS encryption
D.Enable AWS Config rules in each account to detect and remediate non-compliant buckets
AnswerC

An SCP in the management account is the correct preventive control because AWS Organizations applies SCPs to all member accounts, OUs, and their principals, including the root user. The SCP can deny s3:CreateBucket unless the request includes the condition key s3:x-amz-server-side-encryption-aws-kms, forcing all new buckets to use SSE-KMS. Because SCPs are evaluated before the API call is allowed, they stop the bucket from being created at all, giving central management of encryption policy across the entire organization.

Why this answer

A service control policy (SCP) applied at the AWS Organizations management account can centrally deny the creation of S3 buckets that do not have AWS KMS encryption enabled, affecting all member accounts without requiring individual account changes. SCPs act as a permission guardrail that restricts what actions accounts can perform, even for account administrators, making them ideal for enforcing organization-wide security policies like mandatory KMS encryption on S3 bucket creation.

Exam trap

The trap here is that candidates often confuse detective controls like AWS Config rules (which alert or remediate after the fact) with preventive controls like SCPs (which block the action at the API level), leading them to choose a reactive solution instead of the correct proactive, centrally enforced SCP.

How to eliminate wrong answers

Option A is wrong because IAM policies are account-specific and must be applied in each account individually, failing the requirement for a central, no-change-per-account approach; additionally, IAM policies cannot enforce encryption settings on S3 bucket creation because the encryption requirement is a resource-level condition, not an identity-based permission. Option B is wrong because S3 bucket policies are configured per bucket and require manual changes on each existing and new bucket, which does not meet the central enforcement requirement and does not prevent creation of unencrypted buckets. Option D is wrong because AWS Config rules operate within each account and require individual setup and remediation actions per account, which violates the central enforcement without per-account changes; Config rules are detective and reactive, not preventive at the point of bucket creation.

735
Multi-Selectmedium

A company is designing a disaster recovery strategy for its production database hosted on Amazon RDS for MySQL. The primary database is in us-east-1. The company requires an RPO of less than 5 minutes and an RTO of less than 1 hour in the event of a Regional failure. Which TWO actions should the company take to meet these requirements?

Select 2 answers
A.Take daily manual snapshots and copy them to us-west-2.
B.Create a cross-Region Read Replica in us-west-2 and promote it during a disaster.
C.Enable cross-Region automated backups.
D.Enable Multi-AZ deployment for the RDS instance.
E.Use a single-AZ RDS instance with automated backups.
AnswersB, C

A cross-Region Read Replica uses Amazon RDS's asynchronous replication to continuously stream transactions from the primary DB instance in the source Region to a read replica in us-west-2. In a disaster, you can promote the replica to a standalone primary instance within minutes, and the replication lag is typically well under 5 minutes when the network is healthy, meeting the RPO requirement. This gives you a warm standby database in the target Region, enabling fast failover without needing to restore from backups.

Why this answer

A cross-Region Read Replica in us-west-2 can be promoted to a standalone primary database during a disaster, enabling failover with an RTO typically under 1 hour. The replication lag is usually seconds to a few minutes, meeting the RPO of less than 5 minutes. This approach provides a warm standby in another Region without requiring manual snapshot restores.

Exam trap

The trap here is that candidates often confuse Multi-AZ (which only protects against AZ failures within the same Region) with cross-Region disaster recovery, leading them to incorrectly select Option D as a solution for Regional failures.

736
MCQmedium

A company wants to encrypt data at rest in an Amazon RDS for MySQL DB instance. Which solution meets this requirement with minimal administrative overhead?

A.Create a new encrypted DB instance and migrate the data.
B.Use application-level encryption to encrypt data before storing it in the DB.
C.Enable encryption on the existing DB instance by modifying the DB instance.
D.Store the data in an S3 bucket with encryption enabled and use RDS to access it.
AnswerA

RDS encryption at rest is a one-time immutable setting that must be enabled during DB instance creation. To encrypt an existing unencrypted database, you must create a new encrypted DB instance—either by restoring from a snapshot of the original or by exporting/importing data—and then migrate traffic, since there is no in-place conversion. The new instance will use an AWS KMS customer master key to encrypt the storage, automated backups, snapshots, and read replicas. This approach is the only supported path to satisfy the encryption requirement without losing data.

