Courseiva

AWS Certified SysOps Administrator Associate SOA-C02 (SOA-C02) — Questions 976–1050

1169 questions total · 16pages · All types, answers revealed

Page 13

Page 14 of 16

Page 15
976
MCQeasy

A SysOps administrator needs to ensure that all Amazon S3 buckets in an AWS account are configured with server-side encryption using AWS KMS (SSE-KMS). The administrator wants to automatically detect any S3 buckets that are not compliant and remediate them by enabling SSE-KMS. Which AWS service should be used to implement this automated compliance enforcement?

A.AWS Config
B.AWS Trusted Advisor
C.AWS Service Catalog
D.AWS CloudFormation
AnswerA

AWS Config continuously evaluates S3 bucket configurations against managed rules such as s3-bucket-server-side-encryption-enabled, which specifically verifies that default encryption is set to SSE-KMS. When a bucket is non-compliant, AWS Config can automatically invoke an SSM automation document (e.g., AWS-EnableS3BucketEncryption) to remediate the violation, enforcing SSE-KMS without manual intervention. This real-time monitoring and automated remediation capability is exactly what the SysOps administrator needs to ensure all S3 buckets meet the encryption requirement.

Why this answer

AWS Config is the correct service because it provides managed rules (e.g., s3-bucket-server-side-encryption-enabled) that can continuously evaluate S3 buckets for compliance with SSE-KMS. When a non-compliant bucket is detected, AWS Config can trigger an AWS Systems Manager Automation document or a custom remediation action (via AWS Config Rules remediation) to automatically enable SSE-KMS on the bucket, ensuring automated enforcement without manual intervention.

Exam trap

The trap here is that candidates often confuse AWS Config's reactive compliance monitoring with Trusted Advisor's advisory checks, or assume CloudFormation can handle post-deployment compliance, but only AWS Config provides the continuous evaluation and automated remediation required for this use case.

How to eliminate wrong answers

Option B is wrong because AWS Trusted Advisor only provides reactive recommendations and best-practice checks (e.g., S3 bucket permissions) but does not support automated remediation or custom compliance rules; it cannot automatically enable SSE-KMS on non-compliant buckets. Option C is wrong because AWS Service Catalog is used to create and manage a catalog of approved IT services (e.g., pre-configured S3 bucket templates) but does not perform ongoing compliance monitoring or remediation of existing resources. Option D is wrong because AWS CloudFormation is an infrastructure-as-code service for provisioning resources via templates; it can enforce SSE-KMS at deployment time but cannot automatically detect or remediate non-compliant buckets that already exist or are created outside of CloudFormation stacks.

977
Multi-Selectmedium

Which TWO actions can be used to protect data in transit between an EC2 instance and an S3 bucket? (Choose two.)

Select 2 answers
A.Configure security group rules on the EC2 instance to allow only S3 traffic.
B.Apply an S3 bucket policy that denies access unless the request includes the x-amz-server-side-encryption header.
C.Use HTTPS instead of HTTP when accessing S3 from the EC2 instance.
D.Enable S3 default encryption (SSE-S3) on the bucket.
E.Use S3 VPC endpoints to ensure traffic between the VPC and S3 does not traverse the internet.
AnswersC, E

HTTPS uses TLS to encrypt the entire HTTP request and response payload between the EC2 instance and S3, including object data, providing confidentiality and integrity against eavesdropping and tampering. This is a client-side action: the application must explicitly use the https:// prefix in the S3 endpoint URL, and AWS recommends this as the primary measure for protecting data in transit.

Why this answer

Option C is correct because using HTTPS (TLS) when accessing S3 from the EC2 instance encrypts the data in transit between the instance and S3, protecting it from interception or tampering on the network. Option E is correct because an S3 VPC endpoint (gateway endpoint for S3) keeps traffic between the VPC and S3 on the AWS private network, so it does not traverse the public internet, reducing exposure to interception. Option A is incorrect because security groups control which traffic is allowed to and from the instance but do not encrypt or otherwise protect the data in transit.

Option B is incorrect because the x-amz-server-side-encryption header relates to server-side encryption of data at rest, not protection of data in transit. Option D is incorrect because S3 default encryption (SSE-S3) encrypts objects at rest in the bucket, not data moving between the EC2 instance and S3.

Exam trap

The trap here is confusing encryption in transit (HTTPS) with encryption at rest (SSE-S3 or bucket policies requiring encryption headers), leading candidates to select options that protect data only after it reaches S3 rather than during network transmission.

978
MCQmedium

A company runs a gaming application that uses Amazon EC2 instances to handle real-time multiplayer sessions. The application requires low-latency communication with users around the world. The SysOps administrator needs to accelerate content delivery for non-cacheable, dynamic content (such as real-time game state updates) and also provide static asset delivery. The solution must support both TCP and UDP traffic. Which AWS service should be used?

A.AWS Global Accelerator
B.Amazon CloudFront with origins configured for both dynamic and static content
C.AWS Shield Advanced
D.AWS App Mesh
AnswerA

Global Accelerator uses the AWS global network to optimize the path from users to applications. It supports both TCP and UDP traffic, making it suitable for real-time gaming applications that require low latency for both dynamic data and static assets (if static assets are served from the same endpoint).

Why this answer

AWS Global Accelerator is the correct choice because it uses the AWS global network and Anycast IPs to route TCP and UDP traffic to the optimal endpoint, providing low-latency performance for non-cacheable dynamic content like real-time game state updates. It also supports static asset delivery by directing traffic to origins such as Application Load Balancers or EC2 instances, and it handles both TCP and UDP protocols natively, which is essential for real-time multiplayer gaming.

Exam trap

The trap here is that candidates often assume CloudFront can handle all content delivery scenarios, but it does not support UDP traffic and is designed for cacheable HTTP/HTTPS content, making it unsuitable for real-time multiplayer games that require low-latency UDP communication.

How to eliminate wrong answers

Option B is wrong because Amazon CloudFront is a content delivery network (CDN) optimized for cacheable content (HTTP/HTTPS) and does not support UDP traffic; it cannot accelerate non-cacheable dynamic content with low-latency UDP requirements. Option C is wrong because AWS Shield Advanced is a DDoS protection service that provides mitigation against volumetric attacks, but it does not accelerate content delivery or handle TCP/UDP traffic routing for performance. Option D is wrong because AWS App Mesh is a service mesh for microservices communication within a cluster (e.g., ECS/EKS) and does not provide global traffic acceleration or support for UDP traffic at the edge.

979
MCQeasy

A SysOps administrator needs to deploy a web application stack consisting of an Amazon EC2 instance, an Amazon RDS database, and an Application Load Balancer. The administrator wants to define the infrastructure as code and version control it. Which AWS service should the administrator use?

A.AWS Elastic Beanstalk
B.AWS CloudFormation
C.AWS OpsWorks
D.AWS CodeDeploy
AnswerB

AWS CloudFormation is an Infrastructure-as-Code service that lets you define every AWS resource—VPCs, subnets, EC2 instances, IAM roles, RDS databases, and application-specific components—in a declarative YAML or JSON template. Templates are stored in version control, so deployments are fully repeatable and auditable, and change sets let you preview modifications before executing them. CloudFormation also manages rollbacks on failure and stack lifecycle, making it the most complete and precise tool for provisioning a web application environment from scratch. This is why it is the correct answer for a sysops administrator who needs deterministic, fully controlled deployment.

Why this answer

AWS CloudFormation is the correct choice because it is an Infrastructure as Code (IaC) service that allows you to define and provision AWS resources—such as EC2 instances, RDS databases, and Application Load Balancers—using declarative templates (JSON or YAML). These templates can be version-controlled in a repository like Git, enabling repeatable, auditable deployments. Elastic Beanstalk abstracts infrastructure management but does not give you the same level of granular control over individual resources as CloudFormation.

Exam trap

The trap here is that candidates often confuse AWS Elastic Beanstalk (a PaaS that automates deployment) with Infrastructure as Code, but Elastic Beanstalk does not allow you to version-control the raw infrastructure definition; CloudFormation is the dedicated IaC service for that purpose.

How to eliminate wrong answers

Option A is wrong because AWS Elastic Beanstalk is a Platform as a Service (PaaS) that automates deployment and scaling of applications but does not provide native version control for the underlying infrastructure definition; it manages resources behind the scenes, not as a user-defined IaC template. Option C is wrong because AWS OpsWorks is a configuration management service based on Chef and Puppet, designed for managing server configurations and application stacks, not for declaratively provisioning and version-controlling infrastructure resources like EC2, RDS, and ALB as code. Option D is wrong because AWS CodeDeploy is a deployment automation service that handles code deployment to compute services (e.g., EC2, Lambda) but does not define or provision the underlying infrastructure resources themselves.

980
MCQmedium

A SysOps administrator needs to ensure that all API calls made to AWS are logged for auditing purposes. Which AWS service should be enabled to capture management events?

A.AWS CloudTrail
B.S3 server access logs
C.VPC Flow Logs
D.Amazon CloudWatch Logs
AnswerA

AWS CloudTrail is the correct service because it records API activity across all AWS services, capturing the identity of the caller, the time of the call, the source IP address, and the user agent. Management events are logged and can be delivered to an S3 bucket or CloudWatch Logs for governance, compliance, and operational auditing. CloudTrail is specifically designed to answer 'who did what and when' at the API level, making it the authoritative audit trail for API calls in an AWS account.

Why this answer

AWS CloudTrail is the service specifically designed to record API activity in an AWS account, including management events (control plane operations) such as creating, modifying, or deleting resources. It captures the identity of the caller, the time of the call, the source IP address, and other details, making it the correct choice for auditing API calls. CloudTrail logs can be delivered to an S3 bucket and optionally to CloudWatch Logs for further analysis.

Exam trap

SOA-C02 often tests the distinction between services that log API activity (CloudTrail) and those that log network traffic (VPC Flow Logs) or resource access (S3 server access logs). Candidates may incorrectly choose CloudWatch Logs because it sounds like a logging service, but it does not capture API calls natively.

How to eliminate wrong answers

Option B is wrong because S3 server access logs record requests made to an S3 bucket (data plane operations) and do not capture API calls across all AWS services. Option C is wrong because VPC Flow Logs capture IP traffic metadata for network interfaces, not API calls. Option D is wrong because Amazon CloudWatch Logs is a log storage and analysis service, not a service that itself captures API calls; it can receive CloudTrail logs but is not the source.

981
MCQeasy

A SysOps administrator needs to reduce costs for a non-production environment that runs 24/7 but is only used during business hours. What is the MOST effective action?

A.Create a schedule to stop instances after business hours and start them before.
B.Switch all instances to Spot Instances.
C.Purchase Reserved Instances for the environment.
D.Reduce the instance sizes to the smallest available.
AnswerA

Stopping EC2 instances outside of business hours eliminates per-second compute charges while they are in the stopped state, while EBS volumes and their data persist. You can use AWS Instance Scheduler or Systems Manager Automation to codify the start/stop routine, ensuring instances are only running when needed. This approach directly targets idle compute waste without deprovisioning the environment.

Why this answer

Creating a schedule to stop instances after business hours and start them before business hours is the most effective cost-saving action because it directly reduces the hours the instances run, which is the primary cost driver for EC2. Since the environment is only used during business hours, stopping instances during off-hours eliminates unnecessary compute charges. This approach is simple, requires no architectural changes, and yields immediate savings.

Exam trap

SOA-C02 often tests the difference between cost-saving measures that reduce usage versus those that reduce rates; candidates may choose Reserved Instances or Spot, but stopping instances is most effective for intermittent usage.

How to eliminate wrong answers

Option B is wrong because Spot Instances can reduce costs but are not suitable for all workloads due to potential interruptions; they are best for fault-tolerant, flexible workloads, and may not be appropriate for a non-production environment that might need to be available. Option C is wrong because Reserved Instances provide discounts for committed usage, but if the instances are only used during business hours, you're still paying for 24/7 reservation, which is not cost-effective. Option D is wrong because reducing instance sizes may not be possible without performance impact, and it doesn't address the fact that instances run 24/7; it's a vertical scaling approach that may not yield significant savings compared to stopping them.

982
Multi-Selecteasy

A SysOps administrator is configuring a new VPC and wants to ensure that only traffic from a specific IP address range can access an EC2 instance via SSH. Which TWO components should be configured? (Choose two.)

Select 2 answers
A.VPC endpoint
B.Network ACL (NACL)
C.Security group
D.Internet gateway
E.Route table
AnswersB, C

A network ACL is a stateless virtual firewall at the subnet boundary. It evaluates ingress and egress rules independently, so to allow SSH from a specific CIDR you must add an inbound allow rule and a corresponding outbound rule for ephemeral ports. NACLs can explicitly deny traffic (e.g., block a hostile IP) and are applied to all instances in the subnet, making them an effective subnet-level control for SSH.

Why this answer

To restrict SSH access to a specific IP range, you configure a network ACL at the subnet level and a security group at the instance level. NACLs are stateless and evaluate rules in order; security groups are stateful. Both can allow inbound SSH from the specific IP range.

Internet gateway enables internet access but does not filter by IP. Route tables direct traffic but do not filter. VPC endpoint is for private connectivity to AWS services.

983
MCQeasy

A company uses CloudFront to distribute content globally. They want to reduce data transfer costs and improve performance for users. What feature should they enable?

A.Configure multiple origins with failover.
B.Enable Lambda@Edge to modify requests and responses.
C.Enable Origin Shield to create a central caching layer.
D.Increase the TTL for cache behaviors to the maximum allowed value.
AnswerC

Origin Shield adds a centralized caching layer in a specific AWS Region, so all CloudFront edge locations forward cache misses to that single regional endpoint rather than directly to your origin. This consolidates requests from multiple edges, dramatically improving the global cache hit ratio and reducing both the volume of origin requests and the data transfer from origin to edges—and because you pay less for data transfer and origin load, it directly lowers your cost. Origin Shield is an AWS-native feature purpose-built for this cost-reduction scenario.

Why this answer

Origin Shield adds an additional caching layer between CloudFront edge locations and the origin, consolidating origin fetches through a single regional cache. This reduces the number of requests that reach the origin, lowering data transfer costs and improving cache hit ratios and latency for users. It is the specific CloudFront feature designed for this cost-and-performance goal.

Exam trap

SOA-C02 often tests the confusion between caching optimizations (TTL, Origin Shield) and availability features (multi-origin failover), causing candidates to pick TTL or failover when the question specifically asks about reducing origin load and data transfer cost.

How to eliminate wrong answers

Option A is wrong because multiple origins with failover improves availability and resilience, not caching efficiency or data transfer cost. Option B is wrong because Lambda@Edge runs custom code at edge locations to modify requests/responses; it does not inherently reduce origin fetches or data transfer costs. Option D is wrong because increasing TTL to the maximum can improve cache hit ratio but does not create a centralized caching layer, and it can serve stale content; it is not the targeted feature for reducing origin load and cost.

984
MCQeasy

A company is designing a highly available architecture for a web application using an Application Load Balancer (ALB) across multiple Availability Zones. Which configuration ensures that traffic is distributed evenly across all healthy targets?

A.Enable cross-zone load balancing on the ALB
B.Configure sticky sessions (session affinity) on the target group
C.Use a Network Load Balancer with path-based routing
D.Enable connection draining on the target group
AnswerA

Enabling cross-zone load balancing on the ALB allows the load balancer to distribute incoming traffic evenly across all registered targets in all enabled Availability Zones, rather than confining traffic to targets within the same AZ. This is the correct approach because it ensures optimal resource utilization and fault tolerance, especially when workloads or target capacities vary across AZs. Without this feature, each AZ would receive an equal share of traffic, but targets within a less capable AZ could become overwhelmed.

Why this answer

Cross-zone load balancing enables the ALB to distribute incoming traffic evenly across all healthy targets in all enabled Availability Zones, rather than sending traffic only to targets within the same zone as the requesting client. By default, ALBs distribute traffic equally across zones first, then round-robin within each zone, which can lead to uneven load if target counts differ per zone. Enabling cross-zone load balancing overrides this behavior, ensuring each healthy target receives an equal share of requests regardless of its zone.

Exam trap

The trap here is that candidates often confuse cross-zone load balancing with sticky sessions or connection draining, assuming that session affinity or graceful termination will improve distribution, when in fact only cross-zone load balancing ensures even traffic spread across all healthy targets.

How to eliminate wrong answers

Option B is wrong because sticky sessions (session affinity) bind a client to a specific target for the duration of its session, which can cause uneven traffic distribution and does not ensure even distribution across all healthy targets. Option C is wrong because a Network Load Balancer (NLB) does not support path-based routing; path-based routing is a feature of Application Load Balancers, and using an NLB would not address the requirement for even distribution across healthy targets. Option D is wrong because connection draining (deregistration delay) allows in-flight requests to complete before a target is removed from service, but it does not influence how traffic is distributed among healthy targets during normal operation.

985
MCQmedium

Refer to the exhibit. A SysOps administrator creates the CloudWatch Alarm shown. However, the alarm never enters ALARM state even though the CPU utilization of the EC2 instance is consistently above 90%. What is the most likely reason?

A.The alarm is missing the InstanceId dimension.
B.The threshold is set too high; it should be 80%.
C.The evaluation periods are too few.
D.The statistic should be Maximum instead of Average.
AnswerA

A CloudWatch EC2 metric such as CPUUtilization is published with an InstanceId dimension, and the metric name alone is ambiguous because multiple instances in the account can have similar CPU data. Without the InstanceId dimension, the alarm cannot select the specific instance's metric stream; in practice, the alarm will either fail validation or remain in INSUFFICIENT_DATA because no datapoints match the metric signature. Adding the InstanceId dimension scopes the alarm to the instance shown in the exhibit, which lets CloudWatch evaluate that instance's CPU utilization against the threshold.

