Courseiva

AWS Certified SysOps Administrator Associate SOA-C02 (SOA-C02) — Questions 151–225

1169 questions total · 16pages · All types, answers revealed

Page 2

Page 3 of 16

Page 4
151
MCQmedium

An organization needs to enforce that all Amazon EC2 instances launched in a specific AWS account are created from a baseline Amazon Machine Image (AMI) that includes required security patches. The AMI ID is ami-0abcdef1234567890. What is the MOST efficient way to enforce this requirement?

A.Use an AWS Config rule to mark non-compliant instances and automatically terminate them.
B.Use an AWS Lambda function that is triggered by EC2 launch events to terminate non-compliant instances.
C.Use AWS CloudTrail to monitor and alert on any instance launched with a different AMI.
D.Use an IAM policy that denies the ec2:RunInstances action unless the AMI ID matches the approved one.
AnswerD

An IAM policy can use the ec2:ImageId condition key to deny ec2:RunInstances for any AMI that is not the approved one. Because IAM policies are evaluated during API authorization, this acts as a hard, pre-emptive block: the request is denied by AWS before any instance resource is created. This is a true preventive control and meets the organization's enforcement requirement directly. To implement it, add a statement with Effect: Deny, Action: ec2:RunInstances, and Condition: StringNotEquals on the ec2:ImageId key.

Why this answer

An IAM policy with a condition that denies ec2:RunInstances unless the AMI ID matches the approved one (ami-0abcdef1234567890) prevents non-compliant instances from being launched at all. This is the most efficient approach as it enforces the requirement proactively at the API level, avoiding the need for reactive detection or termination.

Exam trap

The trap here is that candidates often choose reactive solutions (like AWS Config or Lambda) because they seem more flexible, but the question asks for the 'MOST efficient' way, which is preventive enforcement via IAM policies at the API level.

How to eliminate wrong answers

Option A is wrong because AWS Config rules can mark non-compliant instances and trigger remediation (e.g., termination), but this is reactive—instances are launched before being detected and terminated, which wastes resources and may cause disruption. Option B is wrong because an AWS Lambda function triggered by EC2 launch events (via CloudTrail or EventBridge) also reacts after the instance is launched, leading to unnecessary resource consumption and potential race conditions. Option C is wrong because AWS CloudTrail only logs API calls for auditing and alerting; it cannot enforce or prevent the launch of non-compliant instances, making it purely detective and not preventive.

152
MCQhard

A company uses AWS CloudFormation to deploy a stack that includes an Amazon RDS DB instance with automated backups enabled. The stack is deleted and then recreated. The administrator wants to restore data from the backup of the original DB instance. How can this be achieved?

A.Restore from the latest automated backup stored in S3.
B.Restore from the automated backup snapshot that is retained after deletion.
C.Use the RDS recycle bin to recover the deleted DB instance.
D.Data cannot be restored because automated backups are deleted when the DB instance is deleted.
AnswerD

When an RDS DB instance is deleted, all automated backups—including system snapshots and transaction logs—are also deleted by default, unless you had previously chosen to create a final snapshot. Since the CloudFormation stack deletion did not specify that a final snapshot was taken, the automated backups were lost along with the instance. Therefore, the data cannot be restored because no independent backup artifact survives the instance deletion.

Why this answer

When an RDS DB instance is deleted, its automated backups are deleted along with it — they are tied to the instance's lifecycle and are not retained independently. Because the CloudFormation stack deletion removed the original DB instance, the automated backups no longer exist, so there is nothing to restore from. Unless a manual snapshot was taken beforehand, the data is unrecoverable.

Exam trap

SOA-C02 often tests the misconception that automated backups persist after instance deletion like manual snapshots do — candidates must remember automated backups die with the instance unless explicitly retained.

How to eliminate wrong answers

Option A is wrong because RDS automated backups are not stored as user-accessible objects in S3; they live in RDS-managed backup storage and cannot be restored directly from an S3 bucket. Option B is wrong because automated backup snapshots are deleted when the DB instance is deleted — they are not retained after deletion (only manual snapshots persist). Option C is wrong because RDS has no 'recycle bin' feature; that concept does not exist in RDS, so there is no mechanism to recover a deleted instance that way.

153
Multi-Selecthard

A company runs a stateless web application on EC2 instances behind an Application Load Balancer. The application is deployed in an Auto Scaling group with a minimum of 2 and maximum of 10 instances. During a traffic spike, the Auto Scaling group launches new instances, but the new instances are immediately marked as unhealthy by the ALB and terminated. What could be the cause? (Choose TWO.)

Select 2 answers
A.The health check path is misconfigured.
B.The Auto Scaling group does not have sufficient capacity in the target AZ.
C.The instances do not have the required IAM role to register with the ALB.
D.The security group for the instances does not allow inbound traffic from the ALB.
E.The instances are launched with a larger instance type than expected.
AnswersA, D

The ALB health check sends HTTP(S) requests to a configured path and expects a 2xx or 3xx response within a set timeout. If the path is incorrect (e.g., a missing endpoint or a route that returns 404), the health check fails, causing the ALB to mark the instance unhealthy and eventually terminate it. This is the most common cause of healthy-appearing instances being deregistered, and correcting the path to a verified reachable endpoint resolves the issue.

Why this answer

Option A is correct because if the ALB health check path is misconfigured (for example, pointing to a non-existent URL or wrong port), the target group health checks will fail and the ALB will mark the newly launched instances as unhealthy, causing the Auto Scaling group to terminate them. Option D is correct because the ALB must be able to reach the instances on the health check and traffic ports; if the instances' security group does not allow inbound traffic from the ALB's security group (or from the ALB subnet CIDRs), the health checks will time out and the instances will be marked unhealthy. Option B is not correct because insufficient capacity in a target AZ would prevent instances from launching at all, not cause them to launch and then be marked unhealthy by the ALB.

Option C is not correct because EC2 instances do not need an IAM role to register with an ALB; target registration is handled by the Auto Scaling group or ELB service itself, not by instance-level IAM permissions. Option E is not correct because a larger instance type does not inherently cause ALB health checks to fail; instance size is unrelated to health check success.

Exam trap

The trap here is that candidates often overlook the security group requirement for inbound traffic from the ALB, assuming that the ALB can always reach instances, or they confuse IAM roles with network-level registration requirements.

154
MCQmedium

A company runs a critical web application on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). The application uses session stickiness (sticky sessions) to maintain user sessions. The SysOps administrator notices that when instances are replaced during a scale-in or failure event, users lose their session data. The administrator needs to preserve session data across instance failures without losing stickiness benefits. What should the administrator do?

A.Disable sticky sessions on the ALB and configure the application to store session data in an external session store like Amazon ElastiCache for Redis.
B.Increase the stickiness duration to a very high value so that sessions are not lost during brief interruptions.
C.Change the Auto Scaling group to use a larger instance type to handle more sessions per instance, reducing the likelihood of session loss.
D.Configure the Auto Scaling group to use a larger minimum size and a lower maximum, so instances are less likely to be terminated.
AnswerA

Disabling sticky sessions and moving session state to an external service like ElastiCache for Redis decouples user session data from individual EC2 instance lifecycles. When an ALB routes requests to any healthy instance, the instance can retrieve the session from Redis, so a failed or terminated instance does not lose state. Because ElastiCache replicates across AZs, sessions also survive single-cache-node failures, making the app tier effectively stateless and highly resilient.

Why this answer

It eliminates the dependency on stickiness by storing session data externally in Amazon ElastiCache for Redis. This way, if an instance fails or is scaled in, any other instance can retrieve the session data from the shared cache, preserving the user session. Disabling sticky sessions is necessary because with external storage, stickiness is no longer needed and can cause uneven load distribution.

Exam trap

The trap is that candidates may think they need to keep stickiness active, but the correct solution is to remove stickiness and store session data externally. Stickiness only provides routing affinity, not data persistence, and with external storage, any instance can serve any session.

How to eliminate wrong answers

Option B is wrong because increasing the stickiness duration does not preserve session data when an instance is terminated or fails; it only controls how long the ALB remembers the routing cookie, but the session data stored locally on the instance is still lost. Option C is wrong because using a larger instance type does not solve the fundamental problem of session data being stored locally; it only reduces the frequency of scale-in events but does not protect against instance failures or replacements. Option D is wrong because adjusting the Auto Scaling group's minimum and maximum sizes does not prevent session loss during scale-in or failure events; it only changes the number of instances running, but any instance that is terminated or replaced will still lose its locally stored session data.

155
MCQeasy

A company uses Amazon Route 53 for DNS. They want to ensure that if the primary web server fails, traffic is automatically routed to a secondary server in another region. Which routing policy should be used?

A.Simple routing policy
B.Failover routing policy
C.Latency routing policy
D.Weighted routing policy
AnswerB

Failover routing is designed specifically for active-passive failover: you create two (or more) records with the same name and type, designate one as primary and one as secondary, and attach health checks. Route 53 monitors the health of the primary and automatically routes traffic to the secondary if the primary becomes unhealthy. This behavior directly matches the requirement to ensure DNS-based failover when an endpoint fails.

Why this answer

The Failover routing policy in Amazon Route 53 is specifically designed for active-passive failover configurations. When the primary endpoint fails a health check, Route 53 automatically returns the secondary record in DNS responses, ensuring traffic is routed to the secondary server in another region. This directly meets the requirement for automatic failover between primary and secondary web servers.

Exam trap

The trap here is that candidates often confuse Failover routing policy with Weighted routing policy, mistakenly thinking weights can be set to 100/0 for failover, but Weighted routing does not automatically fail over based on health checks—it requires manual intervention or custom automation to adjust weights.

How to eliminate wrong answers

Option A is wrong because Simple routing policy only returns a single record (e.g., one IP) and does not support health checks or automatic failover; if the primary server fails, DNS continues to return the same IP, causing downtime. Option C is wrong because Latency routing policy routes traffic based on the lowest network latency to the client, not on the health or availability of endpoints; it does not provide failover between primary and secondary servers. Option D is wrong because Weighted routing policy distributes traffic across multiple endpoints based on assigned weights, but it does not automatically fail over to a secondary endpoint when the primary fails unless combined with health checks and manual weight adjustment, which is not the intended use for active-passive failover.

156
MCQmedium

A company is using AWS Organizations with SCPs to restrict access to services. The security team wants to ensure that no IAM user can create access keys, but the SCP is not working as expected. What is the most likely cause?

A.The SCP is applied to the root OU but not inherited by the account.
B.The SCP is applied to a member account, but the IAM user is in the management account.
C.The SCP has a Deny effect, but it takes 24 hours to apply.
D.The SCP only applies to root users, not IAM users.
AnswerB

SCPs act as a permission boundary for member accounts, but they have no effect on the management account (also known as the payer account) in AWS Organizations. IAM users and roles in the management account retain their full permissions even if an SCP is attached to a member account. Therefore, if the IAM user resides in the management account, the SCP applied to the member account cannot possibly restrict that user's access, making this the correct explanation.

Why this answer

SCPs apply only to member accounts, not the management account. If the IAM user is in the management account, the SCP cannot restrict their actions. Option A is incorrect because SCPs are inherited from the root OU to all member accounts, so the SCP would be applied if the account were a member account; the issue is that the user is in the management account.

Option C is wrong because SCPs take effect almost immediately, not 24 hours. Option D is wrong because SCPs apply to all principals (including IAM users) in member accounts, not just root users.

157
MCQmedium

A company runs a critical production database on Amazon RDS for MySQL with a Multi-AZ deployment. The database experiences a primary instance failure. The SysOps administrator needs to understand exactly how the failover process worked and why the application experienced a longer-than-expected downtime. Which AWS service or feature should the administrator use to review detailed events and actions during the failover?

A.AWS Personal Health Dashboard
B.Amazon RDS Performance Insights
C.Amazon CloudWatch Logs
D.AWS CloudTrail
AnswerA

The AWS Personal Health Dashboard (PHD) is the correct resource because it surfaces service health events that are specific to your AWS account and resources. For an RDS Multi-AZ failover, PHD provides a detailed event with the exact time, date, affected database instance, and the cause of the failover (e.g., infrastructure maintenance, hardware degradation, or patching). PHD also includes a timeline of activity and often links to related operational guidance, making it the authoritative source for reviewing automated failover details. Unlike generic service health dashboards, PHD filters events down to your particular resources, ensuring you see the actual failover incident that occurred.

Why this answer

AWS Personal Health Dashboard provides a personalized view of the health of AWS services and resources, including detailed event logs for RDS Multi-AZ failovers. It surfaces the exact sequence of actions (e.g., DNS record update, failover initiation, completion) and any underlying AWS infrastructure issues that caused the extended downtime, such as degraded hardware or network latency. This is the correct tool because it gives the administrator a chronological, AWS-side account of the failover process, which is not available through other services.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (which records API calls) with the ability to view internal service events, but CloudTrail does not capture automatic failover processes or infrastructure health events that are only available through AWS Personal Health Dashboard.

How to eliminate wrong answers

Option B is wrong because Amazon RDS Performance Insights focuses on database performance metrics (e.g., CPU, memory, SQL query load) and does not log failover events or infrastructure-level actions. Option C is wrong because Amazon CloudWatch Logs can capture RDS log files (e.g., error logs, slow query logs) but does not inherently record the failover process steps or AWS-side infrastructure events; it would require custom agent configuration to capture such data. Option D is wrong because AWS CloudTrail records API calls made to the RDS service (e.g., ModifyDBInstance) but does not capture internal failover events or DNS propagation details that occur automatically during a Multi-AZ failover.

158
MCQhard

A company has a production RDS for PostgreSQL instance. They need to recover from a logical corruption that occurred 2 hours ago. Which recovery method will minimize data loss?

A.Restore from the latest automated snapshot taken 1 hour ago.
B.Use pg_dump to export the database and restore it.
C.Fail over to the read replica in another AZ.
D.Perform a point-in-time recovery to a time just before the corruption occurred.
AnswerD

Point-in-Time Recovery (PITR) leverages automated backups and WAL transaction logs to restore a new database instance to any time within the backup retention window, typically with accuracy to a second. By selecting a time immediately before the corrupt transaction executed, you recover a clean dataset while retaining all legitimate transactions that occurred up to that moment. This is the intended RDS technique for logical corruption incidents.

Why this answer

Point-in-time recovery (PITR) for RDS PostgreSQL allows you to restore the database to any second within the backup retention period, using automated backups and transaction logs. By restoring to a time just before the logical corruption occurred (2 hours ago), you can recover the database to its state before the corruption, minimizing data loss to only transactions that happened after that point. This is the only option that can target a specific moment before the corruption, unlike a snapshot which is a fixed point in time.

Exam trap

The trap here is that candidates often assume a read replica or a recent snapshot can protect against logical corruption, but both replicate the corruption because they are copies of the same data, whereas point-in-time recovery leverages transaction logs to rewind to a clean state.

How to eliminate wrong answers

Option A is wrong because restoring from the latest automated snapshot taken 1 hour ago would recover data from that snapshot time, which is after the corruption occurred (2 hours ago), so the corruption would be included in the restored data, resulting in data loss of the entire 2-hour window. Option B is wrong because pg_dump exports the current state of the database, which already includes the logical corruption; restoring from that dump would simply reapply the corruption. Option C is wrong because failing over to a read replica in another AZ promotes an asynchronous replica that replicates the same corrupted data from the primary instance, so it does not provide a point-in-time recovery before the corruption.

159
Multi-Selecteasy

A SysOps administrator is implementing an automated backup solution for Amazon RDS databases. The solution must support point-in-time recovery and cross-region disaster recovery. Which TWO AWS services or features should be used?

Select 2 answers
A.Manual DB snapshots.
B.Cross-region read replicas.
C.Automated backups with a retention period.
D.Amazon S3 lifecycle policies.
E.Automated cross-region snapshot copy.
AnswersC, E

Automated backups with a retention period enable RDS to automatically perform daily backups and capture transaction logs every five minutes, allowing point-in-time recovery to any second within the configured retention window (default 7 days, maximum 35 days). This option is technically valid for automated backups, but it is confined to a single Region; it does not provide cross-Region durability or disaster recovery, so it fails the specific requirement for a backup copy stored in a different geographical location.

Why this answer

Option C (Automated backups with a retention period) is correct because RDS automated backups capture daily snapshots plus transaction logs, enabling point-in-time recovery (PITR) to any second within the retention window (up to 35 days), which directly satisfies the PITR requirement. Option E (Automated cross-region snapshot copy) is correct because configuring RDS to automatically copy snapshots to a target region provides the cross-region disaster recovery capability, allowing restoration of the database in another region if the primary region fails. Together, C and E cover both stated requirements: PITR via automated backups and DR via cross-region snapshot replication.

Option A (Manual DB snapshots) is not suitable because manual snapshots do not support point-in-time recovery and must be triggered manually, so they cannot form an automated PITR solution. Option B (Cross-region read replicas) provides read scaling and can be promoted, but it is not a backup mechanism and does not deliver point-in-time recovery. Option D (Amazon S3 lifecycle policies) manages object storage transitions/expiration and has no role in RDS backup or recovery.