Why this answer

To encrypt data at rest in Amazon RDS for MySQL, encryption must be enabled at launch time; it cannot be added later. Therefore, the correct approach is to create a new encrypted DB instance and migrate the existing data (Option A). Option B (application-level encryption) adds administrative overhead and is not native to RDS.

Option C is incorrect because encryption cannot be enabled on an existing instance; you must create a new one. Option D is incorrect because RDS does not use S3 for its primary storage; it uses Amazon EBS volumes.

737
MCQeasy

A SysOps administrator needs to generate a report of all IAM users and their last activity. Which AWS service can provide this information?

A.AWS Config
B.IAM Credential Report
C.AWS Trusted Advisor
D.AWS CloudTrail
AnswerB

The IAM Credential Report is a downloadable CSV that lists every IAM user in the account with detailed fields including password last used, password last changed, access key IDs, key last used, and key rotation dates. This report is generated on demand or on a schedule using the AWS API, CLI, or console and directly satisfies the requirement to report on IAM users. It is the correct answer because it is purpose-built for summarizing user credential activity.

Why this answer

IAM Credential Report provides a consolidated report of all IAM users and their last activity, including password last used and access key last rotated. Option A is incorrect because AWS Config tracks resource configuration changes, not user activity. Option C is incorrect because AWS Trusted Advisor provides cost optimization and security recommendations, not detailed user activity reports.

Option D is incorrect because AWS CloudTrail logs API calls but does not generate a summarized report of user credentials.

738
MCQeasy

Refer to the exhibit. The command returns no datapoints for CPUUtilization for the specified instance. What is the most likely reason?

A.The instance was stopped or did not emit metrics during the specified time range.
B.The metric name is incorrect.
C.The instance does not have detailed monitoring enabled.
D.The period of 300 seconds is too short.
AnswerA

CloudWatch retains CPUUtilization only while the instance runs; a stopped instance emits no datapoints, so the queried period returns an empty result set. The metric namespace and dimensions remain valid, making the instance's stopped state the reason no datapoints appear for the specified range.

Why this answer

The most likely reason for no datapoints is that the instance was stopped or did not emit metrics during the specified time range. CloudWatch only retains and returns metric data when the instance is running and the CloudWatch agent or EC2 hypervisor is actively publishing CPUUtilization. If the instance was in a stopped state, no metrics are generated, resulting in an empty response from the GetMetricStatistics API call.

Exam trap

The trap here is that candidates often assume missing datapoints are due to a configuration issue (like detailed monitoring not enabled or wrong period), when in fact the instance simply wasn't running during the queried time window.

How to eliminate wrong answers

Option B is wrong because CPUUtilization is a standard EC2 metric name; if the metric name were incorrect, the API would return an error message (e.g., 'InvalidParameterValue') rather than an empty dataset. Option C is wrong because basic monitoring (5-minute granularity) still emits CPUUtilization datapoints; detailed monitoring only affects the frequency (1-minute granularity), not the existence of data. Option D is wrong because a period of 300 seconds is a valid and common value for basic monitoring (matching the default 5-minute interval) and does not cause missing datapoints.

739
MCQmedium

A SysOps administrator is troubleshooting an application that runs on AWS Lambda. The application occasionally fails with timeout errors. The administrator needs to identify the exact lines of code that are causing the delays. Which AWS service or feature should be used to gather this information?

A.Enable detailed CloudWatch Logs and search for 'timeout' strings.
B.Use AWS X-Ray to trace the Lambda function and view segment details.
C.Set a CloudWatch Metric Filter for 'Duration' and create an alarm.
D.Enable AWS CloudTrail data events for the Lambda function.
AnswerB

AWS X-Ray is the correct choice because it provides end-to-end distributed tracing for Lambda invocations, capturing a segment for the entire execution and subsegments for each downstream operation, such as DynamoDB queries, HTTP calls, or custom code blocks. When the X-Ray SDK is installed and the function is instrumented with wrappers or decorators, you can view segment details to see the exact duration of each subsegment, pinpointing which line or API call is slow. Even without custom instrumentation, X-Ray shows the overall execution time and any downstream service traces, but adding subsegments yields the precise line-level breakdown needed for this troubleshooting.