Why this answer

The alarm never enters ALARM state because it is missing the required `InstanceId` dimension. CloudWatch metrics for EC2, such as `CPUUtilization`, are published with the `InstanceId` dimension to uniquely identify the data stream. Without specifying this dimension in the alarm configuration, CloudWatch cannot match the alarm to the metric data emitted by the EC2 instance, so the alarm remains in INSUFFICIENT_DATA or OK state regardless of actual CPU usage.

Exam trap

The trap here is that candidates focus on tuning threshold or evaluation periods, overlooking the fundamental requirement that CloudWatch alarms must include the correct dimensions to match the metric data stream.

How to eliminate wrong answers

Option B is wrong because the threshold being set to 90% is not the issue; the alarm never evaluates the metric at all due to the missing dimension, so adjusting the threshold would not fix the problem. Option C is wrong because the evaluation periods being too few would cause the alarm to take longer to trigger or require more consecutive datapoints, but it would still eventually enter ALARM state if the metric were being evaluated; here the alarm never evaluates due to the missing dimension. Option D is wrong because using Average vs Maximum might affect sensitivity, but the alarm is not receiving any metric data to evaluate, so changing the statistic would not resolve the missing dimension issue.

986
MCQeasy

A company wants to ensure that its Amazon RDS database can withstand the loss of an entire Availability Zone. Which feature should the SysOps administrator enable?

A.Enable automated backups with a retention period of 35 days.
B.Enable Multi-AZ deployment.
C.Take manual snapshots and copy them to another Region.
D.Create a read replica in a different Availability Zone.
AnswerB

Multi-AZ deployment maintains a synchronous standby replica in a separate Availability Zone, enabling automatic failover if one AZ is lost. This directly satisfies the requirement to survive an entire Availability Zone failure without manual intervention.

Why this answer

Multi-AZ deployment for Amazon RDS automatically provisions and maintains a synchronous standby replica in a different Availability Zone. If the primary AZ fails, Amazon RDS automatically fails over to the standby, ensuring database availability without manual intervention. This is the only option that directly protects against an entire AZ loss by maintaining a hot standby in a separate AZ.

Exam trap

The trap here is that candidates often confuse a read replica with a Multi-AZ standby, assuming that a read replica in a different AZ can be promoted for failover, but read replicas are asynchronous and require manual promotion, whereas Multi-AZ provides automatic synchronous failover.

How to eliminate wrong answers

Option A is wrong because automated backups with a retention period of 35 days only provide point-in-time recovery to a specific time, not automatic failover or high availability; they do not protect against AZ loss as they are stored within the same Region but not in a separate AZ for immediate failover. Option C is wrong because manual snapshots copied to another Region provide disaster recovery across Regions, not high availability within a Region; they require manual restoration and do not offer automatic failover if an AZ fails. Option D is wrong because a read replica in a different AZ is an asynchronous copy used for offloading read traffic, not for automatic failover; it does not provide synchronous replication or automatic promotion to primary in case of AZ failure, and promoting it requires manual intervention.

987
Multi-Selectmedium

A company has a CloudWatch dashboard that displays metrics for several EC2 instances. The SysOps administrator wants to share the dashboard with external stakeholders who do not have AWS accounts. Which actions should the administrator take? (Select TWO.)

Select 2 answers
A.Use the CloudWatch dashboard sharing feature to make the dashboard public.
B.Create a web application that reads CloudWatch metrics and host it on EC2.
C.Create IAM users for each stakeholder and assign appropriate permissions.
D.Generate a shareable URL for the dashboard and send it to the stakeholders.
E.Export the dashboard to Amazon QuickSight and share it via email.
AnswersA, D

The CloudWatch dashboard sharing feature provides a built-in mechanism to expose a dashboard to anyone via a public link without requiring AWS credentials or sign-in. This is the most direct solution for external stakeholders because they only need the URL to view the live metrics, and you can revoke access by disabling sharing at any time. It avoids the need to create AWS identities or build custom applications.

Why this answer

Option A is correct because CloudWatch dashboards support a built-in sharing feature that lets you share a dashboard publicly with anyone, including people who do not have AWS accounts, by configuring the dashboard's share settings. Option D is correct because after enabling sharing, CloudWatch generates a shareable URL that can be sent to external stakeholders so they can view the dashboard without signing in to AWS. Options B, C, and E are not appropriate: building a custom EC2 web application is unnecessary and overly complex, creating IAM users requires stakeholders to have AWS accounts and credentials, and exporting to QuickSight is not a supported CloudWatch dashboard sharing mechanism for anonymous external viewers.

Exam trap

The trap here is that candidates often confuse the CloudWatch dashboard sharing feature with IAM-based access, assuming external users must have AWS credentials, when in fact the public URL mechanism is designed specifically for sharing with non-AWS users.

988
MCQhard

An organization uses AWS OpsWorks for configuration management. The SysOps administrator notices that a stack's instances are not receiving the updated custom cookbooks after a new deployment. The cookbooks are stored in a private GitHub repository. What is the most likely cause?

A.The cookbooks are not stored in an S3 bucket.
B.The OpsWorks agent is not running on the instances.
C.The instances do not have internet access.
D.The SSH key for the Git repository is not configured in the stack.
AnswerD

Correct. AWS OpsWorks uses the SSH key stored in the stack configuration to authenticate with private GitHub repositories. If the key is missing or invalid, the instances cannot download the updated cookbooks, causing the failure.

Why this answer

The most likely cause is that the SSH key for the Git repository is not configured in the stack. AWS OpsWorks uses SSH keys to authenticate to private Git repositories when deploying custom cookbooks. Without the correct key, the instances cannot pull the updated cookbooks, resulting in deployment failures or outdated cookbooks.

Exam trap

The trap is assuming that internet access alone is sufficient for private repository access, overlooking the need for authentication credentials like SSH keys.

How to eliminate wrong answers

Option A is wrong because OpsWorks supports custom cookbooks from Git repositories, not just S3; storing in S3 is not a requirement. Option B is wrong because if the OpsWorks agent were not running, the instances would not be managed at all, and other symptoms like missing lifecycle events would occur. Option C is wrong because instances can access the internet via NAT or other means, but even with internet access, authentication to a private repository requires the SSH key; lack of internet would cause broader connectivity issues.

989
MCQeasy

A SysOps administrator needs to centralize logs from multiple AWS accounts into a single S3 bucket for analysis. Which solution is the MOST operationally efficient?

A.Use S3 replication to copy logs from each account's bucket to a central bucket.
B.Use CloudWatch Logs subscription filter to stream logs to a central account.
C.Use Amazon Kinesis Data Firehose to deliver logs from each account to a central S3 bucket.
D.Configure CloudTrail in each account to deliver logs to the same S3 bucket in the central account.
AnswerD

Configure each account's CloudTrail trail to deliver logs to the same central S3 bucket by creating a shared destination bucket with a bucket policy that trusts the CloudTrail service principal (cloudtrail.amazonaws.com) and grants write permissions to each source account. Set a distinct log-file prefix per account or enable partition-based prefixes to keep logs organized, and ensure the bucket versioning is enabled for log integrity. This is the standard, AWS-supported method for centralizing CloudTrail logs across multiple accounts, requiring no replication, streaming, or additional services.

Why this answer

AWS CloudTrail can be configured in each account to deliver logs directly to the same S3 bucket in a central account by specifying the central bucket's ARN and setting appropriate bucket policies. This approach is operationally efficient as it eliminates the need for intermediate services or replication, reducing complexity and cost while ensuring logs are centralized without manual intervention.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing Kinesis or replication, missing that CloudTrail natively supports cross-account S3 delivery, which is the simplest and most cost-effective method for centralizing logs.

How to eliminate wrong answers

Option A is wrong because S3 replication requires logs to first be delivered to separate buckets in each account, then replicated to a central bucket, adding latency, storage costs, and management overhead; it is not the most operationally efficient. Option B is wrong because CloudWatch Logs subscription filters are designed to stream logs to a central account for real-time processing, but they require additional configuration and do not directly deliver to S3 without an intermediary like Kinesis or Lambda, making it less efficient for simple centralized storage. Option C is wrong because Amazon Kinesis Data Firehose introduces an unnecessary streaming layer and additional cost for a batch-logging use case, whereas CloudTrail can directly write to S3 without extra services.

990
MCQmedium

A company uses AWS CloudFormation to manage infrastructure. A developer accidentally deletes a resource from the stack template, and the next stack update attempts to delete the resource. The SysOps administrator wants to prevent accidental deletion of critical resources. Which CloudFormation feature should be used?

A.Enable termination protection on the stack.
B.Stack policy to deny delete actions.
C.Set a DeletionPolicy attribute to 'Retain' on the resource.
D.Attach an IAM policy that denies cloudformation:DeleteStack.
AnswerC

Setting the DeletionPolicy attribute to 'Retain' is the correct mechanism. It instructs CloudFormation to keep the resource and its contents when the resource is removed from the stack template, whether during an update or a stack deletion. The resource is simply orphaned from CloudFormation management, allowing you to preserve data such as an S3 bucket or RDS database for later use or manual cleanup.

Why this answer

The DeletionPolicy attribute set to 'Retain' on a resource ensures that CloudFormation will preserve the resource even if it is removed from the stack template or the stack itself is deleted. This directly prevents accidental deletion of critical resources during stack updates. It is a resource-level safeguard, not a stack-level one.

Exam trap

SOA-C02 often tests the difference between stack-level protections (termination protection, IAM policies) and resource-level protections (DeletionPolicy), causing candidates to choose stack-level options when the question asks about preventing deletion of a specific resource.

How to eliminate wrong answers

Option A is wrong because termination protection only prevents deletion of the entire stack, not individual resources removed from the template. Option B is wrong because a stack policy can deny update actions on specific resources, but it does not prevent deletion when the resource is removed from the template; it only blocks updates that would modify or delete the resource, but the resource would still be deleted if the policy allows it. Option D is wrong because an IAM policy denying cloudformation:DeleteStack only prevents stack deletion, not resource deletion during a stack update.

991
MCQmedium

A company runs a batch processing application on Amazon EC2 instances every night. The job takes exactly 1 hour to complete and is time-sensitive. The SysOps administrator wants to minimize compute costs while ensuring the job can be interrupted and resumed if needed. Which EC2 purchasing option is most cost-effective?

A.On-Demand Instances
B.Reserved Instances (Standard 1-year)
C.Spot Instances
D.Dedicated Hosts
AnswerC

Spot Instances let you bid for unused EC2 capacity at discounts of up to 90% compared to On-Demand pricing. AWS can reclaim that capacity with a two-minute interruption notice, but because this batch processing job is checkpointed and resumable, an interruption simply means restarting from the last saved state and continuing toward completion. This makes Spot the most cost-effective option for this workload, especially since the job is inherently fault-tolerant and runs only for short periods.

Why this answer

Spot Instances are the most cost-effective option because the batch job is fault-tolerant (can be interrupted and resumed) and runs for exactly 1 hour nightly. Spot Instances offer up to 90% discount compared to On-Demand, and with the ability to handle interruptions via checkpointing, they meet the requirement for cost minimization while supporting resumption.

Exam trap

The trap here is that candidates often assume Spot Instances are unsuitable for time-sensitive jobs due to potential interruptions, but the question explicitly states the job can be interrupted and resumed, making Spot the correct cost-effective choice over Reserved Instances or On-Demand.

How to eliminate wrong answers

Option A is wrong because On-Demand Instances provide no discount and are the most expensive option for a predictable nightly workload, failing to minimize costs. Option B is wrong because Reserved Instances require a 1-year commitment and are not cost-effective for a job that runs only 1 hour per night, as the upfront cost would not be amortized efficiently. Option D is wrong because Dedicated Hosts are designed for licensing or compliance requirements, not for cost savings, and are significantly more expensive than other options for this use case.

992
Multi-Selectmedium

A company is using Amazon CloudWatch Logs to centralize logs from multiple EC2 instances. The SysOps administrator needs to ensure that log data is encrypted at rest and in transit. Which TWO actions should the administrator take? (Choose TWO.)

Select 2 answers
A.Encrypt the CloudWatch Logs log group using an AWS KMS customer managed key.
B.Enable server-side encryption with S3-managed keys (SSE-S3) on the CloudWatch Logs log group.
C.Apply an S3 bucket policy that requires encryption for objects uploaded to the bucket.
D.Configure the CloudWatch Logs agent to use TLS/SSL for log delivery.
E.Install an AWS Certificate Manager (ACM) certificate on the EC2 instances.
AnswersA, D

CloudWatch Logs supports encryption at rest by associating an AWS KMS customer managed key with the log group. When this key is attached, every incoming log event is encrypted before storage and decrypted only by authorized readers; you must grant the CloudWatch Logs service permission to use the key via key policies. Using a customer managed key allows you to control rotation, access, and lifecycle independently of the default AWS-managed aws/logs key.

Why this answer

CloudWatch Logs supports encryption at rest using AWS KMS customer managed keys (CMKs). By associating a KMS key with a log group, all log data stored in that log group is encrypted at rest, meeting the encryption-at-rest requirement. Option D is correct because the CloudWatch Logs agent can be configured to use TLS/SSL (port 443) for log delivery, ensuring encryption in transit between the EC2 instances and CloudWatch Logs.

Exam trap

The trap here is that candidates may confuse CloudWatch Logs encryption with S3 server-side encryption options (SSE-S3 or SSE-KMS) or assume that ACM certificates are needed for agent-to-service encryption, when in fact the CloudWatch Logs agent uses AWS SDK-managed TLS automatically.

993
MCQmedium

A SysOps administrator needs to monitor Amazon S3 for object-level operations such as PUT and DELETE events in a specific bucket. The administrator wants these events to be sent to an Amazon SQS queue for downstream processing by an application. Which solution should be used to achieve this with the least operational overhead?

A.Use Amazon CloudWatch Events to match S3 API calls from CloudTrail and route to an SQS queue.
B.Configure an S3 event notification on the bucket to send events to an SQS queue.
C.Deploy an application that periodically polls S3 for changes using ListObjects.
D.Use AWS CloudTrail to deliver logs to CloudWatch Logs, then create a metric filter and trigger a Lambda function to send to SQS.
AnswerB

S3 bucket event notifications natively publish a rich event envelope (bucket, object key, size, etag) to a designated SQS queue as soon as the object operation completes, making them the most direct, low-latency mechanism for this requirement. The integration is fully managed: you enable the notification in the bucket configuration, attach an SQS resource policy that allows S3 to send messages, and S3 handles retries and batching automatically. This eliminates the need for custom intermediaries or polling, and supports prefix/suffix filters so the queue only receives relevant object events.

Why this answer

Amazon S3 can directly publish event notifications for object-level operations (e.g., PUT, DELETE) to an SQS queue without any intermediate services. This native integration requires no custom code or additional infrastructure, minimizing operational overhead while meeting the requirement to send events to SQS for downstream processing.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing CloudTrail or Lambda-based approaches, forgetting that S3 has a built-in, direct event notification feature for SQS that requires no additional services.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Events can match S3 API calls from CloudTrail, but this approach requires enabling CloudTrail and incurs additional cost and complexity; it also introduces latency and is not the simplest native method for S3 event delivery to SQS. Option C is wrong because periodically polling S3 with ListObjects is inefficient, does not capture real-time events, and introduces significant operational overhead for an application that must detect changes. Option D is wrong because it chains CloudTrail logs to CloudWatch Logs, then uses a metric filter and Lambda to send to SQS, adding multiple layers of complexity, cost, and potential failure points compared to the direct S3 event notification.

994
MCQeasy

Refer to the exhibit. An IAM policy is attached to a user. What is the effective permission regarding the s3:DeleteObject action on the example-bucket?

A.Denied because of the explicit Deny statement
B.Denied because the action is not allowed explicitly
C.Allowed because the Allow statement is listed first
D.Allowed because the Deny statement has a typo
AnswerA

The presence of an explicit Deny statement for the s3:DeleteObject action creates an unresolvable conflict with the Allow statement in the same policy. AWS IAM evaluates all policies and any explicit Deny always overrides every Allow, regardless of how broad or specific the Allow may be. Even though the first statement grants all S3 actions, the Deny takes precedence and the request is ultimately denied.

Why this answer

The effective permission is Denied because of the explicit Deny statement. In AWS IAM policy evaluation, an explicit Deny always overrides any Allow, regardless of the order in which statements appear or whether the action is otherwise permitted. Since the policy contains an explicit Deny for s3:DeleteObject on example-bucket, the request is denied.

Exam trap

SOA-C02 often tests whether candidates know that explicit Deny always wins over Allow and that statement order in an IAM policy is irrelevant to evaluation.

How to eliminate wrong answers

Option B is wrong because the action is explicitly denied, not merely absent from an Allow statement; the presence of an explicit Deny makes the distinction between implicit and explicit denial irrelevant here. Option C is wrong because statement order in an IAM policy has no effect on evaluation; AWS evaluates all statements and applies the explicit Deny rule regardless of ordering. Option D is wrong because a typo in the Deny statement would only matter if it prevented the Deny from matching the action or resource; the question states the Deny applies, and typos do not convert a Deny into an Allow.

