Courseiva

AWS Certified SysOps Administrator Associate SOA-C02 (SOA-C02) — Questions 1051–1125

1169 questions total · 16pages · All types, answers revealed

Page 14

Page 15 of 16

Page 16
1051
MCQeasy

A SysOps administrator needs to monitor the CPU utilization of an Amazon RDS DB instance and receive an alarm when CPU utilization exceeds 80% for 5 consecutive minutes. Which AWS service should be used to create this alarm?

A.AWS CloudTrail
B.Amazon CloudWatch
C.AWS Config
D.AWS Trusted Advisor
AnswerB

Amazon CloudWatch is the native monitoring service for RDS, automatically collecting the CPUUtilization metric at one-minute or five-minute granularity depending on the database instance class. You can create an alarm that evaluates the metric over consecutive periods and then publishes to an SNS topic or invokes an action when the threshold is breached. This makes CloudWatch the appropriate tool for monitoring CPU utilization and alerting.

Why this answer

Amazon CloudWatch is the native AWS monitoring service that can track RDS DB instance metrics, such as CPU utilization, and trigger alarms based on thresholds and time periods. In this scenario, you would create a CloudWatch alarm on the `CPUUtilization` metric for the specific DB instance, with a threshold of 80% and a period of 5 consecutive minutes (e.g., 5 datapoints of 1-minute periods).

Exam trap

The trap here is that candidates often confuse CloudTrail (for auditing API calls) with CloudWatch (for monitoring metrics and logs), leading them to select CloudTrail when the question explicitly asks about creating an alarm on a performance metric.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity and governance events, not real-time performance metrics like CPU utilization; it cannot create metric alarms. Option C is wrong because AWS Config evaluates resource configurations against rules and compliance standards, not operational metrics; it cannot monitor CPU utilization or trigger alarms based on threshold breaches. Option D is wrong because AWS Trusted Advisor provides best-practice recommendations and cost optimization checks, but it does not support custom metric alarms or real-time monitoring of CPU utilization.

1052
MCQmedium

A company runs a production Amazon RDS for PostgreSQL DB instance. The SysOps administrator needs to ensure that in the event of a database failure, there is automatic failover to a standby instance in another Availability Zone with minimal downtime. Which deployment configuration should the administrator enable?

A.Multi-AZ deployment
B.Read Replicas
C.Automated backups with point-in-time recovery
D.Amazon RDS Proxy
AnswerA

Multi-AZ maintains a synchronous standby replica in a different Availability Zone and performs automatic failover via DNS endpoint redirection when the primary fails. This satisfies the requirement for automatic cross-AZ failover with minimal downtime, unlike read replicas, which require manual promotion.

Why this answer

A Multi-AZ deployment for Amazon RDS automatically provisions and maintains a synchronous standby replica in a different Availability Zone. In the event of a database failure or an Availability Zone outage, Amazon RDS automatically fails over to the standby, typically within 60-120 seconds, without requiring manual intervention. This ensures high availability and minimal downtime for the production PostgreSQL DB instance.

Exam trap

The trap here is that candidates often confuse Read Replicas with Multi-AZ deployments, mistakenly believing that Read Replicas provide automatic failover, when in fact they only support manual promotion and are intended for read scaling, not high availability.

How to eliminate wrong answers

Option B is wrong because Read Replicas are designed for read traffic offloading and do not provide automatic failover; they require manual promotion to become the primary instance, which incurs significant downtime. Option C is wrong because automated backups with point-in-time recovery are for data durability and recovery from corruption or accidental deletion, not for automatic failover to a standby instance with minimal downtime. Option D is wrong because Amazon RDS Proxy is a connection pooling and management service that improves application scalability and resilience to database failures, but it does not replace the need for a standby instance or provide automatic failover itself.

1053
MCQhard

Refer to the exhibit. This bucket policy is attached to an S3 bucket that is used as an origin for a CloudFront distribution. Users are reporting Access Denied errors when accessing objects via the CloudFront URL. What is the MOST likely cause?

A.The condition is missing the aws:SourceVpce condition for VPC endpoints.
B.The bucket policy does not grant access to the CloudFront service principal.
C.The resource ARN is missing the bucket ARN for the bucket itself.
D.The condition restricts access to a specific IP range, but CloudFront requests come from its own IP addresses.
AnswerD

The bucket policy includes a condition that allows requests only from a specific IP address range. When CloudFront fetches the object from the S3 origin, the request originates from CloudFront's edge server IP addresses, not from the viewer's IP. These CloudFront addresses are not in the allowed range, so S3 denies the GET request. The correct fix is to either remove the IP restriction or replace it with an OAI/OAC and a condition that specifically identifies the CloudFront distribution.

Why this answer

The bucket policy condition restricts access to a specific IP range (likely the corporate CIDR), but CloudFront fetches objects from its own globally distributed edge IP addresses, not the end user's IP. CloudFront forwards the viewer's IP in the X-Forwarded-For header, but the actual TCP connection to S3 originates from CloudFront's IPs, so the IpAddress condition blocks all CloudFront requests, causing Access Denied.

Exam trap

SOA-C02 often tests whether candidates understand that CloudFront requests to S3 originate from CloudFront's IPs, not the viewer's — so IP-based bucket policy conditions break CloudFront origins.

How to eliminate wrong answers

Option A is wrong because aws:SourceVpce is only needed when restricting access to a VPC endpoint, not for CloudFront origins — CloudFront uses OAC, not VPC endpoints. Option B is wrong because CloudFront does not use a service principal in S3 bucket policies the way some other services do; access is granted via Origin Access Identity (OAI) or Origin Access Control (OAC), not a service principal. Option C is wrong because the resource ARN format shown (bucket ARN with /*) is correct for granting object access — the missing bucket ARN would only matter for bucket-level operations like ListBucket.

1054
MCQmedium

A company runs a critical web application on EC2 instances behind an Application Load Balancer in a single Availability Zone. To improve reliability, what is the MOST effective design change?

A.Place the RDS database in a Multi-AZ deployment.
B.Add a second Application Load Balancer in the same Availability Zone.
C.Increase the EC2 instance size to handle more traffic.
D.Launch EC2 instances across two or more Availability Zones.
AnswerD

Launching EC2 instances across two or more Availability Zones eliminates the AZ as a single point of failure for the compute tier. When used with an Application Load Balancer (or other load balancing) and ideally an Auto Scaling group, traffic can be distributed to healthy instances in the remaining AZs even if one entire AZ fails. This is the core architectural pattern for building a highly available web application on AWS.

Why this answer

The most effective design change to improve reliability is to launch EC2 instances across two or more Availability Zones. This eliminates the single point of failure at the Availability Zone level, ensuring that if one AZ experiences an outage, the Application Load Balancer can route traffic to healthy instances in another AZ. This directly addresses the core reliability principle of fault isolation and high availability.

Exam trap

The trap here is that candidates often focus on scaling or database redundancy (options A and C) instead of recognizing that the fundamental reliability gap is the single Availability Zone, which requires distributing compute resources across multiple AZs to achieve true high availability.

How to eliminate wrong answers

Option A is wrong because placing the RDS database in a Multi-AZ deployment improves database availability but does not address the single-AZ failure risk for the web application tier; the EC2 instances and ALB remain vulnerable to an AZ outage. Option B is wrong because adding a second Application Load Balancer in the same Availability Zone does not eliminate the single point of failure at the AZ level; both ALBs would be unavailable if that AZ fails. Option C is wrong because increasing the EC2 instance size only improves capacity within the same AZ, not fault tolerance; a larger instance still fails if the AZ goes down.

1055
MCQeasy

An EC2 instance runs a Java application. The operations team wants to monitor heap memory utilization in CloudWatch and set alarms when it exceeds 85 percent. EC2 does not natively publish memory metrics to CloudWatch. What is the simplest way to get this metric into CloudWatch?

A.Install the CloudWatch agent on the instance and configure it to collect mem_used_percent; publish JVM heap metrics from the application using PutMetricData
B.Enable detailed monitoring on the EC2 instance to increase metric resolution to 1-minute intervals
C.Configure a CloudWatch Logs metric filter on the application log stream to count lines containing 'OutOfMemoryError'
D.Use AWS Systems Manager Inventory to collect memory data and sync it to CloudWatch
AnswerA

The CloudWatch agent handles OS-level memory automatically once configured. For JVM heap, the application publishes a custom namespace metric via PutMetricData. Both appear in CloudWatch within minutes and can be graphed and alarmed like any native metric.

Why this answer

The CloudWatch agent can collect custom metrics like memory utilization from the EC2 instance, and the Java application can directly publish JVM heap metrics to CloudWatch using the PutMetricData API. This combination provides the simplest and most direct way to monitor heap memory utilization and set alarms at the 85% threshold, as EC2 does not natively expose memory metrics.

Exam trap

The trap here is that candidates often assume detailed monitoring or Systems Manager Inventory can provide memory metrics, but neither feature collects or publishes memory utilization data to CloudWatch.

How to eliminate wrong answers

Option B is wrong because enabling detailed monitoring increases the resolution of standard EC2 metrics (like CPU, network) to 1-minute intervals, but it does not add memory or JVM heap metrics, which are not published by EC2 at all. Option C is wrong because a CloudWatch Logs metric filter on 'OutOfMemoryError' only detects when the application has already crashed, not proactive heap utilization levels, and it cannot measure the percentage of heap memory used. Option D is wrong because AWS Systems Manager Inventory collects software inventory and configuration data, not real-time memory utilization metrics, and it does not sync data to CloudWatch as a metric for alarm purposes.

1056
MCQmedium

A company uses AWS CloudTrail to log all management events. The SysOps administrator needs to be notified when an IAM user creates a new access key. Which configuration is the MOST efficient?

A.Create a CloudWatch Logs metric filter on the CloudTrail log group for CreateAccessKey events and set an alarm.
B.Use AWS Trusted Advisor to check for excessive access keys.
C.Create a CloudWatch Events rule that matches the CreateAccessKey API call and triggers an SNS notification.
D.Use AWS Config to monitor the 'iam-user' resource type for changes to access keys.
AnswerC

CloudWatch Events (now Amazon EventBridge) directly intercepts the CloudTrail API event as soon as it occurs. By defining a rule with an event pattern that filters the 'CreateAccessKey' API call and linking it to an SNS topic, the architecture provides a real-time, serverless notification pipeline. This is the simplest and most efficient way to alert on security-sensitive IAM actions because it consumes the event stream directly without requiring log parsing or polling.

Why this answer

CloudWatch Events (now Amazon EventBridge) can directly match the CreateAccessKey API call from CloudTrail in real time and trigger an SNS notification. This is the most efficient solution as it requires no additional log analysis or polling, and it reacts immediately when the API call occurs.

Exam trap

The trap here is that candidates often default to CloudWatch Logs metric filters (Option A) because they are familiar with log-based monitoring, but they overlook the more efficient and real-time event-driven approach using CloudWatch Events/EventBridge for API call notifications.

How to eliminate wrong answers

Option A is wrong because it requires creating a metric filter on CloudTrail logs in CloudWatch Logs, which introduces latency from log ingestion and metric evaluation, and is less efficient than a direct event-driven approach. Option B is wrong because AWS Trusted Advisor checks for excessive access keys based on best practices (e.g., keys older than 90 days), not for the creation event itself, so it cannot provide real-time notification when a new key is created. Option D is wrong because AWS Config monitors configuration changes and can detect access key modifications, but it is designed for compliance and resource tracking, not for real-time event notification, and it would require additional setup to trigger a notification.

1057
Multi-Selecteasy

A company needs to comply with PCI DSS requirements for its AWS environment. Which TWO services should the SysOps administrator use to automate compliance checks and generate reports? (Choose TWO.)

Select 2 answers
A.Amazon CloudWatch
B.AWS Config
C.AWS CloudTrail
D.AWS Trusted Advisor
E.AWS Audit Manager
AnswersB, E

AWS Config continuously records the configuration state of supported AWS resources and evaluates those configurations against AWS-managed or custom rules. For PCI DSS, you can use the managed rule pack to check for requirements like encrypted storage, restricted security group rules, and MFA on root accounts, then view the overall compliance snapshot over time. It generates a compliance timeline and aligned findings, making it the core service for automated configuration compliance.

Why this answer

AWS Config (B) is correct because it continuously records resource configuration changes and evaluates them against managed or custom rules, such as the PCI DSS conformance pack, which automates compliance checks against AWS resources. AWS Audit Manager (E) is correct because it automates evidence collection and produces audit-ready reports mapped to frameworks like PCI DSS, which is exactly what the company needs for generating compliance reports. Amazon CloudWatch (A) is for metrics, logs, and alarms, not compliance evaluation or audit reporting.

AWS CloudTrail (C) records API activity for auditing but does not itself perform automated compliance checks or generate compliance reports. AWS Trusted Advisor (D) provides best-practice recommendations across cost, security, and limits, but it is not a PCI DSS compliance automation or reporting service.

Exam trap

SOA-C02 often tests the distinction between services that detect (Config, CloudTrail, GuardDuty) and services that report/assess (Audit Manager) — candidates who pick CloudTrail for 'compliance checks' miss that CloudTrail only logs API calls and does not evaluate compliance.

1058
MCQhard

A SysOps administrator is designing a disaster recovery plan for a critical application that runs on EC2 instances with data stored on EBS volumes. The application requires an RPO of 15 minutes and an RTO of 2 hours. The current solution uses EBS snapshots taken every 6 hours. The administrator needs to improve the backup strategy to meet the RPO. What is the most cost-effective way to achieve this?

A.Enable EBS Recycle Bin with a retention rule of 15 minutes.
B.Change the EBS volume type to io2 Block Express.
C.Increase the snapshot frequency to every 15 minutes.
D.Use EBS Multi-Attach to attach volumes to multiple instances for redundancy.
AnswerC

Increasing the snapshot frequency to every 15 minutes directly reduces the recovery point objective (RPO) to 15 minutes by creating a new snapshot at that interval. Even in the worst-case failure, you can restore from a snapshot that is at most 15 minutes old, so no more than 15 minutes of changes would be lost. This is the correct approach because it actively creates more frequent, consistent recovery points and is the standard technique to meet a tight RPO for EBS-backed EC2 instances.

Why this answer

Increasing the snapshot frequency to every 15 minutes directly reduces the recovery point objective (RPO) from 6 hours to 15 minutes, meeting the requirement without incurring additional infrastructure costs. EBS snapshots are incremental and cost-effective, as only changed blocks are stored after the initial snapshot, making frequent snapshots a practical approach for achieving a low RPO.

Exam trap

The trap here is that candidates may confuse the EBS Recycle Bin (which protects against accidental deletion) with a backup frequency solution, or think that changing volume types or using Multi-Attach can improve RPO, when neither addresses the need for more frequent recovery points.

How to eliminate wrong answers

Option A is wrong because the EBS Recycle Bin is designed to recover accidentally deleted snapshots or EBS volumes, not to create frequent recovery points; its retention rule controls how long deleted resources are kept, not the frequency of backups. Option B is wrong because changing the volume type to io2 Block Express improves performance and durability but does not affect snapshot frequency or RPO; it is a performance optimization, not a backup strategy. Option D is wrong because EBS Multi-Attach allows a single volume to be attached to multiple instances for shared storage, but it does not create backups or recovery points; it provides high availability within a single Availability Zone, not disaster recovery across regions or over time.

1059
MCQmedium

A company runs a stateful web application on a single Amazon EC2 instance with an Elastic IP address. The SysOps administrator needs to increase availability so that if the instance fails, a new instance can be launched quickly with the same configuration and the same IP address. The administrator also needs to ensure data is not lost. Which solution meets these requirements with the least operational overhead?

A.Use an Application Load Balancer with an Auto Scaling group and a launch configuration that includes the Elastic IP
B.Create an AMI from the instance, store data on an Amazon EFS file system, and use an Auto Scaling group with a lifecycle hook to associate the Elastic IP
C.Create a CloudFormation template that launches a new instance and associates the Elastic IP
D.Place the instance in an Auto Scaling group with a minimum of 1 and a maximum of 1, and set the health check to replace unhealthy instances
AnswerB

The AMI provides a pre-configured launch template. EFS provides durable, shared storage for application data. The Auto Scaling group automatically launches a new instance if the current one fails, and the lifecycle hook script associates the Elastic IP to the new instance, ensuring continuity with the same IP.

Why this answer

It separates the stateful data (stored on Amazon EFS) from the compute instance, ensuring data persistence even if the instance fails. Creating an AMI from the instance captures the configuration, and an Auto Scaling group with a lifecycle hook can associate the Elastic IP to the new instance automatically, providing a quick failover with minimal operational overhead.

Exam trap

The trap here is that candidates often assume an Auto Scaling group alone can handle Elastic IP association, but without a lifecycle hook or custom script, the new instance will not automatically receive the Elastic IP, leading to IP address changes and potential downtime.

How to eliminate wrong answers

Option A is wrong because an Application Load Balancer (ALB) does not support Elastic IP addresses; ALBs use DNS names and are designed for distributing traffic, not for preserving a static IP for a stateful application. Option C is wrong because a CloudFormation template requires manual or automated invocation to launch a new instance and associate the Elastic IP, which introduces additional operational overhead and does not automatically handle instance failure detection and replacement. Option D is wrong because placing the instance in an Auto Scaling group with a minimum and maximum of 1 does not automatically launch a new instance with the same configuration or data; it only replaces the instance if it becomes unhealthy, but without a lifecycle hook to associate the Elastic IP or a mechanism to preserve stateful data, the solution fails to meet the requirements.

1060
Multi-Selectmedium

A company stores critical application logs in an Amazon S3 bucket. The SysOps administrator must implement a backup strategy that protects against accidental deletion of objects and allows recovery of previous versions. The solution must be cost-effective and require minimal operational overhead. (Choose two.)

