Courseiva

AWS Certified SysOps Administrator Associate SOA-C02 (SOA-C02) — Questions 451–525

1169 questions total · 16pages · All types, answers revealed

Page 6

Page 7 of 16

Page 8
451
MCQhard

A company runs a microservices architecture on Amazon ECS with Fargate. They need to ensure that if a task fails, it is automatically restarted. Which configuration is required?

A.Configure a CloudWatch alarm to restart the task
B.Define tasks using the ECS RunTask API
C.Use an Auto Scaling group for the Fargate tasks
D.Create an ECS service with a desired count and task definition
AnswerD

An ECS service is the correct mechanism for running a long-lived microservice: you specify a task definition, a desired count, and a cluster, and the service scheduler ensures that the desired number of tasks is always running. When a task crashes, is killed, or fails a health check, the service automatically replaces it by starting a new task from the same task definition. This provides self-healing and integrates with Application Load Balancers, target groups, and service discovery for production traffic.

Why this answer

An ECS service with a desired count and task definition ensures that Fargate tasks are automatically restarted if they fail. The ECS service scheduler monitors the desired count and replaces any stopped or failed tasks to maintain the specified number of running instances, providing built-in resilience without additional infrastructure.

Exam trap

The trap here is that candidates confuse the RunTask API (for one-off tasks) with ECS services (for long-running, self-healing tasks), or mistakenly think CloudWatch alarms or Auto Scaling groups are needed for task restart logic when the ECS service itself provides this capability.

How to eliminate wrong answers

Option A is wrong because CloudWatch alarms can trigger actions like sending notifications or scaling, but they cannot directly restart an ECS task; restarting requires a service or custom automation. Option B is wrong because the RunTask API launches tasks on-demand for batch or one-off jobs, not for continuous availability or automatic restart on failure. Option C is wrong because Auto Scaling groups are used for EC2 instances, not for Fargate tasks; Fargate tasks are managed by ECS services or standalone RunTask calls, and scaling is handled via ECS Service Auto Scaling, not an Auto Scaling group.

452
MCQmedium

A company runs a batch processing job every night that takes 2 hours on a single m5.xlarge EC2 instance. The job is fault-tolerant and can be interrupted. The SysOps administrator wants to reduce costs. Which solution is MOST cost-effective?

A.Use an On-Demand instance and set up a CloudWatch alarm to stop it when the job completes.
B.Use a Spot Instance with a Spot Fleet that includes a fallback to On-Demand if Spot is not available.
C.Use a Dedicated Host to run the job.
D.Purchase a Reserved Instance for the m5.xlarge instance.
AnswerB

A Spot Fleet is the correct choice here because it lets you request Spot Instances at a significantly lower cost while maintaining reliability with an On-Demand fallback. The nightly batch job is fault-tolerant, meaning it can restart or rerun if Spot capacity is reclaimed. If Spot capacity is unavailable or gets interrupted, the Spot Fleet automatically launches an On-Demand instance to ensure the job still completes, giving you a balance of cost savings and capacity assurance.

Why this answer

The most cost-effective solution is to use a Spot Instance with a Spot Fleet that includes a fallback to On-Demand if Spot is not available (Option B). The job is fault-tolerant and can be interrupted, making it ideal for Spot Instances which offer significant cost savings (up to 90% compared to On-Demand). The Spot Fleet with an On-Demand fallback ensures the job completes even if Spot capacity is unavailable.

Option A (On-Demand with CloudWatch alarm) does not reduce costs since On-Demand is more expensive. Option C (Dedicated Host) is costly and unnecessary for a batch job. Option D (Reserved Instance) requires a 1- or 3-year commitment and is not cost-effective for a 2-hour daily job.

453
Multi-Selecteasy

A SysOps administrator needs to ensure high availability for a web application running on EC2 instances across multiple Availability Zones. Which TWO actions should the administrator take?

Select 2 answers
A.Launch EC2 instances in at least two different Availability Zones.
B.Place a CloudFront distribution in front of the instances.
C.Launch all EC2 instances in a single Availability Zone for consistency.
D.Register the instances with an Application Load Balancer that has health checks enabled.
E.Attach an EBS volume to each instance and replicate data in real-time.
AnswersA, D

Spreading instances across two or more Availability Zones ensures an outage affecting one data centre does not take down the whole application, directly satisfying the multi-AZ high-availability constraint. Each AZ has independent power, cooling and networking, so a single-zone failure leaves capacity running elsewhere.

Why this answer

Option A is correct because distributing EC2 instances across at least two Availability Zones ensures the application survives the failure of a single AZ, which is the foundation of high availability in AWS. Option D is correct because an Application Load Balancer with health checks automatically detects unhealthy instances and routes traffic only to healthy targets across those AZs, maintaining availability during instance or AZ failures. Option B is not correct because CloudFront is a CDN that caches content at edge locations; it improves latency and offloads origin traffic but does not by itself provide multi-AZ failover for EC2 compute.

Option C is not correct because concentrating all instances in one AZ creates a single point of failure, directly contradicting the high-availability requirement. Option E is not correct because EBS volumes are tied to a single AZ and cannot be attached across AZs, and real-time replication of EBS is not how EC2-level high availability is achieved.

Exam trap

SOA-C02 often tests the confusion between content delivery (CloudFront) and high availability, or between data replication (EBS) and compute redundancy, causing candidates to select options that do not address AZ-level fault tolerance.

454
MCQhard

A company runs a stateful web application on a single EC2 instance. The SysOps Administrator wants to improve fault tolerance. Which design should they implement?

A.Create a Multi-AZ RDS instance and attach it to the existing EC2 instance.
B.Add a second EC2 instance in the same Availability Zone and use a Network Load Balancer.
C.Use an Auto Scaling group with a launch configuration that stores session data on instance store.
D.Place instances in an Auto Scaling group across two Availability Zones, use an Application Load Balancer, and store session state in ElastiCache.
AnswerD

Placing the application instances in an Auto Scaling group across two Availability Zones ensures that both an instance failure and a full AZ failure can be absorbed automatically, as the ASG launches a replacement instance in the remaining healthy AZ. An Application Load Balancer distributes traffic and performs health checks, routing requests only to healthy instances. Storing session state in ElastiCache (or a similar external store) decouples sessions from compute instances, so any instance can handle any request without losing user data; if an instance terminates, a new instance can access the same session state from ElastiCache. This combination provides both high availability and fault tolerance for a stateful web application.

Why this answer

It distributes the web application across multiple Availability Zones for high availability, uses an Application Load Balancer to route traffic to healthy instances, and stores session state externally in ElastiCache. This decouples the stateful session data from the EC2 instances, allowing any instance to handle any request without losing session context, which is essential for fault tolerance in a stateful application.

Exam trap

The trap here is that candidates often confuse high availability with fault tolerance, choosing a single-AZ solution (Option B) or a database-only fix (Option A), failing to recognize that stateful applications require externalized session state to survive instance or AZ failures.

How to eliminate wrong answers

Option A is wrong because Multi-AZ RDS provides database high availability, but the web application itself remains a single point of failure on one EC2 instance; it does not address the fault tolerance of the application tier. Option B is wrong because adding a second EC2 instance in the same Availability Zone does not protect against an Availability Zone failure; the entire zone could go down, taking both instances with it. Option C is wrong because instance store is ephemeral and data is lost if the instance stops, terminates, or fails; storing session data on instance store would cause session loss during any fault event, defeating the purpose of improving fault tolerance.

455
Multi-Selecthard

A SysOps administrator is designing a VPC for a web application that must be secure. Which THREE security measures should the administrator implement? (Choose THREE.)

Select 3 answers
A.Configure network ACLs to filter traffic at the subnet level.
B.Enable VPC Flow Logs to capture traffic information.
C.Place all resources in public subnets to simplify access.
D.Use security groups to control inbound and outbound traffic at the instance level.
E.Use the default VPC for simplicity.
AnswersA, B, D

Network ACLs are a stateless, subnet-level firewall that filters traffic based on numbered rules evaluated in ascending order. Because they are stateless, you must explicitly define both inbound and outbound rules, and responses to allowed inbound traffic require a corresponding outbound rule. NACLs apply uniformly to every instance in the subnet, providing a coarse boundary that can block traffic before it reaches security groups, though they cannot inspect individual instance traffic.

Why this answer

Network ACLs (NACLs) are stateless firewalls that operate at the subnet level, providing an additional layer of security by filtering traffic entering and exiting each subnet. By default, NACLs allow all traffic, but you can configure custom rules to explicitly allow or deny traffic based on IP addresses, protocols, and port ranges, which is essential for securing a web application VPC.

Exam trap

The trap here is that candidates often confuse network ACLs (stateless, subnet-level) with security groups (stateful, instance-level), or assume that using the default VPC is acceptable for simplicity, when in fact it lacks the granular control needed for a secure architecture.

456
Drag & Dropmedium

Drag and drop the steps to migrate an on-premises application to AWS using AWS Application Migration Service (MGN) into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence for migrating an on-premises application to AWS using AWS Application Migration Service is: first install the AWS Replication Agent on the source server, then configure the replication settings including launch settings and target VPC, then start the initial sync to replicate the entire server volume, then perform a test launch to validate the replicated environment, and finally initiate the cutover to redirect production traffic to the new AWS instance. Each step builds on the previous one to ensure a successful migration with minimal downtime.

457
MCQeasy

A SysOps administrator is reviewing the monthly AWS bill and notices a significant cost for data transfer from EC2 to the internet. The EC2 instances are in a VPC and serve content to users. Which action would MOST effectively reduce data transfer costs?

A.Use VPC endpoints to connect to S3 and DynamoDB.
B.Use Amazon CloudFront as a content delivery network (CDN).
C.Move the EC2 instances to a different AWS Region with lower data transfer rates.
D.Use a NAT Gateway to route traffic through a single IP.
AnswerB

Amazon CloudFront serves as a content delivery network, caching responses at edge locations so repeat requests never reach the EC2 origin. This reduces the volume of data transferred directly from EC2 to the public internet and, for requests that do go to the origin, the AWS-to-CloudFront leg is free while CloudFront's egress rate is lower than EC2's standard internet data transfer rate. Offloading delivery to edge servers therefore both cuts total egress gigabytes and shifts remaining traffic to a cheaper pricing tier, directly lowering the monthly bill.

Why this answer

Using Amazon CloudFront as a CDN caches content at edge locations closer to users, reducing the amount of data transferred directly from EC2 instances to the internet. This lowers data transfer out (DTO) costs because CloudFront has lower data transfer rates and can also cache content, reducing the load on EC2. The question specifies data transfer from EC2 to the internet, so offloading to CloudFront is the most effective cost reduction.

Exam trap

The trap is confusing VPC endpoints with CDNs. VPC endpoints reduce costs for private traffic to AWS services, not for internet-facing traffic. Candidates might also think NAT Gateway reduces costs, but it actually adds data processing charges.

How to eliminate wrong answers

Option A is wrong because VPC endpoints are for private connectivity to AWS services like S3 and DynamoDB, not for reducing internet data transfer from EC2 to users; they don't affect EC2-to-internet traffic. Option C is wrong because moving to a different region with lower data transfer rates is not a standard cost optimization strategy; AWS data transfer rates are generally consistent across regions, and moving regions introduces latency and complexity. Option D is wrong because a NAT Gateway is used for outbound internet access from private subnets, but it does not reduce data transfer costs; in fact, NAT Gateway data processing charges can increase costs.

458
MCQmedium

A company uses an Amazon DynamoDB table with provisioned capacity. The average write usage is 500 write capacity units (WCU) but regularly spikes to 2,000 WCU during business hours. The SysOps administrator wants to reduce costs without affecting performance during the spikes. Which solution should the administrator implement?

A.Enable DynamoDB auto scaling
B.Switch to DynamoDB on-demand capacity mode
C.Purchase reserved capacity for 2,000 WCU
D.Use DynamoDB Time to Live (TTL) to delete old items
AnswerA

DynamoDB auto scaling uses CloudWatch metrics (ConsumedWriteCapacityUnits and ConsumedReadCapacityUnits) to automatically adjust provisioned capacity between configured minimum and maximum limits. This handles predictable spikes by scaling up in advance and reduces costs by scaling down during low usage, eliminating manual intervention. With a target utilization set (e.g., 70%), auto scaling maintains enough capacity to handle demand while avoiding overprovisioning.

Why this answer

DynamoDB auto scaling allows the table to automatically adjust its provisioned write capacity between a minimum and maximum range based on actual traffic. By setting the minimum WCU to cover the average usage (500) and the maximum to handle the spikes (2,000), the administrator pays only for the baseline capacity most of the time, while the service scales up during spikes without manual intervention or over-provisioning.

Exam trap

The trap here is that candidates often confuse on-demand mode as a cost-saving measure for spiky workloads, but in reality, on-demand is more expensive than provisioned capacity with auto scaling when there is a predictable baseline, and the question specifically asks to reduce costs without affecting performance.

How to eliminate wrong answers

Option B is wrong because switching to on-demand capacity mode would eliminate the need to manage capacity but would result in significantly higher costs for the described workload, as on-demand charges per write request are higher than provisioned capacity, especially when the baseline usage is predictable. Option C is wrong because purchasing reserved capacity for 2,000 WCU would lock the company into paying for that high capacity 24/7, even during off-peak hours when usage is only 500 WCU, leading to wasted expenditure. Option D is wrong because DynamoDB Time to Live (TTL) is a feature for automatically expiring and deleting old items to manage storage costs, not for handling write capacity spikes or optimizing provisioned throughput costs.

459
MCQmedium

A company uses AWS CodePipeline to deploy a web application to Amazon EC2 instances behind an Application Load Balancer. During a deployment, the pipeline fails at the Deploy stage with an error indicating that the CodeDeploy agent is not responding. The instances are in an Auto Scaling group. What is the MOST likely cause of this issue?

A.The pipeline does not have a VPC endpoint to connect to the instances.
B.The IAM role attached to the instances does not have permissions for CodeDeploy.
C.The CodeDeploy agent is not installed on the EC2 instances.
D.The Application Load Balancer is not configured with a target group.
AnswerC

The CodeDeploy agent must be installed and running on every EC2 instance that participates in a CodeDeploy deployment. This background service registers the instance with CodeDeploy, polls for deployment instructions, runs the lifecycle events on the instance, and reports success or failure back to the service. When the agent is missing, no instance ever reports back, so CodePipeline fails with a message like 'No hosts received a command' or 'Overall deployment failed because no instances have been successfully registered.'

Why this answer

The CodeDeploy agent is a software package that must be installed and running on each EC2 instance to receive deployment instructions from the CodeDeploy service. If the agent is absent, the service cannot communicate with the instance, producing the 'agent not responding' error. Auto Scaling group instances launched from an AMI that lacks the agent will exhibit exactly this symptom.

Exam trap

SOA-C02 often tests the distinction between agent-level failures and IAM/network-level failures; candidates frequently pick the IAM role answer because permissions feel like the default cause, but 'agent not responding' specifically points to the agent software itself.

How to eliminate wrong answers

Option A is wrong because CodePipeline and CodeDeploy communicate with instances over the public AWS service endpoints (or via VPC endpoints if configured), but a missing VPC endpoint would cause a connectivity error, not an 'agent not responding' error. Option B is wrong because a missing IAM permission on the instance profile would produce an authorization/access-denied error, not an agent communication failure. Option D is wrong because an ALB target group misconfiguration affects traffic routing to the application, not the CodeDeploy agent's ability to receive deployment commands.

460
MCQeasy

A company has an application that runs on EC2 instances behind an Application Load Balancer. The application uses an RDS Multi-AZ database. The company wants to ensure that the application remains available during a database failover. What should the SysOps administrator do?

A.Ensure the application retries database connections during failover.
B.Create a read replica of the database to offload read traffic.
C.Increase the EC2 instance size to handle the load.
D.Enable termination protection on the EC2 instances.
AnswerA

During a Multi-AZ RDS failover, the RDS DNS CNAME is repointed to the standby database, a process that typically takes 60–120 seconds, during which existing database connections are forcibly terminated. A resilient application must catch connection errors and retry with exponential backoff or a fresh connection attempt so it can ride through the interruption; without this retry logic, requests that arrive during the failover window will return errors even after the new primary is ready.

Why this answer

During an RDS Multi-AZ failover, the database DNS record is updated to point to the standby instance, which can take up to 60 seconds. Existing connections are dropped, so the application must implement connection retry logic with exponential backoff to re-establish connections to the new primary. Without retries, the application will fail to serve requests until the database is reachable again, breaking availability.

Exam trap

The trap here is that candidates confuse high-availability infrastructure (Multi-AZ, termination protection) with application-level resilience, assuming the infrastructure alone guarantees uptime without requiring the application to handle transient connection failures.

How to eliminate wrong answers

Option B is wrong because creating a read replica offloads read traffic but does not help the application survive a Multi-AZ failover; the read replica is a separate instance and does not become the new primary during failover. Option C is wrong because increasing EC2 instance size addresses compute capacity, not database connectivity issues caused by a failover. Option D is wrong because termination protection prevents accidental EC2 instance termination, but has no effect on database failover behavior or connection handling.