Exam trap

The trap is choosing cross-region read replicas for DR because they sound like replication; candidates must distinguish read replicas (performance/availability) from automated backups plus cross-region snapshot copy (point-in-time recovery and DR).

160
MCQmedium

Refer to the exhibit. A company has a CloudTrail trail in us-east-1 that logs events for that region only. The company operates in multiple regions and wants to ensure all API calls from all regions are logged. What is the most efficient way to achieve this?

A.Use Amazon CloudWatch Events to capture API calls from all regions.
B.Use S3 event notifications to trigger a Lambda function that logs API calls.
C.Create a new CloudTrail trail in each region.
D.Update the existing trail to be a multi-region trail.
AnswerD

Updating the existing trail to be a multi-region trail is the correct action because CloudTrail's multi-region trail design automatically collects API events from every region and delivers them to a single S3 bucket. This ensures comprehensive visibility into account activity without the need to create separate trails. By modifying the existing trail, you preserve its current configuration while expanding its scope, which is both efficient and administratively simple.

Why this answer

Updating the existing trail to be a multi-region trail is the most efficient way to log events from all regions. A multi-region trail logs API calls from all AWS regions into a single trail, aggregating them in the same S3 bucket. Option A is incorrect because CloudWatch Events can capture API calls, but it is less efficient and more complex than using a multi-region trail.

Option B is incorrect because S3 event notifications are triggered by S3 events, not API calls, and cannot capture all API calls. Option C is incorrect because creating a new trail in each region results in multiple trails and log files, which is less efficient to manage than a single multi-region trail.

161
MCQhard

A company has a production RDS for PostgreSQL instance with Multi-AZ enabled. During a recent failover test, the application experienced a 5-minute downtime. The company requires that failover be completed within 2 minutes. Which action should be taken to meet this requirement?

A.Migrate the database to Amazon Aurora with Multi-AZ.
B.Enable automated backups with a short retention period.
C.Increase the DB instance class to a larger size.
D.Configure an RDS Proxy in front of the database.
AnswerD

Configuring an RDS Proxy in front of the database is the correct, targeted fix because the proxy maintains persistent outbound connections to the DB endpoints and pools inbound client connections. During a failover, RDS Proxy automatically establishes connections to the new primary and keeps the client-side connections open, making the failover appear essentially transparent to the application. This eliminates the need for clients to implement complex reconnect logic and reduces the overall failover time by avoiding a cold-start connection establishment storm.

Why this answer

RDS Proxy reduces failover time by maintaining database connections and connection pooling, allowing the application to reconnect quickly without waiting for DNS propagation or new connection setup. In a Multi-AZ failover, RDS Proxy can typically complete failover in under 60 seconds, meeting the 2-minute requirement by minimizing connection disruption.

Exam trap

The trap here is that candidates assume increasing instance size or enabling backups improves failover speed, but the real bottleneck is connection management and DNS propagation, which RDS Proxy addresses directly.

How to eliminate wrong answers

Option A is wrong because Amazon Aurora with Multi-AZ already provides fast failover (typically under 30 seconds), but migrating to Aurora is not the simplest action and does not directly address the application's connection handling issue that caused the 5-minute downtime. Option B is wrong because enabling automated backups with a short retention period does not affect failover speed; backups are for point-in-time recovery, not for reducing failover time. Option C is wrong because increasing the DB instance class improves performance but does not reduce failover time; failover duration depends on DNS propagation and connection re-establishment, not instance size.

162
MCQmedium

A SysOps administrator manages a web application hosted on EC2 instances behind an Application Load Balancer. The application uses sticky sessions (session affinity) based on cookies. Recently, the development team deployed a new version that increases the load time for certain pages. Users report that they are randomly seeing other users' data. The administrator suspects that the sticky session configuration is not working correctly. The ALB target group is configured with stickiness enabled using the AWSALB cookie. What should the administrator do to verify that sticky sessions are being honored?

A.Increase the stickiness duration to 7 days and test again
B.Check the ALB access logs for the presence of the stickiness cookie
C.Use a browser's developer tools to inspect the cookies on the client side and verify the AWSALB cookie is being set and includes the correct target group identifier
D.Check the target group health check settings to ensure all instances are healthy
AnswerC

Using a browser's developer tools directly exposes the client-side cookie jar, allowing you to confirm the presence of the AWSALB or AWSALBCORS cookie and its value, which encodes the target group identifier. You can also inspect the Network tab to see the Set-Cookie header on the initial response and verify that subsequent requests include the same cookie value. This provides definitive, real-time evidence that sticky sessions are functioning, because the cookie is the mechanism that the ALB uses to pin a session to a specific target.

Why this answer

To verify sticky sessions, inspect browser developer tools to confirm the AWSALB cookie is set and remains unchanged across requests. The cookie value is opaque and cannot be decoded to reveal the target group identifier. ALB access logs can also be used to correlate the cookie with the target IP, and the presence of the cookie in access logs does prove the client sent it.

163
MCQhard

An application running on Amazon EC2 needs to access an S3 bucket. The SysOps administrator wants to ensure that only that specific EC2 instance can access the bucket, without storing any long-term credentials on the instance. What is the most secure way to achieve this?

A.Attach an IAM role to the EC2 instance using an instance profile and grant the role S3 access
B.Configure a resource-based policy on the EC2 instance to allow S3 access
C.Create an IAM user with S3 access and store the access keys in the instance's user data
D.Generate pre-signed URLs for each S3 object the application needs to access
AnswerA

Attaching an IAM role to the EC2 instance through an instance profile is the AWS best practice because the instance retrieves temporary security credentials from the instance metadata service. These credentials are automatically rotated by AWS, eliminating the need to store or manage long-term access keys on the instance. The role's identity-based policy grants the instance exactly the S3 permissions required, following the principle of least privilege.

Why this answer

Attaching an IAM role to the EC2 instance via an instance profile allows the instance to obtain temporary credentials from the EC2 Instance Metadata Service (IMDS), which are automatically rotated. This eliminates the need to store long-term access keys on the instance and scopes permissions to the specific role. It is the AWS-recommended best practice for granting EC2 access to S3.

Exam trap

SOA-C02 often tests the misconception that storing credentials in user data or using pre-signed URLs is 'secure enough' — the exam expects recognition that IAM roles with instance profiles and IMDSv2 are the only best-practice answer for EC2-to-S3 access without long-term credentials.

How to eliminate wrong answers

Option B is wrong because EC2 instances do not support resource-based policies — resource-based policies apply to resources like S3 buckets, SQS queues, and KMS keys, not to EC2 instances. Option C is wrong because storing access keys in user data is insecure: user data is visible via the metadata service and console, and long-term keys can be leaked or committed to logs. Option D is wrong because pre-signed URLs grant temporary access to specific objects but require the application to generate them using credentials anyway, and they are not a scalable identity mechanism for an application needing broad S3 access.

164
MCQeasy

A company has an application that requires UDP traffic to be distributed across multiple EC2 instances. Which AWS load balancer type should be used?

A.Network Load Balancer
B.Classic Load Balancer
C.Amazon CloudFront
D.Application Load Balancer
AnswerA

Network Load Balancer (NLB) operates at Layer 4 of the OSI model and explicitly supports UDP traffic, along with TCP and TLS. It is designed to handle millions of requests per second with ultra-low latency, making it the only Elastic Load Balancer variant capable of routing connectionless UDP packets, such as DNS or NTP queries, to backend targets. For UDP workloads, NLB preserves the client source IP and can be allocated a static Elastic IP, which is often required for firewall allow-listing in front of your application.

Why this answer

A Network Load Balancer (NLB) operates at Layer 4 and can handle both TCP and UDP traffic, making it the correct choice for distributing UDP traffic across multiple EC2 instances. Unlike other load balancers, NLB preserves the source IP address and can forward UDP packets without inspecting application-layer headers, which is essential for UDP-based applications such as DNS, VoIP, or gaming servers.

Exam trap

The trap here is that candidates may confuse the Application Load Balancer's support for WebSockets (which start as HTTP) with UDP support, or assume the Classic Load Balancer can handle any Layer 4 protocol, but AWS specifically removed UDP support from CLB and ALB, reserving it for NLB.

How to eliminate wrong answers

Option B (Classic Load Balancer) is wrong because it does not support UDP traffic; it only supports HTTP, HTTPS, TCP, and SSL. Option C (Amazon CloudFront) is wrong because it is a content delivery network (CDN) that works over HTTP/HTTPS and does not support UDP traffic distribution. Option D (Application Load Balancer) is wrong because it operates at Layer 7 and only supports HTTP, HTTPS, and WebSocket protocols, not UDP.

165
MCQeasy

A SysOps administrator needs to deploy a set of AWS Lambda functions and an Amazon API Gateway API using infrastructure as code. The administrator wants to manage the deployment across multiple environments (dev, test, prod) with consistent resource configurations. Which AWS service should the administrator use?

A.AWS CloudFormation
B.AWS CodeDeploy
C.AWS Elastic Beanstalk
D.AWS OpsWorks
AnswerA

AWS CloudFormation is the correct choice because it is a declarative infrastructure-as-code service that provisions and manages AWS resources through a template. You can define Lambda functions, API Gateway REST APIs, IAM roles, and all related dependencies in a single stack template, then deploy them consistently across development, test, and production environments. CloudFormation also handles resource ordering, rollback on failure, and drift detection, giving you repeatable and auditable deployments.

Why this answer

AWS CloudFormation is the correct choice because it is an Infrastructure as Code (IaC) service that allows you to define and provision AWS resources, including Lambda functions and API Gateway APIs, using templates. It supports managing deployments across multiple environments (dev, test, prod) by using parameters, mappings, and stacks, ensuring consistent resource configurations through repeatable, version-controlled templates.

Exam trap

The trap here is that candidates often confuse AWS CodeDeploy (which deploys application code) with CloudFormation (which provisions infrastructure), leading them to choose CodeDeploy because they think of 'deploying' Lambda functions, but the question specifically requires managing infrastructure as code across environments, which is CloudFormation's role.

How to eliminate wrong answers

Option B (AWS CodeDeploy) is wrong because it is a deployment service for automating code deployments to compute services like EC2, Lambda, or ECS, but it does not manage the provisioning of infrastructure resources like API Gateway or Lambda functions themselves; it focuses on deploying application code, not defining the underlying infrastructure. Option C (AWS Elastic Beanstalk) is wrong because it is a Platform as a Service (PaaS) that abstracts infrastructure management for web applications, but it does not provide the granular, template-based control over individual resources like Lambda and API Gateway that IaC requires; it is designed for application deployment, not for defining and versioning infrastructure components. Option D (AWS OpsWorks) is wrong because it is a configuration management service that uses Chef or Puppet to manage EC2 instances and on-premises servers, but it is not designed for defining serverless resources like Lambda functions or API Gateway APIs; it focuses on server-based configurations, not declarative IaC for serverless services.

166
MCQhard

A company is using AWS Organizations with multiple accounts. The security team wants to prevent any IAM user from creating access keys for themselves across all accounts. What is the most effective way to enforce this policy?

A.Attach an IAM policy to the root user that denies iam:CreateAccessKey.
B.Configure an IAM password policy that requires strong passwords.
C.Apply a service control policy (SCP) that denies iam:CreateAccessKey to all accounts in the organization.
D.Use AWS CloudTrail to monitor and alert on CreateAccessKey events.
AnswerC

A service control policy (SCP) is the correct mechanism because it centrally governs the maximum available permissions for all IAM users, roles, and even the root user within every member account of an AWS Organization. An SCP that denies iam:CreateAccessKey ensures that no principal in any account can create new access keys, regardless of their IAM policies, making it a preventive, organization-wide control.

Why this answer

Service control policies (SCPs) are the most effective way to enforce a guardrail across all accounts in an AWS Organization because they allow you to centrally deny or restrict permissions at the root, OU, or account level, overriding any IAM policies attached to users or roles. By applying an SCP that denies iam:CreateAccessKey, the security team ensures that no IAM user in any account within the organization can create access keys, regardless of their individual IAM policies. This approach is scalable and cannot be bypassed by account administrators, making it the correct choice for organization-wide enforcement.

Exam trap

The trap here is that candidates often confuse IAM password policies or CloudTrail monitoring with preventive controls, but only SCPs provide a centralized, enforceable denial across all accounts in an AWS Organization.

How to eliminate wrong answers

Option A is wrong because the root user is not an IAM user; it is a special account with full administrative access that cannot be restricted by IAM policies, and attaching a policy to the root user is not supported. Option B is wrong because an IAM password policy controls password complexity and rotation for IAM users, but it does not prevent users from creating access keys; it only affects password-based authentication. Option D is wrong because AWS CloudTrail is a logging and monitoring service that can alert on CreateAccessKey events, but it does not prevent the action from occurring; it only provides visibility after the fact.

167
MCQeasy

An administrator needs to grant an IAM user the ability to stop and start EC2 instances, but only for instances tagged with 'Environment:Production'. Which IAM policy element should be used to enforce this condition?

A.Effect
B.Resource
C.Action
D.Condition
AnswerD

The Condition element is the correct place to enforce tag-based restrictions through condition operators and keys such as StringEquals with ec2:ResourceTag/environment. A policy could combine Action: ec2:StartInstances with Condition: StringEquals: {'ec2:ResourceTag/environment': 'dev'} so the action is allowed only when the instance's tag matches. This works because Condition evaluates context keys against the request and resource attributes at runtime, which is exactly what is needed for tag-based authorization.

Why this answer

The Condition element in an IAM policy allows specifying conditions, such as restricting actions to instances with a specific tag (e.g., 'Environment:Production'). Option A is incorrect because Effect determines whether the policy allows or denies access. Option B is incorrect because Resource specifies the ARN of the resources the policy applies to.

Option C is incorrect because Action specifies the specific operations (e.g., ec2:StopInstances) that are allowed or denied.

168
MCQmedium

A company manages multiple AWS accounts under AWS Organizations. The SysOps administrator needs to deploy a baseline set of AWS Config rules and an Amazon SNS topic to each account in the organization. The deployment must be centrally managed from the management account and automatically applied to any new member account added in the future. Which solution should the administrator use?

A.Create an AWS CloudFormation StackSet with the template containing the AWS Config rules and SNS topic. Configure the StackSet to deploy to the organization and enable automatic deployment to new accounts.
B.Use AWS Service Catalog to create a product that bundles the AWS Config rules and SNS topic. Grant each account access to launch the product.
C.Configure AWS Config conformance packs in the management account and use AWS Resource Access Manager to share them with member accounts.
D.Create an AWS Organizations Service Control Policy (SCP) that enforces the creation of AWS Config rules and SNS topics in every account.
AnswerA

StackSets deploy a single CloudFormation template across every account in AWS Organizations from the management account, and the automatic deployment setting propagates it to accounts added later. This satisfies both the central management and future-account constraints without per-account scripting.

Why this answer

AWS CloudFormation StackSets can be deployed to an entire AWS Organizations organization or organizational units (OUs), and they support automatic deployment to new accounts added to the organization. By creating a StackSet with a template that defines the AWS Config rules and SNS topic, and enabling automatic deployment, the administrator ensures that every current and future member account receives the baseline configuration without manual intervention.

Exam trap

The trap here is that candidates often confuse Service Control Policies (SCPs) with resource enforcement, not realizing that SCPs only control permissions and cannot create or configure resources like AWS Config rules or SNS topics.

How to eliminate wrong answers

Option B is wrong because AWS Service Catalog requires each account to manually launch the product, which does not provide automatic deployment to new accounts and is not centrally enforced. Option C is wrong because AWS Config conformance packs can be deployed to multiple accounts via StackSets, but AWS Resource Access Manager (RAM) is used to share resources like subnets or license configurations, not to deploy conformance packs; conformance packs themselves are deployed using StackSets or directly per account. Option D is wrong because Service Control Policies (SCPs) are used to restrict permissions and cannot enforce the creation of specific resources like AWS Config rules or SNS topics; they only control what actions are allowed or denied.

169
MCQhard

A SysOps administrator is troubleshooting a failed AWS CloudFormation stack creation. The stack includes an Amazon RDS DB instance with a custom DB parameter group. The error message states: 'The following resource(s) failed to create: [DBParameterGroup].' The administrator checks the CloudFormation template and sees that the DBParameterGroup resource has a property 'Parameters' with a list of parameters. What is the MOST likely reason for the failure?

A.The parameter group name contains invalid characters.
B.The parameter group is configured with parameters that are not compatible with the DB engine version.
C.The DB subnet group specified for the DB instance does not exist.
D.The VPC does not have an RDS VPC endpoint enabled.
AnswerB

When you associate a custom DB parameter group with a new DB instance, RDS verifies that the parameter group's family matches the target engine and version, and that every parameter value is valid for that engine. If the parameter group was created for a different engine version (e.g., a MySQL 5.7 group attached to MySQL 8.0) or contains parameters that were removed/renamed in the target version, RDS aborts the creation with an error referencing the parameter group. This is the most common cause of a failed launch when the parameter group name, subnet group, and network configuration are otherwise correct.

