Courseiva

AWS Certified SysOps Administrator Associate SOA-C02 (SOA-C02) — Questions 601–675

1169 questions total · 16pages · All types, answers revealed

Page 8

Page 9 of 16

Page 10
601
MCQeasy

A DevOps engineer wants to automate the creation of an Amazon EC2 instance with a specific security group and IAM role. Which AWS service should be used to define the infrastructure as code?

A.AWS Elastic Beanstalk
B.AWS CodeDeploy
C.AWS CloudFormation
D.AWS OpsWorks
AnswerC

CloudFormation is the native AWS infrastructure-as-code service: you define resources in a JSON or YAML template, and the service provisions, updates, and deletes them as a stack with order-aware dependencies and automatic rollback on failures. It supports almost every AWS resource and allows drift detection to compare actual configuration to template state. This exactly matches the goal of automating creation of Amazon infrastructure.

Why this answer

AWS CloudFormation is the infrastructure-as-code (IaC) service that allows you to define AWS resources such as EC2 instances, security groups, and IAM roles in declarative JSON or YAML templates. It automates provisioning and management of the entire stack, ensuring consistent and repeatable deployments. This directly matches the requirement to define infrastructure as code.

Exam trap

SOA-C02 often tests the distinction between IaC services and deployment/configuration services, so candidates must recognize that CloudFormation is the declarative IaC tool, while CodeDeploy, Elastic Beanstalk, and OpsWorks serve different purposes.

How to eliminate wrong answers

Option A is wrong because AWS Elastic Beanstalk is a PaaS service that abstracts infrastructure for deploying applications, but it does not provide declarative IaC templates for defining arbitrary resources like security groups and IAM roles. Option B is wrong because AWS CodeDeploy is a deployment service for automating application deployments to EC2, Lambda, or on-premises servers, not for defining infrastructure. Option D is wrong because AWS OpsWorks is a configuration management service using Chef and Puppet, which manages server configuration but is not the primary IaC service for defining AWS resources declaratively.

602
MCQhard

A company operates a web application behind an Application Load Balancer (ALB). The SysOps administrator needs to block incoming requests from specific geographic locations (countries X and Y) and also enforce a rate limit of 100 requests per IP address per 5-minute window to mitigate DDoS attacks. The solution must be centrally configured and apply to all requests handled by the ALB. Which AWS service should be used to implement these requirements?

A.AWS WAF
B.Amazon CloudFront geo restriction
C.AWS Shield Advanced
D.Security Groups
AnswerA

AWS WAF offers both geo-match conditions to block requests from specific countries and rate-based rules to limit request rates from an IP address. It integrates directly with ALB and provides a single, centrally managed solution.

Why this answer

AWS WAF is the correct service because it provides both geographic (geo-match) blocking and rate-based rules that can be associated directly with an Application Load Balancer. Geo-match conditions allow you to block requests from specific countries (X and Y), while rate-based rules can limit requests to 100 per 5-minute window per source IP. This solution is centrally configured at the ALB level, applying to all incoming requests without requiring additional infrastructure.

Exam trap

The trap here is that candidates often confuse AWS WAF with CloudFront geo restriction or AWS Shield Advanced, not realizing that only WAF provides both geo-blocking and rate-based rules that can be directly associated with an ALB without requiring CloudFront.

How to eliminate wrong answers

Option B (Amazon CloudFront geo restriction) is wrong because CloudFront geo restriction only works when CloudFront is the front-end service, not directly with an ALB; it cannot be applied to an ALB alone and does not support rate limiting. Option C (AWS Shield Advanced) is wrong because while it provides enhanced DDoS protection and cost protection, it does not offer granular geo-blocking or configurable rate-based rules; it is a managed threat protection service, not a web application firewall. Option D (Security Groups) is wrong because security groups operate at the network layer (Layer 3/4) and cannot inspect application-layer attributes like geographic origin or enforce rate limits based on HTTP request counts.

603
MCQhard

A SysOps admin is investigating why a CloudWatch alarm did not trigger an SNS notification when a metric breached the threshold. The alarm state is visible in the console as 'ALARM'. What is the most likely reason the notification was not sent?

A.The SNS topic's subscription is not confirmed
B.The alarm name contains special characters
C.The alarm's evaluation period is set to 1 minute
D.The metric has a resolution of 1 minute
AnswerA

For CloudWatch alarms that use Amazon SNS to send notifications, the SNS subscription must be confirmed before messages can be delivered to the endpoint. Email subscriptions require the recipient to click the confirmation link sent by SNS; if this step is skipped, the subscription remains in a 'PendingConfirmation' state, and SNS silently drops the alarm notification while the alarm itself still changes state. This is a common cause of a 'silent' CloudWatch alarm, so checking the subscription confirmation status in the SNS console is the first troubleshooting step.

Why this answer

The most likely reason the notification was not sent is that the SNS topic's subscription is not confirmed. When an SNS topic sends a notification to an endpoint such as email, HTTP, or SMS, the subscription must first be confirmed by the subscriber. If the subscription remains in a 'Pending confirmation' state, SNS will not deliver messages to that endpoint, even if the CloudWatch alarm transitions to the ALARM state and publishes to the topic.

Exam trap

The trap here is that candidates assume any alarm in ALARM state will automatically trigger its configured SNS action, overlooking the requirement that the SNS subscription must be in a confirmed state before messages can be delivered.

How to eliminate wrong answers

Option B is wrong because CloudWatch alarm names can contain special characters (e.g., hyphens, underscores, spaces) without affecting notification delivery; the alarm name is simply a label and does not impact SNS publishing. Option C is wrong because setting the evaluation period to 1 minute does not prevent notifications; it only affects how quickly the alarm evaluates metric data and transitions state. Option D is wrong because a metric resolution of 1 minute (standard resolution) is normal and does not interfere with alarm actions or SNS notifications; high-resolution metrics (1 second) are also supported without issue.

604
MCQmedium

A SysOps administrator needs to ensure that all Amazon S3 buckets in an AWS account are encrypted at rest using server-side encryption. Which combination of actions should be taken to enforce this policy?

A.Enable default encryption on each S3 bucket and create a CloudWatch alarm to notify if unencrypted objects are uploaded.
B.Use an S3 bucket policy with a Deny statement for s3:PutObject without encryption applied to all buckets via a single policy.
C.Use AWS CloudTrail to monitor PutObject calls and trigger an AWS Lambda function to delete unencrypted objects.
D.Use an S3 bucket policy on each bucket that denies s3:PutObject if the x-amz-server-side-encryption header is not present.
AnswerD

A bucket policy with a Deny for s3:PutObject when the x-amz-server-side-encryption header is absent enforces encryption at upload time by rejecting the request before any object is written. The condition evaluates the presence of the encryption header (e.g., using StringNotEquals if s3:x-amz-server-side-encryption is not AES256 or aws:kms), and this applies to every PutObject on that bucket. Because each bucket needs its own policy, the administrator must attach the policy to every bucket individually, but this fully satisfies the enforcement requirement.

Why this answer

An S3 bucket policy with a Deny statement for s3:PutObject that requires the x-amz-server-side-encryption header ensures that any PUT request without encryption headers is rejected. This enforces server-side encryption at the point of upload, preventing unencrypted objects from being stored in the bucket. Default encryption (Option A) only applies encryption to objects that are uploaded without encryption headers, but it does not prevent unencrypted uploads; a bucket policy denial is the only way to block them outright.

Exam trap

The trap here is that candidates confuse default encryption (which is applied server-side after upload) with a bucket policy that denies unencrypted uploads, thinking that default encryption alone enforces encryption, when in fact it does not prevent the upload of unencrypted objects.

How to eliminate wrong answers

Option A is wrong because enabling default encryption on each S3 bucket does not prevent unencrypted objects from being uploaded; it only applies encryption after the object is stored, and a CloudWatch alarm is reactive, not preventive. Option B is wrong because a single S3 bucket policy cannot be applied to all buckets; bucket policies are per-bucket resources, and a single policy cannot span multiple buckets. Option C is wrong because using CloudTrail and Lambda to delete unencrypted objects is a reactive, non-compliant approach that allows unencrypted data to exist temporarily, violating the 'enforce' requirement, and it introduces unnecessary complexity and potential data loss.

605
MCQeasy

A company needs to audit all changes to IAM policies in their AWS account. Which AWS service should be used to track these changes?

A.AWS Config
B.AWS CloudTrail
C.Amazon CloudWatch
D.AWS Trusted Advisor
AnswerB

AWS CloudTrail is the correct service because it records all IAM API calls as events, including actions like PutRolePolicy, AttachUserPolicy, and DeletePolicy. Each CloudTrail event contains the principal who made the call, the source IP, the user agent, the request parameters, and the response—creating a complete, immutable audit log. This evidence trail enables you to answer exactly who changed which IAM policy and when, satisfying the requirement to audit all policy modifications.

Why this answer

AWS CloudTrail is the correct service because it records API activity in your AWS account, including all IAM policy changes such as CreatePolicy, PutUserPolicy, AttachRolePolicy, and DeletePolicy. CloudTrail logs these events with details like the user, source IP, and timestamp, providing a complete audit trail for security and compliance. AWS Config, while capable of tracking configuration changes, does not capture the API-level detail required for auditing who made the change and how.

Exam trap

The trap here is that candidates often confuse AWS Config (which tracks configuration state) with CloudTrail (which tracks API activity), leading them to choose Config for change auditing when only CloudTrail provides the necessary who, what, and when details for IAM policy modifications.

How to eliminate wrong answers

Option A is wrong because AWS Config tracks resource configuration changes and evaluates compliance rules, but it does not record the API calls that initiated those changes, so it cannot provide the detailed audit trail of who made the IAM policy change and when. Option C is wrong because Amazon CloudWatch is a monitoring service for metrics, logs, and alarms, not designed to track API-level changes to IAM policies; it can ingest CloudTrail logs but does not natively capture them. Option D is wrong because AWS Trusted Advisor is an advisory service that inspects your environment for best practices and cost optimization, not a logging or auditing service for tracking changes.

606
Multi-Selecteasy

A SysOps administrator is creating a monitoring solution for a web application that uses an Application Load Balancer (ALB) and an Auto Scaling group of EC2 instances. The administrator wants to monitor the average request count per minute and the number of healthy hosts. Which TWO CloudWatch metrics should the administrator use? (Choose TWO.)

Select 2 answers
A.AWS/ApplicationELB Latency
B.AWS/ApplicationELB HealthyHostCount
C.AWS/EC2 CPUUtilization
D.AWS/AutoScaling GroupInServiceInstances
E.AWS/ApplicationELB RequestCount
AnswersB, E

AWS/ApplicationELB HealthyHostCount is the ALB metric that reports the number of targets that are considered healthy by the load balancer's health checks. This metric directly reflects the availability of registered instances as seen by the ALB, making it the correct choice for monitoring healthy hosts; a drop in this value can indicate failed health checks and potential service disruption.

Why this answer

AWS/ApplicationELB HealthyHostCount, is correct because it directly reports the number of registered instances that are passing health checks, which is exactly what the administrator needs to monitor the number of healthy hosts behind the ALB. Option E, AWS/ApplicationELB RequestCount, is correct because it tracks the total number of requests handled by the ALB, and by dividing by the time period, the administrator can calculate the average request count per minute.

Exam trap

The trap here is that candidates often confuse Auto Scaling group metrics (like GroupInServiceInstances) with ALB health check metrics (HealthyHostCount), not realizing that an instance can be InService but still unhealthy to the ALB if it fails health checks.

607
MCQmedium

A company has an S3 bucket policy as shown. A developer tries to upload an object using the AWS CLI without the --no-verify-ssl flag. What will happen?

A.The upload will succeed only if the developer uses HTTP.
B.The upload will fail because the policy denies all s3:* actions.
C.The upload will fail because the policy requires explicit HTTPS.
D.The upload will succeed because the CLI uses HTTPS by default.
AnswerD

The bucket policy allows s3:PutObject only when the request is made over a secure transport, as captured by the aws:SecureTransport condition key. The AWS CLI uses the HTTPS endpoint by default, so the request's SecureTransport value is true and the Allow branch applies. Consequently the upload is authorized and completes successfully.

Why this answer

The bucket policy denies requests that do not use secure transport (HTTP) but allows HTTPS requests. The AWS CLI uses HTTPS by default, and since the developer did not use --no-verify-ssl, the request is made over HTTPS. Therefore, the upload succeeds.

Option D is correct. Option A is incorrect because the CLI uses HTTPS, not HTTP. Option B is incorrect because the policy does not deny all s3:* actions; it only denies requests over HTTP.

Option C is incorrect because the policy requires HTTPS, and the CLI complies, so the upload does not fail.

608
Matchingmedium

Match each AWS database service to its type.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Relational database

NoSQL key-value and document

In-memory caching

Data warehousing

Graph database

Why these pairings

The correct matches are: Amazon RDS with relational database, Amazon DynamoDB with NoSQL key-value and document database, Amazon Redshift with data warehouse, and Amazon ElastiCache with in-memory cache. Common confusions include mistaking RDS for NoSQL or Redshift for caching.

609
MCQhard

A company uses AWS CloudFormation to deploy a multi-tier application. The stack includes an RDS DB instance with automated backups enabled. The SysOps administrator needs to ensure that the database can be recovered to any point within the last 35 days with minimal data loss. What should the administrator do?

A.Create a manual snapshot daily and retain 35 snapshots.
B.Set the backup retention period to 35 days.
C.Enable Multi-AZ on the RDS instance.
D.Configure AWS Backup with a 35-day backup plan.
AnswerB

Setting the backup retention period to 35 days on the RDS instance enables automated backups that include daily snapshots and transaction logs. These logs allow point-in-time recovery to any second within the retention window, which is exactly what the application needs. RDS supports a maximum retention period of 35 days, so this directly meets the stated requirement without additional tooling.

Why this answer

Automated backups in RDS allow point-in-time recovery (PITR) to any second within the backup retention period. By setting the retention period to 35 days, the administrator enables recovery to any point within that window, minimizing data loss to the last committed transaction before the restore time.

Exam trap

The trap here is that candidates confuse manual snapshots or AWS Backup with the point-in-time recovery capability that only automated backups provide, leading them to choose options that offer only full snapshot recovery rather than granular log-based restore.

How to eliminate wrong answers

Option A is wrong because manual snapshots are not point-in-time recoverable; they capture only the state at the time of creation, so you cannot recover to an arbitrary point between snapshots, leading to potential data loss of up to 24 hours. Option C is wrong because Multi-AZ provides high availability and automatic failover, not point-in-time recovery; it does not extend the backup retention or enable granular restore capabilities. Option D is wrong because AWS Backup can manage RDS snapshots but does not support point-in-time recovery for RDS; it only creates full snapshots, which lack the granularity needed for recovery to any second within 35 days.

610
MCQmedium

A company runs an e-commerce application on Amazon EC2 instances behind an Auto Scaling group. The application has a predictable baseline load from 8 AM to 8 PM daily and low load overnight. The SysOps administrator wants to optimize costs while ensuring sufficient capacity for the baseline load. Which purchasing option and scaling strategy should the administrator use?

A.Use On-Demand instances for the baseline and Spot Instances for any additional capacity.
B.Use Reserved Instances for the predicted baseline and On-Demand for any unexpected spikes.
C.Use Dedicated Hosts for all instances to maximize cost savings.
D.Use Spot Instances for all instances to minimize costs.
AnswerB

Reserved Instances should back the predictable baseline because they offer a substantial discount (up to 72% compared to On-Demand) for a commitment you know you will use, while On-Demand covers unexpected spikes without requiring a long-term contract. This combination minimizes cost on the steady-state load while retaining the flexibility to launch extra capacity at any moment, and it avoids the interruption risk of Spot for the mission-critical spikes.

Why this answer

Reserved Instances provide a significant discount (up to 72%) over On-Demand for predictable, steady-state workloads like the 8 AM to 8 PM baseline. On-Demand instances then cover any unexpected spikes without requiring upfront commitment, ensuring cost optimization while maintaining capacity for the predictable load.

Exam trap

The trap here is that candidates assume Spot Instances are always the cheapest option, but they fail to recognize that the predictable baseline load requires guaranteed availability, which Spot Instances cannot provide due to potential interruptions.

How to eliminate wrong answers

Option A is wrong because Spot Instances can be interrupted with a 2-minute warning when AWS needs capacity back, making them unsuitable for a baseline load that must be reliably available during business hours. Option C is wrong because Dedicated Hosts are a physical server dedicated to your use, which is far more expensive than Reserved Instances and provides no cost optimization benefit for a standard e-commerce application that does not require license compliance or physical isolation. Option D is wrong because Spot Instances are not suitable for all instances due to their potential for interruption, which would cause the application to fail during the predictable baseline load.

