Courseiva

AWS Certified SysOps Administrator Associate SOA-C02 (SOA-C02) — Questions 226–300

1169 questions total · 16pages · All types, answers revealed

Page 3

Page 4 of 16

Page 5
226
MCQeasy

A company's security policy requires that the AWS account root user must have multi-factor authentication (MFA) enabled. A SysOps administrator needs to continuously verify compliance and automatically notify the security team if the root user is not configured with MFA. Which AWS service can be used to create a compliance rule for this requirement?

A.AWS Trusted Advisor
B.AWS Config with the managed rule 'root-account-mfa-enabled'
C.AWS Identity and Access Management (IAM) Access Analyzer
D.Amazon Inspector
AnswerB

AWS Config with the managed rule 'root-account-mfa-enabled' continuously evaluates the root user's MFA configuration against the rule's desired state. When the root account becomes non-compliant, AWS Config can publish configuration change notifications to Amazon SNS via EventBridge, allowing automated alerting and remediation. This rule is available as a managed rule and works across all supported regions and accounts with minimal setup, making it the correct choice for verifying and monitoring root MFA compliance.

Why this answer

AWS Config provides a managed rule called 'root-account-mfa-enabled' that continuously evaluates whether the root user has an MFA device configured. When the rule detects non-compliance, it can trigger an Amazon SNS notification to alert the security team, meeting the requirement for automated compliance verification and alerting.

Exam trap

The trap here is that candidates confuse AWS Trusted Advisor's security checks (which include a root MFA check but lack continuous evaluation and automated notification) with AWS Config's managed rules that provide ongoing compliance monitoring and event-driven alerts.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor provides best-practice checks and recommendations but does not offer continuous compliance rules with automated notifications for root user MFA status. Option C is wrong because IAM Access Analyzer analyzes resource policies for external access, not root user MFA configuration compliance. Option D is wrong because Amazon Inspector assesses vulnerabilities in EC2 instances and container workloads, not IAM user configurations.

227
MCQhard

A company runs a critical application on EC2 instances in an Auto Scaling group. The application stores state information locally on the instance. The SysOps administrator needs to ensure that if an instance fails, the state is not lost. What should the administrator do?

A.Move the state data to an external data store such as ElastiCache or RDS.
B.Attach an EBS volume and set the 'DeleteOnTermination' flag to false.
C.Use instance store volumes for the state data.
D.Use Amazon SQS to store the state data.
AnswerA

Externalizing state to a managed service like ElastiCache or RDS decouples application data from the EC2 instance lifecycle, so any instance failure, termination, or replacement has no impact on data availability. ElastiCache provides extremely low-latency in-memory state ideal for session/state caching, while RDS offers durable, ACID-compliant storage with automated backups and multi-AZ failover. This design pattern makes the application stateless at the instance tier, enabling Auto Scaling, rolling deployments, and immediate recovery because new instances simply reconnect to the same external state store.

Why this answer

State stored locally on an EC2 instance is ephemeral and lost if the instance fails or is terminated. The most reliable solution is to externalize state to a durable, shared data store such as ElastiCache (for session state) or RDS (for relational state). This decouples the application from the instance lifecycle and allows any instance in the Auto Scaling group to serve requests.

Exam trap

SOA-C02 often tests the misconception that EBS volumes with DeleteOnTermination=false provide high availability for state; candidates must recognize that shared, external state stores are required for Auto Scaling groups.

How to eliminate wrong answers

Option B is wrong because attaching an EBS volume with DeleteOnTermination=false preserves the volume but does not automatically make the state available to a replacement instance; the new instance would need to attach and mount the volume, and EBS volumes are tied to an Availability Zone, complicating Auto Scaling. Option C is wrong because instance store volumes are ephemeral and lose data on instance stop, termination, or hardware failure, which is the opposite of what is needed. Option D is wrong because SQS is a message queue, not a data store for application state; it is designed for asynchronous messaging, not for storing and retrieving session state.

228
MCQeasy

A SysOps administrator is configuring a VPC peering connection between two VPCs in the same AWS account and Region. The VPCs have non-overlapping CIDR blocks. The administrator needs to ensure that instances in both VPCs can communicate with each other. Which additional configuration is required after accepting the peering connection?

A.Create a transit gateway and attach both VPCs to it, then route traffic through the transit gateway.
B.Modify the security groups in both VPCs to allow traffic from the peer VPC's CIDR block.
C.Update the route tables in both VPCs to include a route to the peer VPC's CIDR block through the VPC peering connection.
D.Configure a VPN connection between the two VPCs to enable communication.
AnswerC

VPC peering connections do not automatically add routes. You must manually add a route in each VPC's route table that points to the peering connection for the peer VPC's CIDR block. This enables traffic to be routed between the VPCs. Without these routes, instances cannot communicate even though the peering connection is active.

Why this answer

After establishing a VPC peering connection, you must update the route tables in both VPCs to direct traffic destined for the peer VPC's CIDR block to the peering connection. Security groups must also allow the traffic, but the question asks for the additional configuration specifically required after accepting the peering connection, which is route table updates. Without these routes, communication fails.

Exam trap

The trap here is assuming that VPC peering automatically updates route tables or that security group changes alone are sufficient, when manual route table entries are mandatory.

229
MCQhard

A company has a VPC with public and private subnets. An Application Load Balancer (ALB) is deployed in the public subnets, and an Auto Scaling group of web servers is deployed in the private subnets. The web servers need to frequently make HTTPS requests to an external API. The API provider requires that all requests originate from a consistent set of static IP addresses for whitelisting. The SysOps administrator must ensure that outbound traffic from the web servers has static source IP addresses. Which solution should be implemented?

A.Place the web servers in public subnets and assign each instance an Elastic IP address.
B.Deploy a NAT gateway in a public subnet with an Elastic IP and route outbound traffic from the private subnets through the NAT gateway.
C.Create a VPC endpoint for the external API service.
D.Use AWS Global Accelerator to provide static IP addresses for outbound traffic.
AnswerB

Deploying a NAT gateway in a public subnet and adding a route (0.0.0.0/0) to the private subnets' route tables enables outbound internet access while preserving the private nature of the instances. The NAT gateway's Elastic IP provides a consistent, static public source IP for all outbound traffic, meeting the requirement to whitelist a single address for the external API. No inbound connections are permitted, as the NAT gateway is one-way, and this managed service is highly available within each Availability Zone. This is the standard AWS architecture for outbound-only internet access from private subnets.

Why this answer

A NAT gateway placed in a public subnet with an Elastic IP provides a consistent, static source IP for all outbound traffic from instances in private subnets. The web servers route their outbound HTTPS requests through the NAT gateway, which performs source NAT (SNAT) using the Elastic IP, satisfying the API provider's whitelisting requirement. This design keeps the web servers in private subnets for security while ensuring a fixed public IP for outbound traffic.

Exam trap

The trap here is that candidates confuse AWS Global Accelerator's static IPs for inbound traffic with the need for static outbound IPs, or mistakenly think VPC endpoints can be used for any external service, when they only work with supported AWS services.

How to eliminate wrong answers

Option A is wrong because placing web servers in public subnets with Elastic IPs would expose them directly to the internet, bypassing the ALB and compromising security; it also requires managing individual Elastic IPs per instance, which is not scalable for an Auto Scaling group. Option C is wrong because a VPC endpoint is used for private connectivity to AWS services (e.g., S3, DynamoDB) via the AWS network, not for reaching external HTTPS APIs over the internet; it does not provide static IP addresses for outbound traffic to third-party endpoints. Option D is wrong because AWS Global Accelerator provides two static Anycast IP addresses for inbound traffic to your application endpoints (e.g., ALB, NLB), not for outbound traffic from instances; it does not affect the source IP of outbound requests from web servers.

230
MCQeasy

A company has a VPC that requires DNS resolution for custom domain names within the VPC. They want to use a private hosted zone in Amazon Route 53. Which resource is required to associate the private hosted zone with the VPC?

A.A resolver rule
B.A public hosted zone
C.A VPC
D.A CNAME record
AnswerC

A private hosted zone must be associated with one or more Amazon VPCs before resources inside those VPCs can resolve the zone's records. Without this explicit association, the zone remains created but unusable, even if instances are in the same AWS account. Route 53 merges the private hosted zone's records with the default VPC DNS only after the association request succeeds, which makes the VPC the required target resource.

Why this answer

To associate a private hosted zone with a VPC in Amazon Route 53, you must specify the VPC ID and the AWS Region of the VPC. The VPC itself is the required resource because the private hosted zone is scoped to one or more VPCs, enabling DNS resolution for custom domain names only within those VPCs. Without a VPC association, the private hosted zone cannot serve DNS queries.

Exam trap

The trap here is that candidates often confuse the resource needed for association (the VPC) with DNS record types or resolver configurations, mistakenly thinking a CNAME record or resolver rule is required to link the hosted zone to the VPC.

How to eliminate wrong answers

Option A is wrong because a resolver rule is used with Route 53 Resolver to forward DNS queries to or from on-premises networks, not to associate a private hosted zone with a VPC. Option B is wrong because a public hosted zone is used for DNS resolution over the internet, not for private DNS within a VPC, and it cannot be associated with a VPC. Option D is wrong because a CNAME record is a DNS record type that maps an alias to a canonical name, not a resource that associates a hosted zone with a VPC.

231
MCQmedium

A company uses AWS CloudFormation to deploy infrastructure. The SysOps administrator has a template that creates an Amazon EC2 instance and an Amazon RDS DB instance. The administrator needs to reuse the same template for development, test, and production environments, where the only differences are the EC2 instance type and the RDS DB instance class. Which CloudFormation feature should be used to define these environment-specific values?

A.Nested stacks
B.Parameters
C.Mappings
D.Conditions
AnswerB

Parameters are the native CloudFormation feature designed to accept external input at stack creation or update time. By defining a parameter for the instance type and another for the DB class, the exact same template can be reused across dev, test, and production with different values supplied via the console, CLI, or API. This makes Params the most direct and maintainable way to achieve environment-specific resource configuration without editing the template.

Why this answer

Parameters are the correct CloudFormation feature because they allow you to pass environment-specific values (such as EC2 instance type and RDS DB instance class) into the template at stack creation or update time. This enables reuse of the same template across development, test, and production environments without modifying the template itself, simply by providing different parameter values for each environment.

Exam trap

The trap here is that candidates often confuse Mappings (which are static and cannot be changed per stack instance) with Parameters (which are dynamic and input at runtime), leading them to incorrectly choose Mappings for environment-specific values that must vary per deployment.

How to eliminate wrong answers

Option A is wrong because nested stacks are used to compose infrastructure from multiple templates or to isolate reusable components, not to inject environment-specific variable values into a single template. Option C is wrong because mappings provide static lookup tables (e.g., mapping environment names to instance types) but cannot be overridden at runtime; they are hardcoded in the template and not suitable for values that must change per deployment. Option D is wrong because conditions control whether a resource or property is created or omitted based on a condition (e.g., deploy a resource only in production), but they do not define or pass variable values like instance type or DB class.

232
MCQmedium

A SysOps administrator ran the above AWS CLI command to update an existing CloudFormation stack. The command failed with the error shown. What is the most likely cause?

A.The template file has a syntax error.
B.The stack is in a failed state from a previous operation and must be deleted or rollback continued.
C.The parameter values provided are invalid.
D.The IAM role specified lacks permissions.
AnswerB

This is the correct answer because the UpdateStack API explicitly rejects any stack whose current status is ROLLBACK_COMPLETE with a ValidationError stating the stack is in that state and cannot be updated. ROLLBACK_COMPLETE is a terminal failed state typically reached after a failed stack creation rolled back all resources, leaving the stack with no usable resources. To recover, you must delete the stack and recreate it, or if the rollback was incomplete, use ContinueUpdateRollback to reach an updatable state.

Why this answer

When a CloudFormation stack is in a failed state (e.g., UPDATE_ROLLBACK_FAILED or ROLLBACK_COMPLETE), any subsequent update operation is rejected with an error stating the stack is in a state that does not permit updates. The administrator must either continue the rollback (ContinueUpdateRollback) or delete and recreate the stack before another update can proceed. This matches the typical 'Stack is in UPDATE_ROLLBACK_FAILED state and can not be updated' error returned by the CLI.

Exam trap

SOA-C02 often tests whether candidates can distinguish between template/parameter validation errors and stack lifecycle state errors — the misleading options all describe plausible failure causes, but only the stack-state explanation matches a CLI error that explicitly references the stack's current status.

How to eliminate wrong answers

Option A is wrong because a template syntax error would produce a validation error during the change set or template parsing phase, not a stack-state rejection. Option C is wrong because invalid parameter values would fail parameter validation with a specific message about the parameter, not a stack-state error. Option D is wrong because insufficient IAM permissions would return an AccessDenied or authorization error, not a stack-state failure message.

233
MCQhard

A SysOps administrator is responsible for a multi-tier web application running on AWS. The application consists of an Application Load Balancer (ALB), an Auto Scaling group of EC2 instances, and an Amazon RDS for MySQL database. Recently, the operations team has been receiving alerts from CloudWatch that the ALB's 'HTTPCode_Target_5XX_Count' metric is spiking periodically. The team has also noticed that the database CPU utilization is high during these spikes. The application logs show that some requests are timing out. The administrator needs to identify the root cause and implement a remediation. After reviewing the architecture, the administrator rules out the database as the bottleneck because the database connections are pooled and the query response times are normal. The administrator suspects that the issue is related to the application server's health. Which course of action should the administrator take to diagnose and resolve the issue?

A.Increase the health check timeout and threshold to allow for transient high CPU usage.
B.Add an Amazon ElastiCache cluster to cache database queries.
C.Decrease the health check interval to detect unhealthy instances faster.
D.Increase the idle timeout on the ALB to keep connections open longer.
AnswerA

The ALB's health check timeout determines how long it waits for a response from the target, and the unhealthy threshold is the number of consecutive failed checks that mark an instance as unhealthy. By increasing both, you give a CPU-spiking instance more time to respond and require more failures before deregistering it, directly preventing false-positive health check failures that would otherwise trigger 5xx errors.

Why this answer

The periodic spikes in ALB 5xx errors, high database CPU, and application timeouts, combined with normal query response times and pooled connections, strongly suggest that the application servers are becoming overwhelmed and failing health checks. By increasing the health check timeout and threshold, the ALB will allow the EC2 instances more time to recover from transient CPU or memory pressure before being marked unhealthy and removed from service, which prevents unnecessary instance replacement and reduces the cascading load on remaining instances and the database.

Exam trap

The trap here is that candidates often assume high database CPU means the database is the bottleneck, but the question explicitly states query response times are normal and connections are pooled, so the real issue is application server health causing retries and cascading load, which is remediated by tuning health check sensitivity rather than adding caching or changing timeouts.

How to eliminate wrong answers

Option B is wrong because adding an ElastiCache cluster addresses database read performance, but the database is not the bottleneck (query response times are normal and connections are pooled), so caching would not resolve the application server health issue causing the 5xx errors. Option C is wrong because decreasing the health check interval would cause the ALB to check instances more frequently, potentially marking them unhealthy even faster during transient spikes, worsening the problem by cycling instances out of service more aggressively. Option D is wrong because increasing the idle timeout on the ALB keeps connections open longer, which does not address the root cause of application server health failures; it would only delay connection closure, potentially masking the issue and increasing resource consumption on already stressed instances.

234
Drag & Dropmedium

Drag and drop the steps to create an Amazon CloudWatch alarm that sends an email notification when CPU utilization exceeds 90% into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First set up the SNS topic, then create the alarm selecting the metric, define the condition, and finally add the notification action.

235
MCQeasy

A company wants to ensure that its EC2 instances automatically recover from an instance failure. Which feature should be used?

A.Create a CloudWatch alarm that sends an email when the instance status check fails.
B.Configure an Auto Scaling group with a launch configuration.
C.Attach the instance to an Elastic Load Balancer.
D.Enable EC2 Auto Recovery on the instance.
AnswerD

EC2 Auto Recovery, when enabled and attached to a CloudWatch alarm on the StatusCheckFailed_System metric, automatically restores the instance on new underlying hardware if the host is degraded. It preserves the instance ID, private IP address, Elastic IP address, and instance metadata, allowing applications to continue with minimal downtime. This is the only option that actually performs the instance recovery automation described in the scenario.

Why this answer

EC2 Auto Recovery is a feature that automatically recovers an EC2 instance when it becomes impaired due to an underlying hardware or system issue. When enabled, CloudWatch monitors the instance's status checks and, upon detecting a failure, automatically stops and starts the instance on a new healthy host, preserving its private IP, Elastic IP, and instance metadata.