Why this answer

Custom DB parameter groups must be configured with parameters that are compatible with the DB engine and version specified for the RDS instance. If the parameter group includes parameters that are not supported by the chosen engine version, the stack creation will fail with an error for the DBParameterGroup resource. In this case, the most likely cause is that one or more parameters in the 'Parameters' list are incompatible with the DB engine version.

Option B is correct. Option A is incorrect because parameter group names can contain letters, numbers, and hyphens; they are not restricted. Option C is incorrect because the DB subnet group is not related to parameter group creation failure.

Option D is incorrect because RDS does not require a VPC endpoint to create a parameter group.

170
MCQhard

A company uses Amazon CloudWatch Logs to store application logs from EC2 instances. The log volume is 100 GB per day, and logs are retained for 1 year. The SysOps administrator wants to reduce costs while maintaining compliance. Which solution is MOST effective?

A.Reduce the log retention period to 30 days.
B.Disable server-side encryption for the log group to reduce overhead.
C.Use CloudWatch Logs Insights to query logs instead of storing them.
D.Export logs to Amazon S3 and configure a lifecycle policy to transition them to Glacier Deep Archive after 30 days.
AnswerD

Exporting logs to Amazon S3 offloads them from CloudWatch Logs, where storage is more expensive, and then an S3 Lifecycle policy can automatically transition the objects to Glacier Deep Archive after 30 days. Glacier Deep Archive provides the lowest per-GB storage cost and still satisfies the one-year retention requirement, making this the most cost-effective compliant solution. For optimal savings, after a successful export you should also delete the original log group or set a very short CloudWatch retention so you do not pay for duplicate storage.

Why this answer

Exporting logs to Amazon S3 and transitioning them to Glacier Deep Archive after 30 days is the most cost-effective compliant solution because CloudWatch Logs storage is significantly more expensive per GB than S3, and Glacier Deep Archive costs roughly $0.00099/GB-month versus CloudWatch Logs at ~$0.03/GB-month. This preserves the 1-year retention requirement while cutting storage costs by over 90%.

Exam trap

SOA-C02 often tests whether candidates know CloudWatch Logs storage is far more expensive than S3, and that 'reduce retention' is a trap when compliance explicitly requires long-term retention.

How to eliminate wrong answers

Option A is wrong because reducing retention to 30 days violates the 1-year compliance requirement — cost reduction cannot come at the expense of regulatory retention. Option B is wrong because disabling server-side encryption does not meaningfully reduce CloudWatch Logs cost (encryption is not a billed line item) and would violate security/compliance requirements. Option C is wrong because CloudWatch Logs Insights is a query tool that operates on stored logs — it does not replace storage, and you cannot query logs you have not retained.

171
MCQmedium

A company's compliance team requires that all changes to IAM policies be logged and immediately alerted. Which AWS solution should be used?

A.Use AWS Config rules to monitor IAM policy changes and send notifications.
B.Use Amazon CloudWatch Logs to capture IAM policy changes and create metric filters.
C.Use Amazon GuardDuty to detect unauthorized IAM policy changes.
D.Use AWS CloudTrail to log API calls and Amazon CloudWatch Events to send alerts.
AnswerD

AWS CloudTrail records every IAM management API call (for example, PutUserPolicy, AttachRolePolicy, or DeleteRole) as an event. When CloudTrail delivers those events to Amazon CloudWatch Events (now Amazon EventBridge), you can create a rule that matches the specific event names and triggers an SNS topic or Lambda function. This event-driven pattern provides near-real-time alerts for each individual policy change, making it the correct choice.

Why this answer

AWS CloudTrail records every IAM API call (CreatePolicy, AttachRolePolicy, PutRolePolicy, etc.) as a management event, and CloudWatch Events (now EventBridge) can match those events with a rule and trigger an SNS notification or Lambda for immediate alerting. This combination satisfies both the logging and the real-time alerting requirements.

Exam trap

The trap is picking AWS Config or GuardDuty because they sound compliance- and security-oriented, but the question demands immediate alerting on every API call, which only CloudTrail + EventBridge delivers deterministically.

How to eliminate wrong answers

Option A is wrong because AWS Config rules evaluate resource configuration compliance on a periodic or change-triggered basis and are designed for drift detection, not immediate alerting on every API call; there is inherent latency and Config is not an event-streaming service. Option B is wrong because CloudWatch Logs metric filters operate on log data but IAM policy changes are not natively written to CloudWatch Logs unless CloudTrail is configured to deliver them there — and even then, metric filters are for aggregation, not immediate per-event alerting. Option C is wrong because GuardDuty is a threat-detection service that uses ML and threat intelligence to find anomalous behaviour; it does not provide a deterministic, immediate alert on every IAM policy change.

172
MCQeasy

A company is using AWS CloudTrail to log API activity. They need to ensure that log files are protected from unauthorized modification and can be used to verify the integrity of log files. Which AWS feature should be enabled?

A.Enable CloudTrail log file integrity validation.
B.Enable S3 server-side encryption on the CloudTrail S3 bucket.
C.Stream CloudTrail logs to Amazon CloudWatch Logs.
D.Enable S3 Multi-Factor Authentication (MFA) Delete on the CloudTrail S3 bucket.
AnswerA

CloudTrail log file integrity validation provides cryptographic assurance that your log files have not been tampered with. It uses SHA-256 hashing to generate a hash for each log file, and then digitally signs it with a private key. You can validate these signatures using the public key published by AWS, which lets you detect any modification, deletion, or unauthorized change to the logs, even if someone attempts to alter the digest files themselves.

Why this answer

CloudTrail log file integrity validation uses a SHA-256 hash chain to create a digest file that can be used to verify that log files have not been modified, deleted, or tampered with after delivery. This feature is specifically designed to provide cryptographic assurance of log file integrity, meeting the requirement to protect against unauthorized modification and enable verification.

Exam trap

The trap here is that candidates often confuse data protection features like encryption or deletion prevention with integrity verification, not realizing that integrity validation specifically requires a cryptographic hash chain to detect modification, not just access control or encryption.

How to eliminate wrong answers

Option B is wrong because enabling S3 server-side encryption protects log files at rest from unauthorized access but does not provide a mechanism to verify that the log files have not been modified or tampered with after they were written. Option C is wrong because streaming CloudTrail logs to CloudWatch Logs enables real-time monitoring and alerting but does not provide cryptographic integrity verification of the original log files stored in S3. Option D is wrong because S3 MFA Delete protects against accidental or unauthorized deletion of objects by requiring multi-factor authentication for delete operations, but it does not provide a hash-based integrity check to detect modification of log file contents.

173
MCQmedium

A company runs a stateful web application on a single Amazon EC2 instance. The SysOps administrator needs to implement a high availability architecture that can tolerate an Availability Zone (AZ) failure. The application stores session state in memory and also writes critical data to an Amazon EBS volume. The administrator wants to use an Auto Scaling group and an Application Load Balancer (ALB). Which combination of steps is required to make the application highly available?

A.Create an Auto Scaling group that spans at least two Availability Zones, attach the existing EBS volume to the new instances, and use an ALB to distribute traffic.
B.Migrate session state to Amazon ElastiCache for Redis, store critical data in Amazon EFS, create an Auto Scaling group across multiple AZs, and place it behind an ALB.
C.Place the EC2 instance in an Auto Scaling group with a minimum and maximum of 1 in the same AZ, and attach an Elastic IP to the instance.
D.Use an ALB with the existing single instance as the target, and enable cross-zone load balancing.
AnswerB

This option makes the application stateless at the compute layer by externalizing session state to ElastiCache for Redis, which all instances can access, and storing critical application data on Amazon EFS, a shared regional file system. An Auto Scaling group spanning multiple Availability Zones ensures that an instance failure or entire AZ outage triggers replacement, while the ALB distributes traffic only to healthy instances and performs health checks. This architecture achieves both high availability and horizontal scalability because no unique state is tied to any individual EC2 instance.

Why this answer

It addresses both the stateless requirement for horizontal scaling and the persistence of critical data across AZ failures. Migrating session state to ElastiCache for Redis removes the dependency on local instance memory, allowing any instance to handle any request. Storing critical data on Amazon EFS provides a shared, NFS-based file system that is accessible from all instances across multiple AZs, unlike EBS which is tied to a single AZ.

Combining these with a multi-AZ Auto Scaling group and an ALB ensures the application can survive an entire AZ outage.

Exam trap

The trap here is that candidates assume EBS volumes can be shared across instances or AZs, or that a single-instance setup with an ALB provides high availability, when in fact EBS is a single-AZ resource and the ALB requires multiple healthy targets to tolerate failures.

How to eliminate wrong answers

Option A is wrong because EBS volumes are AZ-scoped and cannot be attached to instances in a different AZ; attaching the existing EBS volume to new instances in another AZ is impossible without snapshotting and recreating, which defeats high availability. Option C is wrong because keeping a single instance in one AZ with an Elastic IP does not provide fault tolerance for an AZ failure; the Auto Scaling group with min/max of 1 cannot replace the instance in a different AZ automatically, and the Elastic IP does not reroute traffic to a healthy instance. Option D is wrong because using an ALB with a single instance as the target and enabling cross-zone load balancing does not add redundancy; if the instance or its AZ fails, the ALB has no other targets to route traffic to, so the application becomes unavailable.

174
MCQmedium

An administrator needs to be notified when the root user signs in to the AWS Management Console. Which method should be used?

A.Create a CloudWatch Events rule for 'AWS Console Sign-In' events and set the target to an SNS topic.
B.Enable CloudTrail Insights to detect root login anomalies.
C.Create a CloudWatch alarm on the RootAccountUsage metric.
D.Use AWS Config to track IAM password policy changes.
AnswerA

A CloudTrail record of every console sign-in is emitted as an AWS Console Sign-In event, and CloudWatch Events (EventBridge) can match those events using a rule that filters on eventName=ConsoleLogin and userIdentity.type=Root. Setting the rule's target to an SNS topic delivers a near-real-time notification to the administrator's endpoint (email, SMS, etc.). This is the standard event-driven approach because it consumes the actual audit trail event rather than relying on periodic scans or metrics that don't exist.

Why this answer

You can create an Amazon CloudWatch Events rule (now called Amazon EventBridge rule) that matches the 'AWS Console Sign-In' event from AWS CloudTrail. When the root user signs in, this event is generated, and the rule can trigger an SNS topic to send a notification to the administrator. This is the recommended approach for real-time alerting on root user activity.

Exam trap

The trap here is that candidates may think CloudWatch alarms can monitor root account usage directly via a metric, but AWS does not expose a 'RootAccountUsage' metric; instead, you must use CloudTrail events as the source for event-driven alerts.

How to eliminate wrong answers

Option B is wrong because CloudTrail Insights analyzes write management events to detect unusual activity patterns, but it does not provide real-time notifications for specific events like root user sign-ins; it focuses on anomaly detection, not event-driven alerts. Option C is wrong because the 'RootAccountUsage' metric is not a standard CloudWatch metric; CloudWatch does not have a built-in metric for root account usage, and you cannot create an alarm on a non-existent metric. Option D is wrong because AWS Config tracks resource configuration changes, such as IAM password policy changes, but it does not monitor or alert on root user sign-in events.

175
MCQmedium

A company uses AWS CodePipeline to automate its software release process. The pipeline includes a source stage (Amazon S3), a build stage (AWS CodeBuild), and a deploy stage (AWS CodeDeploy). Recently, a developer committed a change that broke the build. The pipeline failed and the developer fixed the code. The developer wants to rerun the pipeline from the source stage without making another commit. What should the developer do?

A.Create a new commit with an empty message to trigger the pipeline.
B.Use the 'Release change' button in the CodePipeline console to manually rerun the pipeline.
C.Wait for the pipeline to automatically retry after the failure.
D.Re-upload the same artifact to the source S3 bucket to trigger the pipeline.
AnswerB

Using the 'Release change' button in the CodePipeline console manually reruns the pipeline from the source stage, using the latest source revision. This is the correct action because it triggers a new execution without requiring a new commit.

Why this answer

AWS CodePipeline provides a 'Release change' button in the console that manually triggers the pipeline to run from the source stage using the latest commit. This allows the developer to rerun the pipeline without making a new commit. The pipeline will fetch the latest source revision and proceed through the stages.

Exam trap

SOA-C02 often tests the misconception that you need to make a new commit or re-upload artifacts to rerun a pipeline, rather than using the built-in 'Release change' feature.

How to eliminate wrong answers

Option A is wrong because creating an empty commit adds unnecessary noise to the repository and is not the intended way to rerun a pipeline. Option C is wrong because CodePipeline does not automatically retry after a failure; it requires manual intervention. Option D is wrong because re-uploading the same artifact to the S3 bucket may not trigger the pipeline if the object key and version are unchanged; CodePipeline triggers on new object versions or changes.

176
Multi-Selecthard

A SysOps administrator is monitoring an Amazon ECS cluster running Fargate tasks. The administrator wants to receive a notification when any task fails to start due to insufficient memory. Which combination of actions should be taken? (Choose TWO.)

Select 2 answers
A.Enable AWS CloudTrail and create a metric filter for RunTask API calls.
B.Configure the CloudWatch Events rule to send notifications to an SNS topic.
C.Create a CloudWatch Events rule that matches ECS task state changes with a reason of 'RESOURCE:MEMORY'.
D.Create a CloudWatch alarm on the ECS cluster's CPUUtilization metric.
E.Enable CloudWatch Logs for the ECS cluster and filter for error messages.
AnswersB, C

An Amazon SNS topic is the target of the CloudWatch Events rule, allowing notifications to be delivered via email, SMS, HTTP endpoints, or Lambda. By configuring an SNS subscription and including the topic as the event rule's target, the operator ensures that whenever the matching ECS task state change occurs, alerts are sent immediately. This is the notification mechanism that makes the monitoring actionable, rather than just detecting the event in the AWS console.

Why this answer

Amazon CloudWatch Events (now Events) can trigger an SNS notification when a specific ECS task state change occurs. Option C is correct because you can create a CloudWatch Events rule that matches ECS task state changes with a reason of 'RESOURCE:MEMORY', which indicates the task failed to start due to insufficient memory. Together, these actions ensure you receive a notification when a Fargate task fails to start due to memory constraints.

Exam trap

The trap here is that candidates often confuse CloudTrail (audit logging) with CloudWatch Events (event-driven notifications), or they mistakenly think CPU metrics can indicate memory-related failures, leading them to select options that do not directly capture the specific 'RESOURCE:MEMORY' reason.

177
Multi-Selecteasy

A SysOps administrator is creating a CloudFormation template to provision an Amazon S3 bucket with versioning enabled and server access logging. Which TWO properties must be configured in the AWS::S3::Bucket resource?

Select 2 answers
A.Tags
B.VersioningConfiguration
C.LoggingConfiguration
D.LifecycleConfiguration
E.AccessControl
AnswersB, C

VersioningConfiguration is the required property in an AWS::S3::Bucket template to actually enable S3 versioning. Without this property, the bucket is created with versioning disabled (the default), even if other properties like LoggingConfiguration are present. You must set Status to 'Enabled' inside this property; note that versioning can later be suspended but never fully reset to the original default, so enabling it is a one-way configuration decision.

Why this answer

The `VersioningConfiguration` property must be set to `Enabled` to enable versioning on the S3 bucket. Option C is correct because the `LoggingConfiguration` property must specify the target bucket and prefix to enable server access logging. Both are explicit properties of the `AWS::S3::Bucket` resource in CloudFormation.

Exam trap

The trap here is that candidates often confuse `LoggingConfiguration` with `AccessControl` or assume `LifecycleConfiguration` is required for logging, when in fact only `VersioningConfiguration` and `LoggingConfiguration` are mandatory for the stated requirements.

178
MCQhard

A company uses a Multi-AZ RDS for MySQL instance for its production database. During a maintenance window, the primary instance fails and a failover occurs. However, the application experiences a 5-minute downtime. The application uses a DNS CNAME record pointing to the RDS endpoint. What is the MOST likely cause of the downtime?

A.The application was using a cached DNS resolution for the RDS endpoint.
B.The application was not configured to retry connections after a failover.
C.The RDS endpoint changed after failover and the application did not update.
D.The failover process took longer than expected due to a large transaction log.
AnswerA

The RDS endpoint is a DNS name, and during a Multi-AZ failover, Amazon RDS updates the DNS record to point to the new primary instance's private IP address. If the application caches the DNS resolution longer than the TTL (or ignores TTL), it continues to attempt connections to the old, now-unavailable IP, causing persistent failures even though the endpoint name itself is correct. This is the classic root cause for post-failover connection errors: the client is not using the updated DNS mapping.