611
MCQhard

A company runs a stateful web application on EC2 instances in an Auto Scaling group across two Availability Zones. The application uses an Application Load Balancer for traffic distribution. Users report that their sessions are frequently lost during scale-in events. The SysOps administrator needs to minimize session loss without introducing significant latency. What should the administrator do?

A.Replace the Application Load Balancer with a Network Load Balancer. Enable proxy protocol v2 to pass client IP addresses.
B.Enable sticky sessions (session affinity) on the ALB. Configure a lifecycle hook on the Auto Scaling group with a wait time equal to the ALB's connection draining timeout.
C.Increase the Auto Scaling group's cooldown period to 600 seconds. Configure the ALB to have a deregistration delay of 600 seconds.
D.Configure the Auto Scaling group to scale based on memory utilization instead of CPU. Set the cooldown period to 300 seconds.
AnswerB

Enabling sticky sessions on the ALB uses the AWSALB cookie to pin a client's requests to the same target instance, preserving session state across the fleet. A lifecycle hook on the Auto Scaling group pauses the termination process during scale-in, and setting its wait time to match the ALB's connection draining timeout (deregistration delay) allows in-flight requests to finish before the instance is removed. This coordinated approach ensures that a terminating instance drains gracefully while session continuity is maintained.

Why this answer

Enabling sticky sessions (session affinity) on the ALB ensures that a client's requests are consistently routed to the same EC2 instance, preventing session loss during scale-in. Configuring a lifecycle hook on the Auto Scaling group with a wait time equal to the ALB's connection draining timeout (deregistration delay) allows in-flight requests to complete before the instance is terminated, minimizing session disruption without adding significant latency.

Exam trap

The trap here is that candidates often assume increasing timeouts (cooldown or deregistration delay) alone is sufficient, but without a lifecycle hook to coordinate the Auto Scaling group with the ALB's draining process, instances can be terminated prematurely, causing session loss.

How to eliminate wrong answers

Option A is wrong because replacing the ALB with a Network Load Balancer (NLB) does not provide session affinity (sticky sessions) natively; NLB operates at Layer 4 and cannot inspect HTTP session cookies, so it would not prevent session loss during scale-in. Option C is wrong because increasing the cooldown period to 600 seconds only delays subsequent scaling activities, not the termination of instances during scale-in, and the deregistration delay on the ALB alone does not coordinate with the Auto Scaling group to hold instances; without a lifecycle hook, instances can be terminated while still handling active sessions. Option D is wrong because changing the scaling metric to memory utilization and setting a cooldown period does not address session persistence or graceful instance termination; it only alters when scaling occurs, not how sessions are maintained during scale-in.

612
MCQmedium

A company uses AWS CodePipeline to deploy a web application. The pipeline includes a stage that runs a database migration script. The SysOps administrator wants to ensure that if the migration script fails, the entire pipeline stops and the previous version of the application remains deployed. Which pipeline stage configuration should be used to achieve this behavior?

A.Use a parallel action group for the migration step so other steps continue.
B.Configure the migration step as a sequential action and set the OnFailure to ABORT.
C.Configure the migration step as a sequential action and set the OnFailure to ROLLBACK.
D.Use a manual approval step after the migration to verify success.
AnswerB

Configuring the migration step as a sequential action with OnFailure set to ABORT causes CodePipeline to immediately stop the pipeline execution when that action fails, without running any subsequent actions or stages. The existing deployment remains untouched because no further deployment stages are triggered after the failure. This matches the requirement precisely: the pipeline halts and the prior version stays in place.

Why this answer

Setting the migration step as a sequential action with OnFailure set to ABORT ensures that if the migration script fails, the pipeline immediately stops and does not proceed to any subsequent stages. This prevents the deployment of a new application version that depends on a failed database migration, thereby keeping the previous version deployed.

Exam trap

The trap here is that candidates confuse the OnFailure ROLLBACK option with a full infrastructure rollback (like AWS CloudFormation stack rollback), not realizing that CodePipeline's ROLLBACK only affects the pipeline execution state and does not automatically revert the deployed application or database changes.

How to eliminate wrong answers

Option A is wrong because using a parallel action group would allow other steps to continue even if the migration fails, which contradicts the requirement to stop the entire pipeline and preserve the previous deployment. Option C is wrong because setting OnFailure to ROLLBACK would attempt to revert the pipeline to a previous state, but CodePipeline does not natively support automatic rollback of deployed application versions; ROLLBACK only retries the failed action or transitions to a failed state without restoring the prior application version. Option D is wrong because a manual approval step after the migration only adds a gate to verify success but does not automatically stop the pipeline or prevent deployment if the migration fails; it relies on human intervention and does not enforce the required behavior.

613
MCQhard

A SysOps administrator notices that a Lambda function is timing out after 30 seconds. The function processes large files from S3. How can the administrator improve performance while minimizing cost?

A.Increase the timeout value to 5 minutes.
B.Enable Provisioned Concurrency.
C.Increase the memory allocation of the Lambda function.
D.Deploy the function on an EC2 instance.
AnswerC

Lambda allocates CPU power in direct proportion to the memory configuration, so increasing memory gives the function more compute capacity to execute faster. For CPU-bound or memory-intensive workloads, this can dramatically reduce execution time and prevent timeouts. Since Lambda billing is based on compute time, a shorter duration may actually lower overall cost, making memory tuning the primary lever for performance optimization.

Why this answer

Increasing the memory allocation of the Lambda function also proportionally increases the allocated CPU power, which directly reduces the execution time for CPU-bound tasks like processing large files. This often resolves timeout issues without incurring additional cost per invocation, as the cost is a product of memory and duration, and a faster execution can offset the higher memory price.

Exam trap

The trap here is that candidates often assume increasing the timeout is the only way to fix a timeout error, overlooking that Lambda's memory setting controls CPU allocation and can actually speed up execution to stay within the original timeout.

How to eliminate wrong answers

Option A is wrong because simply increasing the timeout value does not address the root cause of slow processing; it only allows the function to run longer, which does not improve performance and may increase costs if the function still takes longer than 30 seconds. Option B is wrong because Provisioned Concurrency is designed to reduce cold start latency and handle burst scaling, not to improve the execution speed of a single invocation; it does not reduce the time a function takes to process data. Option D is wrong because deploying the function on an EC2 instance would require managing servers, increase operational overhead, and likely incur higher costs for the same workload, contradicting the goal of minimizing cost.

614
MCQhard

An application running on EC2 instances sends custom metrics to CloudWatch using the PutMetricData API. The metrics are not appearing in the CloudWatch console. The IAM role attached to the instances has the following policy: { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "cloudwatch:PutMetricData", "Resource": "*" } ] }. What is the most likely cause?

A.The metric timestamp is older than 14 days.
B.The metric namespace must start with 'AWS/'.
C.The metric data is being sent to a different AWS region.
D.The IAM policy does not allow the 'cloudwatch:PutMetricData' action.
AnswerC

Amazon CloudWatch is region-scoped, so metrics sent via PutMetricData are stored in the region of the endpoint used by the AWS SDK or CLI. If the application's CloudWatch client is configured with a region different from the one you are viewing in the console, the custom metrics will appear in that other region's CloudWatch and not in the region you are inspecting. An IAM policy allows the action and the timestamps are current, so the regional mismatch is the most plausible explanation for the metrics being absent.

Why this answer

The most likely cause is that the metric data is being sent to a different AWS region than the one displayed in the CloudWatch console. The PutMetricData API call includes a regional endpoint, and if the EC2 instance is configured to send metrics to a region other than the one you are viewing, the metrics will not appear. The IAM policy correctly allows the action, so authentication is not the issue.

Exam trap

The trap here is that candidates often assume the issue is a missing IAM permission or an invalid namespace, but the real problem is a region mismatch between where the data is sent and where it is viewed.

How to eliminate wrong answers

Option A is wrong because CloudWatch accepts metric data with timestamps up to 15 days in the past (and 2 hours in the future), so a timestamp older than 14 days is still within the acceptable range and would not prevent the metric from appearing. Option B is wrong because custom metric namespaces can be any string and do not need to start with 'AWS/'; the 'AWS/' prefix is reserved for AWS services, but custom metrics can use any namespace. Option D is wrong because the IAM policy explicitly allows 'cloudwatch:PutMetricData' on all resources, so there is no permission issue.

615
MCQeasy

A company has an EC2 instance that needs to have a static public IP address that does not change even if the instance is stopped and started. Which AWS resource should be attached to the instance?

A.An Elastic IP address
B.An automatically assigned public IP address
C.A secondary private IP address
D.A static private IP address
AnswerA

An Elastic IP address is a static public IPv4 address allocated to your AWS account that persists until you explicitly release it. Unlike an automatically assigned public IP, an EIP can be associated with an instance and remains fixed across instance stops, starts, and replacements. You can also remap it to another instance in the same region, making it the correct way to give an EC2 instance a permanent public endpoint.

Why this answer

An Elastic IP address is a static, public IPv4 address designed for dynamic cloud computing. When associated with an EC2 instance, it remains fixed even if the instance is stopped and started, unlike automatically assigned public IPs which change on stop/start. This meets the requirement for a static public IP.

Exam trap

The trap is confusing private and public IPs — candidates might think a static private IP (Option D) provides public accessibility, but only Elastic IPs offer static public addressing.

How to eliminate wrong answers

Option B is wrong because an automatically assigned public IP is dynamic and is released when the instance is stopped, then a new one is assigned on start. Option C is wrong because a secondary private IP is internal to the VPC and not publicly routable; it does not provide a static public IP. Option D is wrong because a static private IP is also internal and does not provide public internet accessibility.

616
MCQeasy

A SysOps administrator uses AWS CloudFormation to deploy infrastructure. The administrator needs to store and reference sensitive data such as database passwords in the stack without hardcoding them in the template. Which CloudFormation feature should be used?

A.Use AWS Systems Manager Parameter Store secure strings and dynamic references in the CloudFormation template
B.Use AWS Secrets Manager and reference the secret using a static reference in the template
C.Define plaintext parameters in the template and mark them as NoEcho
D.Store the secrets in an encrypted S3 object and reference it via a URL in the template
AnswerA

CloudFormation dynamic references (e.g., {{resolve:ssm-secure:MyParameter}}) resolve secure string parameter values from Systems Manager Parameter Store during stack create and update operations, so the plaintext secret never appears in the template itself. The secure string is encrypted with a customer-managed or AWS-managed KMS key, and CloudFormation retrieves the decrypted value only at stack operation time, which prevents secrets from being exposed in template files, repository history, or AWS CloudTrail logs.

Why this answer

AWS CloudFormation supports dynamic references (using the `resolve:ssm` or `resolve:ssm-secure` syntax) that allow you to reference Systems Manager Parameter Store secure strings directly in the template. This keeps sensitive data like database passwords out of the template and the stack's metadata, ensuring they are not exposed in plaintext during stack operations or in the console.

Exam trap

The trap here is that candidates confuse `NoEcho` (which only hides display output) with actual secure storage, or they assume static references work with Secrets Manager when only dynamic references are supported for both Parameter Store secure strings and Secrets Manager secrets.

How to eliminate wrong answers

Option B is wrong because AWS Secrets Manager secrets cannot be referenced using a static reference in CloudFormation; they require a dynamic reference (e.g., `resolve:secretsmanager:secret-id:secret-string:json-key:version-stage:version-id`) to retrieve the secret value at deploy time, not a static reference. Option C is wrong because marking a parameter as `NoEcho` only hides its value in console output and logs, but the plaintext value is still passed to the CloudFormation template and can be exposed in the stack's metadata or API responses; it does not provide encryption or secure storage. Option D is wrong because storing secrets in an encrypted S3 object and referencing it via a URL in the template requires the S3 object to be publicly accessible or the template to include IAM permissions to read it, and the URL itself could be exposed in the template or stack metadata, defeating the purpose of secure handling.

617
MCQmedium

A company has an Application Load Balancer (ALB) in the us-east-1 region. Users in Asia report high latency. The SysOps administrator wants to use AWS Global Accelerator to improve performance by directing traffic to the closest edge location. Which step is required to integrate Global Accelerator with the ALB?

A.Create a CloudFront distribution and point it to the ALB as an origin.
B.Configure the ALB as an endpoint group in a Global Accelerator accelerator.
C.Set up a Route 53 geoproximity routing policy for the ALB.
D.Use AWS WAF to allow traffic from Global Accelerator edge locations.
AnswerB

Global Accelerator is a networking service that provides two static anycast IP addresses at AWS edge locations and routes traffic over the AWS global network to the ALB endpoint. By adding the ALB as an endpoint in an endpoint group for the us-east-1 region, user traffic from Asia enters the AWS backbone at the nearest edge and traverses the private, low-latency AWS network instead of the congested public internet. This also brings health checking, automatic failover, and consistent performance even during internet disruptions.

Why this answer

AWS Global Accelerator uses the AWS global network to route traffic to the closest edge location, then forwards it over the AWS backbone to the ALB endpoint. To integrate, you must configure the ALB as an endpoint in an endpoint group within the accelerator, which allows Global Accelerator to direct traffic to the ALB based on proximity and health. This reduces latency for users in Asia by minimizing internet hops.

Exam trap

The trap here is that candidates often confuse Global Accelerator with CloudFront or Route 53 routing policies, assuming any CDN or DNS-based solution can achieve the same latency reduction, but Global Accelerator uniquely provides static IP addresses and optimized network pathing without caching or DNS caching delays.

How to eliminate wrong answers

Option A is wrong because CloudFront is a content delivery network (CDN) optimized for caching static and dynamic content, not for TCP/UDP traffic acceleration to an ALB; it adds unnecessary complexity and does not provide the anycast IP-based global acceleration that Global Accelerator offers. Option C is wrong because Route 53 geoproximity routing is a DNS-based routing policy that can direct users to different endpoints based on geographic location, but it does not provide the static anycast IP addresses or the optimized network path that Global Accelerator uses to reduce latency; DNS-based routing is also subject to client-side caching and does not offer the same performance improvements. Option D is wrong because AWS WAF is a web application firewall that filters HTTP/S traffic based on rules, not a mechanism to integrate or allow traffic from Global Accelerator edge locations; Global Accelerator automatically handles traffic routing without requiring WAF configuration for integration.

618
MCQmedium

A security policy prohibits opening SSH port 22 on any EC2 instance. The operations team needs to run a shell script on 150 Linux instances to collect configuration inventory data. The script output must be captured for review. How should the team execute the script?

A.Use SSM Run Command with the AWS-RunShellScript document targeting all 150 instances; send output to an S3 bucket
B.Create a bastion host with SSH access and use a for loop to SSH into each instance and run the script
C.Use EC2 Instance Connect to establish a temporary SSH session for each instance and run the script
D.Terminate all instances and re-launch them from a new AMI that includes the configuration inventory already baked in
AnswerA

Run Command invocations use the SSM Agent's existing outbound HTTPS connection (port 443) — no inbound rule changes are needed. The command output for each instance is stored separately in S3, allowing the team to review per-instance results. Commands can target instances by tag (e.g., Environment=production) to avoid listing all 150 instance IDs manually.

Why this answer

SSM Run Command with the AWS-RunShellScript document allows you to execute shell scripts on multiple EC2 instances without opening SSH port 22, as it operates over the AWS Systems Manager agent (SSM Agent) using HTTPS (port 443). The output can be directed to an S3 bucket for centralized review, satisfying both the security policy and the requirement to capture script output.

Exam trap

The trap here is that candidates may assume EC2 Instance Connect or a bastion host are acceptable workarounds, but both still rely on SSH (port 22), which is explicitly prohibited by the security policy, whereas SSM Run Command operates over HTTPS and fully complies.

How to eliminate wrong answers

Option B is wrong because it requires opening SSH port 22 on the instances or the bastion host, which directly violates the security policy prohibiting SSH access. Option C is wrong because EC2 Instance Connect still relies on SSH (port 22) to establish a temporary session, which is also prohibited by the policy. Option D is wrong because terminating and re-launching instances from a new AMI is an overly destructive and inefficient approach that does not capture runtime configuration inventory data from the existing instances.

619
MCQhard

A company has a web application behind an Application Load Balancer (ALB) in a VPC. The application needs to authenticate users using an external identity provider (IdP). The SysOps Administrator recommends using Amazon Cognito as an identity broker. Which ALB action should be configured to authenticate users before forwarding requests to the target group?