Exam trap

The trap here is that candidates often confuse Auto Scaling groups (which replace instances) with EC2 Auto Recovery (which recovers the same instance), leading them to choose option B instead of D.

How to eliminate wrong answers

Option A is wrong because creating a CloudWatch alarm that sends an email only notifies an administrator of the failure; it does not automatically recover the instance. Option B is wrong because an Auto Scaling group with a launch configuration can replace a failed instance by launching a new one, but it does not recover the original instance's state, such as its private IP or Elastic IP, and is not designed for automatic recovery of a single instance. Option C is wrong because attaching the instance to an Elastic Load Balancer only distributes traffic and can route around a failed instance, but it does not recover the instance itself.

236
MCQhard

A company uses Amazon CloudFront to serve static content from an S3 bucket. The S3 bucket is configured as an origin with RestrictBucketAccess set to Yes, and the origin access identity (OAI) is configured. Users can access the content via CloudFront, but direct S3 URLs return Access Denied. However, some users report that they can still access the content directly via S3 URLs. What is the most likely reason?

A.The OAI is not properly associated with the CloudFront distribution.
B.The S3 bucket policy allows public read access in addition to the OAI.
C.The CloudFront distribution is using a custom origin instead of S3.
D.CloudFront is using pre-signed URLs that are being shared.
AnswerB

The OAI only authenticates CloudFront to S3; it does not automatically override a bucket policy that grants `s3:GetObject` to the public. If the bucket policy includes an `Allow` for `*` (or `AllPrincipals`), any user can access objects directly via the S3 bucket URL or website endpoint, entirely bypassing CloudFront. This explains the reported behavior: CloudFront works via the OAI, but the bucket remains publicly readable, so the security requirement is violated.

Why this answer

The most likely reason users can still access content directly via S3 URLs is that the S3 bucket policy allows public read access in addition to the OAI. Even though CloudFront is configured with OAI and RestrictBucketAccess, if the bucket policy grants public read permissions (e.g., via a statement with Principal: "*"), then direct S3 access remains possible. The OAI only restricts access when the bucket policy explicitly denies public access and allows only the OAI.

Exam trap

SOA-C02 often tests the misconception that configuring OAI and RestrictBucketAccess automatically blocks all direct S3 access, ignoring the possibility of a permissive bucket policy that overrides these settings.

How to eliminate wrong answers

Option A is wrong because if the OAI were not properly associated, users would not be able to access content via CloudFront either, but the scenario states they can. Option C is wrong because if CloudFront were using a custom origin instead of S3, the RestrictBucketAccess and OAI settings would not apply, but the scenario indicates S3 is the origin. Option D is wrong because pre-signed URLs are a feature of CloudFront or S3 that grant temporary access, but the scenario describes direct S3 URL access, not pre-signed URLs; also, pre-signed URLs would not be the default behavior.

237
Drag & Dropmedium

Drag and drop the steps to configure a VPC peering connection between two VPCs into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First create the peering request, then accept it, then update route tables in both VPCs, and finally adjust security groups.

238
MCQhard

A company uses AWS Backup to back up its Amazon EFS file system daily. The backup retention policy is set to 30 days. Recently, a user accidentally deleted a critical directory. The company wants to restore the directory as it existed 2 days ago. What is the MOST cost-effective and quickest way to achieve this?

A.Use the EFS console to recover the directory from the .Trash folder.
B.Enable EFS replication to another region and then fail back.
C.Use AWS Backup to restore the entire file system to an on-premises server, then copy the directory back.
D.Restore the backup from 2 days ago to a new EFS file system, then copy the directory to the original file system.
AnswerD

AWS Backup for EFS captures point-in-time snapshots accessible as recovery points; you can restore the recovery point from two days ago to a brand-new EFS file system, which is a fast, fully managed operation. Once the restored file system is mounted (e.g., on a temporary EC2 instance), you can selectively copy the missing directory from it to the original file system using cp or rsync or AWS DataSync. This provides a clean, isolated recovery path that does not alter the current file system until you explicitly copy the target directory, so it is the correct way to achieve selective point-in-time recovery.

Why this answer

AWS Backup creates point-in-time snapshots of EFS file systems. Restoring a backup from 2 days ago to a new EFS file system allows you to mount that new file system, copy the specific directory back to the original file system, and then delete the temporary file system. This is the most cost-effective and quickest approach since it avoids moving data to on-premises servers and uses native AWS services without additional replication costs.

Exam trap

The trap here is that candidates may assume AWS Backup can restore directly into the original EFS file system, but AWS Backup for EFS always creates a new file system during restore, requiring a manual copy step to recover specific data.

How to eliminate wrong answers

Option A is wrong because EFS does not have a '.Trash' folder; that concept is specific to certain desktop operating systems, not Amazon EFS. Option B is wrong because EFS replication is a continuous, region-level feature designed for disaster recovery, not for restoring a specific point-in-time backup; enabling replication and failing back would be slow, expensive, and does not target a specific backup from 2 days ago. Option C is wrong because restoring an entire EFS file system to an on-premises server requires significant network bandwidth, time, and infrastructure, and is not the quickest or most cost-effective method for recovering a single directory.

239
MCQhard

A SysOps administrator discovers that an EC2 instance was compromised because the SSH key pair was leaked. The administrator wants to ensure that future access to EC2 instances is secured using a method that does not rely on static keys. Which solution should the administrator implement?

A.Use a bastion host with a security group that allows SSH from a limited IP range.
B.Create a new key pair and distribute it securely to authorized users.
C.Use AWS Systems Manager Session Manager to connect to instances.
D.Use EC2 Instance Connect to connect to instances.
AnswerD

EC2 Instance Connect uses IAM policies to authorize individual users and temporarily publishes a one-time SSH public key to the instance's metadata service. The user then SSHes with a private key that is valid for only 60 seconds, eliminating long-lived key pairs and enabling per-user audit trails. This integrates with AWS CloudTrail to record access requests and empowers administrators to revoke access instantly by changing IAM permissions. It supports both console and CLI access, making it a secure, keyless-compatible solution while preserving native SSH functionality.

Why this answer

EC2 Instance Connect allows you to connect to EC2 instances using IAM policies and does not require managing or distributing static SSH key pairs. This eliminates the risk of key leakage. Option A (bastion host with limited IP range) still relies on SSH key pairs for authentication.

Option B (create new key pair) continues to use static keys and does not address the root cause. Option C (Systems Manager Session Manager) provides secure access without keys, but it requires the SSM Agent and an IAM instance role, and is not as directly focused on SSH key replacement as EC2 Instance Connect. Therefore, Option D is the best solution.

240
Multi-Selectmedium

A company is using Amazon RDS for MySQL with Multi-AZ deployment. They want to optimize costs while maintaining high availability. Which TWO actions should the SysOps administrator take?

Select 2 answers
A.Purchase Reserved Instances for the database instance.
B.Remove Multi-AZ to reduce costs.
C.Enable auto scaling for the RDS instance to handle variable load.
D.Review the instance size and downsize if it is over-provisioned.
E.Move to a single-AZ deployment and take snapshots for recovery.
AnswersA, D

Purchasing Reserved Instances for the RDS instance is a cost-optimization practice that does not affect the deployment architecture. Reserved Instances provide a significant hourly discount in exchange for a one- or three-year commitment, applied to the compute portion of the DB instance, while Multi-AZ and its automatic failover capability remain fully intact. This directly reduces operational costs without compromising high availability, making it a correct choice.

Why this answer

Option A is correct because purchasing Reserved Instances for the RDS DB instance provides a significant discount (up to ~69% for 3-year All Upfront terms) compared to On-Demand pricing, directly reducing cost while leaving the Multi-AZ high-availability configuration fully intact. Option D is correct because rightsizing the DB instance class (for example, moving from db.m5.xlarge to db.m5.large) eliminates spend on over-provisioned CPU/memory, and it can be done with a modification that preserves the Multi-AZ standby, so high availability is maintained. Option B is wrong because removing Multi-AZ sacrifices the synchronous standby replica and automatic failover, violating the requirement to maintain high availability.

Option C is wrong because RDS does not support auto scaling of the DB instance itself; only storage can be auto scaled, and read scaling requires Read Replicas, not instance auto scaling. Option E is wrong because a Single-AZ deployment plus snapshots is not highly available—snapshot restore creates a new instance and involves substantial RPO/RTO, so it fails the availability requirement.

Exam trap

SOA-C02 often tests the misconception that RDS supports compute auto scaling like EC2 Auto Scaling — candidates must remember RDS only auto-scales storage, not instance class.

241
MCQmedium

A SysOps administrator is troubleshooting a failed AWS CloudFormation stack creation. The error message indicates that an IAM role creation failed because the role already exists. The administrator wants to ensure the stack creation can proceed without manual intervention. What should the administrator do?

A.Modify the template to use a unique name for the IAM role.
B.Use the 'Retain' deletion policy on the IAM role resource.
C.Manually delete the existing IAM role and retry the stack creation.
D.Use a stack policy to prevent the creation of the IAM role.
AnswerA

CloudFormation IAM roles with an explicit RoleName property must be unique within the account and Region. If a role with that name already exists, stack creation fails with a resource conflict error. By appending the stack name or a random suffix to the RoleName, you ensure uniqueness without manual cleanup; this is the standard automated fix and aligns with AWS best practices for avoiding namespace collisions.

Why this answer

The error indicates a naming conflict: the IAM role name in the template already exists in the account. By modifying the template to use a unique name (e.g., appending a random string or using `AWS::NoValue` with `Fn::Sub`), CloudFormation can create the role without conflicting with the existing resource. This approach avoids manual intervention and allows the stack creation to proceed automatically.

Exam trap

The trap here is that candidates may confuse deletion policies (which affect resource lifecycle after deletion) with creation-time conflicts, or mistakenly think stack policies can block resource creation when they only govern updates and deletions.

How to eliminate wrong answers

Option B is wrong because the 'Retain' deletion policy only controls what happens to the resource when the stack is deleted; it does not prevent a creation failure caused by a duplicate name. Option C is wrong because it requires manual intervention, which the administrator wants to avoid, and it does not address the root cause of the naming conflict for future stack creations. Option D is wrong because a stack policy controls update or deletion actions on stack resources, not the creation of new resources; it cannot prevent the IAM role creation failure.

242
MCQeasy

A SysOps administrator needs to monitor the memory utilization of an EC2 instance running Windows Server. Which steps are required to collect memory metrics?

A.Install and configure the Amazon CloudWatch agent on the instance.
B.Install the AWS Systems Manager Agent (SSM Agent) and use Run Command.
C.Enable detailed monitoring on the EC2 instance.
D.Use the AWS Management Console to enable memory monitoring.
AnswerA

Memory utilisation is not a default EC2 hypervisor metric; it must be collected from inside the guest OS. Installing and configuring the Amazon CloudWatch agent on the Windows Server instance publishes memory metrics to CloudWatch.

Why this answer

Amazon CloudWatch does not collect memory metrics from EC2 instances by default; it only captures hypervisor-level metrics such as CPU, network, and disk I/O. To monitor in-guest memory utilization on a Windows Server instance, you must install and configure the Amazon CloudWatch agent, which sends custom metrics (e.g., Memory % Committed Bytes In Use) to CloudWatch. The agent uses the Windows Performance Monitor (PerfMon) counters to gather this data.

Exam trap

The trap here is that candidates assume memory metrics are automatically available or can be enabled via a simple console toggle, when in fact they require the CloudWatch agent to be installed and configured on the instance.

How to eliminate wrong answers

Option B is wrong because the AWS Systems Manager Agent (SSM Agent) and Run Command are used for management tasks like patching or executing scripts, not for collecting and publishing memory metrics to CloudWatch. Option C is wrong because enabling detailed monitoring only increases the frequency of existing hypervisor-level metrics (e.g., CPU, network) from 5 minutes to 1 minute; it does not add in-guest memory metrics. Option D is wrong because the AWS Management Console does not have a built-in toggle to enable memory monitoring; memory metrics require the CloudWatch agent to be installed and configured on the instance.

243
Multi-Selectmedium

A company is using Amazon CloudFront to distribute content globally. They want to restrict access to their content so that only users from specific countries can access it. Which TWO actions can be taken to achieve this?

Select 2 answers
A.Configure an S3 bucket policy with a condition for aws:SourceIp.
B.Configure CloudFront geo restriction (whitelist or blacklist) at the distribution level.
C.Use IAM policies to restrict access based on the user's location.
D.Use AWS WAF associated with CloudFront to create a rule that blocks requests based on geographic origin.
E.Set up an Application Load Balancer rule to deny traffic from certain IP ranges.
AnswersB, D

CloudFront geo restriction (whitelist or blacklist) is a native feature that uses a country-level database derived from the request's source IP to allow or block requests at the edge. It is configured directly on the distribution through the 'Restrictions' tab and applies to all content types before the request reaches the origin, requiring no changes to your application or backend. This is the simplest and most cost-effective way to enforce geographic access controls, as it requires no additional AWS services and works automatically with the CloudFront's global edge network.

Why this answer

CloudFront geo restriction allows you to whitelist or blacklist countries at the distribution level, directly controlling access based on the geographic location of the viewer's IP address. This is a native CloudFront feature that does not require additional services, making it a straightforward solution for country-based access control.

Exam trap

The trap here is that candidates often confuse the ability to use S3 bucket policies with aws:SourceIp for CloudFront-distributed content, not realizing that CloudFront acts as a proxy and the source IP seen by S3 is the CloudFront edge IP, not the end user's IP.

244
MCQeasy

A company runs a web application on Amazon EC2 instances that have variable traffic patterns. The application experiences steady baseline traffic with occasional spikes. The SysOps administrator wants to optimize costs while ensuring performance during spikes. Which pricing model should be used for the baseline capacity and for the burst capacity?

A.Reserved Instances for baseline, Spot Instances for burst capacity
B.On-Demand Instances for baseline, Reserved Instances for burst capacity
C.Spot Instances for baseline, On-Demand Instances for burst capacity
D.Dedicated Hosts for baseline, Spot Instances for burst capacity
AnswerA

Reserved Instances (RIs) lock in a lower hourly rate (up to 72% off On-Demand) for a 1- or 3-year term, making them ideal for the steady, predictable baseline portion of the workload. Spot Instances, priced at up to 90% off On-Demand, provide cheap burst capacity that can be interrupted and replaced, which is acceptable for transient spikes. This combination minimizes cost while ensuring the always-on core stays reliable.

Why this answer

Reserved Instances provide a significant discount (up to 72%) over On-Demand for steady-state workloads, making them ideal for baseline capacity. Spot Instances offer the lowest cost (up to 90% discount) but can be interrupted with a 2-minute warning, which is acceptable for burst capacity that can tolerate interruptions or be designed to failover gracefully. This combination minimizes cost while ensuring the baseline always runs and burst capacity can be added during spikes.

Exam trap

The trap here is that candidates often assume On-Demand is the only safe choice for baseline or that Spot Instances are too risky for any production use, but the question specifically allows for burst capacity that can tolerate interruptions, making Spot the optimal cost-saving choice.

How to eliminate wrong answers

Option B is wrong because Reserved Instances are designed for predictable, long-term workloads, not for burst capacity that is temporary and variable; using them for bursts would lock in capacity that may go unused, wasting money. Option C is wrong because Spot Instances can be terminated at any time, making them unreliable for baseline capacity that must always be available; using On-Demand for bursts is more expensive than using Spot for bursts. Option D is wrong because Dedicated Hosts are a physical server dedicated to a single customer, which is overkill and costly for baseline capacity that does not require dedicated hardware or licensing restrictions; they do not provide cost optimization for variable traffic.

245
MCQeasy

A company wants to create a disaster recovery (DR) strategy for its RDS for PostgreSQL database. The primary database is in us-east-1. The company needs a recovery point objective (RPO) of less than 5 minutes and a recovery time objective (RTO) of less than 1 hour. Which solution meets these requirements?

A.Enable Multi-AZ in us-east-1 and create a standby in a different Availability Zone.
B.Create a cross-region Read Replica in us-west-2 and promote it during a disaster.
C.Use AWS Database Migration Service (DMS) to continuously replicate to an EC2 instance.
D.Take daily automated snapshots and copy them to us-west-2.
AnswerB

A cross-region Read Replica in us-west-2 receives asynchronous replication from the primary in us-east-1, keeping a warm standby in a separate geographic region. During a disaster, you can promote the replica to a standalone primary in minutes, providing a low RPO (typically seconds or minutes of data loss) and a low RTO (often under 15 minutes). This option directly addresses region failure while also offloading read traffic before promotion.