995
MCQmedium

An organization requires that all Amazon S3 buckets be encrypted with AES-256 server-side encryption. A SysOps administrator needs to enforce this policy across the entire AWS account. Which action should be taken?

A.Enable default encryption on all existing and future S3 buckets.
B.Use AWS CloudTrail to monitor uploads without encryption and alert the administrator.
C.Use S3 Inventory to list unencrypted objects and remediate them manually.
D.Apply an S3 bucket policy that denies s3:PutObject unless the request includes the x-amz-server-side-encryption header set to AES256.
AnswerD

This bucket policy is the correct preventive control. By using a Deny statement with the s3:x-amz-server-side-encryption condition key and the StringNotEquals operator, S3 evaluates the policy before accepting any PUT and rejects the request unless the header is exactly AES256. This forces every upload—from CLI, SDKs, or other IAM principals—to explicitly request SSE-S3 encryption, and it overrides any default bucket encryption behavior because the policy blocks requests that do not meet the condition.

Why this answer

A bucket policy that denies PutObject without the x-amz-server-side-encryption header set to AES256 will enforce encryption. Option A is wrong because default encryption does not prevent objects from being uploaded without encryption header. Option B is wrong because CloudTrail logs but does not enforce.

Option C is wrong because S3 Inventory does not enforce.

996
Multi-Selecthard

A company is using AWS CloudTrail to log all API calls. The security team wants to ensure that logs are tamper-proof and stored securely. Which TWO actions should be taken? (Choose two.)

Select 2 answers
A.Write logs to a different AWS account.
B.Encrypt the CloudTrail log files with SSE-KMS.
C.Enable MFA Delete on the S3 bucket.
D.Enable S3 server access logs.
E.Enable CloudTrail log file validation.
AnswersB, E

SSE-KMS encrypts the CloudTrail log files at rest using a customer managed AWS KMS key, so an unauthorized user who gains access to the S3 bucket cannot read the logs without also having kms:Decrypt permissions. This protects the confidentiality of the log data, though it must be paired with log file validation to prove the logs have not been altered.

Why this answer

Option B is correct because enabling SSE-KMS encryption on the S3 bucket that receives CloudTrail logs protects the log files at rest with AWS KMS keys, ensuring confidentiality and helping meet the requirement that logs are stored securely. Option E is correct because CloudTrail log file validation creates a digitally signed digest file for each log, allowing you to verify that logs have not been altered or deleted after delivery, which directly addresses tamper-proofing. Option A is not required for tamper-proofing or secure storage; while a separate account can improve isolation, it is not one of the two actions that specifically ensure integrity and encryption.

Option C (MFA Delete) adds protection against accidental or unauthorized deletion but does not itself make log contents tamper-proof or encrypted. Option D (S3 server access logs) only records access requests to the bucket and does not provide integrity validation or encryption of CloudTrail logs.

Exam trap

SOA-C02 often tests the distinction between access control (who can read/delete) and integrity verification (detecting tampering) — candidates pick MFA Delete or cross-account logging as tamper-proofing, but the exam expects SSE-KMS for confidentiality and log file validation for integrity.

997
MCQeasy

A company runs containerized applications on Amazon ECS using the Fargate launch type. The SysOps administrator needs to monitor CPU and memory utilization at the task level. Which AWS service provides pre-built dashboards and metrics for this purpose?

A.Amazon CloudWatch Container Insights
B.Amazon CloudWatch custom metrics
C.Amazon CloudWatch Logs
D.Amazon CloudWatch Synthetics
AnswerA

Amazon CloudWatch Container Insights automatically collects and aggregates CPU, memory, disk, network, and task-level metrics from ECS clusters, services, and tasks, then displays them on prebuilt, out-of-the-box dashboards without requiring custom instrumentation. For ECS on EC2, you run the CloudWatch agent as a daemon service; for Fargate, you simply enable the cluster setting. This is exactly the native, low-effort monitoring solution that matches the scenario.

Why this answer

Amazon CloudWatch Container Insights provides pre-built dashboards and metrics specifically for monitoring containerized applications, including CPU and memory utilization at the task level for Amazon ECS with the Fargate launch type. It automatically collects, aggregates, and summarizes metrics and logs from containerized applications, offering out-of-the-box visualizations without requiring custom setup.

Exam trap

The trap here is that candidates may confuse CloudWatch Logs (which stores logs) with Container Insights (which provides pre-built dashboards and metrics), or assume custom metrics are required when a managed solution already exists.

How to eliminate wrong answers

Option B is wrong because Amazon CloudWatch custom metrics require manual creation and publishing of metrics via the PutMetricData API, which is not a pre-built dashboard solution and adds operational overhead. Option C is wrong because Amazon CloudWatch Logs is designed for log storage, search, and analysis, not for providing pre-built dashboards or metrics for CPU and memory utilization. Option D is wrong because Amazon CloudWatch Synthetics is used for monitoring application endpoints and APIs through canary tests, not for collecting or visualizing CPU and memory metrics from ECS tasks.

998
MCQhard

An organization has a production AWS environment with multiple VPCs and hundreds of EC2 instances. The security team wants to be alerted when any security group is modified. Which approach should a SysOps administrator use to meet this requirement with minimal overhead?

A.Enable CloudTrail and create a CloudWatch alarm for each security group modification event.
B.Use AWS Config rules to detect security group changes and trigger an SNS notification.
C.Enable VPC Flow Logs and analyze them with Amazon Athena for security group changes.
D.Deploy Amazon GuardDuty to monitor for security group modifications.
AnswerB

AWS Config records every change to security group resources as a configuration item and can evaluate those changes using managed or custom rules. When a rule marks a security group as noncompliant, AWS Config can send an alert through an SNS topic that you configure, giving you immediate notification of the modification. This approach both detects the change and enforces your security policies, unlike simply logging API activity or monitoring traffic.

Why this answer

AWS Config rules can continuously evaluate security group configurations against desired settings and trigger an SNS notification when a change is detected. This approach provides automated, event-driven monitoring with minimal operational overhead, as it does not require custom scripts or manual log analysis.

Exam trap

The trap here is confusing CloudTrail event monitoring with AWS Config's configuration change detection, leading candidates to choose CloudTrail-based alarms despite the higher overhead and lack of direct compliance evaluation.

How to eliminate wrong answers

Option A is wrong because CloudTrail logs API calls for security group modifications, but creating a CloudWatch alarm for each event would require custom metric filters and alarms, adding complexity and overhead; it also does not provide direct configuration compliance evaluation. Option C is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols), not security group configuration changes, so they cannot detect modifications to security group rules. Option D is wrong because Amazon GuardDuty is a threat detection service that analyzes network and account activity for malicious behavior, not for tracking configuration changes like security group modifications.

999
Multi-Selecteasy

Which TWO security measures should be implemented to protect a VPC from DDoS attacks? (Choose two.)

Select 2 answers
A.Use AWS WAF with rate-based rules
B.Enable AWS Shield Advanced
C.Apply network ACLs with deny rules
D.Use restrictive security groups
E.Enable VPC Flow Logs
AnswersA, B

AWS WAF rate-based rules are specifically engineered to mitigate application-layer DDoS attacks by tracking the number of requests from a single client IP within a set time window. When the request count exceeds the configured threshold, AWS WAF blocks subsequent traffic from that IP for the rule's duration, effectively limiting the volume of requests that can reach your origin. This provides an automated, scalable defense that can be attached to Amazon CloudFront, ALB, or API Gateway, and it allows you to fine-tune thresholds based on your normal traffic baseline.

Why this answer

AWS WAF with rate-based rules (option A) is correct because it can inspect incoming HTTP/HTTPS requests at the application layer and automatically block or throttle source IPs that exceed a defined request threshold, which directly mitigates application-layer (Layer 7) DDoS floods against resources like an ALB or CloudFront. AWS Shield Advanced (option B) is correct because it provides enhanced, always-on detection and automatic inline mitigation for Layer 3/4 (and Layer 7 with WAF integration) DDoS attacks, plus access to the AWS DDoS Response Team and cost protection for scaling charges incurred during an attack. The other options are not the intended answers: network ACLs with deny rules (C) and restrictive security groups (D) are stateful/stateless traffic filters that can block known bad ports or sources but cannot detect or absorb volumetric or application-layer DDoS patterns, and VPC Flow Logs (E) only capture IP traffic metadata for monitoring and forensics—they do not block or mitigate attacks.

Exam trap

SOA-C02 often tests the confusion between preventive security controls (security groups, NACLs) and DDoS-specific services (Shield, WAF), tricking candidates into selecting generic firewall controls that cannot mitigate volumetric attacks.

1000
Multi-Selecteasy

A company is using Amazon S3 to store media files. The files are accessed frequently for the first 90 days, then rarely after that. The company wants to optimize storage costs. Which TWO actions should the SysOps administrator take? (Choose two.)

Select 2 answers
A.Configure a lifecycle policy to delete incomplete multipart uploads after 7 days
B.Enable S3 Object Lock to prevent deletion
C.Create a lifecycle policy to transition objects to S3 Standard-IA after 90 days
D.Enable S3 Versioning to keep multiple versions
E.Enable Requester Pays on the bucket
AnswersA, C

A lifecycle rule with the 'Incomplete multipart upload' action (e.g., days after initiation = 7) automatically aborts and deletes all parts of any multipart upload that was not completed due to network failure, timeout, or user cancellation. Because S3 bills for every stored part of an incomplete upload just like a full object, leaving these orphaned parts accrues storage costs indefinitely. Setting a 7-day expiration ensures orphaned data is removed without requiring manual intervention, directly reducing storage waste from failed uploads. This is a native S3 cost-control mechanism, not a data-protection feature.

Why this answer

Configuring a lifecycle policy to delete incomplete multipart uploads after 7 days prevents orphaned parts from incurring storage costs. Option C is correct because creating a lifecycle policy to transition objects to S3 Standard-IA after 90 days reduces storage costs for infrequently accessed data. Option B is incorrect because S3 Object Lock is used for compliance and retention, not cost optimization.

Option D is incorrect because enabling S3 Versioning can increase storage costs by retaining multiple versions of objects. Option E is incorrect because enabling Requester Pays shifts the cost of requests and data transfer to the requester, but does not optimize storage costs for the company.

1001
MCQeasy

A company wants to host a static website on AWS with high availability and low latency for global users. Which combination of services should be used?

A.Amazon EC2 and Elastic Load Balancing
B.Amazon S3 and Amazon CloudFront
C.Amazon Route 53 and Amazon S3
D.Elastic Load Balancing and Amazon CloudFront
AnswerB

Amazon S3 and Amazon CloudFront is the AWS best-practice architecture for hosting a static website at global scale. S3 stores the HTML, CSS, JavaScript, and images durably and cost-effectively, while CloudFront caches those objects at edge locations around the world, dramatically reducing latency for all users. Using CloudFront with an Origin Access Control (OAC) keeps the S3 bucket private, adds HTTPS enforcement, and provides high availability because content is served from multiple edge locations even if the origin has transient issues.

Why this answer

Amazon S3 provides durable, highly available object storage ideal for hosting static website content, and Amazon CloudFront is a global CDN that caches content at edge locations worldwide, delivering low-latency access for global users. Together they form the canonical AWS static website architecture with no servers to manage.

Exam trap

SOA-C02 often tests whether candidates confuse 'high availability' (S3's multi-AZ durability) with 'low latency for global users' (which specifically requires CloudFront edge caching, not just S3 or Route 53).

How to eliminate wrong answers

Option A is wrong because EC2 requires managing servers and ELB only distributes traffic regionally, not providing global edge caching or static hosting. Option C is wrong because Route 53 alone provides DNS routing but no caching or content delivery acceleration — S3 alone cannot deliver low latency globally. Option D is wrong because ELB requires backend compute (like EC2) and does not host static content or provide global edge caching like CloudFront.

1002
MCQhard

A company runs a web application on Amazon EC2 instances. The application's traffic pattern is unpredictable, often spiking to 3x normal load for short periods. The SysOps administrator needs to ensure that the application can handle spikes without performance degradation while minimizing costs. Which combination of purchasing options and scaling strategies should the administrator use?

A.Use all Spot Instances with a simple scaling policy.
B.Use all On-Demand Instances with a scheduled scaling policy.
C.Use a mix of Reserved Instances for baseline and On-Demand for spikes, with a target tracking scaling policy.
D.Use only Reserved Instances with a manual scaling policy.
AnswerC

This option is correct because Reserved Instances should cover the steady-state, baseline portion of the fleet at a significantly lower hourly rate, while On-Demand instances handle any demand above that baseline without requiring a long-term commitment. A target tracking scaling policy lets the Auto Scaling group proactively maintain a chosen metric, like average CPU utilization, by incrementally adjusting capacity as the actual load fluctuates. This hybrid approach keeps costs down and critically provides immediate elasticity for unpredictable spikes.

Why this answer

It combines Reserved Instances for the predictable baseline load, which reduces costs through a significant discount, with On-Demand Instances to handle unpredictable spikes. The target tracking scaling policy automatically adjusts capacity based on a target metric (e.g., average CPU utilization), ensuring performance is maintained during spikes without manual intervention or over-provisioning.

Exam trap

The trap here is that candidates might choose all Spot Instances (Option A) thinking they are cheapest, but they overlook the risk of interruption during spikes, which violates the requirement to 'handle spikes without performance degradation.'

How to eliminate wrong answers

Option A is wrong because using all Spot Instances risks interruption when AWS reclaims capacity, which can cause performance degradation or application failure during spikes, and a simple scaling policy does not dynamically adjust to unpredictable load. Option B is wrong because using all On-Demand Instances is cost-inefficient for the baseline load, and a scheduled scaling policy cannot handle unpredictable spikes since it relies on fixed time schedules. Option D is wrong because using only Reserved Instances with a manual scaling policy cannot scale to meet unpredictable spikes without over-provisioning (wasting cost) or under-provisioning (causing degradation), and manual scaling is slow and error-prone.

1003
MCQmedium

An organization requires that all Amazon S3 buckets block public access entirely. A SysOps administrator needs to ensure that no bucket can be made public, even accidentally. Which approach enforces this control at the organizational level?

A.Apply an S3 Bucket Policy on each bucket that denies public access.
B.Use an AWS Config managed rule 's3-bucket-public-read-prohibited' to detect and remediate public buckets.
C.Enable S3 Block Public Access at the account level and attach an SCP to deny changes to it.
D.Create an IAM policy that denies s3:PutBucketPolicy for all users.
AnswerC

This is the only correct answer because it provides a centralized, preventive, and tamper-proof control. Enabling S3 Block Public Access at the account level immediately denies all public read/write access to every current and future bucket in that account. Attaching an SCP that denies s3:PutAccountPublicAccessBlock and s3:PutBucketPublicAccessBlock prevents users—even those with full S3 permissions—from modifying those settings, because SCPs cannot be overridden by IAM policies within the member account.

Why this answer

S3 Block Public Access at the account level provides a centralized, immutable control that prevents any bucket in the account from being made public, regardless of bucket policies or ACLs. Attaching an SCP (Service Control Policy) to deny changes to these settings ensures that even administrators with full IAM permissions cannot disable the block, enforcing the control at the organizational level across all accounts in the organization.

Exam trap

The trap here is that candidates often confuse detective controls (like AWS Config rules) with preventive controls (like SCPs and account-level Block Public Access), assuming that detecting and auto-remediating public buckets is equivalent to preventing them from ever becoming public.

How to eliminate wrong answers

Option A is wrong because applying an S3 Bucket Policy on each bucket is not an organizational-level control; it is per-bucket and can be overridden or omitted by users with sufficient permissions, failing to enforce the requirement across all buckets. Option B is wrong because AWS Config managed rules are detective and reactive, not preventive; they can detect and auto-remediate public buckets, but there is a window of exposure before remediation occurs, and the rule can be disabled or modified by authorized users, so it does not enforce a hard block at the organizational level. Option D is wrong because an IAM policy that denies s3:PutBucketPolicy for all users does not prevent public access via bucket ACLs (e.g., granting public read/write via ACLs), and it can be bypassed by users with full administrative privileges who can modify or detach the IAM policy.

1004
MCQeasy

A SysOps administrator wants to identify Amazon EC2 instances that are underutilized to reduce costs. The administrator needs recommendations for rightsizing instances based on historical CPU and memory usage. Which AWS service provides these recommendations?

A.AWS Cost Explorer
B.AWS Trusted Advisor
C.AWS Compute Optimizer
D.AWS CloudTrail
AnswerC

AWS Compute Optimizer is the correct choice because it is purpose-built for this exact need: it continuously analyzes EC2 instance utilization data—CPU, memory, networking, and EBS I/O—collected from CloudWatch (with optional managed or custom metrics). Using machine learning models, it generates actionable rightsizing recommendations that identify both cost savings and performance risks, often suggesting specific instance families or sizes (e.g., moving from m5.large to m6i.large). It also provides estimated monthly savings and reasons for each recommendation, which a sysops administrator can directly use to identify and optimize EC2 instances.

Why this answer

AWS Compute Optimizer is the correct service because it analyzes historical utilization metrics (CPU, memory, I/O, and network throughput) from Amazon CloudWatch and generates rightsizing recommendations for EC2 instances. It uses machine learning to identify underutilized instances and suggests instance types that better match workload requirements, directly addressing the need to reduce costs through rightsizing.

Exam trap

The trap here is that candidates often confuse AWS Trusted Advisor's cost checks (like idle instances) with Compute Optimizer's rightsizing recommendations, but Trusted Advisor does not analyze historical CPU and memory usage for instance type changes.