A.An authenticate action using Amazon Cognito as the user pool.
B.A fixed-response action to return a 401 status code.
C.A redirect action to the IdP login page.
D.A forward action to the target group.
AnswerA

The ALB authenticate action with Amazon Cognito as the user pool is purpose-built for this use case. When a rule has this action, ALB redirects the user to Cognito's hosted UI, performs the OAuth 2.0 authorization code flow, validates the returned tokens, and then forwards the request to the target with user claims embedded in X-AMZN-OIDC headers and a session cookie. This is the only option that both verifies the user's identity and creates an authenticated session at the load balancer layer.

Why this answer

Amazon Cognito integrates directly with Application Load Balancers via an authenticate action. When you configure an ALB rule with an authenticate action using a Cognito user pool, the ALB handles the OAuth 2.0 / OpenID Connect flow with the external IdP, obtains tokens, and only forwards authenticated requests to the target group. This eliminates the need for custom authentication logic in the application.

Exam trap

The trap here is that candidates may think a simple redirect action (Option C) is sufficient, but they miss that the ALB must actively participate in the token exchange and validation, which only the authenticate action provides.

How to eliminate wrong answers

Option B is wrong because a fixed-response action returning a 401 status code would simply reject all requests without any authentication flow, failing to integrate with the external IdP. Option C is wrong because a redirect action to the IdP login page would send users to the IdP but the ALB would not handle the callback or validate tokens, leaving authentication incomplete and unmanaged. Option D is wrong because a forward action to the target group would bypass authentication entirely, allowing unauthenticated requests to reach the application.

620
MCQhard

A SysOps administrator uses AWS CloudFormation to deploy infrastructure. The admin has a template that creates an EC2 instance with a custom software stack. The software stack must be installed and configured using PowerShell scripts. The admin wants to minimize operational overhead by automating the creation of an AMI that includes the software stack, and the AMI should be rebuilt on a weekly basis to include the latest security patches. Which combination of AWS services should be used?

A.Use EC2 Image Builder to define a component with the PowerShell scripts, create a recipe, and schedule a pipeline to run weekly.
B.Use AWS Systems Manager Automation to run a PowerShell script on an existing EC2 instance, then manually create an AMI each week.
C.Use AWS CodePipeline with CodeBuild to run the PowerShell scripts and create an AMI using the AWS CLI, triggered by a weekly CloudWatch Events schedule.
D.Use Amazon EC2 Auto Scaling with a lifecycle hook to run the PowerShell script on instance launch, and schedule a weekly instance refresh.
AnswerA

EC2 Image Builder is the purpose-built AWS service for producing golden AMIs. A component encapsulates the PowerShell script logic, a recipe bundles that component with a base image and OS settings, and a pipeline can be scheduled to run weekly to automatically build, validate, and register the AMI. It also supports post-build testing and cross-account/region distribution, giving a fully managed, auditable image lifecycle with minimal operational overhead.

Why this answer

EC2 Image Builder is purpose-built for automating the creation, patching, and testing of custom AMIs. By defining a component that encapsulates the PowerShell scripts, creating a recipe that references that component, and scheduling a pipeline to run weekly, the administrator achieves fully automated, repeatable AMI builds with minimal operational overhead. This directly meets the requirement for weekly rebuilds with the latest security patches.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing a multi-service orchestration (like CodePipeline + CodeBuild) when a single, purpose-built service (EC2 Image Builder) is designed exactly for this use case, leading to unnecessary complexity and operational overhead.

How to eliminate wrong answers

Option B is wrong because it requires manual intervention each week to create the AMI, which contradicts the goal of minimizing operational overhead and does not provide automation. Option C is wrong because while CodePipeline and CodeBuild can automate AMI creation, they are not the simplest or most purpose-built solution for this task; EC2 Image Builder is specifically designed for image lifecycle management, reducing complexity and maintenance. Option D is wrong because EC2 Auto Scaling with lifecycle hooks and instance refresh is designed for managing running instances and fleet updates, not for building and maintaining a golden AMI; it does not provide a mechanism to create a new AMI on a weekly schedule.

621
MCQmedium

A SysOps administrator needs to monitor AWS CloudTrail logs for any calls to the 'CreateUser' API in AWS Identity and Access Management (IAM). When such an API call is detected, the administrator wants to receive a notification within a few minutes and also log the event to a central log group in Amazon CloudWatch Logs. The solution should use minimal custom code. Which combination of services should be used?

A.Configure AWS CloudTrail to deliver logs to Amazon CloudWatch Logs, create a metric filter for the 'CreateUser' API call, and set up a CloudWatch alarm that sends an Amazon SNS notification.
B.Use AWS CloudTrail with Amazon EventBridge by creating an event rule that matches the 'CreateUser' API call via the 'aws.cloudtrail' event source, and set the targets to an Amazon SNS topic and a CloudWatch Logs log group.
C.Write an AWS Lambda function that is triggered by Amazon S3 events when a new CloudTrail log is delivered to S3. The Lambda parses the log file for 'CreateUser' and if found, sends an SNS notification.
D.Enable AWS Config and create a custom rule that evaluates CloudTrail trail configurations for events.
AnswerB

Amazon EventBridge natively listens for AWS service events, including CloudTrail API calls. By creating a rule with a custom event pattern that matches the specific API call, you can directly send the event to multiple targets (SNS, CloudWatch Logs, Lambda, etc.) without needing metric filters or alarms. This is the recommended low-overhead solution.

Why this answer

Amazon EventBridge can directly consume CloudTrail events in near-real time via the 'aws.cloudtrail' event source, allowing you to create a rule that matches the 'CreateUser' API call. This rule can then target both an Amazon SNS topic for immediate notification and a CloudWatch Logs log group for centralized logging, all without custom code.

Exam trap

The trap here is that candidates often assume CloudTrail-to-CloudWatch Logs delivery is the fastest method, but they overlook the inherent delivery latency and the fact that EventBridge provides a more immediate, event-driven path for real-time monitoring.

How to eliminate wrong answers

Option A is wrong because while CloudTrail can deliver logs to CloudWatch Logs, this delivery has a latency of up to 15 minutes, which does not meet the 'within a few minutes' requirement; also, metric filters and alarms operate on the delivered logs, not on the event stream. Option C is wrong because it requires custom Lambda code to parse S3-delivered CloudTrail logs, which violates the 'minimal custom code' requirement and introduces additional latency and complexity. Option D is wrong because AWS Config evaluates resource configurations, not real-time API call events; a custom Config rule cannot detect individual 'CreateUser' API calls as they occur.

622
MCQmedium

A SysOps administrator notices that traffic to an Application Load Balancer (ALB) is being rejected. The ALB has a security group that allows inbound HTTP (80) and HTTPS (443) from 0.0.0.0/0. The target group health checks are failing. What could be the issue?

A.The target instances' security group does not allow inbound traffic from the ALB security group.
B.The ALB security group does not allow outbound traffic to the targets.
C.The ALB’s security group is blocking health check traffic from the targets.
D.The target instances' security group does not allow inbound HTTP/HTTPS from the internet.
AnswerA

For an ALB health check to succeed, the target instance's security group must explicitly allow inbound traffic on the health check port from the ALB's security group as the source. This rule permits the ALB to establish the health check connection and receive the response. Without it, the target rejects the health check packets, causing the instance to be marked unhealthy even though the application itself may be running.

Why this answer

For an ALB to route traffic to targets, the targets' security group must allow inbound traffic from the ALB's security group on the target port. Even if the ALB's security group allows inbound HTTP/HTTPS from the internet, the targets will reject traffic if their security group does not permit it. This is a common misconfiguration that causes health checks to fail.

Exam trap

The trap is assuming that if the ALB's security group allows inbound traffic, the targets will automatically accept it; candidates forget that the targets have their own security groups that must also allow traffic from the ALB.

How to eliminate wrong answers

Option B is wrong because ALB security groups are stateful and allow outbound traffic by default; outbound rules are not the issue. Option C is wrong because health check traffic originates from the ALB to the targets, not the other way around, so the ALB's security group does not need to allow inbound from targets. Option D is wrong because targets do not need to allow inbound from the internet; they only need to allow traffic from the ALB.

623
MCQhard

An application runs on EC2 instances behind an ALB. Users report slow response times. CPU utilization averages 90% during peak hours. What is the MOST effective way to improve performance?

A.Enable detailed monitoring on CloudWatch.
B.Switch to a memory-optimized instance type.
C.Add more Security Group rules.
D.Increase the instance size to a larger type.
AnswerD

Increasing the instance size to a larger type in the same family directly adds vCPUs and baseline CPU capacity, which helps absorb the workload being distributed by the ALB. For example, moving from one size to the next doubles the number of vCPUs and often increases network bandwidth, allowing the instance to process more concurrent requests without saturating the CPU. This vertical scaling approach correctly addresses the stated CPU-bound bottleneck.

Why this answer

Increasing the instance size (scaling up) provides more CPU resources directly, addressing the high utilization. While Auto Scaling could add more instances, the question specifically asks about the given options, and D is the most effective among them. Detailed monitoring (A) only provides metrics, not performance improvement.

Memory-optimized (B) does not help CPU-bound issues. Security group rules (C) do not affect compute performance.

624
MCQmedium

A company runs a batch processing job every night on Amazon EC2 instances. The job takes exactly 2 hours to complete and can be interrupted and resumed later. The SysOps administrator wants to minimize compute costs. Which purchasing option should be used?

A.Spot Instances
B.Reserved Instances
C.On-Demand Instances
D.Dedicated Instances
AnswerA

Spot Instances deliver up to a 90% discount compared to On-Demand pricing because AWS sells spare EC2 capacity through a bidding market. Nightly batch jobs that can be interrupted and restarted or resumed are textbook use cases for Spot, especially with the EC2 Fleet or Spot Fleet using a capacity-optimized allocation strategy. To tolerate eviction, you can implement checkpointing in the job and set short max-price per instance-hour, letting AWS reclaim the instance mid-run without corrupting output. The ability to tolerate interruption is precisely why Spot minimizes costs over all other options for this flexible, interruptible workload.

Why this answer

Spot Instances are the correct choice because the batch job is fault-tolerant (can be interrupted and resumed) and runs for a fixed 2-hour window nightly. Spot Instances offer up to 90% cost savings compared to On-Demand, and with the ability to handle interruptions via checkpointing, they minimize compute costs without requiring a long-term commitment.

Exam trap

The trap here is that candidates often choose On-Demand Instances due to a mistaken belief that any interruptible workload requires guaranteed availability, ignoring that Spot Instances are explicitly designed for fault-tolerant, stateless, or checkpointable workloads like batch processing.

How to eliminate wrong answers

Option B (Reserved Instances) is wrong because they require a 1- or 3-year commitment and are cost-effective only for steady-state workloads, not for a nightly 2-hour job that can be interrupted. Option C (On-Demand Instances) is wrong because they are the most expensive option and provide no cost savings for a fault-tolerant, interruptible workload. Option D (Dedicated Instances) is wrong because they are designed for regulatory or licensing requirements that demand physical isolation, not for cost optimization, and they incur additional per-instance fees.

625
MCQmedium

A company requires that all Amazon S3 buckets in its AWS account must be encrypted using AWS KMS (SSE-KMS). The SysOps administrator needs to detect any bucket that does not have KMS encryption enabled and automatically remediate it by enabling encryption. Which AWS service should be used to implement this automated compliance enforcement?

A.AWS Config
B.AWS CloudTrail
C.Amazon GuardDuty
D.AWS Trusted Advisor
AnswerA

AWS Config can continuously monitor and evaluate S3 bucket configurations. With a managed rule for server-side encryption, it can detect non-compliant buckets. Combined with automatic remediation actions, AWS Config can enable encryption on non-compliant buckets without manual intervention.

Why this answer

AWS Config is the correct service because it can continuously monitor S3 bucket configurations against a desired encryption state using managed rules like 's3-bucket-server-side-encryption-enabled' or custom Lambda rules. When a non-compliant bucket is detected, AWS Config can trigger an automatic remediation action via Systems Manager Automation to enable SSE-KMS encryption, enforcing compliance without manual intervention.

Exam trap

The trap here is that candidates often confuse AWS Config's detective and remediation capabilities with CloudTrail's logging or Trusted Advisor's advisory-only checks, assuming any 'security' service can enforce compliance, but only AWS Config provides automated remediation via rules and Systems Manager.

How to eliminate wrong answers

Option B is wrong because AWS CloudTrail is a service for auditing API calls and logging activity, not for detecting or remediating configuration drift in real time. Option C is wrong because Amazon GuardDuty is a threat detection service that analyzes DNS, VPC flow logs, and CloudTrail events for malicious activity, not for enforcing encryption policies on S3 buckets. Option D is wrong because AWS Trusted Advisor provides best-practice recommendations and checks for cost optimization, security, and performance, but it cannot automatically remediate non-compliant resources; it only reports findings.

626
MCQeasy

A SysOps administrator needs to automate the creation of an Amazon S3 bucket with versioning enabled and default encryption using AWS CloudFormation. Which CloudFormation resource type should the administrator use?

A.AWS::S3::Bucket
B.AWS::S3::BucketPolicy
C.AWS::KMS::Key
D.AWS::S3::BucketVersioning
AnswerA

AWS::S3::Bucket is the CloudFormation resource type that directly provisions an S3 bucket as part of a stack. It supports configuration properties such as BucketName, VersioningConfiguration, AccessControl, and Encryption, allowing the bucket to be created with the desired settings. When included in a template, CloudFormation handles the full lifecycle of the bucket, including creation, updates, and deletion on stack removal.

Why this answer

AWS::S3::Bucket is the CloudFormation resource type used to create an S3 bucket, and it supports properties such as VersioningConfiguration and BucketEncryption directly within the resource definition. This allows the administrator to enable versioning and default encryption in a single resource declaration.

Exam trap

SOA-C02 often tests whether candidates know that versioning and encryption are properties of AWS::S3::Bucket, not separate resource types — the fictitious AWS::S3::BucketVersioning is a classic distractor.

How to eliminate wrong answers

Option B is wrong because AWS::S3::BucketPolicy only attaches a bucket policy (access control) and cannot create a bucket or configure versioning/encryption. Option C is wrong because AWS::KMS::Key creates a KMS key, which may be referenced by the bucket's encryption configuration but does not create or configure the bucket itself. Option D is wrong because AWS::S3::BucketVersioning is not a valid CloudFormation resource type — versioning is configured as a property (VersioningConfiguration) of AWS::S3::Bucket, not a standalone resource.

627
MCQeasy

A SysOps administrator needs to monitor application logs in Amazon CloudWatch Logs for the occurrence of the string 'ERROR'. The administrator wants to create a custom metric that counts the number of 'ERROR' occurrences per 5-minute window and trigger an Amazon CloudWatch alarm when the count exceeds 10. Which action should the administrator take to create the custom metric?

A.Create a CloudWatch Events rule that triggers on 'ERROR' and publishes a metric.
B.Create a metric filter on the CloudWatch Logs log group that matches the term 'ERROR'.
C.Create a CloudWatch dashboard that displays the log group and set an alarm on the dashboard.
D.Enable AWS CloudTrail on the log group and select the 'ERROR' pattern.
AnswerB

A metric filter is the correct way to define a pattern to look for in log events. CloudWatch Logs uses the filter to publish a numeric metric to CloudWatch, which can then be used for alarms.

Why this answer

Metric filters in CloudWatch Logs allow you to define a pattern (e.g., 'ERROR') that is evaluated against incoming log events. The filter counts occurrences and publishes a custom metric to CloudWatch, which can then be used to set an alarm with a period of 5 minutes and a threshold of 10.

Exam trap

The trap here is that candidates confuse CloudWatch Logs metric filters with CloudWatch Events or CloudTrail, thinking those services can parse log content, when in fact only metric filters can extract and count patterns from log data.

How to eliminate wrong answers

Option A is wrong because CloudWatch Events (now Amazon EventBridge) is used to trigger actions based on events, not to parse log content and create custom metrics; it cannot count string occurrences in log streams. Option C is wrong because a CloudWatch dashboard is a visualization tool and cannot directly create a custom metric or trigger an alarm; alarms are set on metrics, not dashboards. Option D is wrong because AWS CloudTrail records API activity, not application log content; it cannot be enabled on a CloudWatch Logs log group or used to count 'ERROR' strings in application logs.

628
Multi-Selecthard

Which THREE components are required to establish a site-to-site VPN connection between an AWS VPC and an on-premises network? (Choose three.)