Why this answer

AWS X-Ray provides end-to-end tracing for Lambda functions, capturing segment details and subsegments that pinpoint the exact lines of code causing delays. By analyzing the trace timeline and annotations, the administrator can identify which specific function calls or operations exceed the timeout threshold, unlike CloudWatch Logs which only show aggregate duration or error strings without code-level granularity.

Exam trap

The trap here is that candidates often confuse CloudWatch Logs or Metrics (which show aggregate data) with the code-level tracing capability of X-Ray, assuming that searching for 'timeout' strings or monitoring 'Duration' metrics will reveal the exact lines of code causing the delay.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs can show 'timeout' strings but cannot trace the exact lines of code causing delays; they only log output from the function, not internal execution flow. Option C is wrong because a CloudWatch Metric Filter for 'Duration' and an alarm only monitors the overall execution time, not the specific code segments or lines responsible for the timeout. Option D is wrong because AWS CloudTrail data events record API calls to the Lambda service (e.g., Invoke, UpdateFunctionCode) but do not capture the internal execution trace or code-level timing within the function.

740
MCQmedium

A company uses Amazon CloudFront to deliver content from an Application Load Balancer (ALB) origin. The SysOps administrator needs to restrict access to the content so that only users from a specific geographic location can view it. Which CloudFront feature should be used?

A.Geographic restrictions (geo-blocking) in CloudFront
B.Origin Access Identity (OAI)
C.Signed URLs
D.AWS WAF web ACL associated with the CloudFront distribution
AnswerA

CloudFront's native geo-restriction feature allows you to configure an allowlist or blocklist of two-letter ISO country codes directly in the distribution's settings. When a viewer in a denied country requests content, CloudFront's edge locations reject the request with an HTTP error before it ever reaches the origin. This works at the edge, requires no code or additional AWS services, and precisely matches the requirement of restricting access by geographic location. Because this feature is built into CloudFront itself, it is the correct choice among the options.

Why this answer

CloudFront's geographic restrictions (geo-blocking) feature allows you to restrict access to content based on the geographic location of the viewer's IP address. This is the simplest and most direct method to ensure only users from a specific country or region can access the content delivered through CloudFront, without requiring any changes to the origin or additional authentication mechanisms.

Exam trap

The trap here is that candidates often confuse AWS WAF's geo-match rules with CloudFront's built-in geographic restrictions, but the question asks for a CloudFront feature, and the native geo-blocking feature is the correct, simpler answer without requiring an additional service.

How to eliminate wrong answers

Option B is wrong because Origin Access Identity (OAI) is used to restrict access to an S3 bucket origin, not to an ALB origin, and it controls access based on identity rather than geography. Option C is wrong because Signed URLs provide time-limited access to individual files for specific users, but they do not restrict access based on geographic location; they are used for authorization, not geo-blocking. Option D is wrong because while AWS WAF can be used with CloudFront to create geo-match conditions, it is an additional service that incurs extra cost and complexity; CloudFront's built-in geographic restrictions are the native, simpler solution for this requirement.

741
MCQeasy

A company uses AWS CloudFormation to deploy a stack that includes an Amazon S3 bucket. The stack creation fails because the S3 bucket name already exists. What should the administrator do to resolve this issue?

A.Add a tag to the existing bucket to make it available for the stack.
B.Change the S3 bucket name in the CloudFormation template to a unique name.
C.Delete the existing S3 bucket and recreate the stack.
D.Update the bucket policy to allow the stack to use the bucket.
AnswerB

Changing the S3 bucket name in the CloudFormation template to a unique name resolves the conflict because the CreateBucket API only needs a name that is not already taken globally. This is the correct approach because it allows CloudFormation to provision a brand-new bucket without naming collision. Alternatively, you could omit the BucketName property entirely so CloudFormation generates a unique name with a random suffix, but specifying a deliberate unique name works equally well.

Why this answer

S3 bucket names are globally unique across all AWS accounts and regions, so CloudFormation cannot create a bucket whose name is already taken by another account. The correct fix is to change the BucketName property in the template to a name that is not in use, then re-run the stack. This resolves the naming collision without touching resources owned by other accounts.