How to eliminate wrong answers

Option A is wrong because AWS Cost Explorer provides cost and usage data visualization and forecasting, but it does not analyze historical CPU or memory utilization to generate instance-specific rightsizing recommendations. Option B is wrong because AWS Trusted Advisor offers cost optimization checks (e.g., idle instances, underutilized EBS volumes) but does not provide detailed rightsizing recommendations based on historical CPU and memory usage patterns. Option D is wrong because AWS CloudTrail records API activity for auditing and governance, not resource utilization metrics or rightsizing advice.

1005
MCQmedium

A company's security policy requires that all Amazon RDS for PostgreSQL instances be encrypted at rest using AWS Key Management Service (KMS) customer managed keys and have automated backups enabled with a retention period of at least 30 days. A SysOps administrator needs to use AWS Config to automatically detect any RDS instance that is non-compliant with either requirement and automatically remediate it. Which combination of AWS Config managed rules and remediation actions should be used?

A.Use two AWS Config managed rules: 'rds-instance-encrypted' and 'rds-backup-enabled'. Configure each rule with an automatic remediation action that triggers an Amazon CloudWatch alarm, which then invokes an AWS Lambda function to enable encryption and backups.
B.Create custom AWS Config rules as AWS Lambda functions that evaluate the RDS instance configuration. In the Lambda function, if a resource is non-compliant, call the RDS API to enable encryption and modify backup settings.
C.Use the AWS Config managed rules 'rds-instance-encrypted' and 'rds-backup-enabled'. Configure automatic remediation for each rule using the corresponding AWS Systems Manager Automation runbook: 'AWSConfigRemediation-EnableRDSInstanceEncryption' and 'AWSConfigRemediation-EnableRDSInstanceBackup'.
D.Use a single custom AWS Config rule that checks both encryption and backup settings. If non-compliant, trigger an AWS Lambda function that uses the RDS API to configure both settings.
AnswerC

This is the correct approach. Managed rules evaluate compliance, and automatic remediation using Systems Manager Automation runbooks applies the fix without custom code. The runbooks perform the necessary API calls to enable encryption and backups, meeting the policy requirements.

Why this answer

AWS Config managed rules 'rds-instance-encrypted' and 'rds-backup-enabled' natively evaluate encryption and backup compliance. The corresponding AWS Systems Manager Automation runbooks ('AWSConfigRemediation-EnableRDSInstanceEncryption' and 'AWSConfigRemediation-EnableRDSInstanceBackup') provide built-in, automatic remediation without custom code, aligning with the requirement to use managed rules and automatic remediation.

Exam trap

The trap here is that candidates may assume custom Lambda functions are required for complex remediation, but AWS provides pre-built Systems Manager Automation runbooks that integrate directly with AWS Config managed rules for common RDS compliance issues, making custom code unnecessary.

How to eliminate wrong answers

Option A is wrong because triggering a CloudWatch alarm to invoke a Lambda function is an indirect, custom remediation path; AWS Config supports direct automatic remediation via Systems Manager Automation runbooks, making this approach unnecessarily complex and not leveraging native capabilities. Option B is wrong because creating custom AWS Config rules as Lambda functions violates the requirement to use AWS Config managed rules; the question explicitly asks for managed rules, not custom ones. Option D is wrong because using a single custom rule that checks both encryption and backups is not a managed rule, and it requires custom Lambda code for remediation, which contradicts the directive to use managed rules and automatic remediation actions.

1006
MCQmedium

A company requires that all API calls to AWS services be logged for compliance. The logs must be stored in a centralized S3 bucket with server-side encryption enabled. Which AWS service should be used to capture the API calls?

A.AWS Config
B.AWS CloudTrail
C.VPC Flow Logs
D.Amazon CloudWatch Logs
AnswerB

AWS CloudTrail is the native AWS service designed to log all API activity in an account, including actions taken through the AWS Management Console, SDKs, CLI, and other services. Each event records the identity of the caller, the time of the call, the source IP address, and the request parameters. By enabling a trail, these logs can be delivered to Amazon S3 for long-term storage and integrated with CloudWatch Logs or third-party tools for monitoring and alerting.

Why this answer

AWS CloudTrail records API activity across AWS services, capturing who made what call, from where, and when, and can deliver logs to a centralized S3 bucket with SSE enabled. It is the designated service for auditing API calls for compliance.

Exam trap

SOA-C02 often tests the confusion between CloudTrail (API activity auditing) and AWS Config (resource configuration/compliance) or VPC Flow Logs (network traffic), especially when the question emphasizes 'API calls' and 'compliance.'

How to eliminate wrong answers

Option A is wrong because AWS Config records resource configuration changes and evaluates compliance against rules — it does not log API calls themselves. Option C is wrong because VPC Flow Logs capture IP traffic metadata (source/dest IP, ports, bytes) for network interfaces, not AWS API calls. Option D is wrong because CloudWatch Logs is a log aggregation and monitoring service; while CloudTrail can deliver to CloudWatch Logs, CloudWatch Logs itself does not capture API calls.

1007
MCQeasy

A company wants to monitor the performance of its EC2 instances and receive alerts when CPU utilization exceeds 80% for 10 minutes. Which AWS service should be used?

A.Amazon CloudWatch
B.AWS CloudTrail
C.AWS Config
D.VPC Flow Logs
AnswerA

Amazon CloudWatch is the correct choice because it provides a comprehensive monitoring service for EC2 instances. CloudWatch collects and tracks metrics such as CPU utilization, network I/O, and disk activity, which can be visualized in dashboards and evaluated against thresholds. When these metrics breach predefined limits, CloudWatch can trigger Amazon Simple Notification Service (SNS) alarms to notify operators or initiate automated actions, making it the appropriate tool for performance monitoring and alerting.

Why this answer

Amazon CloudWatch can monitor CPU utilization metrics for EC2 instances and trigger alarms when a threshold (e.g., 80% for 10 minutes) is exceeded. Option B (AWS CloudTrail) is wrong because it records API activity, not performance metrics. Option C (AWS Config) is wrong because it evaluates resource configurations, not performance.

Option D (VPC Flow Logs) is wrong because it captures network traffic information, not CPU usage.

1008
MCQmedium

A company is running a critical web application on EC2 instances behind an Application Load Balancer. The instances are in an Auto Scaling group across two Availability Zones. The company needs to ensure that if an entire Availability Zone fails, the application remains available. Which configuration meets this requirement?

A.Use larger EC2 instance types to handle the load during a failure.
B.Use Amazon CloudFront to distribute traffic across multiple regions.
C.Launch all instances in the same Availability Zone to reduce latency.
D.Configure the Auto Scaling group to launch instances in at least two Availability Zones.
AnswerD

Configuring the Auto Scaling group to launch instances in at least two Availability Zones is the correct approach. The Auto Scaling group automatically distributes instances across the selected AZs, and if one AZ fails, the remaining instances continue to operate and serve traffic. Additionally, Auto Scaling can replace unhealthy instances in other AZs, and when combined with an Application Load Balancer, it ensures cross‑AZ load balancing and resilient failover.

Why this answer

Configuring the Auto Scaling group to launch instances in at least two Availability Zones ensures that if one AZ fails, the remaining AZ(s) continue to serve traffic. The Application Load Balancer automatically distributes incoming requests across healthy instances in all configured AZs, and the Auto Scaling group replaces failed instances in the remaining AZs, maintaining capacity. This design provides high availability without relying on a single AZ, which would be a single point of failure.

Exam trap

The trap here is that candidates often confuse scaling (increasing instance size or count) with high availability (distributing across AZs), leading them to choose Option A or C, or they mistakenly think CloudFront provides regional failover for dynamic web applications, which it does not by default.

How to eliminate wrong answers

Option A is wrong because using larger EC2 instance types only increases compute capacity within a single AZ; it does not protect against an entire AZ failure, as all instances would still be in the same AZ and become unavailable simultaneously. Option B is wrong because Amazon CloudFront is a content delivery network (CDN) that caches content at edge locations; it does not distribute traffic across multiple regions for active-active failover of a web application behind an ALB, and it does not replace the need for multi-AZ deployment. Option C is wrong because launching all instances in the same Availability Zone creates a single point of failure; if that AZ fails, all instances become unreachable, causing complete application downtime.

1009
MCQmedium

A company wants to enforce that all Amazon EC2 instances launched in the AWS account must have a specific termination protection setting enabled. The SysOps administrator needs to automatically remediate any instances that are launched without termination protection. Which AWS service should be used to achieve this?

A.AWS Config with a managed rule ec2-instance-no-public-ip and an SSM Automation remediation.
B.AWS Config with a custom rule using AWS Lambda to evaluate and enable termination protection.
C.Amazon Inspector to scan instances and trigger a remediation action.
D.AWS Systems Manager Patch Manager to apply a policy for termination protection.
AnswerB

A custom AWS Config rule can use a Lambda function to check if an EC2 instance has termination protection enabled. If not, the function can call the EC2 API to enable it. This provides automatic remediation for non-compliant resources.

Why this answer

AWS Config can evaluate resources against desired configurations using managed or custom rules. A custom AWS Config rule can invoke a Lambda function to check if termination protection is enabled on EC2 instances and automatically enable it if missing, providing the required remediation. This approach directly addresses the requirement to enforce termination protection on all launched instances.

Exam trap

The trap here is that candidates may confuse AWS Config's managed rules (which cover common compliance checks) with the need for a custom rule and Lambda function to enforce a specific setting like termination protection, or mistakenly think services like Inspector or Patch Manager can handle configuration enforcement.

How to eliminate wrong answers

Option A is wrong because the ec2-instance-no-public-ip rule checks for public IPs, not termination protection, and SSM Automation remediation is not designed to enable termination protection on EC2 instances. Option C is wrong because Amazon Inspector is a vulnerability assessment service that scans for software vulnerabilities and network exposures, not for enforcing instance configuration settings like termination protection. Option D is wrong because AWS Systems Manager Patch Manager is used to automate patching of operating systems and applications, not to apply termination protection policies to EC2 instances.

1010
Multi-Selectmedium

Which TWO actions should a SysOps admin take to troubleshoot an Amazon RDS instance that is experiencing high CPU utilization? (Choose 2.)

Select 2 answers
A.Enable Enhanced Monitoring to view OS-level metrics
B.Enable Multi-AZ to distribute the load
C.Delete the slow query log to free up CPU
D.Enable Performance Insights to identify high-load queries
E.Increase the instance size to reduce CPU utilization
AnswersA, D

Enhanced Monitoring on Amazon RDS delivers a stream of OS-level telemetry, including per-process CPU utilization, memory usage, disk I/O, and network traffic, via the CloudWatch console. This granular view lets you distinguish whether the high CPU is being consumed by the database engine itself or by auxiliary processes such as backups, log writers, or the OS, narrowing the root-cause search. It is a purely diagnostic action—it does not alter the workload but provides the raw data needed to formulate a targeted fix.

Why this answer

Enhanced Monitoring provides OS-level metrics (e.g., CPU, memory, disk I/O) for the RDS instance, which helps identify resource contention at the operating system level. This granularity is essential for diagnosing high CPU utilization that may be caused by OS processes (e.g., backup, patching) rather than database queries alone.

Exam trap

The trap here is that candidates often confuse Multi-AZ with read replicas, assuming it distributes load, or they think deleting logs frees CPU, when in fact logs are written asynchronously and have negligible CPU impact.

1011
MCQmedium

A company uses multiple AWS accounts and needs to generate a detailed cost and usage report that can be queried using Amazon Athena for custom analysis. Which AWS service should the administrator enable?

A.AWS Cost Explorer
B.AWS Budgets
C.AWS Cost and Usage Reports
D.AWS Application Cost Profiler
AnswerC

The AWS Cost and Usage Reports (CUR) can be configured to deliver granular, hourly or daily line items to an S3 bucket in either CSV or Parquet format. CUR integrates natively with Athena, allowing you to create a table and run SQL queries over the data, making it the correct choice for multi-account cost analysis. The Parquet format is columnar and optimized for query performance, and CUR includes account-level dimensions for filtering across all linked accounts.

Why this answer

AWS Cost and Usage Reports (CUR) is the correct service because it generates detailed cost and usage data in CSV or Parquet format, which can be directly queried using Amazon Athena via integration with AWS Glue and Amazon QuickSight. This enables custom analysis and ad-hoc queries on the full billing dataset, unlike other services that provide pre-aggregated views or alerts.

Exam trap

The trap here is that candidates confuse AWS Cost Explorer's interactive dashboard with the raw, queryable data format of CUR, assuming Cost Explorer can export data in a format suitable for Athena, when in fact it only provides CSV exports of aggregated views, not the full normalized dataset.

How to eliminate wrong answers

Option A is wrong because AWS Cost Explorer provides a pre-built visualization and filtering interface for cost data, but it does not generate a downloadable report that can be queried with Athena for custom analysis. Option B is wrong because AWS Budgets is used to set cost or usage thresholds and send alerts, not to produce detailed cost and usage reports for Athena querying. Option D is wrong because AWS Application Cost Profiler is designed to track and allocate costs at the application or software feature level, not to generate comprehensive account-level cost and usage reports for Athena.

1012
Multi-Selecthard

A company uses AWS CloudTrail to log API activity. The security team needs to be notified immediately when an IAM user creates a new access key. Which combination of steps should a SysOps administrator take? (Choose TWO.)

Select 2 answers
A.Create a CloudWatch Logs metric filter for the 'CreateAccessKey' event.
B.Enable AWS Config rules to detect changes to IAM users.
C.Configure CloudTrail to send notifications directly to Amazon SNS.
D.Create a CloudWatch alarm based on the metric filter and publish to an SNS topic.
E.Create an Amazon EventBridge rule to match the 'CreateAccessKey' API call.
AnswersA, D

A CloudTrail trail that is integrated with CloudWatch Logs streams each API event as a JSON log record. A metric filter using a pattern such as `{ $.eventName = "CreateAccessKey" }` scans every incoming log event and increments a CloudWatch metric whenever a new access key is created. This is the core detection step because it transforms raw CloudTrail API activity into a trackable, numerical signal that downstream alarms can act on.

Why this answer

CloudWatch Logs metric filters allow you to extract specific patterns from CloudTrail log data, such as the 'CreateAccessKey' event, and convert them into a metric. This enables you to monitor for this specific API call and trigger an alarm when it occurs, meeting the requirement for immediate notification.

Exam trap

The trap here is that candidates often think CloudTrail can directly send notifications to SNS (Option C) or that AWS Config rules are suitable for real-time event-driven alerts (Option B), but neither is correct for immediate notification of a specific API call.

1013
MCQeasy

A company requires that all Amazon EC2 instances launched in its AWS account must have termination protection enabled. The SysOps administrator needs to automatically remediate any instance launched without termination protection. The solution should use AWS managed services without custom scripts. Which AWS service should be used?

A.Configure AWS Config with a managed rule 'ec2-termination-protection-check' and set an auto-remediation action using an AWS Systems Manager Automation document that enables termination protection on the instance.
B.Use Amazon EC2 Auto Scaling to automatically apply termination protection to all launched instances.
C.Enable AWS Trusted Advisor to send notifications when instances lack termination protection, and have administrators manually fix them.
D.Create an IAM policy that denies the RunInstances action unless termination protection is enabled.
AnswerA

AWS Config's managed rule ec2-termination-protection-check continuously evaluates each EC2 instance against the required configuration, flagging any instance without termination protection as non-compliant. When non-compliance is detected, the associated auto-remediation action invokes an AWS Systems Manager Automation document, such as AWS-EnableEC2TerminationProtection, which calls the ModifyInstanceAttribute API to enable DisableApiTermination on the instance. This serverless, event-driven workflow automatically corrects drift without custom scripts or manual intervention, fully satisfying the company's requirement for automatic remediation.

Why this answer

AWS Config's managed rule 'ec2-termination-protection-check' can detect instances without termination protection, and you can attach an auto-remediation action using an AWS Systems Manager Automation document (e.g., AWS-EnableTerminationProtection) to automatically enable termination protection on noncompliant instances. This solution uses only AWS managed services and requires no custom scripts, meeting the company's requirements.

Exam trap

The trap here is that candidates may confuse AWS Config's detection-only capability with its auto-remediation feature, or assume that IAM policies can enforce instance-level attributes at launch time, when in fact IAM conditions like 'ec2:DisableApiTermination' are not supported for the RunInstances action.

How to eliminate wrong answers

Option B is wrong because Amazon EC2 Auto Scaling does not have a native feature to automatically apply termination protection to all launched instances; it manages scaling policies and health checks, not instance attribute remediation. Option C is wrong because AWS Trusted Advisor only provides notifications and recommendations, not automated remediation; it requires manual intervention by administrators, which violates the requirement for automatic remediation. Option D is wrong because an IAM policy that denies RunInstances unless termination protection is enabled would prevent launching instances without termination protection, but it does not remediate instances already launched without it; additionally, IAM policies cannot enforce instance-level attributes like termination protection at launch time in a granular way, and the requirement is to remediate after launch, not prevent.

1014
MCQeasy

A company wants to provide low-latency access to a web application for users in North America and Europe. The application runs on EC2 instances in us-east-1 and eu-west-1. Which AWS service should be used to route users to the nearest region?

