Courseiva

AWS Certified SysOps Administrator Associate SOA-C02 (SOA-C02) — Questions 376–450

1169 questions total · 16pages · All types, answers revealed

Page 5

Page 6 of 16

Page 7
376
Multi-Selectmedium

A SysOps administrator is troubleshooting an Amazon EC2 instance that is unreachable. The instance passes the system status check but fails the instance status check. Which TWO of the following are likely causes of this issue? (Choose TWO.)

Select 2 answers
A.Network connectivity issues
B.Detached EBS root volume
C.Misconfigured firewall or iptables
D.Insufficient memory for applications
E.Corrupted file system
AnswersC, E

A misconfigured firewall or iptables ruleset can block all inbound and outbound traffic, effectively making the instance unreachable despite the OS running normally. The instance status check performs a network reachability test at the OS level, and if the packet filtering rules prevent the response, the check fails, indicating an instance-level problem. Since the issue stems from guest OS configuration rather than AWS infrastructure, it is correctly identified as an instance status check failure.

Why this answer

An instance status check failure indicates that the operating system or the instance itself is not functioning correctly, even though the underlying hardware (system status check) is healthy. A misconfigured firewall or iptables can block required network traffic, causing the instance to appear unreachable, while a corrupted file system can prevent the OS from booting or operating properly, both of which are detected by the instance status check.

Exam trap

The trap here is that candidates often confuse instance status checks with system status checks, incorrectly attributing network-level issues (like detached volumes or external connectivity) to instance status failures when they actually belong to system status failures.

377
MCQeasy

Refer to the exhibit. A SysOps administrator runs the 'list-metrics' command for CPUUtilization. Based on the output, what can the administrator conclude?

A.The CPUUtilization metric is only available for EC2 instances.
B.There are two EC2 instances that have reported CPUUtilization metrics at some point.
C.Both instances are actively publishing CPUUtilization metrics.
D.An alarm has been set on both instances for CPUUtilization.
AnswerB

list-metrics returns a metadata list of metric definitions that have been registered with CloudWatch when data points were published. The output shows two distinct InstanceId dimension values, which means CloudWatch has received CPUUtilization data from two separate EC2 instances at some point in time. This is true regardless of whether those instances are currently sending new data, as CloudWatch retains the metric definitions for a long period after the last publication.

Why this answer

The 'list-metrics' output shows two distinct dimensions (i-12345678 and i-87654321) for the CPUUtilization metric, indicating that two EC2 instances have reported this metric at some point. Option B is correct because the presence of two unique instance IDs in the metric data confirms that CPUUtilization has been recorded for both instances, regardless of whether they are currently active or have alarms configured.

Exam trap

The trap here is that candidates assume 'list-metrics' shows only currently active resources or that it implies alarm configurations, when in fact it only reflects historical metric reporting and has no relation to current state or alarms.

How to eliminate wrong answers

Option A is wrong because CPUUtilization is not exclusive to EC2 instances; it can also be reported by other services like Auto Scaling groups or Elastic Load Balancers via the AWS/EC2 namespace, but the metric itself is available for any resource that publishes it. Option C is wrong because the output only shows that metrics have been reported at some point; it does not indicate whether the instances are currently publishing metrics (e.g., they could be stopped or terminated). Option D is wrong because the 'list-metrics' command returns metric metadata, not alarm configurations; alarms are managed separately via the 'describe-alarms' API and are not visible in this output.

378
MCQeasy

A SysOps administrator needs to monitor the CPU utilization of an EC2 instance and receive an alert when it exceeds 80% for 10 consecutive minutes. Which AWS service should be used to set up this monitoring and alerting?

A.Amazon CloudWatch
B.AWS Trusted Advisor
C.AWS Config
D.AWS CloudTrail
AnswerA

Amazon CloudWatch is the native monitoring service that collects and tracks metrics from EC2 instances, including the CPUUtilization metric. It supports both default 5-minute and detailed 1-minute monitoring, and you can create CloudWatch Alarms that trigger actions when CPU utilization crosses a defined threshold, enabling proactive remediation.

Why this answer

Amazon CloudWatch is the correct service because it provides the ability to monitor EC2 instance metrics, such as CPU utilization, and create CloudWatch Alarms that trigger when a metric crosses a defined threshold (e.g., 80%) for a specified number of consecutive evaluation periods (e.g., 10 minutes with a 1-minute period). This directly meets the requirement for monitoring and alerting on CPU utilization.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (auditing API calls) or AWS Config (configuration compliance) with CloudWatch, thinking they can monitor performance metrics, but only CloudWatch provides metric collection and alarm-based alerting for EC2 CPU utilization.

How to eliminate wrong answers

Option B (AWS Trusted Advisor) is wrong because it provides best-practice recommendations for cost optimization, performance, security, and fault tolerance, but it does not monitor real-time EC2 CPU utilization or trigger alerts based on metric thresholds. Option C (AWS Config) is wrong because it evaluates and records configuration changes to AWS resources (e.g., security group rules, instance types) and can trigger rules-based remediation, but it does not monitor performance metrics like CPU utilization. Option D (AWS CloudTrail) is wrong because it records API activity and user actions for auditing and governance, not real-time performance monitoring or metric-based alerting.

379
MCQeasy

A company needs to monitor for unauthorized changes to critical IAM policies. The SysOps administrator must receive notifications within minutes of any change. Which combination of AWS services should the administrator use?

A.Use AWS CloudTrail to log IAM changes, and create a CloudWatch Events rule that triggers an SNS notification when specific API calls are made.
B.Use AWS Config rules to detect changes and send notifications via SNS.
C.Use CloudWatch Logs to monitor IAM activity and create a metric filter to trigger an alarm.
D.Use a Lambda function that periodically checks IAM policies and sends an SNS message if changes are detected.
AnswerA

CloudTrail records all IAM management events as API calls, including high-risk actions like `PutUserPolicy` or `DeleteUser`. An EventBridge/CloudWatch Events rule can match on event source and event name, then invoke an SNS topic within seconds. This gives a near-real-time, event-driven alert without polling or manual inspection, making it the only fully purpose-built combination.

Why this answer

AWS CloudTrail logs all IAM API calls (e.g., PutRolePolicy, AttachRolePolicy) as events. A CloudWatch Events rule (now called Amazon EventBridge rule) can be configured to match these specific API calls and trigger an SNS topic, delivering near-instant notifications within minutes. This combination provides real-time, event-driven monitoring without polling or delays.

Exam trap

This question tests the distinction between event-driven (CloudTrail + EventBridge) and polling-based (AWS Config, Lambda periodic checks) approaches. Candidates often mistakenly choose AWS Config or Lambda because they assume 'detect changes' implies periodic evaluation, missing the real-time requirement.

How to eliminate wrong answers

Option B is wrong because AWS Config rules evaluate resource configurations against desired states on a periodic basis (e.g., every 10 minutes or per configuration change), which can introduce a delay of up to several minutes and does not guarantee notification within minutes of the change event itself. Option C is wrong because CloudWatch Logs requires IAM API calls to be sent to CloudWatch Logs via CloudTrail, and a metric filter + alarm adds latency from log ingestion, metric evaluation, and alarm state transitions, often taking 5–15 minutes. Option D is wrong because a Lambda function that periodically checks IAM policies introduces a polling interval (e.g., every 5 minutes), which means changes could go undetected for up to that interval, failing the 'within minutes' requirement and potentially missing changes made between checks.

380
MCQhard

A company uses AWS Organizations and wants to restrict access to S3 buckets based on project tags. The security policy requires that users in the 'DataScientists' group can only access S3 buckets that have the tag 'Project: DataEngineering'. Which IAM policy condition key should the SysOps administrator use in a customer managed policy to enforce this restriction?

A.aws:ResourceTag
B.s3:ExistingObjectTag
C.s3:ResourceTag
D.iam:ResourceTag
AnswerA

The aws:ResourceTag condition key allows you to control access based on tags attached to the resource being accessed (e.g., S3 bucket tag). You can use it in the 'Condition' element of an IAM policy to enforce the tag requirement.

Why this answer

The `aws:ResourceTag` condition key is used in IAM policies to control access based on the tags attached to the AWS resource (in this case, an S3 bucket). By specifying `aws:ResourceTag/Project` with a value of `DataEngineering`, the policy ensures that only S3 buckets with that exact tag are accessible to the 'DataScientists' group. This key is evaluated against the resource's tags at the time of the request, making it the appropriate choice for tag-based resource restrictions.

Exam trap

The trap here is that candidates often confuse `aws:ResourceTag` with service-specific keys like `s3:ExistingObjectTag`, mistakenly applying object-level conditions to bucket-level restrictions, or they assume `s3:ResourceTag` exists as a valid key when it does not.

How to eliminate wrong answers

Option B is wrong because `s3:ExistingObjectTag` is used to condition access based on tags on individual objects within an S3 bucket, not on the bucket itself, and thus cannot restrict access to buckets based on bucket-level tags. Option C is wrong because `s3:ResourceTag` is not a valid IAM condition key; AWS uses `aws:ResourceTag` for resource-level tags across services, and S3-specific condition keys like `s3:ExistingObjectTag` or `s3:RequestObjectTag` are for object-level operations. Option D is wrong because `iam:ResourceTag` is specific to IAM resources (such as users, roles, or policies) and cannot be used to restrict access to S3 buckets based on bucket tags.

381
MCQeasy

A company wants to ensure that its EC2 instances receive patches automatically to maintain security compliance. Which AWS service can be used to automate patch management?

A.Amazon CloudWatch
B.AWS Systems Manager
C.AWS Config
D.AWS CloudTrail
AnswerB

AWS Systems Manager Patch Manager automates the process of patching managed EC2 instances and on-premises servers. It uses the Systems Manager Agent (SSM Agent) to discover missing patches, download them from configured patch baselines, and install them according to maintenance window schedules. Patch Manager supports both Linux and Windows, including security updates, bug fixes, and non-security patches, and can generate compliance reports. This is the native AWS service designed specifically for patch management.

Why this answer

AWS Systems Manager Patch Manager automates the process of patching managed EC2 instances and on-premises servers. It uses patch baselines to define approved patches and can schedule patching across maintenance windows, ensuring security compliance without manual intervention.

Exam trap

The trap here is that candidates often confuse AWS Config's compliance evaluation with actual remediation actions, but Config only detects drift and can trigger automation via Systems Manager Automation documents—it does not directly patch instances.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch is a monitoring and observability service for metrics, logs, and alarms; it does not have any capability to apply patches to EC2 instances. Option C is wrong because AWS Config is a service for evaluating resource configurations against desired policies and tracking compliance, but it cannot automate the installation of patches. Option D is wrong because AWS CloudTrail records API activity for auditing and governance; it does not perform any operational actions like patching.

382
MCQeasy

A web application runs on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. To achieve high availability, what is the minimum number of Availability Zones (AZs) that must be configured for the Auto Scaling group?

A.1
B.2
C.3
D.4
AnswerB

Placing instances across two Availability Zones in an Auto Scaling group ensures that if one AZ fails, the remaining AZ's instances continue serving traffic, and the group can automatically launch new instances in that healthy AZ to maintain the desired capacity. This configuration meets the classic high-availability requirement because AWS guarantees independent failure of AZs, so two AZs provide sufficient redundancy. For most production workloads, two AZs are the minimum architectural baseline for high availability.

Why this answer

For high availability, an Auto Scaling group must span at least two Availability Zones (AZs) to ensure that if one AZ fails, the application remains available from the other AZ. A single AZ would create a single point of failure, violating the high-availability requirement. The Application Load Balancer distributes traffic across healthy instances in all configured AZs, so two AZs are the minimum to achieve fault tolerance.

Exam trap

The trap here is that candidates often think a single AZ is sufficient if the Auto Scaling group can replace failed instances, but they overlook that the AZ itself is a failure domain, and high availability requires redundancy across at least two AZs.

How to eliminate wrong answers

Option A is wrong because configuring only one AZ creates a single point of failure; if that AZ becomes unavailable, the application will be completely inaccessible, which does not meet high-availability requirements. Option C is wrong because while three AZs provide even greater resilience, the question asks for the minimum number required for high availability, and two AZs satisfy that requirement. Option D is wrong because four AZs are excessive for the minimum requirement; high availability is achieved with two AZs, and additional AZs increase cost without being necessary for the basic goal.

383
MCQhard

A company runs a production application on EC2 instances in an Auto Scaling group. The application stores data on an EBS volume. The SysOps administrator wants to ensure that the data is durable and available even if an EC2 instance fails. Which approach should the administrator take?

A.Use an instance store volume and replicate data across instances.
B.Use an EBS volume with snapshots taken every hour.
C.Move the data to an S3 bucket and access it via S3 API.
D.Migrate the data to Amazon EFS and mount it to all instances.
AnswerD

Amazon EFS provides a fully managed, elastic NFS file system that can be mounted concurrently on multiple EC2 instances across multiple Availability Zones. It is durable and highly available, with data stored redundantly across AZs, and supports standard file system semantics such as locking and concurrent access. This makes it the right choice for a shared file system that all application instances can access simultaneously.

Why this answer

Amazon EFS provides a fully managed, scalable, and shared file system that can be mounted concurrently to multiple EC2 instances across Availability Zones. By migrating the data to EFS and mounting it to all instances in the Auto Scaling group, the data remains durable and available even if an individual EC2 instance fails, because the file system persists independently of any single instance's lifecycle.

Exam trap

The trap here is that candidates often confuse EBS snapshots (which are backups, not high-availability solutions) with a truly shared, durable file system, leading them to choose Option B despite its inability to provide automatic failover and continuous availability.

How to eliminate wrong answers

Option A is wrong because instance store volumes provide only ephemeral, block-level storage that is physically attached to the host; data is lost if the instance stops, terminates, or fails, and replication across instances would require custom, complex logic without built-in durability guarantees. Option B is wrong because while EBS snapshots provide point-in-time backups, they do not ensure continuous availability or automatic failover; if the EC2 instance fails, the EBS volume is still tied to that instance and cannot be immediately attached to another instance without manual intervention and potential downtime. Option C is wrong because moving data to S3 and accessing it via the S3 API would require significant application refactoring to replace file-system semantics with object storage operations, and S3 does not support standard file locking or POSIX permissions needed by many production applications.

384
MCQeasy

A SysOps administrator needs to monitor the CPU utilization of an Amazon RDS for MySQL DB instance. The administrator wants to receive a notification when the average CPU utilization exceeds 80% for 10 consecutive minutes. Which steps should the administrator take to set up this monitoring?

A.Use CloudWatch Logs to monitor the database logs and create an alarm based on log patterns.
B.Enable Enhanced Monitoring and create an alarm on the 'CPUUtilization' metric in RDS console.
C.Create a CloudWatch alarm on the 'CPUUtilization' metric with a threshold of 80% and an SNS topic for notifications.
D.Enable CloudTrail and create a metric filter for CPU utilization.
AnswerC

This is the standard method because Amazon RDS automatically publishes the 'CPUUtilization' metric in the AWS/RDS namespace to CloudWatch at one-minute or five-minute granularity. Creating a CloudWatch alarm with an 80% threshold and an SNS topic allows you to be notified via email, SMS, or Lambda when the alarm triggers. You should also set an appropriate evaluation period and period to avoid false alarms from temporary spikes.

Why this answer

Amazon RDS automatically publishes the 'CPUUtilization' metric to CloudWatch, and a CloudWatch alarm can be configured with a threshold of 80% for the 'Average' statistic over a period of 10 consecutive minutes (e.g., 10 evaluation periods of 1 minute each). The alarm can then trigger an SNS topic to send notifications when the threshold is breached. This directly meets the requirement without additional services.

Exam trap

The trap here is that candidates confuse Enhanced Monitoring (which provides OS-level metrics like memory and disk I/O) with the standard CloudWatch metrics, leading them to incorrectly think Enhanced Monitoring is required for CPU utilization alarms.

How to eliminate wrong answers

Option A is wrong because CloudWatch Logs monitors database logs (e.g., error logs, slow query logs) for patterns, not CPU utilization metrics; CPU utilization is a numeric metric, not a log pattern. Option B is wrong because Enhanced Monitoring provides OS-level metrics (e.g., 'cpuUtilization' in the RDS console) but is not required for the basic 'CPUUtilization' metric already available in CloudWatch; creating an alarm on that metric does not require Enhanced Monitoring. Option D is wrong because CloudTrail records API calls (e.g., RDS instance modifications), not CPU utilization metrics; metric filters in CloudTrail cannot capture CPU utilization data.

385
MCQmedium

A SysOps administrator is creating an IAM policy for automation. The policy is attached to an IAM role used by an automated deployment script. The script needs to launch EC2 instances of type t2.micro and describe all EC2 resources. However, the script fails when trying to launch instances. What is the MOST likely reason?

A.The Resource ARN for the instance is incorrect.
B.The policy does not include the 'ec2:DescribeInstances' action.
C.The policy does not grant permissions for additional resources required by RunInstances, such as images, network interfaces, and security groups.
D.The Condition key 'ec2:InstanceType' is misspelled.
AnswerC

RunInstances is a multi-resource API action: IAM evaluates it against every resource type that the new instance will create or use, including the AMI (image), network interface, security group, volume, and optionally subnet and key pair. A policy that only grants ec2:RunInstances on the instance ARN (e.g., arn:aws:ec2:region:account:instance/*) does not grant the needed permissions on those other resource types, so the request will be denied even though the instance ARN itself is correct. To allow the launch, you must either use Resource * for the ec2:RunInstances action or provide a separate statement with the appropriate ARNs for each resource type involved. This is the core reason the policy fails as written.