Select 3 answers
A.Customer gateway (CGW)
B.Transit gateway
C.VPN connection
D.Virtual private gateway (VGW)
E.AWS Direct Connect
AnswersA, C, D

The Customer Gateway (CGW) is a logical object in AWS that represents the on-premises VPN device or software application. It stores the public IP address of the customer-side router and, if BGP is used, the Border Gateway Protocol Autonomous System Number (ASN). It is mandatory because the AWS-side virtual private gateway needs a defined peer endpoint to establish the IPsec tunnels, and route propagation depends on this object. Without the CGW, there is no specified remote device to encrypt traffic to.

Why this answer

A customer gateway (CGW) is required because it represents the on-premises side of the site-to-site VPN connection. It provides the public IP address and BGP ASN (if dynamic routing is used) of the on-premises VPN device, allowing AWS to establish IPsec tunnels with the correct endpoint.

Exam trap

The trap here is that candidates often think a transit gateway is required for site-to-site VPN, but it is only needed when you want to centralize routing across multiple VPCs or use advanced features like route propagation; a single VPC-to-on-premises VPN works with just a VGW, CGW, and VPN connection.

629
MCQmedium

A SysOps administrator is creating a CloudFormation stack and receives the error shown in the exhibit. The template snippet for the Auto Scaling group is: "MyAutoScalingGroup": { "Type": "AWS::AutoScaling::AutoScalingGroup", "Properties": { "MinSize": "1", "MaxSize": "5", "DesiredCapacity": "2", ... } }

A.The DesiredCapacity value must be less than MinSize.
B.The MinSize value exceeds the MaxSize value.
C.The Auto Scaling group must have a scaling policy.
D.The MinSize value must be specified as an integer, not a string.
AnswerD

CloudFormation enforces strict type validation for resource properties, and the MinSize attribute for AWS::AutoScaling::AutoScalingGroup is defined as an integer. When a value like "1" is passed as a quoted string, CloudFormation rejects the template because it does not match the expected Integer type. The fix is to remove the quotes or use the intrinsic function with a proper numeric value in the template.

Why this answer

The `MinSize`, `MaxSize`, and `DesiredCapacity` properties in an `AWS::AutoScaling::AutoScalingGroup` resource must be specified as integer values, not strings. In the provided template snippet, `"1"` is a string literal, which causes CloudFormation to fail validation because it expects a numeric type (e.g., `1` without quotes).

Exam trap

The trap here is that candidates often focus on logical constraints like MinSize vs MaxSize or DesiredCapacity ranges, overlooking the subtle but critical data type mismatch between a string and an integer in the template syntax.

How to eliminate wrong answers

Option A is wrong because `DesiredCapacity` must be between `MinSize` and `MaxSize` inclusive, not less than `MinSize`; a value less than `MinSize` would be invalid. Option B is wrong because `MinSize` (1) does not exceed `MaxSize` (5); the error is unrelated to this comparison. Option C is wrong because an Auto Scaling group does not require a scaling policy to be created; it can operate with only the `MinSize`, `MaxSize`, and `DesiredCapacity` values.

630
MCQmedium

A SysOps administrator needs to ensure that all traffic to an Application Load Balancer (ALB) uses encryption. How can this be enforced?

A.Configure the security group to allow only HTTPS traffic (port 443).
B.Create a listener that redirects HTTP requests (port 80) to HTTPS (port 443).
C.Use AWS WAF to block HTTP requests.
D.Configure the ALB to use a custom SSL certificate.
AnswerB

An Application Load Balancer listener rule can define a redirect action that responds to every HTTP (port 80) request with a 301 or 302 status and the corresponding HTTPS URL, preserving the path and query parameters. This is the native, supported pattern to force HTTPS because it transparently upgrades the client before the request reaches any target. The redirect action is evaluated before routing to target groups, so no compute resources are needed to enforce the policy.

Why this answer

An Application Load Balancer can be configured with a listener rule that redirects incoming HTTP (port 80) requests to HTTPS (port 443). This ensures that all traffic to the ALB is encrypted in transit, as any unencrypted HTTP request is automatically redirected to the secure HTTPS protocol. The redirect action is a native ALB feature and does not require additional services or complex configurations.

Exam trap

The trap here is that candidates often confuse security group rules with application-layer behavior, mistakenly believing that restricting the security group to port 443 alone will enforce encryption, when in fact it only controls network access and does not prevent unencrypted traffic on that port.

How to eliminate wrong answers

Option A is wrong because security groups operate at the network layer and can only allow or deny traffic based on IP addresses, ports, and protocols; they cannot enforce encryption or redirect traffic. Even if the security group allows only port 443, a client could still send unencrypted HTTP traffic to that port, and the ALB would accept it if a listener exists for HTTP on port 443. Option C is wrong because AWS WAF is a web application firewall that inspects HTTP/HTTPS requests for malicious patterns, but it cannot enforce encryption or redirect HTTP to HTTPS; it operates after the listener has accepted the connection.

Option D is wrong because configuring a custom SSL certificate on the ALB enables HTTPS but does not automatically redirect HTTP traffic to HTTPS; without a redirect rule, clients can still send unencrypted HTTP requests to the ALB.

631
Multi-Selecthard

A SysOps Administrator is configuring VPC Flow Logs to monitor network traffic. Which THREE pieces of information are included in VPC Flow Log records?

Select 3 answers
A.HTTP status code
B.Protocol number
C.Source IP address
D.DNS query name
E.Destination IP address
AnswersB, C, E

The protocol number field in a VPC Flow Log record identifies the IP protocol used for the traffic, using IANA-assigned numbers (e.g., 6 for TCP, 17 for UDP, 1 for ICMP). This numeric value is captured directly from the IP header, independent of the application layer. Flow log records include this field regardless of whether the traffic is TCP, UDP, or another protocol, making it a reliable attribute for filtering and analyzing traffic types.

Why this answer

VPC Flow Logs capture metadata about network traffic, including source IP address (C), destination IP address (E), and protocol number (B). They do not include HTTP status codes (A) or DNS query names (D), as those are application-layer details beyond the scope of network flows.

632
MCQeasy

A SysOps administrator needs to automatically deploy a new version of an application to a fleet of Amazon EC2 instances every time changes are pushed to the main branch of a code repository hosted on AWS CodeCommit. Which combination of AWS services should be used?

A.AWS CodePipeline, AWS CodeBuild, and AWS CodeDeploy.
B.AWS CloudFormation and AWS CodeDeploy.
C.Amazon EventBridge and AWS Systems Manager.
D.AWS CloudTrail and AWS Lambda.
AnswerA

AWS CodePipeline, AWS CodeBuild, and AWS CodeDeploy form a fully managed CI/CD service chain: CodePipeline is the orchestrator that automatically starts on a new CodeCommit push, CodeBuild compiles and packages the application into an artifact, and CodeDeploy deploys that artifact to compute services such as EC2 or Lambda. This trio natively supports stage progression, artifact handoff, rollback alarms, and permission transitions without custom code, making it the only choice that delivers end-to-end automated deployment from a repository event.

Why this answer

AWS CodePipeline orchestrates the continuous delivery workflow by detecting changes in the CodeCommit repository, then automatically triggering AWS CodeBuild to compile and package the application, and finally deploying the new version to EC2 instances using AWS CodeDeploy. This combination provides a fully managed, end-to-end CI/CD pipeline that meets the requirement of deploying on every push to the main branch.

Exam trap

The trap here is that candidates often confuse AWS CloudFormation (infrastructure provisioning) with CI/CD pipeline services, or assume EventBridge and Lambda can replace the full pipeline, but they lack built-in artifact management, deployment strategies, and rollback capabilities that CodePipeline, CodeBuild, and CodeDeploy provide together.

How to eliminate wrong answers

Option B is wrong because AWS CloudFormation is an infrastructure-as-code service for provisioning resources, not a CI/CD pipeline orchestrator; it cannot automatically detect CodeCommit pushes or trigger deployments without an external event source. Option C is wrong because Amazon EventBridge can capture CodeCommit events but AWS Systems Manager is primarily for operational management and patching, not for orchestrating a multi-stage build-and-deploy pipeline with artifact management. Option D is wrong because AWS CloudTrail records API activity for auditing, not for triggering deployments, and AWS Lambda alone cannot manage the full build, test, and deployment lifecycle required for application updates.

633
MCQeasy

A company needs a dedicated private network connection from its on-premises data center to AWS that provides consistent network performance and high bandwidth. The connection must bypass the public internet. Which AWS service should the SysOps administrator use?

A.AWS Site-to-Site VPN
B.AWS Client VPN
C.AWS Direct Connect
D.AWS Transit Gateway
AnswerC

AWS Direct Connect is the correct answer because it provides a dedicated private network connection from an on-premises data center to AWS using a physical cross-connect at a Direct Connect location. This connection bypasses the public internet, delivering consistent network performance, lower latency, and higher bandwidth options (e.g., 1 Gbps or 10 Gbps, and up to 100 Gbps with aggregated links). It also reduces bandwidth costs and provides a more predictable networking experience for hybrid architectures. Direct Connect is the dedicated private circuit required by the company.

Why this answer

AWS Direct Connect is the correct choice because it provides a dedicated, private network connection from an on-premises data center to AWS, bypassing the public internet entirely. This ensures consistent network performance, low latency, and high bandwidth, which are critical for workloads requiring predictable throughput and a private link.

Exam trap

The trap here is that candidates often confuse AWS Site-to-Site VPN with a private connection, overlooking that it still traverses the public internet and cannot guarantee consistent performance or bypass it, whereas Direct Connect provides a dedicated physical link.

How to eliminate wrong answers

Option A is wrong because AWS Site-to-Site VPN uses the public internet to establish an encrypted tunnel (IPsec) between the on-premises network and AWS, which cannot guarantee consistent performance or bypass the public internet. Option B is wrong because AWS Client VPN is a managed remote access VPN service for individual clients (e.g., laptops) connecting over the internet, not for dedicated private network connections between data centers and AWS. Option D is wrong because AWS Transit Gateway is a network transit hub that connects VPCs and on-premises networks via VPN or Direct Connect, but it is not a connection service itself; it requires a separate underlying connection like Direct Connect or VPN to provide the private link.

634
MCQhard

A company has a production application running on Amazon ECS with Fargate launch type. The application uses an Application Load Balancer. The SysOps administrator notices that during deployments, the application experiences a brief period of downtime. Which combination of actions should the administrator take to achieve zero-downtime deployments?

A.Configure the ECS service to use a rolling update with a minimum healthy percent of 0 and a maximum percent of 100.
B.Increase the deregistration delay on the ALB target group to 300 seconds.
C.Use a blue/green deployment with CodeDeploy and set the 'Minimum healthy percent' to 50.
D.Configure the ECS service to use a rolling update with a minimum healthy percent of 100 and a maximum percent of 200.
AnswerD

This rolling update configuration ensures that ECS starts new tasks up to twice the desired count (maximum percent 200) before terminating any existing tasks, while the minimum healthy percent of 100 guarantees that the service never drops below the desired number of running tasks. Because new tasks are registered with the load balancer and pass health checks before old tasks are stopped, traffic is served continuously without interruption. This is the classic zero-downtime deployment strategy for ECS services behind an ALB.

Why this answer

Setting the minimum healthy percent to 100 and maximum percent to 200 ensures that during a rolling update, the ECS service first launches new tasks (up to 200% of the desired count) before terminating any old tasks. This guarantees that the ALB always has a sufficient number of healthy targets to serve traffic, eliminating downtime. The Application Load Balancer distributes traffic between old and new tasks during the transition, achieving zero-downtime deployments.

Exam trap

The trap here is that candidates often confuse the minimum healthy percent and maximum percent values, mistakenly thinking that allowing all tasks to be replaced at once (0/100) is acceptable, or that blue/green deployments inherently guarantee zero downtime without proper configuration.

How to eliminate wrong answers

Option A is wrong because setting minimum healthy percent to 0 and maximum percent to 100 allows all existing tasks to be terminated before new ones are started, causing a period with zero healthy targets and thus downtime. Option B is wrong because increasing the deregistration delay to 300 seconds only affects how long the ALB waits before removing a target that is deregistering; it does not prevent the underlying issue of insufficient healthy targets during the update. Option C is wrong because blue/green deployments with CodeDeploy and a minimum healthy percent of 50 still allow up to half of the targets to be unhealthy during the transition, which can cause downtime if the ALB’s health checks fail; moreover, blue/green deployments typically require a full set of new targets before switching, but the 50% setting contradicts that goal.

635
Multi-Selectmedium

A company is using Amazon S3 to store data for analytics. The data is accessed frequently for the first 30 days, then rarely after that. The company wants to optimize storage costs. Which THREE actions should the SysOps administrator recommend?

Select 3 answers
A.Use S3 Intelligent-Tiering to automatically optimize storage costs.
B.Use S3 One Zone-IA for all data after 30 days to reduce costs.
C.Create a lifecycle policy to transition objects to S3 Glacier Deep Archive after 90 days.
D.Create a lifecycle policy to transition objects to S3 Standard-IA after 30 days.
E.Use S3 Standard storage for all data to ensure high performance.
AnswersA, C, D

S3 Intelligent-Tiering automatically monitors access patterns and moves objects between frequent, infrequent, and archive-instant access tiers, charging a small monthly monitoring and automation fee per object. Unlike a static lifecycle rule, it adapts to changing access without retrieval fees or operational overhead, making it ideal for data with unpredictable usage. However, it does not compress or deduplicate data, and you still pay for the storage class actually used, but it optimizes cost by minimizing manual tier choices.

Why this answer

The correct actions are A, C, D. Option A: S3 Intelligent-Tiering automatically moves data between tiers based on access patterns, optimizing costs for data with changing access patterns. Option C: A lifecycle policy to transition objects to S3 Glacier Deep Archive after 90 days is appropriate for data that is rarely accessed after the initial 30 days.

Option D: A lifecycle policy to transition objects to S3 Standard-IA after 30 days is a good cost-saving measure for data that is accessed infrequently after the first 30 days. Option B is incorrect because S3 One Zone-IA is not durable enough for analytics data that may need availability, and it does not automatically optimize costs like Intelligent-Tiering. Option E is incorrect because using S3 Standard for all data would be more expensive than using the lifecycle policies or Intelligent-Tiering.

636
Matchingmedium

Match each AWS cost management tool to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Visualize and analyze costs

Set custom cost and usage alerts

Detailed billing data

Discount in exchange for commitment

Flexible pricing model

Why these pairings

The correct matches: AWS Cost Explorer visualizes costs, AWS Budgets sets alerts, AWS Cost and Usage Report provides detailed data, and AWS Trusted Advisor offers cost optimization recommendations. Common confusions include swapping the purposes of Cost Explorer and Budgets, or Budgets with the Cost and Usage Report.

637
Multi-Selecthard

A company has a centralized logging solution where CloudTrail logs from multiple accounts are delivered to a single S3 bucket. The security team needs to be alerted when an IAM user is created in any of the accounts. Which steps should be taken? (Choose THREE.)

Select 3 answers
A.Create a CloudWatch Logs metric filter for 'CreateUser' event.
B.Configure CloudTrail to deliver logs to CloudWatch Logs.
C.Create an AWS Config rule to detect IAM user creation.
D.Configure S3 event notification on the central bucket to trigger a Lambda function.
E.Create a CloudWatch alarm on the metric filter that publishes to an SNS topic.
AnswersA, B, E

CloudWatch Logs metric filters scan incoming log events for a specific pattern—here, the 'CreateUser' API call as recorded by CloudTrail—and increment a custom metric for each match. This is the core detection mechanism because it parses the log content in real time as logs are delivered, rather than reacting to file-level events. The metric filter must be defined on the log group where CloudTrail delivers its logs, and it translates the occurrence of the API call into a numeric value that an alarm can evaluate.

Why this answer

A CloudWatch Logs metric filter can parse CloudTrail logs delivered to CloudWatch Logs and match the 'CreateUser' event pattern. This filter creates a metric that can be used to trigger an alarm. Option B is correct because CloudTrail must be configured to deliver logs to CloudWatch Logs in each account so that the metric filter can be applied to the log group.

Option E is correct because a CloudWatch alarm on the metric filter can publish to an SNS topic, which sends notifications (e.g., email, SMS) to the security team when an IAM user is created.

Exam trap

The trap here is that candidates confuse AWS Config rules (which assess resource compliance) with CloudWatch metric filters (which monitor log events), leading them to select Config for event detection instead of the correct CloudWatch-based approach.

638
MCQeasy

A company hosts a static website on Amazon S3. Users access the website from around the world. The SysOps administrator needs to deliver content with low latency and support HTTPS with a custom domain. Which AWS service should be used?