Why this answer

During a Multi-AZ RDS failover, the RDS DNS CNAME record is updated to point to the new primary instance in a different Availability Zone. However, the application's DNS resolver may have cached the previous IP address (TTL-based). If the application does not flush its DNS cache or the TTL is long, it continues to connect to the old (failed) IP, causing connection timeouts until the cache expires.

This is the most likely cause of the 5-minute downtime, as RDS failovers typically complete within 1-2 minutes.

Exam trap

The trap here is that candidates assume the RDS endpoint changes after failover (Option C), but AWS explicitly states the CNAME remains the same; the real issue is client-side DNS caching, which is a common oversight in high-availability architectures.

How to eliminate wrong answers

Option B is wrong because even if the application retries connections, it will still fail if it keeps resolving the old cached IP address; retries alone do not fix a stale DNS cache. Option C is wrong because the RDS endpoint (CNAME) does not change after a failover — it remains the same; only the underlying IP address changes. Option D is wrong because a large transaction log can delay failover completion, but the question states the failover occurs and the downtime is 5 minutes, which is longer than typical failover time; the primary issue is DNS caching, not transaction log size.

179
MCQmedium

A company uses Amazon CloudFront to deliver static content from an S3 bucket. The SysOps administrator wants to restrict access so that only CloudFront can access the S3 bucket. Which solution should be used?

A.Use pre-signed URLs for all objects.
B.Use an S3 bucket policy that allows access from any AWS service.
C.Generate CloudFront key pairs and configure signed URLs.
D.Configure an origin access control (OAC) and update the S3 bucket policy to allow CloudFront access.
AnswerD

Configuring an origin access control (OAC) attaches a CloudFront distribution to an S3 bucket using a service principal (cloudfront.amazonaws.com) and an aws:SourceArn condition that uniquely identifies the distribution. The bucket policy then explicitly grants that principal s3:GetObject permission, ensuring only your CloudFront distribution (and not the public or arbitrary AWS services) can read the objects. OAC also supports SSE-KMS encrypted origins, making it the current best practice over the legacy origin access identity (OAI).

Why this answer

Origin Access Control (OAC) is the recommended method to restrict S3 bucket access exclusively to CloudFront. OAC uses a CloudFront-owned service principal to sign requests, and the S3 bucket policy must explicitly grant the `s3:GetObject` action to that principal, ensuring no direct S3 access from other sources.

Exam trap

The trap here is confusing origin security (restricting S3 bucket access to CloudFront) with viewer security (restricting who can view content via signed URLs or cookies), leading candidates to incorrectly choose signed URLs or key pairs.

How to eliminate wrong answers

Option A is wrong because pre-signed URLs grant temporary access to specific objects but do not restrict the bucket to CloudFront; they are used for individual object access, not for origin access control. Option B is wrong because allowing access from any AWS service would permit any AWS service or principal to access the bucket, violating the requirement to restrict access solely to CloudFront. Option C is wrong because CloudFront key pairs and signed URLs are used to restrict viewer access to content, not to secure the origin; they control who can view content, not which origin can fetch from S3.

180
MCQeasy

A company wants to monitor the health of its web application running on EC2 instances behind an Application Load Balancer (ALB). Which CloudWatch metric from the ALB can indicate that requests are failing due to server errors?

A.HTTPCode_Target_5XX_Count
B.HTTPCode_Target_4XX_Count
C.HTTPCode_Target_2XX_Count
D.HTTPCode_Target_3XX_Count
AnswerA

HTTPCode_Target_5XX_Count is the most direct health indicator because it counts responses from the target instances (EC2 containers or Lambda) where the application itself generated a server-side error, such as a 500 Internal Server Error or 503 Service Unavailable. A rising trend in this metric signals that the web application is experiencing failures processing requests, making it the ideal CloudWatch metric to alarm on for monitoring application health.

Why this answer

The HTTPCode_Target_5XX_Count metric from the Application Load Balancer (ALB) specifically counts the number of HTTP response codes in the 5xx range returned by the target (EC2 instances). A 5xx status code indicates a server-side error, such as an internal server error (500), gateway timeout (504), or service unavailable (503), which directly reflects that requests are failing due to issues on the EC2 instances themselves.

Exam trap

The trap here is that candidates often confuse HTTPCode_Target_5XX_Count with HTTPCode_ELB_5XX_Count, mistakenly thinking any 5xx error is from the target, when in fact the ELB can also generate 5xx errors (e.g., 502 from a malformed response) that are tracked separately.

How to eliminate wrong answers

Option B is wrong because HTTPCode_Target_4XX_Count tracks client-side errors (e.g., 400 Bad Request, 403 Forbidden, 404 Not Found), which indicate issues with the request from the client, not server failures. Option C is wrong because HTTPCode_Target_2XX_Count counts successful responses (e.g., 200 OK), which indicate healthy application behavior, not failures. Option D is wrong because HTTPCode_Target_3XX_Count counts redirection responses (e.g., 301 Moved Permanently, 302 Found), which are not errors and do not indicate server-side problems.

181
Multi-Selecthard

A SysOps administrator is troubleshooting an issue where an EC2 instance running a web server is becoming unresponsive under high load. The administrator has enabled detailed monitoring and set up CPUUtilization alarms. Which THREE additional steps could help diagnose the root cause? (Choose THREE.)

Select 3 answers
A.Install the CloudWatch agent and collect disk space metrics.
B.Place the instance behind an Auto Scaling group.
C.Install the CloudWatch agent and collect memory metrics.
D.Increase the instance size to handle more load.
E.Enable access logs on the load balancer to analyze request patterns.
AnswersA, C, E

The CloudWatch agent is required to collect OS-level disk space metrics because default EC2 monitoring only provides hypervisor-level metrics such as CPU and network I/O. A full disk can cause application failures, failed log writes, or prevent service startup. Collecting this metric lets you correlate disk exhaustion with incident timing and configure alarms for early warning.

Why this answer

Under high load, the web server could become unresponsive due to disk space exhaustion (e.g., from log files filling the root partition). The CloudWatch agent can collect disk space metrics, which are not available by default, allowing the administrator to correlate disk usage with performance degradation.

Exam trap

The trap here is that candidates confuse reactive scaling actions (like resizing the instance or adding Auto Scaling) with diagnostic steps, failing to recognize that the question asks for steps to diagnose the root cause, not to mitigate the symptom.

182
MCQmedium

A company uses AWS CloudFormation to deploy its infrastructure. The SysOps administrator needs to be notified if a stack creation fails. Which method is the most efficient way to achieve this?

A.Use Amazon Simple Email Service (SES) to send emails on stack failure.
B.Specify an SNS topic ARN in the 'NotificationARNs' parameter of the stack.
C.Create a Lambda function that polls the CloudFormation API for stack status changes.
D.Enable CloudTrail and create a metric filter for 'CreateStack' events.
AnswerB

CloudFormation provides a native push-based notification mechanism through the 'NotificationARNs' property of a stack. When you create or update a stack, you can supply up to five Amazon SNS topic ARNs, and CloudFormation automatically publishes all stack events—including failure states like CREATE_FAILED—to those topics. Subscribers such as email, SMS, or Lambda receive the notification immediately without any custom code. This is the simplest and most reliable way to be alerted on stack failure.

Why this answer

CloudFormation natively supports specifying an Amazon SNS topic ARN in the 'NotificationARNs' parameter of the stack. When a stack creation fails, CloudFormation automatically publishes a notification to the SNS topic, which can then deliver the message via email, SMS, or other protocols without any custom polling or additional services.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing CloudTrail or Lambda polling, missing the fact that CloudFormation has a built-in, efficient notification mechanism via SNS that requires no additional services or custom code.

How to eliminate wrong answers

Option A is wrong because Amazon SES is an email sending service, not a notification delivery mechanism integrated with CloudFormation; it would require custom logic to trigger on stack failure. Option C is wrong because polling the CloudFormation API for stack status changes is inefficient, introduces latency, and incurs additional API call costs compared to the native push-based notification via SNS. Option D is wrong because CloudTrail and metric filters are used for auditing and monitoring API calls, not for real-time notification of stack failures; they would require additional setup with CloudWatch Alarms and SNS to achieve similar functionality, making it less efficient than the direct SNS integration.

183
MCQhard

A web application on EC2 instances behind an ALB experiences increased latency during peak hours. The SysOps administrator notices that the ALB's RequestCount per target is high. What design change should improve performance?

A.Switch to a Network Load Balancer.
B.Add more EC2 instances to the target group.
C.Enable sticky sessions on the ALB.
D.Reduce the idle timeout on the ALB.
AnswerB

Adding more EC2 instances to the target group horizontally scales the application and directly reduces the number of concurrent requests each instance must handle. Since the ALB already distributes traffic at the request level, an increase in target count lets the same request rate be spread across more processing capacity, lowering queue wait times and therefore end-to-end latency. This is the standard approach when per-instance CPU utilization is high or when the request queue delay is proportional to the load per target. It is the correct choice among the options.

Why this answer

Increasing the number of targets (EC2 instances) spreads the load and reduces latency.

184
MCQeasy

A company has an S3 bucket that contains sensitive customer data. The security team requires that all data in transit to and from the bucket must be encrypted. Which bucket policy condition should be used?

A.aws:SecureTransport
B.s3:x-amz-server-side-encryption-aws-kms-key-id
C.s3:x-amz-server-side-encryption
D.aws:TLSSupport
AnswerA

aws:SecureTransport is the legitimate boolean condition key used in S3 bucket policies to verify whether the request was made over HTTPS/TLS. When you set "Bool": {"aws:SecureTransport": "true"} in a Deny statement, you explicitly block any request that uses plain HTTP, ensuring all data transmitted to and from the bucket is encrypted in transit. This directly satisfies the requirement to enforce secure transport.

Why this answer

The aws:SecureTransport condition key in an S3 bucket policy checks whether the request was sent using SSL/TLS. Setting it to 'true' denies any requests that are not encrypted in transit, enforcing HTTPS for all access to the bucket. This directly meets the requirement that all data in transit must be encrypted.

Exam trap

The trap is confusing encryption at rest condition keys (s3:x-amz-server-side-encryption) with encryption in transit (aws:SecureTransport), causing candidates to pick a key that enforces SSE instead of HTTPS.

How to eliminate wrong answers

Option B is wrong because s3:x-amz-server-side-encryption-aws-kms-key-id is used to enforce a specific KMS key for server-side encryption at rest, not for transit encryption. Option C is wrong because s3:x-amz-server-side-encryption enforces server-side encryption at rest (e.g., AES256 or aws:kms), not transit encryption. Option D is wrong because aws:TLSSupport is not a valid condition key in AWS; the correct key is aws:SecureTransport.

185
MCQhard

A company uses AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment strategy is set to CodeDeployDefault.HalfAtATime. The lifecycle hooks for the Auto Scaling group include a test hook that runs during instance launch. During a recent deployment, the deployment failed because the new instances failed the test hook and were not marked as healthy. The SysOps administrator needs to ensure that failed instances are automatically terminated and replaced with new ones from the Auto Scaling group. Which configuration change should the administrator make?

A.Modify the Auto Scaling group's health check type to ELB
B.Modify the CodeDeploy deployment configuration to use an increased minimum healthy instance count
C.Modify the Auto Scaling group's health check grace period to a lower value
D.Modify the CodeDeploy deployment to ignore the lifecycle hook failure
AnswerA

When the health check type is set to ELB, the Auto Scaling group uses the Application Load Balancer's health checks. If the test hook fails, the instance will be marked unhealthy by the ALB, and the Auto Scaling group will terminate and replace it, ensuring only healthy instances remain.

Why this answer

Setting the Auto Scaling group's health check type to ELB (Elastic Load Balancer) ensures that the Auto Scaling group uses the ELB's health check status to determine instance health. When the test lifecycle hook fails, the new instances are not marked as healthy by the ELB, causing the Auto Scaling group to automatically terminate and replace them. This aligns with the requirement to automatically replace failed instances, as the default EC2 health check only considers instance status (e.g., running vs. stopped) and does not reflect application-level health.

Exam trap

The trap here is that candidates often assume the default EC2 health check is sufficient for detecting application-level failures, but it only monitors instance status (e.g., running/stopped), not the success of lifecycle hooks or application health, so the ELB health check type is required to trigger automatic replacement.

How to eliminate wrong answers

Option B is wrong because increasing the minimum healthy instance count in the CodeDeploy deployment configuration (e.g., using CodeDeployDefault.AllAtOnce or a custom configuration) does not cause failed instances to be terminated and replaced; it only adjusts the number of instances that must remain healthy during the deployment, which could actually reduce the deployment's tolerance for failures. Option C is wrong because reducing the health check grace period would cause the Auto Scaling group to check instance health sooner, but it does not change the health check type; with the default EC2 health check, the test hook failure is not detected, so a shorter grace period has no effect on terminating failed instances. Option D is wrong because ignoring the lifecycle hook failure would allow the deployment to proceed despite the test failure, but it would not trigger automatic termination and replacement of the failed instances; the instances would remain in service, potentially causing application issues.

186
MCQhard

A company runs a critical web application on Amazon EC2 instances that are part of an Auto Scaling group. The application receives unpredictable traffic spikes. The SysOps administrator needs to ensure that when a scale-out event occurs, new instances are ready to serve traffic quickly to minimize latency spikes. Currently, the instance launch and configuration process (including software installs and cache warming) takes about 5 minutes. The administrator wants to reduce the time it takes for new instances to start serving traffic. Which combination of Auto Scaling features should be used?

A.Use a launch template that includes a pre-warmed Amazon Machine Image (AMI) with all software pre-installed, and configure the Auto Scaling group to use a larger instance type to reduce initialization time.
B.Implement an Auto Scaling warm pool with a minimum number of pre-initialized instances in a 'Stopped' state. Configure the scaling policy to move instances from the warm pool to the Auto Scaling group when needed.
C.Use scheduled scaling to predictively launch instances before the traffic spikes based on historical patterns.
D.Configure lifecycle hooks to add a wait time during instance launch so that the instance is fully configured before it is placed behind the load balancer.
AnswerB

A warm pool maintains instances that have been fully launched and configured but are stopped or in a standby state. When scale-out occurs, instances from the warm pool are started or moved into service quickly, drastically reducing the time to handle traffic.

Why this answer

An Auto Scaling warm pool maintains a pool of pre-initialized instances in a 'Stopped' state that are fully configured (software installed, cache warmed) and ready to serve traffic. When a scale-out event occurs, instances from the warm pool are moved to the Auto Scaling group and transitioned to 'Running' state, bypassing the 5-minute launch and configuration delay, thereby minimizing latency spikes.

Exam trap

The trap here is that candidates often confuse warm pools with lifecycle hooks or pre-warmed AMIs, assuming that reducing software install time alone is sufficient, when the real bottleneck is the entire instance initialization process that warm pools bypass.

How to eliminate wrong answers

Option A is wrong because using a pre-warmed AMI reduces software installation time but does not eliminate the instance launch and initialization overhead (e.g., kernel boot, network setup, cache warming), and using a larger instance type does not inherently reduce initialization time—it may even increase it due to more hardware resources to initialize. Option C is wrong because scheduled scaling relies on predictable traffic patterns and cannot handle unpredictable traffic spikes; it would either over-provision or under-provision for unexpected demand. Option D is wrong because lifecycle hooks add a wait time during instance launch, which would increase the time before the instance is ready to serve traffic, contradicting the goal of reducing latency spikes.

187
MCQmedium

A company has a VPC with public and private subnets across two Availability Zones. An application running on EC2 instances in the private subnets needs to access the internet for updates. Which configuration should be used to provide internet access while minimizing administrative overhead?

A.Assign public IP addresses to the private instances and update route tables accordingly.
B.Set up AWS Direct Connect to an internet gateway.
C.Deploy a NAT Gateway in a public subnet and update private route tables to point to it.
D.Launch a NAT instance in the private subnet and configure routing.
AnswerC

A NAT gateway is a highly available, fully managed AWS service that allows instances in a private subnet to initiate outbound traffic to the internet while blocking unsolicited inbound connections. It must be placed in a public subnet with a route to an internet gateway, and the private subnet's route table should direct 0.0.0.0/0 traffic to the NAT gateway's network interface. This design is the standard for providing internet access to private resources securely, with no need to patch or manage the gateway yourself.

Why this answer

A NAT Gateway, deployed in a public subnet with an Elastic IP, allows instances in private subnets to initiate outbound traffic to the internet (e.g., for updates) while preventing inbound traffic from the internet. This is a fully managed AWS service, so it requires no patching or scaling management, minimizing administrative overhead. The private subnet's route table must have a default route (0.0.0.0/0) pointing to the NAT Gateway's network interface.

Exam trap

The trap here is that candidates confuse a NAT Gateway with a NAT instance, assuming both require similar administrative effort, or they mistakenly think assigning public IPs to private instances is sufficient for outbound-only internet access.