Why this answer

The RunInstances API action requires permissions for not only the EC2 instance resource itself but also for dependent resources such as Amazon Machine Images (AMI), network interfaces, security groups, and key pairs. If the IAM policy only grants ec2:RunInstances on the instance resource ARN but omits these supporting resources, the launch will fail with an 'unauthorized operation' error. Option C correctly identifies this missing dependency.

Exam trap

The trap here is that candidates assume granting ec2:RunInstances on the instance resource is sufficient, overlooking that AWS requires explicit permissions for all dependent resources that are implicitly created or modified during instance launch.

How to eliminate wrong answers

Option A is wrong because an incorrect Resource ARN would cause a failure for all actions referencing that ARN, but the script can describe EC2 resources, indicating the ARN is valid for DescribeInstances; the failure is specific to RunInstances. Option B is wrong because the script successfully describes EC2 resources, so ec2:DescribeInstances must be present in the policy. Option D is wrong because a misspelled Condition key would not cause a launch failure unless the condition was evaluated and rejected; the error is due to missing permissions, not a condition syntax issue.

386
MCQhard

A company runs a stateful web application on EC2 instances in an Auto Scaling group. The application uses a sticky session (session affinity) feature of the Application Load Balancer. During a scale-in event, some users lose their session data. What should the SysOps administrator do to prevent session data loss?

A.Disable sticky sessions and use a round-robin routing algorithm.
B.Store session state in an external data store such as Amazon ElastiCache.
C.Use a lifecycle hook to back up session data before termination.
D.Increase the Auto Scaling group's cooldown period to delay termination.
AnswerB

Storing session state in an external data store such as Amazon ElastiCache decouples the session data from the lifecycle of any single EC2 instance. When an instance is terminated or replaced, other instances can immediately retrieve the same session from the shared ElastiCache cluster, so users experience no interruption. This is the correct pattern because ElastiCache, especially with Redis, provides low latency reads and writes and can be configured with replication and persistence for high availability.

Why this answer

Sticky sessions (session affinity) tie a user's session to a specific EC2 instance. When a scale-in event terminates that instance, the session data stored locally on the instance is lost. Storing session state in an external data store like Amazon ElastiCache decouples session data from individual instances, allowing any healthy instance to serve the user's request without data loss, even after a scale-in event.

Exam trap

The trap here is that candidates may think lifecycle hooks (Option C) are a valid solution, but they only delay termination and do not prevent data loss for in-flight sessions, whereas the correct approach is to externalize session state entirely.

How to eliminate wrong answers

Option A is wrong because disabling sticky sessions and using round-robin routing does not solve the problem; it would cause users to be routed to different instances on each request, which would still lose locally stored session data and could break the application entirely. Option C is wrong because a lifecycle hook can delay termination and allow a script to back up session data, but this is a complex, race-condition-prone workaround that does not guarantee zero data loss and adds significant latency to scaling events. Option D is wrong because increasing the cooldown period only delays the termination of instances, it does not prevent session data loss when the instance is eventually terminated.

387
MCQmedium

A company has a VPC with public and private subnets. An EC2 instance in a private subnet needs to download software patches from the internet. Which component should be used to provide internet access to the instance?

A.NAT Gateway in a public subnet
B.AWS Site-to-Site VPN
C.Internet Gateway attached to the VPC
D.VPC Endpoint for Amazon S3
AnswerA

A NAT Gateway is a fully managed service that enables instances in private subnets to initiate outbound IPv4 traffic to the internet while preventing inbound connections from the internet. It must be deployed in a public subnet with a route table entry in each private subnet pointing 0.0.0.0/0 to the NAT Gateway's network interface. This is the correct solution because it provides reliable, scalable outbound internet access without assigning public IPs to private instances, and it automatically handles connection tracking and dynamic scaling.

Why this answer

A NAT Gateway in a public subnet allows EC2 instances in private subnets to initiate outbound traffic to the internet (e.g., to download patches) while preventing unsolicited inbound connections. The NAT Gateway uses an Elastic IP and routes traffic from the private subnet through the internet gateway attached to the VPC, translating the private IP to the public IP of the NAT Gateway.

Exam trap

The trap here is that candidates often confuse an Internet Gateway with a NAT Gateway, assuming the IGW can be used directly by private instances, but the IGW requires a public IP on the instance and a route to 0.0.0.0/0 via the IGW, which is only possible from a public subnet.

How to eliminate wrong answers

Option B is wrong because an AWS Site-to-Site VPN connects your VPC to an on-premises network over the internet, but it does not provide direct internet access to instances in a private subnet; it only extends your corporate network. Option C is wrong because an Internet Gateway attached to the VPC provides internet access only to resources in public subnets (with a route table entry pointing to the IGW); a private subnet cannot use the IGW directly without a NAT device. Option D is wrong because a VPC Endpoint for Amazon S3 provides private connectivity to S3 over the AWS network, not general internet access for downloading patches from arbitrary internet hosts.

388
Multi-Selectmedium

A company wants to audit all API calls made in their AWS account for compliance. Which THREE AWS services can be used together to capture and store these logs? (Choose three.)

Select 3 answers
A.Amazon CloudWatch Logs
B.AWS CloudTrail
C.AWS Config
D.Amazon S3
E.Amazon GuardDuty
AnswersA, B, D

Amazon CloudWatch Logs is correct because it can be the destination for a CloudTrail trail: you can configure CloudTrail to deliver all API call events to a CloudWatch Logs log group. From there, you can store the logs, apply metric filters for real-time monitoring, and retain them for analysis or alerting. This integration makes CloudWatch Logs a valid place to audit and act on API activity, even though CloudTrail itself is the original recorder.

Why this answer

AWS CloudTrail (B) is the service that records API activity in an AWS account, capturing management and data events as audit trails, which is exactly what is needed to audit all API calls. Amazon CloudWatch Logs (A) is used to receive and store those CloudTrail event logs via a trail's CloudWatch Logs integration, enabling centralized monitoring and retention of the API call records. Amazon S3 (D) is the destination where CloudTrail delivers the log files for durable, long-term storage and later compliance analysis.

AWS Config (C) evaluates resource configurations and compliance against rules rather than capturing API call logs, and Amazon GuardDuty (E) is a threat-detection service that analyzes findings from sources like CloudTrail but does not itself capture and store the raw API call logs.

Exam trap

SOA-C02 often tests the confusion between CloudTrail (captures API activity) and AWS Config (records resource configuration state) — candidates pick Config thinking it logs API calls, but Config tracks configuration drift, not API events.

389
MCQhard

A company uses Amazon CloudFront to deliver content to a global audience. The origin is an Application Load Balancer in us-east-1. The SysOps administrator wants to reduce costs by minimizing the number of requests that reach the origin server. Which action should the administrator take?

A.Enable CloudFront Origin Shield.
B.Configure multiple origins for failover.
C.Enable CloudFront Web Application Firewall (WAF) integration.
D.Increase the cache TTL for CloudFront distributions.
AnswerA

CloudFront Origin Shield acts as an intermediary caching layer between all edge locations and the origin, located in a specific AWS Region. When an edge cache misses, it forwards the request to Origin Shield; if the object is already cached there, Origin Shield serves it directly, preventing a redundant fetch to the origin. This aggregation of requests from multiple edges substantially reduces the number of origin requests and the associated compute and data transfer costs, while also providing a single point for cache fills and origin protection.

Why this answer

CloudFront Origin Shield acts as an additional caching layer in front of the origin, reducing the load on the origin by consolidating requests from multiple edge locations. This minimizes the number of requests that reach the Application Load Balancer, directly lowering origin request costs and improving cache hit ratio.

Exam trap

The trap here is that candidates often assume increasing cache TTL is the primary way to reduce origin requests, but they overlook that Origin Shield directly reduces origin load by consolidating requests, which is a more targeted cost optimization feature for CloudFront.

How to eliminate wrong answers

Option B is wrong because configuring multiple origins for failover improves availability, not cost reduction, and does not reduce the number of requests reaching the origin. Option C is wrong because enabling CloudFront WAF integration provides security filtering (e.g., against SQL injection or DDoS), but does not minimize origin requests; it may even add latency for inspection. Option D is wrong because increasing cache TTL can improve cache hit ratio, but it does not guarantee fewer origin requests if the content is already cached; it only extends the time before a cached object expires, and may lead to stale content if not managed properly.

390
MCQmedium

A SysOps administrator notices that an RDS instance's storage is nearly full. The instance uses General Purpose SSD (gp2) storage. The administrator needs to increase storage with minimal downtime. Which action should be taken?

A.Modify the RDS instance to increase the allocated storage size
B.Enable storage auto-scaling
C.Delete old data to free up space
D.Convert the storage type to Provisioned IOPS
AnswerA

Use the AWS Management Console, CLI (modify-db-instance), or API to increase AllocatedStorage on the existing RDS DB instance. RDS performs the storage expansion online, so the database remains available during the modification, and this immediately gives InnoDB/MyISAM or other engine files additional space. This is the correct immediate remediation because it directly addresses the current storage-full condition.

Why this answer

Modifying the RDS instance to increase the allocated storage size is the correct action because RDS for MySQL, MariaDB, PostgreSQL, Oracle, and SQL Server supports dynamic storage scaling with minimal downtime. When you modify the allocated storage for a gp2 volume, RDS performs the modification in the background, and the instance remains available during the process, though you may experience a brief performance impact. This directly addresses the near-full storage condition without requiring a full outage.

Exam trap

The trap here is that candidates often confuse storage auto-scaling (which is a preventive measure) with the immediate need to increase storage, or they mistakenly believe that deleting data will instantly free up space on an RDS instance, ignoring the filesystem and volume-level allocation behavior.

How to eliminate wrong answers

Option B is wrong because enabling storage auto-scaling only prevents future storage exhaustion by automatically increasing storage when thresholds are met; it does not resolve the current near-full condition and may take time to trigger. Option C is wrong because deleting old data from an RDS instance does not immediately free up space on the underlying EBS volume due to the way filesystems handle deletion; the storage remains allocated and the volume may still report as full until a vacuum or reorg is performed, and this approach risks data loss without guaranteeing space recovery. Option D is wrong because converting the storage type to Provisioned IOPS (io1/io2) does not increase storage capacity; it only changes the performance characteristics and incurs additional cost without solving the space shortage.

391
MCQmedium

A SysOps administrator needs to deploy a new version of a Lambda function while minimizing downtime. The function is behind an API Gateway endpoint. What is the MOST effective approach?

A.Update the Lambda function code in-place and publish a new version
B.Create a new Lambda version, then use an alias with weighted routing to shift traffic gradually
C.Create a new Lambda version and update the API Gateway integration to point to it
D.Deploy a new Lambda function and use an Amazon Route 53 weighted record set to distribute traffic
AnswerB

This is the correct approach because it leverages Lambda's built-in alias weighting to implement a canary deployment. You first publish the updated code as a new immutable version, then configure the alias (e.g., the one referenced by API Gateway) with a weighted routing policy, sending a small percentage of traffic to the new version and gradually increasing it as confidence grows. Weighted aliases allow you to monitor error rates and latency, and instantly roll back by shifting weight back to the old version without redeploying code. Unlike the other options, this method preserves the ability to test new code with a fraction of real traffic while keeping the previous version fully available.

Why this answer

The most effective approach for zero-downtime Lambda deployment behind API Gateway is to publish a new version and use an alias with weighted routing (canary or linear). API Gateway integrates with the alias ARN, so traffic can be shifted gradually from the old version to the new one, allowing rollback if errors spike. This is the native, serverless-safe deployment pattern that minimizes downtime and risk.

Exam trap

SOA-C02 often tests the difference between DNS-level traffic shifting (Route 53) and Lambda alias-level traffic shifting, so candidates who pick Route 53 weighted records misunderstand that Lambda versions are not DNS-addressable.

How to eliminate wrong answers

Option A is wrong because updating the function code in-place (even with a new version) does not provide traffic shifting — the $LATEST or alias still points to the new code immediately, causing a hard cutover and potential downtime if the new code fails. Option C is wrong because pointing API Gateway directly to a new version creates an all-or-nothing switch with no gradual traffic shift and no easy rollback without reconfiguring the integration. Option D is wrong because Route 53 weighted records operate at the DNS layer and cannot distribute traffic between Lambda versions — Lambda is not addressed by DNS; API Gateway is the integration point, and Route 53 would only route to different API Gateway endpoints, not Lambda versions.

392
MCQmedium

An application running on Amazon EC2 instances behind an Application Load Balancer (ALB) is experiencing intermittent 5xx errors. CloudWatch metrics show that the ALB's 'HTTPCode_ELB_5XX_Count' is elevated. What is the MOST likely cause?

A.The target instances are returning HTTP 503 errors.
B.The target instances have high latency but are still responding.
C.The load balancer is timing out waiting for a response from the target.
D.Client requests are malformed and being rejected by the load balancer.
AnswerC

When a target fails to send a complete HTTP response before the load balancer's idle timeout (default 60 seconds for Application Load Balancers), the load balancer terminates the connection and returns a 504 Gateway Timeout to the client. This 504 is generated entirely by the load balancer, so it appears in the ELB 5XX error metrics, not in the target instance's metrics. A common cause is a long-running application task that exceeds the idle timeout without sending interim data.

Why this answer

When the ALB's 'HTTPCode_ELB_5XX_Count' is elevated, it indicates that the load balancer itself is generating the 5xx error, not the target. The most common cause is that the load balancer is timing out while waiting for a response from the target instances, which occurs when the target takes longer than the configured idle timeout (default 60 seconds) to respond. This results in the ALB returning a 504 Gateway Timeout error, which is counted in the ELB 5xx metric.

Exam trap

The trap here is that candidates confuse 'HTTPCode_ELB_5XX_Count' (errors generated by the load balancer) with 'HTTPCode_Target_5XX_Count' (errors generated by the target), leading them to incorrectly assume the target is returning 5xx errors when the actual issue is a load balancer timeout.

How to eliminate wrong answers

Option A is wrong because if target instances return HTTP 503 errors, those would be counted in the target group's 'HTTPCode_Target_5XX_Count' metric, not the ALB's 'HTTPCode_ELB_5XX_Count' — the ALB forwards the target's 503 response to the client without generating its own 5xx. Option B is wrong because high latency alone does not cause ELB 5xx errors unless the latency exceeds the idle timeout; if the target eventually responds, the ALB will forward the response successfully. Option D is wrong because malformed client requests are rejected by the ALB with a 400 Bad Request error, which is a 4xx error, not a 5xx error, and would be reflected in the 'HTTPCode_ELB_4XX_Count' metric.

393
MCQeasy

A SysOps administrator needs to monitor the memory utilization of an EC2 instance running a custom application. The instance is not using the default CloudWatch metrics for memory. What should the administrator do to collect memory metrics?

A.Enable detailed monitoring on the EC2 instance
B.Use AWS Trusted Advisor to check memory utilization
C.Use Amazon Inspector to monitor memory
D.Install and configure the CloudWatch agent on the instance
AnswerD

The CloudWatch agent is the correct solution because it runs directly inside the guest operating system and reads metrics from OS sources, such as /proc/meminfo on Linux or the Windows performance counters, to capture memory utilization. Once the agent is configured with a JSON config that enables the mem plugin, it publishes custom metrics like mem_used_percent to CloudWatch under the CWAgent namespace. The agent requires appropriate IAM permissions and can be installed on EC2 instances or on-premises servers via SSM or manually.

Why this answer

The default CloudWatch metrics for EC2 include CPU, disk, and network utilization, but not memory utilization. To collect custom metrics like memory usage, you must install and configure the CloudWatch agent on the instance. The agent collects memory and disk metrics from the OS and sends them to CloudWatch as custom metrics.

Exam trap

The trap here is that candidates assume 'detailed monitoring' or other AWS services like Trusted Advisor or Inspector can capture OS-level metrics, but only the CloudWatch agent can collect memory and disk metrics from inside the instance.

How to eliminate wrong answers

Option A is wrong because enabling detailed monitoring increases the frequency of default metrics (e.g., CPU, disk I/O) from 5 minutes to 1 minute, but it does not add memory metrics. Option B is wrong because AWS Trusted Advisor checks for best practices (e.g., idle instances, security groups) and does not monitor memory utilization. Option C is wrong because Amazon Inspector is a vulnerability assessment service that scans for software vulnerabilities and network exposure, not for OS-level memory metrics.

394
MCQeasy

A SysOps administrator notices that an Amazon RDS DB instance is running at 10% CPU utilization consistently. The instance has 8 vCPUs and 32 GB RAM. The application's performance is adequate. Which action will reduce costs without affecting performance?

A.Enable Multi-AZ deployment for the DB instance.
B.Change the DB instance to a smaller instance type.
C.Change the storage type from gp2 to gp3.
D.Increase the provisioned IOPS.
AnswerB

RDS instance pricing is based on the instance class and size, so choosing a smaller class directly reduces the hourly compute charge. Since CPU utilization is consistently low, a smaller instance type can meet the workload's performance requirements while still leaving headroom for spikes. This is the most straightforward and effective way to reduce database costs without sacrificing availability or storage.

Why this answer

The DB instance is over-provisioned for the current workload, as evidenced by the consistently low CPU utilization (10%) and adequate application performance. By changing to a smaller instance type, you reduce compute costs directly while maintaining sufficient capacity for the workload. This is the most straightforward cost optimization action when performance requirements are already met.

