Courseiva

CCNA Deployment, Provisioning, and Automation Questions

75 of 182 questions · Page 2/3 · Deployment, Provisioning, and Automation · Answers revealed

76
MCQhard

An organization is using OpsWorks to manage a stack of application servers. They need to automatically scale out based on CPU utilization. Which configuration should the SysOps administrator use to achieve this?

A.Enable auto-healing on the layer to replace unhealthy instances automatically.
B.Create a custom Chef recipe that runs on a lifecycle event to launch new instances.
C.Add a load-based layer and configure the scaling thresholds for CPU utilization.
D.Configure a time-based instance with a recurring schedule to add instances during peak hours.
AnswerC

Adding a load-based layer and specifying CPU utilization thresholds lets OpsWorks Stacks watch the layer's load metrics and automatically add or remove instances when CPU crosses upper or lower limits, with configurable cooldown and evaluation periods. This directly satisfies the CPU-based demand requirement because the layer scales out to more instances when CPU is high and scales in when it drops. Load-based instances are one of the built-in OpsWorks scaling types (along with time-based and 24/7 instances), and they are the only option listed that triggers scaling based on actual utilization.

Why this answer

OpsWorks load-based layers automatically scale instances based on CloudWatch alarms, such as CPU utilization thresholds. Option A is incorrect because auto-healing replaces failed instances, not scales out. Option B is incorrect because custom Chef recipes run on lifecycle events (setup, configure, etc.) but do not directly handle automatic scaling.

Option D is incorrect because time-based instances scale on a schedule, not based on CPU utilization.

77
MCQmedium

A SysOps administrator is troubleshooting a failed AWS CloudFormation stack update. The error message indicates that a resource failed to create due to insufficient IAM permissions. The administrator used a service role for CloudFormation. What should the administrator do to resolve the issue?

A.Add the required permissions to the administrator's IAM user.
B.Request a limit increase for IAM roles in the AWS account.
C.Update the IAM policy attached to the CloudFormation service role to include the necessary permissions.
D.Modify the resource's IAM policy to allow CloudFormation to create it.
AnswerC

The CloudFormation service role must have a permissions policy that explicitly grants the actions needed to create, update, and delete the stack's resources, because CloudFormation assumes this role to make those API calls on your behalf. Editing the role's IAM policy to include the required permissions, such as the relevant ec2:* or s3:* actions (or a narrowly scoped set), will allow the stack operation to proceed. This is the correct remedy because the service role's trust policy already permits CloudFormation to assume it; the missing piece is the authorization for the resource operations.

Why this answer

When CloudFormation assumes a service role to perform stack operations, all API calls made on behalf of the stack use that role's permissions — not the administrator's user permissions. The fix is to attach or update the IAM policy on the CloudFormation service role to grant the missing permissions (e.g., ec2:CreateInstance, s3:CreateBucket). This is the least-privilege, correct remediation.

Exam trap

SOA-C02 often tests whether candidates understand that CloudFormation uses the SERVICE ROLE's permissions, not the invoking user's — the trap is picking 'add permissions to my IAM user' out of habit.

How to eliminate wrong answers

Option A is wrong because adding permissions to the administrator's IAM user has no effect — CloudFormation is acting under the service role, not the user's credentials, so the user's permissions are irrelevant to the stack operation. Option B is wrong because the error is a permissions (authorization) failure, not a service quota/limit issue; requesting a limit increase for IAM roles does not grant the missing actions. Option D is wrong because modifying the resource's own IAM policy is backwards — the resource does not yet exist (it failed to create), and even if it did, the blocker is the CALLER's (CloudFormation service role's) permission to create it, not the resource's policy.

78
MCQmedium

A company uses AWS CodePipeline to automate deployments. The pipeline has a source stage that pulls code from an Amazon S3 bucket. The company wants to automatically trigger the pipeline when a new object is uploaded to the S3 bucket. How should this be configured?

A.Configure a CloudWatch Events rule that matches S3 object creation events and triggers the pipeline.
B.Use an AWS Lambda function to poll the S3 bucket and start the pipeline.
C.Configure the S3 bucket to send events to an Amazon SNS topic that triggers the pipeline.
D.Configure the S3 bucket to send events to an Amazon SQS queue that triggers the pipeline.
AnswerA

CloudWatch Events (now integrated with Amazon EventBridge) natively supports CodePipeline as a target, so you can create a rule with an event pattern for s3:ObjectCreated:* from the source bucket. When the S3 object is created, the event is matched and CodePipeline automatically starts an execution without any polling, custom code, or intermediary services, making this the fully event-driven and direct solution.

Why this answer

Configuring a CloudWatch Events (now Amazon EventBridge) rule that matches S3 object creation events and triggers the pipeline is the correct approach. EventBridge can directly target CodePipeline as a target, enabling automatic pipeline execution when a new object is uploaded to the S3 bucket. This is the native, serverless integration for event-driven pipelines.

Exam trap

SOA-C02 often tests the misconception that SNS or SQS can directly trigger CodePipeline — candidates must know that EventBridge (CloudWatch Events) is the service that can target CodePipeline directly.

How to eliminate wrong answers

Option B is wrong because polling with Lambda is inefficient, introduces latency, and is not the recommended event-driven pattern. Option C is wrong because SNS cannot directly trigger CodePipeline; it would require an intermediary (e.g., Lambda) and is not the most direct method. Option D is wrong because SQS also cannot directly trigger CodePipeline and would require additional components, adding complexity.

79
MCQmedium

A company uses AWS CodeBuild to compile code and run unit tests. The build environment requires a specific version of Java that is not available in the default build images. What should the administrator do?

A.Request AWS Support to add the Java version to the default build image.
B.Use an AWS Lambda function to set up the build environment before CodeBuild runs.
C.Install the required Java version in the buildspec file using a command.
D.Create a custom build image with the required Java version and push it to Amazon ECR.
AnswerD

Creating a custom build image and pushing it to Amazon ECR lets you pre-install the exact Java JDK version (e.g., OpenJDK 17.0.9) along with any required build tools and system libraries. CodeBuild then uses that image as the environment baseline, so every build start from a consistent, immutable configuration. This approach supports image tagging and version rollback, and it eliminates the need for runtime package installation in the buildspec.

Why this answer

CodeBuild allows you to specify a custom Docker image for the build environment, which can include any required software such as a specific Java version. By creating a custom image, installing the needed Java version, and pushing it to Amazon ECR, the administrator ensures the build environment meets the exact requirements. This approach is flexible and repeatable, and CodeBuild natively supports pulling images from ECR.

Exam trap

SOA-C02 often tests the misconception that buildspec commands can fully customize the environment, but the exam expects knowledge that custom images are the proper solution for specific runtime versions.

How to eliminate wrong answers

Option A is wrong because AWS Support cannot modify default build images; these are managed by AWS and not customizable per customer request. Option B is wrong because AWS Lambda cannot modify the build environment of CodeBuild; Lambda runs separately and cannot inject software into the CodeBuild container before the build starts. Option C is wrong because while you can install software in the buildspec, it is inefficient and may not persist across phases; moreover, installing Java during the build can be slow and may not be possible if the base image lacks necessary package managers or permissions.

80
MCQmedium

A company uses AWS CodeDeploy to deploy an application to Amazon EC2 instances. The SysOps administrator wants to implement a deployment strategy that minimizes risk by deploying the new version to a small number of instances first, verifying that the deployment is successful, and then deploying to the remaining instances. If the initial deployment fails, the process should stop and roll back. Which CodeDeploy deployment configuration should be used?

A.CodeDeployDefault.AllAtOnce
B.CodeDeployDefault.HalfAtATime
C.CodeDeployDefault.OneAtATime
D.CodeDeployDefault.Canary10Percent10Minutes
AnswerC

OneAtATime deploys to a single instance at a time, verifies that it is healthy, and then proceeds to the next. This is the most cautious approach and matches the requirement of deploying to a small number (one) first, then continuing to the rest.

Why this answer

CodeDeployDefault.OneAtATime, is correct because it deploys the new application revision to one instance at a time, checking for success before proceeding to the next. If any deployment step fails, the process stops and automatically rolls back, minimizing risk by limiting the blast radius of a bad deployment.

Exam trap

The trap here is that candidates often confuse CodeDeployDefault.Canary10Percent10Minutes (a traffic-shifting configuration for Lambda/ECS) with a linear EC2 deployment strategy, or they mistakenly think HalfAtATime provides sufficient risk mitigation when the requirement explicitly calls for deploying to a 'small number' first and stopping on failure.

How to eliminate wrong answers

Option A is wrong because CodeDeployDefault.AllAtOnce deploys to all instances simultaneously, which does not minimize risk — a failure would affect all instances at once. Option B is wrong because CodeDeployDefault.HalfAtATime deploys to half the instances at a time, which still exposes a large portion of the fleet to a potential failure before verification is complete. Option D is wrong because CodeDeployDefault.Canary10Percent10Minutes is a canary deployment configuration that shifts 10% of traffic for 10 minutes, but this is a traffic-shifting strategy for Lambda or ECS deployments, not for EC2/On-Premises instances, and it does not stop on failure by default.

81
MCQmedium

A SysOps administrator manages a fleet of Amazon EC2 instances that run critical software. The administrator needs to automatically apply security patches every Tuesday at 2 AM. The instances are part of an Auto Scaling group and must be patched without downtime. Which AWS Systems Manager feature should be used?

A.State Manager
B.Patch Manager
C.Maintenance Windows
D.Run Command
AnswerC

AWS Systems Manager Maintenance Windows is the purpose-built service for scheduling and executing administrative tasks during defined time windows while preserving availability. It allows you to register an Auto Scaling group as a target and assign tasks (such as Patch Manager or custom Automation) with rate control to limit concurrency and error thresholds, ensuring only a controlled subset of instances is patched at a time. Maintenance Windows supports stop times, task priorities, and integration with Run Command and Automation documents, which can be used to recycle instances, refresh launch templates, or place instances in Standby during the maintenance activity. This orchestration is precisely what enables zero-downtime patching across a fleet managed by Auto Scaling, making it the correct answer.

Why this answer

Maintenance Windows is the correct choice because it allows you to schedule a recurring window (every Tuesday at 2 AM) during which Systems Manager actions, such as patching, can be executed on EC2 instances. This feature is specifically designed to coordinate patching across Auto Scaling groups without downtime by ensuring instances are patched in a controlled manner, often using a patching rate or concurrency limit to maintain availability.

Exam trap

The trap here is that candidates confuse Patch Manager (the patching engine) with Maintenance Windows (the scheduler), assuming Patch Manager alone can handle recurring schedules, when in fact it requires Maintenance Windows or a separate cron-like trigger to run at a specific time.

How to eliminate wrong answers

Option A is wrong because State Manager is used to define and maintain consistent configuration of instances over time (e.g., ensuring a specific software state), not to schedule one-time or recurring patching tasks with a defined window. Option B is wrong because Patch Manager is the service that actually scans for and installs patches, but it lacks the scheduling and windowing capabilities needed to run at a specific time (2 AM) without additional orchestration. Option D is wrong because Run Command is designed for ad-hoc, immediate execution of commands on instances, not for recurring scheduled operations with a defined maintenance window.

82
MCQmedium

A company is using AWS CodePipeline to automate their CI/CD pipeline. The pipeline includes a deployment stage that uses AWS CloudFormation to deploy infrastructure. The company wants to add a manual approval step before the CloudFormation deployment. How should this be configured?

A.Add a CloudFormation change set action before the deployment.
B.Configure an Amazon SNS topic to send a notification and require a confirmation.
C.Add a manual approval action in the pipeline before the CloudFormation deployment stage.
D.Use an AWS Lambda function to send an email and wait for a response.
AnswerC

In CodePipeline, a manual approval action is a stage action with category Approval that pauses the pipeline execution at that point. Once the action is reached, the pipeline enters a Wait state and notifies designated approvers via SNS; deployment to CloudFormation proceeds only after an authorized IAM user or role approves the change. This is the native mechanism designed to block progression until human sign-off, making it the correct way to require confirmation before deployment.

Why this answer

AWS CodePipeline natively supports a manual approval action that pauses the pipeline until a designated approver reviews and approves or rejects the action. Placing this action in the pipeline immediately before the CloudFormation deployment stage is the correct, built-in way to add a manual gate.

Exam trap

SOA-C02 often tests the confusion between notification (SNS) and enforcement (manual approval action), leading candidates to choose SNS or Lambda-based workarounds instead of the native CodePipeline manual approval action.

How to eliminate wrong answers

Option A is wrong because a CloudFormation change set action creates a preview of changes but does not require human approval; it simply generates the change set and can be followed by an execute action. Option B is wrong because SNS notifications are informational and do not block pipeline execution; they cannot enforce a manual approval. Option D is wrong because a Lambda function that sends an email and waits is a custom workaround, not the native CodePipeline feature, and would require complex state management.

83
MCQmedium

A SysOps administrator uses AWS CloudFormation to deploy a stack that includes an Amazon EC2 instance and a security group. The administrator wants to ensure that when the stack is updated, the security group is not accidentally replaced if its properties change. The administrator wants to receive a failure if an update would require replacement of the security group. Which CloudFormation feature should the administrator use?

A.Add a 'DeletionPolicy' attribute set to 'Retain' on the security group resource.
B.Add a 'CreationPolicy' attribute to the security group resource.
C.Define a stack policy that denies replacement of the security group resource.
D.Use an 'UpdatePolicy' attribute with 'AutoScalingReplacingUpdate' on the security group.
AnswerC

A stack policy can specify the allowed update actions per resource. By denying the 'Replace' action for the security group, CloudFormation will fail updates that would require recreating the security group, protecting it from accidental replacement.

Why this answer

A stack policy can explicitly deny update actions that would replace a resource, such as the security group. By defining a stack policy with a Deny statement for the 'Replace' effect on the security group's logical resource ID, CloudFormation will fail the update if any property change triggers a replacement, preventing accidental deletion and recreation.

Exam trap

The trap here is that candidates confuse 'DeletionPolicy' (which only applies on stack deletion) with preventing replacement during updates, or mistakenly think 'UpdatePolicy' or 'CreationPolicy' can control resource replacement behavior.

How to eliminate wrong answers

Option A is wrong because the 'DeletionPolicy' attribute set to 'Retain' only preserves the security group when the stack is deleted, not during an update; it does not prevent replacement during an update. Option B is wrong because 'CreationPolicy' is used to wait for signals or resource creation success, not to control update behavior or prevent replacement. Option D is wrong because 'UpdatePolicy' with 'AutoScalingReplacingUpdate' is specific to Auto Scaling groups to control rolling updates, not applicable to security groups.

84
MCQeasy

A SysOps administrator needs to automate the creation of an Amazon RDS for MySQL database instance. The administrator wants to use AWS CloudFormation and ensure that the database password is not stored in plaintext in the template. Which solution meets these requirements?

A.Store the password as a CloudFormation parameter with a default value and use the Ref intrinsic function.
B.Generate a password manually and store it in a text file in Amazon S3; reference the S3 URL in the template.
C.Use AWS Secrets Manager to generate a random password and reference it in the CloudFormation template using a dynamic reference (resolve:secretsmanager).
D.Use AWS Systems Manager Parameter Store (String type) and reference it with the dynamic reference resolve:ssm.
AnswerC

Using AWS Secrets Manager with a dynamic reference allows CloudFormation to retrieve a secret at deployment time without exposing the value in the template, console, or logs. An AWS::SecretsManager::Secret resource with GenerateSecretString can automatically create a random password, and the rest of the stack can reference it via {{resolve:secretsmanager:secret-id:SecretString}}. This approach integrates with IAM policies, supports fine-grained permissioning, and can enable automatic rotation via a Lambda function, making it the AWS recommended best practice for secrets in infrastructure as code.