461
Multi-Selectmedium

A company is designing a highly available architecture for a web application using AWS services. Which TWO actions should the SysOps administrator take to improve reliability? (Choose TWO.)

Select 2 answers
A.Use a single large EC2 instance to eliminate complexity.
B.Use an Auto Scaling group with an Elastic Load Balancer.
C.Use a single NAT gateway for outbound traffic.
D.Deploy EC2 instances in multiple Availability Zones.
E.Store application data on a single EBS volume.
AnswersB, D

An Auto Scaling group combined with an Elastic Load Balancer delivers high availability by maintaining a desired instance count across healthy capacity and automatically replacing failed instances based on health checks. The ELB distributes incoming traffic across all healthy instances, preventing any single node from being overwhelmed and allowing the fleet to scale in and out with demand. When integrated across multiple Availability Zones, this pattern provides both elasticity and fault tolerance, making it a core AWS high-availability design.

Why this answer

An Auto Scaling group combined with an Elastic Load Balancer automatically distributes incoming traffic across healthy EC2 instances and replaces any failed instances, ensuring the application remains available even during instance failures or traffic spikes. This architecture is a core AWS best practice for building highly available and resilient web applications.

Exam trap

The trap here is that candidates often think a single large instance is simpler and more reliable, but AWS explicitly recommends horizontal scaling with multiple instances across Availability Zones to eliminate single points of failure.

462
MCQhard

An organization is using OpsWorks to manage a stack of application servers. They need to automatically scale out based on CPU utilization. Which configuration should the SysOps administrator use to achieve this?

A.Enable auto-healing on the layer to replace unhealthy instances automatically.
B.Create a custom Chef recipe that runs on a lifecycle event to launch new instances.
C.Add a load-based layer and configure the scaling thresholds for CPU utilization.
D.Configure a time-based instance with a recurring schedule to add instances during peak hours.
AnswerC

Adding a load-based layer and specifying CPU utilization thresholds lets OpsWorks Stacks watch the layer's load metrics and automatically add or remove instances when CPU crosses upper or lower limits, with configurable cooldown and evaluation periods. This directly satisfies the CPU-based demand requirement because the layer scales out to more instances when CPU is high and scales in when it drops. Load-based instances are one of the built-in OpsWorks scaling types (along with time-based and 24/7 instances), and they are the only option listed that triggers scaling based on actual utilization.

Why this answer

OpsWorks load-based layers automatically scale instances based on CloudWatch alarms, such as CPU utilization thresholds. Option A is incorrect because auto-healing replaces failed instances, not scales out. Option B is incorrect because custom Chef recipes run on lifecycle events (setup, configure, etc.) but do not directly handle automatic scaling.

Option D is incorrect because time-based instances scale on a schedule, not based on CPU utilization.

463
Multi-Selectmedium

A SysOps administrator is optimizing costs for an AWS account. The account has multiple EC2 instances running 24/7 with varying utilization. Which TWO actions will help reduce costs without impacting performance? (Choose TWO.)

Select 2 answers
A.Use AWS Compute Optimizer to right-size instances.
B.Use larger instance types to improve performance.
C.Enable detailed CloudWatch monitoring for all instances.
D.Enable termination protection on all instances.
E.Purchase Reserved Instances for instances that run consistently.
AnswersA, E

AWS Compute Optimizer is a machine-learning-based service that analyzes your instance utilization (CPU, memory, network, and disk) over the previous 14 days or longer, and generates right-sizing recommendations that match instance type and size to actual workload requirements. By migrating to recommended smaller or more modern instance families, you eliminate over-provisioning and reduce monthly EC2 costs without degrading application performance, making it a direct and effective cost-optimization action.

Why this answer

AWS Compute Optimizer analyzes historical utilization metrics (CPU, memory, network, etc.) and provides right-sizing recommendations to match instance types to actual workload demands. By downsizing over-provisioned instances, you reduce costs without degrading performance, as the new instance type still meets the workload's peak requirements.

Exam trap

The trap here is confusing operational safeguards (like termination protection or monitoring) with cost optimization actions, leading candidates to select options that add cost or provide no savings.

464
MCQmedium

A SysOps administrator needs to reduce costs for a fleet of EC2 instances that run a stateless web application. The instances are currently On-Demand. The workload runs 24/7 for the next 12 months. Which pricing model provides the greatest cost savings?

A.Use Dedicated Hosts.
B.Use Spot Instances.
C.Purchase Standard Reserved Instances for a 1-year term.
D.Purchase Convertible Reserved Instances for a 1-year term.
AnswerC

Standard Reserved Instances for a 1-year term are the most cost-effective choice for a predictable, always-on fleet because they apply a significant hourly discount (up to 40% relative to On-Demand) while requiring no management overhead. By committing to a 1-year term with an All Upfront or Partial Upfront payment, you lock in that discounted rate for the entire year, directly reducing costs for steady-state usage without sacrificing reliability or capacity. This makes them the correct answer for an administrator tasked with trimming costs on a non-interruptible workload.

Why this answer

Standard Reserved Instances (RIs) for a 1-year term provide a significant discount (up to 40%) over On-Demand pricing for workloads that run continuously 24/7. Since this stateless web application runs constantly for the next 12 months, Standard RIs offer the greatest cost savings among the options, as they are designed for steady-state usage and do not require flexibility in instance family or operating system.

Exam trap

The trap here is that candidates often choose Spot Instances (Option B) thinking they are always cheaper, but they overlook the requirement for 24/7 availability and the risk of interruption, which makes them unsuitable for a stateless web application that must run continuously without disruption.

How to eliminate wrong answers

Option A is wrong because Dedicated Hosts are a physical server dedicated to your use, which incurs additional costs (per-host billing) and does not provide the same discount level as Reserved Instances; they are used for licensing or compliance requirements, not cost savings for a stateless web app. Option B is wrong because Spot Instances can be interrupted with a 2-minute warning, making them unsuitable for a 24/7 stateless web application that requires constant availability; they are designed for fault-tolerant or batch workloads, not always-on production traffic. Option D is wrong because Convertible Reserved Instances offer flexibility to change instance attributes (family, OS, tenancy) but have a lower discount (typically 10-20% less than Standard RIs) for the same 1-year term, making them less cost-effective for a fixed, predictable workload.

465
MCQhard

A company's security policy requires that all Amazon S3 buckets must be encrypted at rest with AWS Key Management Service (AWS KMS) customer managed keys. A SysOps administrator discovers that some buckets are not encrypted. Which combination of AWS services should be used to automatically detect and remediate non-compliant buckets using infrastructure as code?

A.AWS Config with a managed rule and AWS Lambda for automatic remediation.
B.AWS CloudTrail and Amazon GuardDuty.
C.Amazon Inspector and AWS Systems Manager.
D.Amazon Macie and AWS CloudFormation.
AnswerA

AWS Config is the correct service because it performs continuous, resource-level compliance evaluation. The managed rule 's3-bucket-server-side-encryption-enabled' can be configured with a parameter to require SSE-KMS (aws:kms) rather than just SSE-S3, and when a bucket is non-compliant, AWS Config triggers an automatic remediation action that invokes a Lambda function to apply the required default encryption settings. This creates an end-to-end detect-and-fix pipeline, which CloudTrail, GuardDuty, Inspector, or Macie cannot provide.

Why this answer

AWS Config with a managed rule (e.g., s3-bucket-server-side-encryption-enabled) can continuously evaluate S3 buckets for compliance with the encryption policy. When a non-compliant bucket is detected, AWS Config can automatically invoke an AWS Lambda function to remediate the issue, such as enabling encryption with a customer managed KMS key. This combination provides automated detection and remediation using infrastructure as code, as the Config rule and Lambda function can be defined in AWS CloudFormation or similar IaC tools.

Exam trap

The trap here is that candidates may confuse detection services (like GuardDuty or Macie) with compliance evaluation services (AWS Config), or assume that CloudFormation alone can detect non-compliance without a continuous evaluation mechanism like AWS Config rules.

How to eliminate wrong answers

Option B is wrong because AWS CloudTrail and Amazon GuardDuty are used for auditing API activity and threat detection, not for automated compliance detection and remediation of S3 bucket encryption. Option C is wrong because Amazon Inspector is a vulnerability management service for EC2 instances and container workloads, not for S3 bucket encryption compliance, and AWS Systems Manager is for operational management, not automated encryption remediation. Option D is wrong because Amazon Macie is a data discovery and classification service for sensitive data, not for encryption compliance, and AWS CloudFormation alone cannot automatically detect non-compliant buckets without a trigger like AWS Config.

466
MCQmedium

A SysOps administrator is troubleshooting an IAM policy that is not granting the expected permissions. The policy has a Deny effect on a specific action, but the user is still able to perform that action. What is the most likely reason?

A.The Deny statement is listed after an Allow statement in the policy
B.IAM policies do not support deny statements with conditions
C.The Deny statement includes a condition that is not met by the request
D.The user has an attached AWS managed policy that allows the action
AnswerC

This is the correct option. IAM evaluates the Condition element of a Deny statement before treating that statement as an effective deny; if the request's context does not satisfy the condition, the Deny statement is skipped entirely. Once that Deny is out of the way, the default-implicit-deny behavior is replaced by any applicable Allow policies, which then permit the action.

Why this answer

An explicit Deny in IAM only takes effect when the condition attached to that Deny statement evaluates to true for the request. If the Deny statement includes a condition (such as a specific IP range, MFA requirement, or time window) that the current request does not satisfy, the Deny does not apply, and an Allow from another policy can grant access. This is the most likely reason a user can still perform the action despite a Deny statement existing.

Exam trap

SOA-C02 often tests the misconception that any Deny statement automatically blocks access — candidates forget that a Deny with an unmet condition is effectively inert, and they overlook the condition evaluation step in the IAM policy evaluation flow.

How to eliminate wrong answers

Option A is wrong because IAM policy evaluation does not depend on the order of statements within a policy — explicit Deny always overrides Allow regardless of statement order. Option B is wrong because IAM policies absolutely do support deny statements with conditions; condition keys like aws:SourceIp, aws:MultiFactorAuthPresent, and aws:CurrentTime are commonly used with Deny. Option D is wrong because an attached AWS managed policy that allows the action would be overridden by an explicit Deny in another policy — explicit Deny always wins in IAM evaluation logic, so this cannot be the reason the user still has access.

467
MCQmedium

A company's security team requires that all Amazon EC2 instances in a specific AWS account must have the tag 'Environment' set to either 'Production' or 'Test'. Any instance that is launched without this tag or with an invalid value must be automatically terminated within five minutes. Which combination of AWS services can enforce this requirement with minimal manual intervention?

A.AWS Config with a custom rule and AWS Lambda
B.AWS CloudTrail and Amazon CloudWatch Events
C.AWS Service Catalog and AWS Organizations
D.Amazon Inspector and AWS Systems Manager
AnswerA

A custom AWS Config rule can evaluate EC2 instances when they are created (configuration change trigger) and invoke an AWS Lambda function to terminate instances lacking the required tag or having an invalid value. This provides continuous compliance enforcement.

Why this answer

AWS Config with a custom rule can evaluate EC2 instances for the required 'Environment' tag with valid values. When a non-compliant instance is detected, AWS Config triggers an AWS Lambda function that terminates the instance within the required five-minute window. This combination provides automated, event-driven enforcement with minimal manual intervention.

Exam trap

The trap here is that candidates may think CloudTrail and CloudWatch Events alone can enforce tag compliance, but they lack the evaluation logic and automated remediation that AWS Config with a custom Lambda rule provides.

How to eliminate wrong answers

Option B is wrong because AWS CloudTrail records API calls and CloudWatch Events can trigger on those events, but they lack native tag validation logic; you would still need a Lambda function to evaluate tag values and terminate instances, making this an incomplete solution. Option C is wrong because AWS Service Catalog enforces compliance at provisioning time through predefined products, but it cannot retroactively terminate instances launched outside the catalog or enforce tag compliance on existing instances. Option D is wrong because Amazon Inspector is a vulnerability assessment service and AWS Systems Manager is for operational management; neither service has the capability to evaluate tags or terminate instances based on tag compliance.

468
MCQeasy

A company stores large volumes of log data in Amazon S3. The logs are accessed frequently for the first 30 days, then occasionally for the next 60 days, and after 90 days they are rarely accessed but must be retained for 7 years for compliance. The SysOps administrator wants to minimize storage costs while ensuring data is available when needed. Which S3 lifecycle policy configuration should be applied?

A.Transition objects to S3 Standard-IA after 30 days, and to S3 Glacier after 60 days. Delete after 7 years.
B.Transition objects to S3 Glacier Deep Archive after 30 days, and delete after 7 years.
C.Transition objects to S3 One Zone-IA after 30 days, and to S3 Glacier Deep Archive after 90 days. Delete after 7 years.
D.Transition objects to S3 Standard-IA after 30 days, and to S3 Glacier Deep Archive after 90 days. Delete after 7 years.
AnswerD

This lifecycle policy matches the access patterns: frequent access -> Standard-IA after 30 days, occasional access for next 60 days (still in IA), then rarely accessed -> Deep Archive after 90 days. Deep Archive is the lowest-cost storage option for long-term retention. Deleting after 7 years meets compliance. This is the most cost-effective configuration.

Why this answer

It aligns the lifecycle transitions with the access patterns: frequent access for the first 30 days (S3 Standard), occasional access for the next 60 days (S3 Standard-IA), and rare access after 90 days (S3 Glacier Deep Archive, the lowest-cost storage class for long-term retention). The deletion after 7 years meets compliance requirements while minimizing costs by using progressively cheaper storage classes.

Exam trap

The trap here is that candidates may choose Option A because they think S3 Glacier is the standard archival tier, but they overlook that S3 Glacier Deep Archive is cheaper for 7-year retention and that the occasional-access period (days 31–90) is better served by S3 Standard-IA, not S3 Glacier.

How to eliminate wrong answers

Option A is wrong because transitioning to S3 Glacier after 60 days (instead of 90) would incur unnecessary retrieval costs and slower access during the occasional-access period (days 31–90), and S3 Glacier is more expensive than S3 Glacier Deep Archive for long-term retention. Option B is wrong because moving directly to S3 Glacier Deep Archive after 30 days ignores the frequent-access period, causing high retrieval costs and latency for logs that are still accessed often. Option C is wrong because S3 One Zone-IA is not resilient to AZ failures and is unsuitable for compliance data that must be retained for 7 years; also, transitioning after 30 days to One Zone-IA does not match the occasional-access pattern (days 31–90) as well as Standard-IA.

469
MCQhard

A company runs a production Amazon DynamoDB table with provisioned capacity of 1000 write capacity units (WCU). The table experiences unpredictable spikes up to 2000 WCU, causing throttling. The SysOps administrator wants to minimize cost while handling the spikes. Which solution should be used?

A.Switch to on-demand capacity mode.
B.Increase provisioned WCU to 2000 to cover the peak.
C.Enable DynamoDB Auto Scaling with minimum 1000, maximum 2000 WCU.
D.Use a DynamoDB Accelerator (DAX) cache.
AnswerA

Switch to on-demand capacity mode: On-demand mode instantly accommodates usage spikes without requiring capacity planning or pre-provisioning. You pay per request, so there is no charge for unused provisioned capacity, making it highly cost-effective for unpredictable write traffic. It eliminates throttling errors because DynamoDB automatically scales write and read capacity to match your application's actual demand, even during sudden bursts.

Why this answer

Switching to on-demand capacity mode eliminates throttling during unpredictable spikes by automatically scaling write capacity up to the required 2000 WCU without any manual intervention or pre-provisioning. This minimizes cost because you pay only for the actual reads and writes consumed, avoiding the fixed cost of over-provisioning for peak capacity that may be rarely used.

Exam trap

The trap here is that candidates often choose DynamoDB Auto Scaling (Option C) thinking it handles spikes instantly, but they overlook the inherent scaling delay and the fact that it still requires a maximum capacity setting that may not cover sudden bursts, leading to throttling.

How to eliminate wrong answers

Option B is wrong because increasing provisioned WCU to 2000 permanently incurs higher base costs even during low-traffic periods, which contradicts the goal of minimizing cost. Option C is wrong because DynamoDB Auto Scaling adjusts capacity based on utilization metrics, but it cannot react instantly to sudden spikes up to 2000 WCU, leading to throttling during the scaling delay. Option D is wrong because DynamoDB Accelerator (DAX) is an in-memory cache that improves read performance, not write capacity, and does not address write throttling caused by insufficient WCU.

470
MCQhard

A SysOps administrator is troubleshooting an issue where an EC2 instance cannot access an S3 bucket using an instance profile. The instance profile has an IAM role with a policy that allows s3:GetObject on the bucket. The S3 bucket policy has a Deny for all principals except a specific service role. What is the most likely reason for the access failure?