A.AWS Global Accelerator
B.Amazon CloudFront
C.Amazon Route 53 latency-based routing
D.S3 Transfer Acceleration
AnswerB

CloudFront caches static content at global edge locations, cutting latency for worldwide users, and provides HTTPS with a custom domain via ACM certificates. This satisfies both the low-latency and secure custom-domain constraints that S3 static website hosting alone cannot meet.

Why this answer

Amazon CloudFront is a content delivery network (CDN) that caches static content at edge locations worldwide, reducing latency for global users. It natively supports HTTPS with custom domains via SSL/TLS certificates from AWS Certificate Manager (ACM) and integrates with S3 as an origin. This combination of low-latency delivery and HTTPS termination makes CloudFront the correct choice for this scenario.

Exam trap

The trap here is that candidates often confuse AWS Global Accelerator with CloudFront because both improve performance, but Global Accelerator does not cache content or terminate HTTPS for static websites, making it unsuitable for this use case.

How to eliminate wrong answers

Option A is wrong because AWS Global Accelerator improves TCP/UDP traffic performance using the AWS global network but does not cache content or terminate HTTPS for static website delivery; it is designed for dynamic applications, not static content caching. Option C is wrong because Amazon Route 53 latency-based routing only directs DNS queries to the region with the lowest latency, but it does not cache content or provide HTTPS termination; the origin S3 bucket would still serve content directly without edge caching. Option D is wrong because S3 Transfer Acceleration speeds up uploads to S3 using edge locations, but it does not cache content for downloads, does not support custom domain HTTPS, and is intended for large object uploads, not global static website delivery.

639
MCQmedium

A company is using AWS Elastic Beanstalk to deploy a web application. The application experiences high traffic during peak hours. The SysOps administrator wants to automatically scale the environment based on CPU utilization. Which configuration change is required?

A.Manually add EC2 instances to the Auto Scaling group.
B.Configure a scaling trigger based on a CloudWatch alarm for CPU utilization.
C.Modify the instance type to a larger size.
D.Increase the number of load balancers.
AnswerB

This is the correct approach because Elastic Beanstalk's Auto Scaling group uses CloudWatch alarms to drive scaling actions based on the average CPU utilization of the EC2 instances in the environment. You can define a scaling trigger—either a simple/step scaling policy tied to a CloudWatch alarm or a target tracking policy that continuously adjusts capacity to keep CPU near a target value. When the alarm enters an ALARM state (e.g., CPU exceeds 70% for 5 minutes), the policy proactively launches additional instances, and when it returns to OK, it terminates excess instances, providing dynamic, workload-aware scaling.

Why this answer

AWS Elastic Beanstalk integrates with Amazon CloudWatch and Auto Scaling to allow you to define a scaling trigger based on a CloudWatch alarm for CPU utilization. When the alarm threshold is breached, the Auto Scaling group automatically adds or removes EC2 instances, enabling the environment to handle high traffic during peak hours without manual intervention.

Exam trap

The trap here is that candidates often confuse vertical scaling (changing instance size) with horizontal scaling (adding/removing instances), or they assume manual actions like adding instances or load balancers are valid automation strategies for Elastic Beanstalk environments.

How to eliminate wrong answers

Option A is wrong because manually adding EC2 instances to the Auto Scaling group defeats the purpose of automatic scaling and does not respond dynamically to CPU utilization changes. Option C is wrong because modifying the instance type to a larger size (vertical scaling) does not automatically scale the number of instances; it only increases the capacity of each instance, which is not a dynamic scaling solution for fluctuating traffic. Option D is wrong because increasing the number of load balancers does not directly scale compute capacity; it distributes traffic but does not add or remove EC2 instances based on CPU utilization.

640
MCQmedium

Refer to the exhibit. The output shows the health status of two targets in a target group. One target is unhealthy with a 502 error. What is the most likely cause?

A.The target instance’s security group is blocking the health check traffic.
B.The target instance is not allowing outbound traffic to the ALB.
C.The web server on the target instance is returning HTTP 502 status codes.
D.The ALB health check is misconfigured with an incorrect path.
AnswerC

An HTTP 502 Bad Gateway response is produced by a web server acting as a reverse proxy or gateway when it receives an invalid response from an upstream server, such as an application server or backend service that the target depends on. In the context of an ALB health check, the load balancer considers any non-2xx HTTP response (including 502) as a health check failure, and the target is marked unhealthy. The fact that the ALB received a 502 proves that the target was reachable and successfully responded at the HTTP layer, so the issue is not network-level but application-layer, specifically that the target's own upstream dependencies are failing.

Why this answer

A 502 Bad Gateway error from the target indicates that the web server on the instance is returning an invalid response, often due to an application error or misconfiguration. Option A is incorrect because a security group blocking health check traffic would result in a connection timeout or refusal, not a 502. Option B is incorrect because the health check is initiated by the ALB to the target instance, so outbound traffic from the instance is not relevant.

Option D is incorrect because a misconfigured health check path would typically result in a 404 or other error, but not necessarily a 502. The 502 error is directly caused by the target's web server returning an HTTP 502 status code.

641
MCQmedium

A company uses AWS Elastic Beanstalk for a Java application. The environment uses a custom platform. The SysOps administrator wants to update the environment's configuration to use a larger instance type to handle increased load. What is the correct way to perform this change with minimal downtime?

A.Use the Elastic Beanstalk console to update the instance type and choose a rolling update strategy.
B.SSH into each instance and modify the instance type manually.
C.Terminate all instances and launch new ones with the larger instance type.
D.Create a new environment with the larger instance type and swap the environment URLs.
AnswerA

The Elastic Beanstalk console provides a supported, declarative way to change the environment's instance type. When updated, Elastic Beanstalk modifies the Auto Scaling launch configuration and then applies a rolling update strategy, progressively replacing instances so that at least the minimum capacity stays available. This preserves all environment-level settings and can be done with minimal or zero downtime, making it the correct approach.

Why this answer

Elastic Beanstalk allows you to update the environment's configuration, such as instance type, via the console or CLI. To minimize downtime, you can choose a rolling update strategy, which updates instances in batches, ensuring that the environment remains available throughout the process. Option B is incorrect because manually SSHing into instances is not a scalable or persistent solution; Elastic Beanstalk manages the instances and changes may not survive environment updates.

Option C is incorrect because terminating all instances causes complete downtime until the new instances are launched. Option D is incorrect because while creating a new environment and swapping URLs (blue/green deployment) can achieve zero downtime, it is more complex and resource-intensive than necessary for a simple instance type change, and the question asks for minimal downtime with correct method.

642
Multi-Selectmedium

A company is designing a backup strategy for its on-premises file servers to AWS. Which TWO services can be used to back up data to AWS? (Choose TWO.)

Select 2 answers
A.AWS Backup
B.AWS Snowball
C.AWS Storage Gateway (File Gateway)
D.Amazon EFS
E.S3 Transfer Acceleration
AnswersA, C

AWS Backup is the correct answer because it natively supports backing up on-premises workloads via the AWS Backup Gateway, which connects your on-premises virtual machines to AWS Backup. This service allows you to define backup policies, retention rules, and lifecycle management in a single place, covering both cloud and on-premises resources. Unlike simple data replication or file syncing tools, AWS Backup provides a centralized, scheduled, and auditable backup solution that ensures recoverability of on-premises VMs.

Why this answer

AWS Backup is correct because it provides a fully managed, policy-based backup service that can centrally automate and manage backups for on-premises file servers via the AWS Backup Gateway (formerly Storage Gateway Virtual Tape Library). It integrates with AWS Storage Gateway to back up on-premises data to S3 and Glacier, supporting file-level recovery without needing custom scripts.

Exam trap

The trap here is that candidates confuse data transport services (Snowball) or storage targets (EFS) with backup services, or mistake a performance feature (S3 Transfer Acceleration) for a backup solution, when the question specifically asks for services that can be used to back up data to AWS.

643
MCQmedium

A company is using Amazon Route 53 as its DNS service. The company has a web application running on an Auto Scaling group of EC2 instances behind an Application Load Balancer (ALB). The company wants to ensure that if the ALB fails, traffic is automatically redirected to a static error page hosted on an Amazon S3 bucket. Which Route 53 routing policy should be used to achieve this?

A.Geolocation routing policy
B.Failover routing policy
C.Latency routing policy
D.Weighted routing policy
AnswerB

Failover routing policy in Amazon Route 53 implements active-passive failover by associating a primary record with a health check that continuously monitors the resource. When the primary endpoint fails its health check, Route 53 automatically responds to DNS queries with the secondary record, such as an S3 bucket configured for static website hosting. You can pair a primary resource like an EC2 instance or load balancer with a secondary static S3 bucket, ensuring traffic shifts to the passive site during an outage. This is the direct mechanism for the requirement described.

Why this answer

The Failover routing policy in Amazon Route 53 is designed to route traffic to a primary resource (the ALB) and automatically redirect to a secondary resource (the S3 bucket static error page) when the primary health check fails. This ensures high availability by failing over to the static error page if the ALB becomes unhealthy, meeting the requirement precisely.

Exam trap

The trap here is that candidates often confuse Weighted routing policy with failover behavior, assuming weights can handle health-based redirection, but Weighted routing policy does not automatically remove unhealthy targets from DNS responses without additional health check integration.

How to eliminate wrong answers

Option A is wrong because Geolocation routing policy routes traffic based on the geographic location of the user, not on health or failover conditions, so it cannot redirect traffic to a static error page upon ALB failure. Option C is wrong because Latency routing policy routes traffic to the region with the lowest latency for the user, ignoring health checks and failover logic, thus it cannot automatically switch to a backup resource. Option D is wrong because Weighted routing policy distributes traffic across multiple resources based on assigned weights, but it does not support automatic failover based on health checks; it would continue sending traffic to the ALB even if it fails.

644
MCQeasy

A SysOps administrator is configuring an Amazon RDS for MySQL Multi-AZ deployment. What is the primary benefit of using Multi-AZ?

A.Improved read performance by distributing queries across multiple instances.
B.Automatic failover to a standby instance in a different Availability Zone.
C.Synchronous replication across AWS Regions.
D.Automatic creation of read replicas for disaster recovery.
AnswerB

This is the core benefit of a Multi-AZ Amazon RDS deployment: the primary DB instance synchronously replicates data to a standby instance in a different Availability Zone within the same Region. If the primary fails, RDS automatically detects the issue and promotes the standby to primary, updating the DNS endpoint so applications can reconnect with minimal downtime. This provides high availability without requiring manual intervention.

Why this answer

In Amazon RDS for MySQL Multi-AZ deployments, the primary benefit is automatic failover to a standby instance in a different Availability Zone. This is achieved through synchronous replication to a standby in a separate AZ, ensuring that if the primary instance fails, RDS automatically promotes the standby to become the new primary, minimizing downtime and maintaining data durability.

Exam trap

The trap here is that candidates confuse Multi-AZ with read replicas, assuming Multi-AZ provides read scaling, when in fact it is solely for high availability and automatic failover.

How to eliminate wrong answers

Option A is wrong because Multi-AZ does not improve read performance; read traffic is always directed to the primary instance, and the standby is not used for serving reads. Option C is wrong because Multi-AZ replication is within a single AWS Region, not across Regions; cross-Region replication is handled by Aurora Global Database or manual read replicas. Option D is wrong because Multi-AZ does not automatically create read replicas; read replicas are a separate feature for offloading read traffic and are not part of the Multi-AZ failover mechanism.

645
Matchingmedium

Match each AWS compute service to its use case.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Virtual machines in the cloud

Serverless function execution

Container orchestration with Docker

Managed Kubernetes clusters

Serverless compute for containers

Why these pairings

Amazon EC2 gives full server control; AWS Lambda runs serverless code; Amazon ECS manages containers. Distractors swap definitions with Lambda or Elastic Beanstalk.

646
MCQmedium

A company has an S3 bucket that stores critical data. The bucket has versioning enabled. A SysOps administrator accidentally deletes a version of an object. What is the quickest way to recover the deleted version?

A.Use the S3 bucket's 'Undelete' feature.
B.Enable MFA Delete and then restore the object.
C.Contact AWS Support to restore the object.
D.Copy the deleted version from the bucket's version history.
AnswerD

With S3 Versioning enabled, deleting an object does not erase the data; it simply creates a delete marker that becomes the current version while the original object remains as a noncurrent version. To restore it, copy the most recent noncurrent (deleted) version back into the bucket, which removes the delete marker and makes that version current again. This self-service method is the standard and reliable way to recover a deleted object.

Why this answer

S3 object versioning maintains a version history for each object, including deleted versions. When a version is deleted, it is not permanently removed; instead, a delete marker is created, and the deleted version remains in the version history. The quickest way to recover it is to copy the deleted version ID from the bucket's version history (e.g., using the AWS CLI `aws s3api copy-object` with the `--version-id` parameter) to restore the object without contacting support or enabling additional features.

Exam trap

The trap here is that candidates may think S3 has an 'Undelete' feature (Option A) or that MFA Delete (Option B) can reverse deletions, but S3's versioning model requires manual recovery via version history, not a built-in undo function.

How to eliminate wrong answers

Option A is wrong because S3 does not have an 'Undelete' feature; deleted versions are recovered by removing the delete marker or copying from version history. Option B is wrong because MFA Delete is a security feature that requires multi-factor authentication for permanent deletions, but it does not provide a recovery mechanism for already-deleted versions; enabling it after deletion does not restore the object. Option C is wrong because AWS Support cannot restore deleted S3 object versions; recovery is entirely self-service through the S3 versioning feature.

647
MCQmedium

A company has an on-premises data center connected to AWS via an AWS Direct Connect connection. The SysOps administrator needs to ensure high availability for the connectivity. Which configuration provides the highest availability for the Direct Connect connection?

A.Establish a single Direct Connect connection with a VPN backup.
B.Establish two Direct Connect connections to the same AWS Direct Connect location.
C.Establish two Direct Connect connections to different AWS Direct Connect locations.
D.Use multiple virtual interfaces on a single Direct Connect connection.
AnswerC

By connecting to two separate Direct Connect locations, you eliminate the facility as a single point of failure. If one location goes down, BGP routing automatically directs traffic over the surviving connection, assuming appropriate routing policies. This configuration meets AWS's recommendation for redundant connections with diverse paths, achieving high availability for hybrid networking.

Why this answer

Establishing two Direct Connect connections to different AWS Direct Connect locations provides geographic redundancy. If one AWS Direct Connect location experiences an outage, the other connection remains operational, ensuring high availability. This configuration eliminates single points of failure at the facility level, which is the most resilient design for hybrid connectivity.

Exam trap

The trap here is that candidates assume multiple connections to the same location provide redundancy, but AWS Direct Connect locations are single points of failure; true high availability requires geographic diversity across different locations.

How to eliminate wrong answers

Option A is wrong because a single Direct Connect connection with a VPN backup does not provide true high availability; the VPN backup relies on the public internet, which introduces variable latency, lower bandwidth, and potential security concerns, and the failover is not seamless. Option B is wrong because two Direct Connect connections to the same AWS Direct Connect location share the same physical facility and power infrastructure, meaning a location-level outage (e.g., fiber cut or power failure) will take down both connections simultaneously. Option D is wrong because multiple virtual interfaces on a single Direct Connect connection still depend on a single physical connection; if that connection fails, all virtual interfaces are lost, providing no redundancy.

648
MCQmedium

A SysOps administrator needs to create a custom Amazon CloudWatch metric to track the number of active user sessions from application logs. The administrator wants to publish this metric to CloudWatch and set an alarm when the count exceeds a threshold. Which solution should be used?

A.Use a CloudWatch Logs Metric Filter on the log group.
B.Use CloudWatch Contributor Insights to extract the metric from logs.
C.Use CloudWatch Synthetics Canary to simulate user sessions and publish metrics.
D.Use CloudWatch Embedded Metric Format to have the application publish metrics directly.
AnswerA

A metric filter scans log entries for a pattern and increments a metric each time the pattern appears. The resulting metric can be used to trigger an alarm. This is the correct and straightforward approach.

Why this answer

CloudWatch Logs Metric Filters allow you to define a filter pattern that matches specific log events (e.g., 'User session started') and convert them into a custom metric. The metric is automatically published to CloudWatch, where you can set an alarm on the count of matching log entries. This is the standard, cost-effective approach for extracting metrics from application logs without modifying the application code.

Exam trap

Candidates often confuse CloudWatch Contributor Insights (which analyzes log data for top contributors) with a simple metric filter, or assume Embedded Metric Format is required. A CloudWatch Logs Metric Filter is the standard, cost-effective way to create a custom metric from log events without requiring application changes.