Why this answer

AWS CloudFormation dynamic references with the resolve:secretsmanager syntax retrieve a secret value at stack deployment time directly from AWS Secrets Manager without ever storing it in the template or its parameters. Secrets Manager can generate and rotate the password automatically, and the template only contains a reference such as '{{resolve:secretsmanager:MySecret:SecretString:password}}'. This satisfies the requirement that the password never appears in plaintext in the template.

Exam trap

SOA-C02 often tests the difference between storing secrets in plaintext (parameters, S3, String parameters) versus using Secrets Manager dynamic references — candidates pick Parameter Store String because it sounds secure, but only SecureString or Secrets Manager avoids plaintext.

How to eliminate wrong answers

Option A is wrong because a CloudFormation parameter with a default value stores the password in plaintext in the template (and in the console/API), which is exactly what the question forbids. Option B is wrong because storing the password in an S3 text file and referencing the URL still exposes the plaintext secret in S3 and requires the template to fetch it insecurely; it also lacks rotation and access control. Option D is wrong because Systems Manager Parameter Store with the String type stores the value in plaintext — only SecureString (KMS-encrypted) parameters are appropriate, and even then Secrets Manager is the AWS-recommended service for RDS-managed credentials with built-in rotation.

85
MCQeasy

A SysOps administrator needs to deploy a CloudFormation stack across multiple AWS accounts in an organization using AWS Organizations. The administrator wants to use a single template and a single deployment operation. Which AWS service should be used to centrally manage the deployment?

A.AWS Systems Manager
B.AWS OpsWorks Stacks
C.AWS CodePipeline
D.AWS CloudFormation StackSets
AnswerD

AWS CloudFormation StackSets lets you deploy the same CloudFormation template into multiple AWS accounts and Regions from a single administrator account. It creates stack instances in target accounts using either service-managed permissions with AWS Organizations or self-managed execution roles, and it includes deployment safeguards such as failure tolerance and maximum concurrent account thresholds. This is the native service designed specifically for orchestrated cross-account, cross-Region infrastructure rollout.

Why this answer

AWS CloudFormation StackSets allows you to deploy a single CloudFormation template across multiple AWS accounts and regions with a single operation. It is designed for centralized management of stacks in an organization, leveraging AWS Organizations for automatic deployment to member accounts. This meets the requirement of using one template and one deployment operation across multiple accounts.

Exam trap

SOA-C02 often tests the distinction between services that can deploy across accounts, and candidates may confuse StackSets with CodePipeline or Systems Manager due to overlapping use cases.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager is used for operational management of resources (e.g., patching, automation) but does not deploy CloudFormation stacks across accounts. Option B is wrong because AWS OpsWorks Stacks is a configuration management service that uses Chef/Puppet, not CloudFormation, and is not designed for cross-account stack deployment. Option C is wrong because AWS CodePipeline is a CI/CD service that can orchestrate deployments but requires additional configuration and does not natively deploy a single stack across multiple accounts in one operation without custom scripting.

86
MCQmedium

A company uses AWS CloudFormation to deploy a stack that includes an Amazon RDS DB instance. The administrator wants to ensure that the DB instance is not deleted when the stack is deleted. Which property should the administrator set in the CloudFormation template?

A.DeletionPolicy: Delete
B.DeletionPolicy: Snapshot
C.DeletionPolicy: Replace
D.DeletionPolicy: Retain
AnswerD

DeletionPolicy: Retain is the correct choice because it tells CloudFormation to leave the RDS DB instance untouched when the stack is deleted. The resource is removed from the stack's management, but the database remains live, accessible, and incurring costs in your AWS account. This exactly matches the goal of preserving the database after stack deletion.

Why this answer

The DeletionPolicy: Retain property ensures that the RDS DB instance is not deleted when the CloudFormation stack is deleted. It preserves the resource, allowing it to continue running independently of the stack. This is the correct choice to prevent accidental data loss.

Exam trap

SOA-C02 often tests the confusion between DeletionPolicy: Snapshot and Retain, where candidates think Snapshot preserves the instance, but it only preserves a snapshot and deletes the instance.

How to eliminate wrong answers

Option A is wrong because DeletionPolicy: Delete would delete the DB instance when the stack is deleted, which is the opposite of what is desired. Option B is wrong because DeletionPolicy: Snapshot takes a snapshot before deleting the resource, but the resource is still deleted; the snapshot is retained, but the instance is not. Option C is wrong because DeletionPolicy: Replace is not a valid DeletionPolicy value; valid values are Delete, Retain, and Snapshot.

87
MCQhard

A SysOps administrator is investigating a failed CloudFormation stack creation. The describe-stack-events output shows that the stack creation failed with the reason 'Resource creation cancelled'. What is the most likely cause of this failure?

A.The stack template contains an invalid parameter value.
B.The IAM role used by CloudFormation does not have sufficient permissions to create the resources.
C.A WaitCondition resource did not receive the required signal within the specified timeout period.
D.A nested stack within the parent stack failed to create.
AnswerC

In the CloudFormation event history, a 'Resource creation cancelled' status for a stack resource is the result of a WaitCondition or WaitConditionHandle timing out. For a WaitCondition resource, CloudFormation pauses the stack creation until it receives a success signal (typically sent by cfn-signal) from the launched resources. If that signal is not delivered within the specified Timeout period, the resource is marked as cancelled and the entire stack creation is stopped and rolled back. This failure mode is distinct from error-driven rollbacks because the resource itself never finished creating — it was simply waiting on an external signal that never arrived.

Why this answer

The WaitCondition timed out before receiving the required signal, causing CloudFormation to cancel the stack creation. Option A is incorrect because a parameter validation error would appear as a different reason. Option B is incorrect because there is no indication of missing IAM permissions.

Option D is incorrect because the stack creation was cancelled due to the wait condition timeout, not a nested stack failure.

88
MCQeasy

A SysOps administrator wants to deploy a new version of an application to an existing Auto Scaling group of Amazon EC2 instances. The deployment must minimize disruption by launching new instances, performing health checks, and shifting traffic to the new instances before terminating the old ones. Which AWS CodeDeploy deployment configuration should the administrator choose?

A.Blue/green
B.Rolling
C.AllAtOnce
D.Canary
AnswerA

Blue/green in CodeDeploy for EC2 Auto Scaling groups provisions a separate, temporary 'green' replacement fleet alongside the original 'blue' fleet. After the green instances pass the configured health checks and tests, the load balancer or target group shifts production traffic from blue to green, enabling an immediate, nearly zero-downtime release. Because the blue fleet remains untouched until deployment completion, rollback is trivial: just flip traffic back and terminate green. This is the only option that both eliminates downtime and provides a built-in instant rollback path.

Why this answer

The blue/green deployment configuration in AWS CodeDeploy is designed to minimize disruption by provisioning a new set of instances (green environment), performing health checks against them, and then shifting traffic from the old instances (blue environment) to the new ones before terminating the old instances. This matches the requirement of launching new instances, health-checking, and shifting traffic before termination, which is not possible with in-place deployment types like rolling or all-at-once.

Exam trap

The trap here is that candidates often confuse 'rolling' with 'blue/green' because both involve gradual updates, but rolling updates modify the existing Auto Scaling group in-place without creating a separate environment or shifting traffic before termination.

How to eliminate wrong answers

Option B (Rolling) is wrong because it performs an in-place update by gradually replacing instances within the existing Auto Scaling group without creating a separate environment, so traffic is not shifted before termination and health checks occur on the same instances. Option C (AllAtOnce) is wrong because it deploys to all instances simultaneously in-place, causing full downtime or disruption during the update. Option D (Canary) is wrong because it is a traffic-shifting pattern used in AWS CodeDeploy for Lambda or ECS deployments, not for EC2 Auto Scaling groups, and it does not launch new instances in a separate environment.

89
Multi-Selectmedium

A SysOps administrator is deploying a critical application using AWS CloudFormation. The stack must be updated frequently. Which TWO strategies should the administrator use to minimize the risk of update failures? (Choose TWO.)

Select 2 answers
A.Use change sets to review the impact of changes before applying them.
B.Disable rollback on failure to avoid stack deletion.
C.Always use the AWS CLI to perform updates instead of the console.
D.Manually approve each resource update through the console.
E.Use a stack policy to protect critical resources from accidental updates.
AnswersA, E

Change sets in AWS CloudFormation provide a summary of proposed changes to resources, including creations, modifications, and deletions, and flag any replacements. By reviewing a change set before executing it, you can detect unintended resource replacements (e.g., an RDS instance being replaced due to an immutable parameter) and abort the update if needed, thereby minimizing risk of change-related downtime or data loss.

Why this answer

Option A is correct because CloudFormation change sets generate a preview of the proposed changes, showing which resources will be added, modified, or replaced, so the administrator can detect unintended replacements or deletions before executing the update and thereby reduce the risk of a failed or destructive stack update. Option E is correct because a stack policy is a JSON document that explicitly denies Update:Modify or Update:Replace actions on specified critical resources, preventing accidental updates to those resources during stack updates and thus lowering the chance of update failures or outages. Option B is not appropriate because disabling rollback on failure does not prevent update failures; it only leaves the stack in UPDATE_FAILED or UPDATE_ROLLBACK_FAILED state, which can complicate recovery rather than minimize risk.

Option C is incorrect because the AWS CLI and the console both invoke the same CloudFormation UpdateStack API, so the interface used has no bearing on update risk. Option D is incorrect because CloudFormation does not provide a per-resource manual approval mechanism during stack updates; change sets are the supported review mechanism.

Exam trap

The trap is assuming that disabling rollback or using the CLI improves safety — candidates confuse 'avoiding stack deletion' with 'reducing update risk,' but rollback is a safety net, not a hazard.

90
MCQhard

A company uses AWS CloudFormation with nested stacks. The parent stack creates a child stack that launches an Auto Scaling group. The child stack fails to create, and the parent stack rolls back. The administrator wants to debug the child stack. What is the most efficient way to view the child stack's events?

A.Navigate to the child stack in the AWS CloudFormation console and view its events.
B.Rerun the parent stack with a different name to see the child stack creation.
C.Check the CloudWatch Logs for the parent stack.
D.View the parent stack's events in the AWS Management Console.
AnswerA

The child stack persists after rollback, because CloudFormation leaves it in a terminal state for inspection. Its Events tab lists every resource created or attempted within the child, including the exact failure reason (e.g., an EC2 instance's user-data script exit code, an IAM permission denial, or a resource creation timeout). This is the authoritative source of diagnostic information because the parent stack only sees the child as an atomic resource.

Why this answer

After a nested stack fails, it remains in a FAILED state and is visible in the AWS CloudFormation console. You can navigate directly to the child stack to view its events and identify the cause of failure. Option B is incorrect because rerunning the parent stack with a different name would create a new child stack, not help debug the original failed child stack.

Option C is incorrect because CloudWatch Logs are not automatically enabled for CloudFormation stacks; you would need to configure logging. Option D is incorrect because the parent stack's events only show aggregated status or a failure message for the child stack, not the detailed events inside the child stack.

91
MCQeasy

A SysOps administrator is automating the deployment of an application across multiple AWS accounts using AWS CodePipeline. The pipeline must deploy to different environments (dev, test, prod) sequentially. Which deployment approach should be used?

A.Use AWS CodeCommit repositories in each account and trigger builds.
B.Use AWS CLI scripts with cross-region replication.
C.Use separate CodePipeline stages with cross-account actions using IAM roles.
D.Create a single pipeline with all deployment stages in the same account.
AnswerC

Separate CodePipeline stages with cross-account actions using IAM roles is the correct architecture because CodePipeline natively supports cross-account actions by assuming a role in the target account for each stage. The pipeline in the originating account uses a source stage, then invokes a deployment action that assumes an IAM role in the destination account, allowing you to deploy the same artifact to multiple accounts sequentially or in parallel. This design enforces least privilege, keeps the pipeline state centralized while distributing execution, and meets the requirement of deploying to multiple accounts without combining resources.

Why this answer

Cross-account deployment in CodePipeline is achieved by defining separate stages (or actions) that assume an IAM role in the target account, allowing the pipeline in the tooling account to deploy into dev, test, and prod accounts sequentially. This uses sts:AssumeRole with a trust policy on the target account's role, and the stages run in order with manual approval gates as needed.

Exam trap

SOA-C02 often tests the confusion between cross-region and cross-account deployment — candidates pick CLI scripting or single-account pipelines when the question explicitly requires multiple accounts with sequential stages.

How to eliminate wrong answers

Option A is wrong because separate CodeCommit repositories per account do not create a sequential cross-account deployment mechanism — they just fragment source control and still require a pipeline to orchestrate. Option B is wrong because AWS CLI scripts with cross-region replication address data movement, not multi-account pipeline orchestration, and they bypass CodePipeline's stage/approval model. Option D is wrong because a single pipeline with all stages in one account cannot deploy into other accounts without cross-account roles, and it violates the isolation the question requires.

92
MCQhard

An organization uses AWS Systems Manager to manage a fleet of EC2 instances. The SysOps administrator needs to run a script on all instances that have a specific tag (Environment: Production). The script must be executed immediately and only once. Which approach should be used?

A.Use Patch Manager to apply the script as a patch baseline.
B.Create an Automation document and execute it.
C.Use Run Command with a target based on the tag.
D.Create a State Manager association with the script.
AnswerC

Run Command's SendCommand API accepts a target that can be a tag key-value pair, like tag:Environment=Production, and every SSM agent that matches will execute the AWS-RunShellScript or AWS-RunPowerShellScript document immediately in a one-time, unmanaged fashion. This satisfies the requirement of running a script once across the fleet, with output optionally streamed to S3 or CloudWatch Logs for auditing. Because no association, schedule, or patch baseline is involved, it is the simplest and most direct SSM primitive for this task.

Why this answer

Run Command enables you to run commands on EC2 instances immediately and only once, using tags to target specific instances. Option A is incorrect because Patch Manager is designed for applying patches, not running arbitrary scripts. Option B is incorrect because Automation documents are for multi-step workflow orchestration, not simple one-time script execution.

Option D is incorrect because State Manager is for recurring configurations or ensuring a desired state over time, not immediate one-time execution.

93
MCQmedium

An administrator attempts to deploy an application using AWS CodeDeploy. The deployment fails with 'Access Denied' when trying to download the revision from the S3 bucket 'example-bucket'. The IAM policy attached to the instance profile is shown in the exhibit. What is the cause of the failure?

A.The policy does not include s3:ListBucket
B.The policy is missing the s3:GetObjectVersion action for the bucket
C.The policy grants s3:ListBucket but not s3:GetObject
D.The policy is attached to the wrong IAM role
AnswerB

When you enable S3 Versioning, every object version has a unique versionId, and a GetObject request that specifies that version requires an explicit s3:GetObjectVersion permission in addition to s3:GetObject. The deployment workflow is calling GetObject with a versionId to fetch a unique revision, and the policy only grants the standard object-level actions. Without s3:GetObjectVersion, AWS rejects the request with AccessDenied, making this the exact root cause.

Why this answer

The deployment fails with 'Access Denied' when trying to download the revision from S3. The IAM policy attached to the instance profile must allow the s3:GetObject action to download objects. However, if the deployment uses a specific version of the revision (e.g., when using CodeDeploy with S3 versioning), the s3:GetObjectVersion action is also required.

The exhibit shows the policy includes s3:GetObject but not s3:GetObjectVersion, causing the failure. Option B is correct because the missing s3:GetObjectVersion action is the cause. Option A is incorrect because s3:ListBucket is present in the policy.

Option C is incorrect because the policy does include s3:GetObject. Option D is incorrect because the policy is attached to the correct instance profile.

94
MCQhard

A company is using AWS Elastic Beanstalk to deploy a web application. The application uses a custom Amazon Machine Image (AMI) that must be updated periodically. The SysOps administrator creates a new AMI and updates the Elastic Beanstalk environment's configuration. However, new instances are still launched with the old AMI. What is the most likely cause?