Exam trap

The trap here is that candidates may confuse cost optimization with performance improvement or high availability, leading them to select Multi-AZ or IOPS changes, which increase costs rather than reduce them.

How to eliminate wrong answers

Option A is wrong because enabling Multi-AZ deployment increases costs by provisioning a standby replica in a different Availability Zone and does not reduce costs; it improves availability and fault tolerance. Option C is wrong because changing storage type from gp2 to gp3 may reduce storage costs but does not address the over-provisioned compute resources (vCPUs and RAM) that are the primary cost driver here. Option D is wrong because increasing provisioned IOPS increases costs and is unnecessary when performance is already adequate and CPU utilization is low.

395
MCQhard

The security team requires that no S3 bucket in the account ever has public read or write ACLs enabled. They want non-compliant buckets automatically remediated within 5 minutes of detection without any manual intervention. What is the correct implementation?

A.Create an AWS Config rule for s3-bucket-public-read-prohibited; configure auto-remediation using the AWS-DisableS3BucketPublicReadWrite SSM Automation document
B.Create an EventBridge rule that matches S3 PutBucketAcl API calls and triggers a Lambda function to re-apply a private ACL
C.Enable S3 Block Public Access at the account level to prevent public ACLs from being set in the first place
D.Schedule a daily Lambda function that lists all buckets, checks ACLs, and removes public grants if found
AnswerA

Config evaluates the rule within seconds of a bucket ACL change. The auto-remediation action invokes the SSM document automatically when compliance status changes to NON_COMPLIANT. The SSM document calls PutBucketAcl to remove public grants. The entire cycle completes in 1-3 minutes under normal conditions.

Why this answer

AWS Config can evaluate S3 bucket ACLs against the `s3-bucket-public-read-prohibited` managed rule and automatically trigger an AWS Systems Manager (SSM) Automation document (`AWS-DisableS3BucketPublicReadWrite`) as a remediation action. This ensures non-compliant buckets are fixed within minutes without manual intervention, meeting the 5-minute requirement.

Exam trap

The trap here is that candidates often choose Option C (Block Public Access) thinking it prevents all public access, but it does not remediate existing non-compliant buckets, which is explicitly required by the question.

How to eliminate wrong answers

Option B is wrong because EventBridge rules matching `PutBucketAcl` API calls only trigger on new ACL changes, not on existing buckets that already have public ACLs; it also cannot detect public ACLs set via other methods (e.g., S3 console or SDK) and does not provide a 5-minute remediation guarantee for all non-compliant buckets. Option C is wrong because S3 Block Public Access at the account level prevents new public ACLs from being set but does not automatically remediate existing buckets that already have public ACLs; it also does not meet the requirement for automatic remediation within 5 minutes of detection. Option D is wrong because a daily Lambda function runs only once per day, which violates the 5-minute remediation requirement; it also relies on a custom script that may miss edge cases or fail to handle all ACL configurations.

396
MCQeasy

A SysOps administrator needs to automate the provisioning of AWS resources using infrastructure as code. The solution must track changes and allow rollbacks. Which AWS service should the administrator use?

A.AWS CloudFormation
B.AWS Config
C.AWS Service Catalog
D.AWS OpsWorks
AnswerA

AWS CloudFormation is the core Infrastructure as Code (IaC) service on AWS. You define resources declaratively in JSON or YAML templates, and CloudFormation creates and updates those resources as stacks. It automatically rolls back changes on failure, providing safe, repeatable provisioning of entire environments. This makes it the correct choice for automating provisioning.

Why this answer

AWS CloudFormation provides infrastructure as code with change tracking and rollback capabilities. Option B (AWS Config) is for compliance and auditing, not provisioning. Option C (AWS Service Catalog) is for managing approved products, not general IaC.

Option D (AWS OpsWorks) is a configuration management service, not primarily IaC.

397
MCQmedium

A web application publishes a custom metric 'FailedLoginAttempts' to Amazon CloudWatch. The SysOps administrator needs to be notified via Amazon SNS when the number of failed login attempts exceeds 100 within a 5-minute period. Which AWS service or feature should be used to create this notification?

A.Amazon CloudWatch Logs metric filter
B.Amazon CloudWatch alarm
C.Amazon CloudWatch dashboard
D.AWS Config rule
AnswerB

A CloudWatch alarm continuously evaluates a single metric against a defined threshold over a specified number of evaluation periods. When the metric crosses the threshold (for example, failedloginattempts exceeding a certain count within 5 minutes), the alarm state changes to ALARM and triggers an action such as publishing to an Amazon SNS topic, which can then send email or SMS notifications. This is the only option that directly monitors the existing custom metric and initiates a notification with built-in alerting logic.

Why this answer

An Amazon CloudWatch alarm is the correct service because it monitors a specific CloudWatch metric (such as 'FailedLoginAttempts') and triggers an action (such as sending an SNS notification) when the metric crosses a defined threshold over a specified period. In this case, the alarm evaluates whether the sum of 'FailedLoginAttempts' exceeds 100 within a 5-minute period, and upon breaching, it publishes to the SNS topic to notify the SysOps administrator.

Exam trap

The trap here is that candidates often confuse CloudWatch Logs metric filters (which extract metrics from logs) with CloudWatch alarms (which evaluate metrics and trigger actions), leading them to choose Option A even though the custom metric is already published to CloudWatch and does not require log extraction.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Logs metric filters are used to extract metric data from log events (e.g., from CloudWatch Logs), not to monitor a custom metric that is already published directly to CloudWatch; they cannot directly trigger SNS notifications without an alarm. Option C is wrong because an Amazon CloudWatch dashboard is a visualization tool for displaying metrics and alarms, not a service that evaluates metric thresholds or triggers notifications. Option D is wrong because AWS Config rules evaluate resource configurations for compliance against desired policies, not real-time metric values like failed login attempts, and they cannot directly trigger SNS notifications based on metric thresholds.

398
MCQeasy

A SysOps administrator needs to ensure that an EC2 instance can access an S3 bucket without storing AWS credentials on the instance. What should the administrator do?

A.Create a bucket policy that allows access from the instance's public IP.
B.Create an IAM role with S3 access and attach it to the instance profile.
C.Store the access key and secret key in a file on the instance.
D.Configure the security group to allow outbound traffic to S3.
AnswerB

Attaching an IAM role to the EC2 instance via an instance profile is the secure, recommended way to grant S3 permissions. The instance automatically retrieves temporary security credentials from the instance metadata service (IMDS), which are rotated automatically, eliminating the need to embed long-lived access keys. The role's permissions policy (e.g., AmazonS3ReadOnlyAccess) defines exactly what S3 actions the instance can perform, and the instance profile is the container that delivers the role to the instance.

Why this answer

The correct approach is to create an IAM role with the required S3 permissions and attach it to the EC2 instance profile, so the instance's SDK/CLI can retrieve temporary credentials from the instance metadata service (IMDS). This eliminates the need to store long-term AWS credentials on the instance and follows AWS best practices for least privilege and credential hygiene.

Exam trap

SOA-C02 often tests whether candidates know that IAM roles attached via instance profiles are the only secure way to grant EC2 access to AWS services, so options involving stored keys or IP-based policies are classic distractors.

How to eliminate wrong answers

Option A is wrong because bucket policies based on public IP are fragile (IPs change), do not authenticate the instance, and expose the bucket to anyone from that IP range. Option C is wrong because storing access keys in a file on the instance is exactly the insecure practice the question asks to avoid — keys can be exfiltrated if the instance is compromised. Option D is wrong because security groups control network reachability, not identity or authorization; allowing outbound traffic to S3 does not grant the instance permission to access the bucket.

399
MCQmedium

A company has an Amazon VPC with public and private subnets across two Availability Zones. The company hosts a web application on EC2 instances in the private subnets. The application needs to access an Amazon S3 bucket to upload and download files. The SysOps administrator must ensure that traffic to S3 does not traverse the internet and minimizes data transfer costs. Which solution should the administrator implement?

A.Create an S3 VPC Gateway Endpoint in the VPC and associate it with the route tables of the private subnets.
B.Create an S3 VPC Interface Endpoint in the VPC and associate it with the security groups of the private subnets.
C.Set up a NAT Gateway in the public subnets and add a route to the private subnets' route tables pointing to the NAT Gateway for S3 traffic.
D.Use AWS PrivateLink with an S3 endpoint service hosted in a different VPC.
AnswerA

Gateway Endpoints provide private connectivity to S3 at no additional cost (only standard data transfer rates apply). By adding a route for the S3 prefix list to the private subnet route tables, traffic destined for S3 is routed through the endpoint.

Why this answer

An S3 VPC Gateway Endpoint provides a private, cost-effective connection to S3 from within the VPC without traversing the internet. By associating the endpoint with the route tables of the private subnets, traffic destined for S3 is routed directly through AWS's internal network, avoiding data transfer costs and internet egress charges.

Exam trap

The trap here is that candidates often confuse Gateway Endpoints with Interface Endpoints, assuming both are equally suitable for S3, but Gateway Endpoints are free and optimized for S3 and DynamoDB, while Interface Endpoints incur costs and are better for other AWS services.

How to eliminate wrong answers

Option B is wrong because an S3 VPC Interface Endpoint uses AWS PrivateLink with an elastic network interface, incurring per-hour and per-GB data processing costs, which is more expensive than a Gateway Endpoint and unnecessary for S3 access. Option C is wrong because a NAT Gateway routes traffic through the internet to reach S3, incurring data transfer costs and internet egress charges, violating the requirement to avoid internet traversal. Option D is wrong because AWS PrivateLink with an S3 endpoint service hosted in a different VPC is not a standard or supported method for accessing S3; S3 Gateway Endpoints are designed for direct VPC-to-S3 connectivity without cross-VPC complexity.

400
MCQhard

A company uses AWS Global Accelerator to improve the performance of a web application hosted in multiple AWS regions. The application uses an Application Load Balancer (ALB) in each region as the endpoint. Users report that traffic is not being routed to the closest region. What could be the cause?

A.The Global Accelerator is not configured with a custom routing accelerator.
B.The ALBs are not configured to allow cross-region communication.
C.The health checks for the ALBs are failing, so traffic is diverted to other regions.
D.The endpoints are configured in the same AWS region.
AnswerC

Global Accelerator continuously performs TCP or HTTP(S) health checks against each endpoint in an endpoint group, using the configured interval, thresholds, and path. When an ALB fails these checks consecutively, it is marked unhealthy and Global Accelerator immediately excludes it from traffic routing, redistributing the load to other healthy endpoint groups, often in different regions. This is exactly the behavior described in the scenario, so the failing health checks are the root cause of the traffic being diverted.

Why this answer

Global Accelerator uses health checks to determine endpoint availability. If the health checks for an ALB in a user's closest region are failing, Global Accelerator will consider that endpoint unhealthy and route traffic to the next closest healthy region. This causes users to be directed to a region farther away, even though a closer region exists.

Exam trap

The trap here is that candidates often overlook the impact of health checks on routing decisions and assume the issue is a misconfiguration of the accelerator or endpoints, rather than a failure in endpoint health monitoring.

How to eliminate wrong answers

Option A is wrong because custom routing accelerators are used for specific use cases like gaming or VoIP where you need to control traffic routing per client, not for standard HTTP/HTTPS traffic to ALBs; the default routing accelerator is appropriate here. Option B is wrong because ALBs do not need cross-region communication for Global Accelerator to route traffic to the closest region; Global Accelerator itself handles cross-region routing independently of ALB configuration. Option D is wrong because if all endpoints were in the same region, traffic would still be routed to that region, not to a different one, and the reported issue is traffic not going to the closest region, which implies multiple regions are configured.

401
MCQhard

A company is running a stateful web application on EC2 instances in an Auto Scaling group. The application requires low latency and high throughput. Currently, the application is experiencing performance degradation during peak hours. Which scaling strategy should the SysOps administrator implement to improve performance and optimize cost?

A.Step scaling policy based on memory utilization
B.Scheduled scaling with fixed times
C.Simple scaling policy based on CPU utilization
D.Predictive scaling policy
AnswerD

A predictive scaling policy uses machine learning to analyze historical traffic patterns and forecast future demand, allowing Auto Scaling to launch instances ahead of the actual spike. This proactive approach is ideal for a stateful web application because it eliminates the cold start lag and reduces the risk of insufficient capacity during sudden bursts. It also improves cost efficiency by avoiding over-provisioning, and when combined with a dynamic scaling policy, it can handle both anticipated trends and unexpected deviations. The key is that predictive scaling learns from recurring patterns (daily, weekly, or monthly) and smooths out the capacity curve before the load actually arrives.

Why this answer

Predictive scaling is the correct choice because it uses machine learning to analyze historical traffic patterns and proactively adjust capacity before demand spikes, which is ideal for a stateful web application experiencing predictable peak-hour performance degradation. This approach ensures low latency and high throughput by pre-warming instances, while optimizing cost by avoiding over-provisioning during off-peak periods.

Exam trap

The trap here is that candidates often choose scheduled scaling (Option B) because they see 'peak hours' and assume a fixed schedule, but they miss that predictive scaling uses ML to handle variable peak patterns more efficiently than rigid schedules.

How to eliminate wrong answers

Option A is wrong because memory utilization is not a reliable metric for scaling a stateful web application that requires low latency and high throughput; step scaling based on memory would react to memory pressure rather than the actual workload demand, potentially causing delayed scaling and performance issues. Option B is wrong because scheduled scaling with fixed times assumes perfectly predictable traffic patterns and cannot adapt to variations in peak-hour load, leading to either under-provisioning or over-provisioning and wasted cost. Option C is wrong because simple scaling policies based on CPU utilization have a cooldown period that prevents rapid scaling, causing slow response to sudden traffic spikes and degrading performance during peak hours.

402
MCQeasy

Refer to the exhibit. An IAM role has the trust policy shown. Which entity can assume this role?

A.Only the IAM user with the ARN arn:aws:iam::123456789012:user/Admin
B.Any IAM user in any AWS account
C.Any IAM user in the AWS account 123456789012
D.Only users who have MFA enabled
AnswerC

Because the Principal value is arn:aws:iam::123456789012:root, AWS treats it as the account root principal, which in a trust policy effectively acts as a wildcard for all IAM users (and roles) within that account. The trust policy does not restrict the source identity to a hyper-specific user ARN or to a particular MFA state. Each IAM user still needs an identity-based policy permitting the sts:AssumeRole action, but the trust relationship is open to every user in the account.

Why this answer

The trust policy specifies `"AWS": "arn:aws:iam::123456789012:root"` as the principal, which allows any IAM user or role within the AWS account 123456789012 to assume the role, provided they have the necessary permissions in their own identity-based policies. This is because the root ARN of an account acts as a wildcard for all identities in that account. Option C correctly identifies that any IAM user in that account can assume the role.

Exam trap

The trap here is that candidates often confuse the account root ARN with a specific user ARN, thinking it only allows the root user, when in fact it allows any identity in the account to assume the role.

How to eliminate wrong answers

Option A is wrong because the trust policy does not restrict the principal to a specific IAM user ARN; it uses the account root ARN, which allows all identities in the account, not just the Admin user. Option B is wrong because the trust policy explicitly limits the principal to account 123456789012, so users from other AWS accounts cannot assume the role unless a cross-account trust is configured. Option D is wrong because the trust policy does not include a condition for MFA (e.g., `"aws:MultiFactorAuthPresent": "true"`), so MFA is not required to assume the role.

403
Multi-Selecthard

A company uses AWS CloudTrail to log API activity. The security team wants to be alerted when an IAM user creates a new access key. Which THREE steps should the SysOps administrator take to meet this requirement?

Select 3 answers
A.Configure the CloudTrail trail to deliver logs directly to an SNS topic.
B.Configure the Lambda function to publish a custom metric to CloudWatch.
C.Set a CloudWatch alarm on the custom metric to send an Amazon SNS notification when the metric exceeds a threshold.
D.Create a CloudWatch Logs subscription filter that sends matching log events to an AWS Lambda function.
E.Create an Amazon EventBridge rule that matches the CreateAccessKey event and triggers an SNS notification.
AnswersB, C, D

The Lambda function that receives the CloudWatch Logs subscription filter must parse the base64 gzip-compressed log data, extract only the CreateAccessKey events, and call PutMetricData to publish a custom CloudWatch metric (e.g., IAMAccessKeyCreatedCount) in a custom namespace. Publishing a custom metric is essential because CloudTrail log entries are not natively represented as CloudWatch metrics, so you need this transformation to enable threshold-based alarm evaluation. The metric count can be incremented for each matching event, allowing the later CloudWatch alarm to compare against a threshold. Without this step, there is no numeric time-series data on which to set an alarm.

Why this answer

The Lambda function processes CloudWatch Logs subscription filter events and publishes a custom metric to CloudWatch. This custom metric can then trigger a CloudWatch alarm (Option C) to send an SNS notification, meeting the requirement. The combination of a CloudWatch Logs subscription filter (Option D) with a Lambda function is the standard pattern for real-time log-based alerting when CloudTrail logs are delivered to CloudWatch Logs.

Exam trap

The trap here is that candidates might think CloudTrail can directly send logs to SNS (Option A) or that a single EventBridge rule (Option E) is sufficient, but the exam expects the multi-step CloudWatch Logs subscription filter + Lambda + custom metric + alarm pipeline as the correct three-step solution.

404
MCQeasy

A company is using Amazon CloudFront to deliver content globally. Which feature can help reduce costs by minimizing data transfer from the origin?