A.Application Load Balancer with cross-region load balancing
B.Amazon CloudFront
C.AWS Global Accelerator
D.Amazon Route 53 with latency-based routing
AnswerD

Amazon Route 53 latency-based routing sends each user's DNS query to the endpoint in the AWS Region that currently has the lowest latency from the user's DNS resolver. Route 53 maintains latency data for traffic between regions and the resolver, and returns the appropriate IP address for that region, enabling low-latency access when the application is deployed in multiple Regions.

Why this answer

Amazon Route 53 with latency-based routing directs user traffic to the AWS region that provides the lowest latency for the end user. By configuring latency records for the EC2 instances in us-east-1 and eu-west-1, Route 53 responds to DNS queries with the IP address of the region that offers the best network performance, effectively routing users to the nearest region.

Exam trap

The trap here is that candidates often confuse Global Accelerator's Anycast-based routing with DNS-based latency routing, but Global Accelerator optimizes the network path from the edge to the origin, not the user's initial routing to the nearest region, which is a DNS-level decision.

How to eliminate wrong answers

Option A is wrong because an Application Load Balancer with cross-region load balancing distributes traffic across targets in multiple regions but does not route users based on their geographic proximity; it balances load regardless of user location. Option B is wrong because Amazon CloudFront is a content delivery network (CDN) that caches content at edge locations for low-latency delivery, but it does not route users to the nearest origin region; it serves cached content from the edge, not direct traffic to the closest EC2 instance. Option C is wrong because AWS Global Accelerator uses Anycast IP addresses and the AWS global network to direct traffic to the optimal endpoint based on health and latency, but it is designed for TCP/UDP traffic and requires static IP addresses, whereas the question specifically asks for routing users to the nearest region, which is a DNS-level function best handled by Route 53 latency-based routing.

1015
MCQeasy

A company is using an Application Load Balancer (ALB) to distribute traffic to a fleet of EC2 instances. The company needs to ensure that the ALB sends requests to instances that are healthy and can serve traffic. Which feature should be used to monitor the health of the instances?

A.Health checks
B.Sticky sessions
C.Cross-zone load balancing
D.Connection draining
AnswerA

Health checks in an Application Load Balancer (ALB) are the mechanism that actively monitors the availability of targets by sending HTTP or HTTPS requests to a specified path, such as /health, and evaluating the response against configured success codes, e.g., 200. If a target fails a consecutive number of checks, the ALB marks it unhealthy and stops routing new traffic to it, while healthy targets continue to receive requests. This is the core feature that enables the ALB to perform automatic failover and maintain high availability.

Why this answer

Health checks allow the ALB to monitor the health of EC2 instances by sending periodic requests to a specified endpoint (e.g., /health). If an instance fails consecutive health checks, the ALB stops sending traffic to it. Option B is incorrect because sticky sessions (session affinity) ensure a client's requests are sent to the same instance, not health monitoring.

Option C is incorrect because cross-zone load balancing distributes traffic across instances in multiple Availability Zones. Option D is incorrect because connection draining (deregistration delay) allows in-flight requests to complete before an instance is removed from the target group.

1016
MCQmedium

A company hosts a critical web application on Amazon EC2 instances in a single AWS Region (us-east-1). The SysOps administrator needs to implement a Disaster Recovery (DR) solution using a different AWS Region (us-west-2). The DR plan requires a Recovery Time Objective (RTO) of 1 hour and a Recovery Point Objective (RPO) of 15 minutes. The application uses an Amazon Aurora MySQL DB cluster and static assets stored in an Amazon S3 bucket. Which combination of actions should the administrator take to meet these requirements?

A.Create an Aurora cross-Region read replica in us-west-2. Configure S3 Cross-Region Replication from the source bucket to a destination bucket in us-west-2. During DR, promote the read replica to a primary cluster and update DNS.
B.Take a manual snapshot of the Aurora DB cluster every 15 minutes and copy it to us-west-2. Use S3 batch operations to copy assets to us-west-2 daily.
C.Enable Aurora Multi-AZ in us-east-1 and configure S3 transfer acceleration to us-west-2.
D.Use AWS Database Migration Service (DMS) for continuous replication to a DB instance in us-west-2. Use S3 versioning to keep previous object versions.
AnswerA

A cross-Region read replica provides continuous replication for the database, achieving RPO seconds. Promoting it can be done in minutes, meeting RTO of 1 hour. S3 CRR replicates objects asynchronously, typically within minutes, satisfying the RPO.

Why this answer

Aurora cross-Region read replicas provide asynchronous replication with an RPO typically under 1 second, easily meeting the 15-minute RPO requirement. Promoting the read replica to a primary cluster in us-west-2 can be completed within minutes, satisfying the 1-hour RTO. S3 Cross-Region Replication (CRR) automatically replicates static assets to the destination bucket in us-west-2 with near-real-time latency, ensuring the S3 data is also current within the RPO window.

Exam trap

The trap here is that candidates often confuse Multi-AZ (which provides high availability within a single region) with cross-region disaster recovery, or they assume manual snapshots and DMS are simpler alternatives without considering the RPO/RTO constraints and operational overhead.

How to eliminate wrong answers

Option B is wrong because taking manual snapshots every 15 minutes is operationally impractical and cannot guarantee an RPO of 15 minutes due to snapshot creation and copy latency; also, copying assets daily via S3 batch operations far exceeds the 15-minute RPO. Option C is wrong because Aurora Multi-AZ in us-east-1 only provides high availability within a single region, not cross-region disaster recovery, and S3 Transfer Acceleration only improves upload speed to a single bucket, not replication to another region. Option D is wrong because AWS DMS for continuous replication to a DB instance in us-west-2 introduces additional complexity and potential lag that may not meet the 15-minute RPO as reliably as Aurora native replication; S3 versioning alone does not replicate objects to another region, so it fails to provide cross-region DR for static assets.

1017
Multi-Selecteasy

Which TWO AWS services can be used to monitor the performance of an EC2 instance?

Select 2 answers
A.AWS Systems Manager
B.AWS CloudTrail
C.AWS Trusted Advisor
D.AWS Config
E.Amazon CloudWatch
AnswersA, E

AWS Systems Manager is a hybrid operations service that uses the SSM Agent on managed instances to collect operational data, including inventory details and performance-related information, and can execute diagnostic commands such as CPU or memory checks via Run Command. It provides a central console for aggregating and viewing operational data across instance fleets, making it valid for monitoring performance, though its primary purpose is broader managed-instance operations rather than real-time metric storage.

Why this answer

Amazon CloudWatch is the primary service for monitoring EC2 performance metrics like CPU utilization, network, and disk I/O. AWS Systems Manager can also collect performance data through Inventory and Run Command, providing operational insights. AWS CloudTrail logs API activity for auditing, not performance.

AWS Trusted Advisor offers cost and security recommendations. AWS Config tracks configuration changes, not performance metrics.

1018
MCQeasy

An organization is using AWS CloudFormation to manage its infrastructure. The SysOps administrator wants to update a stack that includes an Amazon RDS DB instance. The update requires changing the DB instance class. However, the administrator wants to minimize downtime. What should the administrator do?

A.Use CloudFormation's 'DeletionPolicy' attribute to retain the database during updates.
B.Enable Multi-AZ on the DB instance (if not already enabled) before performing the stack update.
C.Update the stack directly with 'ApplyImmediately' set to true.
D.Create a read replica, promote it, and then delete the original DB instance.
AnswerB

Enabling Multi-AZ gives the DB instance a standby replica in a different Availability Zone, which RDS can fail over to during maintenance. When a stack update changes the DB instance class, RDS applies the modification to the standby first, performs a failover, and then updates the former primary—this keeps the database available during the transition. Because the failover only causes a brief connection interruption rather than a full shutdown, Multi-AZ is the correct way to minimize downtime during an instance class update.

Why this answer

Enabling Multi-AZ allows the RDS instance to have a standby in a different Availability Zone. When updating the DB instance class, CloudFormation can modify the standby first, then fail over to it, minimizing downtime. Options A, C, and D are incorrect: A (DeletionPolicy) controls resource retention on stack deletion, not updates; C (ApplyImmediately) may cause a brief outage; D (read replica promotion) is for scaling reads, not for minimizing downtime during instance class changes.

1019
MCQmedium

An application running on an EC2 instance writes logs to a local file. The operations team needs to monitor these logs in near real-time for troubleshooting. Which solution provides the most efficient way to stream these logs to CloudWatch Logs?

A.Use the AWS CLI to periodically upload the log file using the put-log-events command.
B.Install the CloudWatch Logs agent on the instance and configure it to tail the log file.
C.Install the Amazon Kinesis Agent on the instance and configure it to send logs to CloudWatch Logs.
D.Configure the application to write logs to an S3 bucket and use S3 Event Notifications to trigger a Lambda function that puts logs to CloudWatch.
AnswerB

The CloudWatch Logs agent (or the newer unified CloudWatch agent) runs as a daemon on the EC2 instance and uses the `tail` mechanism to monitor the specified log file, each time a new log line is written it is picked up and pushed to CloudWatch Logs in near real time. The agent manages checkpointing, so if the process restarts it can resume from the last-read position without re-sending old lines or losing new ones, and it also handles batching and `put-log-events` calls to the CloudWatch Logs API automatically. This is the purpose-built solution for streaming application logs to CloudWatch and is the correct choice for a near real-time requirement.

Why this answer

The CloudWatch Logs agent (or the newer unified CloudWatch agent) is designed specifically to tail log files from EC2 instances and stream them to CloudWatch Logs in near real-time. This provides the most efficient solution because it continuously monitors the file for new entries and sends them with minimal latency, without requiring periodic uploads or complex event-driven pipelines.

Exam trap

The trap here is that candidates may confuse the Kinesis Agent with the CloudWatch Logs agent, assuming both can send directly to CloudWatch Logs, but the Kinesis Agent only supports Kinesis destinations natively.

How to eliminate wrong answers

Option A is wrong because using the AWS CLI to periodically upload logs via put-log-events introduces significant latency (since it must run on a schedule) and is inefficient for near real-time monitoring; it also requires manual scripting to track the last uploaded position. Option C is wrong because the Amazon Kinesis Agent is designed to send data to Amazon Kinesis Data Streams or Firehose, not directly to CloudWatch Logs; sending logs to CloudWatch would require an additional intermediary (e.g., a Lambda function), adding complexity and cost. Option D is wrong because writing logs to S3 and using S3 Event Notifications with Lambda adds unnecessary latency (S3 is object storage, not a streaming target) and complexity; this approach is better suited for batch or archival processing, not near real-time monitoring.

1020
MCQhard

A SysOps administrator needs to monitor a custom application metric 'OrdersPerMinute' published to Amazon CloudWatch. The metric should trigger an alarm when the count exceeds 100 for more than 2 consecutive data points, but only during business hours (9 AM to 5 PM weekdays). The alarm must evaluate the metric as a rate per minute. How should the administrator configure the alarm?

A.Create a CloudWatch alarm with a period of 1 minute, evaluation periods of 2, datapoints to alarm of 2, and use a math expression to filter time range.
B.Create a CloudWatch alarm with a period of 1 minute, evaluation periods of 2, datapoints to alarm of 2, and disable the alarm outside business hours using a Lambda function triggered by CloudWatch Events.
C.Create a CloudWatch alarm with a period of 1 minute, evaluation periods of 2, datapoints to alarm of 2, and use a metric math expression 'IF(IN_BUSINESS_HOURS(), OrdersPerMinute, 0)' but CloudWatch does not have IN_BUSINESS_HOURS function.
D.Create a CloudWatch alarm with a period of 1 minute, evaluation periods of 1, datapoints to alarm of 2 (impossible).
AnswerB

This solution uses a scheduled Lambda function (via CloudWatch Events) to enable/disable the alarm. The alarm itself is configured with the correct evaluation criteria (2 out of 2 datapoints above 100). This meets the requirement while using automated remediation.

Why this answer

To trigger when 'OrdersPerMinute' exceeds 100 for more than 2 consecutive data points, the alarm must require 3 consecutive breaching data points. This is achieved by setting evaluation periods to 3 and datapoints to alarm to 3. The Lambda/EventBridge approach to disable the alarm outside business hours is correct, but option B's evaluation period settings are incorrect.

As written, no option fully satisfies the requirement.

Exam trap

The trap here is that candidates assume CloudWatch has a built-in time-based filtering function (like IN_BUSINESS_HOURS) or that math expressions can evaluate time, when in reality AWS requires external scheduling via Lambda or EventBridge to manage alarm activation windows.

How to eliminate wrong answers

Option A is wrong because CloudWatch math expressions do not include a function like 'IN_BUSINESS_HOURS()' to filter by time range; math expressions operate on metric values, not time-based conditions. Option C is wrong because it incorrectly claims CloudWatch has an 'IN_BUSINESS_HOURS' function, which does not exist; this would cause the alarm to fail or evaluate incorrectly. Option D is wrong because it sets evaluation periods to 1 and datapoints to alarm to 2, which is impossible—the number of datapoints to alarm cannot exceed the number of evaluation periods.

1021
MCQmedium

A company uses Amazon CloudFront with an Application Load Balancer (ALB) as the origin. The SysOps administrator needs to restrict access to the ALB so that it only accepts requests from CloudFront. Which solution should the administrator implement?

A.Replace the ALB with a Network Load Balancer and use a VPC endpoint
B.Create an origin access identity (OAI) and attach it to the CloudFront distribution
C.Add a security group rule to the ALB that allows traffic only from the CloudFront IP ranges
D.Configure CloudFront to add a custom HTTP header to requests, and configure the ALB to only forward requests that contain that header
AnswerD

Configure CloudFront to inject a secret custom HTTP header into every request it forwards to the ALB, and then configure the ALB listener rule to only route traffic that contains that exact header and value. CloudFront strips any client-supplied header with the same name, so the secret cannot be discovered or forged by users making direct requests to the ALB. This ensures only traffic that passed through your CloudFront distribution is accepted, securely restricting access to your origin.

Why this answer

It uses a shared secret mechanism: CloudFront is configured to add a custom HTTP header (e.g., X-Origin-Verify) to all requests, and the ALB's listener rule is configured to only forward requests that contain that specific header value. This ensures that only requests originating from your CloudFront distribution reach the ALB, as the header is not present in direct client requests. This approach is recommended by AWS for restricting ALB access to CloudFront when the origin is an ALB, because CloudFront does not support Origin Access Identity (OAI) with ALB origins.

Exam trap

The trap here is that candidates often confuse Origin Access Identity (OAI) as a universal CloudFront feature, not realizing it only works with S3 origins, and they overlook the impracticality of using CloudFront IP ranges in security groups due to their dynamic nature.

How to eliminate wrong answers

Option A is wrong because replacing the ALB with a Network Load Balancer (NLB) and using a VPC endpoint does not inherently restrict access to CloudFront; a VPC endpoint is used for private connectivity, not for authenticating the source of traffic, and NLB does not support custom header-based filtering natively. Option B is wrong because Origin Access Identity (OAI) is a feature specific to Amazon S3 origins, not Application Load Balancers; OAI cannot be attached to a CloudFront distribution with an ALB origin. Option C is wrong because CloudFront does not have a fixed set of IP ranges; its IP addresses change frequently and are published via a public list, making it impractical and insecure to maintain a security group rule that only allows CloudFront IP ranges, as the list is large and dynamic.

1022
Multi-Selecthard

A company runs a critical web application on EC2 instances behind an ALB. The application experiences unpredictable traffic spikes. The SysOps administrator wants to ensure that the application can handle spikes without performance degradation while minimizing costs. Which TWO actions should the administrator take?

Select 2 answers
A.Use a mix of On-Demand and Spot Instances in the Auto Scaling group.
B.Use Amazon DynamoDB auto scaling to handle the spikes.
C.Use scheduled scaling to add instances during expected peak hours.
D.Use a target tracking scaling policy based on CPU utilization.
E.Use larger EC2 instance types to handle spikes.
AnswersA, D

A mixed instances policy in an Auto Scaling group lets you define an On-Demand base capacity plus Spot percentage for the remaining instances. This maintains baseline availability through On-Demand instances while using lower-cost Spot capacity to absorb unpredictable traffic spikes. Spot interruptions can occur, but the ASG automatically replenishes capacity, and you can configure instance rebalancing and termination handling.

Why this answer

Spot Instances can reduce costs if the application can handle interruptions. Option D is correct because target tracking scaling adjusts capacity based on load. Option B is wrong because DynamoDB auto scaling is not relevant for EC2.

Option C is wrong because scheduled scaling cannot handle unpredictable spikes. Option E is wrong because increasing instance size may not be as cost-effective as scaling out.

1023
MCQmedium

An organization is using AWS CloudFormation to deploy infrastructure. The SysOps administrator needs to receive notifications when stack creation fails. What is the simplest way to achieve this?

A.Create a CloudWatch alarm on the 'StackCreationFailure' metric.
B.Provide an SNS topic ARN in the --notification-arns parameter when creating the stack.
C.Create an EventBridge rule that triggers on CloudFormation events.
D.Enable CloudTrail and create a metric filter for 'CreateStack' failures.
AnswerB

The correct approach is to specify an SNS topic ARN in the --notification-arns parameter when creating the stack (or the equivalent NotificationARNs property in the CloudFormation template). CloudFormation publishes all stack-level events, including CREATE_FAILED, to that SNS topic, and subscribers such as email, SMS, or Lambda functions receive immediate notifications. This native integration is purpose-built for CloudFormation lifecycle monitoring and requires no additional resources or custom logic.