A.The environment is configured to use a launch template, and the AMI was not updated in the launch template.
B.The environment is using an immutable update policy.
C.The environment's platform version is pinned to an older version.
D.The old AMI was not deregistered.
AnswerA

When an Elastic Beanstalk environment uses a custom AMI through a launch template, the template holds the exact AMI ID. Updating the source AMI or rebuilding the environment does not change that ID. You must explicitly edit the launch template's ImageId (or use a new launch template version) and then rebuild, otherwise EC2 instances continue to launch with the original AMI. This is the direct cause of the environment still running the old configuration.

Why this answer

When an Elastic Beanstalk environment is configured to use a launch template, the AMI ID is specified in the launch template, not in the environment's configuration. Updating the environment configuration alone does not change the launch template, so new instances continue to use the old AMI. The administrator must update the launch template with the new AMI ID.

Exam trap

SOA-C02 often tests the misconception that updating the environment configuration automatically updates all underlying resources; candidates forget that launch templates are separate entities that must be explicitly updated.

How to eliminate wrong answers

Option B is wrong because an immutable update policy performs a rolling update with new instances and would actually pick up the new AMI if the configuration were correctly updated; it does not cause instances to launch with the old AMI. Option C is wrong because platform version pinning affects the runtime and infrastructure software versions, not the custom AMI ID used for instances. Option D is wrong because deregistering the old AMI is not required to launch new instances with a new AMI; in fact, leaving the old AMI registered does not force its use.

95
MCQeasy

A company uses AWS CodeDeploy to automate deployments to an Auto Scaling group. The deployment fails with the error 'The overall deployment failed because too many individual instances failed deployment'. The logs on a failed instance show that the 'BeforeInstall' lifecycle event script exited with a non-zero exit code. What is the MOST likely cause?

A.The BeforeInstall script has a bug that causes it to exit with a non-zero exit code.
B.The instance does not have the required permissions to download the application revision.
C.The instance is not healthy according to the Elastic Load Balancer health checks.
D.The CodeDeploy agent is not running on the instance.
AnswerA

The BeforeInstall hook is a lifecycle event in a CodeDeploy deployment. If the script exits with any non-zero exit code, CodeDeploy treats that as an unrecoverable failure and immediately stops the deployment, marking the instance as failed. A bug such as a missing command, a syntax error, or a failed dependency check would produce exactly this behavior, and the agent log would show the script's error output.

Why this answer

The error message indicates that the deployment failed because too many instances failed, and the logs on a failed instance show that the 'BeforeInstall' lifecycle event script exited with a non-zero exit code. In AWS CodeDeploy, each lifecycle event script must exit with a zero exit code to indicate success; any non-zero exit code is treated as a failure, causing the deployment to fail on that instance. Since the logs explicitly point to the BeforeInstall script's non-zero exit, the most likely cause is a bug in that script.

Exam trap

The trap here is that candidates may confuse the cause of a deployment failure with external factors like permissions or health checks, but the logs explicitly point to the BeforeInstall script's non-zero exit code, making a script bug the direct and most likely cause.

How to eliminate wrong answers

Option B is wrong because if the instance lacked permissions to download the application revision, the error would typically occur during the 'DownloadBundle' lifecycle event, not during 'BeforeInstall', and the logs would show a permission-related error. Option C is wrong because Elastic Load Balancer health checks are used for traffic routing and instance health monitoring, but they do not directly cause a CodeDeploy lifecycle event script to exit with a non-zero code; a failed health check would result in the instance being deregistered, not a script exit code error. Option D is wrong because if the CodeDeploy agent were not running, the instance would not execute any lifecycle events at all, and the logs would not show a BeforeInstall script exit code; instead, the deployment would likely show a 'pending' or 'failed' status with an agent connectivity error.

96
MCQeasy

A DevOps engineer wants to automate the creation of an Amazon EC2 instance with a specific security group and IAM role. Which AWS service should be used to define the infrastructure as code?

A.AWS Elastic Beanstalk
B.AWS CodeDeploy
C.AWS CloudFormation
D.AWS OpsWorks
AnswerC

CloudFormation is the native AWS infrastructure-as-code service: you define resources in a JSON or YAML template, and the service provisions, updates, and deletes them as a stack with order-aware dependencies and automatic rollback on failures. It supports almost every AWS resource and allows drift detection to compare actual configuration to template state. This exactly matches the goal of automating creation of Amazon infrastructure.

Why this answer

AWS CloudFormation is the infrastructure-as-code (IaC) service that allows you to define AWS resources such as EC2 instances, security groups, and IAM roles in declarative JSON or YAML templates. It automates provisioning and management of the entire stack, ensuring consistent and repeatable deployments. This directly matches the requirement to define infrastructure as code.

Exam trap

SOA-C02 often tests the distinction between IaC services and deployment/configuration services, so candidates must recognize that CloudFormation is the declarative IaC tool, while CodeDeploy, Elastic Beanstalk, and OpsWorks serve different purposes.

How to eliminate wrong answers

Option A is wrong because AWS Elastic Beanstalk is a PaaS service that abstracts infrastructure for deploying applications, but it does not provide declarative IaC templates for defining arbitrary resources like security groups and IAM roles. Option B is wrong because AWS CodeDeploy is a deployment service for automating application deployments to EC2, Lambda, or on-premises servers, not for defining infrastructure. Option D is wrong because AWS OpsWorks is a configuration management service using Chef and Puppet, which manages server configuration but is not the primary IaC service for defining AWS resources declaratively.

97
MCQmedium

A company uses AWS CodePipeline to deploy a web application. The pipeline includes a stage that runs a database migration script. The SysOps administrator wants to ensure that if the migration script fails, the entire pipeline stops and the previous version of the application remains deployed. Which pipeline stage configuration should be used to achieve this behavior?

A.Use a parallel action group for the migration step so other steps continue.
B.Configure the migration step as a sequential action and set the OnFailure to ABORT.
C.Configure the migration step as a sequential action and set the OnFailure to ROLLBACK.
D.Use a manual approval step after the migration to verify success.
AnswerB

Configuring the migration step as a sequential action with OnFailure set to ABORT causes CodePipeline to immediately stop the pipeline execution when that action fails, without running any subsequent actions or stages. The existing deployment remains untouched because no further deployment stages are triggered after the failure. This matches the requirement precisely: the pipeline halts and the prior version stays in place.

Why this answer

Setting the migration step as a sequential action with OnFailure set to ABORT ensures that if the migration script fails, the pipeline immediately stops and does not proceed to any subsequent stages. This prevents the deployment of a new application version that depends on a failed database migration, thereby keeping the previous version deployed.

Exam trap

The trap here is that candidates confuse the OnFailure ROLLBACK option with a full infrastructure rollback (like AWS CloudFormation stack rollback), not realizing that CodePipeline's ROLLBACK only affects the pipeline execution state and does not automatically revert the deployed application or database changes.

How to eliminate wrong answers

Option A is wrong because using a parallel action group would allow other steps to continue even if the migration fails, which contradicts the requirement to stop the entire pipeline and preserve the previous deployment. Option C is wrong because setting OnFailure to ROLLBACK would attempt to revert the pipeline to a previous state, but CodePipeline does not natively support automatic rollback of deployed application versions; ROLLBACK only retries the failed action or transitions to a failed state without restoring the prior application version. Option D is wrong because a manual approval step after the migration only adds a gate to verify success but does not automatically stop the pipeline or prevent deployment if the migration fails; it relies on human intervention and does not enforce the required behavior.

98
MCQeasy

A SysOps administrator uses AWS CloudFormation to deploy infrastructure. The administrator needs to store and reference sensitive data such as database passwords in the stack without hardcoding them in the template. Which CloudFormation feature should be used?

A.Use AWS Systems Manager Parameter Store secure strings and dynamic references in the CloudFormation template
B.Use AWS Secrets Manager and reference the secret using a static reference in the template
C.Define plaintext parameters in the template and mark them as NoEcho
D.Store the secrets in an encrypted S3 object and reference it via a URL in the template
AnswerA

CloudFormation dynamic references (e.g., {{resolve:ssm-secure:MyParameter}}) resolve secure string parameter values from Systems Manager Parameter Store during stack create and update operations, so the plaintext secret never appears in the template itself. The secure string is encrypted with a customer-managed or AWS-managed KMS key, and CloudFormation retrieves the decrypted value only at stack operation time, which prevents secrets from being exposed in template files, repository history, or AWS CloudTrail logs.

Why this answer

AWS CloudFormation supports dynamic references (using the `resolve:ssm` or `resolve:ssm-secure` syntax) that allow you to reference Systems Manager Parameter Store secure strings directly in the template. This keeps sensitive data like database passwords out of the template and the stack's metadata, ensuring they are not exposed in plaintext during stack operations or in the console.

Exam trap

The trap here is that candidates confuse `NoEcho` (which only hides display output) with actual secure storage, or they assume static references work with Secrets Manager when only dynamic references are supported for both Parameter Store secure strings and Secrets Manager secrets.

How to eliminate wrong answers

Option B is wrong because AWS Secrets Manager secrets cannot be referenced using a static reference in CloudFormation; they require a dynamic reference (e.g., `resolve:secretsmanager:secret-id:secret-string:json-key:version-stage:version-id`) to retrieve the secret value at deploy time, not a static reference. Option C is wrong because marking a parameter as `NoEcho` only hides its value in console output and logs, but the plaintext value is still passed to the CloudFormation template and can be exposed in the stack's metadata or API responses; it does not provide encryption or secure storage. Option D is wrong because storing secrets in an encrypted S3 object and referencing it via a URL in the template requires the S3 object to be publicly accessible or the template to include IAM permissions to read it, and the URL itself could be exposed in the template or stack metadata, defeating the purpose of secure handling.

99
MCQmedium

A security policy prohibits opening SSH port 22 on any EC2 instance. The operations team needs to run a shell script on 150 Linux instances to collect configuration inventory data. The script output must be captured for review. How should the team execute the script?

A.Use SSM Run Command with the AWS-RunShellScript document targeting all 150 instances; send output to an S3 bucket
B.Create a bastion host with SSH access and use a for loop to SSH into each instance and run the script
C.Use EC2 Instance Connect to establish a temporary SSH session for each instance and run the script
D.Terminate all instances and re-launch them from a new AMI that includes the configuration inventory already baked in
AnswerA

Run Command invocations use the SSM Agent's existing outbound HTTPS connection (port 443) — no inbound rule changes are needed. The command output for each instance is stored separately in S3, allowing the team to review per-instance results. Commands can target instances by tag (e.g., Environment=production) to avoid listing all 150 instance IDs manually.

Why this answer

SSM Run Command with the AWS-RunShellScript document allows you to execute shell scripts on multiple EC2 instances without opening SSH port 22, as it operates over the AWS Systems Manager agent (SSM Agent) using HTTPS (port 443). The output can be directed to an S3 bucket for centralized review, satisfying both the security policy and the requirement to capture script output.

Exam trap

The trap here is that candidates may assume EC2 Instance Connect or a bastion host are acceptable workarounds, but both still rely on SSH (port 22), which is explicitly prohibited by the security policy, whereas SSM Run Command operates over HTTPS and fully complies.

How to eliminate wrong answers

Option B is wrong because it requires opening SSH port 22 on the instances or the bastion host, which directly violates the security policy prohibiting SSH access. Option C is wrong because EC2 Instance Connect still relies on SSH (port 22) to establish a temporary session, which is also prohibited by the policy. Option D is wrong because terminating and re-launching instances from a new AMI is an overly destructive and inefficient approach that does not capture runtime configuration inventory data from the existing instances.

100
MCQhard

A SysOps administrator uses AWS CloudFormation to deploy infrastructure. The admin has a template that creates an EC2 instance with a custom software stack. The software stack must be installed and configured using PowerShell scripts. The admin wants to minimize operational overhead by automating the creation of an AMI that includes the software stack, and the AMI should be rebuilt on a weekly basis to include the latest security patches. Which combination of AWS services should be used?

A.Use EC2 Image Builder to define a component with the PowerShell scripts, create a recipe, and schedule a pipeline to run weekly.
B.Use AWS Systems Manager Automation to run a PowerShell script on an existing EC2 instance, then manually create an AMI each week.
C.Use AWS CodePipeline with CodeBuild to run the PowerShell scripts and create an AMI using the AWS CLI, triggered by a weekly CloudWatch Events schedule.
D.Use Amazon EC2 Auto Scaling with a lifecycle hook to run the PowerShell script on instance launch, and schedule a weekly instance refresh.
AnswerA

EC2 Image Builder is the purpose-built AWS service for producing golden AMIs. A component encapsulates the PowerShell script logic, a recipe bundles that component with a base image and OS settings, and a pipeline can be scheduled to run weekly to automatically build, validate, and register the AMI. It also supports post-build testing and cross-account/region distribution, giving a fully managed, auditable image lifecycle with minimal operational overhead.

Why this answer

EC2 Image Builder is purpose-built for automating the creation, patching, and testing of custom AMIs. By defining a component that encapsulates the PowerShell scripts, creating a recipe that references that component, and scheduling a pipeline to run weekly, the administrator achieves fully automated, repeatable AMI builds with minimal operational overhead. This directly meets the requirement for weekly rebuilds with the latest security patches.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing a multi-service orchestration (like CodePipeline + CodeBuild) when a single, purpose-built service (EC2 Image Builder) is designed exactly for this use case, leading to unnecessary complexity and operational overhead.

How to eliminate wrong answers

Option B is wrong because it requires manual intervention each week to create the AMI, which contradicts the goal of minimizing operational overhead and does not provide automation. Option C is wrong because while CodePipeline and CodeBuild can automate AMI creation, they are not the simplest or most purpose-built solution for this task; EC2 Image Builder is specifically designed for image lifecycle management, reducing complexity and maintenance. Option D is wrong because EC2 Auto Scaling with lifecycle hooks and instance refresh is designed for managing running instances and fleet updates, not for building and maintaining a golden AMI; it does not provide a mechanism to create a new AMI on a weekly schedule.

101
MCQeasy

A SysOps administrator needs to automate the creation of an Amazon S3 bucket with versioning enabled and default encryption using AWS CloudFormation. Which CloudFormation resource type should the administrator use?

A.AWS::S3::Bucket
B.AWS::S3::BucketPolicy
C.AWS::KMS::Key
D.AWS::S3::BucketVersioning
AnswerA

AWS::S3::Bucket is the CloudFormation resource type that directly provisions an S3 bucket as part of a stack. It supports configuration properties such as BucketName, VersioningConfiguration, AccessControl, and Encryption, allowing the bucket to be created with the desired settings. When included in a template, CloudFormation handles the full lifecycle of the bucket, including creation, updates, and deletion on stack removal.

Why this answer

AWS::S3::Bucket is the CloudFormation resource type used to create an S3 bucket, and it supports properties such as VersioningConfiguration and BucketEncryption directly within the resource definition. This allows the administrator to enable versioning and default encryption in a single resource declaration.

Exam trap

SOA-C02 often tests whether candidates know that versioning and encryption are properties of AWS::S3::Bucket, not separate resource types — the fictitious AWS::S3::BucketVersioning is a classic distractor.

How to eliminate wrong answers

Option B is wrong because AWS::S3::BucketPolicy only attaches a bucket policy (access control) and cannot create a bucket or configure versioning/encryption. Option C is wrong because AWS::KMS::Key creates a KMS key, which may be referenced by the bucket's encryption configuration but does not create or configure the bucket itself. Option D is wrong because AWS::S3::BucketVersioning is not a valid CloudFormation resource type — versioning is configured as a property (VersioningConfiguration) of AWS::S3::Bucket, not a standalone resource.