A.Enable multiple origins for load balancing.
B.Configure caching to serve content from edge locations.
C.Configure custom SSL certificates.
D.Use Lambda@Edge to process requests.
AnswerB

CloudFront serves cached objects directly from edge locations that are geographically closer to viewers, so repeat requests for the same content are satisfied without contacting the origin server. This reduces the number of origin fetches and, consequently, the data transfer out of your origin, which is often the largest variable cost. Setting appropriate TTLs and cache policies (including honoring Cache-Control headers) maximizes cache hits and minimizes origin bandwidth usage.

Why this answer

Configuring caching in CloudFront allows content to be served from edge locations, reducing the number of requests that need to go to the origin. This minimizes data transfer from the origin and lowers costs. Option A is incorrect because multiple origins are for routing different content, not for reducing origin transfer; load balancing doesn't inherently reduce data transfer costs.

Option C is incorrect because custom SSL certificates secure connections but do not affect data transfer costs. Option D is incorrect because Lambda@Edge runs custom code at edge locations but does not directly reduce the volume of data transferred from the origin; it may even add compute costs.

405
MCQmedium

A SysOps administrator is tasked with automating the creation of IAM roles and policies using AWS CloudFormation. The template includes an IAM role and a managed policy. The stack creation fails with the error 'Policy arn:aws:iam::123456789012:policy/MyManagedPolicy not found'. The policy is created in the same template. What is the MOST likely solution?

A.Add a 'DependsOn' clause to the IAM role resource for the managed policy, and reference the policy ARN using the 'Ref' intrinsic function.
B.Remove the policy document from the template and create the policy separately.
C.Use a custom resource to create the policy before the role.
D.Create the IAM role in a separate stack.
AnswerA

In CloudFormation, a DependsOn attribute forces the IAM role resource to wait for the managed policy resource to be fully created before proceeding. The Ref intrinsic function on an IAM managed policy returns its ARN by default, so you can directly pass that ARN into the role's ManagedPolicyArns property. Without DependsOn, CloudFormation may attempt to attach the policy before it exists, causing the 'policy not found' error. This native dependency declaration is the simplest, most reliable fix.

Why this answer

The error occurs because CloudFormation attempts to create the IAM role before the managed policy is fully created, even though both are defined in the same template. Adding a 'DependsOn' clause to the IAM role resource ensures that CloudFormation waits for the managed policy to be created first. Using the 'Ref' intrinsic function to reference the policy ARN is correct because 'Ref' for an AWS::IAM::ManagedPolicy returns the policy ARN, which is needed for the role's 'ManagedPolicyArns' property.

Exam trap

The trap here is that candidates assume CloudFormation automatically detects all dependencies based on resource references, but it only does so for direct 'Ref' or 'Fn::GetAtt' calls, not for ARN strings passed as parameters or hardcoded values, leading to a race condition where the role is created before the policy.

How to eliminate wrong answers

Option B is wrong because creating the policy separately defeats the purpose of automation and does not resolve the dependency issue within the single template; it introduces manual steps and increases management overhead. Option C is wrong because using a custom resource is unnecessary and overly complex when a simple 'DependsOn' clause can resolve the dependency; custom resources are typically used for operations not natively supported by CloudFormation. Option D is wrong because creating the IAM role in a separate stack does not fix the dependency issue; it only shifts the problem to cross-stack references, which still require careful ordering and may introduce additional complexity.

406
MCQhard

A SysOps administrator is troubleshooting a slow web application running on EC2 instances behind an ALB. The application uses an RDS MySQL database. The administrator checks CloudWatch metrics and sees that the ALB's latency is high, the RDS CPU is high, and the EC2 CPU is moderate. The application team reports that the database queries are slow. The administrator suspects that the database is the bottleneck. However, the RDS instance is already a db.r5.large and the administrator wants to avoid increasing instance size due to cost. What should the administrator do to improve performance without increasing instance size?

A.Increase the number of EC2 instances to reduce the load on the database.
B.Add an ElastiCache Redis cluster to cache database queries.
C.Create a Read Replica and offload read traffic to it.
D.Enable Performance Insights on the RDS instance to identify slow queries.
AnswerD

RDS Performance Insights provides a real-time and historical dashboard that visualizes database load in terms of wait events and the top SQL statements causing that load. It enables the sysops administrator to identify exactly which queries are slow, whether they suffer from missing indexes, bad execution plans, or resource contention, and then take targeted optimization actions. This is the appropriate first step in troubleshooting a slow database-backed application.

Why this answer

Enabling Performance Insights on the RDS instance allows the administrator to identify the specific slow queries causing the bottleneck. This diagnostic tool provides a database load analysis, showing which queries consume the most resources, enabling targeted optimization (e.g., adding indexes or rewriting queries) without increasing instance size. Since the EC2 CPU is moderate and the ALB latency is high due to slow database queries, resolving the query performance directly addresses the root cause.

Exam trap

The trap here is that candidates often assume scaling out (more EC2 instances) or adding caching/read replicas will solve a database performance issue, when the real problem is unoptimized queries that need to be identified and fixed first.

How to eliminate wrong answers

Option A is wrong because increasing the number of EC2 instances would not reduce the load on the database; it would increase the number of concurrent connections and queries, potentially worsening the database bottleneck. Option B is wrong because adding an ElastiCache Redis cluster caches only specific query results and requires application-level changes to implement caching logic; it does not fix the underlying slow queries that are already identified as the issue. Option C is wrong because creating a Read Replica offloads read traffic but does not improve the performance of the existing slow queries; the replica would execute the same slow queries, and the primary instance would still be impacted by write operations or unoptimized queries.

407
MCQeasy

A SysOps administrator needs to ensure that an Amazon RDS instance is encrypted at rest. The instance is already provisioned unencrypted. What is the correct approach to enable encryption?

A.Create a snapshot of the instance and restore it with encryption enabled
B.Use AWS KMS to encrypt the underlying EBS volumes of the RDS instance
C.Enable encryption using the AWS CLI command modify-db-instance
D.Modify the RDS instance and enable encryption in the configuration
AnswerA

The only supported way to add encryption to an existing Amazon RDS instance is to create a manual snapshot, copy that snapshot with a KMS customer master key (encryption enabled), and then restore a new DB instance from the encrypted copy. Encryption is a creation-time attribute, so this snapshot-and-restore workflow effectively rebuilds the database with at-rest encryption while preserving your data and configuration.

Why this answer

RDS does not allow enabling encryption in place on an existing unencrypted instance. The supported path is to snapshot the instance, then restore that snapshot with encryption enabled, which produces a new encrypted instance. You then repoint applications to the new endpoint.

Exam trap

SOA-C02 often tests the misconception that modify-db-instance can enable encryption — candidates must remember RDS encryption is immutable after creation and requires snapshot-restore.

How to eliminate wrong answers

Option B is wrong because you cannot directly encrypt the underlying EBS volumes of an RDS instance — RDS manages storage and does not expose EBS volume encryption toggles. Option C is wrong because modify-db-instance has no parameter to enable encryption on an existing instance; encryption can only be set at creation or restore. Option D is wrong because the RDS modify operation does not offer an encryption toggle for existing instances.

408
MCQhard

A SysOps administrator is automating the creation of Amazon RDS DB instances using AWS CloudFormation. The template includes a DB instance with a Multi-AZ deployment. During a stack update, the administrator changes the DB instance class from db.t3.small to db.t3.medium. What is the expected behavior during the update?

A.RDS will create a new DB instance with the new class and delete the old one.
B.RDS will modify both instances simultaneously, causing a brief outage.
C.The update will fail because CloudFormation cannot modify a Multi-AZ DB instance class.
D.RDS will modify the standby instance first, then fail over to it, and finally modify the original primary, resulting in minimal downtime.
AnswerD

This is exactly how RDS handles instance-class changes for Multi-AZ DB instances. Because the primary and standby run in different Availability Zones, RDS first applies the new class to the standby while the primary continues to serve traffic. It then performs a failover—typically causing a short DNS/connection disruption of a few seconds—to promote the upgraded instance to primary, and finally applies the new class to the original primary, which is now the standby. This rolling pattern keeps downtime to a minimum and is the documented behavior for class modifications on Multi-AZ deployments.

Why this answer

When updating a Multi-AZ RDS DB instance class via CloudFormation, AWS performs a 'rolling upgrade' to minimize downtime. RDS first modifies the standby instance to the new class, then initiates a failover to make the standby the new primary, and finally modifies the original primary (now the standby) to the new class. This results in only a brief outage during the failover, typically lasting 60–120 seconds.

Exam trap

The trap here is that candidates assume any modification to a Multi-AZ instance causes a full replacement or simultaneous outage, but AWS specifically designed the Multi-AZ update process to minimize downtime by modifying the standby first and then failing over.

How to eliminate wrong answers

Option A is wrong because RDS does not create a new instance and delete the old one for a class modification; that would cause a full replacement with longer downtime. Option B is wrong because RDS does not modify both instances simultaneously; modifying both at once would cause a longer outage or data inconsistency. Option C is wrong because CloudFormation can modify a Multi-AZ DB instance class; the update does not fail, and AWS supports this operation with minimal downtime.

409
MCQmedium

A company runs a web application on Amazon EC2 instances in private subnets across multiple Availability Zones. The instances need to download software patches from the internet. The SysOps administrator requires a highly available, fully managed solution for outbound internet connectivity. Which solution should be implemented?

A.Deploy a NAT gateway in each Availability Zone and update the route tables for each private subnet to point to the NAT gateway in the same Availability Zone.
B.Attach an Internet Gateway to the VPC and add a default route (0.0.0.0/0) to the Internet Gateway in the private subnet route tables.
C.Create a VPC endpoint for Amazon S3 and route traffic through it.
D.Set up an AWS Direct Connect connection and route all internet-bound traffic through it.
AnswerA

Deploying a NAT gateway in each Availability Zone and updating the private subnet route tables to point to the local NAT gateway is the correct pattern for highly available outbound internet access. Each NAT gateway is itself a managed, redundant resource within an AZ, and by pairing it with the private subnets in that same AZ, traffic from instances in one AZ keeps working even if another AZ fails. Crucially, NAT gateways are not a single point of failure, unlike a single NAT instance, and they automatically receive a public IP and can route traffic to the internet without requiring the private instances to have public IPs. This design satisfies both the availability requirement and the need for private instances to reach the internet for patch downloads.

Why this answer

A NAT gateway in each Availability Zone provides highly available outbound internet connectivity for instances in private subnets. By placing a NAT gateway in each AZ and routing private subnet traffic to the NAT gateway in the same AZ, you eliminate a single point of failure and ensure that internet-bound traffic remains within the same AZ for low latency and fault tolerance. This is a fully managed AWS service that handles scaling and failover automatically.

Exam trap

The trap here is that candidates often confuse NAT gateways with Internet Gateways, thinking that a single NAT gateway in one AZ provides high availability, but the correct design requires a NAT gateway in each AZ to avoid cross-AZ data transfer costs and single points of failure.

How to eliminate wrong answers

Option B is wrong because attaching an Internet Gateway to the VPC and adding a default route to it in private subnet route tables would allow direct outbound traffic from private instances, but private subnets do not have a route to the Internet Gateway by design; instances in private subnets cannot reach the Internet Gateway directly without a NAT device or a transit gateway. Option C is wrong because a VPC endpoint for Amazon S3 only provides private connectivity to S3, not general internet access for downloading software patches from arbitrary internet hosts. Option D is wrong because AWS Direct Connect is a dedicated private connection to AWS, not a solution for outbound internet connectivity; it does not provide a route to the public internet unless combined with a NAT device or a virtual private gateway with internet access.

410
MCQhard

A company is using AWS Organizations with multiple accounts. The security team wants to ensure that all new S3 buckets created in any account have encryption enabled. Which approach should be used to enforce this policy?

A.Create a service control policy (SCP) that denies the s3:CreateBucket action unless the request includes the x-amz-server-side-encryption header with a valid encryption algorithm.
B.Create an IAM role in each member account with a policy that denies s3:CreateBucket without encryption, and require all users to assume that role.
C.Use AWS Config managed rule 's3-bucket-server-side-encryption-enabled' to detect non-compliant buckets and automatically remediate.
D.Enable AWS CloudTrail and create a CloudWatch Events rule that triggers a Lambda function to delete any bucket created without encryption.
AnswerA

A service control policy (SCP) attached at the organization or organizational unit level can deny the s3:CreateBucket action unless the request includes an x-amz-server-side-encryption header, using the s3:x-amz-server-side-encryption condition key. Because SCPs apply to every IAM principal in the account—including the root user—they provide a central, preventive guardrail that blocks the API call entirely, rather than merely auditing or remediating after the fact.

Why this answer

Service Control Policies (SCPs) in AWS Organizations allow central governance to deny actions across all accounts. An SCP can deny the s3:CreateBucket action unless the request includes the server-side-encryption header, thus enforcing encryption on new buckets. Option B is incorrect because IAM roles per account lack centralized enforcement and cannot prevent users with their own permissions from creating buckets without encryption.

Option C is incorrect because AWS Config rules are detective, not preventive; they can only detect and optionally remediate after the bucket is created, not block the creation. Option D is incorrect because using CloudTrail and CloudWatch Events with a Lambda function is a reactive approach—it can delete a non-compliant bucket after creation, but does not enforce encryption at the time of creation. The requirement is to enforce the policy, making a preventive SCP the correct solution.

411
MCQeasy

A SysOps administrator is troubleshooting an Amazon RDS for MySQL instance that is experiencing high CPU utilization. The administrator wants to identify the specific queries consuming the most CPU. What is the MOST efficient way to achieve this?

A.Use CloudWatch metrics for RDS and create a dashboard for CPU utilization.
B.Enable Performance Insights for the RDS instance and view the top SQL queries.
C.Enable Enhanced Monitoring for the RDS instance and view the CPU metrics.
D.Enable CloudWatch Logs for the RDS instance and filter for slow query logs.
AnswerB

Performance Insights is the correct choice because it presents a visual database load graph broken down by wait states and, crucially, shows the top SQL queries ranked by their contribution to total load, including CPU time. You can drill down into any time window to identify exactly which query is driving high CPU, directly pinpointing the problematic statement for optimization.

Why this answer

Performance Insights provides a built-in database load visualization and a dashboard that directly shows the top SQL queries consuming the most resources, including CPU. This is the most efficient method because it requires no additional configuration beyond enabling the feature and immediately surfaces the specific queries causing high CPU utilization.

Exam trap

The trap here is confusing Enhanced Monitoring (OS-level metrics) with Performance Insights (database-level query analysis), leading candidates to choose Enhanced Monitoring when it cannot identify specific queries.

How to eliminate wrong answers

Option A is wrong because CloudWatch metrics for RDS show aggregate CPU utilization but do not identify which specific queries are consuming the CPU. Option C is wrong because Enhanced Monitoring provides OS-level metrics (e.g., CPU, memory, disk I/O) but does not correlate those metrics to individual SQL queries. Option D is wrong because enabling CloudWatch Logs for slow query logs only captures queries that exceed a defined execution time threshold, not necessarily the queries consuming the most CPU, and it requires additional parsing to identify top CPU consumers.

412
MCQmedium

A company runs a web application on Amazon EC2 instances in an Auto Scaling group that spans two Availability Zones. The application uses an Application Load Balancer (ALB) that is deployed across the same Availability Zones. The SysOps administrator wants to ensure the application remains available if an entire Availability Zone fails. Which configuration is essential for this high availability?

A.Configure the Auto Scaling group with at least one instance in each Availability Zone.
B.Enable cross-zone load balancing on the Application Load Balancer.
C.Use an Amazon Route 53 health check to route traffic away from a failed AZ.
D.Attach an Elastic IP address to each instance in the Auto Scaling group to ensure IP persistence.
AnswerA

Configuring the Auto Scaling group to maintain at least one instance in each Availability Zone (AZ) ensures that if an entire AZ becomes unavailable, the remaining AZs still have healthy instances to serve traffic. Auto Scaling also performs AZ rebalancing, which automatically detects when one AZ has fewer instances and launches replacements in that AZ to maintain a balanced distribution. This is the fundamental mechanism for achieving fault tolerance at the AZ level within a single region, which is exactly what the requirement demands.

Why this answer

For high availability across an Availability Zone (AZ) failure, the Auto Scaling group must have at least one healthy instance in each AZ. This ensures that if one AZ becomes unavailable, the ALB can route traffic to instances in the remaining AZ. Without this minimum distribution, a single AZ failure could leave the application with zero healthy targets if all instances were in the failed AZ.

Exam trap

The trap here is that candidates often confuse cross-zone load balancing (which balances traffic) with instance distribution across AZs (which ensures survival), leading them to select Option B instead of recognizing that without instances in each AZ, no load balancing can save the application.

How to eliminate wrong answers

Option B is wrong because cross-zone load balancing distributes traffic evenly across all registered instances in all AZs, but it does not protect against an entire AZ failure—it only balances load, not ensures instance survival. Option C is wrong because Route 53 health checks can route traffic away from a failed AZ at the DNS level, but they do not guarantee that instances exist in the surviving AZ; the Auto Scaling group must already have instances there. Option D is wrong because Elastic IP addresses are not used with Auto Scaling groups (which use dynamic scaling and replacement) and do not provide high availability; they are static IPs for individual instances, not for AZ failure resilience.

413
MCQhard

A company has an S3 bucket that stores millions of small objects (1-10 KB) and uses S3 Standard storage. The bucket receives frequent PUT requests and occasional GET requests. The monthly bill shows high costs for S3 PUT requests. Which action would reduce costs?