Select 2 answers
A.Enable S3 Cross-Region Replication to a bucket in another region.
B.Enable S3 Object Lock in governance mode with a retention period of 30 days.
C.Enable S3 Versioning on the bucket.
D.Configure an S3 Lifecycle policy to expire noncurrent versions after 90 days.
E.Configure an S3 Lifecycle policy to transition objects to S3 Glacier Deep Archive after 30 days.
AnswersC, D

S3 Versioning preserves every version of an object, so if an object is overwritten or deleted, previous versions remain accessible. This directly addresses accidental deletion and enables recovery of prior versions without needing to copy data elsewhere. It is a native feature that requires no additional infrastructure and incurs storage costs only for the retained versions, making it cost-effective for this requirement.

Why this answer

Enabling S3 Versioning preserves all object versions, allowing recovery from accidental deletion or overwrite. Pairing it with a lifecycle policy that expires noncurrent versions after a defined period keeps storage costs under control by automatically removing older versions that are no longer needed. Together, these native features provide a cost-effective, low-maintenance backup strategy for the log bucket.

Exam trap

The trap here is assuming that replication or Object Lock alone provides version recovery, when versioning is the core feature that preserves previous versions of objects.

1061
MCQeasy

An organization wants to centrally manage access to multiple AWS accounts in an AWS Organizations setup. Which AWS service should the SysOps administrator use to define and enforce fine-grained permissions across accounts?

A.AWS Config rules
B.Service control policies (SCPs)
C.IAM roles with cross-account trust policies
D.AWS Single Sign-On (SSO)
AnswerC

IAM roles are the correct mechanism because a role in a target account can attach a permissions policy that precisely defines allowable actions and resources, and a trust policy in the same role lists which principals in a central account may assume it. When a user in the central account calls sts:AssumeRole, AWS returns temporary, scoped credentials that carry exactly the role's permissions, no more and no less. This gives fine-grained control while centralizing the decision about who gets to assume which role.

Why this answer

IAM roles with cross-account trust policies allow a SysOps administrator to define fine-grained permissions centrally in a single AWS account (the management or security account) and then grant access to users or services in other accounts by assuming the role. This approach uses AWS Security Token Service (STS) to issue temporary credentials, enabling precise control over actions and resources across accounts without duplicating IAM users or policies.

Exam trap

The trap here is that candidates often confuse Service Control Policies (SCPs) with fine-grained permission enforcement, but SCPs only set guardrails and cannot grant cross-account access or define granular user-level permissions, which is the core requirement of this question.

How to eliminate wrong answers

Option A is wrong because AWS Config rules evaluate resource configurations for compliance against desired policies (e.g., checking if S3 buckets are public) but do not define or enforce permissions for user or role actions across accounts; they are auditing tools, not access control mechanisms. Option B is wrong because Service Control Policies (SCPs) set maximum permission boundaries for all IAM entities in an AWS Organizations member account, but they cannot grant or deny specific actions at the user or role level—they only filter what is allowed by IAM policies, and they do not provide cross-account access delegation. Option D is wrong because AWS Single Sign-On (SSO) centralizes user authentication and assigns permissions via IAM roles or permission sets, but it does not directly define fine-grained permissions across accounts; it relies on IAM roles with trust policies to enable access, making it a management layer rather than the core service for enforcing permissions.

1062
Multi-Selectmedium

A company has an S3 bucket that stores sensitive data. The security team requires that all access to the bucket be encrypted in transit. Which TWO actions should be taken to enforce this requirement? (Choose two.)

Select 2 answers
A.Enable default encryption (SSE-S3) on the bucket
B.Enable S3 Transfer Acceleration
C.Enable AWS CloudTrail to log all S3 API calls and set up a CloudWatch alarm for any HTTP access
D.Create an S3 bucket policy that denies s3:GetObject and s3:PutObject if the aws:SecureTransport condition is false
E.Use S3 VPC endpoints
AnswersC, D

CloudTrail logs every S3 API call, and the event record includes the aws:SecureTransport flag, which distinguishes HTTPS from HTTP. A CloudWatch alarm on that flag lets the company immediately detect and respond to any plaintext request. As a detective control, it does not block the request at the time, but it satisfies the requirement by enabling continuous monitoring for HTTPS-only access.

Why this answer

Enabling AWS CloudTrail to log all S3 API calls and setting up a CloudWatch alarm for any HTTP access allows the security team to detect and alert on any access that is not encrypted in transit (i.e., HTTP instead of HTTPS). This provides monitoring and incident response capability to enforce the encryption-in-transit requirement.

Exam trap

The trap here is confusing encryption at rest (SSE-S3) with encryption in transit (HTTPS/SSL), leading candidates to select default encryption instead of the bucket policy condition or monitoring approach.

1063
MCQeasy

A SysOps administrator needs to allow a Lambda function to access a DynamoDB table in the same AWS account. Which configuration is required?

A.Create a VPC endpoint for DynamoDB and attach it to the Lambda function.
B.Configure a network ACL to allow traffic from Lambda to DynamoDB.
C.Add the Lambda function as a principal in the DynamoDB table's resource-based policy.
D.Assign an IAM role to the Lambda function with DynamoDB permissions.
AnswerD

The correct and only supported mechanism is to attach an IAM execution role to the Lambda function. When the function runs, the Lambda service assumes this role using the service principal `lambda.amazonaws.com`, and the temporary credentials obtained from STS are used to sign all DynamoDB API requests. The role's managed or inline policies must explicitly allow the desired actions (e.g., `GetItem`, `PutItem`) on the target table, and DynamoDB evaluates these permissions for each request, making the role the sole source of access control.

Why this answer

Lambda functions assume an IAM role (the execution role) that grants permissions to AWS services. To allow a Lambda function to access a DynamoDB table in the same account, you attach an IAM policy to that execution role granting the necessary DynamoDB actions (e.g., GetItem, PutItem) on the table's ARN. This is the standard, required configuration for same-account access.

Exam trap

The trap is confusing network-level connectivity (VPC endpoints, NACLs) with authorization (IAM roles), leading candidates to pick a networking answer when the question is about granting service permissions.

How to eliminate wrong answers

Option A is wrong because a VPC endpoint for DynamoDB is only needed when the Lambda function runs inside a VPC and you want private connectivity to DynamoDB; it is not required for IAM-based access and does not grant permissions. Option B is wrong because network ACLs are stateless subnet-level firewalls that filter IP traffic; DynamoDB access is authorized via IAM, not network ACLs, and Lambda outside a VPC uses AWS-managed networking. Option C is wrong because DynamoDB resource-based policies are used for cross-account access or specific scenarios; for same-account Lambda access, the execution role's identity-based policy is the correct and sufficient mechanism.

1064
MCQmedium

A company uses AWS CodePipeline to deploy a web application. The pipeline has a source stage (Amazon S3) and a deploy stage (AWS Elastic Beanstalk). The SysOps administrator needs to add a manual approval step before the deployment proceeds to the production environment. Which action should the administrator take?

A.Add an approval stage in the pipeline using the Amazon SNS topic as a notification method.
B.Add a manual approval action in the pipeline using the AWS CodePipeline approval action type.
C.Use an AWS CloudFormation change set to require manual approval.
D.Create a separate pipeline for production and trigger it manually.
AnswerB

CodePipeline has a native manual approval action with the category "Approval" that can be inserted into any stage. When configured, this action pauses the pipeline and waits for an authorized user to approve or reject the deployment via the console, CLI, or PutApprovalResult API call. You can optionally attach an SNS topic to send notifications to approvers, but the verification step is enforced by the Approval action itself, making this the correct way to implement a manual gate within the existing pipeline.

Why this answer

AWS CodePipeline natively supports a manual approval action type that can be added as a stage in the pipeline. This action pauses the pipeline execution until an authorized user manually approves or rejects the deployment, allowing the SysOps administrator to gate the deployment to the production environment without external services.

Exam trap

The trap here is that candidates may confuse notification mechanisms (like SNS) with the actual approval action, or assume that external tools like CloudFormation change sets can serve as manual approval gates within a pipeline.

How to eliminate wrong answers

Option A is wrong because while Amazon SNS can be used to notify approvers, the approval action itself must be the CodePipeline approval action type; adding an SNS topic alone does not create a manual approval gate. Option C is wrong because AWS CloudFormation change sets are used to review infrastructure changes before execution, not to add manual approval steps within a CodePipeline deployment workflow. Option D is wrong because creating a separate pipeline for production and triggering it manually bypasses the automated pipeline integration and does not add a manual approval step within the existing pipeline.

1065
MCQmedium

An application running on Amazon ECS with Fargate launch type is experiencing intermittent failures. The tasks are spread across multiple Availability Zones. The SysOps administrator notices that failures occur only when an entire AZ becomes unavailable. What should the administrator do to improve the reliability of the application?

A.Use multiple subnets in the same AZ.
B.Use a cluster placement group.
C.Attach an Amazon EFS filesystem to all tasks.
D.Increase the desired task count to ensure sufficient capacity across AZs.
AnswerD

Increasing the desired task count for an ECS service ensures that more Fargate tasks are running, and because the service scheduler distributes tasks across the AZs represented in your VPC subnets, this gives you capacity to absorb an AZ failure. With a higher replica count, if one AZ fails, the remaining tasks in other AZs can continue servicing traffic, and the service can eventually replace tasks in healthy AZs. This is the correct way to provide compute redundancy for a Fargate-based application.

Why this answer

Increasing the desired task count ensures that ECS Fargate tasks are distributed across multiple Availability Zones, providing sufficient capacity to absorb the loss of an entire AZ. When one AZ becomes unavailable, the remaining tasks in other AZs continue to serve traffic, improving application reliability. This approach leverages the multi-AZ architecture already in place by ensuring enough tasks are running to handle the load even after an AZ failure.

Exam trap

The trap here is that candidates may think adding storage (EFS) or using placement groups (which are EC2-specific) can solve AZ-level failures, but the core issue is ensuring enough task capacity across multiple AZs to survive the loss of one.

How to eliminate wrong answers

Option A is wrong because using multiple subnets in the same AZ does not provide AZ-level redundancy; all tasks would still be in a single AZ, so an entire AZ failure would take all tasks down. Option B is wrong because a cluster placement group is used for EC2 instances to achieve low-latency network performance by placing instances close together, but it is not supported with Fargate launch type and does not improve AZ-level fault tolerance. Option C is wrong because attaching an Amazon EFS filesystem provides shared persistent storage across tasks but does not protect against AZ failures; if all tasks are in a single AZ that fails, the EFS mount point becomes unreachable, and the application still fails.

1066
Multi-Selecthard

Which TWO actions should a SysOps administrator take to automate the deployment of a multi-tier application with AWS CloudFormation? (Choose two.)

Select 2 answers
A.Hardcode CIDR blocks and instance types to avoid parameter input
B.Use nested stacks to separate concerns such as network, app, and database
C.Use AWS::Include to reuse snippets instead of parameters
D.Use cross-stack references to pass outputs between stacks
E.Define all resources in a single template to simplify management
AnswersB, D

Nested stacks are the correct way to separate concerns because they allow you to break a large, monolithic infrastructure into smaller, reusable template components—for example, one nested stack for the VPC/network layer, another for the application layer, and another for the database layer. Each nested stack is treated as a CloudFormation resource within the root stack, so you can deploy, update, and roll back the entire architecture from a single root stack while still isolating failures and reusing templates across multiple environments. This modularity improves manageability, makes the stack more readable, and aligns with best practices for infrastructure as code.

Why this answer

Option B is correct because nested stacks let you decompose a multi-tier application into reusable, independently managed templates (for example, a network stack, an application stack, and a database stack), which CloudFormation deploys as a parent stack with AWS::CloudFormation::Stack resources and promotes separation of concerns and reuse. Option D is correct because cross-stack references via Export in an Outputs section and Fn::ImportValue allow one stack to consume another stack's outputs (such as a VPC ID or subnet IDs), enabling modular, loosely coupled templates that pass values between stacks without hardcoding. Option A is wrong because hardcoding CIDR blocks and instance types reduces reusability and portability; parameters (with defaults and constraints) are the proper mechanism for environment-specific inputs.

Option C is wrong because AWS::Include is a transform for inserting template snippets from S3 at deployment time, not a substitute for parameters, and it does not by itself provide the modular stack separation needed here. Option E is wrong because defining every resource in a single template creates a monolithic, hard-to-maintain stack and prevents the independent lifecycle management that nested stacks and cross-stack references provide.

Exam trap

SOA-C02 often tests the confusion between AWS::Include (snippet reuse) and nested stacks (full stack modularity), leading candidates to pick AWS::Include when separation of concerns is required.

1067
MCQhard

A company uses AWS Organizations and has multiple accounts. The security team requires that all Amazon S3 buckets across all accounts must be encrypted at rest with AWS KMS (SSE-KMS). The SysOps administrator needs to automatically detect non-compliant buckets and remediate them by enabling SSE-KMS. The solution must work across all existing and future accounts. Which AWS service should be used?

A.AWS Config with a managed rule and an automatic remediation action using AWS Systems Manager Automation.
B.AWS CloudTrail with a metric filter and Amazon CloudWatch alarm to trigger a Lambda function.
C.AWS Trusted Advisor to check S3 bucket encryption and send notifications.
D.Amazon Macie to discover sensitive data and then manually encrypt buckets.
AnswerA

AWS Config's managed rule s3-bucket-server-side-encryption-enabled continuously evaluates whether every S3 bucket has default encryption configured. When a bucket is found non-compliant, Config's automatic remediation feature can invoke an AWS Systems Manager Automation document (e.g., AWS-EnableS3BucketEncryption) to apply SSE-KMS to that bucket. Because Config is state-based, it detects both pre-existing non-compliant buckets and buckets that drift after creation. With AWS Organizations, you can deploy the rule and remediation across all accounts using CloudFormation StackSets, and aggregators centralize compliance visibility.

Why this answer

AWS Config with the managed rule 's3-bucket-server-side-encryption-enabled' can evaluate all S3 buckets across accounts in an AWS Organization. When a non-compliant bucket is detected, an automatic remediation action using an AWS Systems Manager Automation document (e.g., 'AWS-EnableS3BucketEncryption') can enable SSE-KMS without manual intervention. This solution scales to existing and future accounts because AWS Config can be set up as an aggregator across the organization, and remediation actions apply automatically as new accounts are added.

Exam trap

The trap here is that candidates often confuse detection-only services (like Trusted Advisor or CloudTrail) with services that can both detect and automatically remediate, or they mistakenly think Macie handles encryption compliance when it actually focuses on data classification.

How to eliminate wrong answers

Option B is wrong because AWS CloudTrail with a metric filter and CloudWatch alarm only detects API calls (e.g., PutBucketEncryption) after they occur; it cannot proactively detect non-compliant buckets or automatically remediate them without a custom Lambda function, and it does not provide continuous compliance evaluation across all accounts. Option C is wrong because AWS Trusted Advisor checks S3 bucket encryption only for the root account or linked accounts in a support plan, but it does not support automatic remediation—it only sends notifications, and it cannot enforce encryption across all accounts in an organization. Option D is wrong because Amazon Macie is designed to discover sensitive data (e.g., PII) in S3 buckets, not to check or enforce encryption settings; it requires manual intervention to encrypt buckets and does not provide automated detection or remediation of non-compliant encryption.

1068
MCQeasy

A company is using Amazon CloudFront to distribute content globally. The company wants to restrict access to content so that only users from specific countries can access it. Which CloudFront feature should be used?

A.AWS WAF
B.Signed URLs
C.Geo restriction
D.Origin Access Identity (OAI)
AnswerC

CloudFront geo restriction evaluates the viewer's country against an allowlist or blocklist at edge locations, denying requests before they reach the origin. This directly satisfies the requirement to limit content access to users from specific countries without modifying application code.

Why this answer

CloudFront's geo restriction feature (also known as geo-blocking) allows you to allow or block access to your content based on the geographic location of the viewer's IP address. This is the correct choice because the requirement is specifically to restrict access by country, which is exactly what geo restriction does by using a country-level allowlist or blocklist.

Exam trap

The trap here is that candidates often confuse geo restriction with AWS WAF's geo-match conditions, but the question explicitly asks for a CloudFront feature, and geo restriction is the native, simpler option that does not require WAF integration.

How to eliminate wrong answers

Option A is wrong because AWS WAF is a web application firewall that filters traffic based on rules like SQL injection or IP addresses, but it does not natively provide country-level access control without additional configuration (though it can be integrated with CloudFront for geo-matching via IP sets, the question asks for the CloudFront feature itself). Option B is wrong because Signed URLs provide temporary access to individual files by requiring a cryptographic signature, but they do not restrict access based on the viewer's geographic location. Option D is wrong because Origin Access Identity (OAI) is used to restrict access to an S3 origin so that only CloudFront can fetch content, but it does not control which end users can access the content based on their country.

1069
MCQhard

A company manages multiple AWS accounts using AWS Organizations. The security team wants to restrict the use of Amazon EC2 instance types to only those that are approved for production workloads (e.g., m5.large, m5.xlarge). The policy should be applied to all member accounts in the organization, and it should prevent any non-approved instance type from being launched. The SysOps administrator should implement this with minimal operational overhead. Which solution should be used?

A.Create an IAM policy in each member account that denies ec2:RunInstances unless the instance type is in the approved list.
B.Create an AWS Organizations Service Control Policy (SCP) that denies ec2:RunInstances if the instance type is not in the approved list.
C.Use AWS Config with the managed rule 'ec2-instance-type-check' and an automatic remediation action that terminates non-compliant instances.
D.Use Amazon EventBridge to detect RunInstances API calls and invoke a Lambda function that terminates unapproved instances.
AnswerB

An SCP attached to the organization root, OUs, or individual accounts acts as a preventive guardrail: the deny effect applies to every principal, including the root user. Using a condition such as StringNotEquals on ec2:InstanceType with the approved list, the policy rejects any RunInstances call that uses a non-approved type before the API call can succeed. Because SCPs are inherited and cannot be bypassed by IAM permissions, this gives consistent, low-overhead enforcement across all current and future accounts.