Why this answer

A cross-region Read Replica for Amazon RDS PostgreSQL maintains an asynchronous replication lag typically under 5 seconds, easily meeting the RPO of less than 5 minutes. During a disaster, promoting the Read Replica to a standalone instance can be completed in minutes, satisfying the RTO of less than 1 hour. This approach provides both low RPO and fast recovery without the complexity of additional services.

Exam trap

The trap here is that candidates often confuse Multi-AZ (high availability within a region) with cross-region disaster recovery, assuming Multi-AZ provides regional fault tolerance, but it does not protect against a region-wide outage.

How to eliminate wrong answers

Option A is wrong because Multi-AZ provides high availability within a single region, not disaster recovery across regions; it cannot protect against a regional failure, and failover to a standby in a different Availability Zone does not meet the cross-region DR requirement. Option C is wrong because AWS DMS continuous replication to an EC2 instance introduces additional management overhead, potential licensing costs, and does not guarantee the sub-5-minute RPO or sub-1-hour RTO as reliably as a managed Read Replica; DMS is better suited for heterogeneous migrations or ongoing replication, not as a primary DR mechanism for RDS. Option D is wrong because daily automated snapshots have an RPO of up to 24 hours, far exceeding the required 5-minute RPO, and restoring from a snapshot in another region can take longer than 1 hour, failing the RTO requirement.

246
MCQeasy

A company wants to enforce that all IAM users in an AWS account must use multi-factor authentication (MFA) to access the AWS Management Console. Which IAM policy effect should be used to deny access if MFA is not present?

A.Allow with a condition that aws:MultiFactorAuthPresent is false
B.Allow with a condition that aws:MultiFactorAuthPresent is true
C.Deny with a condition that aws:MultiFactorAuthPresent is false
D.Deny with a condition that aws:MultiFactorAuthPresent is true
AnswerC

A Deny policy with the condition aws:MultiFactorAuthPresent is false explicitly blocks any request where the MFA condition does not evaluate to true, meaning the user did not authenticate with a valid MFA token. Because explicit Deny statements take precedence over any Allow, this effectively enforces MFA for all IAM users, as any attempt without MFA is rejected even if a broad Allow policy would otherwise grant access. This is the correct pattern for mandatory MFA enforcement, typically combined with an Allow that grants the needed permissions when MFA is present.

Why this answer

The IAM policy must explicitly deny access when MFA is not present. By using a Deny effect with the condition aws:MultiFactorAuthPresent set to false, any request that does not include MFA authentication is blocked. This is the standard approach to enforce MFA usage, as IAM policies default to an implicit deny, but an explicit Deny overrides any Allow that might otherwise grant access.

Exam trap

The trap here is that candidates often choose an Allow with a condition (option B) thinking it will restrict access, but they forget that an Allow statement only grants access when the condition is met and does not prevent access from other Allow policies; only an explicit Deny can reliably block access when the condition is false.

How to eliminate wrong answers

Option A is wrong because using Allow with a condition that aws:MultiFactorAuthPresent is false would grant access when MFA is not present, which is the opposite of the desired enforcement. Option B is wrong because Allow with a condition that aws:MultiFactorAuthPresent is true would only permit access when MFA is present, but it does not explicitly deny access when MFA is absent; an Allow statement alone cannot block access because other policies might still grant access, and the implicit deny only applies if no Allow matches. Option D is wrong because Deny with a condition that aws:MultiFactorAuthPresent is true would deny access when MFA is present, which contradicts the requirement to enforce MFA usage.

247
MCQmedium

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). The application experiences variable traffic with occasional spikes. The SysOps administrator wants to optimize costs while ensuring that the application can handle spikes without performance degradation. The current setup uses a fixed number of instances. Which action should the administrator take?

A.Purchase Reserved Instances for the current number of instances to reduce hourly cost.
B.Implement an Auto Scaling group with a target tracking scaling policy based on ALB request count per target.
C.Replace on-demand instances with Spot Instances for all traffic.
D.Increase the instance size to a compute-optimized type to handle spikes.
AnswerB

An Auto Scaling group with a target tracking scaling policy based on ALB request count per target continuously monitors the average number of requests each healthy instance receives. When the metric exceeds the target, the policy automatically launches additional EC2 instances, and when it falls below, it terminates instances, ensuring the fleet size tracks actual demand. This dynamic, horizontal scaling optimizes both cost and performance without manual intervention, making it the correct solution for a variable web workload.

Why this answer

An Auto Scaling group with a target tracking policy based on ALB request count per target automatically scales instances in and out to match traffic, handling spikes while minimizing cost during low-traffic periods. This directly addresses variable traffic with occasional spikes.

Exam trap

SOA-C02 often tests the misconception that Reserved Instances or larger instance types solve variable traffic — the exam expects recognition that elasticity (Auto Scaling) is required for spikes, while RIs only address steady-state cost.

How to eliminate wrong answers

Option A is wrong because Reserved Instances reduce hourly cost but lock in a fixed capacity — they do not help handle spikes and can increase cost if instances are underutilized. Option C is wrong because Spot Instances can be reclaimed with two minutes' notice and are unsuitable for all traffic in a production web application without a diversified, fault-tolerant architecture. Option D is wrong because increasing instance size to compute-optimized provides more capacity per instance but does not scale elastically with traffic, so it over-provisions during low traffic and may still be insufficient during spikes.

248
MCQmedium

A company has a web application running on EC2 instances behind an Application Load Balancer (ALB). The application uses sticky sessions (session affinity) based on cookies. Recently, the SysOps team noticed that user sessions are being lost intermittently, causing users to be logged out. The team checks the ALB configuration and finds that the stickiness is enabled with a cookie name 'AWSALB' and duration of 1 hour. The application also sets its own cookie. What is the most likely cause of session loss?

A.The ALB's health check interval is too short, causing instances to be marked unhealthy
B.The application cookie is overwriting the ALB's stickiness cookie
C.Cross-zone load balancing is disabled on the ALB
D.The application's session cookie has a shorter expiration than the ALB's stickiness duration
AnswerD

In this scenario, the ALB's stickiness cookie (AWSALB) remains valid and continues to route the client to the same EC2 instance for the configured duration, but the application's own session cookie (e.g., JSESSIONID) expires earlier. Once the application session expires, the server-side session data is discarded or considered invalid, causing the user to be logged out even though the ALB still sends them to the exact same server. The user then perceives a lost session, but the underlying issue is the mismatch between the application session timeout and the ALB stickiness duration, not the load balancer's routing behavior.

Why this answer

The most likely cause is that the application's session cookie expires before the ALB's stickiness cookie, causing the user to be logged out even though the ALB still routes to the same instance. The ALB stickiness duration is 1 hour, but if the application cookie has a shorter lifespan, the session ends prematurely. This is a common misconfiguration when application and load balancer session timeouts are not aligned.

Exam trap

SOA-C02 often tests the confusion between ALB stickiness and application session management, leading candidates to blame the ALB cookie or health checks instead of misaligned timeouts.

How to eliminate wrong answers

Option A is wrong because a short health check interval would cause instances to be marked unhealthy only if they fail checks, leading to removal from rotation, but the symptom is intermittent session loss, not complete unavailability. Option B is wrong because the ALB's stickiness cookie (AWSALB) and the application cookie have different names; they do not overwrite each other. Option C is wrong because cross-zone load balancing affects distribution across AZs, not session stickiness; disabling it does not cause session loss.

249
MCQhard

An organization is using AWS OpsWorks for Chef Automate to manage configuration of EC2 instances. The administrator notices that a new cookbook version is not being applied to existing instances in a layer. The cookbook is stored in a private Amazon S3 bucket and the instances have an instance profile that allows read access. What is the MOST likely reason for this issue?

A.The cookbook version is not being automatically downloaded because the instances are not rebooted.
B.The S3 bucket policy does not grant the necessary permissions to the instance profile.
C.The 'Update Cookbooks' stack command needs to be run manually to apply the new cookbook version to existing instances.
D.The Chef client on the instances is not configured to run automatically.
AnswerC

Correct. In AWS OpsWorks, cookbooks are only automatically applied during initial setup or when a Configure lifecycle event occurs. To apply a new cookbook version to existing instances, the administrator must manually run the 'Update Cookbooks' stack command.

Why this answer

In OpsWorks, cookbooks are not automatically applied to existing instances when a new version is published. To force an update on existing instances, the administrator must run the 'Update Cookbooks' stack command. Option A is incorrect because rebooting instances does not automatically download or apply new cookbook versions.

Option B is incorrect because the instance profile already has read access to the S3 bucket as stated, so the bucket policy is not the issue. Option D is incorrect because the Chef client runs automatically, but it does not fetch new cookbooks unless told to do so via the Update Cookbooks command.

250
MCQmedium

A SysOps administrator needs to monitor memory utilization of an Amazon EC2 instance. The default Amazon CloudWatch metrics for EC2 do not include memory utilization. Which solution should the administrator implement to collect memory metrics and set alarms?

A.Install the CloudWatch agent on the instance and configure it to collect memory metrics
B.Enable detailed monitoring on the EC2 instance
C.Use AWS Systems Manager Patch Manager to report memory usage
D.Use AWS CloudTrail to log memory events
AnswerA

The CloudWatch agent runs inside the instance and collects operating system-level metrics, including memory utilization, and sends them to CloudWatch as custom metrics. After installing and configuring the agent, you can create CloudWatch alarms on metrics like mem_used_percent. This is required because EC2 hypervisor-level monitoring cannot see guest OS memory usage.

Why this answer

The CloudWatch agent is specifically designed to collect custom metrics, such as memory utilization, from EC2 instances and on-premises servers. Unlike the default EC2 metrics, which only capture hypervisor-level metrics (e.g., CPU, disk I/O, network), memory utilization requires OS-level access. The CloudWatch agent uses the `mem` plugin to gather memory data and can publish it to CloudWatch as custom metrics, enabling alarm configuration.

Exam trap

The trap here is that candidates often confuse 'detailed monitoring' with the ability to collect additional metrics, but detailed monitoring only increases the resolution of existing metrics, not the scope of what is collected.

How to eliminate wrong answers

Option B is wrong because enabling detailed monitoring increases the frequency of existing EC2 metrics (e.g., CPU, disk I/O) from 5 minutes to 1 minute, but it does not add new metrics like memory utilization. Option C is wrong because AWS Systems Manager Patch Manager is used for patching and compliance, not for collecting or reporting memory usage metrics. Option D is wrong because AWS CloudTrail logs API calls and management events, not OS-level performance data like memory utilization.

251
Multi-Selecthard

Which TWO actions should a SysOps administrator take to secure an S3 bucket that stores sensitive data? (Choose two.)

Select 2 answers
A.Enable S3 Block Public Access settings on the bucket.
B.Enable cross-origin resource sharing (CORS) on the bucket.
C.Enable S3 Versioning.
D.Enable S3 server access logging.
E.Enable S3 Transfer Acceleration.
AnswersA, D

This is a bucket-level and account-level security control that, when applied, overrides any bucket policies or object ACLs that would grant public read/write access, effectively preventing the bucket and its objects from being accessible to the anonymous internet. For a scenario requiring data to be kept private, blocking public access is the direct and definitive remedy, and it also prevents future accidental public exposure through misconfigured policies or ACLs.

Why this answer

Option A is correct because enabling S3 Block Public Access on the bucket applies the four block-public-access settings (BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, RestrictPublicBuckets) that prevent sensitive objects from ever being exposed through public ACLs or bucket policies. Option D is correct because S3 server access logging records detailed, request-level records (requester, bucket, key, operation, response status, source IP) to a target bucket, giving the audit trail needed to detect and investigate unauthorized access to sensitive data. Option B is not appropriate because CORS only controls which web origins may make cross-origin browser requests to the bucket; it is a browser-enforcement mechanism, not an access-control or data-protection control.

Option C is not appropriate because S3 Versioning only preserves multiple object versions to aid recovery from overwrites or deletes; it does not restrict who can read the data. Option E is not appropriate because S3 Transfer Acceleration merely speeds up uploads/downloads via AWS edge locations and provides no security benefit.

Exam trap

SOA-C02 often tests the misconception that features like Versioning or Transfer Acceleration improve security, when in fact Block Public Access and access logging are the correct security-focused controls.

252
MCQhard

A SysOps administrator is deploying a CloudFormation stack that includes an AWS::ECS::Service resource. The service uses a task definition that references a container image stored in Amazon ECR. The stack creation fails with the error: 'Unable to assume the service-linked role.' What is the MOST likely cause?

A.The task execution role does not have permissions to pull the container image from ECR.
B.The CloudFormation service role does not have permission to create ECS resources.
C.The ECR repository policy does not grant access to the ECS service.
D.The ECS service-linked role does not exist in the account.
AnswerD

ECS requires the `AWSServiceRoleForECS` service-linked role so that the ECS service can manage resources such as ENIs, load balancer targets, and Auto Scaling groups on your behalf. If this role has never been created in the account, CloudFormation's calls to create the cluster or service return an error indicating that the service-linked role is not found, causing the stack to roll back. The role can be created with `iam:CreateServiceLinkedRole` or by a prior ECS console/API call; CloudFormation will not create it automatically for you.

Why this answer

The error 'Unable to assume the service-linked role' indicates that the ECS service-linked role (AWSServiceRoleForECS) does not exist in the account. CloudFormation attempts to create the ECS service, which requires this role to manage resources on your behalf. If the role is missing, the stack creation fails.

The most likely cause is that the role has not been created, perhaps because ECS was never used in this account before.

Exam trap

SOA-C02 often tests IAM roles and permissions, and candidates may confuse the task execution role with the service-linked role; the trap is assuming the error is due to missing ECR permissions when it's actually about the ECS service-linked role.

How to eliminate wrong answers

Option A is wrong because if the task execution role lacked ECR permissions, the error would be about pulling the image, not assuming a service-linked role. Option B is wrong because if the CloudFormation service role lacked permissions to create ECS resources, the error would be an authorization failure for CloudFormation, not a service-linked role assumption issue. Option C is wrong because the ECR repository policy controls access to the repository, but the error is specifically about assuming a service-linked role, which is unrelated to ECR permissions.

253
Multi-Selecthard

A company wants to implement a disaster recovery solution for its on-premises database using AWS. The solution must have an RPO of less than 1 hour and an RTO of less than 4 hours. Which THREE steps should the SysOps administrator take? (Choose THREE.)

Select 3 answers
A.Set up a cross-Region read replica for the RDS instance.
B.Launch an EC2 instance with the database software and configure replication.
C.Use AWS Database Migration Service (DMS) to replicate data to an RDS instance.
D.Use AWS DataSync to sync the database files to Amazon S3.
E.Configure the RDS instance with Multi-AZ.
AnswersA, B, C

A cross-Region read replica creates a continuously updated, asynchronous replicate of an RDS database in a different AWS Region, with typical replication lag well under the 1-hour RPO. Promoting the replica makes it a standalone writable instance, a process that generally completes within minutes and satisfies the RTO. This is a solid DR approach, but it presupposes that the database is already running on RDS; for an on-premises source, you would need an initial migration into RDS before this option becomes viable.

Why this answer

A cross-Region read replica for an RDS instance provides asynchronous replication to a secondary Region. After promoting the replica, the RTO can be under 4 hours, and the RPO is typically less than 1 hour. Option B is correct by launching an EC2 instance with the same database software and configuring continuous replication (e.g., log shipping or mirroring) from the on-premises database.

This allows failover to the EC2 instance within the RPO and RTO targets. Option C is correct as AWS DMS can perform ongoing replication from the on-premises database to an RDS instance, meeting the RPO requirement with minimal data loss. Together, these steps form a multi-layered DR strategy: DMS for continuous replication, EC2 as a standby, and a cross-Region replica for regional resilience.

Exam trap

Candidates often assume Multi-AZ (Option E) is a valid DR solution. However, Multi-AZ only provides high availability within a single Region, with synchronous replication and automatic failover. It does not protect against Region-wide outages or on-premises failures, and does not meet the cross-Region disaster recovery requirement implied by the need for an RPO < 1 hour and RTO < 4 hours for an on-premises database.

254
MCQhard

A company runs a critical database on an RDS for PostgreSQL instance in a single Availability Zone. The database experiences high write latency. The SysOps Administrator needs to improve the database's reliability and performance without downtime. Which solution meets these requirements?

A.Modify the RDS instance to be Multi-AZ with a standby in another Availability Zone.
B.Create a Multi-AZ deployment in the same Availability Zone.
C.Increase the allocated storage for the RDS instance.
D.Create a read replica in another Availability Zone and redirect read traffic.
AnswerA

Modifying the RDS instance to a Multi-AZ deployment provisions a synchronous standby replica in a different Availability Zone, and Amazon RDS automatically fails over to that standby if an AZ outage or primary instance failure occurs. This change can typically be applied without downtime, as it only requires a metadata modification and provisioning of the standby. This gives the database the high availability and automatic failover that the company needs.