How to eliminate wrong answers

Option A is wrong because assigning public IP addresses to instances in private subnets would not automatically provide internet access; you would also need an Internet Gateway in the VPC and a route from the private subnet to it, which would expose the instances to inbound traffic, violating the private subnet's purpose. Option B is wrong because AWS Direct Connect is a dedicated private network connection from on-premises to AWS, not a service for providing internet access to VPC resources; it does not replace an Internet Gateway or NAT Gateway for outbound internet traffic. Option D is wrong because a NAT instance is a self-managed EC2 instance that requires manual configuration, patching, and scaling, which increases administrative overhead compared to the managed NAT Gateway.

188
MCQhard

A company runs a critical web application on a fleet of EC2 instances behind an Application Load Balancer (ALB) across multiple Availability Zones. The application is deployed using AWS Elastic Beanstalk with a rolling update deployment policy. Recently, the development team pushed a new application version that introduced a memory leak. Within minutes, the instances started failing health checks, and Elastic Beanstalk initiated a replacement of the instances. However, during the replacement, the application experienced downtime because the new instances were not passing health checks, and the old instances were already terminated. The SysOps Administrator must modify the deployment to prevent downtime during future failed deployments. Which solution should the administrator implement?

A.Increase the Auto Scaling group's minimum and maximum size to handle more instances.
B.Implement a Blue/Green deployment using a separate Elastic Beanstalk environment and swap CNAMEs after testing.
C.Replace the ALB with a Classic Load Balancer to reduce complexity.
D.Change the deployment policy to All at once to speed up the deployment.
AnswerB

Blue/green keeps the original environment serving traffic until the new environment passes health checks, then swaps CNAMEs. This prevents downtime when a bad version fails health checks, unlike rolling updates that terminate old instances first.

Why this answer

Blue/Green deployment with Elastic Beanstalk creates a separate environment running the new version. Health checks validate the new instances before swapping the CNAME. If the new environment fails, the old environment continues serving traffic, eliminating downtime.

Option A is wrong because increasing Auto Scaling sizes does not change the deployment policy; it only affects scaling limits. Option C is wrong because Classic Load Balancer lacks advanced health check features and does not address the deployment strategy. Option D is wrong because All at once deployment would replace all instances simultaneously, causing downtime even without failure, and does not provide a rollback mechanism.

189
MCQmedium

A company runs a batch processing job on Amazon EC2 that runs for 2 hours every night. The job can tolerate interruptions and can resume from the last checkpoint. The SysOps administrator needs to minimize compute costs. Which EC2 purchasing option should be used?

A.On-Demand Instances
B.Spot Instances
C.Reserved Instances
D.Compute Savings Plans
AnswerB

Spot Instances provide access to spare AWS compute capacity at discounts of up to 90% versus On-Demand, but AWS can reclaim them with only a two-minute warning. Batch processing jobs with checkpointing are a canonical Spot use case because a reclaimed instance creates no data loss and the work can simply be retried. Using Spot Fleet or EC2 Fleet with multiple instance types and Availability Zones increases resilience and maintains throughput during interruptions, making Spot the optimal and lowest-cost choice.

Why this answer

Spot Instances are ideal for fault-tolerant, interruptible workloads like this batch processing job because they offer significant cost savings (up to 90% off On-Demand prices) in exchange for being reclaimable by AWS with a 2-minute warning. Since the job can resume from the last checkpoint, interruptions do not cause data loss or restart from scratch, making Spot Instances the most cost-effective choice.

Exam trap

The trap here is that candidates often choose Reserved Instances or Savings Plans because they assume any long-running workload needs a commitment, but the question explicitly states the job is interruptible and runs only 2 hours nightly, making Spot Instances the correct cost-optimization choice.

How to eliminate wrong answers

Option A is wrong because On-Demand Instances provide no discount and are not cost-minimizing for a predictable, interruptible workload. Option C is wrong because Reserved Instances require a 1- or 3-year commitment and are designed for steady-state, always-on workloads, not a 2-hour nightly job that can be interrupted. Option D is wrong because Compute Savings Plans offer discounts (up to 66%) but still require a 1- or 3-year commitment and are less cost-effective than Spot Instances for this specific use case.

190
MCQeasy

A company runs a critical application on an EC2 instance backed by Amazon EBS. To protect against data loss, the company wants to create a backup strategy that allows for point-in-time recovery. Which solution should be used?

A.Configure an S3 Lifecycle policy to move data to Glacier.
B.Create an Amazon Machine Image (AMI) of the instance.
C.Use Amazon EFS to store data.
D.Create automated EBS snapshots.
AnswerD

Automated EBS snapshots use Amazon Data Lifecycle Manager (DLM) or AWS Backup to take scheduled, point-in-time copies of your EC2 instance's volumes. Each snapshot is incremental—only the blocks that changed since the previous snapshot are stored—and snapshots are stored redundantly in S3 for high durability. By setting a regular schedule, you get an ongoing backup that can be restored to a new volume or used to rebuild the instance, making it the correct choice for protecting a critical application's data.

Why this answer

Automated EBS snapshots provide point-in-time backups of the EBS volume, enabling granular recovery to a specific moment. Snapshots are stored in Amazon S3 and can be used to restore the volume or create new instances, directly addressing the requirement for point-in-time recovery against data loss.

Exam trap

The trap here is that candidates may confuse AMIs (which are used for instance-level recovery and launching new instances) with EBS snapshots (which are volume-level backups designed for granular point-in-time recovery), leading them to select Option B instead of D.

How to eliminate wrong answers

Option A is wrong because an S3 Lifecycle policy to move data to Glacier is for archiving objects in S3, not for backing up an EC2 instance's EBS volume; it does not provide point-in-time recovery of the instance or its data. Option B is wrong because an AMI captures the entire instance configuration (including attached volumes) but is typically used for launching new instances, not for granular point-in-time recovery of individual EBS volumes; AMIs are less frequent and more heavyweight than snapshots for backup purposes. Option C is wrong because Amazon EFS is a separate network file system that must be mounted to the instance; it does not back up the existing EBS root or data volumes, and it introduces additional complexity without addressing the requirement for point-in-time recovery of the EBS-backed instance.

191
MCQmedium

A company wants to ensure that an EC2 instance can access an S3 bucket without storing AWS credentials on the instance. What should the SysOps administrator do?

A.Create an IAM role with permissions to the S3 bucket and attach it to the EC2 instance profile.
B.Attach an S3 bucket policy that grants access to the EC2 instance's public IP address.
C.Generate access keys for an IAM user and store them on the instance.
D.Use AWS STS to generate temporary credentials and store them in the instance's user data.
AnswerA

Attaching an IAM role to an EC2 instance through an instance profile is the secure, AWS-recommended approach. The instance profile is passed to the instance at launch, and the Amazon EC2 service uses the role's trust policy to call the AWS Security Token Service (STS) to issue short-term credentials that are delivered via the instance metadata service. These credentials are automatically rotated by the EC2 service before they expire, so the application can access the S3 bucket without ever storing or handling secrets.

Why this answer

An IAM role can be attached to an EC2 instance via an instance profile, granting temporary security credentials that allow the instance to access the S3 bucket without storing long-term credentials on the instance. Option B is incorrect because an S3 bucket policy cannot be attached to an instance; it is attached to the S3 bucket itself, and using the instance's public IP is not a secure or recommended method. Option C is incorrect because storing access keys on the instance violates the requirement of not storing credentials.

Option D is incorrect because while AWS STS can generate temporary credentials, storing them in instance user data is not secure and does not eliminate credential storage on the instance.

192
MCQmedium

A SysOps administrator receives an alert that an EC2 instance in an Auto Scaling group is unhealthy. The instance fails the EC2 status check. What is the BEST course of action to restore availability automatically?

A.Use AWS Systems Manager to replace the underlying host.
B.Manually reboot the instance from the EC2 console.
C.Create a CloudWatch alarm that triggers an SNS notification to the administrator.
D.Configure the Auto Scaling group to use EC2 status checks for health checks and set the health check grace period appropriately.
AnswerD

Configuring the Auto Scaling group to use EC2 status checks as its health check type allows the ASG to automatically detect when an instance fails either a system or instance status check. Once marked unhealthy, the ASG terminates the instance and launches a replacement, providing self-healing without manual intervention. Setting the health check grace period appropriately ensures the instance is given enough time to initialize and pass status checks before being evaluated, preventing premature termination during boot or application startup.

Why this answer

Configuring the Auto Scaling group to use EC2 status checks for health checks allows it to automatically detect when an instance fails the EC2 status check and replace it with a new one, ensuring high availability without manual intervention. The health check grace period prevents premature termination during initial instance bootstrapping. This is the most automated and resilient approach for restoring availability in response to EC2 status check failures.

Exam trap

The trap here is that candidates may think a CloudWatch alarm with SNS notification is sufficient for automatic recovery, but it only provides notification, not automated remediation, whereas the Auto Scaling group's health check configuration directly triggers instance replacement without manual steps.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager does not have a capability to replace the underlying host of an EC2 instance; it is used for operational management like patching and configuration, not for host replacement. Option B is wrong because manually rebooting the instance from the EC2 console requires human intervention and does not provide automatic recovery, which contradicts the requirement to restore availability automatically. Option C is wrong because creating a CloudWatch alarm that triggers an SNS notification only alerts the administrator but does not take any automated action to replace or recover the unhealthy instance, leaving the availability restoration dependent on manual response.

193
MCQhard

A company has a CloudFormation stack that creates an Amazon EC2 instance with a user data script that installs software from the internet. The stack creation is failing with a timeout. The SysOps administrator suspects that the user data script is taking too long or failing. How can the administrator configure the stack to wait for the user data script to complete successfully before marking the instance as CREATE_COMPLETE?

A.Add a CreationPolicy with a resource signal to the EC2 instance resource and have the user data script send a success signal using cfn-signal.
B.Add a DependsOn attribute to the EC2 instance resource to wait for another resource.
C.Add an UpdatePolicy with a resource signal to the EC2 instance resource.
D.Add a WaitCondition resource and a WaitHandle, and have the user data script send a signal to the WaitHandle.
AnswerA

A CreationPolicy on the EC2 instance resource makes CloudFormation hold the stack creation in the CREATE_IN_PROGRESS state until it receives the specified number of success signals. The user data script must invoke cfn-signal after completing its configuration steps, which directly ties the instance's readiness to the stack creation workflow. This is the only option that explicitly synchronizes CloudFormation with the completion of the user data script during initial stack creation.

Why this answer

A CreationPolicy with a resource signal tells CloudFormation to wait for a success signal (via cfn-signal) from the EC2 instance before marking it CREATE_COMPLETE. The user data script calls cfn-signal after the software installation succeeds, ensuring the stack only proceeds when the instance is truly ready.

Exam trap

SOA-C02 often tests whether candidates confuse CreationPolicy (initial creation wait) with UpdatePolicy (update-time rolling behavior) — the question's 'stack creation is failing' keyword points to CreationPolicy.

How to eliminate wrong answers

Option B is wrong because DependsOn only controls resource creation order — it does not wait for user data scripts or application readiness. Option C is wrong because UpdatePolicy governs how resources are updated during stack updates (e.g., AutoScalingRollingUpdate), not initial creation wait behavior. Option D is wrong because WaitCondition + WaitHandle is the older, more manual pattern — CreationPolicy with cfn-signal is the modern, recommended approach for EC2 instances and is what the question asks for.

194
MCQhard

A company runs a critical database workload on an Amazon RDS for MySQL DB instance with Multi-AZ deployment in the us-east-1 region. The SysOps administrator must design a disaster recovery strategy that can recover from a complete regional outage. The Recovery Time Objective (RTO) is 2 hours and the Recovery Point Objective (RPO) is 1 hour. Which solution meets these requirements at the lowest cost?

A.Create manual snapshots of the DB instance every hour and copy them to another AWS Region.
B.Enable automated backups with a retention period of 35 days and restore to a different Region when needed.
C.Create a cross-Region read replica in another Region and promote it to a standalone DB instance during a disaster.
D.Use AWS Database Migration Service (DMS) to continuously replicate data to a DB instance in another Region.
AnswerC

A cross-Region read replica provides continuous asynchronous replication with low lag (typically seconds). In a disaster, promoting the replica to a primary instance takes only minutes, meeting the RTO and RPO requirements with minimal cost.

Why this answer

A cross-Region read replica continuously replicates data from the primary RDS MySQL instance to another Region with minimal lag, typically achieving an RPO of seconds to minutes, well within the 1-hour requirement. Promoting the replica to a standalone instance during a disaster can be done in minutes, meeting the 2-hour RTO. This approach is the lowest cost among the viable options as it uses existing replication infrastructure without additional data transfer fees for snapshots or DMS replication instances.

Exam trap

The trap here is that candidates often choose Option B (automated backups) because they assume backups can be restored cross-Region, but automated backups are Region-specific and do not support cross-Region restore without additional snapshot copy configuration, which is not mentioned in the option.

How to eliminate wrong answers

Option A is wrong because manual snapshots taken every hour would incur significant storage costs for storing and copying snapshots across Regions, and the copy process can take longer than 1 hour, potentially exceeding the RPO. Option B is wrong because automated backups with a 35-day retention period are stored only in the source Region and cannot be restored to a different Region; cross-Region snapshot copy must be explicitly configured and is not part of automated backups. Option D is wrong because AWS DMS incurs additional costs for a replication instance and data transfer, making it more expensive than a cross-Region read replica, and it adds operational complexity for continuous replication that is unnecessary when native MySQL replication can achieve the same RPO/RTO.

195
MCQhard

A SysOps administrator is managing a multi-account AWS environment using AWS Organizations. The security team has mandated that all Amazon S3 buckets across all accounts must be encrypted with SSE-KMS using a centrally managed KMS key. The administrator has created a KMS key in the master account and enabled key rotation. The key policy allows the root user of each member account to use the key. However, users in member accounts report that they cannot upload objects to their S3 buckets with SSE-KMS using the central key, even though they have s3:PutObject permissions. The administrator verifies that the KMS key policy includes the necessary permissions for the member accounts. What should the administrator do to resolve the issue?

A.Create a new KMS key in each member account and configure S3 bucket default encryption accordingly.
B.Ensure that the KMS key policy allows the master account to administer the key.
C.Attach an IAM policy to the users/roles in the member accounts that allows kms:GenerateDataKey using the central KMS key.
D.Update the S3 bucket policy to allow the s3:PutObject action only when encryption is set to SSE-KMS.
AnswerC

For S3 objects encrypted with SSE-KMS, the IAM principal performing the PutObject call must have kms:GenerateDataKey permission on the key that encrypts the object. In a cross-account scenario using a central KMS key in the master account, the member-account users/roles must be explicitly allowed, via an IAM policy, to use that key. The key policy in the master account should grant access to the member account principals, and this IAM policy in the member account completes the authorization chain, enabling the S3 encryption to succeed with the centrally managed key.

Why this answer

Cross-account KMS usage requires permissions on both sides: the key policy must allow the external account, and the IAM principal in that account must also be granted kms:GenerateDataKey (and kms:Decrypt) via an IAM policy. The key policy alone is insufficient.

Exam trap

The trap is assuming that a permissive KMS key policy is sufficient for cross-account access — candidates forget that IAM policies in the member account must also grant the KMS actions.

How to eliminate wrong answers

Option A is wrong because creating per-account keys defeats the requirement for a centrally managed key and adds operational overhead. Option B is wrong because the master account already administers the key — that does not grant member-account users permission to use it. Option D is wrong because the S3 bucket policy controls S3 actions, not KMS permissions; the failure is at the KMS layer, not S3.

196
Multi-Selecteasy

A company wants to reduce costs for their Amazon RDS for PostgreSQL database. Which TWO actions would help achieve this?

Select 2 answers
A.Enable Multi-AZ deployment for high availability.
B.Stop the database instance during non-business hours.
C.Enable deletion protection to prevent accidental deletion.
D.Increase the backup retention period to 35 days.
E.Purchase a Reserved Instance for the database instance.
AnswersB, E

Stopping the RDS DB instance during non-business hours places it in a 'stopped' state (you can stop it for up to 7 days at a time), during which compute and I/O charges are no longer incurred. Storage and backup costs continue, but you effectively eliminate the expensive instance-hour component for test and development environments that are only used in business hours. This delivers direct cost savings and is the correct answer here.

Why this answer

Option B is correct because stopping an RDS for PostgreSQL instance during non-business hours eliminates instance-hour charges while it is stopped (storage charges still apply), directly reducing compute costs for a database that is not needed around the clock. Option E is correct because purchasing a Reserved Instance for the DB instance provides a significant discount (up to roughly 69% versus On-Demand for a 3-year, all-upfront term) in exchange for a commitment to a specific instance family and Region, lowering the effective hourly rate for steady-state workloads. Option A is not cost-reducing because Multi-AZ runs a synchronous standby replica in a second AZ, roughly doubling instance and storage cost in exchange for high availability.

Option C is a safety control that prevents accidental deletion and has no positive effect on cost. Option D increases cost, since extending backup retention to 35 days keeps more automated backup storage beyond the free allocation and incurs additional backup storage charges.

Exam trap

SOA-C02 often tests the misconception that features like Multi-AZ or deletion protection reduce costs, when they actually increase cost or have no cost impact.