A.The IAM role trust policy does not allow EC2 to assume the role.
B.The instance profile is not correctly attached to the EC2 instance.
C.The S3 bucket requires a VPC endpoint.
D.The S3 bucket policy Deny overrides the IAM role permissions.
AnswerD

When both an IAM role policy and a bucket policy apply to the same S3 request, AWS evaluates all identity-based and resource-based policies, and an explicit Deny in any applicable policy takes precedence over any Allow. In this scenario, the IAM role grants the s3:GetObject permission, but the S3 bucket policy contains a separate statement that explicitly denies the same action; the explicit Deny overrides the allow and causes the final authorization decision to be Deny AWS documentation confirms that explicit deny statements in resource policies are authoritative and cannot be overridden by any other allow. Therefore, the bucket policy Deny is the reason the EC2 instance cannot access the object.

Why this answer

An explicit Deny in an S3 bucket policy overrides any Allow permissions granted by IAM policies, including those from an instance profile role. In this scenario, the bucket policy denies access to all principals except a specific service role, so even though the IAM role attached to the EC2 instance allows s3:GetObject, the Deny takes precedence, causing access failure. Option A is incorrect because the issue is not about the trust policy; if the instance profile is attached, EC2 can assume the role.

Option B is incorrect because the instance profile attachment is not the likely cause; the Deny in the bucket policy would block access regardless. Option C is incorrect because a VPC endpoint is not required for S3 access and would not override the bucket policy Deny.

471
MCQhard

Refer to the exhibit. A SysOps administrator deployed the CloudFormation template. Which statement is true about data protection?

A.Deleted objects are immediately and permanently removed.
B.The bucket cannot be deleted by anyone.
C.Objects cannot be deleted from the bucket.
D.Deleted objects become noncurrent versions and are retained for 30 days.
AnswerD

Because versioning is enabled on the bucket, deleting an object creates a delete marker and the object's current version transitions to noncurrent status, rather than being destroyed. The lifecycle configuration specifies that noncurrent versions expire 30 days after they become noncurrent, at which point S3 permanently removes them. Consequently, deleted objects are retained for exactly 30 days before being purged, matching the behavior described in this option.

Why this answer

The CloudFormation template likely configures an S3 bucket with versioning enabled and a lifecycle policy that transitions noncurrent versions to the 'ExpiredObjectDeleteMarker' or retains them for a specified period. By default, when versioning is enabled, deleted objects are not permanently removed but become noncurrent versions, and the lifecycle rule can be set to permanently delete these noncurrent versions after 30 days, as indicated in the template.

Exam trap

The trap here is that candidates often confuse S3 versioning's behavior with standard (non-versioned) buckets, assuming that 'deleted' means 'permanently removed' immediately, or they overlook that lifecycle policies only apply to noncurrent versions and do not prevent direct deletion of objects.

How to eliminate wrong answers

Option A is wrong because with S3 versioning enabled, deleted objects are not immediately and permanently removed; they become noncurrent versions, and permanent removal only occurs after the lifecycle policy's expiration period or manual deletion of all versions. Option B is wrong because the bucket can be deleted by anyone with the appropriate IAM permissions (e.g., s3:DeleteBucket), and the template does not include a bucket policy or resource-based policy that explicitly denies deletion; the 'DeletionPolicy' attribute in CloudFormation (e.g., 'Retain') only protects the bucket from being deleted during stack deletion, not from direct API calls. Option C is wrong because objects can be deleted from the bucket when versioning is enabled; deletion creates a delete marker (for the current version) or permanently deletes a specific version ID, and the lifecycle policy does not prevent deletion—it only governs the expiration of noncurrent versions.

472
Multi-Selecthard

A SysOps administrator is investigating a performance issue where an Amazon RDS for MySQL instance's ReadIOPS metric is consistently high. The database is used by a web application. Which THREE actions should the administrator take to improve performance?

Select 3 answers
A.Increase the InnoDB buffer pool size to cache more data in memory.
B.Enable query caching in MySQL to avoid repeated reads of the same data.
C.Add read replicas to offload read queries from the primary instance.
D.Change the storage type to Provisioned IOPS for better performance.
E.Enable Multi-AZ deployment for high availability.
AnswersA, B, C

Increasing the InnoDB buffer pool size is a direct fix for high ReadIOPS because the buffer pool caches frequently accessed table and index pages in memory. When the pool is too small, pages are repeatedly evicted and must be fetched from disk, driving up read I/O. Enlarging the pool, typically to 75% of DB instance memory, raises the cache hit ratio and reduces disk reads for the working set.

Why this answer

Increasing the InnoDB buffer pool size allows more data and indexes to be cached in memory, reducing the need for disk reads and thus lowering ReadIOPS. This is a direct and effective tuning action for MySQL on RDS when read I/O is the bottleneck.

Exam trap

The trap here is that candidates often confuse Provisioned IOPS with reducing I/O demand, when it only improves I/O performance, and Multi-AZ with read scaling, when it is solely for failover and availability.

473
MCQhard

Refer to the exhibit. The security team wants to ensure that all objects uploaded to the S3 bucket 'my-secure-bucket' are encrypted at rest. Based on the CloudTrail log entry, what can be concluded about the object 'confidential.pdf'?

A.The object is encrypted with AWS KMS
B.The object is not encrypted
C.The object is encrypted with SSE-S3
D.The object was uploaded without an encryption header
AnswerC

The header value AES256 is the standard indicator for SSE-S3, where Amazon S3 manages the encryption keys entirely on your behalf. SSE-S3 uses the AES-256-GCM block cipher to encrypt objects at rest and provides automatic, transparent encryption with no additional cost or key management burden. The logged value matches this mode exactly, confirming that the object is encrypted with SSE-S3.

Why this answer

The CloudTrail log entry shows that the object 'confidential.pdf' was uploaded with the 'x-amz-server-side-encryption' header set to 'AES256'. This header indicates that server-side encryption with Amazon S3-managed keys (SSE-S3) was requested. The response also confirms that encryption was applied.

Therefore, the object is encrypted with SSE-S3, making option C correct. Option A is incorrect because the log does not mention KMS key details. Option B is incorrect because the object is encrypted.

Option D is incorrect because the encryption header was provided.

474
Multi-Selecteasy

A company wants to monitor the performance of its application running on EC2. Which TWO metrics should be monitored to detect performance bottlenecks? (Choose TWO.)

Select 2 answers
A.Network Packets In
B.CPU Utilization
C.Status Check Failed
D.Disk Space Utilization
E.Memory Utilization
AnswersB, E

CPU Utilization is a fundamental performance metric that shows the percentage of allocated EC2 compute capacity being consumed. Prolonged high CPU utilization indicates the application is compute-bound and may be reaching its processing limits, causing higher latency and reduced throughput. CloudWatch provides this metric by default, enabling quick identification of CPU bottlenecks. Setting alarms on CPU Utilization helps trigger scaling actions or performance tuning.

Why this answer

To detect performance bottlenecks on EC2, you should monitor CPU Utilization (B) and Memory Utilization (E). High CPU utilization indicates CPU-bound issues, while high memory utilization can cause swapping and degrade performance. Network Packets In (A) is a network metric but not typically a direct performance bottleneck indicator.

Status Check Failed (C) is for instance health, not performance. Disk Space Utilization (D) is a storage capacity metric, not a performance metric, and is not available by default (requires custom scripts).

475
MCQmedium

A company has an EC2-based application that runs at inconsistent times. The workloads are fault-tolerant and can be interrupted. Which purchasing option provides the most cost savings?

A.Reserved Instances
B.On-Demand Instances
C.Dedicated Hosts
D.Spot Instances
AnswerD

Spot Instances make unused EC2 capacity available at discounts of up to 90% compared to On-Demand prices, making them the cheapest option for fault-tolerant, stateless, or interruptible workloads. Because the workload is inconsistent and can accept interruptions, Spot's main risk (instances being reclaimed with a two-minute warning when EC2 needs capacity back) is not a blocker. You can launch and terminate Spot Instances elastically to match demand, and even use Spot Fleet triggers to replace reclaimed capacity, giving massive cost savings for this use case.

Why this answer

Spot Instances. Spot Instances offer the largest discount (up to 90%) for workloads that are fault-tolerant and can be interrupted. Reserved Instances (A) require a 1- or 3-year commitment and are best for steady-state workloads.

On-Demand Instances (B) provide no discount. Dedicated Hosts (C) are expensive and designed for specific licensing or compliance requirements, not cost savings.

476
MCQhard

A company has an AWS account with multiple VPCs connected via a transit gateway. The security team wants to centrally manage VPC security group rules and ensure compliance. Which approach is most effective?

A.Use AWS Firewall Manager to centrally define and enforce security group rules across all VPCs.
B.Create a single security group and attach it to all VPCs.
C.Define security group rules in AWS CloudFormation templates and deploy them to each VPC.
D.Use network ACLs instead of security groups for centralized management.
AnswerA

AWS Firewall Manager is the correct choice because it provides centrally managed security policies that automatically apply and enforce security group rules across all VPCs and accounts in an AWS Organization. It continuously audits compliance, automatically repairs non-compliant resources, and allows you to define common security group rules in one place, eliminating per-VPC manual updates while offering a single pane of glass for ongoing enforcement.

Why this answer

AWS Firewall Manager is the correct choice because it provides centralized administration of security group rules across multiple VPCs and accounts, enabling the security team to define a common set of rules and automatically enforce compliance. It integrates with AWS Organizations to apply policies to all VPCs in the organization, ensuring consistent security posture without manual intervention.

Exam trap

The trap here is that candidates may think CloudFormation or a single security group can achieve centralized management, but they overlook the cross-VPC scope limitation of security groups and the lack of automated enforcement and compliance monitoring in those approaches.

How to eliminate wrong answers

Option B is wrong because a single security group cannot be attached to resources in different VPCs; security groups are scoped to a single VPC and cannot span VPCs, even when connected via a transit gateway. Option C is wrong because while CloudFormation can deploy security group rules, it does not provide ongoing centralized enforcement or compliance monitoring; it requires manual updates and does not automatically detect or remediate drift. Option D is wrong because network ACLs are stateless and operate at the subnet level, not at the resource level like security groups, and AWS Firewall Manager does not support centralized management of network ACLs for security group rules.

477
MCQmedium

A SysOps administrator needs to ensure that all S3 buckets in the account have server access logging enabled. The administrator wants to be notified if a bucket is created without logging. What is the most efficient solution?

A.Periodically run a script to list all buckets and check logging configuration.
B.Enable S3 event notifications on the bucket creation event and trigger a Lambda function.
C.Use CloudWatch Events to detect CreateBucket API calls and trigger a Lambda function.
D.Use AWS Config with a managed rule to evaluate S3 buckets for server access logging.
AnswerD

AWS Config's managed rule for S3 server access logging continuously evaluates each bucket against the required logging configuration. When a bucket becomes non-compliant—whether created incorrectly or later misconfigured—AWS Config records the configuration change and can trigger notifications via SNS. This provides a real-time, auditable, and automated compliance check, exactly what an administrator needs for ongoing governance.

Why this answer

AWS Config with the managed rule 's3-bucket-server-access-logging-enabled' continuously evaluates all S3 buckets against the desired configuration. When a bucket is created without server access logging, AWS Config automatically flags it as noncompliant and can trigger an SNS notification. This is the most efficient solution because it provides ongoing, automated compliance monitoring without requiring custom scripts or event-driven remediation.

Exam trap

The trap here is that candidates confuse event-driven detection (CloudWatch Events or S3 event notifications) with continuous compliance evaluation, mistakenly believing that a single trigger at creation time is sufficient to meet the requirement of being notified if a bucket is created without logging.

How to eliminate wrong answers

Option A is wrong because periodically running a script is reactive, not proactive; it introduces latency between bucket creation and detection, and requires manual maintenance. Option B is wrong because S3 event notifications are triggered by object-level events (e.g., PUT, POST) within a bucket, not by the CreateBucket API call itself, so they cannot detect bucket creation. Option C is wrong because CloudWatch Events (now Amazon EventBridge) can detect CreateBucket API calls, but this approach only triggers a Lambda function at creation time; it does not provide ongoing compliance evaluation if logging is later disabled, and it requires custom code to check the logging configuration.

478
MCQmedium

A company has deployed an Application Load Balancer (ALB) in a VPC. The ALB is configured with a target group pointing to EC2 instances in a private subnet. Clients receive HTTP 503 errors. What is the likely cause?

A.The ALB does not have an Elastic IP address.
B.The security group for the ALB does not allow inbound HTTP traffic.
C.The target instances are unhealthy and the target group has zero healthy hosts.
D.The route table for the private subnet does not have a route to the ALB.
AnswerC

A 503 Service Unavailable response is returned by the ALB when its target group contains zero healthy hosts, meaning all registered target instances have failed their configured health checks. The ALB cannot forward the request to any instance, so it returns 503 to the client. This is the only condition among the options that directly explains the error, as it happens at the ALB's request-routing layer after the listener accepts the traffic.

Why this answer

HTTP 503 errors from an Application Load Balancer indicate that the target group has no healthy registered targets to forward traffic to. When all EC2 instances in the target group are unhealthy (e.g., failing health checks), the ALB cannot route requests, resulting in a 503 response. This is the most common cause of 503 errors in ALB deployments.

Exam trap

The trap here is that candidates often confuse HTTP 503 (service unavailable due to no healthy targets) with HTTP 504 (gateway timeout) or assume the issue is with the ALB's own configuration, such as security groups or IP addressing, rather than focusing on the health of the target instances.

How to eliminate wrong answers

Option A is wrong because ALBs do not require Elastic IP addresses; they are internet-facing or internal and use DNS names, not static IPs. Option B is wrong because the security group for the ALB controls inbound traffic to the ALB itself, but HTTP 503 errors occur after the ALB accepts the request and fails to find healthy targets; if inbound HTTP were blocked, clients would receive a 504 or timeout, not a 503. Option D is wrong because the route table for the private subnet does not need a route to the ALB; the ALB communicates with targets via their private IPs within the VPC, and traffic flows through the VPC's internal routing, not via a route to the ALB.

479
MCQhard

A company uses AWS Lambda functions to process messages from an SQS queue. The Lambda function is configured with a reserved concurrency of 100. The SQS queue receives unpredictable spikes of up to 10,000 messages per second. The function takes about 1 second to process a message. The SysOps team notices that during spikes, messages are being throttled and appear in the DLQ. How can the team resolve this while optimizing cost?

A.Reduce the reserved concurrency to 10 to force the function to process messages more slowly.
B.Increase reserved concurrency to 1000 and enable batch processing with a batch size of 10 in the SQS event source mapping.
C.Provision an EC2 fleet to poll the SQS queue and invoke the Lambda function.
D.Increase the Lambda function memory and timeout to use a larger instance type.
AnswerB

Increasing reserved concurrency to 1000 allows AWS Lambda to scale out to handle a high volume of SQS messages without throttling, as the event source mapping automatically exercises up to that concurrency. Setting a batch size of 10 instructs the SQS event source to deliver up to 10 records per Lambda invocation, reducing the total number of invocations and overhead while dramatically improving throughput. This is the recommended pattern for processing large SQS workloads in a serverless architecture.

Why this answer

Increasing reserved concurrency to 1000 allows the Lambda function to scale to handle the spike of 10,000 messages per second, and enabling batch processing with a batch size of 10 reduces the number of invocations, which optimizes cost by processing up to 10 messages per invocation instead of one. Option A is wrong because reducing reserved concurrency would throttle even more messages, increasing DLQ traffic. Option C is wrong because using EC2 adds operational overhead and does not leverage Lambda's serverless scaling, increasing complexity and cost.

Option D is wrong because Lambda does not use instance types; memory and timeout adjustments do not directly address concurrency limitations or batch processing.

480
MCQeasy

A SysOps administrator needs to monitor the memory utilization of an EC2 instance running Amazon Linux 2. Which of the following is required to publish memory metrics to CloudWatch?

A.Use the CloudWatch Logs agent to parse memory usage from system logs.
B.Install and configure the CloudWatch agent on the instance.
C.Enable detailed monitoring on the instance.
D.Install the AWS Systems Manager Agent (SSM Agent) and configure it to send metrics.
AnswerB

The unified CloudWatch agent collects in-guest operating system metrics, including memory utilization, and publishes them as custom metrics to CloudWatch using PutMetricData. Once configured with the amazon-cloudwatch-agent-config-wizard or an SSM parameter, it reports values such as mem_used_percent and mem_available_percent at a set interval. This is the standard, fully supported solution for EC2 and on-premises memory monitoring.

Why this answer

The CloudWatch agent is specifically designed to collect custom metrics, such as memory utilization, from EC2 instances and publish them to CloudWatch. Unlike the default EC2 monitoring, which only captures hypervisor-level metrics (CPU, network, disk), memory utilization requires an in-guest agent to read from the operating system's /proc/meminfo or similar interfaces. The CloudWatch agent can be configured via a JSON file to collect memory metrics and send them to CloudWatch using the PutMetricData API.

Exam trap

The trap here is that candidates confuse 'detailed monitoring' (which increases frequency of existing hypervisor metrics) with the ability to collect in-guest metrics, or they assume the SSM Agent or CloudWatch Logs agent can perform metric collection, when only the CloudWatch agent is designed for that purpose.