102
MCQmedium

A SysOps administrator is creating a CloudFormation stack and receives the error shown in the exhibit. The template snippet for the Auto Scaling group is: "MyAutoScalingGroup": { "Type": "AWS::AutoScaling::AutoScalingGroup", "Properties": { "MinSize": "1", "MaxSize": "5", "DesiredCapacity": "2", ... } }

A.The DesiredCapacity value must be less than MinSize.
B.The MinSize value exceeds the MaxSize value.
C.The Auto Scaling group must have a scaling policy.
D.The MinSize value must be specified as an integer, not a string.
AnswerD

CloudFormation enforces strict type validation for resource properties, and the MinSize attribute for AWS::AutoScaling::AutoScalingGroup is defined as an integer. When a value like "1" is passed as a quoted string, CloudFormation rejects the template because it does not match the expected Integer type. The fix is to remove the quotes or use the intrinsic function with a proper numeric value in the template.

Why this answer

The `MinSize`, `MaxSize`, and `DesiredCapacity` properties in an `AWS::AutoScaling::AutoScalingGroup` resource must be specified as integer values, not strings. In the provided template snippet, `"1"` is a string literal, which causes CloudFormation to fail validation because it expects a numeric type (e.g., `1` without quotes).

Exam trap

The trap here is that candidates often focus on logical constraints like MinSize vs MaxSize or DesiredCapacity ranges, overlooking the subtle but critical data type mismatch between a string and an integer in the template syntax.

How to eliminate wrong answers

Option A is wrong because `DesiredCapacity` must be between `MinSize` and `MaxSize` inclusive, not less than `MinSize`; a value less than `MinSize` would be invalid. Option B is wrong because `MinSize` (1) does not exceed `MaxSize` (5); the error is unrelated to this comparison. Option C is wrong because an Auto Scaling group does not require a scaling policy to be created; it can operate with only the `MinSize`, `MaxSize`, and `DesiredCapacity` values.

103
MCQeasy

A SysOps administrator needs to automatically deploy a new version of an application to a fleet of Amazon EC2 instances every time changes are pushed to the main branch of a code repository hosted on AWS CodeCommit. Which combination of AWS services should be used?

A.AWS CodePipeline, AWS CodeBuild, and AWS CodeDeploy.
B.AWS CloudFormation and AWS CodeDeploy.
C.Amazon EventBridge and AWS Systems Manager.
D.AWS CloudTrail and AWS Lambda.
AnswerA

AWS CodePipeline, AWS CodeBuild, and AWS CodeDeploy form a fully managed CI/CD service chain: CodePipeline is the orchestrator that automatically starts on a new CodeCommit push, CodeBuild compiles and packages the application into an artifact, and CodeDeploy deploys that artifact to compute services such as EC2 or Lambda. This trio natively supports stage progression, artifact handoff, rollback alarms, and permission transitions without custom code, making it the only choice that delivers end-to-end automated deployment from a repository event.

Why this answer

AWS CodePipeline orchestrates the continuous delivery workflow by detecting changes in the CodeCommit repository, then automatically triggering AWS CodeBuild to compile and package the application, and finally deploying the new version to EC2 instances using AWS CodeDeploy. This combination provides a fully managed, end-to-end CI/CD pipeline that meets the requirement of deploying on every push to the main branch.

Exam trap

The trap here is that candidates often confuse AWS CloudFormation (infrastructure provisioning) with CI/CD pipeline services, or assume EventBridge and Lambda can replace the full pipeline, but they lack built-in artifact management, deployment strategies, and rollback capabilities that CodePipeline, CodeBuild, and CodeDeploy provide together.

How to eliminate wrong answers

Option B is wrong because AWS CloudFormation is an infrastructure-as-code service for provisioning resources, not a CI/CD pipeline orchestrator; it cannot automatically detect CodeCommit pushes or trigger deployments without an external event source. Option C is wrong because Amazon EventBridge can capture CodeCommit events but AWS Systems Manager is primarily for operational management and patching, not for orchestrating a multi-stage build-and-deploy pipeline with artifact management. Option D is wrong because AWS CloudTrail records API activity for auditing, not for triggering deployments, and AWS Lambda alone cannot manage the full build, test, and deployment lifecycle required for application updates.

104
MCQmedium

A company is using AWS Elastic Beanstalk to deploy a web application. The application experiences high traffic during peak hours. The SysOps administrator wants to automatically scale the environment based on CPU utilization. Which configuration change is required?

A.Manually add EC2 instances to the Auto Scaling group.
B.Configure a scaling trigger based on a CloudWatch alarm for CPU utilization.
C.Modify the instance type to a larger size.
D.Increase the number of load balancers.
AnswerB

This is the correct approach because Elastic Beanstalk's Auto Scaling group uses CloudWatch alarms to drive scaling actions based on the average CPU utilization of the EC2 instances in the environment. You can define a scaling trigger—either a simple/step scaling policy tied to a CloudWatch alarm or a target tracking policy that continuously adjusts capacity to keep CPU near a target value. When the alarm enters an ALARM state (e.g., CPU exceeds 70% for 5 minutes), the policy proactively launches additional instances, and when it returns to OK, it terminates excess instances, providing dynamic, workload-aware scaling.

Why this answer

AWS Elastic Beanstalk integrates with Amazon CloudWatch and Auto Scaling to allow you to define a scaling trigger based on a CloudWatch alarm for CPU utilization. When the alarm threshold is breached, the Auto Scaling group automatically adds or removes EC2 instances, enabling the environment to handle high traffic during peak hours without manual intervention.

Exam trap

The trap here is that candidates often confuse vertical scaling (changing instance size) with horizontal scaling (adding/removing instances), or they assume manual actions like adding instances or load balancers are valid automation strategies for Elastic Beanstalk environments.

How to eliminate wrong answers

Option A is wrong because manually adding EC2 instances to the Auto Scaling group defeats the purpose of automatic scaling and does not respond dynamically to CPU utilization changes. Option C is wrong because modifying the instance type to a larger size (vertical scaling) does not automatically scale the number of instances; it only increases the capacity of each instance, which is not a dynamic scaling solution for fluctuating traffic. Option D is wrong because increasing the number of load balancers does not directly scale compute capacity; it distributes traffic but does not add or remove EC2 instances based on CPU utilization.

105
MCQmedium

A company uses AWS Elastic Beanstalk for a Java application. The environment uses a custom platform. The SysOps administrator wants to update the environment's configuration to use a larger instance type to handle increased load. What is the correct way to perform this change with minimal downtime?

A.Use the Elastic Beanstalk console to update the instance type and choose a rolling update strategy.
B.SSH into each instance and modify the instance type manually.
C.Terminate all instances and launch new ones with the larger instance type.
D.Create a new environment with the larger instance type and swap the environment URLs.
AnswerA

The Elastic Beanstalk console provides a supported, declarative way to change the environment's instance type. When updated, Elastic Beanstalk modifies the Auto Scaling launch configuration and then applies a rolling update strategy, progressively replacing instances so that at least the minimum capacity stays available. This preserves all environment-level settings and can be done with minimal or zero downtime, making it the correct approach.

Why this answer

Elastic Beanstalk allows you to update the environment's configuration, such as instance type, via the console or CLI. To minimize downtime, you can choose a rolling update strategy, which updates instances in batches, ensuring that the environment remains available throughout the process. Option B is incorrect because manually SSHing into instances is not a scalable or persistent solution; Elastic Beanstalk manages the instances and changes may not survive environment updates.

Option C is incorrect because terminating all instances causes complete downtime until the new instances are launched. Option D is incorrect because while creating a new environment and swapping URLs (blue/green deployment) can achieve zero downtime, it is more complex and resource-intensive than necessary for a simple instance type change, and the question asks for minimal downtime with correct method.

106
MCQeasy

A SysOps administrator is provisioning an Auto Scaling group (ASG) for a stateless web application. The ASG should launch EC2 instances in multiple Availability Zones. The administrator needs to ensure that instances are evenly distributed across Availability Zones. Which configuration should the administrator use?

A.Use an 'availability-zone' health check type in the Auto Scaling group.
B.Create subnets in multiple Availability Zones and specify them in the Auto Scaling group.
C.Create the Auto Scaling group with a single subnet in one Availability Zone.
D.Create subnets in multiple Availability Zones but assign them to the same placement group.
AnswerB

By creating subnets in multiple Availability Zones and then referencing those all subnets in the Auto Scaling group's network configuration, you enable the group to automatically distribute instances across all the specified AZs. This is the canonical method for achieving high availability, as the Auto Scaling group will balance instances among the AZs and, if one AZ becomes unhealthy or has insufficient capacity, it can launch replacement instances in the other AZs. Without this multi-subnet specification, the group cannot spread itself across AZs, because it can only launch instances into the subnets explicitly provided.

Why this answer

By creating subnets in multiple Availability Zones and specifying them in the Auto Scaling group configuration, the ASG will automatically distribute instances evenly across the subnets, ensuring high availability. Option A is incorrect because the 'availability-zone' health check type determines how to check instance health, not the distribution of instances. Option C is incorrect because using a single subnet limits instances to one Availability Zone, failing the requirement for multi-AZ distribution.

Option D is incorrect because placement groups are used for low-latency network performance, not for even distribution across AZs.

107
MCQeasy

A company runs 200 EC2 Linux instances across three accounts. The security team requires that critical OS patches are applied automatically every Sunday at 2 AM UTC. Currently patches are applied manually and inconsistently. What is the recommended AWS-native solution?

A.Configure a Patch Manager patch baseline and maintenance window scheduled for Sunday 02:00 UTC; associate the Run Patch Baseline task with all EC2 instance targets
B.Create a cron job on each instance that runs 'yum update -y' every Sunday at 2 AM
C.Use AWS Config managed rules to detect unpatched instances and send SNS notifications for manual remediation
D.Build a CodePipeline that runs weekly, creates new AMIs with the latest patches, and replaces all instances via an Auto Scaling instance refresh
AnswerA

The patch baseline filters patch approvals by severity (e.g., CRITICAL, IMPORTANT). The maintenance window triggers the AWS-RunPatchBaseline SSM document on schedule. All 200 instances receive the same baseline and schedule, replacing manual inconsistency with automated consistency. Patch compliance is recorded in the Patch Manager compliance dashboard.

Why this answer

AWS Systems Manager Patch Manager, combined with a Maintenance Window, provides a fully AWS-native, automated solution for patching EC2 instances on a schedule. The Patch Manager service uses a patch baseline to define which patches are approved (e.g., critical OS patches), and the Maintenance Window triggers the 'AWS-RunPatchBaseline' SSM document at the specified time (Sunday 02:00 UTC) against all targeted instances. This eliminates manual effort and ensures consistent, auditable patching across multiple accounts and instances.

Exam trap

The trap here is that candidates may choose Option D (AMI refresh) because it seems more 'complete' for patching, but they overlook that Patch Manager with Maintenance Windows is the simplest, most direct AWS-native solution for scheduled patching, and the question explicitly asks for the 'recommended' solution, not the most elaborate one.

How to eliminate wrong answers

Option B is wrong because it requires manual creation and maintenance of cron jobs on each instance, which is not a centralized, AWS-native solution and does not scale across 200 instances and three accounts; it also lacks auditing and compliance tracking. Option C is wrong because AWS Config rules can only detect unpatched instances and send notifications, but they do not automatically apply patches, leaving remediation to manual action, which fails the requirement for automatic application. Option D is wrong because while CodePipeline and AMI refresh can achieve patching, it is an overly complex, non-native approach that requires building and maintaining a pipeline, creating new AMIs, and performing instance refreshes, which is not the recommended AWS-native solution for simple scheduled patching.

108
MCQhard

An organization uses AWS CloudFormation to manage infrastructure. They have a stack that includes an Amazon RDS DB instance. The administrator wants to update the DB instance's allocated storage without downtime. The DB instance is currently using gp2 storage. Which action should the administrator take?

A.Create a read replica with the new storage size and promote it.
B.Modify the storage size in the CloudFormation template and update the stack.
C.Stop the DB instance, modify the storage, and start it.
D.Take a manual snapshot and restore it with the new storage size.
AnswerB

Updating the CloudFormation stack with a larger AllocatedStorage value invokes RDS's online storage scaling, so the disk can be expanded while the instance remains available. CloudFormation translates the template change into a ModifyDBInstance operation; with ApplyImmediately not set to true, the change is applied during the next scheduled maintenance window, avoiding an unplanned outage. This keeps the existing endpoint and replication topology intact and is the least disruptive, infrastructure-as-code-friendly approach.

Why this answer

Modifying the allocated storage size in the CloudFormation template and updating the stack triggers a storage modification on the RDS DB instance. For gp2 storage, increasing allocated storage does not require downtime; RDS performs the modification while the instance remains available. This approach aligns with the requirement to avoid downtime and leverages CloudFormation's infrastructure-as-code capabilities.

Exam trap

The trap here is that candidates assume any storage modification requires downtime or a manual snapshot/restore, but AWS RDS allows online storage scaling for gp2 volumes, making a direct CloudFormation update the correct zero-downtime approach.

How to eliminate wrong answers

Option A is wrong because creating a read replica with a new storage size and promoting it introduces a replica promotion process that can cause a brief outage during the promotion, and it does not directly modify the existing DB instance's storage without downtime. Option C is wrong because stopping the DB instance causes downtime, which contradicts the requirement for no downtime; RDS storage modifications for gp2 can be performed online without stopping the instance. Option D is wrong because taking a manual snapshot and restoring it with a new storage size results in downtime during the restore process, as the original instance remains unavailable until the restore completes.

109
MCQmedium

A SysOps administrator needs to deploy a new version of an application to an Auto Scaling group using a blue/green deployment strategy. The application runs on EC2 instances behind an Application Load Balancer. Which AWS service should be used to automate this deployment?

A.AWS Elastic Beanstalk
B.AWS CodeDeploy
C.AWS CodePipeline
D.AWS CloudFormation
AnswerB

AWS CodeDeploy is the dedicated application deployment service that performs in-place or blue/green deployments with configurable traffic routing (canary, linear, or all-at-once). When deploying to an EC2 Auto Scaling group, CodeDeploy creates a new auto-scaling group for the green fleet, installs the revision, and then shifts traffic via the attached load balancer. This gives the administrator fine-grained control over the rollout and rollback behavior.

Why this answer

AWS CodeDeploy is the service designed to automate application deployments, including blue/green deployments to EC2 Auto Scaling groups behind an Application Load Balancer. It supports the blue/green deployment type natively for EC2/on-premises compute, allowing traffic to shift from the original (blue) environment to a replacement (green) environment with configurable traffic rerouting and rollback. This directly matches the SysOps requirement.

Exam trap

SOA-C02 often tests the boundary between orchestration services (CodePipeline) and the actual deployment engine (CodeDeploy), causing candidates to pick CodePipeline because it 'automates deployments' when the question asks which service performs the blue/green mechanics.

How to eliminate wrong answers

Option A is wrong because Elastic Beanstalk is a PaaS that manages deployment for supported platforms, but it does not provide the granular blue/green orchestration with ALB traffic shifting that CodeDeploy offers for arbitrary EC2 Auto Scaling groups. Option C is wrong because CodePipeline is a CI/CD orchestration service that coordinates build and deploy stages — it invokes CodeDeploy or other deploy providers but does not itself perform the blue/green deployment mechanics. Option D is wrong because CloudFormation is an infrastructure-as-code provisioning service; while it can create resources, it is not the deployment automation engine for blue/green traffic shifting.

110
MCQeasy

A SysOps administrator is deploying a new application using AWS CloudFormation. The template includes an EC2 instance with a UserData script that installs software from a private S3 bucket. What is the BEST way to ensure the EC2 instance can access the S3 bucket without storing long-term credentials on the instance?

A.Create an IAM user with S3 access and attach the access key to the instance profile.
B.Store the access key ID and secret access key in the UserData script.
C.Create an IAM role with S3 access and associate it with the instance profile.
D.Configure a security group rule that allows the instance to reach S3 via VPC endpoint.
AnswerC

An IAM role with S3 access is the correct and secure way to grant an EC2 instance permissions. When you attach the role to an instance profile and associate it with the instance, EC2 automatically retrieves temporary credentials from the instance metadata service (IMDSv2), which are rotated every few hours. The application can then make S3 API calls using the AWS SDK without ever managing static credentials. This leverages least privilege and eliminates the risk of exposed access keys.