Why this answer

AWS Organizations Service Control Policies (SCPs) can centrally enforce restrictions across all member accounts without requiring per-account configuration. By creating an SCP that denies ec2:RunInstances when the instance type is not in the approved list, the security team can prevent non-approved EC2 instance types from being launched with minimal operational overhead, as SCPs are applied at the organization, OU, or account level and do not require managing IAM policies in each account.

Exam trap

The trap here is that candidates often confuse SCPs with IAM policies, thinking that SCPs grant permissions, but SCPs only act as a guardrail to restrict permissions, and they must be combined with appropriate IAM policies to allow actions; additionally, candidates may choose reactive solutions like AWS Config or EventBridge because they are familiar, but the question explicitly asks for a preventive control with minimal overhead.

How to eliminate wrong answers

Option A is wrong because creating an IAM policy in each member account introduces significant operational overhead, as it requires manual or automated deployment to every account, and IAM policies can be overridden by account administrators with full permissions, whereas SCPs provide a guardrail that cannot be bypassed by account-level IAM. Option C is wrong because AWS Config with the 'ec2-instance-type-check' rule is a detective control that only identifies non-compliant instances after launch, and automatic remediation via termination is reactive, not preventive, and can lead to resource churn and potential data loss; it also requires additional setup for remediation actions. Option D is wrong because using EventBridge to detect RunInstances API calls and invoking a Lambda function to terminate unapproved instances is a reactive, event-driven approach that still allows the instance to be launched momentarily, incurs additional cost and complexity, and does not prevent the API call from succeeding in the first place.

1070
Multi-Selectmedium

A SysOps administrator is setting up centralized logging for multiple AWS accounts using CloudWatch Logs. Which TWO actions should the administrator take to ensure that logs from all accounts are aggregated in a single account?

Select 2 answers
A.In the central account, create an IAM role that trusts the source accounts and allows PutLogEvents.
B.In the central account, create a CloudWatch Logs destination and attach a resource policy that grants the source accounts permission to write logs.
C.In each source account, configure a subscription filter on the log groups to send log events to the central account's CloudWatch Logs destination.
D.In the central account, create a log group with the same name as the source accounts' log groups.
E.In each source account, create a Kinesis Data Firehose delivery stream that sends logs to the central account's S3 bucket.
AnswersB, C

This is the correct approach because a CloudWatch Logs destination is a logical target that can receive log events from other accounts. The central account must attach a resource-based policy to the destination, explicitly listing the source account IDs and allowing them to call PutLogEvents. This policy grants the necessary write access without requiring cross-account IAM roles or complex key management, enabling centralized aggregation of logs from multiple source accounts.

Why this answer

A CloudWatch Logs destination in the central account, combined with a resource policy that grants the source accounts permission to write logs, is the standard mechanism for cross-account log aggregation. The destination acts as a target for subscription filters, and the resource policy explicitly allows the source accounts to call the PutLogEvents API against that destination. This setup ensures that log events from source accounts are delivered to the central account without requiring IAM roles or additional infrastructure.

Exam trap

The trap here is that candidates often confuse IAM cross-account roles with CloudWatch Logs destinations, assuming that a role with PutLogEvents permissions is sufficient, when in fact CloudWatch Logs requires a destination resource policy for cross-account delivery.

1071
MCQmedium

Refer to the exhibit. A SysOps administrator ran the describe-stack-events command for a CloudFormation stack named 'my-stack'. The stack creation failed with 'Resource creation cancelled'. What is the most likely reason?

A.The stack creation was manually cancelled by the administrator.
B.The IAM role for the stack does not have sufficient permissions.
C.The nested stack creation failed due to an invalid template.
D.The nested stack creation timed out and was cancelled.
AnswerD

Nested stacks can specify a TimeoutInMinutes property, and if the nested stack does not complete within that window, CloudFormation cancels the in-progress creation. When this happens, the event stream for the nested stack resource in the parent stack shows a 'Resource creation cancelled' status, which then triggers a rollback of the parent stack. This exactly matches the exhibited event pattern, making it the correct interpretation.

Why this answer

When a CloudFormation stack creation fails with 'Resource creation cancelled', it typically indicates that a nested stack creation was cancelled due to a timeout. CloudFormation sets a default timeout of 60 minutes for stack creation; if a nested stack does not complete within that period, the parent stack cancels the nested stack creation and reports this error. This is distinct from manual cancellation, which would show a different status.

Exam trap

The trap here is that candidates confuse 'Resource creation cancelled' with manual cancellation or permission errors, but the specific phrasing indicates a timeout scenario, which is a common pitfall in nested stack troubleshooting.

How to eliminate wrong answers

Option A is wrong because manual cancellation by the administrator would result in a 'DELETE_IN_PROGRESS' or 'ROLLBACK_IN_PROGRESS' status, not 'Resource creation cancelled'. Option B is wrong because insufficient IAM permissions would cause an 'AccessDenied' or 'InsufficientCapabilities' error, not a 'Resource creation cancelled' message. Option C is wrong because an invalid template in a nested stack would produce a 'TemplateValidationError' or 'ValidationError' during creation, not a timeout-based cancellation.

1072
MCQeasy

A company runs a batch processing job every Saturday for 3 hours. The job can be interrupted and resumed at any point. The SysOps administrator wants to minimize compute costs for this workload. Which EC2 purchasing option should the administrator use?

A.On-Demand Instances
B.Reserved Instances
C.Spot Instances
D.Dedicated Hosts
AnswerC

Spot Instances offer access to spare EC2 capacity at discounts of up to 90% off On-Demand prices, which makes them the most cost-effective choice for a batch job that runs for only 3 hours every Saturday. The key trade-off is that Spot capacity can be reclaimed with a 2-minute warning, so the workload must be fault-tolerant—for example, using checkpoints or saving results to S3 and restarting on new Spot capacity. Because the job is batch-oriented and resumable, interruption is not a blocker; you can also use a Spot Fleet with multiple instance types and Availability Zones to improve the odds of maintaining capacity.

Why this answer

Spot Instances are ideal for fault-tolerant, interruptible workloads like batch processing that can be resumed. They offer significant cost savings (up to 90% compared to On-Demand) because they use spare EC2 capacity, which can be reclaimed by AWS with a 2-minute interruption notice. Since the job runs only 3 hours weekly and can be interrupted and resumed, Spot Instances minimize compute costs effectively.

Exam trap

The trap here is that candidates may choose Reserved Instances because the workload runs weekly, but they overlook the fact that Reserved Instances require a long-term commitment and are not cost-effective for a short, interruptible batch job, whereas Spot Instances are specifically designed for such fault-tolerant, transient workloads.

How to eliminate wrong answers

Option A is wrong because On-Demand Instances provide no discount and are the most expensive option for a predictable, recurring 3-hour weekly workload. Option B is wrong because Reserved Instances require a 1- or 3-year commitment and are cost-effective only for steady-state, always-on usage, not for a short weekly batch job. Option D is wrong because Dedicated Hosts are a physical server dedicated to your use, incurring high costs per host regardless of usage, and are intended for licensing or compliance needs, not for minimizing compute costs on an interruptible batch job.

1073
MCQhard

A SysOps administrator manages a fleet of EC2 instances that run a batch processing job. The job runs every hour and takes about 45 minutes to complete. The administrator wants to be notified if any job takes longer than 1 hour. Currently, the administrator uses CloudWatch Logs to capture job start and end times from application logs. The job writes a log message at start with 'JOB_START' and at end with 'JOB_END'. The administrator wants to create a metric filter that counts jobs that exceed 1 hour. However, the administrator is unsure how to achieve this with CloudWatch Logs. What should the administrator do?

A.Use CloudWatch Logs Insights to run a query every hour and check the duration.
B.Use CloudWatch Events to capture the log events and trigger a Lambda function to compute duration.
C.Create a metric filter that extracts the timestamp of JOB_START and JOB_END and computes the duration in a custom metric.
D.Create a Lambda function that is triggered by S3 to process the logs and publish a custom metric.
AnswerB

CloudWatch Events (EventBridge) can deliver CloudWatch Log events to a Lambda function in near real-time via a subscription filter, enabling event-driven processing. The Lambda function can parse the JOB_START and JOB_END entries, correlate them by job ID, calculate the duration, and publish a custom metric or trigger an alarm. This serverless architecture avoids polling and reacts immediately to each logged job, making it the recommended pattern.

Why this answer

CloudWatch Events (now part of Amazon EventBridge) can capture log events in real-time and trigger a Lambda function. The Lambda function can then compute job duration by correlating JOB_START and JOB_END events (e.g., using a DynamoDB table to store start times) and publish a custom metric or trigger an alarm if duration exceeds 1 hour. This approach handles the per-job correlation that metric filters cannot achieve.

Exam trap

Candidates often think metric filters can compute duration by extracting timestamps from JOB_START and JOB_END, but metric filters operate on individual log events and cannot correlate two events for the same job. The correct solution uses CloudWatch Events with Lambda for stateful computation.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs Insights is a query-based analysis tool for ad-hoc or scheduled queries, but it cannot directly trigger alarms or continuously monitor for durations exceeding 1 hour without custom scripting and additional services. Option B is wrong because CloudWatch Events (now Amazon EventBridge) can capture log events and trigger a Lambda function, but this approach adds unnecessary complexity and cost compared to a native metric filter, and it requires custom code to compute duration and publish metrics. Option D is wrong because S3 is not involved in the described workflow; the logs are in CloudWatch Logs, not S3, and using S3 triggers would require exporting logs to S3 first, adding latency and complexity.

1074
MCQhard

A company runs a multi-tier application that uses an Amazon RDS for PostgreSQL database. The SysOps administrator needs to monitor the database for performance anomalies, such as sudden spikes in connections or query latencies. The administrator wants to receive alerts when metrics deviate from their expected baseline. The solution must automatically adjust to changes in normal behavior over time, such as seasonal patterns. Which AWS service or feature should the administrator use?

A.Configure Amazon CloudWatch Anomaly Detection on the relevant RDS metrics (e.g., DatabaseConnections, ReadLatency, WriteLatency) and set an alarm to notify when the metric breaches the anomaly band.
B.Use Amazon RDS Performance Insights to analyze database load and set CloudWatch alarms on the DBLoad metric with static thresholds.
C.Enable Amazon CloudWatch Metrics Explorer to create a dashboard that visualizes the metrics and manually review for anomalies.
D.Use AWS X-Ray to trace database queries and set alarms on trace segment durations.
AnswerA

CloudWatch Anomaly Detection uses machine learning to automatically model the expected patterns of RDS metrics such as DatabaseConnections, ReadLatency, and WriteLatency, including daily and weekly seasonal trends. It builds a dynamic baseline band around the metric's normal behavior and can trigger an alarm when data points breach that band, with no need to manually define static thresholds. The alarm action can notify via SNS, providing the automated, adaptive monitoring required to detect unusual RDS behavior without operator intervention.

Why this answer

Amazon CloudWatch Anomaly Detection uses machine learning to continuously analyze metric patterns and establish a dynamic baseline that adapts to seasonal trends and gradual changes in normal behavior. By applying anomaly detection to RDS metrics like DatabaseConnections, ReadLatency, and WriteLatency, the administrator can set an alarm that triggers when a metric deviates outside the calculated anomaly band, automatically adjusting to evolving traffic patterns without manual threshold updates.

Exam trap

The trap here is that candidates often confuse Performance Insights (a diagnostic tool for analyzing database load) with a monitoring and alerting solution, overlooking that it does not provide adaptive baselines or automatic anomaly detection.

How to eliminate wrong answers

Option B is wrong because RDS Performance Insights provides database load analysis and the DBLoad metric, but it relies on static thresholds for CloudWatch alarms, which cannot automatically adapt to changing baselines or seasonal patterns. Option C is wrong because CloudWatch Metrics Explorer is a visualization and query tool for exploring metrics, not a monitoring or alerting feature; it requires manual review and does not provide automated anomaly detection or adaptive baselines. Option D is wrong because AWS X-Ray is designed for tracing and analyzing application requests end-to-end, not for monitoring database-level metrics like connection counts or query latencies, and it cannot set alarms on RDS performance metrics.

1075
MCQhard

A company uses AWS Organizations to manage multiple AWS accounts. The security team wants to restrict access to a specific AWS service (Amazon EC2) in all accounts except for the 'production' account. The SysOps administrator needs to implement this restriction centrally. Which approach should the administrator use?

A.Create an IAM policy that denies Amazon EC2 actions and attach it to all users and roles in non-production accounts.
B.Attach a service control policy (SCP) to the organization root or to the OUs of non-production accounts that denies access to Amazon EC2.
C.Use AWS Config to create a rule that detects EC2 usage in non-production accounts and automatically terminates instances.
D.Create a resource-based policy on each EC2 instance that denies access from non-production accounts.
AnswerB

SCPs are a centralized way to set permission boundaries for all accounts in the organization. By denying EC2 actions via SCP on non-production OUs, the restriction is enforced even for the root user of those accounts, and it applies to all IAM principals.

Why this answer

Service control policies (SCPs) are the correct mechanism for centrally restricting permissions across accounts in AWS Organizations. By attaching an SCP that denies EC2 actions to the organization root or to the OUs containing non-production accounts, the security team can enforce this restriction at the account level, overriding any IAM policies within those accounts. This approach ensures that even if a user or role in a non-production account has an IAM policy granting EC2 access, the SCP will block it.

Exam trap

The trap here is that candidates often confuse IAM policies (which are identity-based and account-specific) with SCPs (which are account-wide and centrally managed), leading them to choose Option A because they think attaching a deny policy to users is sufficient, but they overlook that SCPs provide the only centralized, preventive control across multiple accounts in AWS Organizations.

How to eliminate wrong answers

Option A is wrong because IAM policies attached to users and roles are not centrally managed across multiple accounts; they must be applied individually in each account, which is not a centralized solution and can be bypassed by local administrators. Option C is wrong because AWS Config is a detective service that can detect and react to EC2 usage (e.g., via auto-remediation), but it does not prevent the initial creation or use of EC2 resources; it only responds after the fact, which is not a preventive restriction. Option D is wrong because resource-based policies on EC2 instances control access to the instance itself (e.g., who can start/stop it), not the ability to launch or manage EC2 services in an account; they are also not centrally managed across accounts.

1076
Multi-Selecteasy

A company uses Amazon S3 to store backup data. The SysOps administrator needs to ensure that the data is encrypted at rest and that access is limited to only authorized users. Which TWO actions should be taken? (Choose TWO.)

Select 2 answers
A.Enable default encryption on the S3 bucket using SSE-S3 or AWS KMS.
B.Block all public access to the S3 bucket.
C.Create a bucket policy that allows only specific IAM roles or users.
D.Enable S3 Versioning on the bucket.
E.Enable S3 Transfer Acceleration.
AnswersA, C

Enabling default encryption on the S3 bucket with SSE-S3 or SSE-KMS ensures that every object written to the bucket is encrypted server-side at rest automatically, regardless of how it is uploaded. SSE-S3 uses AES-256 managed by Amazon, while SSE-KMS gives you customer-managed keys and separate audit permissions. This default setting satisfies compliance requirements for encrypted backups and prevents the accidental upload of plaintext objects.

Why this answer

Enabling default encryption on the S3 bucket using SSE-S3 or AWS KMS ensures that all objects stored in the bucket are encrypted at rest automatically, meeting the encryption-at-rest requirement. This can be configured via the bucket properties, and it applies to any object uploaded without explicit encryption headers.

Exam trap

The trap here is that candidates often confuse 'blocking public access' (a network-level control) with 'encryption at rest' (a data protection control), or think that versioning or transfer acceleration somehow addresses encryption or authorization requirements.

1077
MCQhard

A CloudFormation stack manages an RDS database, an S3 bucket, and several Lambda functions. During a recent stack update, a property change caused CloudFormation to replace the RDS instance, deleting the database and re-creating it — resulting in data loss. The team wants to prevent any future stack update from replacing or deleting the RDS instance without an explicit override. What CloudFormation feature accomplishes this?

A.Set a stack policy that denies Replace and Delete actions on the RDS resource; require an override policy to be explicitly provided when a replacement is intentional
B.Enable deletion protection on the RDS instance to prevent CloudFormation from deleting it
C.Use CloudFormation change sets to preview the update and manually reject any change set that includes a replacement
D.Add a DeletionPolicy: Retain attribute to the RDS resource in the template
AnswerA

The stack policy evaluates each update action per resource. A Deny on Replace for the RDS logical resource ID prevents CloudFormation from completing any update that would recreate the database — the update fails with a clear policy error. A temporary override policy passed via --stack-policy-during-update can explicitly allow the replacement for a deliberate migration.

Why this answer

A CloudFormation stack policy can explicitly deny Update (which includes replacement) and Delete actions on specific resources, such as the RDS instance. To intentionally perform a replacement, the user must provide an override stack policy during the update that allows the action, ensuring that no accidental replacement occurs without explicit consent.

Exam trap

The trap here is that candidates confuse RDS deletion protection or DeletionPolicy: Retain with stack policies, mistakenly believing those features can block CloudFormation from replacing a resource during an update, when in fact they only protect against deletion in specific scenarios (e.g., stack deletion or direct API calls).

How to eliminate wrong answers

Option B is wrong because RDS deletion protection prevents the database from being deleted via the RDS API or console, but CloudFormation can still replace the instance (which involves creating a new one and deleting the old one) if the template triggers a replacement; deletion protection does not block CloudFormation from performing a replacement. Option C is wrong because change sets only provide a preview of changes and require manual approval, but they do not prevent a user from accidentally executing a change set that includes a replacement; the team wants a guardrail that blocks replacement without an explicit override, not just a manual review step. Option D is wrong because DeletionPolicy: Retain only preserves the resource when the stack is deleted, but it does not prevent CloudFormation from replacing the resource during a stack update; a replacement still deletes the original resource and creates a new one, and the Retain policy does not block that deletion.