How to eliminate wrong answers

Option A is wrong because the CloudWatch Logs agent is used to send log data to CloudWatch Logs, not to parse and publish custom metrics like memory utilization to CloudWatch Metrics. Option C is wrong because enabling detailed monitoring only increases the frequency of standard EC2 metrics (e.g., CPU, disk I/O) from 5 minutes to 1 minute; it does not enable collection of in-guest metrics such as memory. Option D is wrong because the SSM Agent is used for Systems Manager features like Run Command, Patch Manager, and Inventory, not for publishing custom metrics to CloudWatch; it lacks the metric collection and publishing capabilities of the CloudWatch agent.

481
Multi-Selecthard

Which TWO options are valid ways to send custom metrics to Amazon CloudWatch?

Select 2 answers
A.Use the CloudWatch agent to collect and publish custom metrics.
B.Use the PutMetricData API call.
C.Use Amazon SQS to send metric data to CloudWatch.
D.Use AWS CloudTrail to log custom metrics.
E.Use Amazon Kinesis Data Firehose to deliver metrics to CloudWatch.
AnswersA, B

The CloudWatch agent is a daemon that runs on EC2 instances or on-premises servers and collects operating system-level metrics such as memory usage, disk space, and CPU utilization, as well as custom application metrics via the StatsD and collectd protocols. It is configured locally or through AWS Systems Manager Parameter Store and publishes the collected data to CloudWatch by internally invoking the PutMetricData API. This is a native, fully supported method for publishing custom metrics without having to write application code.

Why this answer

The CloudWatch agent can be installed on EC2 instances or on-premises servers to collect system-level metrics (like memory and disk usage) and custom application metrics, then publish them to CloudWatch. Option B is correct because the PutMetricData API call allows direct programmatic ingestion of custom metrics into CloudWatch, supporting up to 1,000 metrics per call with a maximum payload of 1 MB.

Exam trap

The trap here is that candidates may think SQS or Kinesis Data Firehose can natively push data to CloudWatch, but neither service has a direct integration for custom metric ingestion—only PutMetricData or the CloudWatch agent (which uses that API) are valid methods.

482
MCQhard

A company is running a critical application on Amazon RDS for MySQL. The database is experiencing high read traffic, causing performance issues. The SysOps administrator needs to improve read performance while keeping costs low. Which solution should the administrator choose?

A.Enable Multi-AZ deployment
B.Increase the DB instance class to a larger size
C.Use Amazon ElastiCache to cache read results
D.Add one or more Read Replicas in the same Region
AnswerD

Adding one or more Read Replicas in the same Region creates independent, actively readable database copies that serve SELECT traffic, leaving the primary free to handle writes. Because the replicas stay in the same Region, you avoid inter-Region data transfer charges, and you can select smaller instance classes for the replicas to closely match the read-only workload. This horizontal scaling approach is cost-efficient because you add capacity only for the traffic that needs it, and it also preserves the primary's performance for the write-heavy portion of the workload.

Why this answer

Adding one or more Read Replicas in the same Region offloads read traffic from the primary RDS instance by directing SELECT queries to the replicas, which are asynchronous copies of the primary. This directly addresses high read traffic without incurring the cost of a larger instance or the complexity of caching, making it the most cost-effective solution for read scaling.

Exam trap

The trap here is confusing Multi-AZ (high availability) with read scaling, leading candidates to select Option A, which does not improve read performance because the standby replica is not accessible for reads.

How to eliminate wrong answers

Option A is wrong because Multi-AZ deployment provides high availability and automatic failover, not read scaling; the standby replica cannot serve read traffic. Option B is wrong because increasing the DB instance class improves both read and write performance but is more expensive than adding Read Replicas, which scale reads horizontally at lower cost. Option C is wrong because while ElastiCache can cache read results, it requires additional infrastructure, application code changes, and cache invalidation logic, making it less straightforward and potentially more costly than Read Replicas for this specific database read workload.

483
MCQmedium

A SysOps team is using CloudWatch to monitor CPU utilization of EC2 instances. They want to receive a notification when average CPU exceeds 80% for 5 consecutive minutes. Which combination of services should they use?

A.CloudWatch Metrics, CloudWatch Alarm, and AWS Lambda
B.AWS Config, CloudWatch Alarm, and Amazon SNS
C.CloudWatch Metrics, CloudWatch Alarm, and Amazon SNS
D.CloudWatch Logs, CloudWatch Alarm, and AWS Lambda
AnswerC

Amazon EC2 automatically publishes CPUUtilization to the AWS/EC2 namespace in CloudWatch Metrics, providing the data source for evaluation. A CloudWatch Alarm continuously compares the metric against a threshold over a specified period and transitions between OK, ALARM, and INSUFFICIENT_DATA states. When the alarm enters ALARM, it invokes an action that publishes a message to an Amazon SNS topic, which then delivers notifications through endpoints such as email, SMS, or HTTP. This is the standard, minimal pattern for metric-based alerting.

Why this answer

CloudWatch Metrics collects the CPU utilization data from EC2 instances, a CloudWatch Alarm evaluates whether the average CPU exceeds 80% for 5 consecutive minutes (using a period of 300 seconds and 5 datapoints), and Amazon SNS publishes the notification to subscribers (e.g., email, SMS) when the alarm state transitions to ALARM. This combination directly fulfills the requirement without unnecessary services.

Exam trap

The trap here is that candidates often confuse CloudWatch Logs with CloudWatch Metrics, assuming logs can be used for metric-based alarms, or they overcomplicate the solution by adding Lambda when SNS alone is sufficient for notification.

How to eliminate wrong answers

Option A is wrong because AWS Lambda is not required for simple alarm-based notifications; SNS alone handles the notification, and adding Lambda introduces unnecessary complexity and cost. Option B is wrong because AWS Config is a configuration auditing and compliance service, not a monitoring or metric collection service; it cannot provide CPU utilization metrics. Option D is wrong because CloudWatch Logs is for storing and analyzing log data, not for collecting or evaluating CPU utilization metrics; CPU utilization is a metric, not a log event.

484
MCQmedium

A company's security team notices that an IAM user has access keys that have not been rotated in over a year. Which action should the SysOps administrator take to enforce key rotation automatically?

A.Set up an AWS Config rule to detect old keys and trigger an AWS Lambda function to rotate them.
B.Apply a service control policy (SCP) that requires key rotation.
C.Configure an IAM policy that automatically rotates keys every 90 days.
D.Use AWS Trusted Advisor to automatically rotate the keys.
AnswerA

This is the correct automated approach: AWS Config evaluates IAM access keys against a managed rule such as iam-user-access-key-age, and when a key exceeds the defined maximum age, Config triggers an AWS Lambda function as a remediation action. The Lambda function programmatically rotates the key—creating a new access key, updating or notifying the user, and retiring/deleting the old one—using IAM APIs without manual intervention.

Why this answer

AWS Config can evaluate IAM user access keys against a custom or managed rule (e.g., 'access-keys-rotated') to detect keys older than a specified threshold. When a non-compliant key is found, you can configure an AWS Config rule to invoke an AWS Lambda function that programmatically deactivates the old key and creates a new one, enforcing automatic rotation. This is the only native, automated approach that combines detection and remediation without manual intervention.

Exam trap

The trap here is that candidates confuse AWS Config's evaluation and remediation capabilities with IAM policies or Trusted Advisor, assuming those services can perform automated actions when they only provide static controls or recommendations.

How to eliminate wrong answers

Option B is wrong because service control policies (SCPs) are used to define permission boundaries for AWS Organizations accounts and cannot enforce or trigger key rotation actions—they only allow or deny API calls. Option C is wrong because IAM policies are static permission documents that cannot perform automated actions like rotating keys; they only define what actions are allowed or denied. Option D is wrong because AWS Trusted Advisor provides security checks and recommendations but does not have the capability to automatically rotate keys—it only alerts you to non-rotated keys.

485
MCQmedium

A SysOps administrator is troubleshooting a failed AWS CloudFormation stack update. The error message indicates that a resource failed to create due to insufficient IAM permissions. The administrator used a service role for CloudFormation. What should the administrator do to resolve the issue?

A.Add the required permissions to the administrator's IAM user.
B.Request a limit increase for IAM roles in the AWS account.
C.Update the IAM policy attached to the CloudFormation service role to include the necessary permissions.
D.Modify the resource's IAM policy to allow CloudFormation to create it.
AnswerC

The CloudFormation service role must have a permissions policy that explicitly grants the actions needed to create, update, and delete the stack's resources, because CloudFormation assumes this role to make those API calls on your behalf. Editing the role's IAM policy to include the required permissions, such as the relevant ec2:* or s3:* actions (or a narrowly scoped set), will allow the stack operation to proceed. This is the correct remedy because the service role's trust policy already permits CloudFormation to assume it; the missing piece is the authorization for the resource operations.

Why this answer

When CloudFormation assumes a service role to perform stack operations, all API calls made on behalf of the stack use that role's permissions — not the administrator's user permissions. The fix is to attach or update the IAM policy on the CloudFormation service role to grant the missing permissions (e.g., ec2:CreateInstance, s3:CreateBucket). This is the least-privilege, correct remediation.

Exam trap

SOA-C02 often tests whether candidates understand that CloudFormation uses the SERVICE ROLE's permissions, not the invoking user's — the trap is picking 'add permissions to my IAM user' out of habit.

How to eliminate wrong answers

Option A is wrong because adding permissions to the administrator's IAM user has no effect — CloudFormation is acting under the service role, not the user's credentials, so the user's permissions are irrelevant to the stack operation. Option B is wrong because the error is a permissions (authorization) failure, not a service quota/limit issue; requesting a limit increase for IAM roles does not grant the missing actions. Option D is wrong because modifying the resource's own IAM policy is backwards — the resource does not yet exist (it failed to create), and even if it did, the blocker is the CALLER's (CloudFormation service role's) permission to create it, not the resource's policy.

486
MCQeasy

A company has an Amazon S3 bucket that stores critical data. The security team wants to be notified whenever an object in the bucket is deleted. Which solution should the SysOps administrator implement?

A.Configure an S3 event notification for 's3:ObjectRemoved:*' events to trigger an AWS Lambda function that sends an email.
B.Enable CloudTrail data events for the S3 bucket, create a CloudWatch Events rule for 'DeleteObject' API calls, and send notifications via SNS.
C.Use AWS Config to monitor S3 bucket resources and trigger an SNS notification on configuration changes.
D.Enable S3 server access logs and use Amazon Athena to query for delete events, then send notifications.
AnswerB

CloudTrail data events are the only option here that records object-level API calls (DeleteObject, DeleteObjects) in the S3 bucket, and each event includes the caller's IAM identity, source IP, user agent, and timestamp. By configuring a CloudWatch Events rule that matches the s3.amazonaws.com service with the DeleteObject event name, you get near-real-time alerts delivered through an SNS topic. This provides both a complete audit trail for forensic investigation and immediate operational notification, satisfying the requirement to know who deleted what, when, and from where.

Why this answer

It uses CloudTrail data events to capture 'DeleteObject' API calls specifically for the S3 bucket, then routes those events via CloudWatch Events to an SNS topic for notification. This provides a reliable, real-time notification mechanism for object deletions without requiring custom code or post-hoc analysis.

Exam trap

The trap here is that candidates often assume S3 event notifications are sufficient for all object operations, but they do not provide detailed API call information or integrate natively with CloudWatch Events for centralized monitoring and alerting. CloudTrail data events capture every DeleteObject API call with full request details, enabling robust alerting.

How to eliminate wrong answers

Option A is wrong because S3 event notifications for 's3:ObjectRemoved:*' are triggered asynchronously and may not capture all delete scenarios (e.g., versioned object deletions or MFA delete failures), and they require a Lambda function to send email, adding complexity and potential failure points. Option C is wrong because AWS Config monitors configuration changes to the bucket itself (e.g., policy changes), not object-level operations like deletions, so it cannot detect object deletion events. Option D is wrong because S3 server access logs are delivered on a best-effort basis with potential delays (often hours), and querying with Athena is a reactive, post-hoc approach that does not provide real-time notifications.

487
MCQmedium

An application running on EC2 instances stores session data in an attached EBS volume. The company wants to ensure session data is not lost if an instance fails. Which solution should the administrator implement?

A.Move session storage to Amazon ElastiCache for Redis with replication.
B.Use EBS Multi-Attach to attach the volume to multiple instances.
C.Take frequent EBS snapshots of the volume.
D.Use a larger EC2 instance type with more memory.
AnswerA

ElastiCache for Redis with replication provides a highly available, in-memory session store that is accessible from all EC2 instances. By using Multi-AZ replication, Redis automatically fails over to a replica if the primary node fails, so session data remains available. You can also enable append-only file persistence to guard against data loss, making it a robust and widely used pattern for storing session state in distributed applications.

Why this answer

Amazon ElastiCache for Redis with replication provides a highly available, in-memory data store that persists session data independently of EC2 instances. If an instance fails, the session data remains intact in the replicated Redis cluster, ensuring zero data loss and seamless failover. This decouples session state from ephemeral compute resources, aligning with the reliability and business continuity requirements.

Exam trap

The trap here is that candidates often assume EBS snapshots or Multi-Attach provide real-time session durability, but they fail to recognize that session data is ephemeral and requires a separate, highly available data store like ElastiCache to survive instance failures without data loss.

How to eliminate wrong answers

Option B is wrong because EBS Multi-Attach only supports io1/io2 volumes and is limited to a single Availability Zone; it does not provide cross-instance failover or protect against instance failure, as all attached instances share the same underlying storage and would all lose access if the volume fails. Option C is wrong because frequent EBS snapshots are point-in-time backups stored in Amazon S3, not real-time session storage; restoring from a snapshot would lose any session data written after the last snapshot and introduces significant downtime. Option D is wrong because using a larger EC2 instance type with more memory only increases the capacity for in-memory session data on that single instance; if the instance fails, all session data in memory is lost, regardless of instance size.

488
MCQhard

A company has a VPC with public and private subnets. The private subnets host application servers that need to make outbound HTTPS connections to the internet. The SysOps administrator must implement a solution that provides outbound internet connectivity while preventing inbound connections from the internet. Additionally, the solution must allow the company to control which domains the application servers can access. Which solution should the administrator implement?

A.Configure a NAT Gateway and use security group outbound rules to restrict destinations.
B.Configure a NAT instance with proxy software and use route tables to direct traffic from private subnets to the NAT instance.
C.Configure an egress-only Internet Gateway and route private subnet traffic to it.
D.Configure a VPC endpoint for HTTPS and route private subnet traffic to it.
AnswerB

A NAT instance is an Amazon EC2 instance that performs source network address translation for instances in private subnets, and it can be configured with proxy software such as Squid to enable domain-level access control. By running a proxy, the NAT instance can terminate HTTP/HTTPS requests, inspect the requested DNS names, and apply allow/deny policies based on those names—something security groups and NAT Gateways cannot do. You direct traffic from private subnets to the NAT instance by adding a route in the private route tables that points 0.0.0.0/0 to the instance ID; the proxy software then provides the required domain filtering while still blocking unsolicited inbound connections.

Why this answer

A NAT instance with proxy software (e.g., Squid) allows outbound HTTPS connections from private subnets while blocking inbound connections, and the proxy software can enforce domain-level access control via allow/deny lists. This meets the requirement to restrict which domains the application servers can access, which a standard NAT Gateway cannot do because it only translates IP addresses and cannot filter by domain name.

Exam trap

The trap here is that candidates often assume a NAT Gateway with security group rules can control domain access, but security groups cannot filter by domain name—only by IP address—so the proxy-based NAT instance is required for domain-level restriction.

How to eliminate wrong answers

Option A is wrong because a NAT Gateway translates private IPs to a public IP for outbound traffic, but security group outbound rules can only filter by IP address or CIDR, not by domain name, so it cannot control which domains are accessed. Option C is wrong because an egress-only Internet Gateway is used for IPv6 traffic only, and the question does not specify IPv6; it also cannot filter by domain. Option D is wrong because a VPC endpoint for HTTPS (e.g., interface endpoint) provides private connectivity to specific AWS services (like S3 or DynamoDB) via AWS PrivateLink, not general internet access, and cannot route traffic to arbitrary internet domains.

489
MCQeasy

A company has an Auto Scaling group of EC2 instances behind an Application Load Balancer. The SysOps administrator notices that the healthy host count is lower than expected. The instances are in service, and security groups allow traffic. What is a likely cause?

A.The instances are not registered with the target group.
B.The security group for the load balancer does not allow inbound traffic.
C.The health check path is returning HTTP 503.
D.The target group is not associated with the load balancer.
AnswerC

An HTTP 503 Service Unavailable response from the health check endpoint indicates the target is reachable but the application cannot serve the request. Elastic Load Balancing health checks treat any non-2xx or non-3xx status code as unhealthy, so a 503 will cause the instance to be deregistered from service. This is a common issue when the health check path points to a resource that requires authentication or returns an error when the backend is overloaded.

Why this answer

A health check path returning HTTP 503 (Service Unavailable) indicates that the target instances are reachable but the application is failing to respond correctly. The Application Load Balancer (ALB) marks instances as unhealthy when the health check receives any non-2xx or non-3xx response, which reduces the healthy host count even though the instances are in service and security groups are properly configured.