Exam trap

SOA-C02 often tests whether candidates remember that S3 bucket names are globally unique — the tempting wrong answer is to manipulate the existing bucket (tags, policy) rather than rename the one being created.

How to eliminate wrong answers

Option A is wrong because tags are metadata only — they have no bearing on S3's global namespace uniqueness and cannot 'release' a name for another account to use. Option C is wrong because deleting an existing bucket that belongs to another account is not possible (and would be destructive and inappropriate even if it were your own); it also does not address the template's hard-coded name. Option D is wrong because bucket policies control access to an existing bucket, not the ability to create a new bucket with the same name — the CreateBucket call fails before any policy is evaluated.

742
MCQhard

A company is using AWS CloudFormation to manage infrastructure. A recent stack update failed, and the SysOps administrator needs to roll back to the previous known good state. However, the stack is in UPDATE_ROLLBACK_FAILED state. What should the administrator do to recover the stack?

A.Use the ContinueUpdateRollback API or AWS Management Console to resume the rollback after addressing the failure cause
B.Delete the stack and recreate it from the previous template
C.Contact AWS Support to enable automatic rollback recovery
D.Execute another stack update with the same parameters to overwrite the failed state
AnswerA

When a stack update fails and the automatic rollback also fails, the stack enters the UPDATE_ROLLBACK_FAILED state. To recover, you must first resolve the underlying cause, such as an insufficient IAM permission or a resource that cannot be rolled back, then call the ContinueUpdateRollback API or use the AWS Management Console to resume the rollback. This action transitions the stack to UPDATE_ROLLBACK_COMPLETE, restoring it to its last known stable configuration.

Why this answer

When a CloudFormation stack enters UPDATE_ROLLBACK_FAILED, the rollback could not complete because a resource could not be returned to its previous state. The administrator must first fix the underlying resource issue (e.g., a deleted resource, a permission problem, or a resource that cannot be reverted), then invoke ContinueUpdateRollback via the console, CLI, or API to resume the rollback from where it stopped. This preserves the stack and its resources rather than destroying them.

Exam trap

SOA-C02 often tests UPDATE_ROLLBACK_FAILED by tempting candidates with 'delete and recreate' — the correct answer is always to fix the cause and use ContinueUpdateRollback, not to destroy the stack.

How to eliminate wrong answers

Option B is wrong because deleting the stack would destroy all resources and lose the stack's history and outputs — it is a destructive last resort, not the recovery procedure for UPDATE_ROLLBACK_FAILED. Option C is wrong because AWS Support does not enable automatic rollback recovery; the ContinueUpdateRollback action is a customer-controlled API. Option D is wrong because issuing another stack update while the stack is in UPDATE_ROLLBACK_FAILED is not permitted — CloudFormation rejects updates until the rollback is resolved, and even if it were allowed, it would not address the failed rollback state.

743
Multi-Selectmedium

Which TWO of the following are benefits of using Amazon CloudFront in front of an Application Load Balancer? (Select TWO.)

Select 2 answers
A.Simplify VPC endpoint configuration
B.Protect the application against DDoS attacks
C.Offload SSL/TLS termination from the ALB
D.Reduced latency for users by caching content at edge locations
E.Provide a static IP address for the application
AnswersB, D

CloudFront is a global content delivery network that automatically integrates with AWS Shield Standard, providing always-on detection and inline mitigation for L3 and L4 DDoS attacks such as UDP floods and SYN floods. Its large edge footprint and anycast routing absorb and dissipate attack traffic close to the source, preventing it from reaching the origin. For additional protection, you can enable AWS Shield Advanced and combine it with AWS WAF for L7 attack mitigation.

Why this answer

Amazon CloudFront provides AWS Shield Standard automatically, which mitigates common Layer 3/4 DDoS attacks at the edge before traffic reaches the ALB. By absorbing volumetric attacks at CloudFront's globally distributed edge locations, the ALB is shielded from malicious traffic, ensuring application availability. This is a key benefit because ALBs alone do not have built-in DDoS protection beyond basic security group rules.