A.Move the objects to S3 Glacier Deep Archive to reduce storage cost.
B.Aggregate small objects into larger files (e.g., 1 MB) before uploading to S3.
C.Move the objects to S3 Intelligent-Tiering to optimize storage costs.
D.Use S3 Lifecycle policies to transition objects to S3 Standard-IA after 30 days.
AnswerB

Batching the small objects into larger files, such as 1 MiB objects, directly attacks the root cause because S3 bills every PUT request individually regardless of object size. One million 1 KB PUTs cost the same per-request as one million 1 MB PUTs, so consolidating 1,000 small objects into a single object reduces the number of PUT requests by 99.9%. This is the intended way to reduce per-request charges while retaining the same logical data, and it also lowers the overhead of managing millions of keys.

Why this answer

S3 PUT request charges are per-request, so uploading millions of tiny objects incurs millions of PUT charges. Aggregating small objects into larger files (e.g., 1 MB) before upload dramatically reduces the number of PUT requests and therefore the request cost. This directly targets the line item the bill shows as high.

Exam trap

The trap is assuming storage-class changes reduce request costs; candidates must isolate that the bill's high line item is PUT requests, which only aggregation (fewer requests) addresses.

How to eliminate wrong answers

Option A is wrong because Glacier Deep Archive reduces storage cost, not PUT request cost, and retrieval is expensive and slow; it does not address the frequent PUT pattern. Option C is wrong because Intelligent-Tiering optimizes storage class based on access patterns but still charges per PUT and adds monitoring/automation fees, so it does not reduce request costs. Option D is wrong because lifecycle transition to Standard-IA reduces storage cost after 30 days but does not reduce the PUT request charges incurred at upload time.

414
MCQmedium

A company uses AWS CloudTrail to log API activity. The SysOps administrator needs to receive an email notification whenever a new IAM user is created. Which AWS services should be used together to meet this requirement with the least operational overhead?

A.CloudTrail, Amazon SNS, and AWS Lambda
B.CloudTrail, Amazon CloudWatch Logs, and a metric filter with an alarm
C.CloudTrail, Amazon EventBridge, and Amazon SNS
D.AWS Config and Amazon SNS
AnswerC

Amazon EventBridge natively consumes CloudTrail management events, allowing you to create a rule that matches the `CreateUser` event and directly targets an SNS topic. Because EventBridge performs the filtering and delivers to SNS without any custom code, this is the simplest and most efficient serverless solution. The SNS topic then sends an email notification to the subscribed administrator immediately when the API call occurs.

Why this answer

Amazon EventBridge can directly capture CloudTrail API events (such as CreateUser) and route them to an SNS topic for email notification without needing any custom code or additional infrastructure. This pattern minimizes operational overhead by using a fully managed event bus with built-in filtering and target routing, eliminating the need for Lambda functions or metric filter configurations.

Exam trap

The trap here is that candidates often overcomplicate the solution by adding Lambda or CloudWatch Logs, not realizing that EventBridge provides a direct, serverless integration between CloudTrail and SNS for real-time event-driven notifications.

How to eliminate wrong answers

Option A is wrong because while CloudTrail and SNS are used, adding AWS Lambda introduces unnecessary custom code and operational overhead when EventBridge can directly invoke SNS without a Lambda intermediary. Option B is wrong because using CloudWatch Logs with a metric filter and alarm requires sending CloudTrail logs to CloudWatch Logs, creating a metric filter, and setting an alarm — this adds complexity and latency compared to EventBridge's real-time event routing. Option D is wrong because AWS Config tracks resource configuration changes, not API-level events like IAM user creation; it would require additional rules and custom remediation to trigger SNS, making it less direct and more overhead than EventBridge.

415
Multi-Selectmedium

A SysOps administrator is automating the creation of an Amazon ECS cluster with Fargate launch type using AWS CloudFormation. The template must define the task definition, service, and cluster. Which THREE resources are required to be in the template? (Choose THREE.)

Select 3 answers
A.AWS::EC2::VPC
B.AWS::ECS::TaskDefinition
C.AWS::ECS::Service
D.AWS::ECS::Cluster
E.AWS::ElasticLoadBalancingV2::LoadBalancer
AnswersB, C, D

A task definition is the core configuration document that ECS uses to launch containers. It specifies the Docker image, CPU and memory limits, port mappings, environment variables, logging configuration, and IAM roles. Without a task definition, ECS cannot start a container, making it the fundamental resource required for any ECS deployment.

Why this answer

For an Amazon ECS cluster using the Fargate launch type, the AWS CloudFormation template must define the cluster itself (AWS::ECS::Cluster), the task definition (AWS::ECS::TaskDefinition) that specifies the container image, CPU, memory, and networking configuration, and the service (AWS::ECS::Service) that maintains the desired count of tasks and optionally integrates with a load balancer. These three resources are the minimum required to create and run a Fargate-based ECS workload.

Exam trap

The trap here is that candidates often assume a VPC or load balancer is mandatory for ECS Fargate, but the exam tests that only the cluster, task definition, and service are strictly required, while networking resources can be supplied externally.

416
Multi-Selecthard

Which THREE components are required to set up a site-to-site VPN connection between an on-premises network and an AWS VPC? (Choose three.)

Select 3 answers
A.Virtual private gateway
B.Internet gateway
C.VPN connection
D.Customer gateway
E.Direct Connect virtual interface
AnswersA, C, D

The virtual private gateway is the AWS-side VPN concentrator attached to the VPC; it terminates the two IPSec tunnels from the customer gateway. Without it, no site-to-site VPN endpoint exists on the AWS side, so the connection cannot be established.

Why this answer

A site-to-site VPN between on-premises and AWS requires a virtual private gateway (A), which is the AWS-side VPN concentrator attached to the VPC and terminating the IPSec tunnels; a customer gateway (D), which is the AWS resource representing the on-premises VPN device (its public IP and BGP ASN) that terminates the other end of the tunnels; and a VPN connection (C), which is the actual IPSec tunnel resource linking the virtual private gateway to the customer gateway and carrying traffic between the two networks. An internet gateway (B) is not required for this design because it provides internet access for public subnets, not the encrypted VPN termination, and a Direct Connect virtual interface (E) belongs to AWS Direct Connect private/public transit VIFs, which are a separate dedicated-connection service rather than an IPSec site-to-site VPN component.

Exam trap

The trap here is that candidates confuse an internet gateway with a virtual private gateway, thinking any gateway can serve as a VPN endpoint, but only the VGW supports IPsec termination and route propagation for site-to-site VPNs.

417
MCQmedium

A company stores database credentials in AWS Secrets Manager. The security policy requires that the credentials be rotated automatically every 30 days. Which action should the SysOps administrator take to enforce this requirement?

A.Configure an AWS Lambda function to rotate the secret and set a CloudWatch Events rule to trigger it every 30 days.
B.Enable automatic rotation in the Secrets Manager console and specify a rotation interval of 30 days using a Lambda rotation function.
C.Use AWS Systems Manager Parameter Store to store the credentials and configure a State Manager association for rotation.
D.Create an IAM policy that forces users to rotate the secret manually every 30 days.
AnswerB

Enabling automatic rotation in Secrets Manager is the native solution: you configure the secret's rotation configuration to invoke a dedicated Lambda function (the 'rotation function') that creates new secret versions and updates the resource or database password. Secrets Manager then runs that Lambda on a schedule, and specifying a rotation interval of 30 days gives you exactly the required cadence without building your own scheduler. This approach also integrates with IAM and CloudTrail for permission enforcement and auditability, so the rotation cycle is fully managed rather than custom-coded.

Why this answer

AWS Secrets Manager natively supports automatic rotation using a Lambda function. By enabling automatic rotation in the console and specifying a 30-day interval, the administrator meets the security policy without manual intervention. Secrets Manager handles the rotation schedule and invokes the Lambda function automatically.

Exam trap

The trap here is that candidates may think any automated scheduling (like CloudWatch Events) is sufficient, but AWS Secrets Manager's native rotation feature is the correct and simplest way to enforce automatic rotation without custom infrastructure.

How to eliminate wrong answers

Option A is wrong because while a Lambda function and CloudWatch Events rule could rotate the secret, this approach bypasses Secrets Manager's built-in rotation mechanism and requires custom scheduling logic, making it less reliable and harder to maintain. Option C is wrong because AWS Systems Manager Parameter Store does not support automatic rotation of secrets; it is designed for configuration management, not secret rotation. Option D is wrong because creating an IAM policy that forces manual rotation does not enforce automated rotation and relies on user compliance, which violates the requirement for automatic rotation every 30 days.

418
MCQmedium

A SysOps administrator uses AWS CloudFormation to deploy a stack that includes an Amazon EC2 instance. The administrator wants to ensure that if the stack is updated, the EC2 instance is not accidentally replaced if its properties change. The administrator wants the stack update to fail when a property change would require replacement. Which CloudFormation feature should the administrator use?

A.CreationPolicy
B.DeletionPolicy
C.StackPolicy
D.UpdateReplacePolicy
AnswerC

StackPolicy allows you to define update permissions for stack resources, including denying update actions that would cause replacement, effectively causing the update to fail if such changes are attempted. This meets the requirement.

Why this answer

StackPolicy, is correct because a stack policy is a JSON document that defines which stack resources can be updated or replaced during a stack update. By setting a Deny effect on update actions for the EC2 instance, the administrator can prevent any property change that would cause replacement, causing the update to fail instead of replacing the instance. This directly meets the requirement to block accidental replacement.

Exam trap

The trap here is that candidates often confuse UpdateReplacePolicy (which manages what happens to the old resource after replacement) with a mechanism to prevent replacement, but UpdateReplacePolicy does not block the update—it only controls the disposition of the replaced resource.

How to eliminate wrong answers

Option A is wrong because a CreationPolicy is used to wait for signals (e.g., from cfn-signal) before declaring the resource creation complete; it does not control update behavior or prevent replacement. Option B is wrong because a DeletionPolicy defines what happens to a resource when the stack is deleted (e.g., retain, snapshot, delete), not during an update. Option D is wrong because an UpdateReplacePolicy controls the behavior of a resource when it is replaced during an update (e.g., retain the old resource), but it does not prevent the update from occurring or failing; it only dictates what happens to the replaced resource.

419
MCQmedium

A company runs a stateful web application on a single EC2 instance. To improve reliability, the company wants to implement a highly available architecture. What should the SysOps administrator do?

A.Refactor the application to store session state externally (e.g., ElastiCache), then deploy it across multiple AZs with an Application Load Balancer.
B.Migrate the application to a larger instance type.
C.Create a standby EC2 instance and use an Elastic IP to fail over manually.
D.Use Route 53 health checks to route traffic to a secondary instance if the primary fails.
AnswerA

Externalizing session state to a service like ElastiCache decouples user sessions from individual EC2 instances, making the web tier stateless. With an Application Load Balancer distributing traffic across multiple instances in different Availability Zones, the application survives instance or even AZ failures without manual intervention. The ALB's health checks automatically route around unhealthy targets, and the stateless design allows you to scale out or replace instances without losing any in-flight user session data.

Why this answer

It addresses the core challenge of making a stateful web application highly available. By storing session state externally in ElastiCache, the application becomes stateless from a networking perspective, allowing any EC2 instance to handle any request. Deploying these instances across multiple Availability Zones (AZs) behind an Application Load Balancer (ALB) provides fault tolerance and automatic traffic distribution, eliminating the single point of failure.

Exam trap

The trap here is that candidates often assume that simply adding a second instance or using DNS failover (Route 53) is sufficient for high availability, overlooking the critical requirement to externalize session state for stateful applications.

How to eliminate wrong answers

Option B is wrong because scaling vertically to a larger instance type does not eliminate the single point of failure; if the instance or its AZ fails, the application still goes down. Option C is wrong because manual failover using an Elastic IP is not automated and introduces significant downtime; it also does not handle session state persistence, so users would lose their sessions during failover. Option D is wrong because Route 53 health checks alone cannot provide seamless failover for a stateful application; they operate at the DNS level with TTL delays (often 60 seconds or more), and without external session storage, user sessions would be lost when traffic shifts to a secondary instance.

420
MCQmedium

Refer to the exhibit. A SysOps administrator runs the commands shown. Which key(s) have automatic key rotation enabled?

A.Only the first key
B.Only the second key
C.Neither key
D.Both keys
AnswerA

The first key is the only one that meets the rotation requirement because its KeyRotationEnabled value is true. AWS KMS automatic rotation is enabled on this customer-managed key, meaning AWS replaces the backing key every year. The second key's status is false, so only the first key qualifies.

Why this answer

The first key has automatic key rotation enabled because the `EnableKeyRotation` API call was made specifically for that key (key ID `1234abcd-12ab-34cd-56ef-1234567890ab`). AWS KMS automatic key rotation is a per-key setting that must be explicitly enabled; it is not enabled by default. The second key (key ID `0987dcba-09fe-87dc-65ba-0987654321fe`) was not subjected to any rotation-enabling command, so it retains the default disabled state.

Exam trap

The trap here is that candidates assume automatic key rotation is enabled by default for all KMS keys, but in reality it must be explicitly enabled per key, and the CLI output shows only the first key received the enabling command.

How to eliminate wrong answers

Option B is wrong because the second key never had `EnableKeyRotation` called on it; automatic key rotation remains disabled for that key. Option C is wrong because the first key clearly has rotation enabled via the API call. Option D is wrong because only the first key has rotation enabled, not both.

421
MCQeasy

A company is using AWS OpsWorks for configuration management of their EC2 instances. The SysOps Administrator wants to migrate to AWS Systems Manager for a more modern approach. The administrator needs to ensure that existing instances running Amazon Linux 2 can be managed by Systems Manager without downtime. The instances are currently in a running state and are critical to operations. What should the administrator do?

A.Change the OpsWorks stack configuration to use Systems Manager instead of OpsWorks agent.
B.Create a custom AMI with the SSM Agent pre-installed and launch new instances from it.
C.Delete the OpsWorks stack and recreate it with Systems Manager integration.
D.Install the SSM Agent on the existing instances using a script or AWS Systems Manager Run Command.
AnswerD

Installing the SSM Agent directly on the existing instances, either by running an installation script or via AWS Systems Manager Run Command (once connectivity to the SSM service is available), is an in-place, non-destructive operation. It preserves the OpsWorks stack, all current configurations, and avoids instance replacement or downtime. This enables Systems Manager capabilities such as Run Command, Patch Manager, and Inventory to work alongside OpsWorks' existing configuration management.

Why this answer

The AWS Systems Manager Agent (SSM Agent) can be installed on existing running Amazon Linux 2 instances using a script or AWS Systems Manager Run Command, enabling management by Systems Manager without any downtime. Option A is incorrect because changing the OpsWorks stack configuration does not install the SSM Agent; the stack would still rely on the OpsWorks agent. Option B is incorrect because creating a custom AMI and launching new instances would require replacing the existing instances, causing downtime.

Option C is incorrect because deleting and recreating the OpsWorks stack would be disruptive and does not address the need to manage existing instances without downtime.

422
MCQeasy

A SysOps administrator needs to ensure that all Amazon S3 buckets in an AWS account are encrypted at rest. The administrator wants to automatically remediate any bucket that is created without default encryption. Which AWS service should be used to achieve this with the least operational overhead?

A.AWS Config with a managed rule and auto-remediation via AWS Systems Manager Automation
B.AWS CloudTrail with Amazon CloudWatch Events and AWS Lambda
C.AWS Trusted Advisor with Amazon Simple Notification Service (SNS)
D.Amazon Inspector with AWS Systems Manager Patch Manager
AnswerA

AWS Config's managed rule `s3-bucket-default-encryption-enabled` continuously evaluates each bucket's configuration against the required encryption state. On detecting a noncompliant bucket, Config invokes an SSM Automation runbook (e.g., `AWS-ConfigureS3BucketEncryption`) that calls `PutBucketEncryption` to enable default AES-256 or AWS KMS encryption automatically. Because this combines policy evaluation with an enforcement action, it satisfies the SysOps administrator's requirement directly without requiring custom code.

Why this answer

AWS Config with the managed rule 's3-bucket-default-encryption-enabled' can detect S3 buckets that lack default encryption. By attaching an AWS Systems Manager Automation document (e.g., 'AWS-EnableS3BucketEncryption') as an auto-remediation action, the administrator can automatically apply AES-256 or AWS-KMS encryption to noncompliant buckets without manual intervention, minimizing operational overhead.

Exam trap

The trap here is that candidates may assume AWS Config only provides detection and not remediation, overlooking the auto-remediation integration with Systems Manager Automation, or they may confuse AWS Config's managed rules with Trusted Advisor's advisory checks.

How to eliminate wrong answers

Option B is wrong because AWS CloudTrail with CloudWatch Events and Lambda requires custom code and event-driven architecture, which introduces more operational overhead than AWS Config's built-in auto-remediation. Option C is wrong because AWS Trusted Advisor only provides recommendations and alerts via SNS, not automated remediation. Option D is wrong because Amazon Inspector is designed for vulnerability assessment of EC2 instances and container workloads, not for S3 bucket encryption compliance.

423
MCQeasy

A SysOps administrator wants to automate the creation of an Amazon RDS database instance using AWS CloudFormation. The database must be created in a specific VPC and must be Multi-AZ. Which CloudFormation resource property should the administrator configure to meet these requirements?