Exam trap

The trap here is that candidates often assume a low healthy host count is always due to network-level issues (security groups or registration), but the question explicitly states instances are 'in service' and security groups allow traffic, pointing to an application-level health check failure like a 503 response.

How to eliminate wrong answers

Option A is wrong because instances that are 'in service' in the Auto Scaling group are automatically registered with the target group when the group is associated with the ALB; if they were not registered, they would not appear as 'in service'. Option B is wrong because the security group for the load balancer controls inbound traffic from clients, not health check traffic from the load balancer to instances; health check traffic is governed by the instance security group allowing traffic from the load balancer's security group or CIDR. Option D is wrong because if the target group were not associated with the load balancer, the instances would not be receiving traffic from the ALB at all, and the healthy host count would be zero or the target group would not appear in the ALB configuration.

490
MCQhard

A SysOps administrator is troubleshooting a slow-running RDS MySQL instance. The administrator notices that the ReadIOPS metric is consistently high, but the WriteIOPS is low. The instance type is db.m5.large with 300 GB of General Purpose SSD (gp2). What is the most likely cause?

A.The instance type is too small for the workload.
B.The database is experiencing write contention.
C.The network bandwidth is insufficient.
D.The gp2 volume is experiencing I/O credit exhaustion.
AnswerD

Correct: a gp2 volume has a baseline of 3 IOPS per GiB and can burst to 3,000 IOPS by consuming I/O credits stored in a bucket. Once the BurstBalance reaches zero, the volume is hard-throttled to the baseline rate, which would make the database appear 'slow running.' The fix is to increase volume size (raising baseline), migrate to gp3, or enable Provisioned IOPS.

Why this answer

A db.m5.large instance with 300 GB of gp2 storage has a baseline IOPS of 900 (3 IOPS per GB) and a burst balance of 5.4 million I/O credits. With consistently high ReadIOPS and low WriteIOPS, the volume is likely exhausting its I/O credit balance, causing performance throttling. This is a classic symptom of gp2 I/O credit exhaustion, where read-heavy workloads deplete the burst bucket, leading to degraded performance.

Exam trap

The trap here is that candidates often assume a slow database is always due to an undersized instance type, overlooking that gp2 volumes have a burst credit mechanism that can be exhausted by sustained high read I/O even with low write activity.

How to eliminate wrong answers

Option A is wrong because the instance type (db.m5.large) is not the primary bottleneck; the issue is with the storage layer's I/O credits, not compute or memory. Option B is wrong because write contention would manifest as high WriteIOPS or increased latency on writes, but the metric shows low WriteIOPS, indicating writes are not the problem. Option C is wrong because network bandwidth is unrelated to storage I/O metrics; insufficient bandwidth would cause network latency or throughput issues, not high ReadIOPS on the EBS volume.

491
MCQeasy

A company uses AWS CloudFormation to deploy a VPC with public and private subnets. The stack creation fails with the error 'The maximum number of VPCs has been reached.' The SysOps administrator needs to deploy the stack as soon as possible. What should the administrator do?

A.Delete unused VPCs to free up capacity.
B.Modify the CloudFormation template to use an existing VPC.
C.Request a VPC limit increase from AWS Support.
D.Deploy the stack in a different AWS region.
AnswerC

The default VPC quota is 5 VPCs per region per account, and this is a soft limit that can be increased by requesting a quota raise through the AWS Service Quotas console or by opening an AWS Support case. Once AWS approves the increase, you can deploy the CloudFormation stack normally, making this the correct and scalable fix. Remember that the increase applies to the specific Region you request it for, so you should confirm the target Region.

Why this answer

The error 'The maximum number of VPCs has been reached' indicates the AWS account has hit the default VPC limit (5 per region). Requesting a service limit increase from AWS Support is the fastest way to raise this soft limit without modifying existing infrastructure or templates, allowing the stack to deploy in the same region.

Exam trap

The trap here is that candidates may choose to delete unused VPCs (Option A) thinking it's faster, but AWS Support limit increases are often quicker and safer than auditing and deleting resources, especially in production environments.

How to eliminate wrong answers

Option A is wrong because deleting unused VPCs is an alternative but may not be the fastest solution if no VPCs are truly unused, and it requires identifying and safely removing resources, which could delay deployment. Option B is wrong because modifying the CloudFormation template to use an existing VPC changes the architecture and may not meet the requirement for deploying a new VPC as specified in the question. Option D is wrong because deploying in a different region may avoid the limit but introduces latency, compliance, or service availability issues, and is not the most direct fix for a soft limit that can be increased.

492
MCQhard

A company has a VPC with public and private subnets in two Availability Zones. An Application Load Balancer (ALB) in the public subnets routes traffic to EC2 instances in the private subnets. The EC2 instances need to access the internet for software updates. Which solution is MOST secure and cost-effective?

A.Deploy a NAT Gateway in a public subnet and add a route in the private subnet route tables pointing 0.0.0.0/0 to the NAT Gateway.
B.Set up a VPN connection to an on-premises network and route internet traffic through it.
C.Assign public IP addresses to the EC2 instances and route traffic directly.
D.Attach an internet gateway to the private subnets and route 0.0.0.0/0 to it.
AnswerA

A NAT Gateway is a managed service placed in a public subnet with an Elastic IP, and by adding a route for 0.0.0.0/0 in the private subnet route tables that targets the NAT Gateway, instances receive outbound internet access for tasks like software updates while remaining completely unreachable from the internet. This is the secure and correct design because the NAT Gateway performs stateful address translation, only allowing responses to initiated outbound connections, and it scales automatically without requiring you to manage a separate instance.

Why this answer

A NAT Gateway in a public subnet allows EC2 instances in private subnets to initiate outbound connections to the internet (e.g., for software updates) while preventing inbound connections from the internet. This is the most secure and cost-effective solution because it uses a managed AWS service that scales automatically and incurs charges only for usage and hourly uptime, avoiding the need for a bastion host or VPN.

Exam trap

The trap here is that candidates often confuse NAT Gateways with Internet Gateways, assuming an IGW can be attached to private subnets, or they overlook that assigning public IPs to private instances breaks the subnet's isolation and security model.

How to eliminate wrong answers

Option B is wrong because routing internet traffic through a VPN to an on-premises network adds unnecessary latency, complexity, and cost (e.g., VPN connection charges, bandwidth costs) and is not designed for general internet access—it is intended for hybrid connectivity. Option C is wrong because assigning public IP addresses to EC2 instances in private subnets exposes them directly to the internet, violating the security principle of private subnets and increasing the attack surface; it also requires managing Elastic IPs and security groups. Option D is wrong because an internet gateway (IGW) cannot be attached to private subnets—IGWs are attached to VPCs and route traffic only from subnets with route tables pointing to the IGW; attaching an IGW to a private subnet would require making the subnet public, defeating its purpose.

493
MCQmedium

A company uses AWS CodePipeline to automate deployments. The pipeline has a source stage that pulls code from an Amazon S3 bucket. The company wants to automatically trigger the pipeline when a new object is uploaded to the S3 bucket. How should this be configured?

A.Configure a CloudWatch Events rule that matches S3 object creation events and triggers the pipeline.
B.Use an AWS Lambda function to poll the S3 bucket and start the pipeline.
C.Configure the S3 bucket to send events to an Amazon SNS topic that triggers the pipeline.
D.Configure the S3 bucket to send events to an Amazon SQS queue that triggers the pipeline.
AnswerA

CloudWatch Events (now integrated with Amazon EventBridge) natively supports CodePipeline as a target, so you can create a rule with an event pattern for s3:ObjectCreated:* from the source bucket. When the S3 object is created, the event is matched and CodePipeline automatically starts an execution without any polling, custom code, or intermediary services, making this the fully event-driven and direct solution.

Why this answer

Configuring a CloudWatch Events (now Amazon EventBridge) rule that matches S3 object creation events and triggers the pipeline is the correct approach. EventBridge can directly target CodePipeline as a target, enabling automatic pipeline execution when a new object is uploaded to the S3 bucket. This is the native, serverless integration for event-driven pipelines.

Exam trap

SOA-C02 often tests the misconception that SNS or SQS can directly trigger CodePipeline — candidates must know that EventBridge (CloudWatch Events) is the service that can target CodePipeline directly.

How to eliminate wrong answers

Option B is wrong because polling with Lambda is inefficient, introduces latency, and is not the recommended event-driven pattern. Option C is wrong because SNS cannot directly trigger CodePipeline; it would require an intermediary (e.g., Lambda) and is not the most direct method. Option D is wrong because SQS also cannot directly trigger CodePipeline and would require additional components, adding complexity.

494
MCQeasy

A SysOps administrator manages a web application running on Amazon EC2 instances that run 24/7 for the next 12 months. The workload is steady and predictable. Which EC2 purchasing option provides the highest cost savings for this use case?

A.Standard Reserved Instances
B.Spot Instances
C.On-Demand Instances
D.Savings Plans (Compute)
AnswerA

Standard Reserved Instances are ideal for a steady, predictable 24/7 workload because they offer the deepest discount, up to 72% compared to On-Demand, when you commit to a 1-year or 3-year term. You can choose All Upfront, Partial Upfront, or No Upfront payment options, which further optimize cash flow while locking in the lowest hourly rate for a specific instance family and region. For a workload that runs continuously without interruption, this commitment maximizes cost savings while guaranteeing capacity, making it the most economical choice.

Why this answer

Standard Reserved Instances provide the highest cost savings for a steady, predictable 24/7 workload over a 12-month period because they offer a significant discount (up to 72% compared to On-Demand) in exchange for a commitment to a specific instance family, region, and term length. Since the workload runs continuously without interruption, the upfront payment or partial upfront payment for a 1-year term maximizes savings without the risk of interruption or the need for flexibility.

Exam trap

The trap here is that candidates often choose Savings Plans (Compute) because they offer flexibility across instance families, but for a predictable, steady-state workload with a fixed instance type, Standard Reserved Instances provide the highest discount and capacity guarantee, making them the optimal choice for cost savings.

How to eliminate wrong answers

Option B is wrong because Spot Instances are designed for fault-tolerant, flexible workloads that can handle interruptions, not for a steady 24/7 production web application that requires reliability. Option C is wrong because On-Demand Instances offer no upfront commitment but have the highest per-hour cost, making them the least cost-effective for a predictable, always-on workload. Option D is wrong because Savings Plans (Compute) provide flexibility across instance families and regions but typically offer slightly lower discounts than Standard Reserved Instances for a specific, steady-state workload with a known instance type and region.

495
MCQmedium

A company uses AWS CodeBuild to compile code and run unit tests. The build environment requires a specific version of Java that is not available in the default build images. What should the administrator do?

A.Request AWS Support to add the Java version to the default build image.
B.Use an AWS Lambda function to set up the build environment before CodeBuild runs.
C.Install the required Java version in the buildspec file using a command.
D.Create a custom build image with the required Java version and push it to Amazon ECR.
AnswerD

Creating a custom build image and pushing it to Amazon ECR lets you pre-install the exact Java JDK version (e.g., OpenJDK 17.0.9) along with any required build tools and system libraries. CodeBuild then uses that image as the environment baseline, so every build start from a consistent, immutable configuration. This approach supports image tagging and version rollback, and it eliminates the need for runtime package installation in the buildspec.

Why this answer

CodeBuild allows you to specify a custom Docker image for the build environment, which can include any required software such as a specific Java version. By creating a custom image, installing the needed Java version, and pushing it to Amazon ECR, the administrator ensures the build environment meets the exact requirements. This approach is flexible and repeatable, and CodeBuild natively supports pulling images from ECR.

Exam trap

SOA-C02 often tests the misconception that buildspec commands can fully customize the environment, but the exam expects knowledge that custom images are the proper solution for specific runtime versions.

How to eliminate wrong answers

Option A is wrong because AWS Support cannot modify default build images; these are managed by AWS and not customizable per customer request. Option B is wrong because AWS Lambda cannot modify the build environment of CodeBuild; Lambda runs separately and cannot inject software into the CodeBuild container before the build starts. Option C is wrong because while you can install software in the buildspec, it is inefficient and may not persist across phases; moreover, installing Java during the build can be slow and may not be possible if the base image lacks necessary package managers or permissions.

496
MCQeasy

A company hosts a static website on Amazon S3 with public read access enabled. The website is accessed via a custom domain name that uses Amazon Route 53. The domain name points to the S3 bucket's website endpoint. Users report that they can access the website using the S3 bucket URL but not the custom domain name. What is the most likely cause?

A.The S3 bucket policy does not allow public access.
B.The website does not support HTTPS and the browser blocks it.
C.The Route 53 alias record points to the S3 bucket's regional endpoint instead of the website endpoint.
D.The DNS TTL is too long and the changes have not propagated.
AnswerC

The S3 bucket has two distinct endpoints: the REST API endpoint (bucket-name.s3.amazonaws.com) and the static website endpoint (bucket-name.s3-website-region.amazonaws.com). For a custom domain to serve your static website, the Route 53 alias record must target the website endpoint, because that endpoint processes requests with the Host header matching the custom domain and returns the index document. If the alias record mistakenly points to the REST endpoint, the request is handled by the S3 API, which expects path-style addressing and returns a 403 Forbidden or a connection error when it receives a Host header for a custom domain. This is the classic misconfiguration that prevents the website from appearing.

Why this answer

For an S3 static website behind a custom domain, the Route 53 alias record must point to the bucket's S3 website endpoint (for example, bucket.s3-website-us-east-1.amazonaws.com), not the regional REST endpoint (bucket.s3.us-east-1.amazonaws.com). The regional endpoint does not serve index documents or support website redirects, so requests via the custom domain fail even though the bucket URL works. This mismatch is the most likely cause of the reported behavior.

Exam trap

SOA-C02 often tests the S3 REST endpoint vs. website endpoint distinction — candidates assume any S3 endpoint works for static hosting, but only the website endpoint serves index and error documents.

How to eliminate wrong answers

Option A is wrong because public read access is already enabled and the bucket URL works, so the bucket policy is not blocking access. Option B is wrong because S3 static website endpoints only support HTTP, and browsers do not block plain HTTP by default — the symptom would be a security warning, not a failure to resolve or load the site. Option D is wrong because a long TTL would delay propagation but would not cause a persistent failure once cached records expire, and the question describes a consistent failure rather than a transient one.

497
MCQeasy

A SysOps administrator is configuring Amazon CloudFront to serve content from an Amazon S3 bucket. The content is sensitive and should be encrypted at rest. Which option ensures that content is encrypted at rest in S3?

A.Enable server-side encryption (SSE-S3) on the S3 bucket
B.Enable CloudFront HTTPS-only access to the S3 bucket
C.Configure signed URLs for the distribution
D.Use CloudFront field-level encryption
AnswerA

Server-side encryption with S3-managed keys (SSE-S3) encrypts each object at rest using AES-256 before it is written to disk in the S3 bucket. When CloudFront makes a legitimate origin fetch, S3 transparently decrypts the object and serves it over the configured protocol, so the encryption does not interfere with content delivery. This directly satisfies an encryption-at-rest requirement for the origin storage.

Why this answer

Enabling server-side encryption (SSE-S3) on the S3 bucket ensures that objects are encrypted at rest using AES-256 encryption managed by Amazon S3. This directly addresses the requirement for content to be encrypted while stored in S3, independent of how CloudFront accesses the bucket.

Exam trap

The trap here is that candidates often confuse encryption in transit (HTTPS) or access control mechanisms (signed URLs) with encryption at rest, leading them to select options that only protect data during transfer or restrict access rather than securing stored data.

How to eliminate wrong answers

Option B is wrong because HTTPS-only access encrypts data in transit between CloudFront and S3, but does not encrypt the content at rest within the S3 bucket. Option C is wrong because signed URLs control access to content by requiring authentication, but they do not provide encryption of the data at rest in S3. Option D is wrong because CloudFront field-level encryption encrypts specific data fields at the edge during transit to the origin, not the entire object at rest in S3.

498
MCQmedium

A company uses AWS CodeDeploy to deploy an application to Amazon EC2 instances. The SysOps administrator wants to implement a deployment strategy that minimizes risk by deploying the new version to a small number of instances first, verifying that the deployment is successful, and then deploying to the remaining instances. If the initial deployment fails, the process should stop and roll back. Which CodeDeploy deployment configuration should be used?

A.CodeDeployDefault.AllAtOnce
B.CodeDeployDefault.HalfAtATime
C.CodeDeployDefault.OneAtATime
D.CodeDeployDefault.Canary10Percent10Minutes
AnswerC

OneAtATime deploys to a single instance at a time, verifies that it is healthy, and then proceeds to the next. This is the most cautious approach and matches the requirement of deploying to a small number (one) first, then continuing to the rest.

Why this answer

CodeDeployDefault.OneAtATime, is correct because it deploys the new application revision to one instance at a time, checking for success before proceeding to the next. If any deployment step fails, the process stops and automatically rolls back, minimizing risk by limiting the blast radius of a bad deployment.