Exam trap

The trap here is that candidates often select 'Offload SSL/TLS termination from the ALB' (Option C) thinking it is a benefit of using CloudFront in front of an ALB, but this is a general CloudFront feature that applies to any origin, not a specific advantage of the ALB combination, and the ALB can already handle SSL/TLS termination efficiently.

744
Multi-Selectmedium

A company is using AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment fails because the instances do not have the CodeDeploy agent installed. Which THREE actions are required to resolve this issue?

Select 3 answers
A.Install the CodeDeploy agent on the instances using user data in the launch configuration.
B.Create a new AMI that includes the CodeDeploy agent.
C.Use AWS Systems Manager Run Command to install the agent on existing instances.
D.Change the deployment configuration to 'OneAtATime'.
E.Update the Auto Scaling group's launch configuration to use a different instance type.
AnswersA, B, C

User data in the launch configuration runs at each instance boot, so newly launched Auto Scaling instances install the CodeDeploy agent automatically. This satisfies the requirement that instances joining the group have the agent present before CodeDeploy attempts deployment.

Why this answer

The CodeDeploy agent must be present on every instance that participates in a deployment, so the fix is to ensure it is installed on current and future instances. Option A is correct because adding the agent installation commands to the launch configuration's user data ensures that every new instance launched by the Auto Scaling group automatically installs the CodeDeploy agent at boot. Option B is correct because baking the CodeDeploy agent into a custom AMI and using that AMI in the launch configuration guarantees the agent is already present on all newly launched instances without relying on boot-time scripts.

Option C is correct because AWS Systems Manager Run Command can remotely execute the agent installation script on the already-running instances in the Auto Scaling group, fixing the instances that caused the current deployment to fail. Option D is incorrect because changing the deployment configuration to OneAtATime only alters how many instances are updated at a time; it does not install the missing CodeDeploy agent. Option E is incorrect because changing the instance type has no bearing on whether the CodeDeploy agent is installed and will not resolve the failure.

Exam trap

The trap here is that candidates may confuse deployment configuration settings (like 'OneAtATime') with the fundamental requirement of having the agent installed, or think that changing the instance type will somehow resolve the agent dependency.

745
MCQmedium

A company needs to continuously scan Amazon EC2 instances for software vulnerabilities and unintended network exposure. Which AWS service should be used?

A.AWS Config
B.Amazon Inspector
C.AWS Trusted Advisor
D.Amazon GuardDuty
AnswerB

Amazon Inspector is purpose-built for vulnerability management, using an agent installed on EC2 instances to continuously collect telemetry about software packages, network configurations, and running processes. It correlates this data against a database of known Common Vulnerabilities and Exposures (CVEs) and performs network reachability checks to identify exposure of ports and protocols. This provides ongoing, deep scanning of software vulnerabilities and makes Inspector the correct choice.

Why this answer

Amazon Inspector is the correct service because it is specifically designed to automatically scan Amazon EC2 instances for software vulnerabilities (CVEs) and unintended network exposure (network reachability). It uses a combination of a managed agent (for OS-level assessment) and network configuration analysis to produce a detailed findings report, directly meeting the requirement for continuous scanning.

Exam trap

The trap here is that candidates often confuse Amazon Inspector with Amazon GuardDuty, mistakenly thinking GuardDuty performs vulnerability scanning when it actually focuses on threat detection from network and account activity, not on scanning EC2 instances for CVEs or network exposure.

How to eliminate wrong answers

Option A is wrong because AWS Config is a service for evaluating and auditing the configuration of AWS resources against desired policies (e.g., compliance rules), not for scanning for software vulnerabilities or network exposure. Option C is wrong because AWS Trusted Advisor provides high-level best-practice recommendations across cost, performance, security, and fault tolerance, but it does not perform deep vulnerability scanning of EC2 instances. Option D is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events for malicious activity, not for scanning EC2 instances for software vulnerabilities or unintended network exposure.

746
MCQeasy

A company runs a web application on Amazon EC2 instances in an Auto Scaling group. The application stores session state locally on each instance, so users lose their sessions when an instance is replaced. The SysOps administrator needs to make the application stateless so that instances can be replaced without disrupting users. Which action should the administrator take?