1078
MCQeasy

A company has multiple VPCs in the same AWS Region that need to communicate with each other. The SysOps administrator wants to avoid the complexity of a full mesh of VPC peering connections. Which AWS service should the administrator use to connect all VPCs with a central hub?

A.AWS Direct Connect
B.AWS Transit Gateway
C.VPC peering
D.AWS PrivateLink
AnswerB

AWS Transit Gateway functions as a regional hub-and-spoke router, to which you can attach VPCs, VPN connections, and Direct Connect gateways. It uses central route tables to enable transitive routing, so any attached VPC can communicate with any other without point-to-point connections. This model scales easily with thousands of VPCs and simplifies network management and security. It directly solves the requirement of multiple VPCs needing to communicate, making it the correct choice.

Why this answer

AWS Transit Gateway acts as a central hub that allows you to connect multiple VPCs and on-premises networks through a single gateway, eliminating the need for a full mesh of VPC peering connections. It uses a star topology where each VPC attaches to the Transit Gateway, and routing is managed via route tables, simplifying network management and scaling.

Exam trap

The trap here is that candidates often confuse VPC peering (which is point-to-point) with a hub-and-spoke solution, or mistakenly think AWS PrivateLink can route general traffic between VPCs, when it is actually designed for service-specific endpoints.

How to eliminate wrong answers

Option A is wrong because AWS Direct Connect is a dedicated network connection from on-premises to AWS, not a service for interconnecting multiple VPCs within the same Region. Option C is wrong because VPC peering creates a one-to-one connection between two VPCs, requiring a full mesh of N*(N-1)/2 connections for multiple VPCs, which adds complexity and does not provide a central hub. Option D is wrong because AWS PrivateLink enables private connectivity between VPCs and services (like endpoints), but it is designed for accessing specific services rather than routing traffic between multiple VPCs as a hub-and-spoke model.

1079
MCQeasy

A company's security policy requires that only traffic from the corporate office IP range (203.0.113.0/24) can access an Amazon S3 bucket that stores internal reports. The SysOps administrator must enforce this restriction. Which policy type should be modified to implement this requirement?

A.IAM identity-based policy
B.VPC endpoint policy
C.S3 bucket policy
D.AWS Organizations SCP
AnswerC

An S3 bucket policy is a resource-based policy that can be directly associated with the target bucket. By setting the Principal to '*' and adding a condition key of aws:SourceIp with the allowed CIDR ranges, the bucket denies any request that does not originate from those addresses, regardless of whether the requester is an IAM user, an anonymous caller, or a service. This is the most precise and comprehensive way to enforce an IP-based allowlist at the bucket level.

Why this answer

An S3 bucket policy is the correct choice because it allows you to explicitly deny or allow access to the S3 bucket based on the source IP address using the `aws:SourceIp` condition key. This policy is attached directly to the bucket and can restrict access to only the corporate office IP range (203.0.113.0/24), regardless of the IAM user or role making the request. It enforces the security requirement at the resource level, which is the most direct and effective method for controlling network-based access to an S3 bucket.

Exam trap

The trap here is that candidates often confuse IAM identity-based policies with resource-based policies, mistakenly thinking they can use IAM policies to restrict by source IP, when in fact only S3 bucket policies (or similar resource-based policies) support the `aws:SourceIp` condition for network-level access control.

How to eliminate wrong answers

Option A is wrong because IAM identity-based policies are attached to users, groups, or roles and control what actions those identities can perform, but they cannot restrict access based on the source IP address of the requestor; they lack the `aws:SourceIp` condition key for network-level control. Option B is wrong because a VPC endpoint policy controls access to S3 from a specific VPC endpoint, but it does not allow you to specify a source IP range like 203.0.113.0/24; it only restricts access based on the VPC or endpoint ID, not the client's IP address. Option D is wrong because AWS Organizations SCPs are used to set permission boundaries across accounts in an organization, but they cannot enforce IP-based restrictions on a specific S3 bucket; they operate at the account or organizational unit level, not at the resource level.

1080
MCQeasy

Refer to the exhibit. A SysOps administrator runs the command shown to investigate a CloudWatch alarm named 'HighCPU'. What does the output indicate?

A.The alarm entered the ALARM state and then returned to OK.
B.The alarm was deleted and recreated.
C.The alarm is currently in INSUFFICIENT_DATA state.
D.The alarm never entered the ALARM state.
AnswerA

CloudWatch alarm history records each state transition with a timestamp. In the exhibit, the alarm changed from OK to ALARM at 10:25 and then changed back to OK afterward, which is exactly what the history shows. Therefore, the correct interpretation is that the alarm entered the ALARM state and subsequently returned to OK.

Why this answer

The output shows two state transition datapoints: one at timestamp 2021-03-15T10:30:00Z with 'oldState' OK and 'newState' ALARM, and another at 2021-03-15T10:35:00Z with 'oldState' ALARM and 'newState' OK. This sequence confirms the alarm entered the ALARM state and then returned to OK, which is exactly what the describe-alarm-history command reveals when an alarm has experienced a full ALARM-to-OK cycle.

Exam trap

The trap here is that candidates may misinterpret the two datapoints as separate unrelated events rather than recognizing them as a complete ALARM-to-OK cycle, leading them to incorrectly choose that the alarm never entered ALARM state or that it was recreated.

How to eliminate wrong answers

Option B is wrong because deleting and recreating an alarm would produce a new alarm name or ARN, and the history would show a creation event, not a transition from OK to ALARM and back to OK. Option C is wrong because INSUFFICIENT_DATA state would appear as a transition from OK to INSUFFICIENT_DATA or ALARM to INSUFFICIENT_DATA, but the output only shows transitions between OK and ALARM. Option D is wrong because the first datapoint explicitly shows a transition from OK to ALARM, proving the alarm did enter the ALARM state.

1081
Multi-Selectmedium

A company is using AWS KMS to encrypt data at rest. Which TWO actions can be taken to audit the usage of a customer managed key?

Select 2 answers
A.Enable AWS CloudTrail to log KMS API calls.
B.Enable Amazon S3 server access logs to track KMS operations.
C.Use IAM Access Analyzer to review KMS key policies.
D.Stream CloudTrail logs to Amazon CloudWatch Logs and create metric filters for KMS events.
E.Use AWS Config rules to monitor KMS key usage.
AnswersA, D

AWS CloudTrail is the authoritative audit service for KMS because every KMS API operation—including Encrypt, Decrypt, GenerateDataKey, and CreateKey—is captured as an event containing the principal, source IP, request parameters, and response. These events are delivered to an S3 bucket as JSON files, providing a durable, tamper-evident record that supports compliance and security investigations. Enabling a trail that records management events is sufficient for KMS, as KMS data-plane calls are automatically logged as management events.

Why this answer

AWS CloudTrail captures all KMS API calls (e.g., Encrypt, Decrypt, GenerateDataKey) as events, providing a complete audit trail of who used the key, when, and from which source. By enabling CloudTrail, you can review these logs to audit customer managed key usage. This is the primary method for auditing KMS key operations.

Exam trap

The trap here is that candidates often confuse AWS Config rules (which check configuration compliance) with actual usage auditing, or they think S3 server access logs can capture KMS operations when they only log S3-level requests, not the underlying KMS API calls.

1082
MCQeasy

A SysOps administrator wants to receive a notification when an EC2 instance's status check fails. Which AWS service should be used to achieve this?

A.Amazon CloudWatch Alarms
B.AWS Config
C.AWS CloudTrail
D.AWS Trusted Advisor
AnswerA

Amazon CloudWatch Alarms is the correct service because it directly consumes the EC2 StatusCheckFailed metric, which is emitted every minute by the instance hypervisor. You can configure an alarm on this metric with a threshold (e.g., >=1 for one or more consecutive evaluation periods) to transition to ALARM state, and then invoke an SNS topic to send notifications via email, SMS, or Lambda. CloudWatch also supports separate alarms for StatusCheckFailed_System (host-level issues) and StatusCheckFailed_Instance (guest-OS level issues), giving you granular, near-real-time health monitoring.

Why this answer

Amazon CloudWatch Alarms can monitor EC2 instance status checks (both system and instance checks) and trigger an action, such as sending a notification via Amazon SNS, when a status check fails. This is the native AWS service designed for real-time monitoring and alerting on metric thresholds, making it the correct choice for this use case.

Exam trap

The trap here is that candidates often confuse AWS Config (which evaluates configuration compliance) with CloudWatch Alarms (which monitor metric thresholds), leading them to select AWS Config for real-time health alerts instead of the correct monitoring service.

How to eliminate wrong answers

Option B (AWS Config) is wrong because it is used for evaluating and recording resource configurations against desired policies, not for monitoring real-time status check failures. Option C (AWS CloudTrail) is wrong because it captures API activity and management events, not instance-level health metrics like status checks. Option D (AWS Trusted Advisor) is wrong because it provides best-practice recommendations and cost optimization checks, not real-time monitoring or alerting on EC2 status checks.

1083
Multi-Selecthard

A SysOps administrator is troubleshooting a high error rate on an Application Load Balancer (ALB). The ALB is configured with two target groups: one for EC2 instances and one for Lambda functions. The administrator notices that the EC2 target group is unhealthy. Which THREE steps should the administrator take to resolve the issue?

Select 3 answers
A.Review the ALB's DNS resolution for the target instances.
B.Verify that the EC2 instances' security groups allow traffic from the ALB.
C.Increase the size of the Auto Scaling group to distribute load.
D.Check the health check settings on the target group for correct path and interval.
E.Inspect the application logs on the EC2 instances for errors.
AnswersB, D, E

When an ALB forwards traffic to EC2 instances, it connects from the security group attached to the ALB's elastic network interfaces. If the instance security group's inbound rules do not explicitly allow TCP traffic on the listener port and health check port from that ALB security group (or the VPC CIDR), the instance silently drops both health check probes and client connections. Because security groups are stateful, outbound responses are allowed automatically, but the inbound rule must exist; otherwise the ALB sees connection timeouts, marks the targets unhealthy, and routes only to remaining instances, skyrocketing error rates.

Why this answer

The ALB communicates with EC2 instances using the private IP addresses of the instances. If the EC2 instances' security groups do not explicitly allow inbound traffic from the ALB's security group (or the ALB's VPC CIDR), the health checks and actual traffic will be blocked, causing the target group to be marked unhealthy. This is a common misconfiguration when the ALB and instances are in the same VPC.

Exam trap

The trap here is that candidates often focus on scaling or DNS issues (Options A and C) instead of recognizing that the most common cause of an unhealthy target group is either a security group misconfiguration or an incorrect health check path, both of which are directly addressed by Options B and D.

1084
Multi-Selectmedium

A SysOps administrator needs to monitor the disk space utilization on a fleet of EC2 instances running Windows Server. Which TWO steps should the administrator take to collect and visualize this data? (Choose TWO.)

Select 2 answers
A.Enable detailed monitoring on the EC2 instances.
B.Install the CloudWatch agent on each EC2 instance to collect disk space metrics.
C.Use AWS CloudTrail to log disk space changes.
D.Enable default EC2 monitoring to collect disk space metrics automatically.
E.Create a CloudWatch dashboard to visualize the disk space metrics.
AnswersB, E

The CloudWatch agent is the correct solution because it runs inside the guest OS and directly reads file system utilization from the instance. You configure the agent with a JSON file to collect custom metrics such as disk_space_used, disk_space_free, and disk_space_utilization for each mount point, and it publishes these to CloudWatch under the custom namespace. The agent can be installed via Systems Manager or user data, and it also supports memory and log collection, making it the comprehensive approach for OS-level monitoring including disk space.

Why this answer

The CloudWatch agent is required to collect custom metrics like disk space utilization from EC2 instances running Windows Server. Default EC2 monitoring only collects hypervisor-level metrics (CPU, network, disk I/O), not guest OS metrics such as disk space. Installing the CloudWatch agent and configuring it to collect disk space metrics is the correct step.

Creating a CloudWatch dashboard then allows visualization of those collected metrics.

Exam trap

The trap here is that candidates assume default or detailed EC2 monitoring includes guest OS metrics like disk space, when in fact those metrics require the CloudWatch agent to be installed and configured on the instance.

1085
MCQhard

An application writes logs to a file on an EC2 instance. The SysOps team needs to send these logs to Amazon CloudWatch Logs in real time. The logs must be encrypted at rest in CloudWatch Logs using a customer-managed KMS key. Which steps are required?

A.Use AWS CloudTrail to deliver logs to CloudWatch Logs with KMS encryption.
B.Store logs in S3 with KMS encryption and use S3 event notifications to trigger Lambda to put logs in CloudWatch Logs.
C.Install the CloudWatch Logs agent and enable encryption on the EC2 instance volume using KMS.
D.Install the CloudWatch Logs agent and associate a KMS key with the log group using the 'associate-kms-key' API.
AnswerD

This enables encryption at rest with a customer-managed key.

Why this answer

The CloudWatch Logs agent can send log data from an EC2 instance to CloudWatch Logs in real time, and the 'associate-kms-key' API (or the equivalent AWS CLI command 'put-log-group-encryption') allows you to associate a customer-managed KMS key with a log group, encrypting the logs at rest. This meets both the real-time delivery and customer-managed KMS encryption requirements without additional services or workarounds.

Exam trap

The trap here is that candidates often confuse encrypting the log file on the EC2 instance volume (Option C) with encrypting the logs at rest in CloudWatch Logs, or they overcomplicate the solution by introducing unnecessary services like S3 and Lambda (Option B) instead of using the native KMS integration with CloudWatch Logs.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail delivers API activity logs, not application log files from an EC2 instance, and it cannot be used to send arbitrary application logs to CloudWatch Logs in real time. Option B is wrong because storing logs in S3 and using S3 event notifications to trigger a Lambda function introduces latency and complexity, and does not provide real-time streaming to CloudWatch Logs; it also requires additional services and is not the standard method for real-time log ingestion. Option C is wrong because enabling encryption on the EC2 instance volume using KMS encrypts the log file at rest on the instance, but does not encrypt the logs at rest in CloudWatch Logs; the CloudWatch Logs agent sends data over the network, and the log group itself must be encrypted with a KMS key to meet the requirement.

1086
MCQmedium

A company uses Amazon RDS for MySQL with Multi-AZ deployment. The SysOps administrator notices that the DB instance's CPU utilization spikes to 100% every few minutes. CloudWatch alarms have been set to trigger when CPU exceeds 90% for 5 minutes, but no alarm state changes are observed. The administrator checks the CloudWatch metrics and sees that the CPU utilization metric shows periodic spikes but they last only 2-3 minutes each. What is the most likely cause and what should the administrator do to receive notifications?

A.Set the alarm to evaluate over 1 minute instead of 5 minutes.
B.The Multi-AZ failover is causing the spikes; disable Multi-AZ.
C.The DB instance is not publishing CPU metrics at a high enough resolution.
D.The CPU metric is not accurate; use the CPU credit metric instead.
AnswerA

A CloudWatch alarm with a 5-minute period averages all CPUUtilization samples in that window, so a brief spike in utilization can be smoothed out and never crosses the threshold. Changing the period to 1 minute, which matches the standard metric publishing interval for RDS, ensures the short spike is evaluated as a discrete data point. That is the correct fix for detecting short-duration CPU spikes.

Why this answer

The CPU utilization spikes last only 2-3 minutes, which is shorter than the alarm's evaluation period of 5 consecutive minutes. Since the alarm requires the metric to exceed the 90% threshold for 5 minutes before triggering, these brief spikes never satisfy the alarm's duration condition. Setting the alarm to evaluate over 1 minute will match the spike duration and allow the alarm to trigger on these short-lived bursts.

Exam trap

The trap here is that candidates assume the alarm should trigger because the metric exceeds the threshold, but they overlook the requirement that the breach must persist for the entire evaluation period, not just momentarily.

How to eliminate wrong answers

Option B is wrong because Multi-AZ failover does not cause periodic CPU spikes; failover is a rare event triggered by planned maintenance or failure, not a recurring every-few-minutes pattern, and disabling Multi-AZ would reduce availability without addressing the underlying CPU issue. Option C is wrong because Amazon RDS for MySQL publishes CPU utilization metrics at 1-minute resolution by default (with detailed monitoring enabled), and the administrator can already see the spikes in CloudWatch, so resolution is not the problem. Option D is wrong because CPU credit metrics apply only to burstable performance instances (e.g., T2/T3), not to standard RDS instances, and the CPU metric is accurate; the issue is the alarm evaluation period, not the metric's validity.

1087
MCQeasy

A company hosts a static website on Amazon EC2 instances behind an Application Load Balancer. They want to improve latency for users around the world by caching content at edge locations. Which AWS service should they use?

A.Amazon CloudFront
B.AWS Global Accelerator
C.AWS Direct Connect
D.Amazon Route 53
AnswerA

Amazon CloudFront is a content delivery network (CDN) that caches static assets, such as HTML, CSS, JavaScript, and images, at edge locations geographically close to users. When a user requests a file, CloudFront serves it from the cache if the TTL has not expired, drastically reducing latency and offloading repeated requests from the underlying EC2 instances. It can be configured with an Application Load Balancer or EC2 as the origin and automatically handles SSL termination, HTTP/2, and compression, making it the ideal choice for static website acceleration.

Why this answer

Amazon CloudFront is a content delivery network (CDN) that caches static content (e.g., HTML, CSS, images) at edge locations worldwide, reducing latency for global users by serving cached responses from the nearest edge rather than the origin EC2 instances behind the Application Load Balancer. It integrates directly with ALB as a custom origin, offloading traffic and improving response times for repeated requests.

Exam trap

The trap here is confusing AWS Global Accelerator (which optimizes network path but does not cache) with CloudFront (which caches at edge), leading candidates to pick Global Accelerator for latency improvement without recognizing the requirement for content caching.