Why this answer

The `--notification-arns` parameter in the AWS CLI `create-stack` command directly associates an SNS topic with the stack, causing CloudFormation to publish notifications for all stack events, including failures. This is the simplest method as it requires no additional services or configuration beyond specifying the SNS topic ARN at stack creation.

Exam trap

The trap here is that candidates often over-engineer the solution by choosing EventBridge or CloudTrail, missing the fact that CloudFormation has a built-in, one-step SNS notification feature that is the simplest and most direct way to receive stack failure alerts.

How to eliminate wrong answers

Option A is wrong because CloudFormation does not emit a 'StackCreationFailure' metric to CloudWatch; CloudWatch metrics for CloudFormation are limited to 'Drift' and 'ResourceCount', not stack status events. Option C is wrong because while an EventBridge rule can capture CloudFormation events, it requires additional setup to filter for stack creation failures and is not the simplest approach compared to directly using SNS notifications. Option D is wrong because enabling CloudTrail and creating a metric filter for 'CreateStack' failures is overly complex and indirect; CloudTrail logs API calls but does not natively trigger notifications without additional CloudWatch Alarms or EventBridge rules.

1024
MCQeasy

A company wants to be able to query application logs in near real-time using a SQL-like syntax. Which AWS service should be used?

A.CloudWatch Logs Insights
B.CloudWatch Metrics Insights
C.CloudWatch Events
D.CloudWatch Logs subscription filters
AnswerA

CloudWatch Logs Insights is a purpose-built query engine for log data stored in CloudWatch Logs. It uses a SQL-like query language to parse, filter, aggregate, and visualize log events in near real-time. Queries can be run across one or more log groups and saved for reuse, making it the correct tool for directly querying application logs.

Why this answer

CloudWatch Logs Insights is the correct service because it enables interactive querying of log data stored in CloudWatch Logs using a purpose-built SQL-like query language. It is designed for ad-hoc analysis of logs in near real-time, allowing users to filter, aggregate, and visualize log events without needing to export data to another analytics platform.

Exam trap

The trap here is that candidates confuse CloudWatch Logs Insights with CloudWatch Metrics Insights, assuming both can query logs, but Metrics Insights only works with numeric metric data and cannot parse or search log message content.

How to eliminate wrong answers

Option B is wrong because CloudWatch Metrics Insights is used to query and analyze metric data (numerical time-series data), not log data, and does not support SQL-like syntax for log content. Option C is wrong because CloudWatch Events (now part of Amazon EventBridge) is a service for routing events to targets based on rules, not for querying log data with SQL-like syntax. Option D is wrong because CloudWatch Logs subscription filters are used to stream log data in real-time to other destinations (e.g., Lambda, Kinesis, Elasticsearch) for processing, but they do not provide a query interface or SQL-like syntax for interactive analysis.

1025
MCQeasy

A company wants to establish a dedicated, low-latency, private connection between its on-premises data center and an AWS VPC. The company does not want to use the public internet. Which AWS service should be used to meet this requirement?

A.AWS Direct Connect
B.AWS Virtual Private Gateway
C.AWS Transit Gateway
D.VPC Peering
AnswerA

AWS Direct Connect provides a dedicated private network connection from on-premises to AWS, bypassing the public internet entirely. It satisfies the low-latency and privacy constraints by using a physical cross-connect at an AWS Direct Connect location, delivering consistent network performance rather than variable internet routing.

Why this answer

AWS Direct Connect is the correct service because it provides a dedicated, private, low-latency network connection from an on-premises data center to AWS, bypassing the public internet entirely. It uses industry-standard 802.1Q VLANs to create a private virtual interface (VIF) that connects directly to a VPC, ensuring consistent network performance and reduced latency.

Exam trap

The trap here is that candidates often confuse AWS Virtual Private Gateway (a required attachment for Direct Connect) with the Direct Connect service itself, or they assume VPC Peering can extend to on-premises networks, but VPC Peering is strictly limited to inter-VPC connectivity within AWS.

How to eliminate wrong answers

Option B (AWS Virtual Private Gateway) is wrong because it is a logical component that attaches to a VPC to enable VPN or Direct Connect connections, but it is not a service that itself provides a dedicated private connection; it requires Direct Connect or a VPN to function. Option C (AWS Transit Gateway) is wrong because it is a network transit hub used to interconnect multiple VPCs and on-premises networks, but it does not provide the dedicated physical connection itself; it relies on Direct Connect or VPN for the on-premises link. Option D (VPC Peering) is wrong because it only connects two VPCs within AWS using the AWS global network, and it cannot be used to connect an on-premises data center to a VPC.

1026
MCQmedium

A company runs a production database on Amazon RDS for MySQL with Multi-AZ enabled. During a recent Availability Zone outage, the database experienced a failover. After the failover, the application team notices that the database endpoint in the connection string no longer works. What is the most likely cause?

A.The application is using the IP address of the database instance instead of the DNS endpoint.
B.The DB instance identifier changed after the failover.
C.The security group for the RDS instance was modified during the failover.
D.The DNS CNAME record for the RDS endpoint was manually changed.
AnswerA

When a Multi-AZ failover occurs, RDS promotes the standby database instance in a different Availability Zone, which has a different private IP address. The DNS CNAME for the RDS endpoint is automatically updated to point to the new instance's IP. If the application has hardcoded the old IP address rather than using the endpoint, it will not re-resolve DNS and will fail to connect to the new active instance. Always use the RDS DNS endpoint so that connections are directed to the current primary.

Why this answer

When Multi-AZ failover occurs, RDS updates the DNS CNAME record to point to the new primary instance in a different Availability Zone. If the application uses the IP address directly instead of the DNS endpoint, it will continue to resolve to the old (now failed) instance's IP, which is no longer accessible. The DNS endpoint is the only stable reference that automatically follows the failover.

Exam trap

The trap here is that candidates assume the endpoint itself changes or that the instance identifier is modified, when in fact only the underlying IP address changes and the DNS record is updated automatically.

How to eliminate wrong answers

Option B is wrong because the DB instance identifier remains unchanged after a failover; only the underlying compute instance changes. Option C is wrong because security groups are not modified during a failover; they are attached to the RDS instance and persist unchanged. Option D is wrong because the DNS CNAME record is managed automatically by AWS RDS and is not manually changed by users; a manual change would not occur during an automated failover.

1027
MCQmedium

A SysOps administrator needs to provide temporary, limited-privilege credentials to an application running on an EC2 instance. The application needs to access an S3 bucket. What is the most secure way to grant these credentials?

A.Use a Lambda function to generate temporary credentials from an IAM user.
B.Store the AWS access keys in an S3 bucket and have the application download them at startup.
C.Attach an IAM role with the necessary permissions to the EC2 instance.
D.Create an IAM user with programmatic access and store the access keys in the application's environment variables.
AnswerC

Attaching an IAM role to the EC2 instance via an instance profile is the AWS-recommended way to grant AWS API access to applications running on that instance. The AWS SDK and CLI automatically retrieve short-lived credentials from the instance metadata service (IMDSv2) and refresh them before they expire, so no secrets are stored in code, configuration, or environment variables. These credentials carry only the permissions defined in the role, and the role can be updated without changing the instance.

Why this answer

Attaching an IAM role to an EC2 instance is the most secure method because it leverages the AWS Security Token Service (STS) to automatically rotate temporary credentials. The instance retrieves these credentials via the instance metadata service (IMDS), eliminating the need to hardcode, store, or manually manage long-term access keys. This approach follows the principle of least privilege and ensures credentials are automatically rotated and revoked when the role is detached.

Exam trap

The trap here is that candidates may think storing keys in environment variables or S3 is acceptable because it 'works', but the SOA-C02 exam specifically tests the understanding that IAM roles with EC2 instance profiles are the only secure, AWS-recommended method for providing temporary credentials to applications running on EC2, avoiding the pitfalls of long-term static keys.

How to eliminate wrong answers

Option A is wrong because using a Lambda function to generate temporary credentials from an IAM user still requires the IAM user's long-term access keys to be stored somewhere (e.g., in Lambda environment variables), which introduces a static credential risk and adds unnecessary complexity. Option B is wrong because storing AWS access keys in an S3 bucket and having the application download them at startup exposes the keys to potential interception, requires managing bucket policies and encryption, and still relies on long-term credentials that do not rotate automatically. Option D is wrong because creating an IAM user with programmatic access and storing the access keys in environment variables embeds long-term static credentials that are not automatically rotated, increasing the risk of exposure and violating the security best practice of using temporary credentials for EC2 workloads.

1028
Multi-Selectmedium

A company has a VPC with a public subnet and a private subnet. The private subnet contains an EC2 instance that must access the internet for software updates. Which TWO actions are required to enable this? (Choose TWO.)

Select 2 answers
A.Add an Internet Gateway to the private subnet's route table.
B.Deploy a NAT Gateway in a public subnet.
C.Assign a public IP address to the EC2 instance.
D.Attach an Internet Gateway to the NAT Gateway.
E.Add a route in the private subnet's route table pointing to the NAT Gateway for 0.0.0.0/0.
AnswersB, E

Deploying a NAT Gateway in a public subnet is correct because the NAT Gateway is a managed service that must reside in a subnet that has a route to an Internet Gateway (IGW). This placement enables the NAT Gateway to translate private IP addresses from instances in private subnets into its own Elastic IP address and forward traffic to the IGW for outbound connections. Because the NAT Gateway is in a public subnet, it can reach the internet and, at the same time, it does not accept inbound connections from the internet, preserving the security boundary. Its managed nature means you do not need to patch or operate it, and it automatically scales to handle bursts of traffic.

Why this answer

A NAT Gateway in a public subnet provides outbound internet access for private instances while preventing inbound connections. The private subnet's route table must include a default route (0.0.0.0/0) pointing to the NAT Gateway, enabling traffic to be forwarded to the internet via the Internet Gateway attached to the VPC.

Exam trap

The trap here is that candidates often think a public IP on the instance or an Internet Gateway in the private subnet is needed, but the correct solution uses a NAT Gateway in a public subnet with a default route in the private subnet's route table.

1029
MCQhard

A company has an AWS account with multiple VPCs connected via a transit gateway. The SysOps administrator needs to ensure that all traffic between VPCs is encrypted in transit. Which solution should the administrator implement?

A.Use VPC peering connections between the VPCs.
B.Use VPC endpoints to route traffic through AWS PrivateLink.
C.Set up AWS Site-to-Site VPN connections between the VPCs via the transit gateway.
D.Configure network ACLs to deny unencrypted traffic.
AnswerC

AWS Site-to-Site VPN connections establish IPsec tunnels that encrypt all traffic between the connected sites. By attaching these VPN connections to a transit gateway, you can interconnect multiple VPCs and route private traffic through those encrypted tunnels, achieving confidentiality for inter-VPC communication. This is the correct approach because the VPN terminates IPsec encryption at the transit gateway, and the transit gateway handles routing between all attached VPCs and VPN connections.

Why this answer

AWS Site-to-Site VPN connections between VPCs via a transit gateway can enforce IPsec encryption for all inter-VPC traffic. The transit gateway acts as a central hub, and each VPN connection encrypts traffic using IPsec tunnels, ensuring data confidentiality and integrity in transit. This meets the requirement for encrypted transit between VPCs without relying on third-party appliances.

Exam trap

The trap here is that candidates often assume VPC peering provides encryption by default, but AWS does not encrypt traffic over peering connections; encryption must be explicitly added via VPN or other mechanisms.

How to eliminate wrong answers

Option A is wrong because VPC peering connections do not provide encryption in transit by default; traffic between peered VPCs traverses the AWS network without IPsec or TLS encryption. Option B is wrong because VPC endpoints with AWS PrivateLink are used to privately access specific AWS services or your own services, not to route general inter-VPC traffic, and they do not inherently encrypt all traffic between VPCs. Option D is wrong because network ACLs are stateless firewalls that filter traffic based on IP addresses and ports but do not encrypt traffic; they cannot enforce encryption of the data payload.

1030
MCQmedium

A SysOps administrator ran a CloudFormation stack update that failed and rolled back. The stack status is UPDATE_ROLLBACK_FAILED. The administrator needs to fix the issue and bring the stack to a stable state. What should the administrator do FIRST?

A.Identify and resolve the resource issue that caused the rollback failure, then continue the rollback.
B.Wait for CloudFormation to automatically retry the rollback.
C.Execute a new stack update to overwrite the failed resources.
D.Delete the stack and recreate it from the template.
AnswerA

The correct first action is to inspect the stack events and any associated resource status reasons to identify why the rollback itself failed. CloudFormation will not proceed past the UPDATE_ROLLBACK_FAILED state until the underlying resource issue is resolved, because resources that could not be rolled back remain in a state that blocks further stack operations. After fixing the resource problem, such as deleting a non-CloudFormation-managed dependency or manually updating an unresponsive resource, you can use the "Continue update rollback" operation to drive the stack to a stable UPDATE_ROLLBACK_COMPLETE state. This is the only recovery path that preserves the stack and any successfully rolled-back resources without forcing a destructive teardown.

Why this answer

When a CloudFormation stack is in UPDATE_ROLLBACK_FAILED, the rollback itself failed because a resource could not be reverted. The administrator must first identify and resolve the underlying resource issue (e.g., a deleted S3 bucket, a modified IAM role, or a resource in an inconsistent state), then use the ContinueUpdateRollback API to resume the rollback and bring the stack to UPDATE_ROLLBACK_COMPLETE.

Exam trap

The trap is assuming CloudFormation will self-heal or that a new update can override the failure — candidates often pick 'wait' or 'delete and recreate,' but the correct first step is always to fix the resource and continue the rollback.

How to eliminate wrong answers

Option B is wrong because CloudFormation does not automatically retry a failed rollback — the stack remains stuck in UPDATE_ROLLBACK_FAILED until manual intervention. Option C is wrong because you cannot perform a new stack update while the stack is in UPDATE_ROLLBACK_FAILED; the stack must first be returned to a stable state. Option D is wrong because deleting and recreating the stack is destructive, loses resource state, and is unnecessary when the rollback can be continued after fixing the resource.

1031
MCQhard

A company has multiple VPCs in the same AWS account and Region, each with overlapping CIDR blocks (10.0.0.0/16). The SysOps administrator needs to establish connectivity between all VPCs and the on-premises network via AWS Transit Gateway. Additionally, certain VPCs must be isolated from each other while still reaching on-premises. How should the administrator configure the Transit Gateway to meet these requirements?

A.Create a single Transit Gateway route table and add routes for all VPCs and the on-premises network.
B.Create multiple Transit Gateway route tables: one for each group of VPCs that need to communicate, and associate each VPC attachment with the appropriate route table. Add static routes to the on-premises network in each route table.
C.Use VPC peering instead of Transit Gateway to connect VPCs, and use Direct Connect Gateway for on-premises connectivity.
D.Configure VPN connections between each VPC and the on-premises network, bypassing Transit Gateway.
AnswerB

Create separate Transit Gateway route tables, one per group of VPCs that must communicate, and associate each VPC attachment with its group's route table. Within each route table, add static routes pointing to the on-premises network (or propagate from the VPN/DX attachment) so every group retains reachability to the data center. Because route tables are independent, overlapping CIDRs across groups are never compared, avoiding routing conflicts; traffic between groups is denied by default since no routes exist. This gives you transitive routing within a group and full isolation between groups, which is exactly what the scenario demands.

Why this answer

AWS Transit Gateway supports multiple route tables, allowing you to isolate VPC attachments from each other while still providing a common route to the on-premises network. By creating separate route tables for each group of VPCs that need to communicate, and associating the appropriate VPC attachments with those tables, you can enforce isolation between groups. Adding static routes to the on-premises network in each route table ensures all VPCs can reach on-premises, even when they cannot communicate with each other.

Exam trap

The trap here is that candidates assume a single Transit Gateway route table is sufficient for all VPCs, overlooking the need for isolation between specific VPC groups when overlapping CIDRs are present.

How to eliminate wrong answers

Option A is wrong because a single Transit Gateway route table would allow all VPC attachments to communicate with each other, violating the requirement to isolate certain VPCs. Option C is wrong because VPC peering does not support transitive routing and cannot be used with overlapping CIDR blocks; additionally, Direct Connect Gateway alone does not provide the required VPC-to-VPC isolation and connectivity. Option D is wrong because configuring VPN connections between each VPC and on-premises bypasses the Transit Gateway, failing to centralize connectivity and making it impossible to manage isolation and routing efficiently across multiple VPCs.

1032
MCQhard

A company uses AWS Direct Connect to connect its on-premises network to AWS. The SysOps team notices that traffic from the on-premises network to a VPC is not using the Direct Connect connection but instead is going over the internet. The VPC has a virtual private gateway attached and the on-premises router is advertising a specific route. What is the most likely cause?

A.The on-premises network does not have a route to the VPC CIDR.
B.The VPC route table has a more specific route (e.g., 0.0.0.0/0) pointing to an Internet Gateway.
C.The BGP session between the on-premises router and the Direct Connect router is down.
D.The virtual private gateway is not attached to the VPC.
AnswerC

If the BGP session is down, the on-premises router cannot exchange routes with the Direct Connect router, so it loses the Direct Connect path to the VPC and falls back to internet routing. This is the most likely cause.

Why this answer

The BGP session between the on-premises router and the Direct Connect router is down. When BGP is down, the on-premises router cannot exchange routes with the AWS side over Direct Connect. Even though the on-premises router may be advertising a specific route, without an active BGP session, that route is not received by the Direct Connect router, and the virtual private gateway does not propagate it into the VPC.