A.Configure the Auto Scaling group to use a termination policy that terminates the oldest instance.
B.Increase the instance size to reduce the likelihood of replacement.
C.Store session state in an Amazon ElastiCache for Redis cluster.
D.Enable sticky sessions on the Application Load Balancer.
AnswerC

Externalizing session state to ElastiCache for Redis removes the dependency on local instance storage, allowing any instance in the Auto Scaling group to handle any user's request. When an instance is replaced, the session data remains available in the Redis cluster. This makes the application stateless and supports seamless scaling and recovery.

Why this answer

Moving session state to a centralized, highly available store such as ElastiCache for Redis decouples the application from individual instances. Any instance can then serve any user, so instance replacement or scaling does not cause session loss. This is the standard approach to making a stateful web application stateless in a dynamic Auto Scaling environment.

Exam trap

The trap here is thinking that sticky sessions solve session loss, when they only delay the problem until the bound instance is replaced or fails.

747
Multi-Selecthard

A company is designing a disaster recovery strategy for its AWS environment. The primary Region is us-east-1, and the secondary Region is us-west-2. The application uses Amazon RDS for MySQL, Amazon S3 for static assets, and EC2 instances in an Auto Scaling group. The RTO is 30 minutes, and the RPO is 15 minutes. Which TWO actions should the SysOps administrator take to meet these requirements? (Choose two.)

Select 2 answers
A.Configure a cross-Region read replica for the RDS instance in us-west-2.
B.Deploy a single RDS instance in us-west-2 as a standby.
C.Create AMI backups of EC2 instances every hour and copy to us-west-2.
D.Take daily EBS snapshots and copy them to us-west-2.
E.Enable S3 cross-Region replication for the static assets bucket.
AnswersA, E

A cross-Region read replica in us-west-2 maintains an asynchronous copy of the primary RDS database using the engine's native replication. In a disaster, you can promote the replica to a standalone primary DB instance within minutes, which meets a 15-minute RPO because replication lag is typically well below that threshold and the RTO is minimal. The replica also supports read traffic in the DR Region before promotion, making it a cost-effective and operationally proven pattern for RDS disaster recovery.

Why this answer

A cross-Region read replica in us-west-2 can be promoted to a primary instance in under 30 minutes, and with binary log (binlog) replication it can achieve an RPO of 15 minutes or less. This allows the RDS database to be recovered with minimal data loss in the secondary Region, meeting both the RTO and RPO targets.

Exam trap

The trap here is that candidates often confuse cross-Region read replicas with Multi-AZ deployments, assuming a standby in another Region is sufficient, but Multi-AZ only provides high availability within a single Region and does not support cross-Region disaster recovery with the required RPO.

748
MCQeasy

A company has an AWS Lambda function that processes files uploaded to an S3 bucket. The function fails intermittently with a timeout error. What should the SysOps administrator do to monitor and resolve this issue?

A.Place the S3 bucket in a different AWS region to reduce latency.
B.Enable provisioned concurrency for the Lambda function.
C.Increase the Lambda function timeout and review the function logs in CloudWatch Logs.
D.Configure EC2 Auto Scaling to launch more instances for the Lambda function.
AnswerC

A Lambda timeout error indicates that the function exceeded its configured execution time limit, so increasing the timeout gives the process more time to complete its work. Reviewing CloudWatch Logs is essential to determine why the function is slow, such as inefficient logic, a large download, or a blocking call to another service. After increasing the timeout, verify both the function's memory allocation and the maximum allowed timeout (15 minutes) to ensure the new setting is valid, and monitor logs to confirm the root cause is resolved.

Why this answer

Increasing the Lambda function timeout directly addresses the intermittent timeout error by allowing the function more time to complete execution before Lambda terminates it. Reviewing CloudWatch Logs is essential to identify the root cause, such as slow downstream dependencies or inefficient code, enabling targeted optimization. This approach aligns with standard troubleshooting for Lambda timeout issues.

Exam trap

The trap here is that candidates may confuse Lambda's scaling behavior with EC2 Auto Scaling, or assume that provisioned concurrency fixes execution duration issues, when in fact it only addresses cold start latency.