How to eliminate wrong answers

Option B (AWS Global Accelerator) is wrong because it improves latency by directing traffic over the AWS global network using Anycast IPs, but it does not cache content at edge locations—it only optimizes routing to the origin. Option C (AWS Direct Connect) is wrong because it establishes a dedicated private network connection from on-premises to AWS, which does not cache content or serve edge locations; it is used for hybrid connectivity, not global content delivery. Option D (Amazon Route 53) is wrong because it is a DNS service that resolves domain names to IP addresses and can route users to the nearest endpoint via latency-based routing, but it does not cache or store content at edge locations.

1088
Multi-Selecthard

A company wants to use AWS WAF to protect a web application behind an Application Load Balancer. Which of the following can AWS WAF inspect? (Choose all that apply.)

Select 4 answers
A.HTTP headers
B.Query string parameters
C.SSL certificate of the client
D.Request body of HTTPS requests
E.URI path
AnswersA, B, D, E

HTTP headers are one of the key web request components that AWS WAF natively inspects. You can create rules that match on header names and values, such as checking the User-Agent header for known bot signatures or the Authorization header for invalid tokens. WAF supports string matching, regex pattern sets, and size constraints on header values, providing flexible control over header-based threats.

Why this answer

AWS WAF inspects the HTTP request components that reach the Application Load Balancer, and HTTP headers (Option A) are one of the core inspectable request parts used in rules such as header-match statements. Query string parameters (Option B) are also inspectable, allowing rules to match on keys/values in the URL query, which is essential for blocking injection or abuse patterns. The request body of HTTPS requests (Option D) can be inspected because AWS WAF supports body inspection (with size limits and sampling behavior) even though the traffic is TLS-encrypted at the ALB, since WAF evaluates the decrypted HTTP request.

The URI path (Option E) is inspectable via URI-path match conditions, enabling rules that target specific endpoints or path patterns. Option C is not correct because AWS WAF does not inspect the client's SSL/TLS certificate; client certificate handling/validation is a function of the load balancer's mutual TLS configuration, not a WAF match condition.

Exam trap

Candidates may mistakenly think that the request body of HTTPS requests cannot be inspected, but AWS WAF can inspect it when used with an Application Load Balancer because the ALB decrypts the traffic before forwarding to WAF.

1089
MCQeasy

A company has a VPC with a CIDR block of 10.0.0.0/16. They have two subnets: a public subnet (10.0.1.0/24) and a private subnet (10.0.2.0/24). An EC2 instance in the private subnet needs to access an S3 bucket to store logs. The instance currently has no internet access. The SysOps administrator has created a VPC endpoint for S3 (gateway type) and attached it to the VPC. The instance still cannot reach S3. What additional step is required?

A.Attach an Internet Gateway to the VPC and add a route to it
B.Add a security group rule to allow outbound HTTPS traffic to S3
C.Modify the endpoint policy to allow all S3 actions
D.Add a route in the private subnet's route table pointing to the S3 endpoint
AnswerD

For a gateway VPC endpoint to work, the subnet's route table must include a route with the S3 prefix list (e.g., com.amazonaws.region.s3) targeting the endpoint ID. Without this route, S3-bound traffic from private instances follows the default route and fails if there's no internet path. Adding this route directs traffic through the endpoint over AWS's private network.

Why this answer

After creating a gateway VPC endpoint for S3, you must add a route in the subnet's route table that points S3 traffic (using the prefix list pl-xxxxxxxx for S3) to the endpoint. Without this route, the private subnet has no path to the endpoint, so the instance cannot reach S3. The gateway endpoint is not automatically added to route tables; it must be explicitly associated.

Exam trap

SOA-C02 often tests the extra step required after creating a gateway endpoint, tempting candidates to focus on security groups or endpoint policies when the missing piece is the route table entry.

How to eliminate wrong answers

Option A is wrong because attaching an Internet Gateway and adding a route would give the instance internet access, which defeats the purpose of using a gateway endpoint and is unnecessary for private S3 access. Option B is wrong because security groups are stateful and outbound HTTPS is allowed by default; moreover, gateway endpoints for S3 do not use security groups — they use endpoint policies and route table entries. Option C is wrong because modifying the endpoint policy to allow all S3 actions addresses authorization, not connectivity; the default endpoint policy already allows full access, and the instance still cannot reach S3 without a route.

1090
MCQeasy

A SysOps administrator uses AWS CloudFormation to deploy a three-tier application. The administrator has a single template that can be used for development, test, and production environments. The only differences between environments are the EC2 instance type and the RDS DB instance class. Which CloudFormation feature should the administrator use to define these environment-specific values without duplicating the template?

A.Parameters
B.Conditions
C.Mappings
D.Outputs
AnswerA

Parameters are the only mechanism in CloudFormation that lets you pass custom values, such as instance types or DB classes, directly into a template at the time you create or update a stack. By declaring a parameter in the template, AWS CloudFormation prompts the user (or accepts from CLI/API) for a value, which can then be referenced using Ref or Fn::Sub within the template. This makes the same template reusable across multiple environments, like Development and Production, by simply supplying different parameter values on each deployment.

Why this answer

Parameters allow you to input environment-specific values (e.g., EC2 instance type, RDS DB instance class) at stack creation or update time without modifying the template. This is the correct feature because the question explicitly requires defining values that differ per environment while reusing a single template.

Exam trap

The trap here is that candidates confuse Conditions (which toggle resource creation) with Parameters (which supply variable values), leading them to think Conditions can handle environment-specific instance types when they cannot.

How to eliminate wrong answers

Option B (Conditions) is wrong because conditions control whether to create or include specific resources or properties based on a condition (e.g., environment type), but they cannot inject variable values like instance types; they only toggle existence. Option C (Mappings) is wrong because mappings provide static lookup tables (e.g., mapping environment names to instance types) but require hardcoded keys and values in the template, which still requires template duplication if the values change per deployment; parameters are more flexible for runtime input. Option D (Outputs) is wrong because outputs are used to return information about the stack (e.g., endpoint URLs) after creation, not to define input values for resources.

1091
Multi-Selectmedium

A company is designing a VPC with public and private subnets. The private subnets need internet access for patching, but must not be directly reachable from the internet. Which TWO components should be used together?

Select 2 answers
A.VPC Peering connection
B.Private subnet route table with a route to the Internet Gateway
C.Internet Gateway attached to the VPC
D.Private subnet route table with a route to the NAT Gateway
E.NAT Gateway in a public subnet
AnswersD, E

The private subnet's route table must direct 0.0.0.0/0 traffic to the NAT Gateway, keeping instances unaddressable from the internet while enabling outbound patching. Without this route, private instances have no path to the NAT Gateway, so the no-inbound-reachability constraint fails.

Why this answer

Option E is correct because a NAT Gateway must be deployed in a public subnet (with an Elastic IP) so it can route traffic out through the Internet Gateway on behalf of private instances. Option D is correct because the private subnet's route table must have a route (typically 0.0.0.0/0) pointing to that NAT Gateway, which allows instances in the private subnet to initiate outbound traffic for patching while remaining unreachable from the internet. Together, the NAT Gateway in the public subnet and the private route table entry provide one-way outbound internet access.

Option A is incorrect because VPC Peering connects two VPCs and does not provide internet access. Option B is incorrect because routing a private subnet directly to an Internet Gateway would make it a public subnet and expose it to inbound internet traffic. Option C is incorrect because an Internet Gateway alone, attached to the VPC, does not give private subnets outbound access without a NAT device and the corresponding route.

Exam trap

The trap is assuming that attaching an Internet Gateway to the VPC automatically gives private subnets internet access — candidates must remember that private subnets require a NAT Gateway (in a public subnet) plus a route to it, and that the IGW alone is insufficient.

1092
MCQhard

A company runs a stateful web application on EC2 instances in an Auto Scaling group behind an Application Load Balancer. Users report that their sessions are frequently lost during scaling events. What is the MOST effective solution to maintain session persistence?

A.Increase the cooldown period for the Auto Scaling group.
B.Modify the application to store session data in an external data store such as ElastiCache or DynamoDB.
C.Enable sticky sessions (session affinity) on the Application Load Balancer.
D.Use larger EC2 instance types to reduce the frequency of scaling.
AnswerB

Storing session data in an external data store such as ElastiCache (a managed in-memory cache) or DynamoDB (a managed NoSQL database) decouples session state from the compute layer, making each EC2 instance effectively stateless. Any instance in the Auto Scaling group can then serve any request by reading and writing session data to the shared store, so if an instance is terminated, the session remains intact and is immediately accessible to a replacement instance. ElastiCache is ideal for extremely low-latency session reads and writes, while DynamoDB provides persistent, highly available storage; both allow the application to survive scaling events and instance failures without losing user context. This is the architecturally correct approach for a stateful web application running on a horizontally scaled fleet.

Why this answer

Externalizing session state to a durable, shared data store like ElastiCache or DynamoDB decouples session data from individual EC2 instances. This ensures that sessions survive scaling events, including instance termination during scale-in, because any instance can retrieve the session from the external store. Sticky sessions (option C) only route traffic to the same instance, but they do not preserve session data if that instance is terminated.

Options A and D do not address session persistence at all.

Exam trap

Candidates often choose sticky sessions because they associate session persistence with keeping a user on the same server. However, sticky sessions do not protect against session loss when the serving instance is terminated during scale-in. Externalizing session state is the more robust solution for scaling events.

How to eliminate wrong answers

Option A is wrong because increasing the cooldown period only delays the next scaling activity, it does not preserve session data across instances or prevent session loss when scaling does occur. Option B is wrong because while storing session data in an external data store like ElastiCache or DynamoDB is a valid approach for session persistence, the question asks for the 'MOST effective solution' given the context of an ALB and Auto Scaling, and the correct answer (sticky sessions) directly addresses session affinity without requiring application code changes. Option D is wrong because using larger EC2 instance types reduces the frequency of scaling but does not eliminate it, and sessions will still be lost when scaling events happen.

1093
MCQeasy

An organization uses AWS Service Catalog to manage approved IT services. A SysOps administrator needs to update a CloudFormation template used by a product. The administrator wants to ensure that existing provisioned products are updated with the new template version. What step must the administrator take after updating the product?

A.Update the portfolio that contains the product.
B.Create a new product version and update the provisioned products to use the new version.
C.Update the product's CloudFormation template directly in the Service Catalog console.
D.Terminate the existing provisioned products and reprovision them.
AnswerB

To update an existing provisioned product, you must create a new product version in AWS Service Catalog, typically by uploading a new CloudFormation template. Once the version is available, you then use the console or AWS CLI to update each provisioned product to the new version, which triggers CloudFormation change sets to apply only the necessary modifications. This preserves the resource lifecycle and minimizes disruption while ensuring your approved infrastructure is updated consistently.

Why this answer

After updating a CloudFormation template used by an AWS Service Catalog product, the administrator must create a new product version and then update the existing provisioned products to use that new version. Service Catalog versions are immutable — you cannot edit an existing version in place. Existing provisioned products continue using the version they were launched with until explicitly updated, so the administrator must both publish the new version and perform the update on each provisioned product.

Exam trap

SOA-C02 often tests the misconception that editing a product or portfolio automatically updates existing provisioned products, when in fact Service Catalog requires explicit version creation and provisioned-product updates.

How to eliminate wrong answers

Option A is wrong because updating the portfolio only changes which products and principals have access; it does not push a new template version to existing provisioned products. Option C is wrong because you cannot edit a product's CloudFormation template directly in the Service Catalog console — templates are sourced from an S3 URL or CodeCommit, and changes require a new product version. Option D is wrong because terminating and reprovisioning would cause downtime and data loss, and it is not the required step; Service Catalog supports in-place updates to a new version.

1094
MCQeasy

A SysOps administrator needs to monitor the application logs of a web server and receive an email notification when the number of 'ERROR' log entries exceeds 100 in a 5-minute window. The logs are already being sent to Amazon CloudWatch Logs. Which combination of AWS services should be used to meet this requirement with the least operational overhead?

A.CloudWatch Logs metric filter, CloudWatch alarm, and Amazon SNS
B.Amazon Kinesis Data Firehose and AWS Lambda
C.AWS CloudTrail and Amazon EventBridge
D.AWS Config managed rule and Amazon SNS
AnswerA

A CloudWatch Logs metric filter continuously scans incoming log events for a pattern you define (e.g., ERROR or Exception) and incrementally publishes a custom metric to CloudWatch. A CloudWatch alarm then evaluates that metric against a threshold, and when the threshold is breached, the alarm state changes to ALARM and triggers an Amazon SNS topic to send an email notification. This is a native, fully managed, near-real-time monitoring solution with no custom code to maintain, making it the correct architecture.

Why this answer

CloudWatch Logs metric filters can parse log events for the string 'ERROR' and count them in real time. A CloudWatch alarm can then trigger when the metric exceeds 100 in a 5-minute period, and Amazon SNS sends the email notification. This combination requires no custom code or additional infrastructure, minimizing operational overhead.

Exam trap

The trap here is that candidates may confuse CloudTrail (which logs API calls) with CloudWatch Logs (which stores application logs), leading them to choose Option C, but CloudTrail cannot inspect application log content.

How to eliminate wrong answers

Option B is wrong because Amazon Kinesis Data Firehose is designed for streaming large volumes of data to destinations like S3 or Redshift, not for real-time metric extraction and alerting; adding AWS Lambda would introduce custom code and increase complexity. Option C is wrong because AWS CloudTrail records API activity, not application log entries, and Amazon EventBridge is for event-driven workflows, not for counting log patterns. Option D is wrong because AWS Config managed rules evaluate resource compliance against desired configurations, not log content; they cannot parse log entries for 'ERROR' strings.

1095
MCQmedium

A SysOps administrator uses AWS CloudFormation to deploy infrastructure. The administrator has a template that creates an Amazon EC2 instance and an Amazon RDS DB instance. The administrator needs to reuse the same template for development, test, and production environments, where the only differences are the EC2 instance type and the RDS DB instance class. Which CloudFormation feature should be used to define these environment-specific values?

A.Mappings
B.Conditions
C.Parameters
D.Outputs
AnswerC

Parameters are the CloudFormation feature designed to accept input values from the user at stack creation or update time. The template can reference parameters using the Ref intrinsic function, and you can define constraints such as AllowedValues, Default, and MinLength/MaxLength to control the input. By declaring parameters for the instance type and DB class, the SysOps administrator can deploy the same template to multiple environments simply by providing different parameter values, which is the most flexible and maintainable approach for this requirement.

Why this answer

Parameters are the correct CloudFormation feature to define environment-specific values because they allow you to input custom values (e.g., EC2 instance type and RDS DB instance class) at stack creation or update time without modifying the template. This enables reuse of the same template across development, test, and production environments by simply passing different parameter values for each environment.

Exam trap

The trap here is that candidates often confuse Parameters with Mappings, thinking Mappings can handle environment-specific values, but Mappings are static and cannot accept runtime input, whereas Parameters are designed exactly for this purpose.

How to eliminate wrong answers

Option A is wrong because Mappings are static lookup tables used to define fixed key-value pairs (e.g., mapping AWS regions to AMI IDs) and cannot accept dynamic user input per environment. Option B is wrong because Conditions control whether certain resources or properties are created based on logical expressions (e.g., create a resource only in production), but they do not define variable values like instance types. Option D is wrong because Outputs are used to return information about the created stack (e.g., endpoint URLs or resource IDs) and cannot be used to pass input values into the template.

1096
Multi-Selecthard

A company uses AWS CloudFormation to deploy infrastructure. The SysOps administrator needs to ensure that if a stack update fails, the stack is automatically rolled back to the last known good state. Which TWO steps should the administrator take? (Choose two.)

Select 2 answers
A.Create a manual snapshot of the database before each update.
B.Configure the stack to use a service role with permissions to perform rollback actions.
C.Use rollback triggers to monitor CloudWatch metrics and automatically roll back the stack if a metric breache.
D.Enable termination protection on the stack.
E.Define a stack policy that prevents updates to the database resources.
AnswersB, C

CloudFormation uses a service role to make API calls when creating, updating, or deleting stack resources. On a failed update, the service must be able to reverse changes—delete newly created resources, revert modifications, and in some cases re-create previous resources—so the role needs explicit permissions for those rollback actions. Without those permissions, rollback can stall, leaving the stack in UPDATE_ROLLBACK_FAILED.

Why this answer

A service role grants CloudFormation the necessary IAM permissions to perform rollback actions on resources, such as deleting or reverting changes, even if the user who initiated the update lacks those permissions. This ensures that the stack can automatically return to its last known good state without manual intervention. Option C is correct because rollback triggers allow monitoring CloudWatch metrics; if a metric breaches the specified threshold, CloudFormation automatically rolls back the stack, providing an additional safeguard.

Option E is incorrect because a stack policy only prevents updates to protected resources but does not enable or automate rollback on failure.

Exam trap

The trap here is that candidates often confuse termination protection (which only prevents stack deletion) with rollback behavior, or they assume manual snapshots are part of CloudFormation's automatic rollback process, when in fact CloudFormation relies on resource-level reversal and service roles.

1097
MCQmedium

An RDS Multi-AZ DB instance fails over to the standby. The application uses the DB instance endpoint. What should the SysOps administrator usually do in the application after failover?

A.Ensure the application retries/reconnects using the same DB endpoint.
B.Manually change the application to the standby instance IP address.
C.Restore from the latest snapshot before reconnecting.
D.Create a new read replica and promote it immediately.
AnswerA

The RDS Multi-AZ architecture abstracts the active database behind a consistent DNS endpoint. When failover occurs, AWS automatically repoints that endpoint to the newly promoted standby, so the application must simply retry/reconnect to the same hostname rather than changing any configuration. Implementing connection retry logic with backoff is essential, because the failover process typically causes existing connections to be dropped for 60–120 seconds while DNS updates propagate.

Why this answer

When an RDS Multi-AZ DB instance fails over to the standby, the DNS record for the DB instance endpoint is automatically updated to point to the new primary instance. The application should simply retry or reconnect using the same endpoint; no manual changes are needed because the endpoint remains valid. This is the standard behavior for Multi-AZ deployments, ensuring minimal disruption.