Why this answer

Enabling Multi-AZ for an RDS for PostgreSQL instance provisions a standby replica in a different Availability Zone and synchronously replicates data to it. This eliminates the single point of failure, improving reliability. The modification is performed as a zero-downtime operation via a DNS update, meeting the requirement for no downtime.

Note that Multi-AZ improves availability but does not reduce write latency; performance improvement may come from offloading backups and other administrative tasks to the standby.

Exam trap

The trap here is that candidates confuse Multi-AZ (synchronous replication for high availability) with read replicas (asynchronous replication for read scaling), assuming a read replica can improve write performance or reliability when it only helps with read traffic.

How to eliminate wrong answers

Option B is wrong because Multi-AZ requires the standby to be in a different Availability Zone; deploying in the same AZ provides no fault isolation and does not improve reliability. Option C is wrong because increasing allocated storage addresses capacity or IOPS limits but does not improve reliability through redundancy or reduce write latency caused by synchronous replication overhead. Option D is wrong because a read replica is asynchronous and does not improve write latency or reliability for the primary database; it only offloads read traffic, leaving the primary as a single point of failure.

255
MCQeasy

A SysOps administrator has deployed an Application Load Balancer (ALB) that distributes traffic to a fleet of Amazon EC2 instances. The administrator notices that the ALB is sending all traffic to instances in a single Availability Zone (AZ), ignoring instances in other AZs. The ALB was created with default settings. Which action should the administrator take to ensure traffic is distributed evenly across all AZs?

A.Enable cross-zone load balancing on the ALB.
B.Enable connection draining on the target group.
C.Enable sticky sessions (session stickiness) on the target group.
D.Configure health checks on the target group to ensure unhealthy instances are not used.
AnswerD

Health checks ensure traffic is only sent to healthy instances, but they do not control the AZ-level distribution. If all instances are healthy, the ALB will still only send traffic to instances in the same AZ as the node that received the request if cross-zone is disabled.

Why this answer

By default, an Application Load Balancer has cross-zone load balancing always enabled, so traffic can be sent to healthy targets in any enabled Availability Zone. If traffic is not reaching instances in other AZs, the likely cause is that targets in those AZs are failing health checks or are not registered. Configuring accurate health checks on the target group will allow the ALB to mark those targets healthy and distribute traffic across all AZs.

Connection draining and sticky sessions do not affect AZ-level distribution.

Exam trap

Candidates often believe cross-zone load balancing must be enabled on an Application Load Balancer. However, ALB cross-zone load balancing is always enabled by default (unlike Network Load Balancers, where it is disabled by default). When an ALB appears to ignore instances in other AZs, check target health checks and registration instead of cross-zone settings.

How to eliminate wrong answers

Option B is wrong because connection draining (also known as deregistration delay) is used to complete in-flight requests before an instance is deregistered or becomes unhealthy, not to distribute traffic across AZs. Option C is wrong because sticky sessions (session stickiness) bind a client's requests to a specific target instance, which can actually prevent even distribution across AZs by concentrating traffic on a single instance. Option D is wrong because health checks only mark unhealthy instances as out of service; they do not influence how traffic is distributed across AZs—traffic would still be sent to healthy instances in the same AZ even if other AZs have healthy instances.

256
MCQeasy

Which AWS service can be used to create a private, dedicated connection between an on-premises data center and AWS?

A.AWS Site-to-Site VPN
B.AWS Transit Gateway
C.VPC Peering
D.AWS Direct Connect
AnswerD

AWS Direct Connect is the correct answer because it provides a dedicated, private, physical network connection from your on-premises data center directly to AWS, completely bypassing the public internet. This is achieved through a cross-connect at an AWS Direct Connect location, and you can create private virtual interfaces to access your VPC resources with consistent latency and higher bandwidth. It fulfills the requirement for a private dedicated connection, unlike VPN or other network constructs.

Why this answer

AWS Direct Connect provides a dedicated, private network connection from an on-premises data center to AWS, bypassing the public internet. It offers more consistent network performance, lower latency, and reduced bandwidth costs compared to internet-based connections. This makes it the correct choice for a private, dedicated connection.

Exam trap

SOA-C02 often tests the distinction between a dedicated private connection (Direct Connect) and an encrypted connection over the public internet (Site-to-Site VPN). Candidates may confuse Transit Gateway as a connectivity service, but it is a hub, not a direct connection.

How to eliminate wrong answers

Option A is wrong because AWS Site-to-Site VPN uses the public internet to create an encrypted tunnel, not a dedicated private connection. Option B is wrong because AWS Transit Gateway is a network transit hub for connecting VPCs and on-premises networks, but it does not itself provide the dedicated physical connection; it can be used with Direct Connect or VPN. Option C is wrong because VPC Peering connects two VPCs within AWS, not an on-premises data center to AWS.

257
MCQhard

A company is running a critical application on Amazon EC2 instances. The application performance has degraded over the past week. The SysOps administrator suspects a memory leak. The administrator needs to collect detailed memory usage metrics every minute and store them for 30 days. Which solution is the MOST cost-effective and operationally efficient?

A.Use AWS CloudTrail to log memory usage and store the logs in Amazon S3.
B.Enable default EC2 monitoring to collect memory metrics every 5 minutes.
C.Enable detailed monitoring on the EC2 instances to collect memory metrics every 1 minute.
D.Install the CloudWatch agent on the EC2 instances to collect memory metrics and publish them to CloudWatch.
AnswerD

The CloudWatch agent is a software component installed on the EC2 instance that reads memory usage from the operating system (/proc/meminfo on Linux or performance counters on Windows) and publishes those values to CloudWatch as custom metrics. Once configured, the agent can report memory utilization with a 1-minute resolution and even collect additional metrics like swap usage or disk space, all of which appear under the CWAgent namespace. Because the agent runs inside the instance, it can access OS-level data that hypervisor-based default and detailed monitoring cannot, making this the required solution.

Why this answer

The CloudWatch agent is specifically designed to collect custom metrics like memory utilization from EC2 instances, which are not available through default or detailed EC2 monitoring. By installing the agent and configuring it to publish memory metrics to CloudWatch every minute, the administrator can meet the requirement for 1-minute granularity and 30-day retention cost-effectively, as CloudWatch retains metric data at 1-minute resolution for 15 days by default, but can be extended to 30 days via a custom metric retention setting.

Exam trap

The trap here is that candidates often confuse detailed EC2 monitoring (which only covers hypervisor-level metrics) with in-guest monitoring, assuming that enabling detailed monitoring will capture memory usage, but memory is a guest OS metric that requires the CloudWatch agent.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail logs API activity, not system-level metrics like memory usage; it cannot capture memory utilization data from EC2 instances. Option B is wrong because default EC2 monitoring collects metrics (e.g., CPU, network) every 5 minutes, not memory metrics, and the 5-minute interval does not meet the 1-minute requirement. Option C is wrong because detailed EC2 monitoring collects metrics every 1 minute but only includes hypervisor-level metrics (e.g., CPU, disk I/O, network); memory metrics are not provided by EC2 monitoring and require an in-guest agent like the CloudWatch agent.

258
Multi-Selectmedium

A SysOps administrator is planning a VPC design with high availability for an application that must tolerate the failure of an entire Availability Zone. Which TWO configurations should be implemented? (Select TWO.)

Select 2 answers
A.Use a single NAT Gateway for all private subnets.
B.Deploy a NAT Gateway in each Availability Zone.
C.Launch EC2 instances in at least two Availability Zones.
D.Use a placement group to ensure instances are in different AZs.
E.Use only one public subnet and one private subnet.
AnswersB, C

A NAT Gateway is a zonal resource: each gateway runs from a specific Availability Zone and has its own elastic IP, and its availability is tied to that AZ. By deploying one NAT Gateway in each Availability Zone and routing each private subnet's 0.0.0.0/0 traffic to the gateway in its own AZ, outbound internet access from private instances continues to work even if an entire AZ fails. This design eliminates the cross-AZ dependency and avoids a single point of failure for private-subnet egress.

Why this answer

Option B is correct because a NAT Gateway is an AZ-scoped resource, so deploying one in each Availability Zone ensures that private subnet egress continues to function if a single AZ fails; a single NAT Gateway would become a single point of failure. Option C is correct because launching EC2 instances in at least two Availability Zones provides the actual compute redundancy needed to tolerate the loss of an entire AZ, allowing traffic to be served from the surviving AZ. Option A is incorrect because one NAT Gateway shared by all private subnets concentrates the egress path in a single AZ and fails during an AZ outage.

Option D is incorrect because placement groups (cluster, spread, or partition) do not by themselves guarantee multi-AZ resilience and are not the mechanism for AZ-level failover. Option E is incorrect because a single public and single private subnet confines resources to one AZ, directly contradicting the high-availability requirement.

Exam trap

The trap here is that candidates often think a single NAT Gateway is sufficient for high availability because it is a managed service, but they overlook that it is still tied to a single AZ and will fail if that AZ fails, making per-AZ deployment essential for AZ-level fault tolerance.

259
MCQhard

An organization has a VPC with public and private subnets. The private subnets need to access the internet for software updates. A NAT gateway is deployed in a public subnet and the private subnet route table has a route for 0.0.0.0/0 pointing to the NAT gateway. However, instances in the private subnet cannot reach the internet. What could be the issue?

A.The NAT gateway's subnet does not have a route to an internet gateway
B.The private subnet's network ACL blocks outbound HTTPS traffic
C.The security group attached to the NAT gateway does not allow outbound traffic
D.The private instances do not have a public IP address assigned
AnswerA

For the NAT gateway to successfully forward traffic from private subnets to the internet, the subnet where the NAT gateway resides must have a route to an internet gateway (IGW). Without a route to the IGW in that subnet's route table, the NAT gateway cannot send or receive traffic from the internet, even though it has a public Elastic IP. This is the most common reason for failed outbound internet access from private instances when a NAT gateway is present.

Why this answer

The NAT gateway must be in a public subnet with a route table that includes a default route (0.0.0.0/0) pointing to an internet gateway (IGW). Without this route, the NAT gateway cannot forward traffic from the private subnet to the internet, because the IGW is the only way to reach public IP addresses. The question states the NAT gateway is deployed in a public subnet, but if that subnet's route table lacks the IGW route, outbound traffic from the NAT gateway will fail.

Exam trap

The trap here is that candidates assume placing a NAT gateway in a 'public subnet' automatically gives it internet access, but the subnet must have a route table entry pointing 0.0.0.0/0 to an internet gateway for the NAT gateway to function.

How to eliminate wrong answers

Option B is wrong because a network ACL (NACL) is stateless and would need to block both outbound HTTPS (port 443) and the corresponding inbound ephemeral return traffic; however, the default NACL allows all traffic, and the question does not indicate any custom NACL changes, so this is unlikely the root cause. Option C is wrong because security groups are stateful and are attached to resources like EC2 instances, not to NAT gateways; NAT gateways do not have security groups, so this option is technically invalid. Option D is wrong because instances in a private subnet do not need public IP addresses; they rely on the NAT gateway's public IP for outbound internet access, so the absence of a public IP on the private instances is not the issue.

260
MCQeasy

A SysOps administrator needs to receive an email notification when an IAM user's console login fails. Which AWS service should be used to set up this notification?

A.Amazon CloudWatch
B.AWS CloudTrail
C.Amazon Simple Notification Service (SNS)
D.AWS Config
AnswerA

CloudWatch can create a metric filter on a CloudTrail log group to count failed login events, set an alarm on that metric, and publish to SNS for email notification. CloudWatch is the core monitoring and alerting service.

Why this answer

Amazon CloudWatch can monitor AWS CloudTrail log events for IAM console login failures by creating a metric filter on the CloudTrail log group for the `ConsoleLogin` event with a `failure` status. When the filter matches, CloudWatch can trigger an alarm that sends an email notification via Amazon SNS. This is the correct service because CloudWatch is designed for monitoring and alerting on operational metrics and log patterns.

Exam trap

The trap here is that candidates often pick Amazon SNS directly, forgetting that SNS is a notification channel, not a monitoring service, and requires CloudWatch to detect the failure event first.

How to eliminate wrong answers

Option B (AWS CloudTrail) is wrong because CloudTrail only records API activity and audit logs; it cannot directly send email notifications or trigger alerts without CloudWatch. Option C (Amazon SNS) is wrong because SNS is a pub/sub messaging service that delivers notifications, but it cannot monitor or detect login failures on its own; it requires a trigger from another service like CloudWatch. Option D (AWS Config) is wrong because Config evaluates resource configurations and compliance rules, not real-time login events or authentication failures.

261
MCQmedium

A company uses AWS CloudFormation to manage infrastructure. They have a stack that creates an Amazon RDS DB instance. The database is in a VPC with public and private subnets. The DB instance is in a private subnet. When the stack is created, the DB instance is not accessible from an EC2 instance in the same VPC. What is the most likely cause?

A.The DB subnet group does not include the correct subnets.
B.The security group for the DB instance does not allow inbound traffic from the EC2 instance.
C.The VPC does not have an internet gateway attached.
D.The DB instance does not have a public IP address.
AnswerB

RDS security groups are stateful firewalls that deny all inbound traffic by default. The DB instance's security group must have a custom inbound rule for the database port (e.g., TCP 3306 for MySQL) with a source referencing the EC2 instance's security group ID, not a CIDR from memory. Without this explicit allow, the EC2 instance cannot reach the DB even when both are in the same VPC and subnet, making this the classic cause of 'same VPC, still can't connect'.

Why this answer

The most likely cause is that the security group attached to the RDS DB instance does not permit inbound traffic from the EC2 instance's security group or IP address on the database port. In a VPC, security groups act as virtual firewalls, and even if the DB is in the same VPC, traffic is blocked unless explicitly allowed. CloudFormation stack creation would succeed, but connectivity would fail.

Exam trap

SOA-C02 often tests the misconception that an internet gateway or public IP is required for internal VPC communication, when in fact security group rules are the typical culprit for connectivity failures between EC2 and RDS.

How to eliminate wrong answers

Option A is wrong because if the DB subnet group did not include the correct subnets, the RDS instance would not be placed in the private subnet as intended, but the question states the DB is in a private subnet, implying the subnet group is correct. Option C is wrong because an internet gateway is not required for internal VPC communication between an EC2 instance and an RDS instance; they communicate using private IP addresses. Option D is wrong because a public IP address is not needed for internal VPC access; RDS instances in private subnets are accessed via their private IPs.

262
MCQmedium

A company runs a web application on Amazon EC2 instances in an Auto Scaling group. The application experiences steady traffic during business hours and very low traffic overnight. The SysOps administrator wants to optimize costs by using a mix of On-Demand and Spot Instances. The administrator also requires that the total capacity never falls below the baseline level needed during business hours, even if Spot Instances are reclaimed. Which combination of Auto Scaling features should be used?

A.Use a mixed instances policy and set the 'On-Demand Base' capacity to the minimum number of instances required during business hours, and 'On-Demand percentage above base' to 0% so that any additional capacity is Spot.
B.Use a launch template that specifies a Spot Instance type and set the total capacity to the desired level, relying on capacity rebalance to replace interrupted Spot Instances.
C.Purchase Compute Savings Plans to cover the entire Auto Scaling group, and use only Spot Instances for all capacity.
D.Configure the Auto Scaling group with a launch template that sets the instance market to 'spot' and use a scaling policy that always maintains the minimum capacity.
AnswerA

A mixed instances policy lets the Auto Scaling group combine On-Demand and Spot capacity while distributing across instance types. Setting On-Demand Base to the minimum needed during business hours creates a hardened floor that will always be fulfilled by On-Demand instances, and setting On-Demand percentage above base to 0% directs all growth beyond that floor to Spot Instances. This isolates the availability-critical baseline from Spot interruptions while saving money on the burst capacity, and it automatically balances between the two markets as the group scales in and out.

Why this answer

A mixed instances policy allows the Auto Scaling group to use both On-Demand and Spot Instances. By setting the 'On-Demand Base' capacity to the minimum number of instances required during business hours, you guarantee that baseline capacity is always fulfilled by On-Demand Instances, which are not subject to interruption. Setting 'On-Demand percentage above base' to 0% ensures that any additional capacity beyond the base is fulfilled by Spot Instances, optimizing cost while maintaining the required capacity floor.

Exam trap

The trap here is that candidates often assume that using Spot Instances with a scaling policy or capacity rebalance alone can guarantee capacity, but they fail to recognize that only On-Demand Instances provide a hard guarantee against interruption, which is why the mixed instances policy with an explicit On-Demand base is required.