A.DBSubnetGroupName and MultiAZ
B.Engine
C.DBInstanceClass
D.DBInstanceIdentifier
AnswerA

DBSubnetGroupName specifies the VPC subnet group where the RDS instance will be provisioned, and MultiAZ (or Multi-AZ) enables a synchronous standby replica in a different Availability Zone. Together they are the required parameters for automating a Multi-AZ deployment across a defined network topology. Without a valid DBSubnetGroupName spanning at least two AZs, the MultiAZ setting cannot be properly fulfilled.

Why this answer

The DBSubnetGroupName property specifies the VPC subnets for the RDS instance, ensuring it is created in the desired VPC. The MultiAZ property enables Multi-AZ deployment for high availability. Other options: DBInstanceIdentifier (D) is only a name, Engine (B) defines the database engine type, and DBInstanceClass (C) specifies the instance size; none affect VPC placement or Multi-AZ functionality.

424
MCQhard

A company runs a critical database on an EC2 instance with an EBS volume. The administrator wants to create a disaster recovery plan that can recover the database in a different AWS Region within 4 hours. The database size is 1 TB. What is the MOST efficient approach to meet the RTO?

A.Share the AMI with the target region.
B.Copy the AMI and underlying EBS snapshots to the DR region.
C.Use EBS snapshots directly in the DR region.
D.Configure AWS Backup to copy backups to the DR region.
AnswerB

Copying the AMI to the DR region automatically copies its underlying EBS snapshots, creating fully independent regional resources you can launch immediately. This approach yields a ready-to-use, region-specific AMI with the original launch permissions, block device mappings, and tags, which directly supports the RTO for the critical database. It is the standard, most efficient way to enable cross-region instance recovery.

Why this answer

Copying the AMI and its underlying EBS snapshots to the DR region creates a fully independent, bootable image that can be launched as an EC2 instance in the target region. This approach directly supports the 4-hour RTO by allowing the administrator to pre-stage the AMI copy or initiate the copy on-demand, and then launch the instance from the copied AMI without needing to recreate the volume from individual snapshots or reconfigure instance metadata.

Exam trap

The trap here is that candidates confuse 'sharing' an AMI (which only grants cross-account access, not cross-region availability) with 'copying' an AMI (which physically replicates the image to another region), leading them to select Option A despite it not enabling DR in a different region.

How to eliminate wrong answers

Option A is wrong because sharing an AMI with the target region only grants access permissions; it does not copy the AMI or its underlying snapshots to the target region, so the AMI remains in the source region and cannot be used to launch an instance in the DR region. Option C is wrong because EBS snapshots are region-specific and cannot be used directly in another region; they must be copied to the DR region first, and even after copying, launching an instance requires creating volumes and configuring the instance manually, which adds complexity and time. Option D is wrong because AWS Backup can copy backups to the DR region, but it introduces additional overhead (backup plan, vault, restore testing) and typically has a longer restore time compared to directly copying the AMI and snapshots, making it less efficient for a 4-hour RTO.

425
Multi-Selectmedium

A SysOps administrator is using AWS CodeDeploy to deploy a new version of an application to a fleet of Amazon EC2 instances. The deployment must minimize downtime and automatically roll back if any instance fails health checks. The administrator needs to configure the deployment group settings. Which two actions should the administrator take to meet these requirements? (Choose two.)

Select 2 answers
A.Configure the deployment configuration to use a custom deployment configuration with a minimum healthy hosts value of 0.
B.Associate the deployment group with an Application Load Balancer and enable load balancer health checks.
C.Configure the deployment configuration to use CodeDeployDefault.HalfAtATime.
D.Configure the deployment configuration to use CodeDeployDefault.OneAtATime.
E.Enable automatic rollback on deployment failure in the deployment group settings.
AnswersB, E

Associating the deployment group with an Application Load Balancer and enabling load balancer health checks allows CodeDeploy to validate the health of new instances before routing traffic to them. If an instance fails health checks, the deployment can be stopped and rolled back. This helps minimize downtime by ensuring only healthy instances serve traffic.

Why this answer

To minimize downtime and automatically roll back on failure, the administrator should enable automatic rollback in the deployment group and associate the deployment group with an Application Load Balancer with health checks. Automatic rollback ensures recovery from failures, while load balancer health checks ensure that only healthy instances receive traffic. Together, these settings provide a safe deployment with minimal downtime.

Exam trap

The trap here is focusing solely on deployment configuration (like OneAtATime) and overlooking that automatic rollback and load balancer health checks are separate settings that must be explicitly enabled.

426
MCQeasy

A company runs a batch processing job on a single EC2 instance that runs for 2 hours every night. The job is fault-tolerant and can be interrupted. The SysOps administrator wants to minimize compute costs. What is the MOST cost-effective solution?

A.Use an On-Demand instance to ensure the job runs every night.
B.Purchase a Reserved Instance for 1 year to get a discount.
C.Launch a Dedicated Host to ensure consistent performance.
D.Use a Spot Instance that can be interrupted but is significantly cheaper.
AnswerD

Spot Instances are the correct choice because they offer significant cost savings, up to 90% off On-Demand pricing, in exchange for the possibility of interruption with a two-minute warning. A batch processing job is typically fault-tolerant and can be designed to checkpoint progress or be reprocessed from the last saved state, making it an ideal Spot workload. Even if Spot capacity is reclaimed, you can automatically relaunch the instance or use AWS Batch to retry the job, so the job still completes every night at a fraction of the cost.

Why this answer

A Spot Instance is the most cost-effective choice because the job is fault-tolerant and can be interrupted, allowing you to leverage unused AWS EC2 capacity at up to 90% discount compared to On-Demand pricing. Since the job runs for only 2 hours nightly and can handle interruptions, Spot Instances provide the lowest compute cost while meeting the workload requirements.

Exam trap

The trap here is that candidates often choose Reserved Instances for any recurring workload, failing to recognize that the short duration (2 hours/night) and interruptibility of the job make Spot Instances far more cost-effective without the long-term commitment.

How to eliminate wrong answers

Option A is wrong because using an On-Demand instance incurs the highest per-hour cost with no discount, which is not cost-effective for a fault-tolerant batch job that can be interrupted. Option B is wrong because purchasing a Reserved Instance for 1 year requires a long-term commitment and upfront payment, which is wasteful for a job that runs only 2 hours per night (approximately 730 hours per year) and does not benefit from the steady-state usage discount. Option C is wrong because a Dedicated Host is a physical server dedicated to your use, which is significantly more expensive and unnecessary for a single batch processing job that does not require dedicated hardware or licensing compliance.

427
MCQeasy

A SysOps administrator wants to identify underutilized Amazon EC2 instances that could be downsized to reduce costs. The administrator needs a tool that provides recommendations based on historical utilization data. Which AWS service should the administrator use?

A.AWS Trusted Advisor
B.AWS Compute Optimizer
C.AWS Cost Explorer
D.AWS Budgets
AnswerB

AWS Compute Optimizer is the correct service because it uses machine learning to analyze historical CloudWatch metrics—CPU, memory, network, and storage—and generates specific, right-sized recommendations for EC2 instances. It can suggest downsizing an instance family or size, or even terminating instances that are consistently underutilized, while estimating the monthly cost savings and performance risk. This granular, workload-specific analysis directly addresses the goal of identifying underutilized Amazon EC2 resources.

Why this answer

AWS Compute Optimizer is the correct service because it analyzes historical utilization metrics (CPU, memory, network, and storage) for EC2 instances and generates specific downsizing recommendations to reduce cost without sacrificing performance. It uses machine learning to identify underutilized resources and provides actionable guidance, making it the ideal tool for this use case.

Exam trap

The trap here is that candidates often confuse AWS Trusted Advisor's idle instance check with Compute Optimizer's detailed, ML-driven downsizing recommendations, but Trusted Advisor only flags instances with low average CPU utilization (e.g., below 10%) without considering memory, network, or storage patterns.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor provides general best-practice checks (e.g., idle instances, security groups) but does not offer granular, ML-based downsizing recommendations based on historical utilization data. Option C is wrong because AWS Cost Explorer focuses on visualizing and analyzing cost and usage trends, not on providing specific EC2 instance type recommendations for downsizing. Option D is wrong because AWS Budgets allows you to set cost thresholds and alerts, but it does not analyze historical utilization or generate downsizing recommendations.

428
MCQmedium

A SysOps administrator needs to monitor the CPU utilization of an Amazon RDS for PostgreSQL instance and receive an alert if the usage exceeds 80% for 5 consecutive minutes. The database is in a production environment. What is the MOST efficient way to achieve this?

A.Configure an Amazon Simple Notification Service (SNS) topic to subscribe to CloudWatch alarms for all RDS metrics and filter for CPUUtilization.
B.Create an AWS Lambda function that queries the RDS performance schema every minute and publishes a custom metric to CloudWatch, then set an alarm.
C.Create an Amazon CloudWatch alarm on the CPUUtilization metric with a threshold of 80 and an evaluation period of 5 minutes.
D.Use a third-party monitoring tool such as Datadog because CloudWatch cannot monitor RDS CPU utilization.
AnswerC

CloudWatch directly monitors RDS metrics and can trigger an alarm based on the metric's value over a specified period.

Why this answer

Amazon CloudWatch natively publishes the CPUUtilization metric for RDS instances every minute (standard monitoring) or every 5 minutes (enhanced monitoring). Creating a CloudWatch alarm with a threshold of 80% and an evaluation period of 5 consecutive minutes directly meets the requirement without additional infrastructure. This is the most efficient approach as it uses built-in RDS monitoring capabilities with no custom code or third-party tools.

Exam trap

The trap here is that candidates may overcomplicate the solution by assuming CloudWatch cannot natively monitor RDS CPU utilization or that custom code is required, when in fact RDS automatically publishes CPUUtilization to CloudWatch and alarms can be configured directly.

How to eliminate wrong answers

Option A is wrong because subscribing an SNS topic to all CloudWatch alarms for RDS metrics would require filtering at the SNS level, which is inefficient and does not directly create the alarm; the alarm must be created first, and SNS is a notification target, not a monitoring configuration tool. Option B is wrong because querying the RDS performance schema every minute via Lambda is unnecessarily complex, introduces latency, and incurs additional cost; CloudWatch already provides the CPUUtilization metric natively for RDS without custom instrumentation. Option D is wrong because CloudWatch fully supports monitoring RDS CPU utilization; a third-party tool like Datadog adds cost and complexity without solving the stated requirement.

429
MCQmedium

A company is using Amazon CloudWatch Logs to monitor application logs from EC2 instances. The operations team wants to receive a notification when a specific error pattern appears in the logs. Which solution requires the least operational overhead?

A.Install the CloudWatch agent on EC2 instances and configure it to stream logs to CloudWatch Logs. Create a metric filter for the error pattern and set a CloudWatch alarm that sends an SNS notification.
B.Use Amazon Kinesis Data Firehose to stream all logs to Amazon S3, then run an AWS Glue job to search for the error pattern and trigger an SNS notification.
C.Install the CloudWatch agent on EC2 instances, stream logs to CloudWatch Logs, and use a subscription filter to invoke an AWS Lambda function that publishes a message to an SNS topic.
D.Configure the application to write logs to a file, use the CloudWatch agent to send logs to CloudWatch Logs, set a metric filter, and use the filter to send data to Amazon EventBridge, which then triggers a Lambda function to send an SNS notification.
AnswerA

The CloudWatch agent streams logs to CloudWatch Logs, where a metric filter converts the error pattern into a metric that triggers an alarm and SNS notification. This is fully managed, requiring no custom code or polling infrastructure.

Why this answer

It uses native CloudWatch capabilities: the CloudWatch agent streams logs to CloudWatch Logs, a metric filter extracts the error pattern, and a CloudWatch alarm directly sends an SNS notification. This approach requires no additional compute resources like Lambda and no custom code, resulting in the least operational overhead. Option C requires creating and managing a Lambda function, which adds complexity and maintenance.

Options B and D are more complex with extra services.

Exam trap

Candidates often overcomplicate the solution by introducing Lambda functions (Option C) because they think serverless is always simpler. However, native CloudWatch features (metric filter + alarm) provide a fully managed, no-code solution that requires fewer components to manage, making it the least overhead.

How to eliminate wrong answers

Option A is wrong because while it uses metric filters and alarms, this approach requires polling and incurs additional latency; metric filters are evaluated on a schedule, not in real-time, and the alarm must transition through states, adding operational overhead. Option B is wrong because it introduces unnecessary complexity by streaming logs to S3 and running AWS Glue jobs, which are batch-oriented and not designed for real-time notification; this adds significant operational overhead and latency. Option D is wrong because it adds an unnecessary intermediate step by sending data to EventBridge before triggering Lambda; the subscription filter can directly invoke Lambda, making the EventBridge hop redundant and increasing overhead.

430
MCQeasy

A company hosts a web application on multiple EC2 instances behind an Application Load Balancer (ALB). The SysOps administrator receives a report that the application is experiencing intermittent 503 errors. The ALB target group health checks are configured to check the /health endpoint every 30 seconds with a healthy threshold of 2 and an unhealthy threshold of 2. The administrator checks the ALB metrics and notices that the number of healthy hosts occasionally drops to zero. The EC2 instances are normal and the application logs show no errors. What is the most likely cause and solution?

A.Increase the health check interval to 60 seconds.
B.Increase the health check timeout to 10 seconds.
C.Add more EC2 instances to the target group.
D.Decrease the healthy threshold to 1.
AnswerB

Raising the health check timeout to 10 seconds gives the application's health check endpoint more time to respond before the load balancer declares it unhealthy. For example, if the default timeout is 5 seconds and the endpoint occasionally takes 7 seconds under brief CPU or database contention, a 10-second timeout avoids false positives. This directly addresses the cause of the health check failures while still allowing unhealthy instances to be removed if they truly stop responding.

Why this answer

The intermittent 503 errors and healthy hosts dropping to zero indicate that health checks are timing out before the application can respond. With a default health check timeout of 5 seconds and a 30-second interval, if the /health endpoint occasionally takes longer than 5 seconds (e.g., due to transient load), the ALB marks instances unhealthy after two consecutive failures (unhealthy threshold of 2). Increasing the timeout to 10 seconds gives the endpoint more time to respond, preventing false negatives without changing the check frequency.

Exam trap

The trap here is that candidates often confuse increasing the health check interval (Option A) with giving more time for the application to respond, when in fact the timeout parameter directly controls how long the ALB waits for a response before marking the check as failed.

How to eliminate wrong answers

Option A is wrong because increasing the health check interval to 60 seconds would reduce the frequency of checks, delaying detection of actual failures and not addressing the root cause of timeouts. Option C is wrong because adding more EC2 instances does not fix the underlying health check timeout issue; the new instances would also fail the same timeout-based health checks. Option D is wrong because decreasing the healthy threshold to 1 would make the target group more sensitive to transient failures, potentially causing even more frequent flapping and 503 errors.

431
MCQhard

A SysOps administrator is troubleshooting an issue where an EC2 instance is not sending logs to CloudWatch Logs. The instance has the CloudWatch agent installed, but no logs appear in the log group. The IAM role assigned to the instance has the following policy: {"Version": "2012-10-17", "Statement": [{"Effect": "Allow", "Action": ["logs:CreateLogGroup", "logs:CreateLogStream", "logs:PutLogEvents"], "Resource": "arn:aws:logs:us-east-1:123456789012:log-group:MyAppLogs:*"}]}. What is the most likely cause?

A.The log group name in the agent configuration does not match the policy resource.
B.The CloudWatch agent is not running on the instance.
C.The IAM role does not have permission to describe log groups.
D.The instance does not have outbound internet access to reach CloudWatch Logs.
AnswerA

The IAM policy attached to the instance role explicitly restricts `logs:PutLogEvents` to the `arn:aws:logs:region:account:log-group:MyAppLogs:*` resource, but the CloudWatch agent's logs section in its configuration file (e.g., `/opt/aws/amazon-cloudwatch-agent/etc/amazon-cloudwatch-agent.toml`) references a different log group name. Because CloudWatch Logs evaluates the resource ARN of the target log group against the policy, a mismatch — even a typo or an environment suffix like `MyAppLogs-prod` instead of `MyAppLogs` — causes an `AccessDeniedException` before any log event is accepted. This is the most likely root cause in this scenario because the policy is intentionally scoped to `MyAppLogs` and the agent runs but sends nothing.

Why this answer

The IAM policy grants permissions only for the log group named 'MyAppLogs' (with a wildcard for streams). If the CloudWatch agent configuration specifies a different log group name, the agent's API calls to CreateLogGroup, CreateLogStream, or PutLogEvents will fail with an AccessDenied error because the resource ARN in the policy does not match the actual log group being targeted. This is the most common cause when the agent is installed and running but no logs appear.

Exam trap

The trap here is that candidates often assume the agent is not running or lacks internet access, but the real issue is a mismatch between the IAM policy resource and the log group name in the agent configuration, which causes an implicit deny.

How to eliminate wrong answers

Option B is wrong because if the CloudWatch agent were not running, the instance would not be able to send any logs at all, but the question states the agent is installed and the issue is that no logs appear—the agent could be running but failing due to permissions. Option C is wrong because the logs:DescribeLogGroups action is not required for sending logs; the agent only needs CreateLogGroup, CreateLogStream, and PutLogEvents to write logs. Option D is wrong because EC2 instances can reach CloudWatch Logs via the AWS public endpoint or a VPC endpoint without requiring internet access; the policy mismatch is a more specific and likely cause.

432
MCQeasy

A company wants to receive alerts when its AWS costs exceed a certain threshold. Which AWS service should be used?