How to eliminate wrong answers

Option A is wrong because moving the S3 bucket to a different region does not resolve Lambda timeout errors; it may increase latency due to cross-region data transfer and does not affect the function's execution duration. Option B is wrong because provisioned concurrency initializes execution environments to reduce cold starts, but it does not extend the maximum execution time allowed by the Lambda timeout setting. Option D is wrong because EC2 Auto Scaling manages EC2 instances, not Lambda functions; Lambda scales automatically based on incoming requests, and Auto Scaling has no role in Lambda execution.

749
Multi-Selecthard

A SysOps administrator is troubleshooting an issue where an EC2 instance has failed a status check. The instance is still running but is unresponsive. Which THREE actions should the administrator take to diagnose and resolve the issue? (Choose THREE.)

Select 3 answers
A.Reboot the instance.
B.Check the system status checks in the EC2 console.
C.Review the instance system log (console output).
D.Restore the instance from the latest AMI.
E.Stop and start the instance (recovery action).
AnswersB, C, E

Checking the system status checks in the EC2 console is the correct first triage step because these checks directly report on the health of the underlying physical host, network connectivity, and power delivery. A failed system status check (e.g., 'System reachability' or 'Instance connectivity') indicates a hardware-level issue that is independent of the guest OS, guiding you toward a stop/start recovery rather than a reboot. CloudWatch metrics for status checks should also be reviewed to confirm the duration and pattern of the failure.

Why this answer

System status checks (Option B) monitor the underlying physical host for issues like network or power loss, while instance status checks (like system log in Option C) detect OS-level problems. Reviewing the system log helps identify kernel panics or boot failures. Stopping and starting the instance (Option E) forces a migration to a new physical host, which can resolve host-level impairments without losing the instance's configuration or data.

Exam trap

The trap here is that candidates confuse 'reboot' with 'stop/start' — rebooting does not change the underlying host, while stopping and starting does, which is the key recovery action for host-level failures.

750
MCQeasy

A company runs a static website on Amazon S3 with a custom domain name (www.example.com). The website is accessed via Amazon CloudFront. The company's marketing team recently updated the website content, but users are reporting that they still see the old content. The SysOps administrator checks the S3 bucket and confirms that the new files are present. The administrator also checks CloudFront and finds that the default TTL for the cache behavior is 24 hours. The marketing team needs the new content to be visible immediately. What should the administrator do to make the new content available to users as quickly as possible?

A.Disable the CloudFront distribution and re-enable it after 5 minutes.
B.Change the default TTL for the CloudFront cache behavior to 0 seconds.
C.Create a CloudFront invalidation for the path '/*' to remove all cached files.
D.Change the S3 bucket's lifecycle policy to expire objects after 1 day.
AnswerC

Creating an invalidation for the path '/*' issues a request that removes all cached objects from every edge location in the CloudFront distribution. When the invalidation completes, the next request for any of those objects causes CloudFront to go back to the S3 origin and fetch the latest version, thereby ensuring users see updated content. This is the immediate, targeted mechanism designed for exactly this scenario.

Why this answer

CloudFront caches objects at edge locations according to the cache behavior's TTL settings; changing the TTL only affects future cache fills, not objects already cached. To immediately remove stale content from all edge locations, the administrator must create an invalidation for the affected paths — here '/*' invalidates everything. This forces CloudFront to fetch fresh copies from the S3 origin on the next request, making the new content visible right away.

Exam trap

SOA-C02 often tests the misconception that lowering the TTL or restarting the distribution refreshes already-cached content — candidates must remember that only an invalidation (or versioned object keys) evicts objects already stored at edge locations.

How to eliminate wrong answers

Option A is wrong because disabling and re-enabling a distribution does not purge cached objects — the edge caches retain their content, and the distribution also takes time to redeploy, so users would still see stale files. Option B is wrong because setting the default TTL to 0 only affects objects cached after the change; it does not evict objects already stored at edge locations, so existing users continue to receive the old content. Option D is wrong because an S3 lifecycle expiration policy deletes objects after a retention period and has no effect on CloudFront's edge cache or on how quickly updated content propagates.

Page 9

Page 10 of 16

Page 11