As a result, traffic from the on-premises network to the VPC falls back to using the internet route instead of Direct Connect. Option B is incorrect because the VPC route table controls outbound traffic from the VPC, not inbound traffic from on-premises; a default route to an Internet Gateway would cause asymmetric routing for return traffic but would not prevent inbound traffic from using Direct Connect if the BGP session is active.

Exam trap

The trap is that candidates often suspect VPC route misconfigurations or virtual private gateway attachment issues, but the core problem is a failed BGP session on the Direct Connect link, which stops route exchange between on-premises and AWS.

How to eliminate wrong answers

Option A is wrong because if the on-premises network lacked a route to the VPC CIDR, traffic would not reach the VPC at all, but the scenario states traffic is going over the internet, indicating a route exists but is misdirected. Option C is wrong because if the BGP session were down, the on-premises router would not advertise any routes, and the VPC would have no learned route to the on-premises network, causing traffic to fail or use the internet gateway as a default; however, the question states the on-premises router is advertising a specific route, implying BGP is up. Option D is wrong because if the virtual private gateway were not attached to the VPC, the VPC would have no connectivity to Direct Connect, and traffic would either fail or use the internet gateway, but the scenario specifically mentions a virtual private gateway is attached, making this option incorrect.

1033
MCQmedium

A company uses an RDS for MySQL Multi-AZ DB instance. They want to minimize downtime during a planned maintenance update that requires a database engine version upgrade. What should the SysOps administrator do?

A.Use the AWS Console to apply the maintenance update immediately; the Multi-AZ configuration will minimize downtime.
B.Modify the DB instance to be a Single-AZ deployment, then apply the upgrade.
C.Take a snapshot, restore it as a new instance, and upgrade that instance.
D.Create a read replica in the same region, upgrade the replica, and promote it.
AnswerA

Applying the maintenance window update immediately via the AWS Console is correct for a Multi-AZ RDS MySQL instance because RDS orchestrates the engine patch as a rolling operation: it first applies the update to the standby replica, then triggers a DNS failover to promote that updated standby to primary, and finally updates the old primary as the new standby. The failover itself typically completes within 60–120 seconds, and because the standby is already patched, the primary's availability impact is limited to a brief connection drop during the automatic failover. This leverages the Multi-AZ architecture exactly as designed—minimizing downtime without manual intervention or data loss—while keeping the instance fully managed by RDS.

Why this answer

RDS for MySQL Multi-AZ deployments perform engine version upgrades with automatic failover, which minimizes downtime by updating the standby instance first, then promoting it to primary. The Multi-AZ configuration ensures that the upgrade process is applied with reduced impact, typically causing only a brief interruption during the failover rather than a full outage.

Exam trap

The trap here is that candidates may overthink the solution and choose complex workarounds like read replica promotion, not realizing that RDS Multi-AZ already provides a built-in mechanism to minimize downtime during engine version upgrades, making the simplest option (applying the update immediately) the correct one.

How to eliminate wrong answers

Option B is wrong because modifying a Multi-AZ instance to Single-AZ before an upgrade eliminates the failover benefit, increasing downtime during the upgrade and requiring a manual failover or longer maintenance window. Option C is wrong because taking a snapshot, restoring it as a new instance, and upgrading that instance does not minimize downtime for the original production instance; it creates a separate upgraded instance that requires DNS changes and data synchronization, leading to potential data loss and extended downtime. Option D is wrong because creating a read replica, upgrading it, and promoting it is a valid approach for major version upgrades with minimal downtime, but it is more complex and not the recommended method for a planned maintenance update on a Multi-AZ instance; the Multi-AZ built-in upgrade process is simpler and achieves the same goal with less operational overhead.

1034
MCQeasy

A company processes orders using an Amazon SQS standard queue. The order processing application occasionally fails to process a message. The SysOps administrator wants to ensure that any message that fails to be successfully processed after three attempts is automatically moved to a separate queue for manual review. Which SQS feature should be configured?

A.Configure a Dead Letter Queue (DLQ) with a redrive policy
B.Increase the visibility timeout of the queue
C.Convert the queue to a FIFO queue
D.Enable redrive allow policy on the queue
AnswerA

A Dead Letter Queue (DLQ) with a redrive policy is the correct mechanism for handling messages that repeatedly fail to process successfully. When you set a redrive policy with a maximum receive count, SQS automatically moves a message to the configured DLQ after that many attempted receives (e.g., after the consumer has received it but failed to delete it). This isolates poison-pill messages from the main queue, allowing the main queue to continue processing healthy messages without retrying broken ones indefinitely, and enables later analysis or manual correction in the DLQ.

Why this answer

A Dead Letter Queue (DLQ) with a configured redrive policy is the correct SQS feature to automatically move messages that have failed processing after a specified number of attempts (in this case, three) to a separate queue for manual review. The redrive policy defines the source queue, the DLQ, and the maximum receive count (maxReceiveCount) threshold. When a message is received from the source queue more times than the maxReceiveCount, SQS automatically redirects it to the DLQ, isolating problematic messages without manual intervention.

Exam trap

The trap here is that candidates may confuse increasing the visibility timeout (which only delays reprocessing) with the automatic isolation provided by a Dead Letter Queue, or think that converting to FIFO or enabling a redrive allow policy alone solves the problem, when the core requirement is a DLQ with a configured redrive policy that specifies the maxReceiveCount.

How to eliminate wrong answers

Option B is wrong because increasing the visibility timeout only prevents other consumers from processing a message for a longer period, but does not move failed messages to a separate queue; it merely delays reprocessing. Option C is wrong because converting the queue to a FIFO queue changes the ordering and exactly-once processing guarantees, but does not provide automatic redirection of failed messages to a separate queue; FIFO queues also support DLQs, but the conversion itself is not the solution. Option D is wrong because enabling a redrive allow policy on the queue is not a standard SQS feature; the correct term is 'redrive policy' (or 'redrive permission policy') which is used to allow a source queue to use a specific DLQ, but the question asks for the feature that moves failed messages, which is the DLQ with a redrive policy, not just the allow policy.

1035
MCQmedium

A SysOps administrator is troubleshooting an issue where an IAM user can launch EC2 instances but cannot terminate them. The user's permissions are based on an IAM group policy. Which action should the administrator take to resolve this?

A.Attach a managed policy that includes ec2:TerminateInstances directly to the user
B.Add the user to a different IAM group that has the required permissions
C.Check the user's permissions boundary for any restrictions
D.Review and modify the IAM group policy to include ec2:TerminateInstances action
AnswerD

The most likely root cause is that the IAM group policy attached to the user's group does not include an ec2:TerminateInstances action, so modifying that policy to allow the API call resolves the issue for every member of the group. Use a statement with "Effect": "Allow" for ec2:TerminateInstances on the appropriate resource, then test with the IAM policy simulator to verify effective access.

Why this answer

Since the user's permissions come from an IAM group policy, the missing ec2:TerminateInstances action must be added to that group policy — that's the source of the user's effective permissions. Modifying the group policy grants the permission to all members consistently and follows AWS best practice of managing permissions at the group level.

Exam trap

SOA-C02 often tests whether candidates jump to user-level policy attachments instead of fixing the group policy that is explicitly identified as the permission source — the exam rewards least-disruption, best-practice fixes.

How to eliminate wrong answers

Option A is wrong because attaching a managed policy directly to the user bypasses the group-based model and creates permission sprawl; while it would technically work, it's not the correct administrative action when the group policy is the identified source. Option B is wrong because moving the user to a different group is disruptive and unnecessary when the existing group policy can simply be corrected. Option C is wrong because a permissions boundary would restrict permissions, but the scenario states permissions are based on a group policy — there's no indication of a boundary, and checking it doesn't resolve the missing action.

1036
MCQhard

A company runs a critical production workload on a fleet of EC2 instances managed by an Auto Scaling group. The instances are behind an Application Load Balancer (ALB). Recently, the company experienced a regional outage that caused all instances to become unhealthy. The SysOps administrator must design a solution to automatically recover from such an outage with minimal downtime. The solution must be cost-effective and not require manual intervention. The administrator considers four options. Which option meets the requirements?

A.Configure the Auto Scaling group to launch instances across multiple Availability Zones and configure the ALB to route traffic to healthy targets.
B.Increase the desired capacity of the Auto Scaling group and use larger instance types to absorb the load during failover.
C.Create a warm standby environment in another AWS Region with a smaller Auto Scaling group. Use Route53 failover routing to switch traffic.
D.Use AWS Lambda to periodically check the health of instances and automatically relaunch failed instances in another region.
AnswerC

A warm standby in a second Region with a smaller Auto Scaling group keeps capacity running at reduced cost, and Route 53 failover routing redirects traffic automatically when health checks fail. This satisfies the regional-outage, minimal-downtime and no-manual-intervention requirements.

Why this answer

A regional outage takes down all Availability Zones in a Region, so only a cross-Region strategy can recover. A warm standby environment in another Region with a smaller Auto Scaling group, combined with Route 53 failover routing, provides automatic, low-downtime recovery without manual intervention. This is the AWS-recommended pattern for regional resilience and is more cost-effective than a fully active-active multi-Region deployment.

Exam trap

SOA-C02 often tests the misconception that multi-AZ equals multi-Region — candidates must recognize that only cross-Region designs survive a full regional outage.

How to eliminate wrong answers

Option A is wrong because spreading instances across multiple AZs within a single Region does not protect against a regional outage — all AZs in the affected Region would still be down. Option B is wrong because increasing capacity and instance size within the same Region does nothing for regional failure and increases cost without improving resilience. Option D is wrong because a Lambda health-checker that relaunches instances in another Region is not a supported or reliable failover mechanism — it lacks DNS integration, capacity pre-provisioning, and would introduce significant downtime and complexity.

1037
MCQmedium

Refer to the exhibit. A SysOps administrator ran the commands shown. What is the state of the EC2 instance?

A.The instance is running and healthy.
B.The instance is terminated.
C.The instance is running but has a system impairment.
D.The instance is stopped.
AnswerC

The instance is running but has a system impairment: The EC2 instance state is 'running', meaning it has been successfully launched and is operational at the hypervisor level. However, the system status check reports 'impaired', which indicates a problem with the physical host or the AWS infrastructure that supports the instance, such as loss of network connectivity, power loss, or hardware failure. The instance may still be responsive at the guest OS level, but the underlying system is degraded, so this option correctly describes both the running state and the system impairment.

Why this answer

The `aws ec2 describe-instance-status` command with the `--instance-id` flag returns the instance's system status checks. The output shows `SystemStatus: impaired`, which indicates that the instance is running but has a system impairment (e.g., loss of network connectivity or power). This status is determined by AWS's automated status checks that run every minute, and an impaired status means the underlying host has an issue that affects the instance.

Exam trap

The trap here is that candidates confuse `SystemStatus: impaired` with instance state (e.g., stopped or terminated), when in fact the instance is still running but the underlying host has a problem that affects its reliability.

How to eliminate wrong answers

Option A is wrong because the output explicitly shows `SystemStatus: impaired`, not `ok`, so the instance is not healthy. Option B is wrong because a terminated instance would not return any instance status output; the command would return an error or an empty set. Option D is wrong because a stopped instance would show `InstanceState: stopped` and `SystemStatus: not-applicable` or no status checks, not `impaired`.

1038
MCQhard

A company is using AWS CodePipeline to deploy a web application. The security team requires that all code changes be reviewed and approved before deployment to production. Which action should be taken to enforce this requirement?

A.Add a manual approval action in the CodePipeline pipeline before the production deployment stage.
B.Create an IAM policy that denies the codecommit:PutFile action unless the user is in a specific group.
C.Enable AWS CloudTrail and create a CloudWatch Events rule to notify the security team of any deployments.
D.Configure a CodeCommit repository to require pull requests for all changes.
AnswerA

A manual approval action is the only option that inserts a human decision gate directly into the CodePipeline execution. You configure an approval action by adding a stage of type 'Approval' with an SNS topic; the pipeline pauses once that stage is reached and sends a notification to the approver(s). The approver must have IAM permissions for codepipeline:PutApprovalResult to approve or reject, and the pipeline does not proceed to the production deployment stage until that explicit approval is granted. This enforces separation of duties and prevents unverified code from reaching production.

Why this answer

Adding a manual approval action in the CodePipeline pipeline before the production deployment stage enforces a required review and approval gate. This action pauses the pipeline at that point, waiting for an authorized user to manually approve the change before it proceeds to the production stage, directly meeting the security team's requirement.

Exam trap

The trap here is that candidates often confuse source-level controls (like pull request requirements or IAM policies) with pipeline-level approval gates, mistakenly thinking that preventing direct pushes or requiring pull requests alone satisfies the deployment approval requirement.

How to eliminate wrong answers

Option B is wrong because denying the codecommit:PutFile action prevents users from pushing code directly to the repository, but it does not enforce a review and approval process within the deployment pipeline; it only restricts write access. Option C is wrong because enabling CloudTrail and creating a CloudWatch Events rule only provides notification of deployments after they occur, not a pre-deployment approval gate. Option D is wrong because configuring a CodeCommit repository to require pull requests for all changes enforces code review at the source code level, but it does not add an approval step within the CodePipeline deployment pipeline itself.

1039
Drag & Dropmedium

Drag and drop the steps to set up an Amazon S3 bucket policy to grant cross-account access into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Identify the bucket and account, write the policy with correct principal and actions, save, and test.

1040
MCQmedium

A SysOps administrator is designing a disaster recovery plan for a critical application hosted on AWS. The application runs on EC2 instances with data stored in an RDS MySQL database. The RPO must be less than 15 minutes, and the RTO must be less than 1 hour. Which solution meets these requirements?

A.Take daily snapshots of the RDS instance and copy them to another Region.
B.Use an RDS DB instance with a Multi-AZ standby and a cross-Region Read Replica.
C.Use an RDS Multi-AZ DB Cluster deployment.
D.Use a single-AZ RDS instance with automated backups and point-in-time recovery.
AnswerC

An RDS Multi-AZ DB Cluster deploys a writer and two readable standby nodes in three separate Availability Zones, with synchronous replication from the writer to both standbys before each transaction is committed. On failure, the cluster automatically promotes one of the standbys, typically completing failover in under a minute, which meets the RTO of less than one hour. Because every commit is synchronously duplicated, no committed transactions are lost, so the RPO is effectively zero and comfortably satisfies the 15-minute requirement.

Why this answer

An RDS Multi-AZ DB Cluster deployment provides synchronous replication across three Availability Zones and automatic failover, enabling an RTO of typically under 1 minute and an RPO of effectively zero (no data loss). This meets the strict RPO (<15 minutes) and RTO (<1 hour) requirements without relying on cross-Region replication or manual recovery steps.

Exam trap

The trap here is that candidates often confuse Multi-AZ standby (which provides high availability but not cross-Region DR) with Multi-AZ DB Cluster (which offers synchronous replication and automatic failover), or they mistakenly believe that a cross-Region Read Replica can meet strict RPO/RTO requirements due to its asynchronous nature and lack of automatic failover.

How to eliminate wrong answers

Option A is wrong because daily snapshots have an RPO of up to 24 hours, far exceeding the required <15 minutes, and copying to another Region adds latency without improving recovery speed. Option B is wrong because a cross-Region Read Replica is asynchronous (RPO can be minutes to hours depending on replication lag) and does not provide automatic failover for the primary DB instance, so RTO could exceed 1 hour. Option D is wrong because a single-AZ instance with automated backups and point-in-time recovery has an RPO of up to 5 minutes (backup window) but RTO can be much longer than 1 hour due to the need to restore from a snapshot and replay transaction logs.

1041
MCQeasy

A company runs a stateless web application on Amazon EC2 instances behind an Application Load Balancer. The application usage is consistent throughout the day and is expected to grow steadily over the next year. The SysOps administrator wants to minimize compute costs while ensuring capacity is available. Which purchasing option should the administrator use for the EC2 instances?

A.On-Demand Instances
B.Reserved Instances (Standard, 1-year or 3-year)
C.Spot Instances
D.Dedicated Hosts
AnswerB

Standard Reserved Instances require a 1- or 3-year commitment to a specific instance family and Region, and optionally an Availability Zone. In exchange, AWS provides a significant hourly discount (up to roughly 72% compared to On-Demand) plus a capacity reservation when you specify an Availability Zone. This makes them the most cost-effective and dependable choice for a stateless web app that has a predictable, steady baseline load and must remain consistently available.

Why this answer

The application has a steady, predictable usage pattern and is expected to grow steadily, making Reserved Instances (Standard) the most cost-effective option. By committing to a 1-year or 3-year term, the administrator can receive a significant discount (up to 72% compared to On-Demand) while ensuring capacity is always available. This aligns with the requirement to minimize compute costs without sacrificing availability for a stateless, load-balanced workload.

Exam trap

The trap here is that candidates often choose On-Demand Instances for simplicity, overlooking the significant cost savings of Reserved Instances for predictable, steady workloads, or they incorrectly choose Spot Instances without considering the interruption risk for a production application.

How to eliminate wrong answers

Option A is wrong because On-Demand Instances offer no discount and would result in higher costs over time for a predictable, steady workload. Option C is wrong because Spot Instances can be interrupted with a 2-minute warning, making them unsuitable for a production web application that requires consistent capacity and availability. Option D is wrong because Dedicated Hosts are designed for licensing or compliance requirements (e.g., per-socket licensing) and are significantly more expensive than shared tenancy, providing no cost benefit for a standard stateless web application.