How to eliminate wrong answers

Option B is wrong because using a launch template that specifies only a Spot Instance type and relying solely on capacity rebalance does not guarantee that the total capacity never falls below the baseline level during business hours; Spot Instances can be reclaimed at any time, and capacity rebalance only attempts to replace them but cannot guarantee uninterrupted capacity. Option C is wrong because Compute Savings Plans cover a commitment to spend a certain amount per hour but do not prevent Spot Instances from being reclaimed; if all capacity is Spot, the baseline could drop below the required level during interruptions. Option D is wrong because configuring the Auto Scaling group with a launch template that sets the instance market to 'spot' and using a scaling policy that always maintains the minimum capacity does not ensure that the minimum capacity is fulfilled by On-Demand Instances; Spot Instances can still be reclaimed, causing the actual capacity to fall below the minimum.

263
MCQhard

A company hosts a critical web application on EC2 instances behind an Application Load Balancer. The security team enabled AWS WAF on the ALB to block SQL injection and XSS attacks. They also use AWS Shield Advanced for DDoS protection. Recently, the application experienced intermittent performance degradation during normal traffic patterns. The security team reviewed the WAF logs and found that legitimate user requests with query strings containing the word "select" (e.g., ?category=select+option) were being blocked. The team wants to ensure that only actual SQL injection attempts are blocked, not legitimate requests with similar patterns. What course of action should the SysOps administrator take to resolve this issue while maintaining security?

A.Disable the SQL injection rule in AWS WAF and rely solely on AWS Shield Advanced for protection.
B.Enable AWS Shield Advanced's automatic mitigation feature to handle all layer 7 attacks.
C.Create a custom WAF rule that inspects specific query string parameters with a more precise regex pattern to reduce false positives.
D.Replace the WAF SQL injection rule with a rate-based rule to limit request rates from specific IPs.
AnswerC

Creating a custom AWS WAF rule that inspects only the specific query string parameters with a more precise regex pattern is the correct solution because it narrows the detection scope while maintaining SQL injection protections. For example, instead of using a managed rule that flags any occurrence of 'select' across the entire request, a custom rule can apply a SQL injection match condition to a parameter like 'id' and use a regex pattern that requires SQL keywords to appear in a syntactically suspicious sequence, such as after a quote or with UNION operators. This reduces false positives by ignoring benign uses of words like 'select' in other fields, while still detecting actual SQLi attempts that target the parameter the application expects to be numeric or constrained.

Why this answer

The issue is that the AWS WAF SQL injection rule is triggering false positives on legitimate query strings containing the word 'select' (e.g., '?category=select+option'). The best course of action is to create a custom WAF rule that inspects specific query string parameters with a more precise regex pattern, allowing legitimate patterns while still blocking actual SQL injection attempts. This maintains security by targeting the actual attack vectors rather than disabling protection entirely.

Exam trap

SOA-C02 often tests the balance between security and availability — candidates may choose to disable the rule to stop false positives, but the exam expects a solution that maintains security while reducing false positives, such as a custom rule with precise regex.

How to eliminate wrong answers

Option A is wrong because disabling the SQL injection rule entirely removes protection against SQL injection attacks, leaving the application vulnerable — this sacrifices security for availability. Option B is wrong because AWS Shield Advanced's automatic mitigation is designed for DDoS attacks (Layer 3/4 and some Layer 7 volumetric attacks), not for refining SQL injection detection or reducing false positives from WAF rules. Option D is wrong because replacing the SQL injection rule with a rate-based rule only limits request rates from IPs; it does not inspect query strings for SQL injection patterns, so actual SQL injection attacks would not be blocked.

264
MCQeasy

A SysOps administrator needs to allow traffic from a specific IP address range (203.0.113.0/24) to access an Amazon EC2 instance in a VPC. Which configuration step should be performed?

A.Create an IAM policy that allows inbound traffic from 203.0.113.0/24.
B.Add a rule to the network ACL associated with the subnet to allow inbound traffic from 203.0.113.0/24.
C.Modify the route table of the subnet to include a route for 203.0.113.0/24 to the internet gateway.
D.Add an inbound rule to the security group associated with the EC2 instance allowing traffic from 203.0.113.0/24.
AnswerD

A security group is a stateful, instance-level virtual firewall that filters traffic at the elastic network interface. Adding an inbound rule that permits 203.0.113.0/24 on the desired port allows that specific source to reach the EC2 instance, and because security groups are stateful, the return traffic is automatically allowed without any additional outbound rule. This provides the most precise and correct method for the stated requirement.

Why this answer

Security groups are the stateful, instance-level virtual firewalls in AWS that control inbound and outbound traffic to EC2 instances. To permit traffic from a specific CIDR block like 203.0.113.0/24 to reach an EC2 instance, you must add an inbound rule to the security group attached to that instance, specifying the source as the CIDR. This is the most direct and correct configuration step because security groups operate at the ENI level and are required for any inbound traffic to be allowed.

Exam trap

SOA-C02 often tests the confusion between security groups and network ACLs, leading candidates to select network ACLs when the question asks for allowing traffic to a specific EC2 instance.

How to eliminate wrong answers

Option A is wrong because IAM policies control AWS API permissions and identity-based access, not network traffic to EC2 instances. Option B is wrong because network ACLs are stateless subnet-level firewalls; while they can allow traffic, they are not the primary or sufficient step—security groups must also allow it, and the question asks for the step to allow traffic to the instance, which is best done via security group. Option C is wrong because route tables direct traffic between subnets and gateways; they do not filter or permit traffic based on source IP, and adding a route for 203.0.113.0/24 to an internet gateway would not allow inbound access to the instance.

265
MCQhard

A company runs a large number of EC2 instances across multiple accounts and regions. The finance team needs to track costs per project and department. Each EC2 instance must be tagged with a ProjectID and Department tag. A SysOps administrator needs to ensure that all newly launched EC2 instances are tagged automatically before they can be used, and that existing untagged instances are retroactively tagged. The tags must be propagated to cost reports in AWS Cost Explorer. Which combination of steps will achieve this with the least operational overhead?

A.Use AWS Config with auto-remediation to tag new instances, and activate the tags as cost allocation tags. For existing instances, run the Tag Editor with a CSV import.
B.Create an AWS Lambda function that tags instances at launch via CloudTrail events, and use AWS Budgets to enforce tagging.
C.Use AWS Cost Categories to automatically group costs based on resource tags.
D.Ensure all AMIs used have tags that propagate to instances, and enable cost allocation tags.
AnswerA

This correctly combines a compliance-driven enforcement mechanism with a retroactive bulk-editing tool. AWS Config can run a managed rule that checks instances for the required tags and, if non-compliant, trigger auto-remediation via an SSM Automation document to apply those tags, covering new and modified resources continuously. Activating those tags in the Billing and Cost Management console makes them appear in cost allocation reports, and the Tag Editor can perform bulk search-and-tag across regions using a CSV import for any existing instances that predate the rule. Together, these steps tag both new and existing resources and ensure cost reporting reflects the tags.

Why this answer

AWS Config with auto-remediation can automatically tag newly launched EC2 instances using a custom Lambda function or SSM document triggered by a Config rule (e.g., 'required-tags'), ensuring compliance before instances are used. Activating the tags as cost allocation tags in AWS Cost Explorer allows the tags to appear in cost reports. For existing untagged instances, the Tag Editor with a CSV import provides a bulk, low-overhead method to retroactively apply tags across accounts and regions.

Exam trap

The trap here is that candidates may assume AMI tags propagate to instances or that AWS Budgets can enforce tagging, but neither is true; the correct approach requires a combination of proactive enforcement (Config auto-remediation) and retroactive bulk tagging (Tag Editor).

How to eliminate wrong answers

Option B is wrong because AWS Budgets cannot enforce tagging; it only sends alerts based on cost or usage thresholds, and does not automatically tag instances or prevent untagged instances from being used. Option C is wrong because AWS Cost Categories group costs based on existing tags or accounts, but they do not automatically tag instances or ensure that newly launched instances are tagged before use. Option D is wrong because AMI tags do not propagate to instances launched from them; instance tags must be explicitly specified at launch or applied via automation, and enabling cost allocation tags alone does not retroactively tag existing untagged instances.

266
Multi-Selecteasy

A company has an Application Load Balancer (ALB) that distributes traffic to EC2 instances. The company wants to enable path-based routing to send requests to different target groups. Which TWO resources must be created to achieve this?

Select 2 answers
A.Subnet for the ALB
B.Target group for each backend service
C.Network Load Balancer (NLB)
D.Listener rule with a path pattern condition
E.Security group for the ALB
AnswersB, D

In an Application Load Balancer, traffic is not forwarded directly to backend instances; it is forwarded to target groups. A target group logically groups a set of backend instances or IP addresses for one specific service, and each target group has its own health checks, stickiness policy, and routing metadata. Because each backend service is a distinct application, you need a separate target group per service so that a listener rule can route a specific URL path to the correct group of instances.

Why this answer

(Target group for each backend service) and Option D (Listener rule with a path pattern condition) are correct. Path-based routing requires creating target groups for each backend service and a listener rule with a path pattern condition to direct requests to the appropriate target group. Option A is incorrect because subnets are needed for the ALB, but they are not specifically required for path-based routing.

Option C is incorrect because a Network Load Balancer is not used; the ALB itself handles path-based routing. Option E is incorrect because a security group controls traffic but does not enable path-based routing.

267
MCQeasy

A company wants to automatically start and stop an EC2 instance on a schedule to reduce costs. The instance runs a critical application that must be available from 8 AM to 6 PM weekdays. Which AWS service should be used to implement this scheduling?

A.AWS Instance Scheduler
B.AWS OpsWorks
C.AWS Systems Manager Automation
D.AWS CloudFormation
AnswerA

AWS Instance Scheduler is an AWS Solutions Library reference implementation that deploys a scheduled stop/start framework using CloudFormation, Amazon EventBridge, and AWS Lambda. It reads user-defined tags such as Schedule=Weekdays-7am-7pm from EC2 and RDS instances, evaluates the current time against the defined periods in a DynamoDB table, and automatically transitions instances between the stopped and started states. It also supports time zones, types such as EC2 and RDS, and cross-account/region execution, making it the purpose-built solution for this exact requirement.

Why this answer

AWS Instance Scheduler is a purpose-built solution (deployed via CloudFormation) that uses Lambda, DynamoDB, and EventBridge to start and stop EC2 instances and RDS databases on customizable schedules. It supports period-based and schedule-based tagging, making it the correct choice for automatically starting/stopping an instance on a weekday 8 AM–6 PM schedule. The other services can be cobbled together to achieve scheduling, but none is designed specifically for this cost-optimization use case.

Exam trap

SOA-C02 often tests whether candidates recognize that Instance Scheduler is a distinct AWS solution (not a core service) and confuse it with Systems Manager Automation or CloudFormation, which require more manual configuration.

How to eliminate wrong answers

Option B is wrong because AWS OpsWorks is a configuration management service (Chef/Puppet-based) for deploying and managing applications, not a scheduling service for starting/stopping instances. Option C is wrong because AWS Systems Manager Automation can run documents on a schedule via maintenance windows, but it requires custom automation documents and is not a turnkey instance-scheduling solution like Instance Scheduler. Option D is wrong because AWS CloudFormation is an infrastructure-as-code provisioning service; while Instance Scheduler itself is deployed via CloudFormation, CloudFormation alone does not provide scheduling logic.

268
MCQmedium

A company runs an application across multiple Availability Zones. The application servers are in private subnets and need outbound internet access to download software updates and patches. The SysOps administrator needs a highly available, fully managed solution to provide this outbound connectivity. Which solution should be used?

A.Deploy a NAT instance in each private subnet
B.Deploy a single NAT Gateway in one public subnet
C.Deploy a NAT Gateway in each public subnet
D.Attach an Internet Gateway directly to the private subnets
AnswerC

By deploying a NAT Gateway in each Availability Zone's public subnet and configuring private subnets to use the NAT Gateway in the same AZ, the solution is both fully managed and highly available. If one AZ fails, the other AZ's NAT Gateway continues to provide internet access.

Why this answer

Deploying a NAT Gateway in each public subnet provides a highly available, fully managed solution for outbound internet access from private subnets. NAT Gateways are managed by AWS, automatically scale, and are resilient within an Availability Zone; using one per AZ ensures that if one AZ fails, the others continue to provide outbound connectivity. This meets the requirement for high availability without the operational overhead of managing NAT instances.

Exam trap

The trap here is that candidates often confuse NAT Gateways with NAT instances or assume a single NAT Gateway is sufficient for high availability, overlooking the need for one per Availability Zone to achieve true fault tolerance.

How to eliminate wrong answers

Option A is wrong because NAT instances are self-managed EC2 instances that require manual patching, scaling, and failover configuration, which contradicts the 'fully managed' requirement and introduces a single point of failure if only one instance is used per subnet. Option B is wrong because a single NAT Gateway in one public subnet creates a single point of failure; if that Availability Zone becomes unavailable, all private subnets lose outbound internet access, violating the high availability requirement. Option D is wrong because attaching an Internet Gateway directly to private subnets would expose those subnets to inbound internet traffic, defeating the purpose of a private subnet and violating security best practices; Internet Gateways are designed for public subnets only.

269
MCQeasy

A SysOps administrator needs to audit all API calls made in an AWS account for compliance and security analysis. The logs must be stored securely for at least one year. Which AWS service should the administrator enable?

A.AWS CloudTrail
B.Amazon CloudWatch Logs
C.AWS Config
D.Amazon GuardDuty
AnswerA

AWS CloudTrail is the correct service because it is a governance, compliance, and audit service that records every AWS API call made in the account, including the identity of the caller, the time of the call, the source IP address, and the request parameters. It delivers event history to an S3 bucket and can also send events to CloudWatch Logs for further monitoring, making it the definitive source for an audit trail of API activity.

Why this answer

AWS CloudTrail is the correct service because it records all API calls made in an AWS account, including the identity of the caller, the time of the call, the source IP address, and the request parameters. This audit log is essential for compliance and security analysis, and CloudTrail can be configured to store logs in an S3 bucket with lifecycle policies to retain them for at least one year.

Exam trap

The trap here is that candidates often confuse CloudTrail with CloudWatch Logs, thinking CloudWatch Logs can capture API calls, but CloudWatch Logs only stores logs from services that explicitly send them, not the full audit trail of API activity.

How to eliminate wrong answers

Option B (Amazon CloudWatch Logs) is wrong because CloudWatch Logs is designed for monitoring, storing, and accessing log files from AWS resources (e.g., EC2, Lambda), not for auditing API calls; it does not capture AWS API activity by default. Option C (AWS Config) is wrong because AWS Config evaluates resource configurations against desired policies and records configuration changes, but it does not log API calls or provide a record of who made changes. Option D (Amazon GuardDuty) is wrong because GuardDuty is a threat detection service that analyzes CloudTrail logs, VPC flow logs, and DNS logs for malicious activity, but it does not itself generate or store API call logs for auditing.

270
MCQmedium

A SysOps administrator is reviewing the reliability of a production system that uses Amazon DynamoDB as its primary data store. The table has on-demand capacity and a single partition key. The application experiences occasional throttling errors during peak hours. Which action would most effectively improve reliability?

A.Switch to provisioned capacity and set high read/write units.
B.Enable auto-scaling and increase the maximum capacity.
C.Review and optimize the partition key design to avoid hot partitions.
D.Enable DynamoDB Accelerator (DAX) to reduce read latency.
AnswerC

Reviewing and optimizing the partition key design is the correct fix because DynamoDB distributes data across partitions based on the partition key's hash value, and on-demand or provisioned table capacity does not guarantee uniform load per partition. Each partition has its own throughput ceiling (3000 RCU / 1000 WCU), so a skewed access pattern—such as one overly popular item or a timestamp prefix—creates a hot partition that gets throttled even when the table's overall capacity is underutilized. Adding high-cardinality suffixes like random or calculated bits to the partition key spreads the writes and reads across many partitions, eliminating the bottleneck while preserving query access if the design accounts for it. This approach directly addresses the root cause rather than masking symptoms.

Why this answer

Throttling errors in DynamoDB with a single partition key are most often caused by uneven access patterns creating hot partitions. Optimizing the partition key design (e.g., using a composite key or adding a suffix to distribute writes) directly addresses the root cause by ensuring requests are spread evenly across partitions, which on-demand capacity alone cannot fix. This improves reliability by preventing throttling at the partition level, regardless of the table's total capacity.