Exam trap

The trap here is that candidates often confuse CodeDeployDefault.Canary10Percent10Minutes (a traffic-shifting configuration for Lambda/ECS) with a linear EC2 deployment strategy, or they mistakenly think HalfAtATime provides sufficient risk mitigation when the requirement explicitly calls for deploying to a 'small number' first and stopping on failure.

How to eliminate wrong answers

Option A is wrong because CodeDeployDefault.AllAtOnce deploys to all instances simultaneously, which does not minimize risk — a failure would affect all instances at once. Option B is wrong because CodeDeployDefault.HalfAtATime deploys to half the instances at a time, which still exposes a large portion of the fleet to a potential failure before verification is complete. Option D is wrong because CodeDeployDefault.Canary10Percent10Minutes is a canary deployment configuration that shifts 10% of traffic for 10 minutes, but this is a traffic-shifting strategy for Lambda or ECS deployments, not for EC2/On-Premises instances, and it does not stop on failure by default.

499
MCQmedium

A SysOps administrator manages a fleet of Amazon EC2 instances that run critical software. The administrator needs to automatically apply security patches every Tuesday at 2 AM. The instances are part of an Auto Scaling group and must be patched without downtime. Which AWS Systems Manager feature should be used?

A.State Manager
B.Patch Manager
C.Maintenance Windows
D.Run Command
AnswerC

AWS Systems Manager Maintenance Windows is the purpose-built service for scheduling and executing administrative tasks during defined time windows while preserving availability. It allows you to register an Auto Scaling group as a target and assign tasks (such as Patch Manager or custom Automation) with rate control to limit concurrency and error thresholds, ensuring only a controlled subset of instances is patched at a time. Maintenance Windows supports stop times, task priorities, and integration with Run Command and Automation documents, which can be used to recycle instances, refresh launch templates, or place instances in Standby during the maintenance activity. This orchestration is precisely what enables zero-downtime patching across a fleet managed by Auto Scaling, making it the correct answer.

Why this answer

Maintenance Windows is the correct choice because it allows you to schedule a recurring window (every Tuesday at 2 AM) during which Systems Manager actions, such as patching, can be executed on EC2 instances. This feature is specifically designed to coordinate patching across Auto Scaling groups without downtime by ensuring instances are patched in a controlled manner, often using a patching rate or concurrency limit to maintain availability.

Exam trap

The trap here is that candidates confuse Patch Manager (the patching engine) with Maintenance Windows (the scheduler), assuming Patch Manager alone can handle recurring schedules, when in fact it requires Maintenance Windows or a separate cron-like trigger to run at a specific time.

How to eliminate wrong answers

Option A is wrong because State Manager is used to define and maintain consistent configuration of instances over time (e.g., ensuring a specific software state), not to schedule one-time or recurring patching tasks with a defined window. Option B is wrong because Patch Manager is the service that actually scans for and installs patches, but it lacks the scheduling and windowing capabilities needed to run at a specific time (2 AM) without additional orchestration. Option D is wrong because Run Command is designed for ad-hoc, immediate execution of commands on instances, not for recurring scheduled operations with a defined maintenance window.

500
MCQmedium

A company is using AWS CodePipeline to automate their CI/CD pipeline. The pipeline includes a deployment stage that uses AWS CloudFormation to deploy infrastructure. The company wants to add a manual approval step before the CloudFormation deployment. How should this be configured?

A.Add a CloudFormation change set action before the deployment.
B.Configure an Amazon SNS topic to send a notification and require a confirmation.
C.Add a manual approval action in the pipeline before the CloudFormation deployment stage.
D.Use an AWS Lambda function to send an email and wait for a response.
AnswerC

In CodePipeline, a manual approval action is a stage action with category Approval that pauses the pipeline execution at that point. Once the action is reached, the pipeline enters a Wait state and notifies designated approvers via SNS; deployment to CloudFormation proceeds only after an authorized IAM user or role approves the change. This is the native mechanism designed to block progression until human sign-off, making it the correct way to require confirmation before deployment.

Why this answer

AWS CodePipeline natively supports a manual approval action that pauses the pipeline until a designated approver reviews and approves or rejects the action. Placing this action in the pipeline immediately before the CloudFormation deployment stage is the correct, built-in way to add a manual gate.

Exam trap

SOA-C02 often tests the confusion between notification (SNS) and enforcement (manual approval action), leading candidates to choose SNS or Lambda-based workarounds instead of the native CodePipeline manual approval action.

How to eliminate wrong answers

Option A is wrong because a CloudFormation change set action creates a preview of changes but does not require human approval; it simply generates the change set and can be followed by an execute action. Option B is wrong because SNS notifications are informational and do not block pipeline execution; they cannot enforce a manual approval. Option D is wrong because a Lambda function that sends an email and waits is a custom workaround, not the native CodePipeline feature, and would require complex state management.

501
MCQmedium

A SysOps administrator uses AWS CloudFormation to deploy a stack that includes an Amazon EC2 instance and a security group. The administrator wants to ensure that when the stack is updated, the security group is not accidentally replaced if its properties change. The administrator wants to receive a failure if an update would require replacement of the security group. Which CloudFormation feature should the administrator use?

A.Add a 'DeletionPolicy' attribute set to 'Retain' on the security group resource.
B.Add a 'CreationPolicy' attribute to the security group resource.
C.Define a stack policy that denies replacement of the security group resource.
D.Use an 'UpdatePolicy' attribute with 'AutoScalingReplacingUpdate' on the security group.
AnswerC

A stack policy can specify the allowed update actions per resource. By denying the 'Replace' action for the security group, CloudFormation will fail updates that would require recreating the security group, protecting it from accidental replacement.

Why this answer

A stack policy can explicitly deny update actions that would replace a resource, such as the security group. By defining a stack policy with a Deny statement for the 'Replace' effect on the security group's logical resource ID, CloudFormation will fail the update if any property change triggers a replacement, preventing accidental deletion and recreation.

Exam trap

The trap here is that candidates confuse 'DeletionPolicy' (which only applies on stack deletion) with preventing replacement during updates, or mistakenly think 'UpdatePolicy' or 'CreationPolicy' can control resource replacement behavior.

How to eliminate wrong answers

Option A is wrong because the 'DeletionPolicy' attribute set to 'Retain' only preserves the security group when the stack is deleted, not during an update; it does not prevent replacement during an update. Option B is wrong because 'CreationPolicy' is used to wait for signals or resource creation success, not to control update behavior or prevent replacement. Option D is wrong because 'UpdatePolicy' with 'AutoScalingReplacingUpdate' is specific to Auto Scaling groups to control rolling updates, not applicable to security groups.

502
MCQeasy

A SysOps administrator configures AWS CloudTrail to log all management events in a company's AWS account. The administrator needs to ensure that CloudTrail logs are not deleted for at least 5 years to meet compliance requirements. Which configuration should the administrator apply?

A.Enable CloudTrail log file validation.
B.Enable CloudTrail data events for S3.
C.Apply an S3 bucket policy that prohibits deletion of log files.
D.Enable S3 Object Lock on the CloudTrail S3 bucket.
AnswerD

S3 Object Lock is the correct control because it enables WORM (Write-Once-Read-Many) protection on the CloudTrail bucket, either in governance or compliance mode. In compliance mode, objects cannot be deleted or overwritten by any user, including the root account, until the 5-year retention period expires. This gives the immutable, time-bound retention that the sysops administrator needs to satisfy the compliance requirement.

Why this answer

S3 Object Lock provides a Write-Once-Read-Many (WORM) model that prevents objects from being deleted or overwritten for a specified retention period. By enabling S3 Object Lock on the CloudTrail S3 bucket and setting a retention mode (e.g., Compliance or Governance) with a 5-year retention period, the administrator ensures that CloudTrail log files cannot be deleted, meeting the compliance requirement.

Exam trap

The trap here is that candidates confuse S3 bucket policies with immutable storage, not realizing that bucket policies can be overridden by IAM permissions or root user actions, whereas S3 Object Lock provides true WORM protection that even the root user cannot bypass in Compliance mode.

How to eliminate wrong answers

Option A is wrong because CloudTrail log file validation uses SHA-256 hashing to verify the integrity of log files, not to prevent deletion; it ensures logs have not been tampered with but does not enforce retention. Option B is wrong because enabling CloudTrail data events for S3 captures object-level API activity (e.g., GetObject, PutObject) but does not protect log files from deletion; it increases logging scope but does not enforce retention. Option C is wrong because an S3 bucket policy that prohibits deletion of log files can be bypassed by the root user or by an IAM policy that grants s3:DeleteObject permissions; bucket policies alone cannot enforce immutable retention against authorized users.

503
MCQmedium

A company runs a web application on EC2 instances in an Auto Scaling group behind an Application Load Balancer. The application is deployed in a single Availability Zone. The SysOps administrator notices that during peak hours, the application becomes slow and some requests fail. CloudWatch metrics show that CPU utilization on the instances reaches 90%, but the Auto Scaling group does not scale out. The administrator has configured a target tracking scaling policy based on average CPU utilization with a target value of 75%. The Auto Scaling group has a minimum of 2, maximum of 10, and desired capacity of 2. What is the MOST likely reason the Auto Scaling group is not scaling out?

A.The Auto Scaling group is configured with a single Availability Zone, and the target tracking policy cannot scale out beyond the capacity of that single AZ.
B.The target tracking policy uses a target value of 75%, but the average CPU is above that, so it should scale out.
C.The target tracking policy requires detailed monitoring to be enabled on the instances.
D.The Auto Scaling group has reached its maximum capacity of 10 instances.
AnswerA

The Auto Scaling group is constrained to a single Availability Zone, and the target tracking policy cannot add instances if that specific AZ does not have sufficient capacity for the instance type defined in the launch template. Auto Scaling attempts to launch new instances, but because the group does not span multiple AZs, it cannot shift to another AZ when the sole AZ reports InsufficientInstanceCapacity. Quotas such as vCPUs typically apply per-region, but the AZ-level capacity limitation is the specific reason here—even though the group's maximum is 10, scale-out fails because there is no available capacity in that one AZ.

Why this answer

The most likely reason is that the Auto Scaling group is configured with a single Availability Zone. Target tracking scaling policies operate within the constraints of the configured subnets. If the group is only in one AZ, the subnet may have insufficient IP addresses or the AZ may have reached its instance limit, preventing the group from scaling out beyond that AZ's capacity.

Since the group has a maximum of 10, but the AZ capacity is limited, the scaling policy cannot add more instances. This is a common issue: AWS recommends using multiple Availability Zones for Auto Scaling groups to allow scaling across AZs and avoid single points of failure.

504
Multi-Selecthard

A SysOps administrator needs to detect unauthorized changes to security groups and automatically notify the operations team. Which two AWS services should be part of the solution? (Choose 2.)

Select 2 answers
A.AWS CloudTrail.
B.Amazon EventBridge.
C.Amazon S3 Transfer Acceleration.
D.AWS Snowball Edge.
AnswersA, B

AWS CloudTrail is the service that continuously records AWS API activity, capturing management events such as AuthorizeSecurityGroupIngress and RevokeSecurityGroupIngress. Each event includes the principal who made the request, the source IP address, the request parameters, and the timestamp, giving administrators a complete audit trail. This makes CloudTrail the foundational data source for detecting unauthorized security group modifications.

Why this answer

AWS CloudTrail is correct because it records API calls made to create, modify, or delete security groups, providing the audit trail needed to detect unauthorized changes. By enabling CloudTrail on the account and configuring a trail to deliver logs to Amazon S3, the administrator can monitor security group events such as AuthorizeSecurityGroupIngress or RevokeSecurityGroupEgress. This log data is essential for identifying when a change occurred, who made it, and from which source IP.

Exam trap

The trap here is that candidates often confuse Amazon S3 Transfer Acceleration with S3 event notifications or S3 server access logging, mistakenly thinking it can trigger alerts, when in fact it is solely a performance optimization for uploads.

505
Multi-Selectmedium

Which TWO actions can be taken to improve the availability of a web application hosted on EC2 instances behind an Application Load Balancer? (Select two.)

Select 2 answers
A.Configure an Auto Scaling group with health checks to replace unhealthy instances.
B.Use larger EC2 instance types.
C.Deploy the EC2 instances across multiple Availability Zones.
D.Use a single AWS Region for all instances.
E.Place all EC2 instances in a single subnet.
AnswersA, C

An Auto Scaling group with ELB health checks detects instances failing load balancer health checks and terminates then replaces them automatically, restoring capacity without manual intervention. This directly addresses instance-level failure, one axis of the availability requirement.

Why this answer

Option A is correct because an Auto Scaling group configured with health checks (ELB or EC2 health checks) automatically detects and replaces unhealthy instances, maintaining the desired capacity and thus improving availability. Option C is correct because deploying EC2 instances across multiple Availability Zones provides fault isolation; if one AZ fails, the Application Load Balancer routes traffic to healthy instances in other AZs, maintaining availability. Option B is incorrect because larger instance types increase capacity/performance but do not address redundancy or failure recovery.

Option D is incorrect because using a single Region does not improve availability against AZ-level failures and is not a redundancy measure. Option E is incorrect because placing all instances in a single subnet concentrates them in one AZ, reducing availability and creating a single point of failure.

Exam trap

The trap is equating 'more capacity' (larger instances, more instances in one AZ) with 'higher availability,' when availability requires distributing across failure domains and automating recovery.

506
MCQmedium

A company hosts a web application behind an Application Load Balancer (ALB) in us-east-1. Users in Europe report high latency. The SysOps administrator decides to use AWS Global Accelerator to improve performance by directing traffic to the closest edge location. However, the application logs require the original client IP addresses of users. The ALB currently provides the client IP via the X-Forwarded-For header, but the development team warns that Global Accelerator may change the source IP. Which configuration should the administrator choose to meet both performance and logging requirements?

A.Configure Global Accelerator with an endpoint group that points directly to the ALB. The ALB will continue to receive the original client IP in the X-Forwarded-For header.
B.Place a Network Load Balancer (NLB) in front of the ALB, and configure Global Accelerator to point to the NLB. The NLB preserves the client IP, and the ALB can still see it in the X-Forwarded-For header.
C.Enable Proxy Protocol v2 on the ALB to ensure client IP addresses are preserved through Global Accelerator.
D.Use Amazon CloudFront instead of Global Accelerator and configure it to forward the client IP in a custom header.
AnswerB

Global Accelerator preserves the client source IP when the endpoint is an NLB. The NLB passes traffic to the ALB, which can see the original client IP in the X-Forwarded-For header. This satisfies both performance (using Global Accelerator) and logging requirements.

Why this answer

Placing a Network Load Balancer (NLB) in front of the ALB allows Global Accelerator to terminate the TCP connection at the edge, then forward traffic to the NLB. The NLB preserves the original client IP address by default (since it operates at Layer 4 and does not terminate the connection), and the ALB can still read the client IP from the X-Forwarded-For header. This setup meets both the performance requirement (via Global Accelerator's edge routing) and the logging requirement (preserving the original client IP).

Exam trap

The trap here is that candidates assume Global Accelerator preserves the client IP like a transparent proxy, but in reality it terminates the TCP connection at the edge, so the source IP changes unless an NLB is used to preserve it.

How to eliminate wrong answers

Option A is wrong because Global Accelerator terminates the TCP connection at the edge location and then creates a new connection to the ALB, so the source IP seen by the ALB becomes the Global Accelerator's internal IP, not the original client IP; the X-Forwarded-For header will contain the Global Accelerator's IP, not the user's IP. Option C is wrong because Proxy Protocol v2 is a feature of Network Load Balancers and TCP listeners, not Application Load Balancers; ALBs do not support Proxy Protocol v2, and enabling it on the ALB would not preserve client IP through Global Accelerator. Option D is wrong because CloudFront does not preserve the original client IP in the X-Forwarded-For header by default; it adds the CloudFront edge IP as the last entry, and while you can forward a custom header, this requires additional configuration and does not guarantee the original client IP is preserved in the same way as the NLB+ALB solution.

507
MCQeasy

A SysOps administrator wants to monitor the cost of EC2 instances. Which AWS service should be used to visualize and track costs over time?

A.AWS CloudWatch
B.AWS Budgets
C.AWS Trusted Advisor
D.AWS Cost Explorer
AnswerD

Cost Explorer is the native AWS service for visualizing, understanding, and analyzing your costs and usage over time. It provides an interactive graph of daily, monthly, or yearly spend, with the ability to filter by EC2-specific attributes like instance type, purchase option (On-Demand, Reserved, Spot), or custom tags. This makes it the correct tool for monitoring EC2 cost trends, predicting future spending, and identifying what is driving your bill.

Why this answer

AWS Cost Explorer is the dedicated cost management tool that provides visualization of historical and forecasted AWS spending, including EC2 costs, through graphs, filters, and grouping by service, tag, or linked account. It ingests the Cost and Usage Report data and lets administrators track spend trends over time, which is exactly what the question asks for.

Exam trap

SOA-C02 often tests the confusion between CloudWatch (operational monitoring) and Cost Explorer (cost visualization), and between Budgets (threshold alerts) and Cost Explorer (trend analysis).