197
MCQhard

A company is using AWS Lambda functions to process incoming messages from Amazon SQS. The Lambda function sometimes fails due to a transient error, and the message is not processed. The team wants to automatically retry failed messages and send them to a dead-letter queue (DLQ) after three failed attempts. Which configuration meets these requirements?

A.Set the Lambda function's reserved concurrency to 1 and enable 'maximumRetryAttempts' to 2.
B.Create an SQS queue with a visibility timeout that allows three retries before sending to a DLQ.
C.Configure the SQS queue as an event source for Lambda with a DLQ specified in the Lambda function's dead-letter configuration.
D.Configure the SQS queue with a redrive policy that allows three maximum receives before sending to a DLQ.
AnswerD

A redrive policy with maxReceiveCount set to 3 ensures that after the message has been received from the queue three times without successful processing, the message is automatically moved to the configured dead-letter queue. This is the standard SQS mechanism for defining retry limits because each receive attempt by the Lambda consumer counts toward maxReceiveCount. The DLQ is configured on the SQS queue itself, not on the Lambda function, and this behavior is specific to SQS event sources.

Why this answer

When SQS is configured as an event source for Lambda, retries are controlled by the SQS queue's redrive policy. The redrive policy with maxReceiveCount determines how many times a message can be received before it is moved to the DLQ. Setting maxReceiveCount to 3 means after three receive attempts (i.e., three failed processing attempts), the message is sent to the DLQ.

Option C is incorrect because Lambda's dead-letter configuration is used for asynchronous invocations, not for SQS event source mappings. For SQS-triggered functions, the DLQ must be configured on the SQS queue itself using a redrive policy, not on the Lambda function.

Exam trap

The trap is that candidates often assume the Lambda dead-letter configuration applies to SQS event source mappings. However, for SQS triggers, retries and DLQ routing are managed by the SQS queue's redrive policy, not by Lambda's DLQ settings.

How to eliminate wrong answers

Option A is wrong because setting reserved concurrency to 1 does not control retry behavior; 'maximumRetryAttempts' is a property of the Lambda event source mapping, not a direct function configuration, and setting it to 2 would only allow 2 retries (total 3 attempts), but the reserved concurrency limit is irrelevant for retry logic. Option B is wrong because the SQS visibility timeout controls how long a message is hidden after being polled, but it does not inherently trigger retries or send messages to a DLQ after three failures; the redrive policy on the SQS queue is needed for that. Option D is wrong because configuring the SQS queue with a redrive policy that allows three maximum receives sends messages to the DLQ after three receives, but this does not integrate with Lambda's automatic retry mechanism; Lambda would need to delete the message after successful processing, and the redrive policy would only trigger if the message is not deleted, which may not align with the requirement for Lambda to retry on transient errors.

198
MCQmedium

A company uses AWS KMS to encrypt data stored in S3. The security team wants to rotate the KMS key automatically every year. The SysOps administrator enabled automatic key rotation for the KMS key. However, after a year, the security team finds that the key has not been rotated. What is the most likely cause?

A.The KMS key is disabled.
B.The KMS key policy does not allow rotation.
C.The KMS key has not been used in the last year.
D.The KMS key was created by importing key material.
AnswerD

Keys with imported key material have an origin of EXTERNAL, meaning the plaintext key material resides only with the customer and AWS KMS cannot access or replace it. Since automatic rotation requires AWS to generate a new backing key, it is unsupported for imported keys. To rotate, you must create a new KMS key, import fresh material, and update any aliases or applications that reference the old key.

Why this answer

AWS KMS does not support automatic key rotation for customer-managed keys that were created by importing key material. This is a key limitation to remember. Options A and B are incorrect because automatic rotation is independent of the key's enabled state or the key policy; rotation occurs automatically for supported keys.

Option C is incorrect because key usage is not a requirement for automatic rotation; the rotation schedule is based on time, not usage.

199
MCQmedium

A SysOps administrator is creating a CloudFormation stack that requires an IAM role to be passed to EC2 instances. The administrator is using the IAM policy shown in the exhibit. The stack creation fails with an error indicating insufficient permissions to pass the role. What is the most likely cause?

A.The cloudformation:* action does not include permission to create stacks.
B.The policy does not include the cloudformation:CreateStack action.
C.The ec2:RunInstances permission is missing from the policy.
D.The iam:PassRole permission is restricted to a specific role ARN that does not match the role the administrator is trying to pass.
AnswerD

The correct explanation is that the iam:PassRole permission in the policy is scoped to a specific role ARN (e.g., arn:aws:iam::123456789012:role/Admin), but the CloudFormation stack is configured to use a different IAM role, such as a dedicated stack role or a role named 'StackRole'. When CloudFormation attempts to pass that role to the EC2 instances or other resources, IAM evaluates the PassRole action and denies it because the ARN does not match the one allowed. This is a classic IAM PassRole mismatch error and is precisely why the stack creation fails.

Why this answer

The IAM policy likely includes an iam:PassRole action restricted to a specific role ARN (e.g., 'arn:aws:iam::account:role/Admin'), but the CloudFormation stack is attempting to pass a different role. This causes an insufficient permissions error because the PassRole permission is scoped to that specific role. Option A is incorrect because cloudformation:* includes all CloudFormation actions, including creating stacks.

Option B is incorrect because the policy uses cloudformation:*, which implicitly includes CreateStack. Option C is incorrect because ec2:RunInstances is not required for passing an IAM role; the necessary permission is iam:PassRole.

200
MCQhard

A company has a VPC with public and private subnets. The private subnets need outbound internet access to download software updates while preventing any inbound internet traffic. The SysOps administrator must minimize costs. Which solution should the administrator implement?

A.Create a NAT Gateway in a public subnet and update the private subnet route table to use it
B.Launch a NAT instance in a public subnet with an Elastic IP and disable source/destination check, then update private subnet route tables
C.Attach an Internet Gateway to the VPC and add a default route to the Internet Gateway in the private subnets
D.Use AWS Transit Gateway with a VPN connection to an on-premises data center for internet access
AnswerB

Launching a NAT instance is the correct cost-minimizing solution because it uses a regular EC2 instance, which incurs only standard instance-hour charges and no per-gigabyte data processing fees, unlike a NAT Gateway. To make it work, you must assign an Elastic IP so the NAT instance has a stable public address, disable the source/destination check so the instance can forward traffic, and update the private subnet route tables to point 0.0.0.0/0 at the NAT instance's private IP. This configuration provides outbound internet access for private instances while preserving the cost advantage over the managed gateway service.

Why this answer

A NAT instance, when launched in a public subnet with an Elastic IP and source/destination check disabled, can route outbound traffic from private subnets to the internet while blocking unsolicited inbound connections. This solution minimizes costs compared to a NAT Gateway, as NAT instances use existing EC2 instance pricing and can be further reduced with spot instances or smaller instance types.

Exam trap

The trap here is that candidates often choose the NAT Gateway (Option A) because it is fully managed and simpler, overlooking the explicit cost-minimization requirement that favors the cheaper, self-managed NAT instance.

How to eliminate wrong answers

Option A is wrong because a NAT Gateway incurs hourly charges and data processing fees, making it more expensive than a NAT instance, which is contrary to the requirement to minimize costs. Option C is wrong because attaching an Internet Gateway directly to private subnets and adding a default route would expose those subnets to inbound internet traffic, violating the security requirement to prevent inbound traffic. Option D is wrong because AWS Transit Gateway with a VPN connection to an on-premises data center is over-engineered and costly for simple outbound internet access, and it does not directly provide internet access without additional routing and infrastructure.

201
MCQeasy

A SysOps administrator wants to receive an email when the average CPU utilization of an EC2 instance exceeds 90% for 5 minutes. What should the administrator create?

A.A CloudWatch Logs metric filter on the instance logs.
B.An AWS Config rule to detect high CPU usage.
C.A CloudWatch Events rule on the EC2 instance state change.
D.A CloudWatch alarm on the CPUUtilization metric with an SNS notification.
AnswerD

A CloudWatch alarm on the CPUUtilization metric with an SNS notification is the standard, correct mechanism. The alarm continuously evaluates the CPUUtilization metric (as a percentage) against a threshold over a specified number of consecutive periods, and when the alarm state is reached, it publishes a message to the configured SNS topic. An email subscription on that SNS topic then delivers the notification directly to the administrator, providing a simple and reliable real-time alert.

Why this answer

A CloudWatch alarm on the CPUUtilization metric can be configured to evaluate the average CPU usage over a 5-minute period and trigger an action when it exceeds 90%. The alarm can send a notification via Amazon SNS, which can deliver an email to subscribed endpoints. This directly meets the requirement for email notification based on a sustained metric threshold.

Exam trap

The trap here is that candidates may confuse CloudWatch Logs metric filters (which require log data) with CloudWatch metrics (which are numeric time-series data), or think AWS Config can monitor performance metrics instead of configuration compliance.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs metric filters analyze log data (e.g., application logs) for specific patterns, not numeric metrics like CPU utilization; CPU utilization is a standard EC2 metric emitted by the hypervisor, not a log entry. Option B is wrong because AWS Config rules evaluate resource configurations (e.g., instance type, tags) for compliance, not real-time performance metrics like CPU usage; Config does not monitor metric thresholds or trigger SNS notifications for metric breaches. Option C is wrong because a CloudWatch Events rule on EC2 instance state changes (e.g., running, stopped) does not monitor CPU utilization; it only reacts to lifecycle events, not metric-based conditions.

202
MCQeasy

Refer to the exhibit. A SysOps administrator runs the describe-target-health command and sees that an EC2 instance in the target group is unhealthy with a timeout error. What is the most likely cause?

A.The target group is configured with an incorrect port
B.The instance's security group does not allow traffic from the ALB on the health check port
C.The instance is in a private subnet without a NAT gateway
D.The instance does not have a route to the internet
AnswerB

The ALB health check requests are sent from the ALB nodes' private IP addresses to the target's health check port. If the instance's security group lacks an inbound rule that permits TCP on port 80 from the ALB's security group (or the VPC CIDR), the packets are silently dropped. This causes the health check to time out and the target to be marked unhealthy, which matches the observed symptom.

Why this answer

The health check is timing out, which indicates that the instance is not responding to health check requests on port 80. The security group must allow inbound traffic from the ALB on the health check port. Option A is wrong because the target group is configured with port 80, which matches.

Option C is wrong because the route table is less likely to cause a timeout; it would cause unreachability. Option D is wrong because the instance is in a public subnet? Not necessarily; but the health check timeout is most often a security group issue.

203
MCQhard

An IAM user has the policy shown in the exhibit. The user is trying to download an object from example-bucket from an IP address of 192.0.2.50. However, the request is denied. What is the most likely reason?

A.The condition key aws:SourceIp should be aws:SourceIpAddress.
B.The bucket has a bucket policy that denies access from the user's IP address.
C.The resource ARN does not include the bucket itself.
D.The condition syntax is incorrect because it should use StringEquals.
AnswerB

A bucket policy is a resource-based policy, and when a user accesses S3, AWS evaluates both the user's IAM policy and the bucket policy together. Even if the IAM policy explicitly allows s3:GetObject, an explicit deny statement in the bucket policy overrides all permits. Therefore, a bucket policy denying access from the user's IP address would correctly block the user regardless of the IAM allow seen in the exhibit.

Why this answer

The bucket policy explicitly denies the request from IP 192.0.2.50, overriding any IAM policy that allows the action. Option A is incorrect because aws:SourceIp is a valid condition key. Option C is incorrect because the resource ARN 'arn:aws:s3:::example-bucket/*' is appropriate for GetObject on objects.

Option D is incorrect because the condition key aws:SourceIp requires the IpAddress operator, not StringEquals.

204
MCQmedium

A SysOps administrator notices that an EC2 instance's CPU utilization has been at 100% for the past hour. The administrator checks CloudWatch metrics and sees no anomalies in network or disk I/O. Which step should the administrator take to investigate further?

A.Install the CloudWatch Logs agent on the instance to capture system logs.
B.Check the EC2 instance's CPU credit balance in CloudWatch.
C.Stop the EC2 instance and start it again to reset the CPU.
D.Enable detailed monitoring on the EC2 instance to get 1-minute CloudWatch metrics.
AnswerD

Enabling detailed monitoring on the EC2 instance changes the CloudWatch metric delivery interval from the default 5 minutes to 1 minute, giving a much finer-grained view of CPU utilization. With 1-minute data, you can correlate CPU spikes with specific events such as cron jobs, deployment windows, or traffic surges, making it much easier to pinpoint the cause. This is the correct first step in a troubleshooting workflow because it collects the high-resolution performance data needed before any remediation.

Why this answer

Detailed monitoring (1-minute metrics) provides higher-resolution data than the default 5-minute metrics, allowing the administrator to identify short-lived CPU spikes or patterns that might be averaged out in the standard 5-minute interval. Since network and disk I/O appear normal, the issue is likely a process or application consuming CPU, and finer-grained metrics help pinpoint the timing and correlate with specific events or logs.

Exam trap

The trap here is that candidates assume CPU credit balance (Option B) is always the answer for high CPU utilization, but credits only apply to T-series instances, and the question does not specify the instance type, making detailed monitoring the more universally correct first step for investigation.

How to eliminate wrong answers

Option A is wrong because the CloudWatch Logs agent captures system logs (e.g., /var/log/messages) but does not provide CPU utilization metrics; the administrator already has CPU metrics and needs higher resolution, not logs. Option B is wrong because CPU credit balance is only relevant for burstable performance instance types (e.g., T2/T3); the question does not specify the instance type, and 100% CPU utilization for an hour on a non-burstable instance would not involve credits. Option C is wrong because stopping and starting the instance does not reset CPU utilization; it only changes the underlying host, and the root cause (e.g., a runaway process) would persist unless the instance is configured to terminate and relaunch.

205
MCQhard

A SysOps administrator needs to detect when an IAM user attempts to modify an Amazon S3 bucket policy in the production AWS account. The administrator wants to receive an email notification within 5 minutes of such an event. The solution must use AWS managed services with no custom code. Which combination of services should the administrator use?

A.AWS CloudTrail, Amazon CloudWatch Events (Amazon EventBridge), and Amazon SNS
B.AWS CloudTrail, Amazon CloudWatch Logs metric filter, and Amazon SNS
C.Amazon S3 event notifications and Amazon SNS
D.AWS CloudTrail, AWS Lambda, and Amazon SNS
AnswerA

CloudTrail captures the IAM user's API attempt as a management event, and an Amazon EventBridge rule can match the exact API call (for example, PutBucketPolicy) using event patterns. The rule then sends the event to an SNS topic, which delivers an email notification. This pipeline is fully managed, near-real-time, and requires no custom code.

Why this answer

AWS CloudTrail captures the S3 bucket policy modification as a management event, which can be sent to Amazon EventBridge (formerly CloudWatch Events) as a real-time event. EventBridge can then trigger an SNS topic to send an email notification within minutes, all using fully managed services with no custom code required.

Exam trap

The trap here is that candidates often confuse S3 event notifications (object-level) with CloudTrail (management-level), or they assume CloudWatch Logs metric filters are the only way to trigger alarms from logs, overlooking EventBridge's direct event-driven capability for real-time notification without custom code.

How to eliminate wrong answers

Option B is wrong because CloudWatch Logs metric filters operate on log data with a latency of up to 5 minutes for the metric to be created, and then an alarm must be evaluated, which can add additional delay; this does not guarantee notification within 5 minutes and is more complex. Option C is wrong because S3 event notifications are designed for object-level events (e.g., PUT, DELETE) and cannot detect IAM user attempts to modify bucket policies, which are management-level events. Option D is wrong because it requires AWS Lambda custom code to process the CloudTrail event and send the notification, violating the requirement to use only managed services with no custom code.

206
Multi-Selecthard

A CloudFormation stack update fails and enters UPDATE_ROLLBACK_FAILED. Which two actions are appropriate next steps? (Choose 2.)

Select 2 answers
A.Review stack events to identify the resource that blocked rollback.
B.Use continue-update-rollback after resolving the underlying issue or specifying resources to skip when appropriate.
C.Delete the CloudFormation service role from IAM.
D.Rename the stack to force rollback completion.
AnswersA, B

Stack events expose the precise CloudFormation status of each logical resource during the failed update and subsequent rollback attempt, including the exact API error that caused the rollback to stall—for example, an EC2 security group dependency that could not be evaluated. By reviewing the most recent event entries, you can pinpoint whether a resource is stuck in CLEANUP_IN_PROGRESS or UPDATE_ROLLBACK_IN_PROGRESS and read the underlying failure message. This diagnosis determines whether you can safely run continue-update-rollback without skipping resources.

Why this answer

When a CloudFormation stack update fails and enters UPDATE_ROLLBACK_FAILED, the stack events provide detailed error messages for each resource that failed during rollback. Reviewing these events is essential to identify the specific resource that blocked the rollback, such as a resource that could not be deleted or updated due to permissions, dependencies, or configuration issues. This diagnosis is the first step before attempting a continue-update-rollback operation.