Why this answer

Creating an IAM role with S3 access and associating it with the instance profile allows the EC2 instance to obtain temporary credentials automatically via the instance metadata service. This avoids storing long-term credentials on the instance, which is a security best practice.

Exam trap

SOA-C02 often tests the difference between IAM users and IAM roles for EC2. Candidates might choose to create an IAM user because it seems straightforward, but that involves long-term credentials, which the question explicitly wants to avoid.

How to eliminate wrong answers

Option A is wrong because creating an IAM user and attaching access keys to the instance profile is not how instance profiles work; instance profiles are for IAM roles, not users. Option B is wrong because storing access keys in UserData is insecure as they are visible in the console and metadata. Option D is wrong because a security group rule alone does not grant S3 access; it only controls network traffic, and S3 access requires IAM permissions.

111
MCQeasy

A company wants to deploy a new version of a web application to an Auto Scaling group of EC2 instances behind an Application Load Balancer. The deployment should be automated and must not cause downtime. Which AWS service should be used?

A.AWS CloudFormation
B.AWS OpsWorks
C.AWS Elastic Beanstalk
D.AWS CodeDeploy
AnswerD

AWS CodeDeploy is purpose-built for application deployment to EC2 instances, including those in an Auto Scaling group. It supports blue/green deployments with traffic shifting via an Application Load Balancer, allowing zero-downtime releases by registering new instances and shifting traffic gradually. Its integration with ASG lifecycle hooks ensures that new instances launched during scaling out automatically receive the latest application revision, making it the correct choice.

Why this answer

AWS CodeDeploy is designed to automate deployments to EC2 instances, including those in an Auto Scaling group, and supports blue/green deployments to avoid downtime. It integrates with ALB to shift traffic gradually. This makes it the correct choice for automated, zero-downtime deployments.

Exam trap

The trap is confusing infrastructure-as-code tools like CloudFormation with deployment tools; candidates might choose Elastic Beanstalk because it's a deployment service, but CodeDeploy is specifically designed for automated deployments to existing EC2/ASG setups.

How to eliminate wrong answers

Option A is wrong because AWS CloudFormation is for infrastructure provisioning, not application deployment automation. Option B is wrong because AWS OpsWorks is a configuration management service, not specifically for automated deployments with traffic shifting. Option C is wrong because AWS Elastic Beanstalk is a PaaS that simplifies deployment but may not provide the same level of control for blue/green deployments with an existing Auto Scaling group and ALB; CodeDeploy is more directly suited.

112
MCQmedium

An administrator uses AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment fails with an error: "The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available for deployment, or some instances in your deployment group are experiencing problems." The deployment group has a minimum of 2 instances. What should the administrator check first?

A.The application revision's compatibility with the instance operating system.
B.The Auto Scaling group's health check settings.
C.The deployment group's deployment configuration settings.
D.The deployment logs on the individual EC2 instances.
AnswerD

CodeDeploy's error is generic, so instance-level detail is decisive. The CodeDeploy agent writes lifecycle event logs to /opt/codedeploy-agent/deployment-root on each EC2 instance, revealing the actual failure (hook script, permissions, or missing dependencies) behind the aggregate deployment-group message.

Why this answer

The error message indicates that too many individual instances failed deployment. The first step is to check the deployment logs on the individual EC2 instances to identify the specific failure reason, such as script errors, missing dependencies, or permissions issues. This provides the most direct insight into why instances are failing.

Exam trap

SOA-C02 often tests the tendency to jump to configuration settings, but the error message points to instance-level failures, so logs are the first check.

How to eliminate wrong answers

Option A is wrong because while OS compatibility could be a factor, it is not the first thing to check; logs will reveal if that is the issue. Option B is wrong because Auto Scaling health check settings affect instance replacement, not the deployment failure itself. Option C is wrong because deployment configuration settings control the rate of deployment and healthy instance thresholds, but the error already indicates too many instances failed, so the configuration is likely not the root cause.

113
MCQeasy

An organization wants to automate the creation of AWS resources using AWS CloudFormation. They need to ensure that certain resources, such as an Amazon S3 bucket, are not accidentally deleted when the stack is deleted. Which CloudFormation feature should they use?

A.DeletionPolicy attribute with value 'Retain'
B.DeletionPolicy attribute with value 'Protect'
C.DeletionPolicy attribute with value 'Delete'
D.Stack policy
AnswerA

The DeletionPolicy attribute with value Retain is the correct CloudFormation resource-level setting to preserve an S3 bucket when its stack is deleted. It instructs CloudFormation to skip deleting the underlying resource, so the bucket and all objects remain in the AWS account as an orphaned resource. This is designed exactly for the use case of retaining stateful data such as S3 buckets or DynamoDB tables after infrastructure teardown.

Why this answer

The DeletionPolicy attribute with value 'Retain' instructs AWS CloudFormation to preserve a resource when its stack is deleted. This is the correct feature to prevent accidental deletion of critical resources like an S3 bucket, as the bucket and its contents will remain in the account even after the stack is removed.

Exam trap

The trap here is that candidates confuse the DeletionPolicy attribute with a stack policy or incorrectly assume 'Protect' is a valid value, when in fact only 'Delete', 'Retain', and 'Snapshot' are permitted.

How to eliminate wrong answers

Option B is wrong because 'Protect' is not a valid value for the DeletionPolicy attribute; valid values are 'Delete', 'Retain', and 'Snapshot'. Option C is wrong because 'Delete' is the default behavior that deletes the resource when the stack is deleted, which is the opposite of what the organization wants. Option D is wrong because a stack policy controls updates to stack resources, not deletion behavior during stack deletion.

114
MCQmedium

A company uses AWS CloudFormation to manage infrastructure. The SysOps administrator needs to update a stack that contains a critical database. The update may require a replacement of the database resource. The administrator wants to review the changes before they are applied. What is the BEST way to achieve this?

A.Use the AWS CloudFormation update-stack command with the --no-fail-on-empty-changeset flag.
B.Apply a stack policy that prevents replacement of the database resource.
C.Use the AWS CloudFormation create-change-set command and then review the changes before executing.
D.Use the AWS CloudFormation detect-stack-drift command to check for differences.
AnswerC

The create-change-set command constructs a change set that describes the modifications CloudFormation would make to the stack if the updated template were applied, without actually changing any resources. You can then use describe-change-set or the CloudFormation console to review every resource action (Add, Modify, Remove) including property details and whether a replacement will occur, before you decide to call execute-change-set. This two-phase approach is specifically designed to give you a safe, non-destructive preview of the update, which is exactly what the question requires.

Why this answer

Creating a change set allows you to review all changes, including replacements, before executing them. Option A is incorrect because the '--no-fail-on-empty-changeset' flag does not provide a review. Option B is incorrect because a stack policy can protect resources but does not allow reviewing changes.

Option D is incorrect because the drift detection feature detects drift, not planned changes.

115
MCQhard

A company has a multi-account AWS environment using AWS Organizations. The SysOps Administrator needs to deploy a standardized set of baseline resources (VPC, subnets, security groups, and an S3 bucket for logs) into each new member account as soon as the account is created. The administrator wants to automate this process using AWS CloudFormation and ensure that the baseline resources are deployed without manual intervention. The organization uses AWS CloudTrail and AWS Config for governance. What solution should the administrator implement?

A.Use AWS CloudFormation StackSets with automatic deployment to accounts in the organization.
B.Create an AWS Config rule that triggers an AWS Lambda function to deploy the baseline resources when a new account is created.
C.Store the CloudFormation template in Amazon S3 and use S3 event notifications to trigger a Lambda function that deploys the stack into the new account.
D.Use AWS Service Catalog to create a portfolio with the baseline products and grant access to the organization.
AnswerA

AWS CloudFormation StackSets with automatic deployment is the native, service-integrated method for account baselining. When a new account is added to an AWS Organization, StackSets with service-managed permissions automatically creates stack instances in that account, using the organization's trusted access to deploy the baseline template. This eliminates the need for custom event-driven orchestration and ensures consistent governance across the entire organization.

Why this answer

AWS CloudFormation StackSets with automatic deployment is purpose-built for this scenario: it deploys a single template across multiple accounts in an AWS Organization and can automatically push the stack to new member accounts as they are added. The 'automatic deployment' setting enables StackSets to target the entire OU or organization, so new accounts inherit the baseline resources without manual intervention. This directly satisfies the requirement to deploy VPC, subnets, security groups, and an S3 log bucket into each new account automatically.

Exam trap

SOA-C02 often tests the difference between reactive compliance tools (AWS Config, Trusted Advisor) and proactive provisioning tools (StackSets, Service Catalog); candidates wrongly pick Config or Lambda-based automation when the question asks for automatic deployment to new accounts.

How to eliminate wrong answers

Option B is wrong because AWS Config rules are for evaluating resource compliance, not for provisioning resources; triggering a Lambda from a Config rule is a reactive, custom-coded workaround that does not natively handle new account creation events. Option C is wrong because S3 event notifications only fire on object-level events within a bucket and have no awareness of new AWS account creation, so the Lambda would never be triggered by account creation. Option D is wrong because AWS Service Catalog requires end users to manually launch products from a portfolio; it does not automatically deploy resources into newly created accounts.

116
MCQeasy

A company uses AWS OpsWorks for configuration management. The SysOps administrator needs to deploy a new application version to a stack. What is the recommended way to update the application on the instances?

A.Create a new CloudFormation stack to replace the OpsWorks stack.
B.Update the custom cookbook and run the 'deploy' recipe on the stack.
C.Use the OpsWorks built-in 'deploy' command on each instance.
D.SSH into each instance and manually update the application files.
AnswerB

Updating the custom cookbook source (e.g., S3, Git, or HTTP) on the OpsWorks stack and then running the 'deploy' lifecycle recipe is the correct and intended method for rolling out application changes. The deploy recipe triggers a stack-wide command that executes your custom Chef recipes on all online instances in the selected layer or stack, following the defined deployment lifecycle (before_deploy, deploy, after_deploy). This ensures all instances receive the same application update in a coordinated, automated fashion, and because OpsWorks uses Chef, the recipe can handle dependencies, configuration templates, and service restarts consistently across the fleet.

Why this answer

AWS OpsWorks uses recipes and custom cookbooks to manage application deployment. To deploy a new version, the SysOps administrator should update the custom cookbook with the new application code or configuration and then run the 'deploy' recipe on the stack. This triggers the deployment process on all instances automatically.

Option A is incorrect because creating a new CloudFormation stack is not the recommended approach for updating an existing OpsWorks stack; CloudFormation is a different service for infrastructure as code. Option C is incorrect because the OpsWorks built-in 'deploy' command is meant for straightforward deployments and may not support custom cookbooks or complex application logic. Option D is incorrect because manually SSH-ing into each instance is not scalable and defeats the purpose of automation.

117
MCQmedium

An organization uses AWS OpsWorks to manage a stack of application servers. The stack uses a custom cookbook that is stored in a private GitHub repository. When deploying new instances, the cookbook download fails. What should the administrator do to resolve this?

A.Upload the cookbook to Amazon S3 and reference the S3 URL
B.Make the GitHub repository public
C.Configure an SSH key in the OpsWorks stack to access the private repository
D.Store the GitHub credentials in the OpsWorks stack settings
AnswerC

Configuring an SSH key in the OpsWorks stack is the correct method because OpsWorks natively supports private Git repositories by letting you supply a private SSH key in the Repository SSH Key field for custom cookbooks. You add the matching public key as a deploy key on the GitHub repository with read-only access, and OpsWorks uses that key to authenticate when it downloads or updates cookbooks on your instances. This keeps the repository private and avoids storing plaintext credentials, while also allowing Chef to automatically pull the latest cookbook revisions during stack updates and instance setup.

Why this answer

AWS OpsWorks needs credentials to clone a cookbook from a private GitHub repository. The correct approach is to configure an SSH key (deploy key) in the OpsWorks stack settings so that the instance can authenticate to GitHub during the cookbook download. This allows OpsWorks to securely access the private repository without exposing credentials in the cookbook or making the repository public.

Exam trap

SOA-C02 often tests the misconception that storing credentials in stack settings or making repositories public is acceptable, when the correct and secure method is configuring an SSH deploy key.

How to eliminate wrong answers

Option A is wrong because uploading the cookbook to Amazon S3 changes the source repository and does not address the underlying authentication issue with private GitHub repositories; it also bypasses the intended workflow. Option B is wrong because making the repository public is a security risk and violates the principle of least privilege, and it is not a recommended solution for private code. Option D is wrong because storing GitHub credentials in OpsWorks stack settings is not the supported mechanism; OpsWorks expects an SSH key for private repository access, and storing plaintext credentials is insecure.

118
MCQmedium

A SysOps administrator is deploying a new version of an application using AWS CodeDeploy with an in-place deployment configuration. The deployment group consists of EC2 instances behind an Application Load Balancer. The administrator wants to ensure that traffic is gradually shifted to the new version. Which CodeDeploy feature should be used?

A.Use a canary deployment instead of in-place.
B.Define a BeforeInstall hook to deregister instances.
C.Use a linear deployment configuration.
D.Configure the load balancer deregistration delay and re-registration in the deployment group.
AnswerD

Configuring the deregistration delay on the load balancer target group and enabling CodeDeploy's load balancer integration ensures that CodeDeploy automatically deregisters each instance, waits for in-flight requests to complete (based on the deregistration delay), performs the deployment, and then re-registers the instance. This built-in integration is the recommended way to avoid downtime during in-place deployments. CodeDeploy also waits for the instance to pass health checks before marking the deployment successful. This configuration is set in the deployment group's load balancer section.

Why this answer

Configuring the load balancer deregistration delay and re-registration in the deployment group allows CodeDeploy to control how instances are gradually removed from and added back to the ALB target group. This enables a controlled traffic shift during an in-place deployment by waiting for in-flight requests to complete (via deregistration delay) before rerouting traffic to the new version, and then re-registering instances after the new application is healthy.

Exam trap

The trap here is that candidates often confuse the deployment configuration (e.g., linear, canary) with traffic shifting mechanics, not realizing that in-place deployments require explicit load balancer settings to gradually shift traffic, whereas blue/green deployments handle traffic shifting natively via the load balancer.

How to eliminate wrong answers

Option A is wrong because using a canary deployment would change the deployment type from in-place to blue/green, which is not what the question specifies; the requirement is to gradually shift traffic within an in-place deployment. Option B is wrong because defining a BeforeInstall hook to deregister instances is a manual, script-based approach that does not leverage CodeDeploy's built-in traffic shifting controls and can lead to race conditions or incomplete traffic draining. Option C is wrong because a linear deployment configuration controls the rate at which instances are updated (e.g., percentage per interval), but it does not inherently manage traffic shifting through the load balancer; traffic shifting requires explicit integration with the ALB's deregistration and re-registration settings.

119
MCQeasy

A SysOps administrator wants to deploy a serverless application using AWS Lambda functions, Amazon API Gateway, and Amazon DynamoDB. The deployment must be automated and repeatable. Which AWS service should the administrator use to define and manage this infrastructure as code?

A.AWS CodeDeploy
B.AWS OpsWorks
C.AWS Elastic Beanstalk
D.AWS CloudFormation with the AWS Serverless Application Model (SAM)
AnswerD

AWS CloudFormation with the AWS Serverless Application Model (SAM) is the definitive infrastructure-as-code approach for serverless applications. SAM is an open-source framework that extends CloudFormation with simplified syntax to define serverless resources like Lambda functions, API Gateway APIs, and DynamoDB tables in a template, then transforms them into full CloudFormation stacks. It also provides local testing via the SAM CLI, supports automatic IAM role generation, and enables deployment through CodeDeploy for safer Lambda traffic shifting, making it purpose-built for serverless. By using SAM, a SysOps administrator can version, review, and reliably replicate the entire serverless application in a repeatable, auditable way.