Exam trap

The trap here is that candidates may think they need to manually update the connection string or IP address, but the DNS endpoint automatically resolves to the new primary after failover, so only retry logic is required.

How to eliminate wrong answers

Option B is wrong because the application should use the DNS endpoint, not the IP address; the IP address can change after failover, and relying on it would break connectivity. Option C is wrong because restoring from a snapshot is unnecessary and would cause data loss; Multi-AZ failover preserves data without requiring a restore. Option D is wrong because creating and promoting a read replica is not the correct recovery action for a Multi-AZ failover; the standby is already promoted automatically by RDS.

1098
MCQhard

An application stores its RDS PostgreSQL credentials in AWS Secrets Manager. The security policy requires credentials to be rotated every 30 days automatically. During rotation, the application must continue to serve traffic with zero downtime. The application retrieves credentials by calling GetSecretValue at the start of each database connection. What must be configured to satisfy all requirements?

A.Enable automatic rotation in Secrets Manager with a 30-day schedule; use the AWS-provided Lambda rotation function for RDS PostgreSQL; ensure the application calls GetSecretValue per connection rather than caching credentials
B.Rotate credentials manually every 30 days by updating the secret value in the console and restarting the application
C.Create an EventBridge scheduled rule every 30 days that triggers a Lambda to generate a new RDS password and update both the database and the secret
D.Store credentials in an environment variable on the application's EC2 instance and rotate by updating the environment variable and reloading the application
AnswerA

The AWS-provided rotation Lambda handles the full four-step lifecycle. The 30-day rotation schedule triggers the Lambda automatically. Because the application fetches credentials fresh per connection, it starts using the new credentials immediately after AWSCURRENT switches, with no restart needed. Secrets Manager's rotation is designed for zero downtime — the new password is validated on the database before the old version is retired.

Why this answer

AWS Secrets Manager's automatic rotation, combined with the AWS-provided Lambda rotation function for RDS PostgreSQL, ensures credentials are rotated every 30 days without manual intervention. The application's practice of calling GetSecretValue at the start of each database connection guarantees it always retrieves the current secret, avoiding stale credentials and achieving zero downtime during rotation.

Exam trap

The trap here is that candidates may think any automated rotation (like EventBridge + Lambda) suffices, but the question specifically tests the integration of Secrets Manager's native rotation with its versioning and staging labels to achieve zero downtime.

How to eliminate wrong answers

Option B is wrong because manual rotation every 30 days with a console update and application restart violates the zero-downtime requirement; restarting the application causes service interruption. Option C is wrong because while it implements rotation via EventBridge and Lambda, it does not use Secrets Manager's built-in rotation mechanism, missing the automatic version management and staging labels (AWSCURRENT, AWSPREVIOUS) that ensure seamless credential transition. Option D is wrong because storing credentials in an environment variable on EC2 and rotating by updating the variable and reloading the application introduces downtime and bypasses Secrets Manager's secure storage, auditing, and rotation capabilities.

1099
MCQhard

Refer to the exhibit. A SysOps administrator runs the CloudWatch Logs Insights query shown. What does this query do?

A.Groups ERROR and FATAL entries by log stream name.
B.Counts the number of ERROR and FATAL log entries per 5-minute interval and displays them in descending order by time.
C.Displays the full log messages of all ERROR and FATAL entries.
D.Deletes all log entries containing ERROR or FATAL older than 5 minutes.
AnswerB

This is the correct interpretation because the query uses the aggregation function 'stats count() by bin(5m)' which counts all matching ERROR/FATAL events within each 5-minute window, then applies 'sort @timestamp desc' to order the resulting time buckets from the most recent to the oldest. The combined pipeline first filters entries using a pattern match, then aggregates counts over fixed time intervals, and finally sorts the aggregated rows by the timestamp field in descending order. Therefore the output is a time series of error/fatal counts per five-minute bucket, not raw messages or stream-level groupings.

Why this answer

The CloudWatch Logs Insights query uses `stats count(*) by bin(5m)` to aggregate log events into 5-minute time buckets, then filters with `filter @message like /ERROR|FATAL/` to include only those severity levels. The `sort @timestamp desc` orders the resulting time buckets in descending chronological order, producing a count of ERROR and FATAL entries per 5-minute interval. This matches option B exactly.

Exam trap

The trap here is that candidates see `ERROR|FATAL` and `sort @timestamp desc` and assume the query returns raw log messages in reverse chronological order, overlooking that `stats count(*)` aggregates the data into counts per time bucket.

How to eliminate wrong answers

Option A is wrong because the query does not include `by @logStream` or any grouping on log stream name; it groups only by the 5-minute time bin. Option C is wrong because the query uses `stats count(*)` which returns counts, not the full log messages; to display full messages you would use `fields @message` without aggregation. Option D is wrong because CloudWatch Logs Insights is a read-only query engine that cannot delete log entries; deletion requires a separate API call or retention policy.

1100
MCQmedium

A company runs a production Amazon RDS for PostgreSQL DB instance in a single Availability Zone (AZ). The SysOps administrator needs to improve database availability so that in the event of a database failure or AZ outage, a standby instance is automatically promoted with minimal downtime. Which configuration should the administrator enable?

A.Enable automated backups with a retention period of 35 days.
B.Create a read replica in another Availability Zone.
C.Enable Multi-AZ deployment on the DB instance.
D.Schedule manual snapshots to be taken every hour and restore from the latest snapshot when needed.
AnswerC

Enabling Multi-AZ on an Amazon RDS for PostgreSQL DB instance provisions a synchronous standby replica in a different Availability Zone and automatically maintains a synchronous physical replication stream. In the event of an infrastructure failure, an availability zone outage, or a database patching event, Amazon RDS automatically performs a failover to the standby, typically completing within 60–120 seconds and preserving your data because all commits are synchronous. The DNS endpoint remains unchanged, so application connections are transparently redirected without manual intervention. This configuration meets the requirement for automatic failover and high availability.

Why this answer

Multi-AZ deployment automatically creates and maintains a synchronous standby replica in a different Availability Zone. In the event of a failure or AZ outage, Amazon RDS automatically fails over to the standby, typically within 60–120 seconds, with no manual intervention required. This meets the requirement for automatic promotion with minimal downtime.

Exam trap

The trap here is that candidates confuse read replicas (which are for read scaling and require manual promotion) with Multi-AZ (which provides automatic failover), or they overestimate the speed and automation of backups and snapshots for disaster recovery.

How to eliminate wrong answers

Option A is wrong because automated backups only provide point-in-time recovery (PITR) to restore the database to a specific time, not automatic failover with minimal downtime; restoration is a manual process that can take hours. Option B is wrong because a read replica is designed for read scaling and asynchronous replication, not automatic failover; promoting a read replica requires manual intervention and can result in data loss due to replication lag. Option D is wrong because manual snapshots require scheduling and manual restoration, which involves significant downtime and does not provide automatic failover or minimal disruption.

1101
Multi-Selectmedium

A SysOps administrator is configuring CloudTrail to log all management events and data events for S3 buckets. Which of the following are true about CloudTrail logging? (Choose THREE.)

Select 3 answers
A.Data events for S3 are logged by default for all buckets
B.CloudTrail logs include the identity of the user who made the API call
C.Management events are logged by default
D.CloudTrail can log events for all AWS services automatically
E.CloudTrail can deliver log files to CloudWatch Logs for real-time analysis
AnswersB, C, E

CloudTrail logs capture the full userIdentity element for every API call, including the IAM user or role, root user, federated user, or assumed role. It also records the access key ID, source IP address, user agent, and session context, enabling you to determine exactly who performed an action. This makes CloudTrail essential for security auditing and governance.

Why this answer

CloudTrail logs include the identity of the user or role that made the API call, captured as the `userIdentity` element in the log record. This element contains details such as the ARN, access key ID, and whether the call was made by an IAM user, federated user, or assumed role, enabling full auditability of who performed each action.

Exam trap

The trap here is that candidates often assume data events are logged by default because S3 is a core service, but CloudTrail requires explicit opt-in for data events, and management events are the only ones enabled by default.

1102
MCQmedium

A company has a web application deployed in a VPC with both public and private subnets. The web servers are in public subnets and the database servers are in private subnets. The web servers need to access the internet for updates. Which configuration is required to provide internet access to the web servers while keeping the database servers private?

A.Place both web and database servers in private subnets and use a NAT Gateway for outbound internet access.
B.Attach an Internet Gateway to the VPC and add a route to it in the route tables for both public and private subnets.
C.Attach an Internet Gateway to the VPC and add a route to it only in the route tables for the public subnets.
D.Use a VPC Gateway Endpoint to provide internet access to the web servers.
AnswerC

This is the standard and correct VPC design for a web application: the Internet Gateway is attached to the VPC and a 0.0.0.0/0 route pointing to it is placed only in the route tables of public subnets hosting the web servers. This allows the web servers to receive inbound user traffic and respond over the internet, while the database servers in private subnets have no route to the IGW, keeping them inaccessible from the internet. The VPC's routing architecture ensures proper traffic flow and security.

Why this answer

An Internet Gateway (IGW) is required for any subnet that needs direct internet access. By attaching an IGW to the VPC and adding a default route (0.0.0.0/0) pointing to the IGW only in the public subnet route tables, web servers in those subnets can reach the internet. Database servers in private subnets remain isolated because their route tables lack the IGW route, preventing direct inbound or outbound internet traffic.

Exam trap

The trap here is that candidates often confuse the role of an Internet Gateway with a NAT Gateway, assuming that adding an IGW route to all subnets is necessary for outbound access, but this would break the isolation of private subnets by allowing direct inbound traffic.

How to eliminate wrong answers

Option A is wrong because placing both web and database servers in private subnets would require a NAT Gateway for outbound internet access, but the question specifies web servers are already in public subnets and need direct internet access, not NAT-mediated access. Option B is wrong because adding a route to the Internet Gateway in private subnet route tables would expose database servers to the internet, violating the requirement to keep them private. Option D is wrong because a VPC Gateway Endpoint provides private connectivity to AWS services (e.g., S3, DynamoDB) via the AWS network, not general internet access for web servers.

1103
MCQeasy

A SysOps administrator wants to automate the creation of an Amazon RDS MySQL instance using AWS CloudFormation. Which CloudFormation resource type should be used?

A.AWS::RDS::DBInstance
B.AWS::DynamoDB::Table
C.AWS::AppStream::DirectoryConfig
D.AWS::Redshift::Cluster
AnswerA

This CloudFormation resource directly creates and manages an Amazon RDS database instance, supporting engines such as MySQL, PostgreSQL, MariaDB, Oracle, and SQL Server. You can specify the DB engine, instance class, storage, Multi-AZ configuration, and network placement in a VPC, all within the resource properties. Because the goal is to automate provisioning of an RDS database, AWS::RDS::DBInstance is the correct resource type.

Why this answer

AWS CloudFormation uses resource types to define infrastructure components. For an Amazon RDS MySQL instance, the correct resource type is `AWS::RDS::DBInstance`, which directly maps to creating and configuring a relational database instance, including engine selection (MySQL), allocated storage, and backup settings. This resource type supports all RDS engines and is the standard way to provision RDS databases via CloudFormation.

Option A is correct because `AWS::RDS::DBInstance` is the appropriate resource for creating an RDS MySQL instance. Option B is incorrect because `AWS::DynamoDB::Table` is for Amazon DynamoDB, a NoSQL database service, not a relational MySQL database. Option C is incorrect because `AWS::AppStream::DirectoryConfig` is used for Amazon AppStream 2.0 directory configuration, unrelated to RDS.

Option D is incorrect because `AWS::Redshift::Cluster` is for Amazon Redshift, a data warehouse service, not a relational MySQL database.

Exam trap

The trap here is that candidates may confuse RDS with other database services like DynamoDB or Redshift, or incorrectly assume that a generic 'database' resource exists, when in fact each AWS database service has its own distinct CloudFormation resource type.

How to eliminate wrong answers

Option B is wrong because `AWS::DynamoDB::Table` is used for NoSQL tables in Amazon DynamoDB, not for relational MySQL databases. Option C is wrong because `AWS::AppStream::DirectoryConfig` is used to configure Active Directory for Amazon AppStream 2.0 streaming instances, unrelated to database provisioning. Option D is wrong because `AWS::Redshift::Cluster` provisions Amazon Redshift data warehouse clusters, which use a different engine (PostgreSQL-based) and are not suitable for a standard MySQL RDS instance.

1104
Drag & Dropmedium

Drag and drop the steps to set up an AWS Site-to-Site VPN connection into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First create and attach the virtual private gateway, then define the customer gateway, then create the VPN connection, configure the on-premises router, and verify the tunnel.

1105
MCQmedium

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB) in a single Availability Zone. The application stores session data in an RDS MySQL DB instance. To improve reliability, the company wants to deploy the application across multiple Availability Zones. Which combination of actions should the company take to achieve this? (Choose the correct course of action.)

A.Deploy EC2 instances in a single Availability Zone behind an Application Load Balancer. Enable Multi-AZ for the RDS MySQL DB instance.
B.Deploy EC2 instances in two Availability Zones and place them behind a Network Load Balancer. Keep RDS MySQL as a single-AZ deployment.
C.Deploy EC2 instances in two Availability Zones. Configure an RDS MySQL Read Replica in a second Availability Zone and route read traffic to it.
D.Deploy EC2 instances in two Availability Zones and place them behind an Application Load Balancer. Enable Multi-AZ for the RDS MySQL DB instance.
AnswerD

This architecture provides high availability for both the application and database layers. The EC2 fleet spans two Availability Zones behind an Application Load Balancer, which performs health checks and distributes request traffic to healthy targets, so an instance or AZ failure is absorbed by the remaining targets. Enabling Multi-AZ on RDS MySQL automatically provisions a synchronous standby in a second AZ and performs automatic failover to that standby if the primary fails, thereby eliminating single points of failure across the stack.

Why this answer

Deploying EC2 instances across two Availability Zones behind an Application Load Balancer (ALB) provides high availability for the web tier, while enabling Multi-AZ for RDS MySQL ensures synchronous replication to a standby instance in a different AZ, providing automatic failover and data durability. This combination addresses the requirement to improve reliability by eliminating single points of failure at both the compute and database layers.

Exam trap

The trap here is that candidates may confuse RDS Read Replicas with Multi-AZ deployments, assuming a Read Replica provides high availability, when in fact it only supports read scaling and does not offer automatic failover for the primary database.

How to eliminate wrong answers

Option A is wrong because deploying EC2 instances in a single Availability Zone behind an ALB does not provide high availability for the web tier; a failure in that AZ would still cause an outage. Option B is wrong because a Network Load Balancer (NLB) operates at Layer 4 and does not support HTTP-based routing or session stickiness required for the web application, and keeping RDS MySQL as single-AZ does not provide database redundancy. Option C is wrong because an RDS MySQL Read Replica is asynchronous and cannot be used for automatic failover; it is designed for read scaling, not high availability, and does not provide a synchronous standby for the primary database.

1106
MCQhard

A company runs a critical application on Amazon EC2 instances across multiple Availability Zones. The application stores state data on a shared Amazon EFS file system. The SysOps administrator needs to ensure that the file system remains available if an entire Availability Zone fails. The file system must also provide low-latency access from all instances. Which configuration meets these requirements?

A.Create an EFS file system with the One Zone storage class and mount it from all instances.
B.Create an EFS file system with the Standard storage class, enable replication to another Region, and use DNS failover.
C.Create an EFS file system with the Standard storage class in the same Region, and mount it from all instances using the regional mount target.
D.Create an EFS file system with the Standard storage class, and enable Multi-AZ deployment.
AnswerC

The Standard storage class automatically replicates file system data redundantly across multiple Availability Zones within the Region, providing built-in resilience against an AZ failure. The regional mount target is a single DNS name that resolves to mount targets in each AZ, so instances in any AZ can mount the same file system with low-latency access. If one AZ becomes unavailable, the DNS/ELF service continues to route instances to healthy mount targets, satisfying the high availability requirement.

Why this answer

The EFS Standard storage class stores data redundantly across multiple Availability Zones (AZs) within a Region, ensuring high availability and durability even if an entire AZ fails. By mounting the file system using the regional mount target (which resolves to the EFS file system's regional DNS name), instances in any AZ can access the file system with low latency, as EFS automatically routes traffic to the most appropriate mount target in the same AZ. This configuration meets both the availability and low-latency requirements without additional replication or failover complexity.

Exam trap

The trap here is that candidates confuse EFS's Standard storage class with RDS's Multi-AZ deployment feature, or incorrectly assume that cross-Region replication is necessary for AZ-level fault tolerance, when in fact EFS's regional storage class already provides Multi-AZ redundancy within a single Region.

How to eliminate wrong answers

Option A is wrong because the One Zone storage class stores data only within a single Availability Zone, so if that AZ fails, the file system becomes unavailable, violating the requirement for continued availability during an AZ failure. Option B is wrong because enabling cross-Region replication does not provide low-latency access from all instances within the same Region; it introduces additional latency for cross-Region data access and requires DNS failover, which is not designed for intra-Region AZ failures and adds unnecessary complexity. Option D is wrong because EFS does not support a 'Multi-AZ deployment' configuration; the term 'Multi-AZ' applies to Amazon RDS, not EFS, and EFS inherently provides Multi-AZ redundancy through the Standard storage class, not through a separate deployment option.

1107
MCQeasy

A company has an Auto Scaling group that launches EC2 instances in private subnets. The instances need to download software patches from the internet. Which component must be added to the VPC to allow outbound internet traffic while keeping the instances private?

A.An internet gateway attached to the VPC
B.A VPC peering connection to a VPC with internet access
C.An egress-only internet gateway
D.A NAT gateway in a public subnet
AnswerD

A NAT gateway operates in a public subnet with an Elastic IP and performs source network address translation for outbound IPv4 traffic. Private subnet instances route their default 0.0.0.0/0 traffic to the NAT gateway, which then forwards it to the internet while masking the private instance IPs. This is the standard AWS-managed method to give private instances outbound internet access without exposing them to inbound connections.