A.Amazon CloudWatch
B.AWS Cost Explorer
C.AWS Trusted Advisor
D.AWS Budgets
AnswerD

AWS Budgets lets you define a cost budget with a threshold and configure alerts that trigger when actual or forecast spend exceeds it, directly satisfying the requirement to be notified when costs cross a set limit. CloudWatch billing alarms alone cannot express budget thresholds.

Why this answer

AWS Budgets allows you to set custom cost and usage budgets and receive alerts when actual or forecasted costs exceed a defined threshold. It directly supports cost-based alerting with actions such as sending an SNS notification or applying an IAM policy to restrict resources when the budget limit is breached.

Exam trap

The trap here is that candidates confuse AWS Budgets with AWS Cost Explorer, assuming Cost Explorer can send alerts, when in fact Cost Explorer is only a reporting and analysis tool without native alerting capabilities.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch monitors AWS resource utilization and application performance metrics, not cost thresholds; while it can trigger alarms on billing metrics if you enable detailed billing metrics, it is not the primary service for cost-based budget alerts. Option B is wrong because AWS Cost Explorer provides visualization and analysis of historical cost data but does not support proactive threshold-based alerts. Option C is wrong because AWS Trusted Advisor offers cost optimization recommendations and checks for idle resources, but it does not allow you to set custom cost thresholds or send alerts when costs exceed a specific amount.

433
MCQmedium

A company has multiple AWS accounts managed under AWS Organizations. The SysOps administrator needs to deploy a common AWS CloudFormation template to all accounts in a specific organizational unit (OU), ensuring consistent security group configurations across the organization. Which AWS service should the administrator use to perform this deployment?

A.AWS CloudFormation StackSets
B.AWS CodePipeline with cross-account actions
C.AWS Service Catalog portfolio
D.AWS Systems Manager Automation
AnswerA

AWS CloudFormation StackSets is the correct choice because it is purpose-built to deploy the same CloudFormation template across many accounts and regions from a single operation. With service-managed permissions, StackSets integrates natively with AWS Organizations, letting the sysops admin target entire organizational units (OUs) and automatically handle account addition/removal without custom roles or scripts. This delivers the least operational overhead for centralized, standardized stack deployment.

Why this answer

AWS CloudFormation StackSets extends the functionality of CloudFormation by allowing you to deploy a common template across multiple accounts and regions from a single management account. In this scenario, the administrator can target the specific organizational unit (OU) within AWS Organizations, ensuring consistent security group configurations are applied to all member accounts without manual intervention.

Exam trap

The trap here is that candidates often confuse AWS Service Catalog as a deployment mechanism for multi-account rollouts, but it is a governance tool for end-user provisioning, not an automated push deployment service like StackSets.

How to eliminate wrong answers

Option B is wrong because AWS CodePipeline with cross-account actions is a CI/CD service that orchestrates build, test, and deploy stages, but it does not natively support deploying a single template to multiple accounts in an OU with built-in drift detection and rollback; it would require custom scripting and manual account targeting. Option C is wrong because AWS Service Catalog portfolios allow you to create and manage a catalog of approved products (including CloudFormation templates) that users can launch, but it does not automatically deploy templates to all accounts in an OU; it relies on end-user self-service provisioning. Option D is wrong because AWS Systems Manager Automation is designed for operational tasks like patching, configuration management, and remediation across instances, not for deploying CloudFormation templates to multiple AWS accounts; it lacks the multi-account, multi-region orchestration capabilities of StackSets.

434
MCQmedium

A company uses Amazon S3 to store sensitive data. The SysOps administrator needs to ensure that any attempt to upload an object with server-side encryption disabled is immediately detected and the administrator is notified. The administrator has enabled AWS CloudTrail and is logging S3 data events. Which approach should the administrator use to achieve this?

A.Enable S3 event notifications to send events to SNS for all PutObject operations.
B.Create a CloudWatch Events rule that matches PutObject API calls without the encryption header and triggers an SNS notification.
C.Create an AWS Config rule to detect objects without encryption.
D.Use S3 Inventory to generate a daily report of unencrypted objects.
AnswerB

A CloudWatch Events (now EventBridge) rule can monitor CloudTrail S3 data events to inspect the requestParameters of each PutObject API call. CloudTrail logs the x-amz-server-side-encryption header in the requestParameters block, so a rule pattern can match when that parameter is absent, identifying unencrypted uploads. The rule then triggers an SNS notification, providing immediate, per-request detection that is not possible with other options.

Why this answer

CloudWatch Events (now Amazon EventBridge) can filter API calls captured by CloudTrail for PutObject operations that lack the x-amz-server-side-encryption header, and then trigger an SNS notification in near real-time. This ensures immediate detection and notification of any upload with server-side encryption disabled, meeting the requirement for instant alerting.

Exam trap

The trap here is that candidates may confuse S3 event notifications (which trigger on all PutObject operations without filtering) with CloudWatch Events (which can filter on API call details), leading them to choose Option A despite its inability to detect missing encryption headers.

How to eliminate wrong answers

Option A is wrong because S3 event notifications for PutObject operations do not inspect the encryption header; they trigger on all PutObject events regardless of encryption status, so they cannot distinguish between encrypted and unencrypted uploads. Option C is wrong because AWS Config rules evaluate resource configurations periodically or on configuration changes, not in real-time for each API call, and they would detect unencrypted objects at rest rather than the act of uploading without encryption. Option D is wrong because S3 Inventory generates a daily report of objects and their metadata, which is not immediate and cannot provide real-time detection or notification of the upload attempt.

435
MCQeasy

EC2 instances in private subnets need to access S3 buckets. Currently the instances use a NAT Gateway to reach S3 over the internet. The team wants to keep S3 traffic private (within the AWS network) and reduce NAT Gateway data processing costs. What is the correct solution?

A.Create an S3 Gateway VPC endpoint and add it to the private subnet's route table; S3 traffic will bypass the NAT Gateway
B.Create an S3 Interface VPC endpoint in the private subnet to route S3 traffic privately
C.Add a route in the private subnet's route table directing all traffic (0.0.0.0/0) to an Internet Gateway
D.Use S3 Transfer Acceleration to route traffic over AWS edge locations instead of NAT
AnswerA

After the Gateway endpoint is created and the route table updated, the AWS networking layer automatically routes S3 API calls from instances in those subnets through the private endpoint path. The NAT Gateway processes zero S3 bytes, eliminating the per-GB data processing cost for S3 traffic. No code changes are required.

Why this answer

An S3 Gateway VPC endpoint allows EC2 instances in private subnets to access S3 privately using AWS’s internal network, bypassing the NAT Gateway entirely. This eliminates NAT data processing costs and keeps traffic within the AWS backbone, as the endpoint is added to the private subnet’s route table with a prefix list for S3, directing traffic directly to S3 without internet routing.

Exam trap

The trap here is that candidates confuse Gateway VPC endpoints with Interface VPC endpoints, assuming both incur costs, but S3 Gateway endpoints are free and designed specifically for S3 and DynamoDB, while Interface endpoints are for other AWS services and have associated charges.

How to eliminate wrong answers

Option B is wrong because an S3 Interface VPC endpoint uses AWS PrivateLink with an elastic network interface in the subnet, incurring hourly charges and per-GB data processing costs, which does not reduce costs compared to a NAT Gateway and is unnecessary for S3 access when a Gateway endpoint (free of charge) is available. Option C is wrong because adding a route directing all traffic (0.0.0.0/0) to an Internet Gateway would expose private instances directly to the internet, violating security requirements and not keeping traffic private within AWS. Option D is wrong because S3 Transfer Acceleration uses AWS edge locations and the public internet to speed up uploads, but it does not keep traffic private within the AWS network and still requires internet connectivity, failing to reduce NAT Gateway costs.

436
MCQeasy

A company wants to monitor the performance of its Amazon RDS for MySQL database. The database is experiencing high CPU utilization during peak hours. The SysOps administrator needs to identify the queries causing the load. Which AWS service should be used?

A.Amazon RDS Performance Insights
B.AWS CloudTrail
C.Amazon Inspector
D.Amazon CloudWatch Logs
AnswerA

Amazon RDS Performance Insights is the correct choice because it is a database performance tuning and monitoring feature specifically designed for RDS. It provides an interactive dashboard that visualizes database load, waits, and identifies the top SQL queries consuming resources. With Performance Insights, you can quickly detect bottlenecks, analyze query performance, and troubleshoot issues in real time, making it directly relevant to monitoring database performance.

Why this answer

Amazon RDS Performance Insights provides a dashboard that visualizes database load and helps identify the queries causing high CPU usage. Option B is wrong because AWS CloudTrail records API activity, not database query performance data. Option C is wrong because Amazon Inspector is a vulnerability management service, not a database performance tool.

Option D is wrong because Amazon CloudWatch Logs collects log files but does not analyze query performance or CPU usage impact.

437
Multi-Selectmedium

A company wants to ensure that its AWS resources are compliant with the CIS AWS Foundations Benchmark. Which TWO AWS services can be used to automate compliance checks and remediation?

Select 2 answers
A.AWS CloudTrail
B.Amazon Inspector
C.AWS Config
D.AWS Security Hub
E.Amazon GuardDuty
AnswersC, D

AWS Config is the native service for tracking resource configuration changes and enforcing compliance through Config rules. You can deploy managed rules aligned with CIS benchmarks and, when a resource is found noncompliant, integrate remediation actions using SSM Automation documents or Lambda functions to automatically correct the drift. Config maintains a configuration item history for every resource, giving auditors the evidence needed to prove compliance over time, which makes it the core service for this use case.

Why this answer

AWS Config (option C) is correct because it continuously records resource configuration changes and evaluates them against managed or custom rules, including CIS AWS Foundations Benchmark conformance packs, and it supports automatic remediation through SSM Automation documents. AWS Security Hub (option D) is correct because it aggregates security findings and runs the CIS AWS Foundations Benchmark as a supported security standard, giving a compliance score and control-level findings that can drive automated response via EventBridge. AWS CloudTrail (option A) only logs API activity for auditing and does not perform compliance evaluation or remediation.

Amazon Inspector (option B) is a vulnerability management service for EC2, ECR images, and Lambda, not a CIS benchmark compliance engine. Amazon GuardDuty (option E) is a threat detection service that identifies malicious or anomalous activity, not configuration compliance against the CIS benchmark.

Exam trap

SOA-C02 often tests the confusion between detection services (GuardDuty, Inspector) and compliance services (Config, Security Hub) — candidates must match the service to the compliance use case.

438
MCQhard

A SysOps administrator is troubleshooting high CPU utilization on an RDS for MySQL instance. The application is read-heavy. Which optimization technique would improve performance and potentially reduce costs?

A.Delete unused indexes from the database.
B.Implement RDS Read Replicas to offload read traffic.
C.Increase the allocated storage size.
D.Enable Multi-AZ deployment for failover support.
AnswerB

Implementing RDS Read Replicas is an effective solution for high CPU utilization when the workload is read-heavy. Replicas are asynchronous read-only copies of the primary instance, and routing SELECT traffic to them offloads query processing and reduces CPU spent on reads on the primary. The primary still handles writes and synchronized reads, but by scaling out read capacity you can prevent CPU saturation without upgrading the primary instance. This approach also delivers cost efficiency because you can choose smaller replicas or a smaller primary rather than purchasing a larger single instance.

Why this answer

Implementing RDS Read Replicas offloads read traffic from the primary instance to one or more replicas, reducing CPU utilization on the primary. This improves performance for read-heavy applications and can also reduce costs because you can potentially use a smaller primary instance or fewer replicas than scaling up the primary. Read Replicas are asynchronous and can be in different AZs or regions.

Exam trap

The trap is confusing Multi-AZ with Read Replicas. Multi-AZ is for high availability, not performance. Also, candidates might think increasing storage improves CPU, but it doesn't.

The key is to offload reads.

How to eliminate wrong answers

Option A is wrong because deleting unused indexes might improve write performance but is unlikely to significantly reduce CPU for read-heavy workloads; indexes are crucial for read performance. Option C is wrong because increasing allocated storage size does not directly improve CPU performance; it may allow for more IOPS if using gp3, but it's not the primary optimization for CPU. Option D is wrong because Multi-AZ deployment provides high availability and failover, not performance improvement; the standby instance does not serve read traffic.

439
MCQmedium

A company uses AWS Elastic Beanstalk for a Java web application. The SysOps administrator needs to deploy a new version of the application with zero downtime and minimize the risk of failure. The administrator wants to deploy the new version to a completely new set of instances, test them, and then swap the environment's CNAME to point to the new instances. Which deployment policy should the administrator choose?

A.All at once
B.Rolling
C.Rolling with additional batch
D.Immutable
AnswerD

Immutable deployment creates a completely separate Auto Scaling group (with its own instances and target group) running the new application version, and Elastic Beanstalk performs health checks against that isolated stack before any traffic is shifted. Once the new instances pass all health checks, Elastic Beanstalk atomically swaps the environment's CNAME (or re-registers the target group) so all production traffic moves to the new version at once. If a health check fails or an alarm is triggered, the new Auto Scaling group is terminated and the old environment remains untouched, giving you a near-instant rollback and zero downtime. This is the most appropriate option when the requirement is to avoid any interruption and guarantee that a bad release never affects existing users.

Why this answer

The Immutable deployment policy (Option D) is correct because it launches a completely new set of instances in a separate Auto Scaling group, deploys the new application version to them, and then swaps the environment's CNAME to point to the new instances. This ensures zero downtime and minimizes risk by allowing full testing of the new instances before traffic is switched, and if the deployment fails, the original instances remain untouched.

Exam trap

The trap here is that candidates often confuse 'Rolling with additional batch' with creating a completely new set of instances, but it still modifies the existing fleet in batches rather than deploying to an entirely separate environment for a CNAME swap.

How to eliminate wrong answers

Option A is wrong because the 'All at once' deployment policy deploys the new version to all instances simultaneously, causing downtime and no ability to test before traffic is served. Option B is wrong because the 'Rolling' deployment policy updates instances in batches, which does not create a completely new set of instances and can cause partial downtime or mixed versions during the process. Option C is wrong because 'Rolling with additional batch' adds a temporary batch of instances during the rolling update, but it still updates existing instances in batches rather than deploying to a completely new set, and it does not perform a full CNAME swap.

440
MCQeasy

A company uses Amazon S3 to store critical data. They need to protect against accidental deletion of objects. Which feature should the SysOps Administrator enable?

A.Create a lifecycle policy to transition objects to Glacier.
B.Configure cross-region replication.
C.Enable versioning on the bucket.
D.Enable MFA Delete on the bucket.
AnswerC

Enabling versioning is the correct choice because it keeps every version of an object, including the original, when a delete is issued. Instead of removing the object, S3 inserts a delete marker at the top of the version stack, and you can restore the object by deleting that marker. This directly provides a recovery mechanism for both accidental overwrites and deletions.

Why this answer

Enabling S3 Versioning preserves every version of an object, including overwrites and deletes. When versioning is enabled, a DELETE request does not remove the object permanently; instead, it adds a delete marker, allowing the object to be restored by removing the marker. This directly protects against accidental deletion by providing a recoverable history of all object changes.

Exam trap

The trap here is that candidates often confuse MFA Delete (which adds a security layer but does not inherently prevent deletion) with versioning (which directly enables recovery from deletion), leading them to select D instead of C.

How to eliminate wrong answers

Option A is wrong because lifecycle policies transition objects to different storage classes (like Glacier) for cost optimization, but they do not prevent deletion; in fact, lifecycle rules can expire objects, causing permanent deletion. Option B is wrong because cross-region replication (CRR) copies objects to another bucket for disaster recovery or compliance, but it does not protect against accidental deletion in the source bucket—deletions are replicated by default, and even with delete marker replication, the source object is still deleted. Option D is wrong because MFA Delete adds an extra authentication requirement for permanent deletions and version suspension, but it does not prevent accidental deletion on its own; it must be combined with versioning to be effective, and the question asks for a feature to protect against accidental deletion, not just to add a security control.

441
MCQmedium

A SysOps administrator needs to ensure that all traffic to an Amazon S3 bucket is encrypted in transit. Which configuration should be used?

A.Use Amazon CloudFront with the S3 bucket as origin and require HTTPS.
B.Create a VPC endpoint for S3 and route all traffic through it.
C.Enable default encryption on the S3 bucket.
D.Add a bucket policy that denies requests where aws:SecureTransport is false.
AnswerD

This bucket policy explicitly denies any request for which the aws:SecureTransport condition is false, meaning the request was not made over HTTPS or TLS. Because a deny in an identity-based or bucket policy overrides any allows, every request must present a valid TLS connection or it will be rejected. This enforces encryption in transit at the S3 bucket level for all clients, including those using the public endpoint, and is the standard method for ensuring HTTPS-only access.

Why this answer

A bucket policy that denies requests where the aws:SecureTransport condition key is false enforces encryption in transit at the S3 API layer, rejecting any HTTP (non-TLS) request regardless of client. This is the canonical AWS-documented method for requiring TLS on an S3 bucket.

Exam trap

SOA-C02 often tests whether candidates confuse encryption at rest (default encryption, SSE) with encryption in transit (aws:SecureTransport deny policy) — the question wording 'in transit' is the discriminator.