Why this answer

AWS CloudFormation with the AWS Serverless Application Model (SAM) is the correct choice for defining and managing serverless infrastructure as code, as SAM extends CloudFormation with shorthand syntax for Lambda, API Gateway, and DynamoDB. Option A is wrong because AWS CodeDeploy automates code deployment to running instances, not infrastructure provisioning. Option B is wrong because AWS OpsWorks manages Chef/Puppet-based application stacks.

Option C is wrong because AWS Elastic Beanstalk is designed for deploying web applications on EC2, not serverless architectures.

120
MCQhard

A company uses AWS OpsWorks to manage a stack of EC2 instances running a web application. They recently migrated to AWS Elastic Beanstalk for easier deployments. However, after the migration, some users report that the application is responding slowly during peak hours. The Elastic Beanstalk environment is configured with a load balancer and auto scaling based on average CPU utilization. What should the SysOps Administrator do to troubleshoot the performance issue?

A.Manually scale the environment to add more instances.
B.Revert to the OpsWorks stack configuration.
C.Review the CloudWatch metrics and logs for the Elastic Beanstalk environment.
D.Increase the instance size in the environment configuration.
AnswerC

CloudWatch metrics track CPU, memory, network, and request latency, while Elastic Beanstalk aggregates application and web server logs that can expose 5xx errors, stack traces, or slow queries. Reviewing these data sources together reveals whether the performance issue is due to a bottleneck, a recent deployment, or a resource limitation, allowing you to make a data-driven adjustment. This is the correct first step before any scaling action to ensure the actual root cause is addressed.

Why this answer

Reviewing CloudWatch metrics and logs from the Elastic Beanstalk environment can identify if the auto scaling policy is not aggressive enough or if there are other bottlenecks. Option A is wrong because manually scaling the environment is a reactive measure that does not help identify the root cause of the performance issue. Option B is wrong because reverting to the OpsWorks stack would be a step backward and does not address the current environment's performance problem.

Option D is wrong because increasing instance size without analysis may be inefficient and not resolve the underlying issue.

121
MCQeasy

A company uses AWS CloudFormation to deploy a stack that includes an Amazon S3 bucket. The stack creation fails because the S3 bucket name already exists. What should the administrator do to resolve this issue?

A.Add a tag to the existing bucket to make it available for the stack.
B.Change the S3 bucket name in the CloudFormation template to a unique name.
C.Delete the existing S3 bucket and recreate the stack.
D.Update the bucket policy to allow the stack to use the bucket.
AnswerB

Changing the S3 bucket name in the CloudFormation template to a unique name resolves the conflict because the CreateBucket API only needs a name that is not already taken globally. This is the correct approach because it allows CloudFormation to provision a brand-new bucket without naming collision. Alternatively, you could omit the BucketName property entirely so CloudFormation generates a unique name with a random suffix, but specifying a deliberate unique name works equally well.

Why this answer

S3 bucket names are globally unique across all AWS accounts and regions, so CloudFormation cannot create a bucket whose name is already taken by another account. The correct fix is to change the BucketName property in the template to a name that is not in use, then re-run the stack. This resolves the naming collision without touching resources owned by other accounts.

Exam trap

SOA-C02 often tests whether candidates remember that S3 bucket names are globally unique — the tempting wrong answer is to manipulate the existing bucket (tags, policy) rather than rename the one being created.

How to eliminate wrong answers

Option A is wrong because tags are metadata only — they have no bearing on S3's global namespace uniqueness and cannot 'release' a name for another account to use. Option C is wrong because deleting an existing bucket that belongs to another account is not possible (and would be destructive and inappropriate even if it were your own); it also does not address the template's hard-coded name. Option D is wrong because bucket policies control access to an existing bucket, not the ability to create a new bucket with the same name — the CreateBucket call fails before any policy is evaluated.

122
MCQhard

A company is using AWS CloudFormation to manage infrastructure. A recent stack update failed, and the SysOps administrator needs to roll back to the previous known good state. However, the stack is in UPDATE_ROLLBACK_FAILED state. What should the administrator do to recover the stack?

A.Use the ContinueUpdateRollback API or AWS Management Console to resume the rollback after addressing the failure cause
B.Delete the stack and recreate it from the previous template
C.Contact AWS Support to enable automatic rollback recovery
D.Execute another stack update with the same parameters to overwrite the failed state
AnswerA

When a stack update fails and the automatic rollback also fails, the stack enters the UPDATE_ROLLBACK_FAILED state. To recover, you must first resolve the underlying cause, such as an insufficient IAM permission or a resource that cannot be rolled back, then call the ContinueUpdateRollback API or use the AWS Management Console to resume the rollback. This action transitions the stack to UPDATE_ROLLBACK_COMPLETE, restoring it to its last known stable configuration.

Why this answer

When a CloudFormation stack enters UPDATE_ROLLBACK_FAILED, the rollback could not complete because a resource could not be returned to its previous state. The administrator must first fix the underlying resource issue (e.g., a deleted resource, a permission problem, or a resource that cannot be reverted), then invoke ContinueUpdateRollback via the console, CLI, or API to resume the rollback from where it stopped. This preserves the stack and its resources rather than destroying them.

Exam trap

SOA-C02 often tests UPDATE_ROLLBACK_FAILED by tempting candidates with 'delete and recreate' — the correct answer is always to fix the cause and use ContinueUpdateRollback, not to destroy the stack.

How to eliminate wrong answers

Option B is wrong because deleting the stack would destroy all resources and lose the stack's history and outputs — it is a destructive last resort, not the recovery procedure for UPDATE_ROLLBACK_FAILED. Option C is wrong because AWS Support does not enable automatic rollback recovery; the ContinueUpdateRollback action is a customer-controlled API. Option D is wrong because issuing another stack update while the stack is in UPDATE_ROLLBACK_FAILED is not permitted — CloudFormation rejects updates until the rollback is resolved, and even if it were allowed, it would not address the failed rollback state.

123
Multi-Selectmedium

A company is using AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment fails because the instances do not have the CodeDeploy agent installed. Which THREE actions are required to resolve this issue?

Select 3 answers
A.Install the CodeDeploy agent on the instances using user data in the launch configuration.
B.Create a new AMI that includes the CodeDeploy agent.
C.Use AWS Systems Manager Run Command to install the agent on existing instances.
D.Change the deployment configuration to 'OneAtATime'.
E.Update the Auto Scaling group's launch configuration to use a different instance type.
AnswersA, B, C

User data in the launch configuration runs at each instance boot, so newly launched Auto Scaling instances install the CodeDeploy agent automatically. This satisfies the requirement that instances joining the group have the agent present before CodeDeploy attempts deployment.

Why this answer

The CodeDeploy agent must be present on every instance that participates in a deployment, so the fix is to ensure it is installed on current and future instances. Option A is correct because adding the agent installation commands to the launch configuration's user data ensures that every new instance launched by the Auto Scaling group automatically installs the CodeDeploy agent at boot. Option B is correct because baking the CodeDeploy agent into a custom AMI and using that AMI in the launch configuration guarantees the agent is already present on all newly launched instances without relying on boot-time scripts.

Option C is correct because AWS Systems Manager Run Command can remotely execute the agent installation script on the already-running instances in the Auto Scaling group, fixing the instances that caused the current deployment to fail. Option D is incorrect because changing the deployment configuration to OneAtATime only alters how many instances are updated at a time; it does not install the missing CodeDeploy agent. Option E is incorrect because changing the instance type has no bearing on whether the CodeDeploy agent is installed and will not resolve the failure.

Exam trap

The trap here is that candidates may confuse deployment configuration settings (like 'OneAtATime') with the fundamental requirement of having the agent installed, or think that changing the instance type will somehow resolve the agent dependency.

124
MCQmedium

A SysOps administrator is updating an AWS CloudFormation stack that contains an Amazon RDS DB instance. The administrator wants to prevent accidental replacement of the database during the update. Which CloudFormation feature should be used?

A.Change sets
B.Stack policies
C.Resource signals
D.Nested stacks
AnswerB

Stack policies are JSON-based IAM-style policies attached to a CloudFormation stack that act as an explicit guard against certain update actions. By configuring a stack policy that denies the Update:Replace action for the RDS DB instance resource (using "Effect": "Deny" and "Action": ["Update:Replace"]), CloudFormation will refuse to replace the database during any stack update. This is exactly the protection the administrator needs to ensure the database is not inadvertently replaced.

Why this answer

Stack policies are the correct feature because they allow you to define explicit deny statements that prevent CloudFormation from updating or replacing specific resources, such as an RDS DB instance, during a stack update. By setting a stack policy that denies replacement actions on the database resource, the administrator ensures that even if the template changes would normally trigger a replacement, the update will fail rather than accidentally recreate the database.

Exam trap

The trap here is that candidates often confuse change sets (which only preview changes) with stack policies (which enforce guardrails), leading them to incorrectly select change sets as the mechanism to prevent accidental replacement.

How to eliminate wrong answers

Option A is wrong because change sets allow you to preview the changes that will be made to a stack before executing them, but they do not prevent the changes from being applied; they only provide visibility. Option C is wrong because resource signals are used to coordinate the creation or update of resources by sending success/failure signals (e.g., via cfn-signal), but they have no mechanism to block replacement of a specific resource. Option D is wrong because nested stacks help organize and reuse templates by embedding one stack within another, but they do not provide any resource-level protection against accidental replacement during updates.

125
MCQhard

Refer to the exhibit. A SysOps administrator creates this CloudFormation template. The stack creation fails with the error: 'The security group 'default' does not exist'. What is the most likely cause?

A.The VPC does not have a default security group.
B.The instance is launched in EC2-Classic, which does not support security groups.
C.The instance is launched in a VPC, but the security group is specified by name instead of group ID.
D.The 'default' security group is not present in the account.
AnswerC

This is correct because when you launch an instance in a VPC, AWS requires you to reference security groups by their group ID (e.g., sg-12345678), not by their name. In a VPC, the CLI parameter "--security-group-ids" expects the resource ID, and passing the name "default" (how it appears in the console) causes a "security group does not exist" error. The default VPC's default security group has a unique ID, and you must retrieve and use that ID to successfully launch the instance.

Why this answer

The error occurs because the template launches the instance in a VPC, where security groups must be referenced by their GroupId, not by name. The template uses 'default' (a name), but CloudFormation interprets it as a GroupId, which does not exist, causing the failure. Option C correctly identifies this issue.

126
MCQhard

A SysOps administrator is automating the creation of Amazon RDS instances using AWS CloudFormation. The template includes a DBInstance resource with a DBSubnetGroupName property referencing a subnet group created in the same template. The stack creation fails with the error 'DBSubnetGroup not found'. What is the MOST likely reason?

A.The VPC ID is incorrect or does not exist.
B.The DBSubnetGroup is not associated with a public subnet.
C.A DependsOn clause is missing between the DBInstance and the DBSubnetGroup.
D.The DBSubnetGroup is defined in a different CloudFormation stack.
AnswerC

CloudFormation does not automatically create an intrinsic dependency between a DBInstance and a DBSubnetGroup when the DBSubnetGroup is referenced by its name string rather than through the Ref function. Since the DBSubnetGroupName property in an RDS DBInstance expects a string, passing a literal name or a parameter does not establish a resource dependency, so CloudFormation may attempt to create the DBInstance before the DBSubnetGroup exists. This results in an error such as 'The specified DB Subnet Group does not exist' or 'DBSubnetGroup not found.' Adding an explicit DependsOn attribute to the DBInstance forces CloudFormation to wait until the DBSubnetGroup has been successfully created, making the creation order deterministic and resolving the failure.

Why this answer

In AWS CloudFormation, resource creation order is not guaranteed unless explicitly defined. When a DBInstance resource references a DBSubnetGroup by name, CloudFormation may attempt to create the DBInstance before the DBSubnetGroup is fully created, resulting in a 'DBSubnetGroup not found' error. Adding a DependsOn clause to the DBInstance resource ensures the DBSubnetGroup is created first, resolving the dependency.

Exam trap

The trap here is that candidates assume CloudFormation automatically resolves all dependencies based on property references, but it only does so for intrinsic function references (Ref, Fn::GetAtt), not for plain string values like DBSubnetGroupName.

How to eliminate wrong answers

Option A is wrong because an incorrect or non-existent VPC ID would cause a different error (e.g., 'VPC not found' or network-related failure), not a 'DBSubnetGroup not found' error. Option B is wrong because RDS subnet groups can be associated with private subnets; public subnets are not required for RDS instances, and this would not cause a 'not found' error. Option D is wrong because if the DBSubnetGroup were defined in a different stack, the error would typically be a cross-stack reference error or 'stack not found', not a simple 'not found' error within the same template; the question states the subnet group is created in the same template.

127
MCQmedium

A company uses AWS OpsWorks for configuration management. The SysOps administrator needs to deploy a new application version to existing EC2 instances managed by OpsWorks. Which OpsWorks lifecycle event should the administrator trigger to install the new application?

A.Configure
B.Deploy
C.Shutdown
D.Setup
AnswerB

Deploy is the OpsWorks lifecycle event explicitly designed for deploying applications. When you deploy, OpsWorks runs the Deploy recipes on specified instances, which typically perform tasks like pulling source code from a repository, running database migrations, and restarting application services. This is the correct event to use whenever you need to roll out a new version of an application to existing instances.

Why this answer

The 'Deploy' lifecycle event is specifically designed for deploying applications. Option B (Deploy) is correct because it triggers the deploy recipes to install the new application version. Option A (Configure) is incorrect because it runs when instances come online or leave the stack, not for application deployment.

Option C (Shutdown) is incorrect because it runs when an instance is terminated. Option D (Setup) is incorrect because it runs only once when the instance is first booted, not for ongoing deployments.

128
MCQmedium

A company uses AWS CodeDeploy to deploy a web application to a fleet of Amazon EC2 instances. The SysOps administrator needs to implement a deployment strategy that ensures zero downtime by creating a new set of instances alongside the current ones, then gradually shifting traffic to the new instances after they pass health checks. If a problem is detected, traffic can be instantly redirected back to the original instances. Which deployment configuration should the administrator use?

A.Rolling update
B.Blue/green deployment
C.All at once deployment
D.Canary deployment
AnswerB

Blue/green deployment provisions a complete second environment (green) alongside the current production environment (blue), allowing you to run tests against the new version while old traffic continues to flow. Once the new environment is validated, you shift traffic at the load balancer or DNS level—either all at once or gradually—making the cutover near-instantaneous. If the new environment fails, you simply switch traffic back to the still-available blue environment, enabling instant rollback with zero downtime, which is why this is the correct choice for high-availability web applications.

Why this answer

Blue/green deployment is the correct choice because it creates a completely new set of instances (green environment) alongside the existing ones (blue environment), shifts traffic gradually to the new instances after health checks pass, and allows instant rollback by redirecting traffic back to the original instances. AWS CodeDeploy supports this strategy natively with a blue/green deployment configuration, ensuring zero downtime during the transition.

Exam trap

The trap here is that candidates often confuse canary deployments with blue/green deployments, but canary deployments do not create a full parallel environment and lack the instant, full-traffic rollback capability that blue/green provides.

How to eliminate wrong answers

Option A is wrong because a rolling update replaces instances incrementally, which can cause temporary capacity reduction and does not guarantee zero downtime or instant rollback to the original fleet. Option C is wrong because an all-at-once deployment updates all instances simultaneously, causing downtime during the deployment and no ability to instantly redirect traffic back. Option D is wrong because a canary deployment shifts a small percentage of traffic to new instances gradually, but it does not create a full parallel environment for instant rollback; it typically requires manual or automated traffic shifting and may not provide the same instant rollback capability as blue/green.