Why this answer

A NAT gateway in a public subnet allows EC2 instances in private subnets to initiate outbound traffic to the internet (e.g., to download patches) while preventing unsolicited inbound connections. The NAT gateway translates the private IPs to its own Elastic IP and routes traffic through an internet gateway attached to the VPC, keeping instances private.

Exam trap

The trap here is that candidates often confuse an internet gateway with a NAT gateway, assuming attaching an internet gateway to the VPC alone will give private instances internet access, but private subnets need a NAT device to route traffic through the internet gateway.

How to eliminate wrong answers

Option A is wrong because an internet gateway alone does not enable outbound traffic from private subnets; it only provides a target for routes in public subnets, and instances in private subnets lack a default route to it. Option B is wrong because a VPC peering connection does not provide internet access; it only enables private IP communication between two VPCs, and the peered VPC would still need its own internet gateway and NAT to reach the internet. Option C is wrong because an egress-only internet gateway is designed for IPv6 traffic only, not for IPv4 traffic, and the question implies IPv4 patches.

1108
MCQeasy

A SysOps administrator is troubleshooting an issue where an IAM user cannot launch an EC2 instance. The user has a policy that allows ec2:RunInstances. What is the most likely cause of the failure?

A.The user does not have permissions for supporting actions like CreateNetworkInterface.
B.The user is not using multi-factor authentication (MFA).
C.The user does not have permission to use the KMS key for encryption.
D.The policy is attached to a group instead of the user.
AnswerA

Launching an instance via RunInstances is a complex API call that implicitly requires permission for several supporting EC2 actions, including CreateNetworkInterface, DescribeSubnets, DescribeVpcs, and CreateTags. If the IAM policy grants only "ec2:RunInstances" without including these supporting actions, the call will fail with an UnauthorizedOperation or dependency error. Thus a user with the RunInstances permission can still be blocked because the instance launch cannot complete without the ability to create and attach the necessary network interfaces.

Why this answer

Launching an EC2 instance requires more than just ec2:RunInstances — the principal also needs permissions for dependent actions such as ec2:CreateNetworkInterface, ec2:DescribeImages, ec2:DescribeSubnets, and ec2:DescribeSecurityGroups, depending on the launch configuration. If the policy only grants ec2:RunInstances, the launch fails with an UnauthorizedOperation error on the supporting action. This is the most likely cause given the scenario.

Exam trap

SOA-C02 often tests the misconception that a single allow action (ec2:RunInstances) is sufficient for a composite operation — candidates overlook the dependent actions that EC2 requires under the hood, so they pick MFA or KMS as the cause instead of the missing supporting permissions.

How to eliminate wrong answers

Option B is wrong because MFA is not required by default to launch EC2 instances; while a policy could enforce MFA via aws:MultiFactorAuthPresent, the question states the user has a policy allowing ec2:RunInstances, and MFA absence would produce a different, explicit error only if such a condition existed. Option C is wrong because KMS permissions are only needed if the instance uses an encrypted EBS volume with a customer-managed key; the scenario does not mention encryption, and the default EBS encryption uses the AWS-managed key which does not require explicit KMS grants. Option D is wrong because IAM policies attached to a group are inherited by group members — attaching a policy to a group rather than directly to the user is a valid and common configuration and would not cause a permission failure.

1109
MCQmedium

A SysOps administrator needs to monitor the CPU utilization of an Amazon EC2 instance fleet and send an alert when the average CPU utilization exceeds 80% for 10 consecutive minutes. The administrator also wants to automatically stop the instance if the CPU utilization remains above 90% for 30 minutes to prevent runaway costs. Which combination of AWS services should be used?

A.Amazon CloudWatch alarm + AWS Lambda + AWS Systems Manager Automation
B.Amazon CloudWatch alarm + Amazon Simple Notification Service (SNS) + AWS Lambda
C.Amazon CloudWatch Logs + Amazon EventBridge + AWS Step Functions
D.AWS CloudTrail + Amazon EventBridge + AWS CodePipeline
AnswerB

A CloudWatch alarm monitors the CPU metric and publishes to an SNS topic when the threshold is breached. The SNS topic triggers a Lambda function that calls the EC2 StopInstances API to stop the instance. This is a clean, low-overhead solution.

Why this answer

It uses Amazon CloudWatch alarms to monitor CPU utilization metrics and trigger an SNS topic, which then invokes an AWS Lambda function. The Lambda function can execute the logic to stop the EC2 instance when the alarm state indicates CPU utilization above 90% for 30 minutes, providing automated cost control without manual intervention.

Exam trap

The trap here is that candidates may assume Systems Manager Automation (Option A) is required for instance stop actions, but Lambda is simpler and directly triggered by SNS, while Automation is better suited for complex multi-step workflows like patching or AMI creation.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Automation is designed for predefined runbook-style remediation (e.g., patching, configuration changes) and is not directly triggered by CloudWatch alarms to stop an instance based on a metric threshold; it requires additional orchestration and does not natively support the stop action from an alarm. Option C is wrong because Amazon CloudWatch Logs is for log data, not metric monitoring, and Amazon EventBridge with Step Functions is overkill for a simple stop action; CloudWatch Logs cannot directly trigger alarms on CPU utilization metrics. Option D is wrong because AWS CloudTrail records API activity, not CPU metrics, and Amazon EventBridge with CodePipeline is for CI/CD pipelines, not for monitoring or stopping instances based on utilization thresholds.

1110
MCQhard

A SysOps administrator is setting up Amazon Route 53 for a domain that will be used for a web application. The application requires failover to a backup data center in another region if the primary becomes unhealthy. The administrator creates a failover routing policy with two records (primary and secondary) associated with health checks. After testing, the failover does not occur when the primary endpoint fails. What is the most likely cause?

A.The primary record is not an alias record
B.The domain registrar's nameservers are not pointing to Route 53
C.The health check is configured to monitor the secondary endpoint instead of the primary
D.The TTL on the primary record is set too high
AnswerC

In Route 53 failover routing, the primary record must be associated with a health check that monitors the primary endpoint. If the health check instead monitors the secondary endpoint, it will remain healthy even when the primary goes down, so Route 53 will never see the failure and will continue returning the primary record in responses. This configuration directly prevents failover from triggering, making it the correct explanation for why the secondary resource is never used.

Why this answer

Failover routing relies on health checks to determine the health of the primary endpoint. If the health check is mistakenly configured to monitor the secondary endpoint, it will not assess the primary's health. Consequently, Route 53 will not trigger a failover to the secondary when the primary fails.

Option A is incorrect because alias records are not required for failover; they are only needed for AWS resources. Option B is incorrect because the registrar's nameservers do not affect Route 53's failover logic once the domain is delegated. Option D is incorrect because while a high TTL can delay propagation, it does not prevent failover from occurring; failover depends on health check status, not TTL.

1111
MCQhard

An S3 bucket policy is shown in the exhibit. The AdminRole attempts to upload an object to my-bucket without specifying any server-side encryption header. What will happen?

A.The upload fails because the Allow statement requires encryption, but the Deny statement is evaluated first.
B.The upload succeeds because the Allow statement grants permission to the AdminRole.
C.The upload succeeds because the Deny statement does not apply to the AdminRole.
D.The upload fails because the Deny statement denies PutObject without encryption.
AnswerD

Option 4 is correct because the Deny statement explicitly denies the s3:PutObject action when the request is not protected with server-side encryption using AWS KMS (aws:kms). Since the upload in the scenario is performed without that encryption header, the Deny statement's condition matches the request, and an explicit Deny overrides any Allow from the same bucket policy or from the role's own IAM policies. Therefore, the upload fails with an AccessDenied error.

Why this answer

The Deny statement denies PutObject when encryption is not aws:kms. Since the request has no encryption header, it does not equal aws:kms, so the Deny applies and the upload fails. The Allow statement allows the action only when encryption is aws:kms, so without encryption, it does not apply.

Because the Deny overrides Allow, the upload is denied. Option A is wrong because the Allow does not apply. Option B is wrong because the Deny applies.

Option C is wrong because the Deny does apply to the AdminRole.

1112
MCQmedium

A SysOps administrator is troubleshooting a failed AWS Elastic Beanstalk environment update. The update changed the configuration of the EC2 instances in the Auto Scaling group, but the new instances fail to launch. The administrator checks the Auto Scaling group's scaling activities and sees a 'Failed' status with the message: 'Instance failed to reach the desired state.' What should the administrator check next?

A.Check the IAM role attached to the environment's EC2 instances for missing permissions.
B.Check the account service quotas for EC2 instances.
C.Check the CloudWatch logs for the failed instance to identify application or configuration errors.
D.Check the termination protection setting on the Auto Scaling group.
AnswerC

The Auto Scaling message indicates the instance launched but failed its health checks, so the fault lies in bootstrap or application configuration rather than capacity. CloudWatch logs from the failed instance expose those errors, satisfying the need to find why instances never reached the desired state.

Why this answer

When Elastic Beanstalk instances fail to launch with 'Instance failed to reach the desired state,' the next step is to examine the instance's logs (via CloudWatch Logs or the EB console's logs bundle) to identify configuration or application errors. This message typically indicates the instance launched but failed health checks or initialization, so logs reveal the root cause.

Exam trap

The trap is jumping to IAM or quota issues — the specific message 'failed to reach desired state' points to instance-level health/configuration problems best diagnosed via logs.

How to eliminate wrong answers

Option A is wrong because missing IAM permissions would typically cause a different error (e.g., launch failure at the API level), and the message indicates the instance reached a state but did not become healthy — logs are more direct. Option B is wrong because service quotas would prevent instance launch entirely with a quota-exceeded error, not a 'failed to reach desired state' message. Option D is wrong because termination protection affects instance termination, not launch or health state.

1113
Multi-Selectmedium

A company has a production application running on Amazon ECS with Fargate. The application must be highly available across multiple Availability Zones. Which TWO configurations should be implemented?

Select 2 answers
A.Configure the ECS service to run tasks in a single Availability Zone to reduce network latency.
B.Configure the ECS service to run tasks in at least two Availability Zones.
C.Use the awsvpc network mode for the task definition.
D.Place the ECS service behind an Application Load Balancer.
E.Use Fargate Spot capacity providers to reduce costs.
AnswersB, D

Running ECS tasks in at least two Availability Zones is the fundamental high-availability pattern, because it ensures that if one AZ fails, the application continues serving from the remaining AZs. This placement strategy allows ECS to distribute tasks and maintains capacity during an AZ outage, preventing total loss of service. It directly addresses the need for fault tolerance and is the most appropriate action for a production workload.

Why this answer

Running ECS tasks across at least two Availability Zones ensures that if one AZ fails, the service continues to operate in the other AZ, meeting the high-availability requirement. Option D is correct because placing the ECS service behind an Application Load Balancer (ALB) enables health checks and automatic traffic distribution to healthy tasks, which is essential for maintaining availability during task failures or AZ disruptions.

Exam trap

The trap here is that candidates often confuse network mode (awsvpc) with high-availability configuration, but awsvpc is about networking capabilities (e.g., per-task ENI) and does not inherently provide multi-AZ resilience.

1114
Multi-Selecthard

A SysOps administrator is designing a disaster recovery strategy for a production RDS MySQL database. The database must be recoverable within 15 minutes with a Recovery Point Objective (RPO) of less than 5 seconds. Which TWO actions should the administrator take? (Choose two.)

Select 2 answers
A.Create a read replica in the same AWS Region.
B.Enable Multi-AZ deployment for the RDS instance.
C.Create a cross-Region read replica in another AWS Region.
D.Enable automated backups with a retention period of 35 days.
E.Take manual snapshots every hour.
AnswersB, C

Enabling Multi-AZ deployment for the RDS instance creates a synchronous standby in a different Availability Zone, guaranteeing zero data loss (RPO=0) because transactions are committed on both the primary and standby before a write is acknowledged. Automatic failover is triggered by Amazon RDS within 60–120 seconds, providing high availability within a Region and protecting against AZ failures, database instance failures, and storage failures. This is the most appropriate choice when the specified RPO is below 5 seconds and the disaster recovery scope is limited to Availability Zone outages, as it eliminates asynchronous replication lag entirely.

Why this answer

Multi-AZ deployment (Option B) provides automatic failover to a standby replica in a different Availability Zone, enabling recovery within minutes and meeting the 15-minute RTO. Cross-Region read replicas (Option C) allow asynchronous replication to another region with an RPO typically under 5 seconds, satisfying the RPO requirement. Together, they ensure both rapid failover and minimal data loss.

Exam trap

The trap here is that candidates often confuse Multi-AZ with read replicas, thinking Multi-AZ alone provides cross-region disaster recovery, or they assume automated backups or snapshots can meet a sub-5-second RPO, which they cannot due to their periodic nature.

1115
MCQeasy

A SysOps administrator needs to deploy a new application version to an Auto Scaling group without causing any downtime. The application runs on EC2 instances behind an Application Load Balancer. Which deployment method should the administrator use?

A.Perform an in-place update by updating the launch template and manually replacing instances one by one.
B.Use a rolling update with a batch size of 100% of the instances.
C.Use a rolling update with a batch size of 1 instance and enable the health check grace period.
D.Create a new Auto Scaling group with the new launch template and gradually shift traffic using a load balancer target group.
AnswerC

A rolling update with a batch size of one uses AWS Instance Refresh to replace one instance at a time while keeping the remaining instances online. The health check grace period delays the start of health checks for newly launched instances, preventing them from being terminated before the application has fully initialized. This approach maintains the group's desired capacity and availability throughout the deployment, satisfying the zero-downtime requirement. It is the AWS-recommended way to update an Auto Scaling group with a new launch template without manual intervention or traffic loss.

Why this answer

A rolling update with a batch size of 1 instance replaces instances one at a time, ensuring that the Auto Scaling group always maintains the desired capacity minus one, which prevents downtime. Enabling the health check grace period allows the new instance to pass the ALB health checks before the next instance is terminated, ensuring traffic is only sent to healthy instances.

Exam trap

The trap here is that candidates often confuse a rolling update with a batch size of 100% (which causes downtime) with a blue/green deployment (Option D), but the question specifically asks for a deployment to an existing Auto Scaling group, making the rolling update with a small batch size the correct choice.

How to eliminate wrong answers

Option A is wrong because manually replacing instances one by one is not a built-in Auto Scaling deployment method and risks downtime if the launch template update is applied without proper orchestration, as the Auto Scaling group does not automatically manage the replacement. Option B is wrong because a rolling update with a batch size of 100% of the instances terminates all instances at once, causing downtime since no instances remain to serve traffic during the replacement. Option D is wrong because creating a new Auto Scaling group and gradually shifting traffic using a load balancer target group is a blue/green deployment, which is valid but not the method specified in the question; the question asks for a deployment method to an existing Auto Scaling group, not a separate group.

1116
Multi-Selecthard

A company wants to audit all AWS account activity for compliance. Which THREE AWS services should be used together to achieve this? (Choose three.)

Select 3 answers
A.Amazon CloudWatch Logs
B.AWS Config
C.AWS Trusted Advisor
D.Amazon GuardDuty
E.AWS CloudTrail
AnswersA, B, E

CloudWatch Logs stores, monitors, and queries log data from applications and AWS services, including CloudTrail events, VPC flow logs, and custom logs. You can create metric filters to detect patterns and set alarms for compliance-related events. While it does not natively generate API activity records, it is essential for centralizing and retaining audit logs for operational analysis and alerting. In this scenario, CloudWatch Logs can be used to ingest trail logs for monitoring, but the actual account activity is captured by CloudTrail.

Why this answer

AWS CloudTrail (E) is the foundational service for auditing AWS account activity because it records API calls and management events across the account, delivering the raw audit trail needed for compliance. Amazon CloudWatch Logs (A) is correct because CloudTrail can deliver its event logs to a CloudWatch Logs log group, where they can be retained, searched with metric filters, and alerted on for compliance monitoring. AWS Config (B) is correct because it continuously records resource configuration changes and evaluates them against compliance rules, complementing CloudTrail's activity records with configuration history and drift detection.

AWS Trusted Advisor (C) is not part of an activity-auditing pipeline; it only provides best-practice checks and recommendations. Amazon GuardDuty (D) is a threat-detection service that analyzes logs for malicious behavior, not a primary audit or compliance-recording service.

Exam trap

The trap here is that candidates often confuse AWS Trusted Advisor's advisory recommendations with actual audit logging, or they think GuardDuty's threat detection logs are sufficient for compliance auditing, when in fact only CloudTrail, Config, and CloudWatch Logs together provide the necessary historical record of all account activity and configuration changes.

1117
MCQmedium

A SysOps Administrator is setting up a VPC peering connection between two VPCs (VPC-A and VPC-B) in different AWS accounts. After the peering connection is accepted, instances in VPC-A cannot ping instances in VPC-B. Both VPCs have non-overlapping CIDR blocks. What is the MOST likely cause?

A.The route tables in both VPCs do not have routes to the peer VPC CIDR.
B.VPC peering does not support cross-account connections.
C.The CIDR blocks overlap, causing routing conflicts.
D.The security groups in VPC-B do not allow inbound ICMP traffic from VPC-A.
AnswerA

For a VPC peering connection to function, each VPC must have an explicit route in its route table that targets the peering connection (pcx-*) and points to the peer VPC's CIDR block. Even if the peering connection is in the 'active' state, traffic will be dropped at the source VPC if no such route exists, because the source instance has no path to the destination CIDR. Both route tables must be updated for bidirectional communication; a missing route on either side breaks connectivity for traffic originating in that direction, and ICMP ping is a common test that will fail immediately without these routes.