How to eliminate wrong answers

Option B is wrong because CloudWatch Contributor Insights is designed to analyze high-cardinality log data to identify top contributors (e.g., top IP addresses), not to produce a simple count metric for alarm thresholds. Option C is wrong because CloudWatch Synthetics Canaries simulate user interactions to generate traffic and metrics, but they do not parse existing application logs to count active sessions; they create synthetic data, not real session counts. Option D is wrong because CloudWatch Embedded Metric Format requires the application to be modified to emit metrics in a specific JSON format, whereas the requirement is to extract metrics from existing logs without code changes.

649
MCQeasy

A SysOps administrator is provisioning an Auto Scaling group (ASG) for a stateless web application. The ASG should launch EC2 instances in multiple Availability Zones. The administrator needs to ensure that instances are evenly distributed across Availability Zones. Which configuration should the administrator use?

A.Use an 'availability-zone' health check type in the Auto Scaling group.
B.Create subnets in multiple Availability Zones and specify them in the Auto Scaling group.
C.Create the Auto Scaling group with a single subnet in one Availability Zone.
D.Create subnets in multiple Availability Zones but assign them to the same placement group.
AnswerB

By creating subnets in multiple Availability Zones and then referencing those all subnets in the Auto Scaling group's network configuration, you enable the group to automatically distribute instances across all the specified AZs. This is the canonical method for achieving high availability, as the Auto Scaling group will balance instances among the AZs and, if one AZ becomes unhealthy or has insufficient capacity, it can launch replacement instances in the other AZs. Without this multi-subnet specification, the group cannot spread itself across AZs, because it can only launch instances into the subnets explicitly provided.

Why this answer

By creating subnets in multiple Availability Zones and specifying them in the Auto Scaling group configuration, the ASG will automatically distribute instances evenly across the subnets, ensuring high availability. Option A is incorrect because the 'availability-zone' health check type determines how to check instance health, not the distribution of instances. Option C is incorrect because using a single subnet limits instances to one Availability Zone, failing the requirement for multi-AZ distribution.

Option D is incorrect because placement groups are used for low-latency network performance, not for even distribution across AZs.

650
MCQeasy

Refer to the exhibit. A SysOps administrator runs the command to list running EC2 instances. What is the purpose of the '--query' parameter?

A.It filters the results on the server side.
B.It limits the API call to only running instances.
C.It filters the output to show only specified fields.
D.It saves the output to a file.
AnswerC

The --query parameter in this command takes a JMESPath expression that processes the JSON response and extracts only the fields the user wants to display, such as instance IDs and their state. It filters the output client-side after the API returns the data, thereby customizing the visible result without changing the underlying API request. This is the correct interpretation of what the command accomplishes.

Why this answer

The AWS CLI '--query' parameter uses JMESPath to filter and shape the JSON response returned by the API call, so it controls which fields appear in the output. It does not change what the API returns from the server; it only transforms the client-side presentation. This is why it is described as filtering the output to show only specified fields.

Exam trap

SOA-C02 often tests the distinction between server-side filtering ('--filters') and client-side output shaping ('--query') — candidates frequently assume '--query' reduces the API payload, when it only reshapes what the CLI prints.

How to eliminate wrong answers

Option A is wrong because '--query' is a client-side JMESPath expression evaluated by the CLI after the response is received; server-side filtering is done with parameters like '--filters' or '--instance-ids'. Option B is wrong because limiting results to running instances requires a server-side filter such as '--filters Name=instance-state-name,Values=running', not '--query'. Option D is wrong because saving output to a file is done with shell redirection or '--output' combined with redirection, not '--query'.

651
MCQeasy

A company runs 200 EC2 Linux instances across three accounts. The security team requires that critical OS patches are applied automatically every Sunday at 2 AM UTC. Currently patches are applied manually and inconsistently. What is the recommended AWS-native solution?

A.Configure a Patch Manager patch baseline and maintenance window scheduled for Sunday 02:00 UTC; associate the Run Patch Baseline task with all EC2 instance targets
B.Create a cron job on each instance that runs 'yum update -y' every Sunday at 2 AM
C.Use AWS Config managed rules to detect unpatched instances and send SNS notifications for manual remediation
D.Build a CodePipeline that runs weekly, creates new AMIs with the latest patches, and replaces all instances via an Auto Scaling instance refresh
AnswerA

The patch baseline filters patch approvals by severity (e.g., CRITICAL, IMPORTANT). The maintenance window triggers the AWS-RunPatchBaseline SSM document on schedule. All 200 instances receive the same baseline and schedule, replacing manual inconsistency with automated consistency. Patch compliance is recorded in the Patch Manager compliance dashboard.

Why this answer

AWS Systems Manager Patch Manager, combined with a Maintenance Window, provides a fully AWS-native, automated solution for patching EC2 instances on a schedule. The Patch Manager service uses a patch baseline to define which patches are approved (e.g., critical OS patches), and the Maintenance Window triggers the 'AWS-RunPatchBaseline' SSM document at the specified time (Sunday 02:00 UTC) against all targeted instances. This eliminates manual effort and ensures consistent, auditable patching across multiple accounts and instances.

Exam trap

The trap here is that candidates may choose Option D (AMI refresh) because it seems more 'complete' for patching, but they overlook that Patch Manager with Maintenance Windows is the simplest, most direct AWS-native solution for scheduled patching, and the question explicitly asks for the 'recommended' solution, not the most elaborate one.

How to eliminate wrong answers

Option B is wrong because it requires manual creation and maintenance of cron jobs on each instance, which is not a centralized, AWS-native solution and does not scale across 200 instances and three accounts; it also lacks auditing and compliance tracking. Option C is wrong because AWS Config rules can only detect unpatched instances and send notifications, but they do not automatically apply patches, leaving remediation to manual action, which fails the requirement for automatic application. Option D is wrong because while CodePipeline and AMI refresh can achieve patching, it is an overly complex, non-native approach that requires building and maintaining a pipeline, creating new AMIs, and performing instance refreshes, which is not the recommended AWS-native solution for simple scheduled patching.

652
MCQeasy

A company runs a stateless web application on EC2 instances in an Auto Scaling group. The instances are behind an Application Load Balancer. The Auto Scaling group uses a dynamic scaling policy based on average CPU utilization. During a traffic spike, new instances are launched but take 5 minutes to become healthy. Users experience errors during this time. Which solution would reduce the time to serve traffic from new instances?

A.Use a launch template with a pre-provisioned AMI.
B.Add a lifecycle hook to delay instance termination.
C.Increase the cooldown period for the scaling policy.
D.Use a larger instance type.
AnswerA

A pre-provisioned (pre-warmed) AMI has the application binary, runtime, and all dependencies already installed and initialized during image creation. When the Auto Scaling group launches a new instance from a launch template using this AMI, the app is immediately ready to serve traffic, avoiding the need for first-boot user-data scripts to install and configure software. This directly reduces the instance's "time to healthy" and is the correct way to speed up scaling in a stateless web tier.

Why this answer

A pre-provisioned AMI eliminates the need for software installation and configuration at launch time, reducing the time for new EC2 instances to become healthy. By baking the application and dependencies into the AMI, instances can start serving traffic almost immediately after booting, rather than waiting for user data scripts or configuration management tools to complete.

Exam trap

The trap here is that candidates may think increasing the cooldown period (Option C) helps stabilize scaling, but it actually delays the launch of new instances, making the problem worse during traffic spikes.

How to eliminate wrong answers

Option B is wrong because a lifecycle hook to delay instance termination would only affect instances being terminated, not newly launched instances, and would actually increase the time before instances become healthy. Option C is wrong because increasing the cooldown period would prevent the Auto Scaling group from launching new instances quickly during a traffic spike, worsening the problem. Option D is wrong because using a larger instance type does not reduce the time to serve traffic from new instances; it only provides more resources per instance, but the boot and configuration time remains the same.

653
MCQhard

A company runs a critical application on a single Amazon EC2 instance with an attached Amazon EBS volume. The SysOps administrator needs to implement a disaster recovery solution that meets a Recovery Point Objective (RPO) of 15 minutes and a Recovery Time Objective (RTO) of 30 minutes. The application runs continuously and data changes frequently. Which solution should the administrator implement?

A.Use Amazon Data Lifecycle Manager (DLM) to take EBS snapshots every 15 minutes and automate the creation of a new AMI.
B.Use AWS Backup to schedule backups every 15 minutes and restore from the latest backup when needed.
C.Use AWS Elastic Disaster Recovery (AWS DRS) to continuously replicate the instance to a staging area in another region.
D.Use an Auto Scaling group with a custom AMI that is updated every 15 minutes by a Lambda function.
AnswerC

AWS Elastic Disaster Recovery (AWS DRS) continuously replicates block-level changes from the source EC2 instance to a staging area in a second region using a lightweight agent, with typical RPO in the seconds and RTO in the single-digit minutes. DRS maintains a converted, continuously updated copy of the source volumes on low-cost staging instances, so at failover time it simply powers on the target instance using the latest replicated state rather than constructing it from snapshots. This always-ready, continuous replication approach is precisely what is required to meet a 30-minute recovery window while ensuring data loss is limited to a few seconds.

Why this answer

AWS Elastic Disaster Recovery (AWS DRS) continuously replicates the entire EC2 instance, including the EBS volume, to a staging area in another AWS Region with sub-second data changes. This meets the RPO of 15 minutes and RTO of 30 minutes because you can launch a fully recovered instance in the target region within minutes from the latest consistent point, without relying on periodic snapshots or backups that would miss frequent data changes.

Exam trap

The trap here is that candidates often choose periodic snapshot or backup solutions (like DLM or AWS Backup) because they think 15-minute intervals satisfy the RPO, but they overlook the RTO constraint and the fact that frequent data changes require continuous replication, not periodic snapshots, to avoid data loss between intervals.

How to eliminate wrong answers

Option A is wrong because Amazon Data Lifecycle Manager (DLM) can take EBS snapshots every 15 minutes, but creating a new AMI from those snapshots is not automated by DLM and the process would take longer than 30 minutes to build and register an AMI, failing the RTO. Option B is wrong because AWS Backup scheduled backups every 15 minutes still rely on periodic snapshots, which cannot capture every data change between intervals, and restoring from the latest backup can take longer than 30 minutes due to volume creation and attachment time. Option D is wrong because an Auto Scaling group with a custom AMI updated every 15 minutes by a Lambda function does not provide continuous replication; the AMI creation process itself takes time and the instance launched from an older AMI would miss data changes made in the interim, failing the RPO.

654
MCQhard

An organization uses AWS CloudFormation to manage infrastructure. They have a stack that includes an Amazon RDS DB instance. The administrator wants to update the DB instance's allocated storage without downtime. The DB instance is currently using gp2 storage. Which action should the administrator take?

A.Create a read replica with the new storage size and promote it.
B.Modify the storage size in the CloudFormation template and update the stack.
C.Stop the DB instance, modify the storage, and start it.
D.Take a manual snapshot and restore it with the new storage size.
AnswerB

Updating the CloudFormation stack with a larger AllocatedStorage value invokes RDS's online storage scaling, so the disk can be expanded while the instance remains available. CloudFormation translates the template change into a ModifyDBInstance operation; with ApplyImmediately not set to true, the change is applied during the next scheduled maintenance window, avoiding an unplanned outage. This keeps the existing endpoint and replication topology intact and is the least disruptive, infrastructure-as-code-friendly approach.

Why this answer

Modifying the allocated storage size in the CloudFormation template and updating the stack triggers a storage modification on the RDS DB instance. For gp2 storage, increasing allocated storage does not require downtime; RDS performs the modification while the instance remains available. This approach aligns with the requirement to avoid downtime and leverages CloudFormation's infrastructure-as-code capabilities.

Exam trap

The trap here is that candidates assume any storage modification requires downtime or a manual snapshot/restore, but AWS RDS allows online storage scaling for gp2 volumes, making a direct CloudFormation update the correct zero-downtime approach.

How to eliminate wrong answers

Option A is wrong because creating a read replica with a new storage size and promoting it introduces a replica promotion process that can cause a brief outage during the promotion, and it does not directly modify the existing DB instance's storage without downtime. Option C is wrong because stopping the DB instance causes downtime, which contradicts the requirement for no downtime; RDS storage modifications for gp2 can be performed online without stopping the instance. Option D is wrong because taking a manual snapshot and restoring it with a new storage size results in downtime during the restore process, as the original instance remains unavailable until the restore completes.

655
MCQmedium

A company uses AWS Organizations to manage multiple accounts. The security team wants to restrict all accounts from using specific AWS services unless explicitly allowed. Which feature should be used?

A.Service control policies (SCPs)
B.Resource-based policies
C.IAM permissions boundaries
D.AWS Config rules
AnswerA

SCPs are the correct answer because they let you centrally govern the maximum permitted actions for every principal (including the root user) across all accounts in your AWS Organizations. By attaching an SCP to an organizational unit or account, you can explicitly deny or allow services (e.g., disabling Amazon S3 or EC2) regardless of the IAM policies attached to individual users or roles. This makes SCPs the only option here that can restrict service usage at the account or organization-wide level.

Why this answer

Service control policies (SCPs) in AWS Organizations define the maximum permissions for member accounts, allowing the security team to restrict which AWS services and actions are available across all accounts unless explicitly allowed. SCPs are applied at the organization, OU, or account level and act as a permissions guardrail that even account administrators cannot override.

Exam trap

The trap is confusing SCPs with IAM permissions boundaries or AWS Config — SCPs are the only mechanism that centrally restricts service usage across all accounts in an AWS Organization, while the others operate within a single account or only detect violations.

How to eliminate wrong answers

Option B is wrong because resource-based policies are attached to individual resources (e.g., S3 buckets, KMS keys) and grant cross-account access — they do not centrally restrict service usage across an organization. Option C is wrong because IAM permissions boundaries apply to individual IAM users or roles within a single account and do not provide organization-wide service restrictions. Option D is wrong because AWS Config rules evaluate resource compliance and trigger remediation; they detect and report violations but do not prevent service usage in real time.

656
MCQhard

A company has an EC2 instance that needs to access an S3 bucket. The instance is launched in a private subnet with no internet gateway. What is the most secure way to provide access to S3 without traversing the internet?

A.Use a NAT gateway in a public subnet
B.Create an S3 VPC gateway endpoint
C.Set up an AWS Direct Connect connection
D.Attach an internet gateway to the VPC and a public IP to the instance
AnswerB

An S3 VPC gateway endpoint is a component you add to the VPC's route table that directs S3-bound traffic to the AWS network via a prefix list, completely bypassing the internet. Because it works via the AWS internal backbone, instances in private subnets can reach S3 without a NAT gateway, internet gateway, public IP, or VPN, and there is no charge for the gateway endpoint itself. The route is confined to the customer VPC and AWS's shared network, making it a private and secure method for S3 access.

Why this answer

An S3 VPC gateway endpoint allows EC2 instances in a private subnet to access S3 privately using AWS’s internal network, without requiring an internet gateway, NAT gateway, or public IP. Traffic stays within the AWS backbone, never traversing the internet, which provides the most secure and cost-effective solution for this scenario.

Exam trap

The trap here is that candidates often confuse VPC gateway endpoints with interface endpoints or assume a NAT gateway is required for private subnet outbound traffic, forgetting that S3 can be accessed directly via a gateway endpoint without internet routing.

How to eliminate wrong answers

Option A is wrong because a NAT gateway in a public subnet would route traffic to the internet, which violates the requirement of not traversing the internet and introduces additional cost and complexity. Option C is wrong because AWS Direct Connect is a dedicated network connection from on-premises to AWS, not designed for VPC-to-S3 access within the same region, and it would be overkill and more expensive. Option D is wrong because attaching an internet gateway and a public IP would expose the instance to the internet, breaking the private subnet requirement and reducing security.

657
MCQmedium

Refer to the exhibit. A SysOps administrator creates this stack. Which of the following is true about the bucket?

A.The bucket has versioning enabled
B.The bucket is publicly accessible
C.The bucket does not have versioning enabled
D.The bucket allows public read access
AnswerA

The exhibit displays the S3 bucket's versioning configuration with the Status field set to 'Enabled'. This confirms that the bucket has versioning enabled, which means every object upload creates a new version rather than overwriting the existing object, preserving history and enabling recovery from accidental deletions or overwrites. Therefore, the statement is correct based on the provided configuration.

Why this answer

The exhibit shows a CloudFormation template where the S3 bucket resource includes the VersioningConfiguration property with Status set to Enabled. When this stack is deployed, AWS applies that configuration to the bucket, so versioning is active. This means every object overwrite or delete creates a new version rather than destroying the prior object.