129
Multi-Selecteasy

Which TWO options are best practices for automating deployments using AWS CodeDeploy? (Choose two.)

Select 2 answers
A.Use a single deployment group for all environments
B.Use a blue/green deployment strategy
C.Deploy to all instances simultaneously
D.Configure automatic rollback in case of deployment failure
E.Require manual approval for every deployment
AnswersB, D

A blue/green deployment strategy is a best practice because it provisions the new application version in a separate 'green' environment alongside the existing 'blue' one, allowing traffic to be switched over only after the new version passes health checks. This minimizes downtime and gives an almost instantaneous rollback path by simply redirecting traffic back to blue if a problem is detected. In AWS, this works with CodeDeploy, Elastic Beanstalk, and ECS, though stateful workloads like databases require careful compatibility analysis between the two environments.

Why this answer

A blue/green deployment strategy minimizes downtime and risk by running two identical environments (blue for current, green for new) and shifting traffic after validation. This approach allows instant rollback by switching traffic back to the blue environment if issues arise, making it a best practice for critical production deployments.

Exam trap

The trap here is that candidates often confuse 'automating deployments' with 'eliminating all manual steps,' leading them to select Option E (manual approval for every deployment) as a safety measure, when in fact AWS CodeDeploy's automatic rollback and blue/green strategies provide safer automation without requiring human intervention for every change.

130
MCQeasy

A company is using AWS OpsWorks for configuration management. They have a stack with multiple layers, and they want to automate the deployment of a custom configuration file to all instances in a specific layer. What is the MOST efficient way to achieve this?

A.Define the file in an AWS CloudFormation template using the AWS::OpsWorks::App resource.
B.Create a custom cookbook and assign it to the layer.
C.Use AWS Systems Manager Run Command to execute a script on each instance.
D.Add the configuration file as user data in the layer's Auto Scaling group.
AnswerB

Custom cookbooks are Chef cookbooks (recipes, templates, and files) that you store in a repository such as S3 or Git and assign to an OpsWorks layer. OpsWorks runs these cookbooks automatically during lifecycle events (Setup, Configure, Deploy, Undeploy), so you can use a template resource inside a recipe to render configuration files consistently on every instance in the layer. This is the native, supported way to manage configuration files in OpsWorks, and it is the correct answer because it integrates with the layer lifecycle and ensures ongoing convergence.

Why this answer

OpsWorks custom cookbooks allow you to run recipes that can deploy files to instances in a layer. Option A is incorrect because the AWS::OpsWorks::App resource is used to deploy applications, not configuration files, and it does not directly add custom configuration files to instances. Option C is incorrect because AWS Systems Manager Run Command can execute commands but is not specific to OpsWorks layers and is less efficient for automating deployments tied to a specific layer's lifecycle.

Option D is incorrect because user data scripts run at boot time only, not on demand, and they are not directly associated with OpsWorks layers.

131
MCQmedium

A company is using AWS CodeDeploy to automate deployments to an Auto Scaling group of Amazon EC2 instances. The deployment fails with the error 'The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available, or some instances in your deployment group are experiencing problems.' The instances are running Amazon Linux 2 and the CodeDeploy agent is installed. Which of the following is the MOST likely cause of this failure?

A.The CodeDeploy agent requires ruby and wget, which are not installed by default on Amazon Linux 2.
B.The S3 bucket containing the deployment artifacts has a bucket policy that denies access to the instances.
C.The deployment configuration is set to 'OneAtATime', causing insufficient healthy instances during the first deployment.
D.The Auto Scaling group has a minimum of 0 instances, so the deployment cannot start.
AnswerA

On Amazon Linux 2, Ruby and wget are not installed by default, and the CodeDeploy agent is a Ruby application that also relies on wget to download deployment artifacts. If these dependencies are missing, the agent process either fails to start or crashes immediately, so the instance never registers with CodeDeploy and the deployment hangs at the 'Stop' or 'BeforeInstall' step. The standard installation procedure requires running `yum install -y ruby wget` before installing the agent, so an AMI that omits them will cause exactly this failure.

Why this answer

The CodeDeploy agent needs the ruby and wget packages to function correctly on Amazon Linux 2. Without them, the agent may fail to download or execute the deployment scripts, causing instance failures. Option B is incorrect because S3 bucket policies do not affect CodeDeploy agent functionality directly; the agent uses HTTPS to download revision files.

Option C is incorrect because the deployment configuration controls how many instances can fail, but does not cause individual instance failures. Option D is incorrect because the deployment group can be configured with any number of instances; the error is not due to group size but individual instance failures.

132
MCQeasy

A SysOps administrator needs to deploy a microservices application using AWS Elastic Beanstalk. The application consists of multiple services that need to communicate with each other. Which Elastic Beanstalk environment type should the administrator choose?

A.Worker environment
B.Web server environment
C.Load-balanced environment
D.Single-instance environment
AnswerC

A load-balanced environment provisions an Elastic Load Balancer (ALB or NLB) in front of the EC2 instances running the microservices. This allows incoming traffic to be distributed across multiple instances, provides a stable endpoint for external clients, and enables services to discover each other via the load balancer DNS name. It also supports health checks, auto scaling, and rolling deployments, which are essential for production microservices.

Why this answer

A load-balanced environment (option C) is the correct choice because it provisions an Elastic Load Balancer (ELB) in front of Amazon EC2 instances, enabling the multiple microservices to communicate via HTTP/HTTPS endpoints. This environment type supports horizontal scaling and distributes incoming traffic across instances, which is essential for inter-service communication in a microservices architecture.

Exam trap

The trap here is that candidates often confuse a Worker environment with a general-purpose compute environment, but Worker environments are specifically for asynchronous message processing via SQS, not for synchronous HTTP communication between microservices.

How to eliminate wrong answers

Option A is wrong because a Worker environment is designed for background processing tasks using an Amazon SQS queue, not for direct HTTP-based inter-service communication. Option B is wrong because a Web server environment is a single-tier setup that does not include a load balancer by default, making it unsuitable for routing traffic between multiple services. Option D is wrong because a Single-instance environment runs only one EC2 instance without a load balancer, providing no mechanism for distributing requests among multiple services or achieving high availability.

133
MCQeasy

A company needs to deploy a new version of an application to an Auto Scaling group. The deployment must ensure that the new version is deployed to all instances, and if any instance fails, the deployment should roll back. Which deployment strategy should be used?

A.Blue/green deployment
B.Rolling deployment with rollback
C.All-at-once deployment
D.Canary deployment
AnswerB

Rolling deployment with rollback updates an Auto Scaling group in controlled batches, replacing or re-launching a subset of instances at a time while the remaining instances continue serving traffic. Elastic Load Balancing health checks verify each batch before the next begins, and if errors exceed a threshold, CodeDeploy or a similar tool automatically redeploys the previous version to restore service. This provides both gradual exposure and a safety net, which matches the requirement of deploying a new version with rollback capability.

Why this answer

A rolling deployment with rollback is the correct choice because it updates instances incrementally, replacing the old version with the new one across the Auto Scaling group while monitoring for failures. If any instance fails to become healthy (e.g., failing an ELB health check), the deployment automatically rolls back to the previous version, ensuring no partial or failed deployment persists. This strategy balances safety and speed, directly meeting the requirement to deploy to all instances with automatic rollback on failure.

Exam trap

The trap here is that candidates confuse 'rolling deployment with rollback' with 'blue/green deployment' because both involve health checks, but blue/green does not automatically roll back on instance failure during the update—it only switches traffic after full validation, making it unsuitable for the stated requirement of automatic rollback on any instance failure.

How to eliminate wrong answers

Option A is wrong because blue/green deployment creates a separate environment (green) and switches traffic after full validation, but it does not inherently roll back on instance failure during the deployment; rollback would require manual intervention or a separate pipeline step. Option C is wrong because all-at-once deployment updates all instances simultaneously, which can cause total downtime and does not support automatic rollback if an instance fails—the entire deployment would fail without a built-in rollback mechanism. Option D is wrong because canary deployment only shifts a small percentage of traffic to the new version initially, not deploying to all instances, and while it can detect issues, it does not guarantee deployment to all instances or automatic rollback on instance failure.

134
Multi-Selecteasy

A SysOps administrator is tasked with automating the provisioning of EC2 instances that must be able to access an Amazon S3 bucket. The administrator needs to ensure that the instances have the necessary permissions without using long-term access keys. Which TWO actions should the administrator take? (Choose TWO.)

Select 2 answers
A.Store AWS access keys in a configuration file on the instances.
B.Attach the IAM role to the EC2 instances using an instance profile.
C.Create an S3 bucket policy that allows access from the instances' private IP addresses.
D.Create an IAM role that grants the necessary S3 permissions.
E.Store the access keys in AWS Systems Manager Parameter Store.
AnswersB, D

Attaching an IAM role to the EC2 instances using an instance profile is the correct, secure mechanism for granting access to S3. When a role is attached, the instance can retrieve temporary, automatically rotating credentials from the instance metadata service (IMDSv2), which are assumed via STS. This eliminates the need to distribute or manage long-term access keys, reduces the risk of credential exposure, and simplifies permission updates because changes to the role policy take effect immediately for all associated instances.

Why this answer

Option D is correct because an IAM role is the identity that carries the S3 permission policy, and it is the prerequisite for granting temporary credentials to EC2. Option B is correct because the role must be delivered to the instances through an instance profile, which lets the EC2 instance metadata service (IMDS) vend rotating temporary credentials via AWS STS, satisfying the no-long-term-keys requirement. Option A is wrong because storing AWS access keys in a configuration file uses long-term credentials, which the scenario explicitly forbids.

Option C is wrong because an S3 bucket policy cannot meaningfully grant access based on an instance's private IP address, which is not a valid principal identifier for EC2. Option E is wrong because Systems Manager Parameter Store is a secrets storage mechanism, not an automatic credential provider, so instances would still need long-term keys to retrieve the values.

Exam trap

The trap is that candidates may pick 'store keys in Parameter Store' as a 'secure' alternative, not realizing it still relies on long-term credentials and misses the point that IAM roles provide keyless, rotating credentials natively.

135
MCQmedium

A company uses AWS CloudFormation to deploy a multi-tier application. The template uses nested stacks. One of the nested stacks creates an Auto Scaling group. The administrator wants to update the Auto Scaling group's launch configuration to use a new AMI ID. The AMI ID is stored in AWS Systems Manager Parameter Store. The administrator wants to ensure that the stack update automatically uses the latest AMI ID value from Parameter Store. What should the administrator do?

A.Use a CloudFormation dynamic reference to the parameter store in the template.
B.Use a CloudFormation mapping to map the AMI ID.
C.Use a custom resource to call Systems Manager to retrieve the AMI ID.
D.Use a CloudFormation parameter with a default value that matches the AMI ID.
AnswerA

A dynamic reference using {{resolve:ssm:parameter-name}} is resolved by CloudFormation at the time a stack operation is performed, not when the template is authored. This means that when you update the stack after the Systems Manager Parameter Store value changes, CloudFormation automatically retrieves the current AMI ID and uses it for resource creation or replacement. It is the only option that inherently satisfies the requirement to automatically adopt the latest AMI ID without editing the template or providing manual input.

Why this answer

CloudFormation dynamic references for Systems Manager Parameter Store (using the `{{resolve:ssm:/parameter-name}}` syntax) automatically resolve the latest parameter value at stack creation or update time. This ensures that the launch configuration always uses the current AMI ID from Parameter Store without manual intervention or hardcoding.

Exam trap

The trap here is that candidates may think a CloudFormation parameter with a default value or a mapping can achieve dynamic updates, but both are static unless manually changed, whereas dynamic references automatically pull the latest value from Parameter Store during stack operations.

How to eliminate wrong answers

Option B is wrong because CloudFormation mappings are static key-value pairs defined in the template; they do not dynamically fetch values from external services like Parameter Store at update time. Option C is wrong because a custom resource would require additional Lambda function code and complexity, and it is unnecessary when CloudFormation natively supports dynamic references to Parameter Store. Option D is wrong because a CloudFormation parameter with a default value is static; it does not automatically update when the underlying AMI ID in Parameter Store changes, and the user would need to manually provide a new value during each stack update.

136
MCQmedium

A SysOps administrator uses AWS Systems Manager Run Command to install software on a fleet of EC2 instances. The command fails on some instances with the error 'Instance ID not found'. What is the MOST likely cause?

A.The user data script has overridden the SSM Agent.
B.The instances are not tagged with the correct key-value pair.
C.The SSM Agent is not installed or configured on the instances, or the instances lack the required IAM role.
D.The instances are in a stopped state.
AnswerC

The SSM Agent is required for an EC2 instance to communicate with AWS Systems Manager and receive Run Command documents. Additionally, the instance must have an attached IAM role that grants the AmazonSSMManagedInstanceCore managed policy, allowing it to register, send heartbeats, and pull commands from the SSM service. Without both the agent running and the correct IAM permissions, the instance never appears in the Managed Instances list, so Run Command returns 'Instance ID not found' when you target it. This is the definitive cause when resolving this specific error.

Why this answer

The error 'Instance ID not found' indicates that Systems Manager Run Command cannot communicate with the SSM Agent on the target instances. This typically occurs when the SSM Agent is not installed, is not running, or the instance does not have an IAM role that grants the necessary permissions (e.g., AmazonSSMManagedInstanceCore) for Systems Manager to manage it. Without a valid agent and IAM role, the instance is not registered with Systems Manager, so Run Command cannot find its Instance ID.

Exam trap

The trap here is that candidates often confuse the 'Instance ID not found' error with network connectivity or instance state issues, but the root cause is almost always the absence of the SSM Agent or the required IAM role, not the instance being stopped or lacking tags.

How to eliminate wrong answers

Option A is wrong because user data scripts run at boot time and do not override the SSM Agent; they run independently and cannot remove or disable the agent unless explicitly scripted to do so, which is not implied by the error. Option B is wrong because tags are not required for Run Command to identify instances; Run Command uses instance IDs directly, and tagging is only used for targeting via resource groups or filters, not for basic connectivity. Option D is wrong because if an instance is in a stopped state, Run Command would not return 'Instance ID not found'; it would return an error indicating the instance is not in a running state or is unreachable, as the instance ID is still known to Systems Manager.

137
MCQeasy

A company uses AWS CloudFormation to deploy a three-tier web application. The SysOps administrator wants to update a critical parameter, such as the instance type, and ensure that the change is applied without recreating the EC2 instance, if possible. Which CloudFormation stack update feature should be used to achieve this?

A.Change sets
B.Stack policy
C.Update with drift detection
D.Directly edit the stack template and use the update stack action
AnswerA

Change sets are the correct method for previewing CloudFormation updates. They generate a summary of the actions CloudFormation will perform when you execute the change set, explicitly flagging each resource as 'Static' (no change), 'Update' (in-place modification), or 'Replace' (recreation with a new physical ID). This allows you to inspect the exact impact before committing, so you can avoid unintended resource recreation and associated data loss or downtime.

Why this answer

Change sets allow you to preview the changes that will be made to your stack resources before executing them. For an update that modifies an instance type, the change set will show whether the change causes replacement. In this case, AWS::EC2::Instance does not support in-place updates for InstanceType and will require replacement, so the change set would confirm that.

By using a change set, you can review the impact before applying the update.

Exam trap

The trap here is that candidates confuse change sets with simply updating the stack directly, not realizing that change sets provide a critical preview to avoid unintended resource replacement, especially for properties that may or may not require replacement depending on the resource type.

How to eliminate wrong answers

Option B is wrong because a stack policy is used to prevent specific stack resources from being updated or deleted during a stack update, not to control how updates are applied or to preview changes. Option C is wrong because drift detection identifies differences between the stack's actual resource configuration and the expected template configuration, but it does not perform or preview updates. Option D is wrong because directly editing the template and using the update stack action applies changes immediately without a preview, which could inadvertently cause resource replacement if the property change requires it; change sets provide the necessary preview to avoid this.