Exam trap

The trap here is that candidates assume throttling is always a capacity issue (solved by increasing RCU/WCU or enabling auto-scaling), when in reality it is often a data modeling problem where a single partition key creates a hot spot that no amount of capacity scaling can fix.

How to eliminate wrong answers

Option A is wrong because switching to provisioned capacity with high read/write units does not solve hot partition issues; if a single partition exceeds its 3,000 RCU or 1,000 WCU limit, throttling still occurs even with high provisioned capacity. Option B is wrong because enabling auto-scaling and increasing maximum capacity only adjusts total table throughput, not per-partition limits; it cannot prevent throttling caused by a hot key hammering one partition. Option D is wrong because DynamoDB Accelerator (DAX) is an in-memory cache that reduces read latency for eventually consistent reads, but it does not eliminate throttling errors caused by write-heavy hot partitions or partition-level throughput limits.

271
Multi-Selecthard

Which THREE are valid methods to control access to an S3 bucket? (Choose three.)

Select 3 answers
A.VPC Flow Logs
B.Access control lists (ACLs)
C.Bucket policies
D.IAM user policies
E.CloudWatch Logs
AnswersB, C, D

Access control lists are legacy sub-resources that can be attached to an S3 bucket or individual object to grant basic read/write permissions to grantees, typically AWS accounts or predefined groups like Authenticated Users. ACLs do not support conditions, complex principals, or fine-grained actions, and AWS now recommends using bucket policies or IAM policies instead. When S3 Object Ownership is set to Bucket owner enforced, ACLs are automatically disabled for the bucket.

Why this answer

Option B (Access control lists, ACLs) is correct because S3 ACLs are a legacy but still supported access-control mechanism that grants read/write permissions on a bucket or object to AWS accounts or predefined groups such as AllUsers or AuthenticatedUsers. Option C (Bucket policies) is correct because an S3 bucket policy is a resource-based JSON policy attached directly to the bucket that can allow or deny principals (IAM users, roles, accounts, or anonymous users) access to the bucket and its objects. Option D (IAM user policies) is correct because identity-based IAM policies attached to users, groups, or roles define what S3 actions (for example s3:GetObject, s3:PutObject) those identities may perform on specified bucket ARNs.

Option A (VPC Flow Logs) is not an access-control method; it captures IP traffic metadata for network interfaces for monitoring and troubleshooting. Option E (CloudWatch Logs) is a logging and monitoring service, not an authorization mechanism, so it cannot grant or deny access to an S3 bucket.

Exam trap

SOA-C02 often tests whether candidates confuse monitoring/logging services (VPC Flow Logs, CloudWatch Logs) with access control mechanisms; the trap is picking a service that observes traffic rather than one that authorizes it.

272
MCQhard

A company has an S3 bucket that stores sensitive data. A SysOps administrator needs to detect when objects in the bucket are publicly accessible. Which AWS service should the administrator use to continuously monitor and report on public access?

A.AWS Config
B.S3 server access logs
C.Amazon GuardDuty
D.AWS Trusted Advisor
AnswerA

AWS Config is correct because it provides continuous, real-time compliance evaluation of S3 bucket policies using managed rules such as s3-bucket-public-read-prohibited and s3-bucket-public-write-prohibited. It captures configuration changes via AWS Config recording and triggers rule evaluation both periodically and on configuration changes, alerting via SNS or auto-remediating through Systems Manager. This directly meets the requirement to evaluate bucket policies against public-access rules continuously.

Why this answer

AWS Config provides a managed rule called 's3-bucket-public-read-prohibited' and 's3-bucket-public-write-prohibited' that continuously evaluates S3 bucket policies and ACLs against the desired configuration. When a bucket becomes publicly accessible, AWS Config flags it as noncompliant and can trigger automated remediation or notifications. This makes it the correct service for ongoing monitoring and reporting of public access to sensitive data.

Exam trap

The trap here is that candidates often confuse 'detecting public access' with 'auditing access logs' (S3 server access logs) or 'threat detection' (GuardDuty), but the question specifically asks for continuous monitoring and reporting of the bucket's configuration state, which is exactly what AWS Config's managed rules provide.

How to eliminate wrong answers

Option B is wrong because S3 server access logs record detailed requests made to the bucket (e.g., requester, action, response status), but they do not evaluate or report on the bucket's public access configuration; they are used for auditing who accessed objects, not for detecting whether the bucket itself is publicly accessible. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes VPC Flow Logs, DNS logs, and CloudTrail events for malicious activity, not S3 bucket policies or ACLs; it does not monitor public access settings on S3 buckets. Option D is wrong because AWS Trusted Advisor provides one-time or periodic checks (e.g., S3 Bucket Permissions check) but does not offer continuous, real-time monitoring or compliance reporting; it is a best-practice advisory tool, not a configuration monitoring service.

273
MCQeasy

A DevOps engineer needs to automate the creation of an Amazon RDS for MySQL DB instance in a VPC. The solution must use infrastructure as code. Which AWS service should be used to provision the database?

A.AWS OpsWorks
B.AWS Elastic Beanstalk
C.AWS CloudFormation
D.EC2 Auto Scaling
AnswerC

AWS CloudFormation is an Infrastructure as Code service that lets you define resources declaratively in a JSON or YAML template. You can specify an AWS::RDS::DBInstance resource, along with all its properties such as engine, instance class, storage, and security groups, and CloudFormation will create the database reproducibly and manage its lifecycle. It supports change sets, rollback on failure, and drift detection, making it the ideal service for automating RDS provisioning.

Why this answer

AWS CloudFormation is the infrastructure-as-code service that allows you to define and provision AWS resources, including RDS DB instances, using declarative templates. It supports the full lifecycle management of RDS instances, including creation, updates, and deletion, and integrates with other AWS services for automation. The other options are not designed for general-purpose infrastructure as code provisioning of databases.

Exam trap

SOA-C02 often tests the distinction between infrastructure-as-code services and application deployment or configuration management services, causing candidates to confuse Elastic Beanstalk or OpsWorks with CloudFormation for provisioning databases.

How to eliminate wrong answers

Option A is wrong because AWS OpsWorks is a configuration management service that uses Chef and Puppet to automate server configuration, but it is not primarily an infrastructure-as-code service for provisioning AWS resources like RDS; it focuses on EC2 instances and applications. Option B is wrong because AWS Elastic Beanstalk is a PaaS service for deploying and scaling web applications, and while it can provision an RDS instance as part of an environment, it is not an infrastructure-as-code tool and does not provide the declarative, version-controlled template approach required. Option D is wrong because EC2 Auto Scaling is a service for automatically adjusting the number of EC2 instances in a fleet, and it has no capability to provision RDS databases.

274
MCQmedium

A company has a production AWS account with multiple IAM users. The security team wants to implement a policy that prevents users from launching EC2 instances without an IAM role that grants access to an S3 bucket containing sensitive data. The policy should also allow users to launch instances with other roles. A SysOps administrator creates an IAM policy that denies ec2:RunInstances if the instance does not have a specific IAM instance profile. However, users are still able to launch instances without any role. What is the most likely reason, and what should be done to fix it?

A.The condition key 'ec2:InstanceProfileArn' is misspelled; it should be 'ec2:IamInstanceProfile'.
B.The policy should be attached to the user's group instead of the user.
C.The policy needs to be applied as a service control policy (SCP) to be effective.
D.The condition key is incorrect; the policy should use 'ec2:InstanceProfile' condition key with a specific ARN.
AnswerD

The condition key should be 'ec2:InstanceProfile', not 'ec2:InstanceProfileArn'. The 'ec2:InstanceProfileArn' condition key does not exist for EC2, so the policy never matches, and the deny effect does not apply, allowing users to launch instances without any role.

Why this answer

The correct condition key for checking an instance's IAM role at launch is 'ec2:InstanceProfile', not 'ec2:InstanceProfileArn'. The 'ec2:InstanceProfile' condition key evaluates the ARN of the instance profile associated with the instance. Using 'ec2:InstanceProfileArn' is not a valid condition key for EC2, so the policy never matches, and the deny effect never applies, allowing users to launch instances without any role.

Exam trap

The trap here is that candidates assume all AWS condition keys follow a consistent 'ResourceArn' naming pattern, but EC2 uses 'ec2:InstanceProfile' without the 'Arn' suffix, leading to a policy that silently fails to deny the action.

How to eliminate wrong answers

Option A is wrong because 'ec2:IamInstanceProfile' is not a valid condition key; the correct key is 'ec2:InstanceProfile'. Option B is wrong because attaching the policy to a user group versus a user does not change the policy's logic or effectiveness; the issue is the condition key itself, not the attachment point. Option C is wrong because service control policies (SCPs) are used to set permission boundaries across accounts in an AWS Organization, not to fix a malformed condition key in an IAM policy; the policy would still fail to deny the action even as an SCP.

275
MCQeasy

A company needs to deploy a set of microservices using Docker containers on AWS. The deployment should be automated and support scaling based on demand. Which AWS service should be used to orchestrate the containers?

A.AWS Lambda
B.AWS Elastic Beanstalk
C.Amazon ECS
D.AWS CodeDeploy
AnswerC

Amazon ECS is a fully managed container orchestration service purpose-built for running Docker containers at scale. It lets you define task definitions, control scheduling and placement, and integrates natively with Application Load Balancer, IAM, CloudWatch, and VPC networking, making it the right choice for deploying and operating a set of microservices as containers on AWS.

Why this answer

Amazon ECS is a fully managed container orchestration service that integrates with Auto Scaling and CloudWatch to automate deployment and scaling of Docker containers. Option A (Lambda) is for serverless functions, not containers. Option B (Elastic Beanstalk) can deploy containers but is less flexible for microservices orchestration.

Option D (CodeDeploy) is for application deployments, not container orchestration.

276
MCQeasy

A SysOps administrator is creating an AWS CloudFormation template to deploy a web server. The template must define an Amazon EC2 instance, a security group, and an Elastic IP. In which section of the template should these resources be declared?

A.Parameters
B.Resources
C.Outputs
D.Mappings
AnswerB

The Resources section is the mandatory core of any AWS CloudFormation template and the only place where you define actual AWS infrastructure objects, such as EC2 instances, S3 buckets, or IAM roles. Each resource declaration includes a logical ID, an AWS::Service::Type string, and a Properties block that specifies configuration and dependencies. CloudFormation reads this section to orchestrate the creation, updating, and deletion of the stack's resources, so all real-world infrastructure must be declared here.

Why this answer

In an AWS CloudFormation template, the Resources section is the mandatory block where all AWS resources (such as EC2 instances, security groups, and Elastic IPs) are declared and configured. The template's logic for creating, updating, and deleting these infrastructure components is defined exclusively within this section, making B the correct choice.

Exam trap

The trap here is that candidates confuse the purpose of the Parameters section (input values) with the Resources section (resource definitions), often thinking that resources like EC2 instances are 'parameters' because they require configuration values like instance type or AMI ID.

How to eliminate wrong answers

Option A is wrong because the Parameters section is used to accept runtime input values (e.g., instance type, AMI ID) from the user, not to define the resources themselves. Option C is wrong because the Outputs section is used to export information about created resources (e.g., instance public IP) for use by other stacks or users, not to declare the resources. Option D is wrong because the Mappings section is used to create static lookup tables (e.g., mapping AWS regions to AMI IDs) for conditional values, not to define resources.

277
MCQhard

A SysOps administrator is setting up a Network Load Balancer (NLB) to handle millions of requests per second. The target group consists of EC2 instances that are in a single Availability Zone. Which of the following is a potential issue?

A.If the single AZ becomes unavailable, the NLB will not automatically fail over to other AZs.
B.The NLB cannot be associated with only one Availability Zone.
C.The NLB cannot preserve the source IP address of the client.
D.The NLB will not be able to handle the traffic volume due to the single AZ limitation.
AnswerA

If only one Availability Zone is configured, the NLB has a single load balancer node with an Elastic Network Interface in that AZ. When that AZ becomes unavailable, the NLB node itself and every registered target are unreachable simultaneously, so the NLB cannot re-route traffic elsewhere because no other AZ has an ENI or target group membership. Automatic failover to another AZ is only possible if at least one additional AZ is enabled and has healthy targets.

Why this answer

Option A is the correct answer because if the NLB is provisioned in a single Availability Zone (AZ) and that AZ fails, the NLB will not automatically fail over to other AZs, which is a potential issue for high availability. Option B is incorrect because an NLB can be associated with only one AZ. Option C is incorrect because the NLB can preserve the source IP address when using instance targets.

Option D is incorrect because the NLB can handle high throughput even in a single AZ.

278
MCQmedium

A company uses AWS CloudTrail to log API calls across all regions. The SysOps administrator notices that logs for a specific region are missing from the centralized S3 bucket. What is the most likely cause?

A.The CloudTrail trail is not enabled for that region.
B.The S3 bucket policy denies write access from CloudTrail for that region.
C.CloudTrail log file validation is disabled.
D.The IAM role for CloudTrail does not have permissions to write logs from that region.
AnswerA

CloudTrail trails are regional resources by default. If the trail was created for a single region, it captures API calls only in that region, and you must explicitly configure a multi-region trail or create separate trails for other regions. The absence of logs for a specific region strongly indicates that no trail is enabled in that region.

Why this answer

CloudTrail trails can be configured to log API calls from specific regions or all regions. If logs for a particular region are missing from the centralized S3 bucket, the most likely cause is that the trail was not enabled for that region during trail creation or update. By default, a trail applied to all regions will automatically log activity from every region, but if the trail is configured for a single region or a subset, other regions will not have their logs delivered.

Exam trap

The trap here is that candidates often assume missing logs are due to a permissions or policy issue (options B or D), when in fact the most common root cause is a simple configuration oversight where the trail is not set to log from all regions or the specific region was not included.

How to eliminate wrong answers

Option B is wrong because if the S3 bucket policy denied write access from CloudTrail for that specific region, logs from all regions would likely be affected or the error would appear in CloudTrail’s delivery status, not just missing logs for one region. Option C is wrong because log file validation is a security feature that adds a digest file for integrity checks; disabling it does not prevent logs from being delivered to the S3 bucket. Option D is wrong because CloudTrail uses a service-linked role or a customer-managed IAM role that is not region-specific; if the role lacked permissions, logs from all regions would fail to be delivered, not just one region.

279
MCQhard

A company uses AWS CloudFormation to deploy a stack that includes an Amazon RDS DB instance with Multi-AZ enabled. During a stack update, the database engine version is changed. The update fails with a rollback. What is the most likely cause?

A.The engine version upgrade is not supported for Multi-AZ deployments.
B.The DB instance class is not available for the new engine version.
C.The storage type is not compatible with the new engine version.
D.The DB subnet group does not have enough IP addresses.
AnswerA

Amazon RDS rejects certain major engine version upgrades on Multi-AZ deployments because the in-place upgrade path is not available for all database engine versions when a standby replica is present. CloudFormation surfaces this as a generic engine version upgrade failure, but the root cause is a service-side limitation, not a misconfigured resource property. To complete the upgrade, you must typically create a snapshot, restore from it, promote the restored instance, or use a blue/green deployment, after which you can update the CloudFormation stack to reference the new instance.

Why this answer

Changing the database engine version on a Multi-AZ RDS instance is not supported directly through a CloudFormation stack update without additional steps. Multi-AZ deployments require both primary and standby instances to be upgraded, and if the new engine version is not compatible or the upgrade path is not supported, the update fails and triggers a rollback. Option B is incorrect because instance class availability is not the primary issue; the error relates to the engine version change, not the instance class.

Option C is incorrect because storage type compatibility is not the relevant factor; the storage type remains unchanged. Option D is incorrect because the DB subnet group is not involved in engine version upgrades, and IP address availability is not a typical cause for this failure.

280
MCQmedium

A SysOps administrator notices that an EC2 instance running a web server is receiving unexpected traffic from an IP address that is known to be malicious. The administrator wants to block this IP address at the instance level. Which solution should be used?

A.Modify the network ACL to deny traffic from that IP.
B.Use AWS WAF to block the IP address.
C.Install a third-party firewall on the instance.
D.Update the security group to deny traffic from that IP.
AnswerC

A third-party firewall installed on the instance, such as iptables or a host-based security agent, can filter inbound traffic based on source IP at the operating system level before the application processes it. This is the only option that fulfills the 'instance level' requirement, as it controls traffic directly on that specific EC2 instance regardless of the surrounding subnet or VPC configuration. Security groups cannot explicitly deny, making a host-based firewall the correct solution.

Why this answer

A host-based firewall (such as a third-party firewall installed on the instance) can block traffic from a specific IP address at the instance level. Option A is incorrect because network ACLs operate at the subnet level, not the instance level. Option B is incorrect because AWS WAF is designed to filter web requests at the application layer and is typically associated with load balancers or CloudFront, not directly with an individual EC2 instance.