1042
MCQmedium

A company is using AWS CloudFormation to manage its infrastructure. The SysOps Administrator needs to ensure that updates to a critical stack do not accidentally replace the database. Which feature should be used?

A.Use drift detection to identify changes.
B.Enable termination protection on the stack.
C.Use a change set to review the updates before executing them.
D.Define a stack policy that denies updates to the database resource.
AnswerD

A CloudFormation stack policy is a JSON policy attached to the stack that explicitly denies update, delete, or replacement actions on specified resources. For example, a Deny on the database logical resource with an action such as Update:Replace prevents CloudFormation from physically replacing the resource during an update, causing the update to fail rather than destroying the database. This is the only control listed that proactively blocks the destructive update before it can happen.

Why this answer

A stack policy in AWS CloudFormation explicitly denies updates to specified resources, such as the database, preventing accidental replacement or deletion during stack updates. Unlike termination protection, which only prevents stack deletion, a stack policy controls update actions on individual resources within the stack.

Exam trap

The trap here is that candidates often confuse termination protection (which only prevents stack deletion) with the ability to protect individual resources from replacement during updates, leading them to incorrectly select option B.

How to eliminate wrong answers

Option A is wrong because drift detection identifies differences between the stack's actual state and its template, but it does not prevent updates or replacements from occurring. Option B is wrong because termination protection prevents the entire stack from being deleted, not individual resources from being updated or replaced during a stack update. Option C is wrong because a change set allows you to review the proposed changes before execution, but it does not enforce any protection; the administrator could still execute the change set and replace the database.

1043
MCQeasy

A company has a VPC with public and private subnets. An Application Load Balancer (ALB) is in the public subnets, and Amazon EC2 instances are in the private subnets. The SysOps administrator needs to allow the EC2 instances to access an Amazon S3 bucket in the same AWS Region without traversing the internet. Which solution should the administrator implement?

A.A VPC Gateway Endpoint for S3
B.A NAT Gateway
C.An Internet Gateway
D.VPC Peering
AnswerA

A gateway endpoint attaches to the route table and provides private connectivity to S3 over the AWS network, so instances in private subnets reach the bucket without a NAT gateway, internet gateway or public addressing. This satisfies the no-internet-traversal constraint.

Why this answer

A VPC Gateway Endpoint for S3 allows EC2 instances in private subnets to access S3 buckets privately using AWS's internal network, without traversing the internet. This endpoint uses prefix lists and route table entries to direct S3 traffic through the AWS backbone, ensuring low latency and no data transfer costs.

Exam trap

The trap here is that candidates often choose a NAT Gateway or Internet Gateway because they think outbound traffic to AWS services must go through the internet, but Gateway Endpoints provide a private, cost-effective alternative for S3 and DynamoDB access within the same region.

How to eliminate wrong answers

Option B (NAT Gateway) is wrong because it routes traffic through the internet, which violates the requirement to avoid internet traversal and incurs data transfer costs. Option C (Internet Gateway) is wrong because it is used for public internet access and requires public IP addresses, not private S3 access. Option D (VPC Peering) is wrong because it connects VPCs but does not provide direct access to S3; S3 is a service outside the VPC, not a peered resource.

1044
MCQhard

A company runs a critical application on Amazon EC2 instances. The application uses an NFS file system stored on an Amazon EFS file system. The SysOps administrator must ensure that the file system is highly available and can withstand an Availability Zone failure. The file system must be accessible from all Availability Zones in the region. Which configuration is required to meet these requirements?

A.Configure the EFS file system for One Zone storage class and mount it using the file system ID.
B.Configure the EFS file system for Standard storage class and mount it using the regional DNS name.
C.Configure EFS to use provisioned throughput and mount it using a mount target IP address.
D.Enable EFS lifecycle management to move files to Infrequent Access storage class.
AnswerB

The Standard storage class automatically replicates file data across multiple Availability Zones, ensuring durability even if one AZ goes down. The regional DNS name (fs-xxxx.region.efs.amazonaws.com) resolves to mount targets in every AZ where the file system is configured, allowing clients to fail over to an available mount target seamlessly. This combination provides the high availability needed for a critical application.

Why this answer

The EFS Standard storage class replicates data across multiple Availability Zones (AZs) within a region, providing high availability and resilience against an AZ failure. Mounting the file system using the regional DNS name ensures that clients in any AZ can reach the file system via the nearest mount target, as the regional DNS name resolves to the mount target IP addresses in the local AZ. This configuration meets the requirement for the file system to be accessible from all AZs in the region while withstanding an AZ outage.

Exam trap

The trap here is that candidates often confuse storage class (One Zone vs. Standard) with performance settings (provisioned throughput) or cost-saving features (lifecycle management), and overlook that the regional DNS name is essential for multi-AZ access and failover.

How to eliminate wrong answers

Option A is wrong because the One Zone storage class stores data only within a single Availability Zone, which does not provide high availability or withstand an AZ failure. Option C is wrong because provisioned throughput is a performance setting, not a high-availability or multi-AZ configuration; mounting via a mount target IP address would pin the client to a specific AZ, failing the requirement for accessibility from all AZs. Option D is wrong because lifecycle management moves files to the Infrequent Access (IA) storage class to reduce costs, but it does not affect the availability or multi-AZ resilience of the file system.

1045
MCQmedium

An Auto Scaling group launches new EC2 instances when CPU exceeds 70 percent. The instances take 4 minutes to bootstrap (install software, register with a service discovery system, and warm up caches). Without a hook, the load balancer routes traffic to new instances before they are ready, causing 503 errors. What is the correct solution?

A.Add a lifecycle hook on the autoscaling:EC2_INSTANCE_LAUNCHING transition; signal CompleteLifecycleAction(CONTINUE) when bootstrap finishes
B.Increase the load balancer health check grace period to 10 minutes to give instances time to bootstrap
C.Increase the warm-up time in the Auto Scaling group's instance refresh configuration
D.Use a weighted target group with 0 weight for new instances until they are confirmed healthy
AnswerA

The hook holds the instance in Pending:Wait, outside the target group, until the signal arrives. The load balancer never routes traffic to the instance during its Pending:Wait phase. After the CONTINUE signal, the instance enters InService and the load balancer registers it normally. The heartbeat timeout (default 1 hour, configurable) should exceed the bootstrap time.

Why this answer

Lifecycle hooks allow the Auto Scaling group to pause instance launch until a custom action (e.g., bootstrap completion) is finished. By adding a hook on the autoscaling:EC2_INSTANCE_LAUNCHING transition, the instance is held in a 'pending:wait' state. Once the bootstrap script calls CompleteLifecycleAction with the CONTINUE result, the instance transitions to 'InService' and can then be registered with the load balancer, preventing premature traffic and 503 errors.

Exam trap

The trap here is that candidates often confuse the health check grace period (which only delays health checks, not registration) with lifecycle hooks (which actually control when the instance becomes available to the load balancer).

How to eliminate wrong answers

Option B is wrong because increasing the load balancer health check grace period only delays when the load balancer starts checking health; it does not prevent the load balancer from routing traffic to the instance before it is ready. The instance is still added to the target group immediately, and the grace period only affects health check status, not registration. Option C is wrong because the warm-up time in an instance refresh configuration controls how long new instances are given to become healthy during a rolling update, not the initial launch or bootstrap process for a scaling event triggered by CPU.

Option D is wrong because weighted target groups distribute traffic based on weights; setting 0 weight for new instances would prevent all traffic, but the instances would still be registered and could receive traffic if the weight is later changed manually, and this approach does not automatically signal readiness after bootstrap.

1046
MCQmedium

An application uses an RDS MySQL DB instance. The administrator notices that read performance is poor during peak hours. What is a cost-effective way to improve read performance?

A.Use Amazon ElastiCache for caching.
B.Enable Multi-AZ deployment.
C.Scale up the DB instance to a larger size.
D.Create a read replica in the same region.
AnswerD

A read replica in the same region is the most direct and cost-effective way to offload read traffic from the primary RDS MySQL instance. It uses asynchronous replication to keep a copy of the database and can handle a large number of SELECT queries, reducing the load on the source instance. Because it is in the same region, replication latency is low, and it also offers the benefit of being promotable to a standalone instance if needed for disaster recovery or migration scenarios.

Why this answer

Creating a read replica offloads read traffic from the primary RDS instance, improving read performance during peak hours at a relatively low cost. Option A (ElastiCache) adds complexity and additional cost. Option B (Multi-AZ) is for high availability and disaster recovery, not for read performance.

Option C (scaling up) addresses performance but is more expensive than adding a read replica.

1047
MCQeasy

A SysOps administrator needs to grant a developer access to view only the logs of a specific Amazon RDS instance. Which IAM action should be allowed?

A.rds:DownloadDBLogFilePortion
B.rds:DescribeDBInstances
C.rds:DescribeDBLogFiles
D.rds:DescribeEvents
AnswerA

rds:DownloadDBLogFilePortion permits retrieving individual log file contents for the specified RDS instance, giving read-only visibility without granting modify or delete permissions. This satisfies the least-privilege requirement of viewing only logs, unlike broader rds actions that expose instance configuration or management.

Why this answer

`rds:DownloadDBLogFilePortion` grants permission to download and view the contents of a log file for a specific RDS instance. The question asks for the action to 'view only the logs', which requires retrieving the log file content. `rds:DescribeDBLogFiles` only lists available log files, not the actual log data. Therefore, to view logs, the developer needs the `DownloadDBLogFilePortion` permission.

Exam trap

The trap here is that candidates often think `rds:DescribeDBLogFiles` (Option C) is sufficient to view logs, but it only lists log files. To actually view the log content, you need `rds:DownloadDBLogFilePortion`. The question specifies 'view only the logs', which implies viewing the content, not just listing files.

How to eliminate wrong answers

Option A is wrong because `rds:DownloadDBLogFilePortion` allows downloading the actual content of a log file, which is more than just viewing — it permits retrieval of log data, and the question specifies 'view only', so this action would grant excessive permissions. Option B is wrong because `rds:DescribeDBInstances` provides metadata about the DB instance (e.g., endpoint, engine, storage) but does not include log file information, so it cannot be used to view logs. Option D is wrong because `rds:DescribeEvents` returns events related to the DB instance (e.g., maintenance, backups) and has no relation to log files or log viewing.

1048
MCQmedium

Refer to the exhibit. A Lambda function is unable to write logs to CloudWatch Logs. The IAM role attached to the Lambda function includes the policy shown. What is the issue?

A.The log group name is incorrect.
B.The policy effect is Deny.
C.The 'logs:PutLogEvents' action is not allowed.
D.The resource ARN does not include a log-stream component.
AnswerD

For PutLogEvents, IAM must authorize against the log-stream ARN, which follows the pattern arn:aws:logs:region:account-id:log-group:log-group-name:log-stream:log-stream-name. The policy's resource ARN stops at 'log-group:my-log-group' and lacks the ':log-stream:...' component, so the permission does not match the API call's resource. To allow writes, the resource must be 'arn:aws:logs:region:account-id:log-group:my-log-group:log-stream:*' or a specific stream name. This is the root cause of the Lambda function's inability to write logs.

Why this answer

The Lambda function's IAM policy grants permissions for `logs:CreateLogGroup`, `logs:CreateLogStream`, and `logs:PutLogEvents` on the resource ARN `arn:aws:logs:us-east-1:123456789012:log-group:/aws/lambda/MyFunction:*`. However, this ARN only specifies the log group and a wildcard for log streams, which is insufficient for the `logs:PutLogEvents` action. The `logs:PutLogEvents` action requires a resource ARN that includes a specific log-stream component (e.g., `arn:aws:logs:us-east-1:123456789012:log-group:/aws/lambda/MyFunction:log-stream:*`), because the API call targets a particular log stream within the log group.

Without this, the Lambda function cannot write logs, resulting in a permissions error.

Exam trap

The trap here is that candidates assume a wildcard on the log group ARN (e.g., `log-group:*`) covers all actions, but AWS requires the log-stream component for write operations like `PutLogEvents`, causing a subtle permissions failure.

How to eliminate wrong answers

Option A is wrong because the log group name `/aws/lambda/MyFunction` is the default naming convention for Lambda functions and is correct; the issue is not with the name but with the resource ARN structure. Option B is wrong because the policy effect is explicitly `Allow`, not `Deny`, and there is no `Deny` statement present to override permissions. Option C is wrong because the `logs:PutLogEvents` action is listed in the policy's `Action` array, so it is allowed; the problem is that the resource ARN does not match the required format for that action.

1049
MCQmedium

A company is running a web application on a fleet of EC2 instances behind an Application Load Balancer. The application experiences variable traffic patterns with predictable spikes every day at 2 PM. The company wants to optimize costs while maintaining performance. Which solution is MOST cost-effective?

A.Use manual scaling by adjusting the desired capacity each day at 2 PM.
B.Purchase Reserved Instances for the entire fleet to reduce costs.
C.Use scheduled scaling to add instances before the spike and remove them after.
D.Use dynamic scaling policies based on CPU utilization.
AnswerC

Scheduled scaling is the correct approach for a predictable, recurring daily spike because it allows you to add capacity in advance and remove it afterward based on a schedule, without any manual intervention. You can configure the Auto Scaling group to increase the desired capacity at, for example, 1:30 PM to give new instances time to enter the InService state and start receiving traffic before the 2 PM spike, then decrease it at 4 PM to terminate unneeded instances. This directly balances performance and cost, and it integrates with CloudWatch metrics and ELB health checks to ensure the added instances are truly ready. It is the idiomatic AWS solution for traffic patterns that repeat on a known timetable.

Why this answer

Scheduled scaling is the correct answer because the traffic spikes are predictable and occur at a known time (2 PM daily). Scheduled scaling allows you to define a schedule (using cron expressions) to automatically increase the desired capacity of the Auto Scaling group before the spike and decrease it afterward, ensuring performance while minimizing costs during off-peak hours. This is more cost-effective than manual scaling because it eliminates the need for human intervention and ensures instances are only running when needed.

Exam trap

SOA-C02 often tests the difference between reactive and proactive scaling; candidates may choose dynamic scaling because it is more commonly discussed, but for predictable spikes, scheduled scaling is the most cost-effective.

How to eliminate wrong answers

Option A is wrong because manual scaling requires human intervention and is error-prone; it does not automatically adjust capacity and may lead to over-provisioning or under-provisioning. Option B is wrong because Reserved Instances provide a billing discount for steady-state usage but do not automatically scale capacity; purchasing RIs for the entire fleet would be cost-inefficient if the fleet size varies. Option D is wrong because dynamic scaling based on CPU utilization reacts to traffic changes but may not provision instances quickly enough for predictable spikes, and it may not be as cost-effective as scheduled scaling for known patterns.

1050
MCQhard

A company runs a critical web application on EC2 instances behind an Application Load Balancer (ALB) in an Auto Scaling group. The application experiences intermittent latency spikes. The SysOps administrator has enabled detailed CloudWatch metrics on the ALB and the EC2 instances. The administrator notices that during the latency spikes, the ALB's TargetResponseTime metric increases, but the EC2 instance's CPU utilization and memory usage remain normal. The administrator also observes that the number of concurrent connections to the ALB spikes during these periods. Which action should the administrator take to identify the root cause?

A.Analyze the ALB's ActiveConnectionCount and RequestCountPerTarget metrics to see if the load balancer is reaching its connection limit.
B.Check the RDS database's DatabaseConnections metric to see if the database is overwhelmed.
C.Enable VPC Flow Logs and analyze the traffic patterns for dropped packets.
D.Enable detailed monitoring on the EC2 instances to capture CPU credits for burstable instances.
AnswerA

The ALB's ActiveConnectionCount metric tracks the total number of concurrent TCP connections (including idle keep-alive connections) flowing through the load balancer, while RequestCountPerTarget measures the number of requests distributed to each backend instance. If the ALB approaches its per-node connection ceiling or the targets reach their connection backlog, new requests can queue in the ALB's network stack, producing latency even when CPU utilization is low. This is the correct first diagnostic step because the symptom is at the application entry point, and these metrics directly reveal whether the load balancer or targets are saturated with connections rather than compute capacity.

Why this answer

The ALB's ActiveConnectionCount and RequestCountPerTarget metrics directly indicate whether the load balancer is approaching its connection limit (default 50,000 for ALBs). During latency spikes, if concurrent connections spike but instance CPU/memory are normal, the bottleneck is likely at the load balancer level, not the instances. Analyzing these metrics helps determine if the ALB is queuing or dropping requests due to connection limits, causing increased TargetResponseTime.

Exam trap

The trap here is that candidates assume latency spikes always indicate backend instance issues (CPU/memory) and overlook the ALB's connection limits, which can cause increased TargetResponseTime even when instances are underutilized.

How to eliminate wrong answers

Option B is wrong because the question states CPU and memory on EC2 instances remain normal, and there is no mention of database-related latency or errors; checking RDS DatabaseConnections would only be relevant if the application was database-bound, which is not indicated. Option C is wrong because VPC Flow Logs capture network traffic metadata (source/destination IPs, ports, protocol, packets) but do not measure ALB connection limits or application-layer latency; dropped packets would indicate network issues, not ALB connection saturation. Option D is wrong because detailed monitoring on EC2 instances provides 1-minute metrics (vs. 5-minute default) but does not expose CPU credit exhaustion for burstable instances; the question already has normal CPU/memory, so this would not identify the root cause of ALB-level connection spikes.

Page 13

Page 14 of 16

Page 15