How to eliminate wrong answers

Option A is wrong because AWS CloudWatch monitors operational metrics (CPU, network, logs) and billing alarms, but it does not provide cost visualization or historical cost trend analysis. Option B is wrong because AWS Budgets is used to set thresholds and receive alerts when costs or usage exceed a defined limit — it does not visualize or track cost trends over time. Option C is wrong because AWS Trusted Advisor provides best-practice recommendations across cost optimization, security, fault tolerance, and service limits, but it does not offer cost visualization or time-series cost tracking.

508
MCQmedium

A SysOps administrator is configuring a new AWS account and wants to set up a secure password policy for IAM users. The policy must require at least 12 characters, one uppercase letter, one number, and must prevent password reuse. Where should this policy be configured?

A.Apply a service control policy (SCP) that enforces password complexity.
B.In the IAM console under Account settings, set the password policy.
C.Set a password policy on the AWS account root user.
D.Create an IAM role with a password policy attached.
AnswerB

The IAM password policy is configured at the AWS account level under IAM > Account settings, and it applies uniformly to all IAM users in that account. This policy can enforce requirements like minimum length, uppercase/lowercase letters, numbers, symbols, password expiration, and reuse prevention. It is the standard mechanism for implementing password complexity rules across all IAM users, and it must be set independently for each AWS account.

Why this answer

The IAM account password policy is configured in the IAM console under Account settings, where you can enforce minimum length, character complexity, password reuse prevention, and expiration. This policy applies to all IAM users in the account and is the correct location for the stated requirements. It is a single account-level setting, not something attached to individual users or roles.

Exam trap

SOA-C02 often tests whether candidates confuse SCPs (permission guardrails) with the IAM account password policy, leading them to pick SCPs for password complexity requirements.

How to eliminate wrong answers

Option A is wrong because SCPs govern permissions for AWS Organizations accounts and do not enforce IAM password complexity rules. Option C is wrong because the root user does not have a separate password policy — the account password policy applies to IAM users, and the root user's password is managed separately without these complexity controls. Option D is wrong because IAM roles do not have passwords; roles are assumed via temporary credentials, so attaching a password policy to a role is meaningless.

509
MCQeasy

A SysOps administrator needs to automate the creation of an Amazon RDS for MySQL database instance. The administrator wants to use AWS CloudFormation and ensure that the database password is not stored in plaintext in the template. Which solution meets these requirements?

A.Store the password as a CloudFormation parameter with a default value and use the Ref intrinsic function.
B.Generate a password manually and store it in a text file in Amazon S3; reference the S3 URL in the template.
C.Use AWS Secrets Manager to generate a random password and reference it in the CloudFormation template using a dynamic reference (resolve:secretsmanager).
D.Use AWS Systems Manager Parameter Store (String type) and reference it with the dynamic reference resolve:ssm.
AnswerC

Using AWS Secrets Manager with a dynamic reference allows CloudFormation to retrieve a secret at deployment time without exposing the value in the template, console, or logs. An AWS::SecretsManager::Secret resource with GenerateSecretString can automatically create a random password, and the rest of the stack can reference it via {{resolve:secretsmanager:secret-id:SecretString}}. This approach integrates with IAM policies, supports fine-grained permissioning, and can enable automatic rotation via a Lambda function, making it the AWS recommended best practice for secrets in infrastructure as code.

Why this answer

AWS CloudFormation dynamic references with the resolve:secretsmanager syntax retrieve a secret value at stack deployment time directly from AWS Secrets Manager without ever storing it in the template or its parameters. Secrets Manager can generate and rotate the password automatically, and the template only contains a reference such as '{{resolve:secretsmanager:MySecret:SecretString:password}}'. This satisfies the requirement that the password never appears in plaintext in the template.

Exam trap

SOA-C02 often tests the difference between storing secrets in plaintext (parameters, S3, String parameters) versus using Secrets Manager dynamic references — candidates pick Parameter Store String because it sounds secure, but only SecureString or Secrets Manager avoids plaintext.

How to eliminate wrong answers

Option A is wrong because a CloudFormation parameter with a default value stores the password in plaintext in the template (and in the console/API), which is exactly what the question forbids. Option B is wrong because storing the password in an S3 text file and referencing the URL still exposes the plaintext secret in S3 and requires the template to fetch it insecurely; it also lacks rotation and access control. Option D is wrong because Systems Manager Parameter Store with the String type stores the value in plaintext — only SecureString (KMS-encrypted) parameters are appropriate, and even then Secrets Manager is the AWS-recommended service for RDS-managed credentials with built-in rotation.

510
MCQmedium

A SysOps administrator manages a fleet of Amazon EC2 instances. The administrator needs to identify underutilized instances and receive recommendations for instance type changes to reduce costs. Which AWS service should be used to provide these rightsizing recommendations?

A.AWS Cost Explorer
B.AWS Trusted Advisor
C.AWS Compute Optimizer
D.Amazon CloudWatch Dashboard
AnswerC

AWS Compute Optimizer uses machine learning to analyze historical utilization metrics — including CPU, memory, EBS volume I/O, and network throughput — over a 14-day period and delivers specific recommendations for right-sizing EC2 instances, Auto Scaling groups, and EBS volumes. It provides a projected monthly cost savings estimate and a performance risk score for each recommendation, helping you balance cost and performance. You can also enable enhanced infrastructure metrics for even more precise suggestions, making it the appropriate tool for rightsizing EC2 instances.

Why this answer

AWS Compute Optimizer is the correct service because it uses machine learning to analyze historical utilization metrics (CPU, memory, network, and storage) of EC2 instances and generates rightsizing recommendations, including instance type changes, to reduce costs and improve performance. It directly addresses the need to identify underutilized instances and provide actionable recommendations for cost optimization.

Exam trap

The trap here is that candidates often confuse AWS Compute Optimizer with AWS Trusted Advisor, because both offer cost optimization checks, but Compute Optimizer is the only service that provides detailed, ML-driven rightsizing recommendations for EC2 instance types based on historical utilization data.

How to eliminate wrong answers

Option A is wrong because AWS Cost Explorer provides cost and usage data visualization and forecasting, but it does not analyze instance utilization metrics or generate specific rightsizing recommendations for EC2 instance types. Option B is wrong because AWS Trusted Advisor offers general best-practice checks, including cost optimization, but its EC2-specific recommendations are limited to idle instances and reserved instance utilization, not detailed rightsizing recommendations based on historical utilization patterns. Option D is wrong because Amazon CloudWatch Dashboard is a monitoring and visualization tool for metrics and logs, but it does not automatically analyze utilization data to produce instance type change recommendations; it requires manual setup and interpretation.

511
MCQmedium

A company runs a web application on EC2 instances behind an ALB. They want to optimize costs for variable traffic patterns while maintaining high availability. Which solution is MOST cost-effective?

A.Use Dedicated Hosts to run the application and share resources across multiple accounts.
B.Use a mix of On-Demand and Spot Instances in an Auto Scaling group with a target tracking scaling policy.
C.Purchase Reserved Instances for the expected baseline capacity and use On-Demand for spikes.
D.Use only On-Demand EC2 Instances with an Auto Scaling group to handle variable traffic.
AnswerB

A mixed-instance Auto Scaling group with On-Demand and Spot Instances is cost-optimal because Spot Instances are available for up to 90% lower hourly price, and the target tracking scaling policy automatically adjusts the desired capacity based on a selected metric such as average CPU utilization, maintaining a baseline with On-Demand while absorbing traffic spikes with Spot. The ASG's capacity rebalancing feature monitors Spot interruption warnings and proactively launches replacement instances, making this an ideal, resilient and inexpensive solution for a fault-tolerant web tier.

Why this answer

The most cost-effective because it combines On-Demand Instances for baseline capacity and Spot Instances for burstable traffic, leveraging lower Spot prices while maintaining high availability through Auto Scaling with a target tracking policy. Option A is wrong because Dedicated Hosts are expensive and provide no cost benefit for variable traffic. Option C is wrong because Reserved Instances require a 1- or 3-year commitment and are not suitable for variable traffic; they are better for steady-state workloads.

Option D is wrong because using only On-Demand Instances is more expensive than using a mix that includes Spot Instances.

512
MCQmedium

An application running on an Amazon EC2 instance needs to access an Amazon S3 bucket. The company security policy requires that credentials are not stored on the instance. What is the most secure way to grant access?

A.Create an IAM role with S3 access permissions and attach it to the EC2 instance profile.
B.Generate an access key and secret key for an IAM user, then store them in a configuration file on the instance.
C.Create an S3 bucket policy that allows access from the instance's public IP address.
D.Define the access keys as environment variables in the user data script when launching the instance.
AnswerA

Attaching an IAM role to the EC2 instance profile is the recommended pattern because the instance retrieves temporary, automatically rotating credentials from the instance metadata service (IMDSv2). These credentials are scoped by the role's trust policy and S3 permissions, so no long-lived access keys are ever written to disk, code, or configuration files. The AWS SDKs and CLI automatically assume the role, enabling secure access to S3 without manual credential management.

Why this answer

Attaching an IAM role to an EC2 instance via an instance profile allows the instance to obtain temporary security credentials from the AWS Security Token Service (STS). These credentials are automatically rotated and never stored on the instance, satisfying the security policy requirement. The EC2 instance retrieves the credentials through the instance metadata service (IMDS), eliminating the need for long-term access keys.

Exam trap

The trap here is that candidates may think storing keys in environment variables or configuration files is acceptable because they are 'hidden' or 'temporary,' but the exam emphasizes that any form of long-term credential storage on the instance violates the principle of least privilege and the security policy.

How to eliminate wrong answers

Option B is wrong because storing an access key and secret key in a configuration file on the instance violates the security policy that credentials must not be stored on the instance, and long-term keys increase the risk of exposure. Option C is wrong because an S3 bucket policy that allows access based on the instance's public IP address is insecure; public IPs can change (e.g., after stop/start) and do not authenticate the instance, leaving the bucket open to any traffic from that IP. Option D is wrong because defining access keys as environment variables in user data still stores the keys in the instance's memory and can be retrieved from the instance, violating the no-storage policy and exposing credentials to processes or logs.

513
MCQeasy

A SysOps administrator needs to deploy a CloudFormation stack across multiple AWS accounts in an organization using AWS Organizations. The administrator wants to use a single template and a single deployment operation. Which AWS service should be used to centrally manage the deployment?

A.AWS Systems Manager
B.AWS OpsWorks Stacks
C.AWS CodePipeline
D.AWS CloudFormation StackSets
AnswerD

AWS CloudFormation StackSets lets you deploy the same CloudFormation template into multiple AWS accounts and Regions from a single administrator account. It creates stack instances in target accounts using either service-managed permissions with AWS Organizations or self-managed execution roles, and it includes deployment safeguards such as failure tolerance and maximum concurrent account thresholds. This is the native service designed specifically for orchestrated cross-account, cross-Region infrastructure rollout.

Why this answer

AWS CloudFormation StackSets allows you to deploy a single CloudFormation template across multiple AWS accounts and regions with a single operation. It is designed for centralized management of stacks in an organization, leveraging AWS Organizations for automatic deployment to member accounts. This meets the requirement of using one template and one deployment operation across multiple accounts.

Exam trap

SOA-C02 often tests the distinction between services that can deploy across accounts, and candidates may confuse StackSets with CodePipeline or Systems Manager due to overlapping use cases.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager is used for operational management of resources (e.g., patching, automation) but does not deploy CloudFormation stacks across accounts. Option B is wrong because AWS OpsWorks Stacks is a configuration management service that uses Chef/Puppet, not CloudFormation, and is not designed for cross-account stack deployment. Option C is wrong because AWS CodePipeline is a CI/CD service that can orchestrate deployments but requires additional configuration and does not natively deploy a single stack across multiple accounts in one operation without custom scripting.

514
MCQeasy

A company runs a web application on EC2 instances behind an Application Load Balancer. The application experiences variable traffic patterns. What is the MOST cost-effective way to ensure the application scales based on demand?

A.Provision a fixed number of EC2 instances that can handle peak load at all times.
B.Use EC2 Auto Scaling with a scheduled scaling policy that adds instances during business hours.
C.Use EC2 Auto Scaling with a target tracking scaling policy based on average CPU utilization.
D.Use EC2 Auto Scaling with a manual scaling plan that requires an administrator to adjust the desired capacity.
AnswerC

A target tracking scaling policy works by setting a target value for a metric—such as average CPU utilization at, say, 60%—and Auto Scaling continuously reads CloudWatch alarms to add or remove instances, keeping the metric near that target. This approach is reactive and automatic, handling sudden traffic surges by launching instances and terminating idle ones when demand falls. It is the most cost-effective and hands-off option for variable web workloads.

Why this answer

A target tracking scaling policy based on average CPU utilization automatically adjusts the number of EC2 instances to maintain a target metric (e.g., 50% CPU), scaling out during high demand and scaling in during low demand. This is the most cost-effective approach for variable traffic patterns as it eliminates over-provisioning and manual intervention, directly aligning capacity with real-time demand.

Exam trap

The trap here is that candidates often choose scheduled scaling (Option B) thinking it covers all variable traffic, but the exam tests the distinction that scheduled scaling only works for predictable patterns, not truly variable demand, making target tracking the correct choice for cost-effective dynamic scaling.

How to eliminate wrong answers

Option A is wrong because provisioning a fixed number of EC2 instances for peak load results in significant over-provisioning and wasted cost during low-traffic periods, as instances remain running idle. Option B is wrong because a scheduled scaling policy only adds instances during predefined business hours, which cannot handle unpredictable or variable traffic patterns outside those hours, leading to either under-provisioning or over-provisioning. Option D is wrong because a manual scaling plan requires an administrator to adjust desired capacity, which is not cost-effective due to delayed response times and the risk of human error, failing to scale dynamically with demand.

515
MCQeasy

An organization needs to back up an Amazon EFS file system daily and retain backups for 30 days. Which AWS service provides a managed backup solution for EFS?

A.AWS Backup
B.Amazon Data Lifecycle Manager (DLM)
C.EFS replication to another region
D.S3 Lifecycle policies
AnswerA

AWS Backup is the correct service because it is the native, fully managed backup service designed specifically for Amazon EFS file systems. A backup plan schedules recurring EFS backups, stores them as recovery points, and applies configurable retention policies, including cross-region and cross-account copies. It also supports point-in-time restore, lifecycle rules that transition recovery points to cold storage, and integration with AWS Organizations for compliance. Thus AWS Backup provides the backup-with-retention capability the organization requires.

Why this answer

AWS Backup is the correct answer because it is a fully managed, policy-based backup service that supports Amazon EFS natively. It allows you to define backup plans with daily schedules and retention rules (e.g., 30 days) without needing to manage any backup infrastructure or scripts. AWS Backup handles the lifecycle of backups, including incremental backups and automatic deletion of expired recovery points.

Exam trap

The trap here is that candidates often confuse Amazon Data Lifecycle Manager (DLM) as a general-purpose backup tool, but DLM is strictly limited to EBS snapshots and AMIs, not EFS file systems.

How to eliminate wrong answers

Option B (Amazon Data Lifecycle Manager) is wrong because DLM is designed for managing the lifecycle of Amazon EBS snapshots and EBS-backed AMIs, not for backing up Amazon EFS file systems. Option C (EFS replication to another region) is wrong because replication provides a cross-region copy of the file system for disaster recovery, but it does not offer point-in-time backup retention or automated deletion after a specific period like 30 days. Option D (S3 Lifecycle policies) is wrong because S3 Lifecycle policies manage the transition and expiration of objects within S3 buckets, and they cannot be applied directly to an EFS file system, which is a separate storage service.

516
MCQmedium

A company has an on-premises data center connected to AWS via an AWS Direct Connect private virtual interface (VIF). The SysOps administrator needs to ensure that all traffic between the on-premises network and Amazon S3 in the same AWS Region stays within the AWS network and does not traverse the internet. Which solution should the administrator implement?

A.Use a Direct Connect gateway and a public VIF with a route to S3 prefix lists
B.Use a Direct Connect gateway and a private VIF with VPC endpoints for S3
C.Use a VPN connection over Direct Connect to access S3
D.Use a Transit Gateway with a private VIF and route S3 traffic through a NAT instance
AnswerB

A private VIF creates a dedicated private network connection between your on-premises data center and a VPC, while a VPC Gateway Endpoint for S3 privately connects the VPC to S3 without traversing the internet. Traffic from on-premises flows via the private VIF into the VPC and then through the Gateway Endpoint directly to S3 over AWS's internal network, successfully meeting the requirement for high-bandwidth, fully private S3 access. This is the recommended AWS architecture for private S3 connectivity over Direct Connect.

Why this answer

A private VIF with VPC endpoints for S3 (Gateway Endpoints) ensures that traffic from on-premises to S3 stays within the AWS network. The private VIF provides connectivity to the VPC, and the Gateway Endpoint routes S3 traffic through the AWS backbone without traversing the internet. This combination meets the requirement of keeping traffic within the AWS network.

Exam trap

The trap here is that candidates often confuse public VIF with private VIF, thinking a public VIF is required for AWS service access, but Gateway Endpoints allow private VIF to access S3 without internet exposure.