How to eliminate wrong answers

Option A is wrong because CloudFront only encrypts traffic between the viewer and CloudFront; the origin fetch to S3 can still be HTTP unless separately enforced, and it does not prevent direct S3 access over HTTP. Option B is wrong because a VPC endpoint (Gateway or Interface) keeps traffic on the AWS backbone but does not itself require TLS — HTTP requests over the endpoint are still possible. Option C is wrong because default encryption (SSE-S3, SSE-KMS, or DSSE-KMS) protects data at rest, not in transit, so it does nothing for the requirement.

442
MCQeasy

A company uses Amazon S3 to store log files. The logs are accessed frequently for the first 30 days, then rarely accessed after that. The company must retain logs for 7 years for compliance. What is the MOST cost-effective storage solution?

A.Use S3 Standard for 30 days and then transition to S3 Glacier Deep Archive.
B.Use S3 Standard for 7 years.
C.Use S3 One Zone-IA for 30 days and then transition to S3 Glacier Flexible Retrieval.
D.Use S3 Intelligent-Tiering for the entire 7 years.
AnswerA

This is optimal because an S3 Lifecycle rule can automatically transition objects from S3 Standard, which is used during the 30-day active period when logs are written and frequently queried, to S3 Glacier Deep Archive, the lowest-cost storage class. Deep Archive is designed for long-term retention of rarely accessed data, offering 99.999999999% durability and a default retrieval time of 12 hours, which is acceptable for 7-year-old logs. This combination minimizes storage spend over the retention period while keeping the logs recoverable for compliance purposes.

Why this answer

S3 Lifecycle policies can transition objects from S3 Standard to S3 Glacier Deep Archive after 30 days, minimizing costs while meeting compliance. S3 Glacier Flexible Retrieval is more expensive than Deep Archive for long-term archival. S3 Intelligent-Tiering adds monitoring costs.

S3 One Zone-IA is not suitable for long-term archival due to lower durability.

443
MCQhard

A company has a VPC with a CIDR of 10.0.0.0/16. They have two subnets: subnet-A (10.0.1.0/24) and subnet-B (10.0.2.0/24). An EC2 instance in subnet-A needs to send traffic to an EC2 instance in subnet-B. Both instances are in the same VPC and have appropriate security group rules. However, traffic is not reaching the destination. What is the MOST likely cause?

A.The route table for subnet-A does not have a route for subnet-B's CIDR.
B.The network ACL associated with subnet-B is denying inbound traffic from subnet-A.
C.The security group on the destination instance does not allow inbound traffic from the source instance.
D.The VPC peering connection is not established between the two subnets.
AnswerB

Network ACLs operate at the subnet boundary and are stateless, meaning both inbound and outbound rules must be evaluated independently. If subnet-B's inbound NACL rules lack an allow rule for traffic from subnet-A's CIDR, the traffic is implicitly denied even if security groups permit it. Since NACLs are enforced before traffic reaches the instance, this would block communication even with appropriate security group rules.

Why this answer

Network ACLs are stateless and must explicitly allow both inbound and outbound traffic for each subnet. If the NACL on subnet-B denies inbound traffic from subnet-A's CIDR (10.0.1.0/24), the packets will be dropped even though security groups allow them. Since the instances are in the same VPC, the default route table includes a local route for the entire VPC CIDR (10.0.0.0/16), so routing is not the issue.

Security groups are stateful and already allow the traffic per the scenario.

Exam trap

SOA-C02 often tests the misconception that security groups are the only access control for EC2 instances, causing candidates to overlook stateless NACLs that can block traffic even when security groups allow it.

How to eliminate wrong answers

Option A is wrong because the default route table for a VPC automatically includes a local route for the VPC CIDR (10.0.0.0/16), which covers both subnets, so no additional route is needed for intra-VPC traffic. Option C is wrong because the scenario states that both instances have appropriate security group rules, so the security group is not the cause. Option D is wrong because VPC peering is used between VPCs, not between subnets within the same VPC; subnets in the same VPC communicate via the local route by default.

444
Multi-Selectmedium

Which TWO actions improve the availability of an application running on EC2 instances in a single Auto Scaling group? (Choose 2)

Select 2 answers
A.Use an Elastic Load Balancer with health checks to route traffic only to healthy instances.
B.Increase the instance size to handle higher load.
C.Create a CloudWatch alarm to notify when the CPU utilization exceeds 80%.
D.Enable EBS optimization on the instances.
E.Configure the Auto Scaling group to launch instances in multiple Availability Zones.
AnswersA, E

An Elastic Load Balancer continuously performs health checks against targets in its target group, using protocols like HTTP or TCP. If an instance fails a configured number of consecutive checks, the ELB automatically marks it unhealthy and stops routing traffic to it, while continuing to send requests only to healthy instances. This provides built-in fault tolerance for instance failures and is essential for maintaining application availability.

Why this answer

An Elastic Load Balancer (ELB) performs health checks against EC2 instances and automatically routes traffic only to instances that pass those checks. If an instance becomes unhealthy, the ELB stops sending traffic to it, preventing user requests from reaching a failing instance and thereby improving application availability.

Exam trap

The trap here is that candidates often confuse scaling actions (like increasing instance size) or monitoring (like CloudWatch alarms) with direct availability improvements, failing to recognize that only redundancy (multiple AZs) and health-based traffic routing (ELB health checks) actively mitigate failures.

445
MCQmedium

A company's security policy requires that all Amazon S3 buckets must be encrypted at rest using server-side encryption with Amazon S3 managed keys (SSE-S3). A SysOps administrator needs to automatically detect any bucket that does not have encryption enabled and automatically apply SSE-S3 encryption. The solution should leverage AWS managed services and minimize custom code. Which combination of AWS services should be used?

A.AWS Config and AWS Lambda
B.Amazon GuardDuty and AWS Lambda
C.AWS CloudTrail and Amazon EventBridge
D.Amazon Macie and AWS Step Functions
AnswerA

AWS Config continuously evaluates S3 buckets against the managed rule for encryption. Non-compliant buckets can trigger a remediation action via an AWS Lambda function that applies SSE-S3 configuration. This minimizes custom code and uses managed services.

Why this answer

AWS Config can evaluate S3 bucket configurations against a managed rule (s3-bucket-server-side-encryption-enabled) to detect non-compliant buckets. When a non-compliant bucket is detected, AWS Config can trigger an AWS Lambda function via an Amazon EventBridge rule or a custom remediation action to automatically enable SSE-S3 encryption on the bucket. This combination uses managed services and minimizes custom code, meeting the security policy requirement.

Exam trap

The trap here is that candidates may confuse AWS Config's compliance evaluation with GuardDuty's threat detection or Macie's data classification, leading them to choose a service that cannot detect or remediate encryption settings.

How to eliminate wrong answers

Option B is wrong because Amazon GuardDuty is a threat detection service that monitors for malicious activity and unauthorized behavior, not for checking or enforcing S3 bucket encryption configurations. Option C is wrong because AWS CloudTrail records API activity but does not evaluate resource compliance or trigger automated remediation; Amazon EventBridge can route events but requires a separate service like AWS Config to detect non-compliance. Option D is wrong because Amazon Macie is a data discovery and protection service that uses machine learning to identify sensitive data, not to detect or enforce encryption settings; AWS Step Functions is an orchestration service that would require custom code to implement the detection logic.

446
MCQmedium

An organization has a policy requiring that all Amazon EC2 instances launched in the production account must have detailed monitoring enabled for Amazon CloudWatch. A SysOps administrator needs to enforce this rule automatically. Which solution will ensure that any EC2 instance launched without detailed monitoring is automatically remediated?

A.Use AWS Config with the managed rule 'ec2-instance-detailed-monitoring-enabled' and configure an automatic remediation action using AWS Systems Manager Automation to enable detailed monitoring on non-compliant instances.
B.Use AWS Trusted Advisor to check for instances without detailed monitoring and send a notification to the administrator via email.
C.Use an Amazon CloudWatch Events rule to detect RunInstances API calls and trigger a Lambda function that enables detailed monitoring on newly launched instances.
D.Use an IAM policy that denies the ec2:RunInstances action unless the user specifies the parameter to enable detailed monitoring.
AnswerA

AWS Config's managed rule 'ec2-instance-detailed-monitoring-enabled' runs continuous evaluations against all recorded EC2 instances, marking any without detailed monitoring as non-compliant. Pairing this with an automatic remediation action leverages an AWS Systems Manager Automation document to run the 'ec2-monitor-instances' command or equivalent, enabling detailed monitoring without manual intervention. Because AWS Config already discovers and tracks instances, this solution covers both newly launched and pre-existing instances, requiring no custom code and providing a fully managed, auditable compliance enforcement loop.

Why this answer

AWS Config with the managed rule 'ec2-instance-detailed-monitoring-enabled' continuously evaluates EC2 instances against the policy. When an instance is non-compliant (i.e., launched without detailed monitoring), the automatic remediation action uses an AWS Systems Manager Automation document to enable detailed monitoring on that instance, ensuring enforcement without manual intervention.

Exam trap

The trap here is that candidates often choose Option C (CloudWatch Events + Lambda) because it seems reactive and automatic, but they overlook that CloudWatch Events may not reliably capture all RunInstances API calls (e.g., when instances are launched by Auto Scaling or other services) and that the Lambda function would need to handle race conditions and permissions, whereas AWS Config remediation is purpose-built for continuous compliance enforcement.

How to eliminate wrong answers

Option B is wrong because AWS Trusted Advisor only provides recommendations and notifications; it cannot automatically remediate non-compliant resources. Option C is wrong because a CloudWatch Events rule triggered by RunInstances API calls cannot reliably catch instances launched without detailed monitoring if the monitoring parameter is not explicitly set in the API call (e.g., instances launched via Auto Scaling or other services may not trigger the rule as expected). Option D is wrong because an IAM policy that denies ec2:RunInstances unless the user specifies the detailed monitoring parameter can be bypassed by users who have permissions to modify the instance after launch, and it does not automatically remediate instances that are already running without detailed monitoring.

447
MCQmedium

A company hosts a static website on Amazon S3 and uses Amazon CloudFront for content delivery. The marketing team wants to know how many users visit the website each day, including the geographic distribution. Which solution requires the LEAST operational overhead?

A.Use CloudWatch metrics for CloudFront to view request counts and enable detailed metrics.
B.Enable CloudFront access logs and use Amazon Athena to query the logs in S3.
C.Enable AWS CloudTrail for CloudFront and query the event history.
D.Enable CloudFront real-time logs and send them to Amazon Kinesis Data Analytics for analysis.
AnswerB

CloudFront access logs are delivered to an S3 bucket and capture each viewer request with fields like date, time, client-IP-derived country, URI, and edge response status. With Amazon Athena, you can define a table over those S3 objects with a serde (or partition projection on the log date) and run serverless SQL queries to aggregate request counts by day and country. This approach matches the requirement with minimal operational overhead and no streaming infrastructure.

Why this answer

Enabling CloudFront access logs and querying them with Amazon Athena provides detailed user visit counts and geographic distribution with minimal operational overhead. Access logs contain client IP addresses and request details, which Athena can analyze using SQL without managing servers or complex pipelines. This approach is serverless and cost-effective for periodic analysis.

Exam trap

The trap here is that candidates may confuse CloudWatch metrics (which show request counts but lack geographic detail) with access logs (which provide the raw data needed for geographic analysis), or overcomplicate the solution by choosing real-time streaming when batch analysis is sufficient.

How to eliminate wrong answers

Option A is wrong because CloudWatch metrics for CloudFront provide aggregated request counts but do not include geographic distribution data, and enabling detailed metrics increases cost without solving the requirement. Option C is wrong because AWS CloudTrail records API calls made to CloudFront (e.g., configuration changes), not user requests to the website, so it cannot provide visitor counts or geographic distribution. Option D is wrong because CloudFront real-time logs with Kinesis Data Analytics introduce significant operational overhead for stream processing, which is unnecessary for daily, batch-oriented analysis of user visits.

448
Multi-Selectmedium

A company uses AWS CloudFormation to deploy infrastructure. The operations team wants to be notified when a stack enters a ROLLBACK_IN_PROGRESS state. Which TWO methods can achieve this?

Select 2 answers
A.Use AWS Config rules to evaluate the stack state.
B.Create an Amazon CloudWatch Events rule that matches the CloudFormation stack status change.
C.Configure a CloudWatch Logs subscription filter to detect the stack state.
D.Create a CloudTrail trail and monitor the UpdateStack API call.
E.Configure CloudFormation stack notifications to send events to an Amazon SNS topic.
AnswersB, E

CloudFormation publishes stack status change events to the default CloudWatch Events event bus. You can create an event rule with an event pattern matching the 'CloudFormation Stack Status Change' detail type and then target a Lambda function, SNS topic, or other service. This provides a near-real-time, serverless way to react to stack transitions without polling.

Why this answer

Amazon CloudWatch Events (now Amazon EventBridge) can capture CloudFormation stack status changes, including ROLLBACK_IN_PROGRESS, by matching the 'CloudFormation Stack Status Change' event pattern. This allows you to trigger a notification action (e.g., via SNS or Lambda) in real time when the stack enters that state.

Exam trap

The trap here is that candidates may confuse CloudTrail API logging (which records the API call but not the asynchronous state transition) with event-driven notifications, or assume CloudWatch Logs subscription filters can parse CloudFormation events, when in fact CloudFormation does not write stack state changes to CloudWatch Logs.

449
MCQeasy

A SysOps administrator is tasked with ensuring that an Amazon S3 bucket can withstand the loss of an entire AWS Region. The bucket stores critical data that must be accessible with minimal latency from multiple regions. Which solution meets these requirements?

A.Enable S3 Versioning and configure a lifecycle policy to transition objects to S3 Glacier Deep Archive.
B.Configure S3 Cross-Region Replication to a bucket in another AWS Region. Use Amazon CloudFront with multiple origins pointing to both buckets.
C.Enable S3 Versioning and MFA Delete on the bucket. Use S3 Object Lock to prevent object deletion.
D.Enable S3 Transfer Acceleration on the bucket and use a CloudFront distribution with the bucket as the origin.
AnswerB

S3 Cross-Region Replication asynchronously copies every uploaded object to a destination bucket in a different Region, giving the bucket contents regional redundancy; versioning must be enabled on both source and destination for CRR to function. Amazon CloudFront can be configured with an origin group containing both buckets—one as primary and one as secondary—so that if the primary origin returns an error or is unreachable, CloudFront automatically fails over to the replicated bucket in the other Region. This combination provides both replicated durability and low-latency edge delivery, supporting failover without manual intervention.

Why this answer

S3 Cross-Region Replication (CRR) automatically replicates objects to a bucket in another AWS Region, ensuring data survives a regional failure. Using Amazon CloudFront with multiple origins pointing to both buckets provides low-latency access from any region by routing requests to the nearest healthy origin, meeting both durability and performance requirements.

Exam trap

The trap here is that candidates may confuse S3 Transfer Acceleration or Versioning with multi-region replication, failing to recognize that only CRR provides cross-region data redundancy and that CloudFront with multiple origins is needed for low-latency access and automatic failover.

How to eliminate wrong answers

Option A is wrong because S3 Glacier Deep Archive is designed for long-term archival with retrieval times of hours, not for low-latency access, and versioning alone does not provide multi-region redundancy. Option C is wrong because S3 Versioning, MFA Delete, and Object Lock protect against accidental deletion but do not replicate data across regions or enable low-latency access from multiple regions. Option D is wrong because S3 Transfer Acceleration speeds up uploads over long distances but does not replicate data to another region or provide failover for regional outages; CloudFront with a single bucket origin does not offer multi-region redundancy.

450
MCQhard

A company runs a stateful application on EC2 instances in an Auto Scaling group. The application maintains state in memory. The SysOps administrator wants to ensure that when an instance is terminated, the state is preserved and a new instance can resume operation. Which approach should the administrator use?

A.Use an Auto Scaling lifecycle hook to offload state before termination.
B.Use a warm standby instance that takes over when the primary fails.
C.Configure the EC2 instance to run a script on shutdown to save state locally.
D.Enable connection draining on the ALB.
AnswerA

Auto Scaling lifecycle hooks pause the instance in the 'terminating:wait' state, providing a window for a script or Lambda function to copy application state to durable external storage such as Amazon S3 or an EFS mount. Only after the state is successfully stored does the hook signal the Auto Scaling group to continue the termination, ensuring no data is lost during a scale-in event. This is the only option that explicitly performs an offload operation before the instance is destroyed.

Why this answer

An Auto Scaling lifecycle hook can be configured to execute a custom action (e.g., offloading in-memory state to Amazon S3 or ElastiCache) before the instance is terminated. The lifecycle hook places the instance in a 'terminating:wait' state, allowing the administrator to run a script that preserves state, and then completes the termination via CompleteLifecycleAction. This ensures state is saved before the instance is fully terminated, enabling a new instance to resume operation.

Exam trap

The trap here is that candidates assume a shutdown script (Option C) is sufficient, but they overlook that local instance store is ephemeral and that the OS shutdown sequence may not complete before the instance is forcefully terminated, making lifecycle hooks the only reliable mechanism for state preservation.

How to eliminate wrong answers

Option B is wrong because a warm standby instance does not address the need to preserve state from a terminating instance; it simply provides a pre-provisioned replacement that would still lack the in-memory state of the failed instance. Option C is wrong because a shutdown script runs after the termination signal is sent, but the instance may be forcibly terminated before the script completes, and local storage (instance store or ephemeral volumes) is lost on termination, making local save unreliable. Option D is wrong because connection draining on an ALB only stops new connections and allows in-flight requests to complete before deregistering the target; it does not preserve or offload application state stored in memory.

Page 5

Page 6 of 16

Page 7