Exam trap

The trap here is that candidates may think deleting the service role or renaming the stack are valid recovery actions, but AWS CloudFormation requires explicit rollback continuation or manual intervention via the continue-update-rollback API, not workarounds that break IAM or naming conventions.

207
MCQhard

An application uses Amazon Route 53 weighted routing to distribute traffic across two AWS regions. After a deployment, users in one region are experiencing errors. What should the administrator do to mitigate the issue immediately?

A.Update the alias record to point to a different load balancer.
B.Change the routing policy from weighted to latency-based.
C.Restart the EC2 instances in the affected region.
D.Set the weight of the affected region's record to 0 and verify health checks are configured.
AnswerD

Weighted routing with weight 0 stops Route 53 returning that region's record while leaving the other region serving traffic, giving immediate mitigation. Health checks then prevent DNS from resolving to the failing region if it is re-enabled.

Why this answer

Setting the weight of the affected region's Route 53 record to 0 immediately removes that region from the weighted routing rotation, diverting all traffic to the healthy region. Verifying that health checks are configured ensures Route 53 can automatically fail over if the region becomes unhealthy again, providing both immediate mitigation and ongoing resilience.

Exam trap

The trap is reaching for a design change (latency-based routing) or a disruptive action (restarting instances) when the question asks for immediate mitigation — candidates must recognize that setting weight to 0 is the fastest, least disruptive Route 53-native way to drain traffic from a failing region.

How to eliminate wrong answers

Option A is wrong because updating an alias record to point to a different load balancer is a manual, disruptive change that doesn't leverage Route 53's weighted routing capabilities and could cause additional downtime. Option B is wrong because changing the routing policy from weighted to latency-based is a design change, not an immediate mitigation — it also doesn't guarantee traffic avoids the failing region if latency is still low. Option C is wrong because restarting EC2 instances is a guess at the root cause and may not resolve the issue; it also causes additional disruption without guaranteeing recovery.

208
MCQmedium

A company's security policy requires that all new Amazon S3 buckets must have server-side encryption with AWS Key Management Service (SSE-KMS) enabled by default. A SysOps administrator wants to enforce this requirement for all current and future S3 buckets in the account. Which AWS service or feature should be used to automatically apply this configuration?

A.Enable S3 default encryption at the account level in the S3 console.
B.Create an AWS CloudTrail trail that captures S3 API calls and triggers a Lambda function to enable encryption on any bucket that is created without it.
C.Use an AWS Organizations Service Control Policy (SCP) to deny the s3:PutBucketPublicAccessBlock action, forcing users to enable encryption.
D.Use AWS Config with the 's3-bucket-server-side-encryption-enabled' managed rule and configure automatic remediation to apply SSE-KMS when a non-compliant bucket is detected.
AnswerD

AWS Config can evaluate all buckets (current and future) against the rule. Automatic remediation can invoke an SSM Automation document or a Lambda function to enable SSE-KMS on the bucket, meeting the requirement with a managed service.

Why this answer

AWS Config with the 's3-bucket-server-side-encryption-enabled' managed rule can evaluate S3 buckets for compliance with server-side encryption requirements. When a non-compliant bucket is detected, automatic remediation can be configured to apply SSE-KMS using an AWS Systems Manager Automation document, ensuring all current and future buckets meet the security policy without manual intervention.

Exam trap

The trap here is that candidates confuse S3 default encryption (which is bucket-level only) with account-level enforcement, or they mistakenly think SCPs can directly enable encryption rather than just deny actions, leading them to pick options that are reactive or misaligned with the requirement.

How to eliminate wrong answers

Option A is wrong because S3 default encryption can only be set at the bucket level, not at the account level; there is no account-level setting in the S3 console to enforce encryption on all buckets. Option B is wrong because while CloudTrail and Lambda can reactively fix buckets after creation, this approach is event-driven and not a proactive enforcement mechanism; it also relies on custom code and may introduce latency or gaps. Option C is wrong because the s3:PutBucketPublicAccessBlock action controls public access block settings, not server-side encryption; denying this action does nothing to enforce SSE-KMS, and SCPs cannot directly enable encryption on resources.

209
MCQmedium

A SysOps administrator needs to grant cross-account access to an S3 bucket in Account A for an IAM user in Account B. The bucket policy in Account A allows the IAM user's account root principal. What additional configuration is required?

A.Modify the AWS KMS key policy to allow the user in Account B
B.Add a bucket ACL granting access to the user in Account B
C.Add an AWS Organizations service control policy to allow access
D.Attach an IAM policy to the user in Account B that allows the required S3 actions
AnswerD

Attaching an IAM policy to the user in Account B is required because the user must have explicit permission to perform the S3 actions against the bucket in Account A. Even if Account A's bucket policy grants cross-account access to that user, the user's own IAM policy must also allow the actions, as permissions in AWS are effectively the intersection of the identity-based and resource-based policies. Without this IAM policy, the user will be denied access regardless of the bucket policy. Therefore, this is the correct necessary step.

Why this answer

D is correct because cross-account access to an S3 bucket requires both a bucket policy that grants access to the root principal of the target account (Account B) and an IAM policy attached to the user in Account B that explicitly allows the desired S3 actions. Without the IAM policy, the user in Account B has no permissions to perform any S3 operations, even though the bucket policy in Account A permits the account root. The IAM policy acts as the identity-based permission that authorizes the specific user to invoke the S3 API calls.

Exam trap

The trap here is that candidates assume the bucket policy alone is sufficient for cross-account access, forgetting that the IAM user in the target account must also have an explicit IAM policy allowing the S3 actions, as AWS requires both resource-based and identity-based permissions to be evaluated and both must allow the operation.

How to eliminate wrong answers

Option A is wrong because AWS KMS key policies are only relevant if the S3 bucket uses SSE-KMS encryption; the question does not mention encryption, and modifying the KMS key policy is not a general requirement for cross-account S3 access. Option B is wrong because bucket ACLs are legacy and cannot grant access to an IAM user in another account; they only support granting access to AWS accounts or predefined groups, not individual IAM users. Option C is wrong because AWS Organizations service control policies (SCPs) apply to all principals within an organization and are used to set permission boundaries, not to grant cross-account access; they cannot be used to allow a specific IAM user in another account.

210
MCQeasy

A company has a fleet of EC2 instances that need to be patched monthly. The SysOps administrator must ensure that the patching process does not affect the availability of the application. Which strategy should the administrator use?

A.Patch one instance at a time manually by stopping and starting.
B.Use an Auto Scaling group with a rolling update strategy.
C.Use AWS Systems Manager Patch Manager to patch all instances at once.
D.Stop all instances, apply patches, then start them.
AnswerB

An Auto Scaling group with a rolling update strategy replaces a small number of instances at a time by updating the launch template with a patched AMI or user data and then performing an instance refresh (or manually incrementing the desired count). Each new instance must pass the group's health checks before the next batch is terminated, so the fleet maintains its desired capacity and continuous availability throughout the patching process. This approach is the correct one because it combines automation, health verification, and controlled blast radius, ensuring that no single point of failure or full downtime occurs.

Why this answer

Using an Auto Scaling group with a rolling update strategy allows the administrator to replace instances in batches, ensuring that a minimum number of instances remain in service throughout the patching process. This maintains application availability by avoiding simultaneous disruption to all instances, which is a key requirement for high-availability architectures.

Exam trap

The trap here is that candidates often assume AWS Systems Manager Patch Manager can be configured to patch instances in a rolling fashion, but by default it runs on all targeted instances simultaneously unless explicitly orchestrated with a maintenance window and rate control, which is not the same as an Auto Scaling group rolling update.

How to eliminate wrong answers

Option A is wrong because manually patching one instance at a time by stopping and starting is error-prone, lacks automation, and does not integrate with health checks or lifecycle hooks to ensure the instance is fully operational before proceeding, risking downtime if the manual process is slow or fails. Option C is wrong because using AWS Systems Manager Patch Manager to patch all instances at once would apply patches simultaneously, potentially causing all instances to reboot at the same time and resulting in complete application downtime. Option D is wrong because stopping all instances, applying patches, and then starting them creates a total outage window where the application is unavailable, violating the requirement to not affect availability.

211
MCQmedium

A company runs a web application on a fleet of Amazon EC2 instances behind an Application Load Balancer. The application has predictable traffic patterns with high traffic during business hours and low traffic at night. The SysOps administrator wants to reduce compute costs while ensuring the application remains responsive during peak hours. The administrator has already implemented Auto Scaling based on CPU utilization. Which additional action should the administrator take to optimize costs?

A.Use On-Demand instances only
B.Purchase Reserved Instances for the baseline capacity and use Spot Instances for the additional capacity during peak hours
C.Increase the minimum number of instances in the Auto Scaling group
D.Use Dedicated Hosts to reduce licensing costs
AnswerB

This approach minimizes costs by applying the highest discount (Reserved Instances) to the steady-state capacity and leveraging the cost savings of Spot Instances for the flexible, peak-demand capacity. Auto Scaling can be configured to launch Spot Instances as needed, providing both cost efficiency and performance.

Why this answer

It combines Reserved Instances for predictable baseline capacity (lower cost per hour) with Spot Instances for elastic peak demand, leveraging Auto Scaling to handle variable traffic. This hybrid approach reduces compute costs compared to using On-Demand instances for all capacity, while maintaining responsiveness during peak hours.

Exam trap

The trap here is that candidates may think increasing the minimum instance count (Option C) improves responsiveness, but it actually increases costs during low-traffic periods without addressing the cost optimization goal.

How to eliminate wrong answers

Option A is wrong because using only On-Demand instances ignores cost-saving opportunities from Reserved or Spot Instances, leading to higher costs for predictable baseline traffic. Option C is wrong because increasing the minimum number of instances raises baseline costs unnecessarily, as the application has low traffic at night and does not require a higher minimum. Option D is wrong because Dedicated Hosts are designed for licensing or compliance requirements, not for general cost optimization, and they incur additional costs without addressing variable traffic patterns.

212
Multi-Selecthard

A SysOps administrator needs to receive alerts when an S3 bucket is publicly accessible. Which TWO AWS services can be used to monitor and detect this configuration?

Select 2 answers
A.AWS CloudTrail
B.AWS Security Hub
C.AWS Trusted Advisor
D.AWS Config
E.Amazon CloudWatch
AnswersB, D

AWS Security Hub aggregates security findings from AWS Config rules and other integrated services, including custom or managed rules that detect S3 bucket policy changes. By enabling appropriate controls, you can use Security Hub's consolidated findings to trigger alerts via EventBridge or CloudWatch. This makes it suitable for receiving actionable alerts when a bucket policy is modified.

Why this answer

AWS Security Hub (B) is correct because it aggregates security findings from multiple AWS services, including Amazon GuardDuty and AWS Config, and can detect publicly accessible S3 buckets via its built-in security standards (e.g., CIS AWS Foundations Benchmark). AWS Config (D) is correct because it can evaluate S3 bucket configurations against rules, such as the managed rule 's3-bucket-public-read-prohibited' or 's3-bucket-public-write-prohibited', and trigger alerts when a bucket becomes publicly accessible.

Exam trap

The trap here is that candidates often choose AWS Trusted Advisor (C) because it has a 'S3 Bucket Permissions' check, but they overlook that it does not provide real-time alerts or continuous monitoring, unlike AWS Config which can trigger immediate notifications via Amazon SNS.

213
MCQeasy

An application uploads files to an S3 bucket. The SysOps administrator needs to ensure that the files are automatically replicated to another bucket in a different AWS Region for disaster recovery. Which action should be taken?

A.Enable Cross-Region Replication on the source bucket.
B.Use S3 Transfer Acceleration for faster uploads.
C.Enable versioning on the source bucket.
D.Configure a lifecycle policy to transition objects to Glacier.
AnswerA

Cross-Region Replication (CRR) is the correct mechanism because it asynchronously copies objects from your source S3 bucket to a separate destination bucket in a different AWS Region. To use CRR, you must enable versioning on both the source and destination buckets, and S3 creates an IAM role with permissions to read from the source and write to the destination. Once configured, every new upload is automatically replicated, including metadata and object versions, giving you a second copy in another region for disaster recovery and compliance.

Why this answer

Cross-Region Replication (CRR) is the correct AWS feature to automatically replicate objects from a source S3 bucket to a destination bucket in a different AWS Region. CRR requires versioning to be enabled on both the source and destination buckets, and it copies every object uploaded to the source bucket asynchronously to the destination bucket, providing disaster recovery across regions.

Exam trap

The trap here is that candidates often confuse enabling versioning (a prerequisite for CRR) with the actual replication action, or they mistakenly think Transfer Acceleration or lifecycle policies can achieve cross-region replication.

How to eliminate wrong answers

Option B is wrong because S3 Transfer Acceleration speeds up uploads over long distances using AWS edge locations, but it does not replicate data to another region. Option C is wrong because enabling versioning alone does not replicate objects; it only preserves multiple versions of objects within the same bucket. Option D is wrong because a lifecycle policy transitions objects to Amazon S3 Glacier for cost optimization, not for cross-region replication or disaster recovery.

214
Multi-Selectmedium

A company is running a high-performance computing (HPC) workload on EC2. The workload is time-sensitive and runs for 2 hours every night. The company wants to minimize costs. Which THREE options should they consider? (Choose THREE.)

Select 3 answers
A.Purchase Reserved Instances for the nightly run.
B.Use an EFS or S3 as shared storage instead of EBS volumes.
C.Use smaller instance types and distribute the workload.
D.Use Dedicated Instances for performance isolation.
E.Use Spot Instances to take advantage of lower pricing.
AnswersB, C, E

Using a shared file system like Amazon EFS or object storage like Amazon S3 lets all HPC compute nodes access the same dataset without each node needing its own EBS volume copy. EBS volumes are per-instance block storage charged by GB-month plus IOPS, so duplicating data across hundreds of instances multiplies storage cost and also creates consistency problems when output is written locally. EFS automatically scales and is designed for shared POSIX access, while S3 is ideal for input/output datasets and checkpoint artifacts—both eliminate redundant EBS allocations.

Why this answer

Options B, C, and E are correct. B is correct because using EFS or S3 as shared storage reduces costs compared to attaching individual EBS volumes to each instance. C is correct because using smaller instance types in parallel can be more cost-effective for HPC workloads that can be parallelized.

E is correct because Spot Instances offer significant discounts for fault-tolerant workloads like HPC. Option A is incorrect because Reserved Instances require a 1-3 year commitment and would not be cost-effective for a 2-hour nightly job. Option D is incorrect because Dedicated Instances are more expensive and not necessary for this workload.

215
MCQhard

A company runs a critical application on a fleet of EC2 instances in an Auto Scaling group. The application is deployed using a blue/green deployment strategy with AWS CodeDeploy. The green environment fails immediately after deployment, and the deployment is automatically rolled back. However, the rollback also fails because the original blue environment's Auto Scaling group has been scaled down. What should the SysOps administrator do to prevent this issue in future deployments?

A.Configure the deployment to automatically delete the green environment after rollback.
B.Increase the minimum size of the Auto Scaling group.
C.Change the deployment type to in-place.
D.Set the original environment termination delay to a longer duration in the CodeDeploy deployment group.
AnswerD

In AWS CodeDeploy blue/green deployments, the original instances (the blue environment) are kept alive for a configured 'original environment termination delay' before being terminated. Extending this delay preserves the blue fleet for a longer period, allowing you to roll back by rerouting traffic back to the original instances if the new deployment proves faulty. This is the proper mechanism to ensure the original environment remains available for rollback, either automatically or through manual intervention.

Why this answer

Setting the original environment termination delay in the CodeDeploy deployment group ensures that the blue Auto Scaling group instances are not terminated immediately after a successful deployment. This delay keeps the blue environment available during the rollback window, preventing the rollback failure that occurs when the original environment has already been scaled down. The termination delay is a configurable setting in CodeDeploy that holds the old instances for a specified period, allowing a safe fallback if the new environment fails.

Exam trap

The trap here is that candidates often assume increasing the Auto Scaling group's minimum size (Option B) will preserve the blue environment, but they miss that CodeDeploy explicitly terminates the old instances as part of the blue/green deployment lifecycle, regardless of the minimum size setting.

How to eliminate wrong answers

Option A is wrong because automatically deleting the green environment after rollback does not address the root cause—the blue environment being unavailable; it only cleans up the failed environment. Option B is wrong because increasing the minimum size of the Auto Scaling group does not prevent the blue group from being scaled down during the deployment lifecycle; it only ensures a minimum number of instances are always running, but the blue group's instances are still terminated by CodeDeploy after the deployment completes. Option C is wrong because changing the deployment type to in-place would cause downtime and does not solve the rollback issue; in-place deployments update existing instances without preserving a separate blue environment, making rollback even more difficult.