How to eliminate wrong answers

Option A is wrong because a public VIF with a route to S3 prefix lists would still route traffic over the public internet (via the Direct Connect public VIF), which does not guarantee that traffic stays within the AWS network; it also requires routing over the internet gateway. Option C is wrong because a VPN connection over Direct Connect would encrypt traffic but still uses the public VIF or internet path, and it does not inherently keep traffic within the AWS network; it adds unnecessary complexity and does not meet the requirement of staying within the AWS network. Option D is wrong because a Transit Gateway with a private VIF and routing S3 traffic through a NAT instance would force traffic through a NAT instance, which typically uses an internet gateway to reach S3, thus traversing the internet; this violates the requirement.

517
MCQmedium

A company runs a REST API on Amazon EC2 instances behind an Application Load Balancer. The SysOps administrator needs to monitor the API endpoint from multiple geographic locations and receive an alarm if the p90 latency exceeds 2 seconds for two consecutive checks. The solution must use AWS managed services and not require custom code running on EC2. Which approach should the administrator use?

A.Set up Amazon CloudWatch Synthetics canaries to run from multiple AWS Regions and publish custom metrics. Create a CloudWatch alarm on the p90 latency metric.
B.Configure VPC Flow Logs on the Application Load Balancer and use Amazon CloudWatch Logs Insights to query for high-latency requests.
C.Enable Amazon CloudWatch RUM (Real User Monitoring) on the client side and create a CloudWatch alarm on the Duration metric.
D.Use AWS CloudTrail to log API calls and set a CloudWatch alarm on the event count for errors.
AnswerA

CloudWatch Synthetics canaries execute Node.js or Python scripts on AWS-managed Lambda functions, and by configuring them in multiple Regions you can actively probe the REST API from geographically distributed vantage points. Each canary can record HTTP response time and success/failure, then publish those measurements as custom metrics to CloudWatch. Because the metric supports percentile statistics, you can create an alarm on the p90 latency (e.g., p90 over 5 minutes) to detect regional or global slowdowns, making this the only option that provides synthetic, multi-region, application-level latency monitoring.

Why this answer

Amazon CloudWatch Synthetics canaries are AWS-managed Node.js scripts that run on a schedule to monitor endpoints from multiple AWS Regions, capturing metrics like duration and latency. By configuring canaries to report p90 latency as a custom metric, you can create a CloudWatch alarm that triggers when p90 exceeds 2 seconds for two consecutive data points, meeting all requirements without custom EC2 code.

Exam trap

The trap here is that candidates may confuse VPC Flow Logs or CloudTrail with application-layer monitoring, but neither provides request-level latency metrics; CloudWatch Synthetics is the only AWS-managed service that can synthetically test an HTTP endpoint from multiple geographic locations and publish percentile latency metrics without custom EC2 code.

How to eliminate wrong answers

Option B is wrong because VPC Flow Logs capture network-level metadata (IPs, ports, protocols) but do not measure application-layer latency like p90; they cannot be used to query for request duration or percentile latencies. Option C is wrong because Amazon CloudWatch RUM collects client-side performance data from actual user browsers, which introduces variability from network conditions and device performance, and it requires client-side JavaScript injection, not a pure AWS-managed service for synthetic monitoring from multiple geographic locations. Option D is wrong because AWS CloudTrail logs API calls to the AWS management plane (e.g., EC2 API calls), not the application-layer REST API requests; it cannot measure p90 latency or trigger alarms on performance metrics.

518
MCQmedium

A company uses AWS CloudTrail to record all API activity. The SysOps administrator needs to be alerted in real time when an IAM user creates a new access key. Which combination of AWS services should be used to create this alert?

A.CloudTrail + Amazon S3 + Amazon SNS
B.CloudTrail + Amazon CloudWatch Logs + Amazon SNS
C.CloudTrail + AWS Config + Amazon SNS
D.CloudTrail + Amazon EventBridge + Amazon SNS
AnswerD

CloudTrail continuously delivers management events to EventBridge (formerly CloudWatch Events) as the default event bus. You can create an EventBridge rule with an event pattern that matches a specific API call, such as s3.amazonaws.com: DeleteBucket or an IAM action, and set an SNS topic as the target for immediate notification. This is the most direct, low-latency, and fully managed approach; no extra storage or external monitoring is needed. Because EventBridge natively ingests CloudTrail events, you get built-in filtering and fan-out, which is ideal for real-time alerting.

Why this answer

Amazon EventBridge can directly consume CloudTrail events in real time and trigger an SNS notification when an IAM user creates a new access key. EventBridge provides a serverless event bus that matches specific API calls (e.g., CreateAccessKey) using event patterns, enabling immediate alerting without additional polling or log processing.

Exam trap

The trap here is that candidates often assume CloudWatch Logs is required for any CloudTrail-based alerting, but EventBridge provides a simpler, lower-latency, and more direct integration for real-time API event monitoring.

How to eliminate wrong answers

Option A is wrong because CloudTrail logs to Amazon S3 are delivered in batches (typically every 5 minutes), not in real time, so S3 events cannot trigger immediate alerts for access key creation. Option B is wrong because CloudTrail integration with CloudWatch Logs introduces latency (up to several minutes) and requires additional metric filters and alarms, which is not the most direct real-time approach. Option C is wrong because AWS Config is designed for resource configuration tracking and compliance evaluation, not for real-time API event alerting; it evaluates rules periodically or on configuration changes, not instantaneously for every API call.

519
Multi-Selecteasy

Which TWO measures help protect an AWS account root user? (Choose two.)

Select 2 answers
A.Use the root user regularly for administrative tasks.
B.Create an access key for the root user for programmatic access.
C.Grant other IAM users full administrator access.
D.Use a strong, complex password for the root user.
E.Enable multi-factor authentication (MFA) for the root user.
AnswersD, E

A strong, complex password for the root user is a core, direct defensive control because the root account bypasses all IAM policies, so the console password is the only baseline barrier against unauthorized sign-ins. A long mix of characters, coupled with the absence of the password being reused elsewhere, materially reduces the risk of credential-stuffing and forced-entry attacks. AWS recommends a minimum of 14 characters for the root password.

Why this answer

Options D and E are correct. Using a strong, complex password and enabling MFA for the root user are essential security measures to protect the account. Option A is incorrect because using the root user regularly increases the risk of compromise; it should be used only for tasks that require root privileges.

Option B is incorrect because creating an access key for the root user exposes long-term credentials that can be misused; root user access keys should be avoided. Option C is incorrect because granting other IAM users full administrator access does not directly protect the root user; it reduces dependency on the root user but is not a security measure for the root user itself.

520
MCQhard

A SysOps administrator is investigating a security breach. An IAM user 'Bob' is suspected of performing unauthorized actions. The administrator needs to determine the source IP addresses from which Bob's access keys were used in the last 30 days. Which AWS service or feature should be used?

A.AWS CloudTrail event history.
B.VPC Flow Logs.
C.Amazon CloudWatch Logs.
D.AWS IAM credential report.
AnswerA

AWS CloudTrail event history retains 90 days of management events, satisfying the 30-day window. Each `sourceIPAddress` field records the originating IP for every API call made with Bob's access keys, letting the administrator trace exactly where those credentials were used.

Why this answer

AWS CloudTrail event history provides a record of all API calls made by IAM users, including the source IP address from which the request originated. By filtering the event history for the IAM user 'Bob' and the time range of the last 30 days, the administrator can identify the source IP addresses associated with each API call made using Bob's access keys. This directly meets the requirement to determine the source IP addresses of unauthorized actions.

Exam trap

The trap here is that candidates may confuse the IAM credential report (which shows credential metadata) with CloudTrail (which records actual API call details), leading them to choose the credential report for investigating source IPs when it only provides static credential status, not historical usage data.

How to eliminate wrong answers

Option B is wrong because VPC Flow Logs capture network traffic at the IP level (source/destination IPs, ports, protocols) but do not log IAM user identity or access key usage; they are used for analyzing network traffic patterns, not for tracking API calls by specific IAM users. Option C is wrong because Amazon CloudWatch Logs can store log data from various sources (e.g., application logs, system logs) but does not natively capture IAM user API call details or source IPs unless custom logging is configured; it is not the primary service for auditing IAM user activity. Option D is wrong because AWS IAM credential report provides information about the status of IAM user credentials (e.g., password last used, access key age, rotation status) but does not include source IP addresses or a history of API calls; it is used for credential auditing, not for investigating specific actions or source IPs.

521
MCQmedium

A company uses AWS CloudFormation to deploy a stack that includes an Amazon RDS DB instance. The administrator wants to ensure that the DB instance is not deleted when the stack is deleted. Which property should the administrator set in the CloudFormation template?

A.DeletionPolicy: Delete
B.DeletionPolicy: Snapshot
C.DeletionPolicy: Replace
D.DeletionPolicy: Retain
AnswerD

DeletionPolicy: Retain is the correct choice because it tells CloudFormation to leave the RDS DB instance untouched when the stack is deleted. The resource is removed from the stack's management, but the database remains live, accessible, and incurring costs in your AWS account. This exactly matches the goal of preserving the database after stack deletion.

Why this answer

The DeletionPolicy: Retain property ensures that the RDS DB instance is not deleted when the CloudFormation stack is deleted. It preserves the resource, allowing it to continue running independently of the stack. This is the correct choice to prevent accidental data loss.

Exam trap

SOA-C02 often tests the confusion between DeletionPolicy: Snapshot and Retain, where candidates think Snapshot preserves the instance, but it only preserves a snapshot and deletes the instance.

How to eliminate wrong answers

Option A is wrong because DeletionPolicy: Delete would delete the DB instance when the stack is deleted, which is the opposite of what is desired. Option B is wrong because DeletionPolicy: Snapshot takes a snapshot before deleting the resource, but the resource is still deleted; the snapshot is retained, but the instance is not. Option C is wrong because DeletionPolicy: Replace is not a valid DeletionPolicy value; valid values are Delete, Retain, and Snapshot.

522
MCQeasy

A company hosts a web application on EC2 instances behind an Application Load Balancer. Users report intermittent 503 errors. Which step should the SysOps administrator take to troubleshoot the issue?

A.Verify the target group health check settings.
B.Enable cross-zone load balancing.
C.Increase the idle timeout on the load balancer.
D.Add more subnets to the load balancer.
AnswerA

The 503 Service Unavailable response from an Application Load Balancer specifically indicates that the target group contains no registered instances that are passing health checks. Health check settings, such as the configured path, expected HTTP success codes, interval, timeout, and unhealthy threshold, directly determine whether EC2 instances are marked healthy or unhealthy. If the health check path returns a non-2xx status due to an application misconfiguration, or if the health check port is blocked by a security group, all targets can be flagged unhealthy, triggering a 503. Verifying and correcting these settings is the first and most effective remediation step.

Why this answer

Intermittent 503 errors from an Application Load Balancer typically indicate that the target instances are failing health checks or are unable to handle the request load. Verifying the target group health check settings (e.g., path, interval, threshold, and protocol) is the first troubleshooting step because if the health checks are misconfigured or the targets are unhealthy, the ALB will stop routing traffic to them, resulting in 503 responses.

Exam trap

The trap here is that candidates often confuse 503 errors with timeout or capacity issues and jump to increasing idle timeout or adding subnets, rather than recognizing that 503 errors from an ALB almost always point to target health check failures.

How to eliminate wrong answers

Option B is wrong because cross-zone load balancing is enabled by default on Application Load Balancers and does not cause intermittent 503 errors; it distributes traffic evenly across all targets in all enabled Availability Zones. Option C is wrong because increasing the idle timeout on the load balancer affects how long the ALB keeps idle connections open, not the availability or health of targets; 503 errors are not related to idle timeout settings. Option D is wrong because adding more subnets to the load balancer increases its availability and capacity but does not directly resolve intermittent 503 errors caused by unhealthy targets or misconfigured health checks.

523
Multi-Selecteasy

A SysOps administrator is planning for disaster recovery of an RDS MySQL database. The database is currently in a single AZ. Which TWO actions will improve recovery time and reduce data loss? (Select TWO.)

Select 2 answers
A.Create a read replica in a different AWS Region.
B.Enable automated backups with a retention period of 7 days.
C.Enable Multi-AZ deployment for automatic failover.
D.Enable deletion protection on the RDS instance.
E.Increase the allocated storage to improve performance.
AnswersB, C

Automated backups with a retention period of 7 days enable point-in-time recovery (PITR), allowing you to restore the database to any second within that retention window. This protects against logical errors, such as accidental table drops or erroneous UPDATE statements, by letting you recover a clean copy of the data as of a specific timestamp. The backup is stored in S3 and is essential for meeting recovery point objectives (RPO) when data corruption occurs, making it a core disaster recovery tool.

Why this answer

Enabling automated backups with a 7-day retention period allows point-in-time recovery (PITR) to any second within the retention window, minimizing data loss (RPO) by restoring to the most recent backup. Option C is correct because Multi-AZ deployment provides automatic synchronous standby replication to a different Availability Zone, enabling automatic failover with minimal downtime (RTO) in case of an AZ failure or instance issue.

Exam trap

The trap here is that candidates often confuse read replicas with Multi-AZ failover, thinking a read replica can serve as a quick disaster recovery option, but read replicas are asynchronous and do not provide automatic failover or synchronous data protection.

524
MCQmedium

A company has two Amazon VPCs: VPC-A (10.0.0.0/16) and VPC-B (10.1.0.0/16) in the same AWS Region. The SysOps administrator needs to enable private IP connectivity between the two VPCs without using the public internet. The solution must be simple, low-cost, and provide high throughput. Which AWS service should the administrator use?

A.VPC peering
B.AWS Site-to-Site VPN
C.AWS Direct Connect
D.AWS Transit Gateway
AnswerA

VPC peering establishes a direct, private network connection between two VPCs using the AWS backbone. It is simple to set up, has low cost (no hourly fees, only data transfer charges), and provides high throughput with no bandwidth constraints.

Why this answer

VPC peering is the correct choice because it enables direct private IP connectivity between two VPCs using the AWS global network, without requiring internet gateways, VPNs, or physical connections. It is simple to set up (no additional hardware or software), low-cost (no per-hour charges, only data transfer costs), and provides high throughput (bandwidth is limited only by the instance types, not by the peering connection itself).

Exam trap

The trap here is that candidates often over-engineer the solution by choosing AWS Transit Gateway (Option D) for its advanced features, forgetting that for a simple two-VPC connection, VPC peering is the most cost-effective and straightforward option without unnecessary complexity.

How to eliminate wrong answers

Option B (AWS Site-to-Site VPN) is wrong because it requires a virtual private gateway on each VPC and an on-premises VPN endpoint, adding complexity and cost (per-hour charges) while throughput is limited by the VPN tunnel (typically up to 1.25 Gbps per tunnel). Option C (AWS Direct Connect) is wrong because it is designed for dedicated on-premises to AWS connectivity, not for VPC-to-VPC peering, and involves high cost, long provisioning times, and physical infrastructure. Option D (AWS Transit Gateway) is wrong because while it can connect multiple VPCs, it introduces additional cost (per-hour and per-GB charges) and complexity (requires transit gateway attachments and route table management) that is unnecessary for a simple two-VPC scenario.

525
MCQeasy

A company is designing a highly available web application on AWS. The application runs on EC2 instances behind an Application Load Balancer. Which configuration ensures that the application remains available if an entire AWS Availability Zone fails?

A.Deploy EC2 instances in multiple subnets of the same Availability Zone.
B.Launch EC2 instances in at least two different Availability Zones.
C.Use a larger EC2 instance type to handle the load.
D.Use EC2 instances in multiple AWS Regions.
AnswerB

Launching EC2 instances in at least two different Availability Zones is the correct approach because each AZ is an isolated, independent failure domain with separate power, cooling, and physical infrastructure. A load balancer can then distribute traffic across these AZs, so if one AZ becomes unavailable, the remaining AZs continue to serve traffic, maintaining high availability within the same AWS Region without cross-region latency.

Why this answer

Deploying EC2 instances in at least two different Availability Zones (AZs) ensures that if one AZ fails, the Application Load Balancer (ALB) can route traffic to healthy instances in the remaining AZ(s). ALBs are regional constructs that automatically distribute traffic across registered targets in multiple AZs, and they perform health checks to detect and route away from failed AZs. This design meets the high availability requirement by eliminating the AZ as a single point of failure.

Exam trap

The trap here is that candidates often confuse high availability with scalability or performance, mistakenly thinking that larger instances (Option C) or multi-Region deployment (Option D) are required, when the core requirement is simply eliminating a single AZ as a point of failure by using multiple AZs within the same region.

How to eliminate wrong answers

Option A is wrong because deploying instances in multiple subnets within the same Availability Zone does not protect against an AZ failure; if that single AZ goes down, all instances become unavailable. Option C is wrong because using a larger EC2 instance type only increases the compute capacity of a single instance, but does not provide redundancy or fault tolerance; a failure of that instance or its AZ still causes downtime. Option D is wrong because using multiple AWS Regions provides disaster recovery across geographic regions, but it is overkill and not necessary for availability within a single region; it also introduces higher latency and complexity not required for the stated goal of surviving an AZ failure.

Page 6

Page 7 of 16

Page 8