Option D is incorrect because security groups do not support deny rules; they only allow traffic, so they cannot be used to block specific IPs.

Exam trap

The question specifies 'at the instance level,' which disqualifies subnet-level solutions like network ACLs. Candidates often overlook this detail and choose NACLs because they support explicit deny.

281
Multi-Selectmedium

A company needs to audit all changes to AWS resources. Which THREE AWS services should be used together to achieve this? (Choose three.)

Select 3 answers
A.Amazon Inspector
B.AWS CloudTrail
C.Amazon CloudWatch Events
D.AWS Trusted Advisor
E.AWS Config
AnswersB, C, E

AWS CloudTrail is the primary service for auditing by recording all API activity across AWS accounts. It captures every management event, including the identity making the call, the source IP, the time, and the request parameters, delivering a complete and verifiable history of who changed what. This immutable log provides the evidence required to audit changes and maintain compliance.

Why this answer

AWS CloudTrail (B) is correct because it records API activity and management events across the account, providing the audit trail of who made which changes to AWS resources. AWS Config (E) is correct because it continuously records resource configuration changes and evaluates them against desired rules, giving configuration history and compliance auditing. Amazon CloudWatch Events (C) is correct because it can detect and route CloudTrail/Config-related events in near real time to targets such as Lambda, SNS, or SQS for alerting and automated response.

Amazon Inspector (A) is not correct because it is a vulnerability management service that scans EC2 instances and container images, not a change-auditing service. AWS Trusted Advisor (D) is not correct because it provides best-practice checks and recommendations, not a record of resource changes.

Exam trap

SOA-C02 often tests the confusion between auditing (CloudTrail/Config) and security assessment (Inspector) or advisory (Trusted Advisor) services — candidates must map each service to its actual function.

282
Multi-Selecthard

A company is using Amazon CloudWatch Logs to collect logs from multiple AWS services. The SysOps administrator needs to query logs across multiple log groups in real-time. Which THREE of the following are capabilities of CloudWatch Logs Insights?

Select 3 answers
A.Export query results directly to an S3 bucket.
B.Schedule queries to run at a specific time.
C.Run queries in real-time against incoming log data.
D.Visualize query results with bar charts and line graphs.
E.Query multiple log groups in a single query.
AnswersC, D, E

CloudWatch Logs Insights operates on log data that has been ingested into CloudWatch Logs, and because ingestion is a near real-time process—typically within seconds—queries reflect the most recent events. The console even offers a 'Live' button that continuously polls and re-runs the query against incoming data, giving a real-time tail-like experience. However, this is not streaming analytics; the query engine still scans the stored log data rather than processing events as a continuous stream.

Why this answer

CloudWatch Logs Insights supports real-time queries against incoming log data, allowing you to analyze logs as they are ingested. This is enabled by its ability to query live streams without requiring data to be indexed first, making it suitable for real-time troubleshooting and monitoring.

Exam trap

The trap here is that candidates may confuse CloudWatch Logs Insights' real-time querying with scheduled or export capabilities, which are actually handled by separate AWS services like EventBridge or S3 Export tasks, not by Insights itself.

283
MCQeasy

A company uses AWS CloudFormation to deploy a web application. The template currently hard-codes the EC2 instance type (e.g., t3.medium). The SysOps administrator wants to make the instance type configurable so that different environments (dev, test, prod) can use different instance types without modifying the template each time. Which CloudFormation feature enables this?

A.Parameters
B.Mappings
C.Conditions
D.Outputs
AnswerA

Parameters are the only CloudFormation construct here that accept runtime input. When you create or update a stack, you supply values, either interactively, via CLI, or via a stack template, and those values are referenced with Ref to set resource properties. Because the same template can be reused with different parameter values, parameters are the correct way to make a stack deployable to multiple environments with different configuration.

Why this answer

CloudFormation Parameters allow you to pass custom values into a template at stack creation or update time. By defining a parameter for the instance type (e.g., with allowed values like t3.micro, t3.medium, t3.large), you can reuse the same template across dev, test, and prod environments without editing the template file itself.

Exam trap

The trap here is that candidates often confuse Mappings (which are static and environment-agnostic) with Parameters (which are dynamic and user-supplied), leading them to incorrectly choose Mappings as the way to make values configurable.

How to eliminate wrong answers

Option B is wrong because Mappings are static lookup tables (e.g., mapping environment names to instance types) that are hard-coded in the template and cannot be overridden at deployment time; they do not accept runtime input. Option C is wrong because Conditions control whether certain resources are created based on logical expressions (e.g., create a larger instance only in prod), but they do not make the instance type configurable as a deploy-time variable. Option D is wrong because Outputs are used to return information about deployed resources (e.g., instance ID or public IP) after stack creation; they do not accept input values.

284
MCQmedium

A SysOps administrator is using AWS CloudFormation to deploy a stack that includes an Amazon EC2 instance and an Amazon RDS DB instance. The administrator needs to ensure that updates to the stack do not accidentally replace the RDS instance if the RDS configuration is changed in a way that would require replacement. Which CloudFormation attribute should be added to the RDS resource?

A.UpdateReplacePolicy with Retain
B.DeletionPolicy with Retain
C.StackPolicy
D.CreationPolicy
AnswerA

During a stack update, if a property change requires CloudFormation to replace a resource, the default behavior is to create a new resource and then delete the old one. UpdateReplacePolicy with Retain overrides this by preserving the existing RDS instance and its data, even after the replacement occurs. This is essential for stateful resources like databases, where the old instance contains critical data that would otherwise be lost.

Why this answer

The `UpdateReplacePolicy` attribute with `Retain` tells CloudFormation to preserve the existing RDS DB instance if a stack update would otherwise require its replacement. This prevents accidental deletion and recreation of the RDS instance when its configuration changes in a way that forces a new physical resource, such as modifying the DB engine version or storage type. The `UpdateReplacePolicy` is specifically designed for update scenarios, unlike `DeletionPolicy` which only applies during stack deletion.

Exam trap

The trap here is that candidates confuse `DeletionPolicy` (which only applies to stack deletion) with `UpdateReplacePolicy` (which applies during stack updates), leading them to choose Option B instead of A.

How to eliminate wrong answers

Option B is wrong because `DeletionPolicy` with `Retain` only protects the RDS instance from being deleted when the entire stack is deleted, not during an update that would replace the resource. Option C is wrong because `StackPolicy` controls permissions for stack-level updates (e.g., who can modify resources), not the lifecycle behavior of individual resources during replacement. Option D is wrong because `CreationPolicy` is used to wait for signals or resource creation completion (e.g., with `cfn-signal`), and has no effect on update or replacement behavior.

285
Multi-Selecteasy

A SysOps administrator wants to be alerted when the root user of the AWS account signs in. Which TWO services can be used together to achieve this?

Select 2 answers
A.AWS Lambda
B.AWS CloudTrail
C.AWS Config
D.Amazon CloudWatch Events (Amazon EventBridge)
E.AWS Trusted Advisor
AnswersB, D

AWS CloudTrail records the ConsoleLogin event as a management event, including the userIdentity type of Root, the source IP, and the login result. A trail configured across all regions delivers these log files to Amazon S3, and the event can also be processed in near real-time by EventBridge, making CloudTrail the authoritative data source for detecting root use. This is why monitoring root login activity fundamentally requires CloudTrail.

Why this answer

AWS CloudTrail logs all API calls, including root user sign-ins, as `RootLogin` events in the management events trail. Option D is correct because Amazon CloudWatch Events (now part of Amazon EventBridge) can be configured with a rule that matches these CloudTrail log events and triggers a notification action, such as sending an SNS alert, when the root user signs in.

Exam trap

The trap here is that candidates often pick AWS Config or Trusted Advisor because they associate them with security monitoring, but neither service captures API call events like root sign-ins, which require CloudTrail and EventBridge for event-driven alerting.

286
Multi-Selectmedium

A SysOps administrator needs to set up monitoring for an application that runs on an EC2 instance. The application generates custom metrics that should be available for analysis in CloudWatch. Which steps are required to achieve this? (Select TWO.)

Select 2 answers
A.Attach an IAM role to the EC2 instance with permissions to call PutMetricData.
B.Create an SNS topic and subscribe the application to send metrics.
C.Install the CloudWatch Logs agent to send custom metrics.
D.Use the CloudWatch agent or AWS CLI to publish custom metrics using the put-metric-data command.
E.Enable detailed monitoring on the EC2 instance to collect custom metrics.
AnswersA, D

Attaching an IAM instance profile role to the EC2 instance is the recommended and secure way to grant the application the necessary cloudwatch:PutMetricData permission. Without these credentials, any call to the PutMetricData API will fail with an authorization error, and embedding long-term access keys in the instance is a security anti-pattern. The IAM role, assumed via the instance metadata service, provides temporary credentials that are automatically rotated and scoped to the exact actions and resources allowed by the attached policy.

Why this answer

The EC2 instance must have an IAM role attached with permissions to call PutMetricData, which authorizes the instance to publish custom metrics to CloudWatch. Without this IAM role, any attempt to send metrics from the instance will fail due to missing credentials.

Exam trap

The trap here is confusing the CloudWatch Logs agent with the CloudWatch agent, as the Logs agent cannot send custom metrics, and assuming detailed monitoring automatically captures application-level metrics rather than just increasing the frequency of default EC2 metrics.

287
MCQmedium

A SysOps administrator needs to grant an IAM user the ability to rotate their own access keys. What is the minimum set of permissions required?

A.iam:ListAccessKeys, iam:CreateAccessKey, iam:DeleteAccessKey, iam:PutUserPolicy
B.iam:ListAccessKeys, iam:CreateAccessKey, iam:DeleteAccessKey, kms:*
C.iam:GetUser, iam:CreateAccessKey, iam:DeleteAccessKey, iam:UpdateAccessKey
D.iam:ListAccessKeys, iam:CreateAccessKey, iam:DeleteAccessKey, iam:UpdateAccessKey
AnswerD

This set of four IAM actions is correct because it represents the minimum required permissions for a self-service access key rotation workflow. First, iam:ListAccessKeys lets the user enumerate their existing keys to identify which one is active or old. iam:CreateAccessKey allows them to generate a new active key, iam:UpdateAccessKey lets them mark the old key as Inactive to avoid downtime, and iam:DeleteAccessKey removes the old key after the new one is confirmed working. Together these actions support a safe, zero-downtime rotation while denying access to unrelated management functions such as policy editing or KMS administration.

Why this answer

The minimum permissions to allow an IAM user to rotate their own access keys are: iam:ListAccessKeys, iam:CreateAccessKey, iam:DeleteAccessKey, and iam:UpdateAccessKey. Option D is correct. Option A is wrong because it includes iam:PutUserPolicy, which is unnecessary for key rotation and grants additional permissions to modify user policies.

Option B is wrong because it includes kms:*, which is unrelated to access key rotation and grants excessive permissions. Option C is wrong because it includes iam:GetUser, which is not required for rotating own keys; the user already knows their username or can be resolved via the policy variable.

288
Matchingmedium

Match each AWS storage service to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Object storage for any data

Block storage for EC2 instances

File storage for Linux instances

Managed file system for Windows or Lustre

Low-cost archival storage

Why these pairings

Amazon S3 is object storage, EBS is block storage, EFS is file storage, and Glacier is archival. Common confusions include mixing S3 and EBS definitions.

289
MCQeasy

A company runs a web application on EC2 instances behind an Application Load Balancer. The application experiences unpredictable traffic spikes. Which AWS service should be used to automatically adjust the number of EC2 instances based on demand, optimizing cost and performance?

A.AWS Auto Scaling
B.Amazon CloudWatch
C.Elastic Load Balancing
D.AWS Lambda
AnswerA

AWS Auto Scaling is the correct service because it directly manages the size of an EC2 Auto Scaling group by launching or terminating instances in response to conditions you define. It uses scaling policies (e.g., step, target tracking, or scheduled scaling) that rely on CloudWatch metrics, such as CPU utilization or request count, to automatically adjust capacity. This is the only option here that actually performs the act of scaling EC2 instances, maintaining both performance and cost efficiency.

Why this answer

AWS Auto Scaling is the correct service because it automatically adjusts the number of EC2 instances in response to demand, using scaling policies based on metrics like CPU utilization or request count. This ensures that the application can handle traffic spikes without manual intervention, optimizing both cost (by scaling down during low demand) and performance (by scaling up during spikes). The service integrates directly with the Application Load Balancer to register and deregister instances as needed.

Exam trap

The trap here is that candidates often confuse the monitoring service (CloudWatch) with the scaling service, or assume Elastic Load Balancing can handle scaling by itself, but neither directly adjusts instance count—only AWS Auto Scaling performs the actual scaling actions.

How to eliminate wrong answers

Option B (Amazon CloudWatch) is wrong because it is a monitoring and observability service that collects metrics and logs, but it does not directly adjust EC2 instance counts; it can trigger Auto Scaling actions via alarms, but the scaling itself is performed by AWS Auto Scaling. Option C (Elastic Load Balancing) is wrong because it distributes incoming traffic across existing EC2 instances but does not add or remove instances; it relies on Auto Scaling to manage capacity. Option D (AWS Lambda) is wrong because it is a serverless compute service for running code in response to events, not for managing EC2 instance scaling; it cannot directly adjust the number of EC2 instances behind a load balancer.

290
MCQhard

A containerized API runs on Amazon ECS with an Application Load Balancer. The team wants to deploy new container versions with zero downtime, automatically route traffic to the new version only after health checks pass, and automatically roll back if error rates spike within 10 minutes of the shift. Which deployment strategy and configuration implements all three requirements?

A.Use CodeDeploy with the ECS blue/green deployment type, configure a Canary or Linear traffic shifting strategy, and attach a CloudWatch alarm for error rate as a deployment alarm
B.Update the ECS service with a rolling update deployment configuration and set the minimum healthy percent to 100
C.Create a second ECS service with the new task definition and use Route 53 weighted routing to shift traffic at the DNS level
D.Enable ECS circuit breaker on the service to roll back failed deployments automatically
AnswerA

The ECS blue/green deployment starts the green task set, registers it with a second target group, and uses ALB weighted routing to shift traffic progressively. The deployment alarm monitors a 5xx error rate metric. If the alarm enters ALARM state at any point during traffic shifting or the bake period, CodeDeploy automatically shifts traffic back to the original blue target group. The team defines the 10-minute bake window via the deployment configuration's terminationWaitTimeInMinutes.

Why this answer

CodeDeploy's ECS blue/green deployment type supports canary or linear traffic shifting, which automatically routes traffic to the new version only after health checks pass. By attaching a CloudWatch alarm for error rate as a deployment alarm, CodeDeploy can automatically trigger a rollback if error rates spike within the specified monitoring period (e.g., 10 minutes), meeting all three requirements: zero downtime, health-check-gated traffic shifting, and automatic rollback on error rate spikes.

Exam trap

The trap here is that candidates often confuse the ECS circuit breaker (which only handles task-level failures during deployment) with the need for post-deployment error rate monitoring and traffic shifting, leading them to select Option D without realizing it lacks the canary/linear traffic shifting and CloudWatch alarm integration required for automatic rollback based on error spikes.

How to eliminate wrong answers

Option B is wrong because a rolling update with minimum healthy percent set to 100 does not provide automatic rollback based on error rate spikes; it only ensures availability during the update but lacks the traffic-shifting and alarm-based rollback capabilities. Option C is wrong because using Route 53 weighted routing at the DNS level does not provide health-check-gated traffic shifting at the application layer, and DNS caching can cause delayed or uneven traffic distribution, failing to ensure zero downtime and immediate rollback on error spikes. Option D is wrong because the ECS circuit breaker only rolls back a service if tasks fail to start or become unhealthy during deployment, but it does not monitor post-deployment error rates or support canary/linear traffic shifting.

291
Multi-Selectmedium

Which TWO actions should a SysOps administrator take to secure an AWS account root user? (Choose two.)

Select 2 answers
A.Delete the root user after creating an admin IAM user.
B.Apply a service control policy (SCP) to restrict the root user.
C.Enable multi-factor authentication (MFA) for the root user.
D.Enable CloudTrail to monitor root user activity.
E.Do not create access keys for the root user.
AnswersC, E

Enabling MFA on the root user adds a second authentication factor, requiring both the password and a temporary code from a hardware or virtual MFA device. The root user has unrestricted access to all AWS services and cannot be limited by IAM policies, so MFA is a critical preventive control. AWS recommends always setting up MFA for the root account immediately after creation.