216
MCQmedium

A SysOps Administrator is troubleshooting connectivity issues between two EC2 instances in the same VPC but different subnets. The instances can communicate over private IP addresses when security groups are set to allow all traffic, but fail when security groups are configured with specific rules. The Administrator wants to allow HTTP (port 80) and HTTPS (port 443) traffic from the client instance to the server instance. What security group rules are needed?

A.Add inbound rules on the server to allow HTTP and HTTPS from the client security group.
B.Add inbound rules on both the client and server.
C.Add outbound rules on both the client and server.
D.Add inbound rules on the client and outbound rules on the server.
AnswerA

Security groups are stateful, so adding inbound rules on the server to permit HTTP (80) and HTTPS (443) from the client security group is the correct, minimal fix. The inbound rule allows the client's request to reach the server, and because stateful filtering tracks the connection, the server's response is automatically allowed back to the client without any outbound rule on the server. The client security group as the source scopes access precisely to instances with that group, avoiding a 0.0.0.0/0 exposure.

Why this answer

Security groups are stateful, meaning that if you allow inbound traffic, the response outbound is automatically allowed regardless of outbound rules. Therefore, you only need to add inbound rules on the server instance to allow HTTP and HTTPS traffic from the client security group. Option B is incorrect because no inbound rules are needed on the client.

Option C is incorrect because no outbound rules are needed on either instance for this traffic. Option D is incorrect because outbound rules on the server are not required.

217
MCQeasy

A company is using Amazon S3 to host a static website. The website receives millions of requests per month from users around the world. The company wants to reduce latency and S3 data transfer costs. Which solution should the company implement?

A.Enable S3 replication to multiple regions.
B.Use Amazon CloudFront as a content delivery network in front of the S3 bucket.
C.Enable S3 Transfer Acceleration.
D.Use S3 Cross-Region Replication to replicate objects to all regions.
AnswerB

Amazon CloudFront fronts the S3 bucket with a global network of edge locations that cache static assets, so requests are served from the closest edge PoP rather than from the origin bucket directly. This reduces round-trip latency significantly for users worldwide and offloads repeated requests from S3. Additionally, CloudFront provides HTTPS termination and helps cut data transfer costs, as egress from edge locations is cheaper than direct S3 transfer for large audiences. This is the standard, designed solution for improving static site performance.

Why this answer

Amazon CloudFront is a content delivery network that caches content at edge locations, reducing latency and data transfer costs from S3. S3 Transfer Acceleration speeds up uploads but not downloads. S3 Replication does not reduce latency.

S3 Cross-Region Replication is for data redundancy, not performance.

218
MCQeasy

A development team uses AWS CloudFormation to deploy infrastructure. They want to update a stack but first need to review how the changes will impact existing resources before applying them. Which CloudFormation feature should they use?

A.Change sets
B.Stack policies
C.Condition functions
D.Custom resources
AnswerA

Change sets in AWS CloudFormation let you create a summary of proposed modifications to a stack without applying them. They provide a preview of exactly which resources will be added, modified, or removed, and indicate whether a change will cause replacement or simple updates. This review capability is especially valuable for production stacks, as it lets you catch unintended destructive actions before they execute.

Why this answer

Change sets allow you to preview how proposed changes to a CloudFormation stack will affect your running resources before you apply them. They generate a summary of the changes (additions, modifications, deletions) based on the new template and parameters, enabling you to assess impact such as resource replacement or updates without executing the changes. This directly addresses the team's requirement to review changes before applying them.

Exam trap

The trap here is that candidates confuse stack policies (which guard resources during updates) with change sets (which preview changes), or assume condition functions or custom resources can simulate change impact, but only change sets provide a declarative diff before execution.

How to eliminate wrong answers

Option B is wrong because stack policies are used to prevent accidental updates or deletions of specific stack resources during a stack update, not to preview changes. Option C is wrong because condition functions (e.g., Fn::If) control whether certain resources are created or properties are set based on conditions in the template, but they do not provide a preview of change impact. Option D is wrong because custom resources allow you to handle provisioning logic for resources not natively supported by CloudFormation, but they do not offer a mechanism to review changes before an update.

219
MCQhard

A company stores video files in Amazon S3. The files are accessed frequently for the first week, then weekly for the next month, and then rarely after that. The files must be retained for 5 years and any access must be served within minutes. The SysOps administrator needs to minimize storage costs while meeting these requirements. Which lifecycle policy configuration is the most cost-effective?

A.Transition to S3 Standard-IA after 7 days, then to S3 Glacier Flexible Retrieval after 30 days.
B.Transition to S3 One Zone-IA after 7 days, then to S3 Glacier Deep Archive after 30 days.
C.Transition to S3 Standard-IA after 7 days, then to S3 Glacier Instant Retrieval after 30 days.
D.Transition to S3 Intelligent-Tiering after 7 days.
AnswerC

S3 Standard-IA after 7 days is a sound choice because the files are accessed weekly during that period, and Standard-IA offers the same high durability (99.999999999%) and millisecond latency as Standard while reducing storage costs. After 30 days, transitioning to S3 Glacier Instant Retrieval further cuts storage costs while still providing millisecond retrieval times, so the videos remain instantly accessible on demand. This lifecycle meets the 'within minutes' requirement without incurring the higher retrieval latency or costs of Flexible Retrieval or Deep Archive, making it the most cost-effective and compliant strategy.

Why this answer

It transitions to S3 Standard-IA after 7 days (matching the frequent first-week access), then to S3 Glacier Instant Retrieval after 30 days (matching the weekly access for the next month). Glacier Instant Retrieval provides millisecond retrieval for rarely accessed data, meeting the 'within minutes' requirement while minimizing costs compared to Standard-IA or Intelligent-Tiering.

Exam trap

The trap here is that candidates often confuse S3 Glacier Flexible Retrieval or S3 Glacier Deep Archive as cost-effective options without verifying the retrieval time requirement, assuming 'Glacier' always means cheap but slow, while the question explicitly requires access 'within minutes'.

How to eliminate wrong answers

Option A is wrong because S3 Glacier Flexible Retrieval has retrieval times of minutes to hours (not within minutes), failing the access requirement. Option B is wrong because S3 One Zone-IA does not provide the durability needed for long-term retention (5 years) and S3 Glacier Deep Archive has retrieval times of 12-48 hours, violating the 'within minutes' requirement. Option D is wrong because S3 Intelligent-Tiering incurs monitoring and automation costs that are not cost-effective for a predictable access pattern, and it does not transition to a cold storage tier that minimizes costs for rarely accessed data after 30 days.

220
MCQhard

A company uses an Amazon DynamoDB table with on-demand capacity mode for a variable workload. The SysOps administrator notices high costs and wants to reduce them without affecting application performance. Which action should the administrator take?

A.Switch the table to provisioned capacity mode with auto scaling.
B.Enable DynamoDB Accelerator (DAX) for caching.
C.Implement DynamoDB Global Tables to distribute data across regions.
D.Set a Time to Live (TTL) attribute to automatically expire old items.
AnswerA

On-demand capacity mode charges per request and is ideal for unpredictable traffic, but for workloads with steady or moderately variable usage, provisioned capacity with auto scaling is significantly cheaper because you commit to a baseline of capacity units and pay only for what you provision, while auto scaling adjusts the provisioned throughput based on real-time utilization via CloudWatch alarms, preventing over-provisioning and reducing cost without manual intervention.

Why this answer

Switching from on-demand to provisioned capacity with auto scaling reduces costs for variable workloads by allowing you to set a lower base capacity and scale only when needed, avoiding the premium per-request pricing of on-demand mode. Auto scaling adjusts read/write capacity based on actual utilization, ensuring application performance is maintained while eliminating the cost overhead of paying for every request at on-demand rates.

Exam trap

The trap here is that candidates assume on-demand mode is always the most cost-effective for variable workloads, but the exam tests that provisioned capacity with auto scaling can be cheaper for predictable variability, and that options like DAX or TTL address different cost components (latency or storage) rather than the per-request compute cost.

How to eliminate wrong answers

Option B is wrong because DynamoDB Accelerator (DAX) is an in-memory caching service that reduces read latency and costs for repeated reads, but it does not address the core issue of high write costs or the per-request pricing model of on-demand mode; it adds an additional service cost. Option C is wrong because DynamoDB Global Tables replicate data across regions for disaster recovery and low-latency global access, which increases costs due to cross-region replication and additional storage, not reduces them. Option D is wrong because setting a Time to Live (TTL) attribute automatically expires old items to reduce storage costs, but it does not reduce the compute cost of read/write operations, which is the primary driver of high costs in on-demand mode.

221
MCQhard

A SysOps administrator is troubleshooting a failed AWS CloudFormation stack creation. The stack includes an AWS::Lambda::Function resource. The error message states: 'The runtime parameter of nodejs8.10 is no longer supported.' The administrator needs to resolve this with minimal changes. What should the administrator do?

A.Modify the Lambda function code to use Python 3.8.
B.Manually update the runtime in the AWS Lambda console after the stack creation fails.
C.Update the CloudFormation template to use a supported Node.js runtime, such as nodejs14.x.
D.Wait for AWS to re-enable the nodejs8.10 runtime.
AnswerC

Updating the CloudFormation template's Runtime property from nodejs8.10 to a supported version like nodejs14.x directly resolves the deprecation error and lets AWS re-validate the template successfully. This is the minimal configuration change that preserves the existing Node.js code while making the stack deployable. After updating the template, the stack can be recreated or updated without further code modifications.

Why this answer

Updating the CloudFormation template to use a supported Node.js runtime (e.g., nodejs14.x) is the minimal-change fix because the error is caused by an unsupported runtime parameter in the template. Changing the template and redeploying resolves the stack creation failure.

Exam trap

SOA-C02 often tests whether candidates choose manual console fixes or code rewrites when the root cause is a deprecated runtime in the CloudFormation template — the minimal fix is updating the template.

How to eliminate wrong answers

Option A is wrong because rewriting the function code in Python is a major change and unnecessary when only the runtime version is the issue. Option B is wrong because manually updating the runtime in the console after a failed stack creation does not fix the template and will cause drift or future failures. Option D is wrong because AWS does not re-enable deprecated runtimes; nodejs8.10 is permanently deprecated.

222
Multi-Selecthard

Which THREE measures help protect an S3 bucket from accidental data loss? (Choose 3)

Select 3 answers
A.Enable MFA Delete on the bucket.
B.Create a lifecycle policy to transition objects to S3 Glacier.
C.Enable server-side encryption on the bucket.
D.Configure cross-region replication to a destination bucket.
E.Enable versioning on the bucket.
AnswersA, D, E

MFA Delete requires a valid multi-factor authentication code to permanently delete an object version or suspend versioning, meaning an accidental delete request without the temporary code will be rejected. Because the MFA device is separate from AWS credentials, even a compromised access key cannot complete destructive actions like version removal. This adds a human/physical factor that effectively prevents costly accidental deletions and serves as a last line of defense for critical data.

Why this answer

Enabling MFA Delete on an S3 bucket requires multi-factor authentication for any delete operations, adding an extra layer of protection against accidental or unauthorized deletion of objects. This helps prevent data loss by ensuring that even if credentials are compromised, a delete action cannot be performed without the MFA token.

Exam trap

The trap here is that candidates often confuse data protection features like encryption or lifecycle policies with data durability and accidental deletion prevention, leading them to select options that secure data but do not prevent loss from deletion.

223
MCQmedium

A company has an application that writes logs to CloudWatch Logs. The SysOps administrator needs to search for a specific error pattern across multiple log groups. Which solution is the most efficient?

A.Create a CloudWatch dashboard to visualize log data.
B.Use CloudWatch Logs Insights to query the log groups.
C.Create a metric filter to count the error pattern.
D.Create a subscription filter to stream logs to Amazon ES.
AnswerB

CloudWatch Logs Insights provides a dedicated query engine with a SQL-like syntax for analyzing log data stored in log groups. It automatically parses fields such as @timestamp, @message, and @logStream, enabling you to filter, aggregate, and search across log events interactively. This is the most efficient and direct method for answering ad-hoc questions about log contents, requiring no additional services or configuration.

Why this answer

CloudWatch Logs Insights is purpose-built for interactive ad-hoc querying of log data across multiple log groups, enabling efficient pattern matching and filtering without requiring pre-configured infrastructure. It uses a dedicated query language optimized for searching, aggregating, and analyzing log events, making it the most efficient solution for searching a specific error pattern across multiple log groups.

Exam trap

The trap here is that candidates often confuse metric filters (which only count occurrences) with the ability to search and retrieve actual log events, leading them to choose Option C instead of the correct query-based solution.

How to eliminate wrong answers

Option A is wrong because CloudWatch dashboards are designed for visualizing metrics and log data in pre-defined widgets, not for performing ad-hoc searches or queries across multiple log groups. Option C is wrong because metric filters only count occurrences of a pattern and emit a metric, but they do not allow you to search or retrieve the actual log events containing the error pattern. Option D is wrong because subscription filters stream logs to Amazon ES (now OpenSearch Service) for long-term analysis and visualization, which adds latency, cost, and operational overhead compared to directly querying the log groups with Logs Insights.

224
MCQhard

An IAM policy is attached to an EC2 instance role to allow sending logs to CloudWatch Logs. The application running on the instance fails to send logs to the log group 'MyAppLogGroup'. Which change is required to fix the issue?

A.Install the CloudWatch agent on the instance.
B.Attach the policy to the EC2 instance instead of the instance role.
C.Add a new statement allowing logs:PutLogEvents on 'arn:aws:logs:us-east-1:123456789012:log-group:MyAppLogGroup:log-stream:*'.
D.Change the log group ARN in the policy to include the log stream name.
AnswerC

Adding a statement that allows logs:PutLogEvents on the log-stream ARN (with a wildcard for the stream name) is the correct fix because CloudWatch Logs evaluates that action against the log stream resource, not the log group. A policy that only grants logs:PutLogEvents on the log group ARN is insufficient; even if the log group action is allowed, the stream-level action is still denied. By explicitly permitting the put operation on 'arn:aws:logs:us-east-1:123456789012:log-group:MyAppLogGroup:log-stream:*', the SDK can create and write to any log stream under that group.

Why this answer

The IAM policy attached to the EC2 instance role is missing the `logs:PutLogEvents` permission for the specific log stream within the log group. Even if the policy allows `logs:CreateLogStream` and `logs:DescribeLogGroups`, the application cannot send log events without `logs:PutLogEvents` on the log stream resource. Option C adds the required statement with the correct ARN pattern to resolve the failure.

Exam trap

The trap here is that candidates assume the CloudWatch agent is required for any log delivery, or that attaching a policy directly to the instance is possible, when the real issue is a missing `PutLogEvents` permission on the log stream resource.

How to eliminate wrong answers

Option A is wrong because the CloudWatch agent is not required for sending logs via the AWS SDK or CLI; the application can use the `PutLogEvents` API directly, and the issue is a permissions problem, not a missing agent. Option B is wrong because IAM policies cannot be attached directly to an EC2 instance; they must be attached to an IAM role that is then associated with the instance profile. Option D is wrong because the log group ARN in the policy does not need to include the log stream name; the policy can use a wildcard for the log stream (e.g., `log-stream:*`) to allow `PutLogEvents` on any stream within the group.

225
MCQmedium

A company's security policy requires that all IAM users must authenticate with multi-factor authentication (MFA) before they can perform any actions on Amazon EC2 instances. The SysOps administrator needs to enforce this requirement using IAM policies. Which IAM policy condition key should the administrator use in the policy?

A.aws:MultiFactorAuthPresent
B.aws:SourceIp
C.iam:PassedToService
D.ec2:SourceInstanceARN
AnswerA

The aws:MultiFactorAuthPresent condition key is a global IAM condition that evaluates to true when the principal authenticated with a valid MFA device. In a policy, adding "aws:MultiFactorAuthPresent": "true" to a condition ensures the action is permitted only if MFA was used, regardless of whether the request originates from the console, an API call, or temporary credentials. If MFA was not used, the key evaluates to false (or is absent), causing the condition to fail, which directly enforces the security policy that all IAM users must use MFA.

Why this answer

The `aws:MultiFactorAuthPresent` condition key allows the administrator to enforce MFA authentication by checking whether the user authenticated with a valid MFA device before allowing the action. When set to `true`, the policy denies access to EC2 actions unless the user has completed MFA. This directly satisfies the security policy requirement.

Exam trap

The trap here is that candidates confuse `aws:MultiFactorAuthPresent` with `aws:SourceIp` or `iam:PassedToService`, mistakenly thinking IP-based or role-passing conditions can enforce MFA, when only the MFA-specific condition key works.

How to eliminate wrong answers

Option B is wrong because `aws:SourceIp` is used to restrict access based on the originating IP address, not to enforce MFA authentication. Option C is wrong because `iam:PassedToService` is used to control which roles can be passed to AWS services (e.g., EC2), not to enforce MFA for user actions. Option D is wrong because `ec2:SourceInstanceARN` is a condition key for EC2-to-EC2 traffic or resource-based policies, not for IAM user authentication requirements.

Page 2

Page 3 of 16

Page 4