Exam trap

SOA-C02 often tests whether candidates can read a CloudFormation snippet and infer the resulting resource state — the trap is assuming a bucket is public or unversioned by default without checking the explicit properties in the template.

How to eliminate wrong answers

Option B is wrong because nothing in the template sets a public bucket policy or ACL — versioning has no bearing on public accessibility. Option C is wrong because the template explicitly sets VersioningConfiguration Status to Enabled, which is the opposite of disabled. Option D is wrong because public read access requires a bucket policy or ACL granting s3:GetObject to a principal like *, which the template does not define.

658
MCQmedium

A SysOps administrator needs to deploy a new version of an application to an Auto Scaling group using a blue/green deployment strategy. The application runs on EC2 instances behind an Application Load Balancer. Which AWS service should be used to automate this deployment?

A.AWS Elastic Beanstalk
B.AWS CodeDeploy
C.AWS CodePipeline
D.AWS CloudFormation
AnswerB

AWS CodeDeploy is the dedicated application deployment service that performs in-place or blue/green deployments with configurable traffic routing (canary, linear, or all-at-once). When deploying to an EC2 Auto Scaling group, CodeDeploy creates a new auto-scaling group for the green fleet, installs the revision, and then shifts traffic via the attached load balancer. This gives the administrator fine-grained control over the rollout and rollback behavior.

Why this answer

AWS CodeDeploy is the service designed to automate application deployments, including blue/green deployments to EC2 Auto Scaling groups behind an Application Load Balancer. It supports the blue/green deployment type natively for EC2/on-premises compute, allowing traffic to shift from the original (blue) environment to a replacement (green) environment with configurable traffic rerouting and rollback. This directly matches the SysOps requirement.

Exam trap

SOA-C02 often tests the boundary between orchestration services (CodePipeline) and the actual deployment engine (CodeDeploy), causing candidates to pick CodePipeline because it 'automates deployments' when the question asks which service performs the blue/green mechanics.

How to eliminate wrong answers

Option A is wrong because Elastic Beanstalk is a PaaS that manages deployment for supported platforms, but it does not provide the granular blue/green orchestration with ALB traffic shifting that CodeDeploy offers for arbitrary EC2 Auto Scaling groups. Option C is wrong because CodePipeline is a CI/CD orchestration service that coordinates build and deploy stages — it invokes CodeDeploy or other deploy providers but does not itself perform the blue/green deployment mechanics. Option D is wrong because CloudFormation is an infrastructure-as-code provisioning service; while it can create resources, it is not the deployment automation engine for blue/green traffic shifting.

659
MCQmedium

A SysOps administrator is troubleshooting slow application performance. The application runs on Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer. Amazon CloudWatch metrics show that the average CPU utilization across the instances is below 20%, but the application is still slow. What is the MOST likely cause of the performance issue?

A.The Auto Scaling group is scaling too aggressively, causing thrashing.
B.The Application Load Balancer has a sticky session configuration that is not distributing traffic evenly.
C.The application database is under-provisioned and is causing slow query responses.
D.The EC2 instances are using burstable performance and have exhausted their CPU credits.
AnswerC

An under-provisioned database can directly cause slow application responses while keeping EC2 CPU low because the application nodes spend most of their time blocked on database queries. Inadequate IOPS, insufficient memory for the buffer cache, or a suboptimal schema can lead to high query latency and connection queueing, which is not reflected in the web-tier CloudWatch CPU metric. The low average CPU is a classic sign of an external dependency bottleneck, making the database the most plausible root cause for the degraded user experience.

Why this answer

The most likely cause is that the application database is under-provisioned, leading to slow query responses. Even though EC2 CPU utilization is low, the application performance is bottlenecked by database latency. This is a common scenario where the database tier is the constraint, not the compute tier.

Exam trap

Candidates may assume low CPU means the compute layer is fine, but the real bottleneck could be the database tier. Don't automatically rule out downstream components.

660
MCQmedium

A SysOps administrator notices that an EC2 instance's status check fails intermittently. The instance is part of an Auto Scaling group. What is the most efficient way to automatically recover the instance?

A.Increase the Auto Scaling group's cooldown period.
B.Create a CloudWatch alarm on StatusCheckFailed and configure an EC2 recovery action.
C.Terminate the instance and wait for Auto Scaling to launch a new one.
D.Place the instance in a different Availability Zone.
AnswerB

Create a CloudWatch alarm on the StatusCheckFailed metric and attach an EC2 recovery action. When the alarm enters the ALARM state, EC2 automatically stops and starts the instance to migrate it to a fresh physical host, preserving the instance ID, private IP, Elastic IP, and placement group membership. This is a proactive, automated recovery path specifically designed for failing system status checks.

Why this answer

Creating a CloudWatch alarm on the StatusCheckFailed metric and configuring an EC2 recovery action (using the 'recover' alarm action) automatically restarts the instance on a new underlying host if a system status check fails. This is the most efficient recovery method for an instance in an Auto Scaling group, as it preserves the instance ID, private IP, and Elastic IP, while Auto Scaling handles only instance replacement if the instance is terminated.

Exam trap

The trap here is that candidates confuse instance recovery with Auto Scaling replacement, thinking termination and relaunch is the default or only option, but EC2 recovery is a separate, more efficient mechanism that preserves instance identity and is directly configurable via CloudWatch alarms.

How to eliminate wrong answers

Option A is wrong because increasing the Auto Scaling group's cooldown period delays the launch of new instances after scaling activities, but does not recover a failing instance or address the status check failure. Option C is wrong because terminating the instance and waiting for Auto Scaling to launch a new one is less efficient—it loses the instance's metadata, private IP, and Elastic IP, and incurs longer downtime compared to an automatic recovery. Option D is wrong because placing the instance in a different Availability Zone does not automatically recover the instance; it requires manual intervention or a new launch, and does not leverage the built-in EC2 recovery mechanism.

661
MCQeasy

A SysOps administrator needs to ensure that all S3 buckets in the account are configured with server access logging. Which AWS service can evaluate the buckets and automatically remediate non-compliant buckets?

A.Amazon GuardDuty
B.AWS CloudTrail
C.AWS Config
D.AWS Trusted Advisor
AnswerC

AWS Config continuously records the configuration of S3 buckets and evaluates that configuration against managed or custom rules, such as checking whether bucket encryption is enabled or public access is blocked. When a rule finds a noncompliant bucket, you can attach an AWS Systems Manager Automation document to automatically apply the required remediation, such as enabling default encryption or adding a bucket policy. This combination of state tracking, rule evaluation, and automated action makes AWS Config the correct tool for ensuring all buckets meet your standards.

Why this answer

AWS Config is the correct service because it can continuously evaluate your S3 buckets against a managed rule (s3-bucket-server-access-logging-enabled) and automatically remediate non-compliant buckets using AWS Systems Manager Automation documents. This allows the SysOps administrator to enforce server access logging as a compliance requirement without manual intervention.

Exam trap

The trap here is that candidates often confuse AWS Config's evaluation and remediation capabilities with CloudTrail's logging of API calls, mistakenly thinking CloudTrail can enforce S3 bucket policies, when in fact CloudTrail only records events and cannot modify resource configurations.

How to eliminate wrong answers

Option A is wrong because Amazon GuardDuty is a threat detection service that monitors for malicious activity using DNS logs, VPC Flow Logs, and CloudTrail events; it does not evaluate S3 bucket configurations for compliance or perform remediation. Option B is wrong because AWS CloudTrail records API activity for auditing and governance but does not evaluate current resource configurations or automatically remediate non-compliant resources. Option D is wrong because AWS Trusted Advisor provides best-practice checks and recommendations, including S3 bucket logging checks, but it cannot automatically remediate non-compliant buckets; it only offers guidance.

662
MCQmedium

Refer to the exhibit. A SysOps administrator deploys this CloudFormation stack. The EC2 instance launches and the web server starts. However, the CloudWatch alarm does not trigger even when CPU utilization exceeds 80%. What is the MOST likely reason?

A.The alarm action is missing a valid SNS topic ARN.
B.The alarm statistic should be 'Maximum' instead of 'Average' to catch CPU spikes that may not sustain the average above 80% for 5 minutes.
C.The alarm dimension is incorrect; it should use the instance's private IP.
D.The user data script fails to start the web server, causing the instance to be unhealthy.
AnswerB

With a 5-minute period and the Average statistic, short-lived CPU spikes can be averaged out, so the metric may remain below 80% even though the instance is repeatedly spiking above the threshold. The Maximum statistic samples the highest value during each period, so any sustained spike in a 5-minute window will breach the threshold. For autoscaling or alerting on CPU exhaustion, Maximum is recommended to catch transient spikes that would otherwise be smoothed by averaging.

Why this answer

The alarm is configured with the 'Average' statistic, which smooths out CPU utilization over the 5-minute period. If CPU utilization spikes above 80% but does not sustain an average above that threshold for the entire duration, the alarm will not trigger. Using the 'Maximum' statistic would catch any single data point exceeding 80% within the period, making it appropriate for detecting short-lived spikes.

Exam trap

The trap here is that candidates often assume any CPU utilization above the threshold will trigger an alarm, overlooking how the chosen statistic (Average vs. Maximum) and evaluation period affect whether a spike is detected.

How to eliminate wrong answers

Option A is wrong because the alarm action missing a valid SNS topic ARN would cause a different issue (e.g., failure to send notifications), but it would not prevent the alarm from triggering based on the metric threshold; the alarm state would still change. Option C is wrong because the alarm dimension should use the instance ID, not the private IP; CloudWatch metrics for EC2 are dimensioned by InstanceId, and using a private IP would cause the alarm to not match the metric data. Option D is wrong because the user data script failing to start the web server would affect the instance's health but has no bearing on the CloudWatch alarm's ability to trigger based on CPU utilization; the alarm monitors CPU, not web server status.

663
MCQhard

A company runs a critical application on EC2 instances in an Auto Scaling group with a minimum of 2 instances. The instances are in a single Availability Zone. The company wants to achieve 99.99% availability. Which change should they make?

A.Modify the Auto Scaling group to launch instances in multiple Availability Zones and place an Application Load Balancer in front.
B.Increase the minimum size of the Auto Scaling group to 4 instances.
C.Use a larger EC2 instance type to handle more traffic.
D.Configure the Auto Scaling group to scale based on memory utilization.
AnswerA

By distributing instances across multiple Availability Zones and using an Application Load Balancer to route traffic, the application can withstand an entire AZ failure because the remaining AZs continue serving. The ALB performs health checks and only forwards requests to healthy registered targets, automatically shifting load away from failed AZs. This is the core high-availability design for EC2-based architectures.

Why this answer

To achieve 99.99% availability, the application must survive an Availability Zone (AZ) failure. Running instances in a single AZ creates a single point of failure. By modifying the Auto Scaling group to launch instances in multiple AZs and placing an Application Load Balancer (ALB) in front, traffic is automatically distributed across healthy instances in different AZs, ensuring fault tolerance even if an entire AZ becomes unavailable.

Exam trap

The trap here is that candidates often focus on increasing instance count or scaling metrics, overlooking that 99.99% availability requires geographic redundancy across Availability Zones, not just more instances in a single zone.

How to eliminate wrong answers

Option B is wrong because simply increasing the minimum size to 4 instances within the same single AZ does not protect against an AZ outage; all instances would still fail if that AZ goes down. Option C is wrong because using a larger EC2 instance type only improves performance and capacity, not availability; it does not address the risk of an AZ failure. Option D is wrong because scaling based on memory utilization helps with performance and cost optimization but does not provide redundancy across AZs; it cannot mitigate an AZ-level failure.

664
MCQeasy

A company is using AWS Cost Explorer to analyze spending. They want to receive an email alert when costs exceed a certain threshold. Which service should they use?

A.AWS Trusted Advisor
B.AWS Cost Explorer
C.Amazon CloudWatch
D.AWS Budgets
AnswerD

AWS Budgets is the correct service because it is specifically designed to track your actual and forecasted AWS cost and usage against a defined threshold and immediately send notifications when that threshold is exceeded. You can create a cost budget, set a fixed spending amount, and configure SNS-based alerts for both actual and forecasted spending, covering scenarios like the company's need to monitor a limit. It also supports actions to prevent overages, such as applying IAM policies or terminating instances. That native, proactive alerting capability is exactly what the scenario requires.

Why this answer

AWS Budgets can send alerts when costs exceed thresholds. Option A (AWS Trusted Advisor) is wrong because it provides recommendations for cost optimization but does not send alerts based on cost thresholds. Option B (AWS Cost Explorer) is wrong because it is used for analyzing cost and usage data, not for sending alerts.

Option C (Amazon CloudWatch) is wrong because CloudWatch monitors AWS resources and applications, but it does not natively monitor AWS costs or send cost threshold alerts.

665
MCQmedium

A company requires that all S3 buckets be tagged with a 'CostCenter' tag. A SysOps administrator needs to enforce this and prevent creation of untagged buckets. Which approach should be used?

A.Apply a service control policy (SCP) that denies s3:CreateBucket unless the request includes the required tag
B.Create an IAM policy that allows s3:CreateBucket only if the bucket has the tag, and attach it to all users
C.Enable AWS CloudTrail to log bucket creation and review logs daily
D.Use an AWS Config rule to automatically delete untagged buckets
AnswerA

An SCP applied at the organizational unit (OU) or root level can explicitly deny s3:CreateBucket when the request lacks a specific tag key (e.g., cost-center). Because SCPs act as a guardrail for all accounts under the OU, they cannot be overridden by individual account IAM policies, making them the most reliable preventive control. The SCP would use a Condition block with the StringNotEquals or StringLike operator on aws:RequestTag, ensuring that only properly tagged bucket creation requests succeed.

Why this answer

AWS Organizations SCPs can be used to deny actions that do not meet certain conditions, such as requiring specific tags. An SCP with a condition for 'aws:RequestTag' can enforce tagging at bucket creation. IAM policies can also enforce tagging for specific users, but SCPs apply to all accounts in the organization.

AWS Config rules can detect non-compliant resources but cannot prevent creation. CloudTrail is for logging, not enforcement.

666
MCQeasy

A SysOps administrator is deploying a new application using AWS CloudFormation. The template includes an EC2 instance with a UserData script that installs software from a private S3 bucket. What is the BEST way to ensure the EC2 instance can access the S3 bucket without storing long-term credentials on the instance?

A.Create an IAM user with S3 access and attach the access key to the instance profile.
B.Store the access key ID and secret access key in the UserData script.
C.Create an IAM role with S3 access and associate it with the instance profile.
D.Configure a security group rule that allows the instance to reach S3 via VPC endpoint.
AnswerC

An IAM role with S3 access is the correct and secure way to grant an EC2 instance permissions. When you attach the role to an instance profile and associate it with the instance, EC2 automatically retrieves temporary credentials from the instance metadata service (IMDSv2), which are rotated every few hours. The application can then make S3 API calls using the AWS SDK without ever managing static credentials. This leverages least privilege and eliminates the risk of exposed access keys.

Why this answer

Creating an IAM role with S3 access and associating it with the instance profile allows the EC2 instance to obtain temporary credentials automatically via the instance metadata service. This avoids storing long-term credentials on the instance, which is a security best practice.

Exam trap

SOA-C02 often tests the difference between IAM users and IAM roles for EC2. Candidates might choose to create an IAM user because it seems straightforward, but that involves long-term credentials, which the question explicitly wants to avoid.

How to eliminate wrong answers

Option A is wrong because creating an IAM user and attaching access keys to the instance profile is not how instance profiles work; instance profiles are for IAM roles, not users. Option B is wrong because storing access keys in UserData is insecure as they are visible in the console and metadata. Option D is wrong because a security group rule alone does not grant S3 access; it only controls network traffic, and S3 access requires IAM permissions.

667
MCQeasy

A company wants to ensure that all Amazon S3 buckets have versioning enabled to protect against accidental deletion of objects. A SysOps administrator needs to automatically detect any buckets that do not have versioning enabled and receive notifications. Which AWS service should the administrator use?

A.AWS CloudTrail
B.AWS Config
C.Amazon Inspector
D.AWS Trusted Advisor
AnswerB

AWS Config continuously records resource configuration changes and evaluates them against desired policies using managed or custom rules. The managed rule 's3-bucket-versioning-enabled' specifically checks whether an S3 bucket has versioning turned on, and AWS Config will flag the bucket as noncompliant if it is disabled. It also integrates with Amazon SNS for real-time notifications and AWS Systems Manager Automation for automatic remediation, making it the appropriate service for proactive compliance enforcement.