Why this answer

Option C is correct because enabling MFA on the root user adds a second authentication factor, so a stolen root password alone cannot be used to sign in to the account. Option E is correct because the root user's access keys grant unrestricted programmatic access that cannot be scoped down by IAM policies, so AWS best practice is to never create them and instead use IAM roles or IAM users. Option A is wrong because the root user cannot be deleted; it is permanently tied to the account and can only have its credentials rotated or removed.

Option B is wrong because SCPs apply to member accounts in AWS Organizations and do not restrict the root user of the management account, nor can they meaningfully limit root credentials. Option D is wrong because CloudTrail provides monitoring and audit logging of root activity, not a preventive control that secures the root user.

Exam trap

SOA-C02 often tests the misconception that the root user can be deleted or restricted by SCPs, when in fact it is permanent and SCPs do not apply to it — candidates must distinguish preventive controls (MFA, no keys) from detective controls (CloudTrail).

292
MCQeasy

A company uses Amazon CloudWatch Logs to store application logs. The SysOps administrator needs to count the occurrences of the string 'ERROR' in the logs and trigger an Amazon SNS notification when more than 10 errors occur within a 5-minute window. Which steps should the administrator take?

A.Create a metric filter on the log group and then create a CloudWatch alarm on the resulting metric
B.Create a CloudWatch alarm directly on the log group
C.Create an AWS Lambda function to parse the logs and send a notification to Amazon SNS
D.Create an Amazon EventBridge rule to filter log events and send to SNS
AnswerA

A metric filter applied to a CloudWatch Logs log group continuously scans incoming log events for a specified pattern (e.g., a literal string or a JSON field value) and converts matching events into a CloudWatch custom metric. Once the metric is published, you can configure a CloudWatch alarm on that metric with thresholds, evaluation periods, and actions such as sending to an SNS topic. This built-in pattern-matching capability runs entirely within the CloudWatch service, with no additional compute or custom code, and is the standard design for alerting on log content.

Why this answer

A metric filter on a CloudWatch Logs log group extracts a numeric metric (e.g., count of 'ERROR' occurrences) and publishes it to a CloudWatch custom metric. A CloudWatch alarm can then be configured on that metric to evaluate a threshold (e.g., >10) over a specified period (e.g., 5 minutes) and trigger an SNS notification when breached. This is the native, serverless, and cost-effective approach for counting log patterns and alerting.

Exam trap

The trap here is that candidates may think they can directly alarm on a log group (Option B) or assume a Lambda function is required for custom log parsing (Option C), but the exam expects knowledge of CloudWatch Logs metric filters as the native solution for counting patterns and triggering alarms.

How to eliminate wrong answers

Option B is wrong because CloudWatch alarms cannot be created directly on a log group; alarms require a numeric metric as input, not raw log data. Option C is wrong because while a Lambda function could parse logs and send to SNS, it introduces unnecessary complexity, cost, and potential latency compared to the built-in metric filter and alarm mechanism. Option D is wrong because Amazon EventBridge rules can filter log events from CloudWatch Logs but cannot perform aggregation (e.g., count occurrences over a time window) to trigger an alarm based on a threshold; EventBridge is designed for event-driven patterns, not metric-based alerting.

293
MCQhard

A SysOps administrator needs to restrict access to an Amazon S3 bucket so that only requests from a specific VPC endpoint are allowed. Which policy statement should be added to the bucket policy?

A.Condition: { StringEquals: { 'aws:SourceVpc': 'vpc-12345' } }
B.Condition: { StringEquals: { 'ec2:Vpc': 'vpc-12345' } }
C.Condition: { IpAddress: { 'aws:VpcSourceIp': '10.0.0.0/16' } }
D.Condition: { StringEquals: { 'aws:SourceVpce': 'vpce-12345' } }
AnswerD

The condition key 'aws:SourceVpce' is the standard and correct way to restrict an S3 bucket policy to a specific VPC endpoint. When a request is made through an AWS PrivateLink VPC endpoint, this global condition contains the endpoint ID (e.g., 'vpce-12345'), allowing you to write a policy that only grants access to that exact endpoint. This ensures that traffic from the VPC must route through the named endpoint, and direct traffic from instances or other endpoints is denied.

Why this answer

The condition key 'aws:SourceVpce' is used to restrict access to requests originating from a specific VPC endpoint (identified by its endpoint ID). Option A uses 'aws:SourceVpc', which restricts to an entire VPC, not a specific endpoint. Option B uses 'ec2:Vpc', which is not a valid condition key for S3 bucket policies.

Option C uses 'aws:VpcSourceIp', which is not a valid condition key; the correct key for IP-based restrictions is 'aws:SourceIp'.

Exam trap

A common trap is confusing 'aws:SourceVpc' with 'aws:SourceVpce'. The former restricts to traffic from any resource in the specified VPC, while the latter restricts to traffic specifically from the VPC endpoint.

294
MCQhard

A company uses AWS KMS to encrypt EBS volumes attached to EC2 instances. The security team wants to ensure that only specific IAM roles can decrypt the volumes. Which configuration meets this requirement?

A.Use a service control policy to deny kms:Decrypt for all users.
B.Apply a bucket policy on the EBS snapshot bucket.
C.Modify the KMS key policy to allow only specific IAM roles to use kms:Decrypt.
D.Attach an instance profile with a policy that denies ec2:DetachVolume.
AnswerC

Modifying the KMS key policy is correct because KMS uses a key policy to specify which principals can use the key for cryptographic operations like kms:Decrypt. By allowing only specific IAM roles in the key policy, you ensure that only those roles (and any other explicitly authorized principals) can decrypt the EBS volumes and snapshots encrypted with that key. This works in conjunction with IAM policies; the key policy explicitly grants the roles decrypt access, while all other IAM principals are implicitly denied. You can further refine this with conditions such as kms:ViaService to limit decrypt calls to EC2.

Why this answer

KMS key policies allow you to specify which IAM roles are allowed to use the key for decryption. Option A is wrong because service control policies (SCPs) are used to set permission boundaries across accounts in an organization, but they are not the most direct way to restrict decryption for specific IAM roles; KMS key policies are more appropriate. Option B is wrong because EBS volumes do not have bucket policies; bucket policies apply to S3 buckets.

Option D is wrong because instance profiles and policies denying ec2:DetachVolume do not affect decryption permissions.

295
MCQmedium

A company runs a web application on EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). The application needs to serve HTTPS content. The SysOps administrator wants to offload SSL termination to the ALB and automatically renew the certificate before expiration. Which solution should the administrator implement?

A.Use AWS Certificate Manager (ACM) to request a public certificate and associate it with the ALB.
B.Upload a third-party certificate to IAM and associate it with the ALB.
C.Store the certificate in Amazon S3 and configure the ALB to read from S3.
D.Use a self-signed certificate on each EC2 instance and configure the ALB for TCP passthrough.
AnswerA

AWS Certificate Manager (ACM) public certificates are fully managed, so ACM automatically renews them before expiration and handles DNS or email validation. You can directly associate the certificate with an ALB listener, and the ALB terminates TLS, meaning EC2 instances receive only HTTP traffic. This offloads the cryptographic overhead and eliminates the need to install or rotate certificates on individual instances, making it the intended and least operationally burdensome approach.

Why this answer

AWS Certificate Manager (ACM) integrates natively with Application Load Balancers to handle SSL/TLS termination. ACM can automatically renew public certificates issued by Amazon's trusted certificate authority, eliminating the need for manual renewal. By associating the ACM certificate with the ALB's HTTPS listener, the administrator offloads SSL termination and ensures automatic certificate renewal before expiration.

Exam trap

The trap here is that candidates may confuse ACM's automatic renewal with manual certificate upload methods (IAM or S3) or incorrectly think self-signed certificates can be used with ACM, when in fact ACM only manages certificates from its own public CA or imported certificates that must be manually renewed.

How to eliminate wrong answers

Option B is wrong because uploading a third-party certificate to IAM is a legacy approach that does not support automatic renewal; IAM certificates must be manually re-uploaded before expiration. Option C is wrong because Amazon S3 cannot be used as a certificate store for ALB; ALB does not support reading certificates from S3. Option D is wrong because using a self-signed certificate on each EC2 instance with TCP passthrough would require the instances to handle SSL termination, defeating the requirement to offload SSL to the ALB, and self-signed certificates are not trusted by browsers and cannot be automatically renewed by ACM.

296
MCQmedium

An application running on EC2 instances in an Auto Scaling group uses an SQS queue for decoupling. The application experiences increased latency when the queue has a high number of messages. The SysOps Administrator needs to maintain responsiveness. Which solution is the most cost-effective?

A.Increase the desired capacity of the Auto Scaling group.
B.Configure a CloudWatch alarm on the queue depth to trigger Auto Scaling policies.
C.Use a larger instance type for the EC2 instances.
D.Increase the visibility timeout of the SQS queue.
AnswerB

Create a CloudWatch alarm on the SQS metric ApproximateNumberOfMessagesVisible, the number of messages waiting in the queue, and attach it to a scaling policy for the ASG. When the backlog exceeds a threshold, the alarm enters ALARM state and adds instances to consume messages faster; when the queue drains, it removes instances. This directly couples consumer fleet size to actual demand, providing cost-efficient elasticity that avoids both under-provisioning and idle over-provisioning.

Why this answer

Using a CloudWatch alarm on the SQS queue depth (ApproximateNumberOfMessagesVisible) to trigger Auto Scaling policies allows the Auto Scaling group to dynamically add EC2 instances only when the queue grows, directly addressing increased latency by scaling out compute capacity. This is the most cost-effective approach as it scales resources based on actual demand, avoiding over-provisioning.

Exam trap

The trap here is that candidates often confuse static scaling (Option A) or vertical scaling (Option C) with dynamic, demand-based scaling, or mistakenly think that increasing the visibility timeout (Option D) will reduce queue depth, when in fact it only delays message reprocessing.

How to eliminate wrong answers

Option A is wrong because increasing the desired capacity of the Auto Scaling group statically raises the number of running instances regardless of queue depth, leading to unnecessary cost when the queue is not deep. Option C is wrong because using a larger instance type increases per-instance cost and does not automatically scale with queue depth; it may still suffer from latency if the queue grows beyond the capacity of a single larger instance. Option D is wrong because increasing the visibility timeout of the SQS queue does not reduce the number of messages or processing time; it only delays when a message becomes visible again after a consumer fails, which can actually increase latency by hiding unprocessed messages longer.

297
Matchingmedium

Match each AWS support plan to its key feature.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Account and billing support only

Business hours email access

24/7 phone, chat, and email; <1 hour response

Concierge support team; <30 min response

Technical Account Manager; <15 min response

Why these pairings

Basic provides community access, Developer provides business hours email, Business provides 24/7 support with 1-hour response, and Enterprise adds a TAM and faster response. Common confusions include swapping Business and Enterprise features.

298
MCQeasy

A SysOps administrator needs to create a custom metric to track the number of active connections to an EC2 instance. Which steps should be taken? (Select TWO.)

A.Enable detailed monitoring on the EC2 instance.
B.Use the AWS CLI to call put-metric-data and publish the custom metric.
C.Store the metric data in an S3 bucket and configure CloudWatch to read from it.
D.Use the EC2 console to enable custom metric collection.
E.Install and configure the Amazon CloudWatch agent on the EC2 instance.
AnswerB, E

Using the AWS CLI's put-metric-data command is a direct way to publish a custom metric by sending the metric name, namespace, value, unit, timestamp, and optional dimensions to CloudWatch's PutMetricData API. This works well for on-demand or scripted collection, such as a cron job that measures an application-specific value and pushes the result. The CLI call requires the cloudwatch:PutMetricData IAM permission and can optionally set StorageResolution to 1 for high-resolution metrics.

Why this answer

The AWS CLI `put-metric-data` command allows you to publish custom metrics directly to CloudWatch, which is the standard method for sending application-level or OS-level metrics that are not automatically provided by AWS. Option E is correct because the Amazon CloudWatch agent can collect custom metrics from the EC2 instance (e.g., active connection counts from netstat or a script) and publish them to CloudWatch, making it the recommended approach for in-guest metric collection.

Exam trap

The trap here is that candidates often confuse 'detailed monitoring' (which only increases frequency of existing metrics) with the ability to create new custom metrics, leading them to select Option A incorrectly.

How to eliminate wrong answers

Option A is wrong because enabling detailed monitoring on an EC2 instance only increases the frequency of standard hypervisor-level metrics (CPU, disk, network) from 5 minutes to 1 minute; it does not enable collection of custom metrics like active connections. Option C is wrong because CloudWatch cannot directly read metric data from an S3 bucket; you would need to use a Lambda function or other service to ingest the data into CloudWatch via PutMetricData. Option D is wrong because the EC2 console does not have a feature to enable custom metric collection; custom metrics must be published programmatically via the CloudWatch API, CLI, or an agent.

299
MCQeasy

A SysOps administrator needs to automate the deployment of a three-tier web application. The application consists of an Application Load Balancer, a fleet of EC2 instances running a web server, and an Amazon RDS MySQL database. The administrator must ensure that the database credentials are securely stored and automatically rotated. The administrator also needs to version the infrastructure configuration. Which combination of AWS services should the administrator use?

A.AWS CloudFormation for infrastructure and AWS Systems Manager Parameter Store for secrets.
B.AWS OpsWorks for infrastructure and AWS Secrets Manager for secrets.
C.AWS CodeCommit for infrastructure versioning and AWS KMS for secrets.
D.AWS CloudFormation for infrastructure and AWS Secrets Manager for secrets.
AnswerD

CloudFormation is the correct infrastructure tool because it provisions AWS resources from declarative templates that can be versioned, reviewed, and rolled back, enabling automated and repeatable deployment. Secrets Manager is the correct secrets tool because it natively supports automatic rotation of RDS credentials through a built-in Lambda rotation function, and CloudFormation can securely reference those secrets using dynamic references. Together they satisfy automated deployment and credential rotation in a single operational pipeline.

Why this answer

AWS CloudFormation is used to automate infrastructure deployment and version the configuration as code. AWS Secrets Manager securely stores database credentials and provides automatic rotation. Together, they meet the requirements for secure credential management and infrastructure versioning.

Exam trap

SOA-C02 often tests the difference between Parameter Store and Secrets Manager, particularly around automatic rotation, leading candidates to choose Parameter Store for secrets that require rotation.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Parameter Store can store secrets but does not provide automatic rotation natively; rotation requires custom Lambda functions. Option B is wrong because AWS OpsWorks is a configuration management service that is not primarily used for infrastructure as code versioning; CloudFormation is more suitable. Option C is wrong because AWS CodeCommit is a source control service for code, not specifically for infrastructure versioning, and AWS KMS is a key management service, not a secrets manager with rotation.

300
MCQmedium

A company's security policy requires that all Amazon S3 buckets must have server-side encryption (SSE-S3 or SSE-KMS) enabled. The SysOps administrator needs to automatically detect any bucket that does not have encryption enabled and remediate it by enabling SSE-S3. Which AWS service should be used to implement this automated compliance enforcement?

A.AWS Config
B.Amazon Inspector
C.AWS Trusted Advisor
D.Amazon Macie
AnswerA

AWS Config is the correct choice because it continuously evaluates S3 bucket configurations against managed rules such as s3-bucket-default-encryption or s3-bucket-server-side-encryption-enabled. When a bucket is non-compliant, AWS Config can trigger automatic remediation by invoking an AWS Systems Manager Automation document or a custom Lambda function. This gives you both detection and enforcement, which matches the security policy's requirement for automatic remediation of unencrypted buckets.

Why this answer

AWS Config is the correct service because it provides managed rules (e.g., s3-bucket-server-side-encryption-enabled) that can continuously evaluate S3 bucket configurations against the security policy. When a non-compliant bucket is detected, AWS Config can trigger an automatic remediation action via Systems Manager Automation to enable SSE-S3, enforcing compliance without manual intervention.

Exam trap

The trap here is that candidates often confuse AWS Config's compliance evaluation and remediation capabilities with Trusted Advisor's advisory checks, leading them to choose Trusted Advisor despite its lack of automated enforcement.

How to eliminate wrong answers

Option B is wrong because Amazon Inspector is a vulnerability management service that scans EC2 instances and container workloads for software vulnerabilities and unintended network exposure, not for evaluating S3 bucket encryption settings. Option C is wrong because AWS Trusted Advisor provides best-practice checks and recommendations but does not offer automated remediation or continuous compliance enforcement; it is a reactive advisory tool. Option D is wrong because Amazon Macie is a data security service that uses machine learning to discover, classify, and protect sensitive data in S3, not to enforce encryption policies or remediate non-compliant buckets.

Page 3

Page 4 of 16

Page 5