Why this answer

The most likely cause is that the route tables in both VPCs do not have routes to the peer VPC CIDR. Even after a VPC peering connection is accepted, traffic cannot flow between the VPCs unless explicit routes are added to each VPC's route table pointing to the CIDR block of the peer VPC, with the VPC peering connection as the target. Without these routes, instances in VPC-A have no path to reach instances in VPC-B, so ping fails.

Exam trap

The trap here is that candidates often assume security groups or NACLs are the primary cause of connectivity issues, but the foundational routing layer must be correctly configured first for any traffic to flow across a VPC peering connection.

How to eliminate wrong answers

Option B is wrong because VPC peering does support cross-account connections; you simply need to accept the peering request from the other account. Option C is wrong because the question explicitly states that the CIDR blocks are non-overlapping, so routing conflicts from overlap are not the issue. Option D is wrong because while security group rules could block ICMP, the most likely cause is the missing route tables, as routing is a prerequisite for any traffic to reach the destination before security groups are evaluated.

1118
MCQhard

A SysOps administrator manages multiple AWS accounts and wants to create a single Amazon CloudWatch dashboard that displays real-time metrics from all accounts in one view. The administrator needs to avoid managing separate dashboards for each account. Which solution should the administrator implement?

A.Use CloudWatch cross-account observability by setting up a monitoring account and sharing metrics from source accounts.
B.Export CloudWatch metrics to Amazon QuickSight and create a dashboard there.
C.Use AWS Config aggregator to collect metrics and display in CloudWatch.
D.Create a Lambda function that periodically pulls metrics from each account and publishes to a central account's CloudWatch.
AnswerA

CloudWatch cross-account observability uses a designated monitoring account in AWS Organizations to search, visualize, and create dashboards from source-account metrics without duplicating or exporting metric data. Enabling resource discovery from source accounts exposes their CloudWatch telemetry read-only, so dashboards show live data and remain useful for real-time operations rather than static exports.

Why this answer

CloudWatch cross-account observability allows you to designate a monitoring account that can view metrics, logs, and traces from multiple source accounts. This feature uses AWS Organizations or CloudWatch cross-account links to share observability data in real time, enabling a single dashboard that aggregates metrics from all accounts without needing separate dashboards.

Exam trap

The trap here is that candidates may confuse AWS Config aggregator (which aggregates configuration data) with CloudWatch cross-account observability (which aggregates monitoring metrics), leading them to choose a service that does not handle real-time metric visualization.

How to eliminate wrong answers

Option B is wrong because Amazon QuickSight is a business analytics service for interactive dashboards, not a real-time CloudWatch metrics viewer; it requires exporting metrics via API calls and cannot provide the low-latency, native CloudWatch dashboard experience. Option C is wrong because AWS Config aggregator collects configuration and compliance data, not real-time CloudWatch metrics; it is designed for resource inventory and rule evaluation, not for monitoring metric streams. Option D is wrong because creating a Lambda function to periodically pull metrics introduces latency, complexity, and potential data staleness; CloudWatch cross-account observability provides native, real-time streaming without custom code or polling overhead.

1119
MCQhard

A company runs a production web application on AWS using Auto Scaling groups (ASGs) behind an Application Load Balancer (ALB). The application state is stored in an Amazon RDS for MySQL Multi-AZ DB instance. The application experiences periodic traffic spikes, and the current ASG uses a simple scaling policy based on average CPU utilization. Recently, during a spike, the application became unresponsive for several minutes. The CloudWatch metrics show that the CPU utilization on the RDS instance peaked at 80%, and the DB Connections metric reached the maximum allowed. The read replica lag increased to over 10 seconds during the spike. The web servers are stateless and scale out quickly. The operations team needs to improve the reliability and performance of the application to handle future spikes. Which solution should the team implement?

A.Increase the desired capacity of the ASG and add more read replicas to distribute the database load.
B.Increase the DB instance size to a larger instance class and implement an Amazon ElastiCache cluster to cache frequent database queries.
C.Migrate the database to Amazon DynamoDB with auto scaling and rewrite the application to use a serverless architecture with AWS Lambda.
D.Reduce the maximum connections parameter on the RDS instance to prevent connection exhaustion and modify the application code to reduce the number of database queries.
AnswerB

Scaling the DB instance to a larger class directly increases available vCPU, memory, and the maximum connection limit, giving the primary database the headroom needed to absorb the current CPU spike. Implementing an ElastiCache cluster (for example, Redis or Memcached) in front of the database caches the results of frequent, repetitive queries, so those reads never reach the RDS instance, which lowers CPU usage and frees connections for writes and less frequent queries. Together these actions provide both immediate compute capacity and durable read-path relief, exactly matching the incident's requirements.

Why this answer

The RDS instance is hitting connection limits and high CPU, causing unresponsiveness. Increasing the DB instance size provides more CPU and memory, allowing it to handle more connections and process queries faster. Adding an ElastiCache cluster offloads frequent read queries from the database, reducing the load on RDS.

This combination addresses both the connection exhaustion and CPU bottleneck, improving performance during spikes.

Exam trap

SOA-C02 often tests the misconception that read replicas can solve all scaling issues, but they only help with read-heavy workloads and do not alleviate connection limits on the primary.

How to eliminate wrong answers

Option A is wrong because adding more read replicas does not help with write-heavy workloads or connection limits on the primary; the application likely uses the primary for writes, and read replicas only offload reads. Option C is wrong because migrating to DynamoDB and Lambda is a major re-architecture that may not be necessary and could introduce new complexities; it's not the most direct solution. Option D is wrong because reducing max connections would worsen the problem by causing connection failures; it doesn't address the root cause of high load.

1120
MCQmedium

Refer to the exhibit. An IAM user has this policy attached. The user tries to start an EC2 instance that has no tags. What will happen?

A.The user will be allowed because the condition only applies if the tag exists
B.The user will be allowed because the resource ARN includes a wildcard
C.The user will be allowed because the policy does not explicitly deny the action
D.The user will be denied because the instance does not have the required tag
AnswerD

The policy includes a condition that requires the instance to have a tag key Environment with value 'Production'. Since the instance in question does not have that tag, the condition is not met, so the allow statement cannot be applied. IAM's default is to deny any request not explicitly allowed, so the user is denied permission to start the instance. The condition must be satisfied even if the resource ARN matches.

Why this answer

The IAM policy includes a condition that requires the EC2 instance to have a tag with key 'Environment' and value 'Production'. When the instance has no tags, the condition evaluates to false, and the default behavior for IAM policies is to deny access when a condition is not met. Since the policy does not explicitly allow the action without the tag, the request is implicitly denied.

Exam trap

The trap here is that candidates often assume a missing tag causes the condition to be ignored or treated as 'not applicable', but in IAM, a missing tag causes the condition to evaluate to false, leading to an implicit deny.

How to eliminate wrong answers

Option A is wrong because the condition does not 'only apply if the tag exists'; the condition key 'aws:ResourceTag' evaluates to false when the tag is absent, resulting in denial. Option B is wrong because the resource ARN wildcard does not override the condition; conditions are evaluated independently and must be satisfied for the allow to take effect. Option C is wrong because IAM policies are deny-by-default; an allow statement with an unsatisfied condition does not grant permission, so the action is implicitly denied.

1121
MCQmedium

A SysOps administrator creates the above IAM policy for a user. The user reports that they cannot delete an object in the bucket 'my-bucket' even though they are using MFA. What is the likely cause?

A.The resource ARN is missing the bucket-level permission.
B.The condition key aws:MultiFactorAuthPresent is incorrectly spelled.
C.The user is not using MFA when making the API call.
D.The policy does not include s3:DeleteObjectVersion.
AnswerC

The condition likely sets `aws:MultiFactorAuthPresent` to `false` or uses the `Bool` operator to deny access when MFA is absent. Because the user made the API call without an MFA token, the condition evaluates to `false`, triggering the `Deny` statement. This is the explicit reason why the delete request fails, as the policy mandates MFA for all actions by this user.

Why this answer

The policy requires MFA for all s3:DeleteObject actions, as indicated by the condition key aws:MultiFactorAuthPresent set to 'true'. If the user reports they cannot delete an object despite using MFA, the most likely cause is that they are not actually using MFA when making the API call — for example, they may have authenticated with long-term credentials (access key/secret key) without a multi-factor authentication session. The condition key checks the presence of an MFA-authenticated session token, not just whether the user has MFA enabled on their account.

Exam trap

The trap here is that candidates confuse 'having MFA enabled on the user account' with 'using MFA in the API call session' — the condition key aws:MultiFactorAuthPresent checks the latter, not the former.

How to eliminate wrong answers

Option A is wrong because the resource ARN 'arn:aws:s3:::my-bucket/*' correctly specifies object-level permissions for all objects in the bucket, and bucket-level permissions (e.g., s3:ListBucket) are not required for the s3:DeleteObject action. Option B is wrong because the condition key 'aws:MultiFactorAuthPresent' is correctly spelled — it is case-sensitive and matches the official AWS documentation. Option D is wrong because s3:DeleteObjectVersion is a separate action for deleting a specific version of an object, and the policy already includes s3:DeleteObject, which covers deleting the current version of an object (the most common operation).

1122
MCQhard

A company stores application log files in an Amazon S3 bucket. The logs are accessed frequently for the first 30 days, then rarely accessed but must be retrievable within 12 hours. After 1 year, the logs must be archived for compliance with a retention period of 5 years, during which retrievals are expected to be extremely rare (one or two per year) and retrieval time of 12 hours is acceptable. The SysOps administrator wants to minimize storage costs. Which S3 lifecycle policy configuration should be used?

A.After 30 days, transition to S3 Standard-IA; after 365 days, transition to S3 Glacier Deep Archive; delete after 5 years.
B.After 30 days, transition to S3 Glacier Flexible Retrieval; after 365 days, transition to S3 Glacier Deep Archive; delete after 5 years.
C.After 30 days, transition to S3 Glacier Flexible Retrieval; delete after 5 years.
D.After 30 days, transition to S3 Glacier Deep Archive; delete after 5 years.
AnswerB

This lifecycle provides cost-optimized storage: S3 Standard for the first 30 days (frequent access), S3 Glacier Flexible Retrieval for the next 335 days (rare access, 12-hour retrieval acceptable), and S3 Glacier Deep Archive for the final 4+ years (extremely rare access, lowest cost). This minimizes overall costs while meeting retrieval requirements.

Why this answer

It uses S3 Glacier Flexible Retrieval for the first year after the initial 30 days, which meets the 12-hour retrieval requirement at lower cost than S3 Standard-IA, then transitions to S3 Glacier Deep Archive for the remaining 4 years to minimize storage costs for extremely rare retrievals. The lifecycle policy transitions objects after 30 days to S3 Glacier Flexible Retrieval (retrieval time minutes to 12 hours), then after 365 days to S3 Glacier Deep Archive (retrieval time 12 hours), and deletes after 5 years, aligning with the access patterns and compliance retention.

Exam trap

The trap here is that candidates often choose S3 Standard-IA (Option A) because it seems logical for infrequent access, failing to recognize that S3 Glacier Flexible Retrieval provides lower storage costs for data that is rarely accessed but still needs retrieval within 12 hours, and that a multi-tier lifecycle (Option B) is more cost-effective than a single transition.

How to eliminate wrong answers

Option A is wrong because transitioning to S3 Standard-IA after 30 days is not cost-optimal for data that is rarely accessed after the first 30 days; S3 Glacier Flexible Retrieval offers lower storage costs for infrequent access with a 12-hour retrieval window. Option C is wrong because it does not transition to S3 Glacier Deep Archive after 1 year, missing the opportunity to further reduce storage costs for the 4-year archival period where retrievals are extremely rare. Option D is wrong because transitioning directly to S3 Glacier Deep Archive after 30 days is premature and more expensive than using S3 Glacier Flexible Retrieval for the first year, as Deep Archive has higher retrieval costs and is designed for long-term archival, not for data that may still be accessed occasionally within 12 hours.

1123
MCQeasy

A company is using Amazon RDS for MySQL and needs to encrypt data at rest. Which action should be taken to enable encryption?

A.Use the RDS console to enable encryption on the existing DB instance.
B.Use AWS KMS to create a customer master key and assign it to the existing DB instance.
C.Modify the existing RDS DB instance and enable encryption.
D.Create a new RDS DB instance with encryption enabled.
AnswerD

The only supported way to get encrypted-at-rest storage for data that currently lives in an unencrypted RDS instance is to create a new DB instance with encryption enabled. This is done either by taking a snapshot of the original instance and restoring it with encryption toggled on, or by launching a new encrypted instance and migrating the data with a tool such as AWS DMS. During creation, you choose an AWS KMS key, and once the instance is created, encryption cannot be removed or changed.

Why this answer

Amazon RDS for MySQL does not support enabling encryption on an existing DB instance. Encryption at rest must be enabled at the time of instance creation. Therefore, the correct action is to create a new RDS DB instance with encryption enabled, and then migrate the data from the unencrypted instance to the new encrypted one.

Exam trap

The trap here is that candidates assume encryption can be toggled on an existing RDS instance via a modification, similar to enabling encryption on an EBS volume, but RDS requires encryption to be set at launch and cannot be added later.

How to eliminate wrong answers

Option A is wrong because the RDS console does not allow enabling encryption on an existing DB instance; encryption can only be enabled during creation. Option B is wrong because while AWS KMS customer master keys are used for RDS encryption, you cannot assign a KMS key to an existing unencrypted DB instance; encryption must be enabled at launch. Option C is wrong because modifying an existing RDS DB instance does not support enabling encryption; the 'Modify' action does not include an encryption toggle for existing instances.

1124
MCQeasy

A company has two VPCs in the same AWS region. VPC A hosts a web application, and VPC B hosts a database. The SysOps administrator needs to enable private IP communication between the two VPCs without using the public internet. The administrator wants a simple, low-cost solution that uses the AWS network backbone. Which AWS service should be used?

A.VPC Peering
B.AWS Transit Gateway
C.AWS Direct Connect
D.AWS Site-to-Site VPN
AnswerA

VPC Peering establishes a direct, logical connection between exactly two VPCs, using a 1:1 relationship that relies on AWS's existing routing infrastructure—no gateways, virtual appliances, or dedicated physical lines are required. Traffic between the peered VPCs uses private IPv4 or IPv6 addresses and stays entirely on the AWS global network, avoiding public-internet exposure and providing low, predictable latency. It is cost-effective for a pair of VPCs because there is no hourly fee or minimum revenue commitment; you pay only for inter-VPC data transfer, which is usually significantly cheaper than traffic traversing the internet. Although VPC peering is non-transitive, that property is irrelevant for a two-VPC architecture, making it the simplest and most operationally efficient solution for this requirement.

Why this answer

VPC Peering allows direct, private IP connectivity between two VPCs using the AWS network backbone without traversing the public internet. It is the simplest and most cost-effective solution for connecting exactly two VPCs in the same region, as there are no additional hourly charges beyond data transfer costs, and no intermediate devices or bandwidth limitations are introduced.

Exam trap

The trap here is that candidates may choose AWS Transit Gateway because it is a powerful networking hub, but the question explicitly asks for a simple, low-cost solution for only two VPCs, making VPC Peering the correct choice despite Transit Gateway's broader capabilities.

How to eliminate wrong answers

Option B (AWS Transit Gateway) is wrong because it is designed for hub-and-spoke connectivity across many VPCs and incurs an hourly attachment fee, making it unnecessarily complex and more expensive for a simple two-VPC connection. Option C (AWS Direct Connect) is wrong because it is a dedicated physical connection from an on-premises data center to AWS, not a service for connecting two VPCs within the same region, and it involves significant setup costs and lead times. Option D (AWS Site-to-Site VPN) is wrong because it establishes encrypted tunnels over the public internet between on-premises networks and AWS, not between two VPCs, and it introduces additional latency and complexity compared to VPC Peering.

1125
MCQeasy

A company has enabled AWS CloudTrail in all regions and is logging to an S3 bucket. The security team needs to be alerted within minutes if any IAM user creates a new access key. What is the MOST efficient way to achieve this?

A.Enable S3 event notifications on the CloudTrail bucket to trigger a Lambda function that parses logs and sends an alert.
B.Use AWS Config rules to detect changes to IAM access keys and trigger an SNS notification.
C.Configure CloudTrail to send logs to CloudWatch Logs. Create a metric filter for the IAM event 'CreateAccessKey' and set a CloudWatch alarm that sends an SNS notification.
D.Run a script on an EC2 instance that polls CloudTrail API for new events every minute and sends alerts.
AnswerC

CloudTrail can be configured to deliver all management events to a CloudWatch Logs log group in near-real-time, allowing you to analyze them with metric filters. By creating a metric filter that matches the event name "CreateAccessKey" and setting a CloudWatch alarm on the resulting metric, you get an SNS notification as soon as the event occurs, with minimal latency and no need for custom code or compute resources. This is the serverless best practice for security event monitoring on AWS.

Why this answer

CloudTrail can be configured to deliver events to CloudWatch Logs, where a metric filter can be created to match the 'CreateAccessKey' event. A CloudWatch alarm based on that metric filter can then trigger an SNS notification within minutes, providing the most efficient and native AWS solution for real-time alerting without custom code or polling.

Exam trap

The trap here is that candidates often choose S3 event notifications (Option A) because they think it's the simplest, but they overlook the built-in CloudWatch Logs integration which provides faster, more reliable, and fully managed alerting without custom code.

How to eliminate wrong answers

Option A is wrong because S3 event notifications on the CloudTrail bucket are not real-time; they can have delays and require a Lambda function to parse logs, which is less efficient than using CloudWatch metric filters. Option B is wrong because AWS Config rules are designed for compliance and configuration tracking, not for real-time event-driven alerting; they evaluate resources periodically or on configuration changes, not within minutes of an API call. Option D is wrong because running a script on an EC2 instance that polls the CloudTrail API every minute introduces latency, operational overhead, and a single point of failure, making it less efficient than the serverless, event-driven approach in option C.

Page 14

Page 15 of 16

Page 16