Why this answer

AWS Config is the correct service because it provides managed rules, such as 's3-bucket-versioning-enabled', that continuously evaluate your S3 buckets against desired configuration states. When a bucket is non-compliant (versioning disabled), AWS Config can trigger an Amazon SNS notification to alert the administrator, enabling automated detection and remediation.

Exam trap

The trap here is that candidates confuse AWS Config (continuous configuration auditing) with AWS CloudTrail (API activity logging), thinking that CloudTrail can detect non-compliant states when it only records actions that change the state.

How to eliminate wrong answers

Option A (AWS CloudTrail) is wrong because it records API activity (e.g., PutBucketVersioning calls) but does not continuously evaluate the current configuration state of resources; it cannot proactively detect buckets with versioning disabled unless an API call is made. Option C (Amazon Inspector) is wrong because it is designed for vulnerability assessment of EC2 instances and container workloads, not for auditing S3 bucket configurations. Option D (AWS Trusted Advisor) is wrong because while it can check S3 bucket versioning as part of its cost optimization and security checks, it does not provide automated, real-time notifications for configuration drift; it is a manual, periodic review tool.

668
Multi-Selecthard

A company uses Amazon S3 to store backup data. The SysOps administrator needs to ensure that the data is protected against accidental deletion by users with administrative privileges. Which combination of actions should the administrator take? (Choose TWO.)

Select 2 answers
A.Enable MFA Delete on the S3 bucket.
B.Apply an S3 bucket policy that denies s3:DeleteObject for all users.
C.Enable versioning on the S3 bucket.
D.Configure a lifecycle policy to transition objects to S3 Glacier.
E.Enable AWS CloudTrail to log all S3 API calls.
AnswersA, C

MFA Delete is the correct safeguard for this scenario because it forces any request that permanently deletes an object version, or that suspends versioning on the bucket, to include a valid code from a hardware or virtual MFA device. This prevents an attacker who has stolen console credentials or an IAM access key from irrevocably erasing backup data, since they would also need possession of the MFA token. It is important to note that MFA Delete can only be enabled when versioning is turned on, and it must be set via the AWS CLI or API rather than the console.

Why this answer

Option A is correct because MFA Delete adds an additional authentication factor requirement for permanently deleting object versions or changing the versioning state of the bucket, which specifically protects against accidental deletion even by users with administrative privileges. Option C is correct because enabling versioning ensures that overwritten or deleted objects are retained as noncurrent versions, allowing recovery of data that would otherwise be lost. Together, versioning preserves deleted objects and MFA Delete prevents an administrator from permanently removing them or disabling versioning without an MFA token.

Option B is not appropriate because a blanket deny of s3:DeleteObject would break legitimate deletion workflows and can be bypassed or modified by users with administrative privileges who can edit bucket policies. Option D is incorrect because lifecycle transitions to S3 Glacier only change storage class and do not protect against deletion. Option E is incorrect because CloudTrail only records API activity for auditing; it does not prevent or recover from accidental deletion.

Exam trap

SOA-C02 often tests the misconception that bucket policies or CloudTrail can prevent deletion, when in fact only MFA Delete and versioning provide protection against accidental deletion by privileged users.

669
MCQmedium

A company runs a stateless web application on EC2 instances in an Auto Scaling group across multiple Availability Zones. The application experiences increased latency during peak hours. The SysOps administrator needs to improve the application's performance and reliability. Which action should be taken?

A.Use larger EC2 instance types instead of smaller ones.
B.Reduce the Auto Scaling group's cooldown period to scale out faster.
C.Change the scaling metric from CPU utilization to memory utilization.
D.Increase the maximum instance count in the Auto Scaling group.
AnswerD

Increasing the maximum instance count in the Auto Scaling group directly expands the group's capacity ceiling, allowing it to launch additional EC2 instances when demand spikes. This is the appropriate solution for a stateless web application because horizontal scaling distributes traffic across multiple instances and provides both elastic capacity and fault tolerance. With a properly configured scaling policy, the group can now add instances beyond its previous limit, accommodating higher traffic volumes without modifying the application.

Why this answer

Increasing the maximum instance count allows the Auto Scaling group to launch more EC2 instances during peak hours, distributing the load across more resources and reducing latency. This directly improves both performance (by handling more requests) and reliability (by maintaining capacity under increased demand).

Exam trap

The trap here is that candidates often confuse scaling metrics or instance sizing with the fundamental need to increase the maximum capacity limit when the group is already hitting its cap during peak load.

How to eliminate wrong answers

Option A is wrong because using larger instance types may improve per-instance performance but does not inherently increase the total capacity to handle peak load; it also reduces granularity for scaling and can increase costs without addressing the need for more instances. Option B is wrong because reducing the cooldown period can cause rapid, unstable scaling (thrashing) and does not solve the underlying capacity shortage; it may lead to unnecessary scaling actions and increased costs. Option C is wrong because memory utilization is not a suitable scaling metric for a stateless web application where CPU utilization directly reflects request processing load; memory usage remains relatively stable and would not trigger timely scaling during CPU-bound latency spikes.

670
MCQmedium

A SysOps admin notices that an EC2 instance's status check fails intermittently. The instance is part of an Auto Scaling group. What is the most appropriate first step to diagnose the issue?

A.Stop and start the instance
B.Terminate the instance and let Auto Scaling replace it
C.Reboot the instance
D.Review the instance's status check history in the EC2 console
AnswerD

Reviewing the instance's status check history in the EC2 console is the correct first step because it tells you the exact type and persistence of the failure. The 'Status Checks' tab displays both System Status Checks and Instance Status Checks over time, allowing you to distinguish between an AWS infrastructure defect (hardware/network power loss) and a guest OS issue (corrupt file system, boot failure, or network misconfiguration). This pattern of history—whether the check is stuck, intermittent, or just recent—directly determines whether you should stop/start, reboot, or inspect the system log, making it the foundational diagnostic action.

Why this answer

The most appropriate first step is to review the instance's status check history in the EC2 console (Option D). This allows the SysOps admin to determine whether the failures are due to system status checks (e.g., underlying hardware issues) or instance status checks (e.g., OS-level problems). Since the instance is part of an Auto Scaling group, understanding the root cause is critical before taking any corrective action, as premature termination or reboot could mask the issue or lead to unnecessary replacements.

Exam trap

The trap here is that candidates often jump to terminating or rebooting the instance immediately, but the SOA-C02 exam emphasizes a methodical troubleshooting approach where reviewing status check history is the first step to differentiate between recoverable and irrecoverable failures.

How to eliminate wrong answers

Option A is wrong because stopping and starting the instance would move it to new hardware, which is only appropriate if the issue is a system status check failure (hardware problem), but this action is not the first diagnostic step and could disrupt the instance without confirming the cause. Option B is wrong because terminating the instance and letting Auto Scaling replace it is a reactive measure that bypasses diagnosis; it could lead to repeated failures if the underlying issue (e.g., a misconfigured application) persists in the replacement instance. Option C is wrong because rebooting the instance only addresses transient software issues and does not resolve hardware-level failures; it also does not provide diagnostic information about the intermittent status check failures.

671
MCQeasy

A company wants to deploy a new version of a web application to an Auto Scaling group of EC2 instances behind an Application Load Balancer. The deployment should be automated and must not cause downtime. Which AWS service should be used?

A.AWS CloudFormation
B.AWS OpsWorks
C.AWS Elastic Beanstalk
D.AWS CodeDeploy
AnswerD

AWS CodeDeploy is purpose-built for application deployment to EC2 instances, including those in an Auto Scaling group. It supports blue/green deployments with traffic shifting via an Application Load Balancer, allowing zero-downtime releases by registering new instances and shifting traffic gradually. Its integration with ASG lifecycle hooks ensures that new instances launched during scaling out automatically receive the latest application revision, making it the correct choice.

Why this answer

AWS CodeDeploy is designed to automate deployments to EC2 instances, including those in an Auto Scaling group, and supports blue/green deployments to avoid downtime. It integrates with ALB to shift traffic gradually. This makes it the correct choice for automated, zero-downtime deployments.

Exam trap

The trap is confusing infrastructure-as-code tools like CloudFormation with deployment tools; candidates might choose Elastic Beanstalk because it's a deployment service, but CodeDeploy is specifically designed for automated deployments to existing EC2/ASG setups.

How to eliminate wrong answers

Option A is wrong because AWS CloudFormation is for infrastructure provisioning, not application deployment automation. Option B is wrong because AWS OpsWorks is a configuration management service, not specifically for automated deployments with traffic shifting. Option C is wrong because AWS Elastic Beanstalk is a PaaS that simplifies deployment but may not provide the same level of control for blue/green deployments with an existing Auto Scaling group and ALB; CodeDeploy is more directly suited.

672
Multi-Selecthard

A company is using Amazon Route 53 as its DNS service. The SysOps team needs to route traffic to multiple resources based on the geographic location of the users. Which TWO routing policies can achieve this? (Select TWO.)

Select 2 answers
A.Geoproximity routing
B.Simple routing
C.Failover routing
D.Latency-based routing
E.Geolocation routing
AnswersA, E

Geoproximity routing uses the geographic location of both the user and the AWS resource to route traffic, and it supports an optional bias value that expands or shrinks the route-to-resource region. For example, you can set a positive bias to direct more traffic to a specific AWS Region, or a negative bias to move traffic away from it. This makes it ideal for gradually shifting traffic between regions while still basing routing on physical proximity.

Why this answer

The question asks for two routing policies that route traffic based on geographic location. Geoproximity routing (Option A) and Geolocation routing (Option E) are the correct choices. Geoproximity routing considers both geographic location and optional bias, while Geolocation routing uses strict geographic boundaries.

Latency-based routing (Option D) routes based on network latency, not geography, even if latency often correlates with distance. Simple routing (Option B) and Failover routing (Option C) do not use geographic information at all.

Exam trap

The question asks for two geographic routing policies, but only Geoproximity routing and Geolocation routing are based on geographic location. Candidates might mistakenly think there is a third correct option, such as latency-based routing, but that uses network latency, not geography. This can cause confusion.

673
MCQhard

Refer to the exhibit. A SysOps administrator runs the AWS CLI command shown. The output shows that the CPUUtilization average over the period is 75%. However, the administrator knows that the instance was idle for the first 15 minutes of the hour. Which explanation best describes why the average might be misleading?

A.The period is too long; a shorter period like 60 seconds would show more granular data.
B.The average statistic over a period of 300 seconds can smooth out spikes, and the overall average of 75% may be due to a high spike after the idle period.
C.The command should include --unit Percent to get accurate data.
D.The --statistics parameter should be set to 'Sum' to capture total usage.
AnswerB

CloudWatch computes the average statistic by taking the mean of data points within each 300-second period, which inherently discards the ordering and magnitude of short-lived CPU spikes. If the instance sat idle for most of the hour then experienced a sudden burst, that single high-utilization period disproportionately raises the overall hourly average when combined with the near-zero idle intervals. This averaging effect masks the spike's brevity and makes the reported 75% average appear to reflect steady utilization, when in fact it is an artifact of aggregating a bursty workload across a long window.

Why this answer

The average statistic over a 300-second period can smooth out brief but intense spikes in CPU utilization. In this scenario, the instance was idle for the first 15 minutes, so the average of 75% over the entire hour must be driven by a very high CPU spike later in the period. The period of 300 seconds aggregates data into 5-minute intervals, which can mask the idle period and make the overall average misleading.

Exam trap

The trap here is that candidates assume a high average always indicates consistent high usage, when in fact the 'Average' statistic over a long period can mask idle periods and be heavily skewed by short, intense spikes.

How to eliminate wrong answers

Option A is wrong because while a shorter period like 60 seconds would provide more granular data, it would not change the fact that the average over the hour is 75%—the issue is not the granularity but the smoothing effect of the average statistic over the chosen period. Option C is wrong because the --unit parameter is not required for CPUUtilization metrics; CloudWatch automatically reports CPUUtilization as a percentage, and omitting --unit does not cause inaccurate data. Option D is wrong because using the 'Sum' statistic would accumulate CPU utilization over each period, which is not meaningful for a percentage metric and would not help identify the misleading average caused by the idle period.

674
MCQmedium

A media company stores millions of video files in S3. Some files are accessed heavily after upload (when new) and rarely afterward; others are accessed unpredictably across months. The team cannot predict which files will be accessed and when. They want to minimize storage costs without risking retrieval latency penalties or per-object retrieval fees. Which storage class is appropriate?

A.Use S3 Intelligent-Tiering so objects automatically move between Frequent and Infrequent Access tiers based on access patterns, with no retrieval fees
B.Use S3 Standard-IA and configure a lifecycle policy to move objects back to Standard after every access
C.Use S3 Glacier Instant Retrieval for all objects because it offers the lowest storage cost with millisecond retrieval
D.Use S3 Standard for all objects because it has no retrieval fees and provides the best availability
AnswerA

Intelligent-Tiering handles the unpredictable access pattern automatically. Objects accessed within 30 days stay in Frequent Access. Unaccessed objects move to Infrequent Access (40 percent lower cost). No retrieval fee ensures there is no cost penalty when an old file is accessed unexpectedly. The per-object monitoring fee is offset by storage savings for objects over 128 KB.

Why this answer

S3 Intelligent-Tiering is the correct choice because it automatically moves objects between Frequent Access and Infrequent Access tiers based on changing access patterns, with no retrieval fees and no performance impact (millisecond latency). This matches the unpredictable access pattern described, as the service monitors access at the object level and adjusts storage tier without manual lifecycle rules or retrieval costs.

Exam trap

The trap here is that candidates often confuse S3 Intelligent-Tiering with S3 Standard-IA, assuming both have retrieval fees, or they incorrectly believe Glacier Instant Retrieval is always cheaper despite its retrieval fees and minimum storage duration penalties.

How to eliminate wrong answers

Option B is wrong because S3 Standard-IA charges a per-object retrieval fee (per GB retrieved) and a minimum storage duration fee (30 days), and moving objects back to Standard after every access would incur repeated retrieval fees and lifecycle transition costs, defeating cost minimization. Option C is wrong because S3 Glacier Instant Retrieval has a higher storage cost than Intelligent-Tiering for frequently accessed data and still incurs retrieval fees (per GB) for every access, plus a minimum 90-day storage charge, making it unsuitable for unpredictable access patterns. Option D is wrong because S3 Standard has the highest storage cost among the options, and while it has no retrieval fees, it does not optimize costs for files that become rarely accessed over time, leading to unnecessary expense.

675
MCQmedium

A company runs a batch processing application on Amazon EC2 instances that runs every night for 2 hours. The job can be interrupted and resumed without any issue. The SysOps administrator wants to minimize compute costs for this workload. Which EC2 purchasing option should be used?

A.Spot Instances
B.On-Demand Instances
C.Reserved Instances
D.Dedicated Hosts
AnswerA

Spot Instances offer spare EC2 capacity at discounts of up to 90% compared to On-Demand, making them ideal for fault-tolerant, interruptible workloads like a nightly 2-hour batch job. If Spot capacity is reclaimed, the job can simply be restarted on another Spot Instance, and the short run duration minimizes disruption risk. The significant cost savings together with the workload's natural resilience to interruption make Spot the most cost-effective choice.

Why this answer

Spot Instances are the correct choice because the workload is fault-tolerant (can be interrupted and resumed) and runs for only 2 hours nightly. Spot Instances offer significant cost savings (up to 90% off On-Demand) but can be reclaimed by AWS with a 2-minute warning, which is acceptable here since the job can resume without issue. This aligns with the goal of minimizing compute costs for a non-critical, interruptible batch process.

Exam trap

The trap here is that candidates often choose Reserved Instances (Option C) thinking they always save money, but they fail to recognize that Reserved Instances are only cost-effective for steady-state, always-on workloads, not for short, interruptible batch jobs where Spot Instances provide greater savings without long-term commitment.

How to eliminate wrong answers

Option B (On-Demand Instances) is wrong because they provide no cost savings for a fault-tolerant workload that can handle interruptions; On-Demand is priced at the standard rate and is intended for unpredictable or critical workloads, not for minimizing costs. Option C (Reserved Instances) is wrong because they require a 1- or 3-year commitment and are designed for steady-state, predictable usage, not for a 2-hour nightly job that could be interrupted; the upfront cost and commitment would not be cost-effective for such a short, interruptible workload. Option D (Dedicated Hosts) is wrong because they are a physical server dedicated to a single customer, incurring high costs regardless of usage, and are intended for compliance or licensing requirements, not for minimizing compute costs for a batch job.

Page 8

Page 9 of 16

Page 10