138
MCQhard

A SysOps administrator is troubleshooting a failed Auto Scaling group launch. The group uses a launch template that specifies an Amazon Linux 2 AMI. The instances fail to pass the EC2 health check and are terminated. The administrator checks the system log and finds that the instance boots but the cloud-init script fails due to a missing package repository. What is the most likely cause?

A.The launch template is using an incorrect version.
B.The IAM instance profile does not have sufficient permissions.
C.The Auto Scaling group is in a private subnet without a NAT gateway.
D.The AMI used by the launch template is outdated and the repositories are no longer valid.
AnswerD

An outdated AMI often contains yum or apt repository URLs that point to deprecated or retired endpoints. When cloud-init executes user data that runs package installs, the package manager tries to reach those old repositories and receives a 404 or 'repository not found' response, causing the boot-time failure. This is a common issue with Amazon Linux AMIs that have reached end-of-life, where the original repositories are no longer maintained and the instance cannot update or install software despite successfully booting.

Why this answer

If the AMI is outdated, the package repository URLs may be deprecated, causing cloud-init failures. The launch template version is not directly related to repository access. User data script problems could cause failures but the log points to a missing repository, which is often due to an outdated AMI.

IAM role issues would affect API calls, not package repos.

139
MCQmedium

A SysOps administrator manages a CloudFormation stack that deploys a web application. The stack includes an Amazon EC2 instance and an Amazon RDS DB instance. The administrator needs to update the stack to change the EC2 instance type. The administrator wants to ensure that the update does not accidentally replace the RDS database. Which CloudFormation feature should the administrator use to protect the RDS resource from being replaced during the stack update?

A.Use a DeletionPolicy of Retain on the RDS resource.
B.Use a stack policy that denies updates to the RDS resource.
C.Use the Resource Signal and CreationPolicy attributes.
D.Use a Change Set to review changes before executing.
AnswerB

A stack policy can explicitly deny update, replace, or delete actions on specific resources. By applying a policy that denies update to the RDS resource, the CloudFormation update will fail if it attempts to modify the RDS instance, thus protecting it from accidental replacement.

Why this answer

A stack policy is an AWS CloudFormation feature that explicitly denies update or replacement actions on specified resources. By applying a stack policy that denies updates to the RDS resource, the administrator prevents any stack update operation (including changing the EC2 instance type) from modifying or replacing the database, even if the template changes would otherwise affect it. This is the correct approach because it provides a guardrail specifically against accidental replacement during updates.

Exam trap

The trap here is that candidates often confuse DeletionPolicy (which only applies on stack deletion) with stack policies (which control updates), leading them to incorrectly choose Option A as a safety measure during updates.

How to eliminate wrong answers

Option A is wrong because a DeletionPolicy of Retain only protects the resource when the stack is deleted, not during a stack update; it does not prevent replacement or modification during an update. Option C is wrong because Resource Signal and CreationPolicy are used to control stack creation behavior (e.g., waiting for signals before marking a resource as created), not to protect resources from being replaced during updates. Option D is wrong because a Change Set only allows you to review proposed changes before executing them; it does not prevent the update from being executed or protect the RDS resource from replacement if the update is applied.

140
Drag & Dropmedium

Drag and drop the steps to troubleshoot high CPU usage on an Amazon EC2 instance into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct order for troubleshooting high CPU usage on an EC2 instance starts with checking CloudWatch metrics to confirm the issue and gain initial insights. Next, connect to the instance using SSH or Systems Manager to access the operating system. Then, identify the process causing high CPU using tools like top or ps.

After identification, analyze the process to understand its behavior, such as checking logs or memory usage. Finally, take corrective action, which may include stopping, killing, or optimizing the process, or scaling the instance up. This sequence ensures efficient and accurate troubleshooting.

141
MCQmedium

A SysOps administrator deploys a web application using AWS Elastic Beanstalk. The administrator wants to deploy a new application version with zero downtime and minimize the risk of failure by launching a completely new set of instances before swapping traffic. Which deployment policy should the administrator choose?

A.All at once
B.Rolling
C.Rolling with additional batch
D.Immutable
AnswerD

Immutable deployment creates a completely separate Auto Scaling group with a new launch template or configuration running the new application version. It lets the new fleet fully initialize, pass health checks, and register with the load balancer before traffic is shifted away from the old fleet. Because the old fleet remains untouched until traffic has moved and can be instantly restored by redirecting traffic back, it provides zero downtime and a trivial rollback mechanism.

Why this answer

The Immutable deployment policy (Option D) is correct because it launches a completely new set of instances in a separate Auto Scaling group, deploys the new application version to them, and then swaps the Elastic Load Balancer (ELB) traffic from the old instances to the new ones in a single, atomic swap. This ensures zero downtime and minimizes risk by keeping the original environment fully intact until the new instances pass health checks, allowing an immediate rollback by simply swapping traffic back.

Exam trap

The trap here is that candidates often confuse 'Rolling with additional batch' (Option C) with immutable deployments because both add new instances, but they fail to recognize that only Immutable launches a completely separate fleet and swaps traffic atomically, while Rolling with additional batch still modifies the existing environment and does not provide a full isolation or instant rollback capability.

How to eliminate wrong answers

Option A is wrong because 'All at once' deploys the new version to all existing instances simultaneously, causing downtime during the deployment and a full outage if the deployment fails. Option B is wrong because 'Rolling' deploys the new version in batches across existing instances, which reduces capacity during the update and does not launch a completely new set of instances, thus not providing the isolation required to minimize failure risk. Option C is wrong because 'Rolling with additional batch' adds a batch of new instances before starting the rolling update, but it still modifies existing instances and does not swap traffic from a fully separate environment; it only partially reduces capacity impact compared to standard rolling, but does not achieve the zero-downtime, full-isolation swap that Immutable provides.

142
MCQeasy

A SysOps administrator uses AWS CodeDeploy to deploy a new version of an application to an Auto Scaling group. The deployment uses the 'CodeDeployDefault.OneAtATime' deployment configuration. During the deployment, the first instance succeeds, but subsequent instances fail because the new application version has a bug that causes the application health check to fail. The administrator wants to immediately roll back the change and restore the previous working version on all instances. Which action should the administrator take?

A.Initiate a rollback from the CodeDeploy console to redeploy the previous working revision.
B.Stop the deployment immediately; the instances that have already been updated will revert automatically.
C.Edit the deployment group settings to pause deployments after a failure, then manually fix the instances.
D.Redeploy the same failing revision but with a different deployment configuration.
AnswerA

CodeDeploy's rollback feature automatically redeploys the last known successful revision to every instance in the deployment group, using the same AppSpec and lifecycle hooks to ensure a clean, consistent transition. The rollback is initiated from the console and runs as a new deployment, honoring deployment configuration settings such as minimum healthy hosts, so it performs a proper rolling update rather than a crude file copy. This restores the working state and provides audit logs for what was rolled back and when, making it the correct and safe recovery method.

Why this answer

CodeDeploy supports automatic and manual rollbacks to a previous working revision. When a deployment fails, the administrator can initiate a rollback from the CodeDeploy console, which redeploys the last successful revision to all instances in the deployment group, including those that were already updated. This ensures the previous working version is restored across the entire Auto Scaling group.

Exam trap

The trap here is that candidates mistakenly think stopping a deployment automatically reverts instances, but in CodeDeploy, stopping only halts the deployment process without rolling back already-updated instances.

How to eliminate wrong answers

Option B is wrong because stopping a deployment does not trigger an automatic revert; instances that have already been updated remain on the new (failing) revision and require a manual rollback or redeployment of the previous version. Option C is wrong because editing the deployment group to pause after failures does not fix the already-failed instances; it only affects future deployments, and manual fixes are not an automated rollback solution. Option D is wrong because redeploying the same failing revision, even with a different deployment configuration, will still deploy the buggy version and cause the same health check failures.

143
MCQeasy

A SysOps administrator needs to deploy a new version of an application that runs on Amazon EC2 instances in an Auto Scaling group. The deployment should minimize downtime and roll back automatically if health checks fail. Which deployment method should the administrator use?

A.Canary deployment
B.Blue/green deployment using a new Auto Scaling group and an Application Load Balancer
C.Rolling update via an Auto Scaling group
D.In-place deployment
AnswerB

Blue/green with a new Auto Scaling group and an Application Load Balancer is the correct answer because it creates a fully independent second environment (green) with its own ASG, then shifts traffic at the ALB listener level from the old (blue) to the new (green) target group. If health checks on the green target group fail or any deployment validation fails, the ALB can instantly route traffic back to the blue target group, making rollback a trivial DNS/rebinding change. This pattern avoids in-place modifications, eliminates downtime, and is explicitly designed for automated health-check-based cutover and rollback.

Why this answer

A blue/green deployment using a new Auto Scaling group and an Application Load Balancer minimizes downtime by shifting traffic from the old environment to the new one only after health checks pass. If health checks fail, traffic is not shifted, and the old environment remains serving, providing automatic rollback. This is the standard AWS pattern for zero-downtime deployments with rollback.

Exam trap

SOA-C02 often tests the difference between blue/green and rolling deployments — candidates pick rolling updates because they sound simpler, but the question's emphasis on automatic rollback and minimal downtime points to blue/green.

How to eliminate wrong answers

Option A is wrong because a canary deployment shifts a small percentage of traffic to the new version but does not inherently provide automatic rollback or minimize downtime as effectively as blue/green for this scenario. Option C is wrong because a rolling update via an Auto Scaling group replaces instances gradually but can cause downtime if capacity is reduced during the update and does not provide instant rollback. Option D is wrong because an in-place deployment updates existing instances, which can cause downtime and does not support automatic rollback based on health checks.

144
MCQmedium

A company is using AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment fails with the error 'The overall deployment failed because too many individual instances failed deployment'. The SysOps administrator checks the deployment logs and finds that the BeforeInstall lifecycle event script is failing on some instances. The instances are Amazon Linux 2. What should the administrator do to troubleshoot this issue?

A.Verify that the CodeDeploy agent on the instances is running and can communicate with the CodeDeploy service.
B.Ensure that the CodeDeploy deployment configuration is set to 'OneAtATime' to reduce instance failures.
C.Check the appspec.yml file for syntax errors in the hooks section.
D.Review the BeforeInstall script's output and exit code in the deployment logs or on the instance.
AnswerD

The BeforeInstall script's exit code is the definitive indicator of hook failure: CodeDeploy expects a 0 for success, and any non-zero value tells the agent to mark the deployment as failed. The deployment logs on the instance, typically under /opt/codedeploy-agent/deployment-root/deployment-logs/, store standard output and standard error for each script, while the CodeDeploy console provides a truncated view of the last 100 lines. Reviewing these logs will reveal the actual error message and the command that failed, enabling you to correct the script or its environment.

Why this answer

The error indicates that the BeforeInstall lifecycle script is failing. The correct first step is to examine the script's output and exit code, which can be found in the deployment logs (under the instance's CodeDeploy agent logs) or directly on the instance. This allows you to identify why the script is failing.

Option A is not directly relevant because the issue is not agent connectivity but script execution. Option B is incorrect because changing the deployment configuration to 'OneAtATime' would only affect the pace of deployments, not fix a failing script. Option C is unnecessary because the appspec.yml syntax is likely correct if the script runs at all; the problem lies in the script itself.

145
MCQmedium

A SysOps administrator is deploying a new web application using AWS Elastic Beanstalk. The application requires a high-performance relational database that can scale read capacity. The administrator needs to ensure that the database is highly available and can handle read replicas. The administrator creates an Elastic Beanstalk environment and adds an Amazon RDS DB instance. However, the database is deployed in a single Availability Zone. The administrator wants to modify the environment to use a Multi-AZ deployment for high availability and add read replicas. The administrator has the following options. Which option should the administrator choose?

A.Increase the DB instance class size to improve performance and then create a read replica.
B.Create a read replica of the existing DB instance and then modify the environment to use the replica.
C.Create a new Multi-AZ RDS DB instance with read replicas outside of Elastic Beanstalk. Update the environment's environment properties to point to the new database. Then delete the old DB instance.
D.Modify the Elastic Beanstalk environment configuration to enable Multi-AZ for the existing DB instance.
AnswerC

Decoupling the database from Elastic Beanstalk is the recommended approach because it gives you full control over RDS features like Multi-AZ failover and read replicas. By creating a separate Multi-AZ RDS instance, you enable synchronous standby replication and automatic failover, and adding read replicas handles read scaling. Updating environment properties (e.g., RDS_HOSTNAME) to reference the new database makes the application use it, and deleting the old EB-managed DB avoids abandoned resources. This solution satisfies high availability and is a standard production practice.

Why this answer

Elastic Beanstalk does not support converting an existing single-AZ RDS instance to Multi-AZ or adding read replicas through environment configuration changes. The supported approach is to create a new Multi-AZ RDS instance (with read replicas) outside of Elastic Beanstalk, then repoint the environment's connection properties to the new database and decommission the old one. This gives the administrator full control over the RDS configuration while keeping the Beanstalk application connected.

Exam trap

SOA-C02 often tests the misconception that Elastic Beanstalk can reconfigure an attached RDS instance in place (e.g., 'just enable Multi-AZ in the environment config'), when in reality the database must be recreated and the environment repointed.

How to eliminate wrong answers

Option A is wrong because increasing the DB instance class only improves vertical performance and does not provide Multi-AZ high availability or address the read-scaling requirement. Option B is wrong because a read replica cannot be promoted in place to become the primary Multi-AZ instance of the existing environment, and Elastic Beanstalk cannot simply 'use the replica' as the primary database. Option D is wrong because Elastic Beanstalk does not expose a configuration option to toggle Multi-AZ on an existing attached RDS instance — the RDS instance must be created as Multi-AZ from the start.

146
MCQeasy

A SysOps administrator uses AWS CloudFormation to manage a stack that includes an Amazon EC2 instance. The administrator wants to update the instance type from t3.medium to t3.large without recreating the instance. The instance type change is supported as a simple update in CloudFormation. Which stack update method should the administrator use to apply this change with the least disruption?

A.Directly update the stack by modifying the template and submitting the update via the AWS Management Console, AWS CLI, or API.
B.Create a change set to review the changes, then execute the change set.
C.Apply a stack policy to the EC2 instance to allow the update, then update the stack.
D.Delete the existing stack and create a new stack with the updated instance type.
AnswerA

A direct stack update is the correct method because CloudFormation compares the modified template against the current stack and applies the changed InstanceType property to the existing EC2 instance without replacement. The update can be submitted via the AWS Management Console, AWS CLI, or API, and because this is a simple, in-place attribute change, it minimizes downtime and avoids extra operational overhead. This approach is the fastest and least disruptive way to achieve the desired configuration.

Why this answer

Changing an EC2 instance type from t3.medium to t3.large is a supported simple update in CloudFormation, meaning the resource can be updated in-place without replacement. By directly updating the stack via the AWS Management Console, AWS CLI, or API, the administrator applies the change immediately with minimal disruption, as CloudFormation will stop the instance, modify the instance type, and restart it. This method avoids the overhead of creating a change set or deleting and recreating the stack, which would cause unnecessary downtime or complexity.

Exam trap

The trap here is that candidates often assume a change set is required for all updates or that it reduces disruption, when in fact it is only a review mechanism and does not change the update behavior; the direct update is equally safe and faster for simple, supported changes.

How to eliminate wrong answers

Option B is wrong because creating a change set is an optional review step that adds delay and does not reduce disruption; executing a change set still performs the same in-place update as a direct update, so it is not the least disruptive method. Option C is wrong because stack policies are used to prevent updates to specific resources, not to allow them; applying a stack policy to allow the update is unnecessary and could inadvertently block other updates if misconfigured. Option D is wrong because deleting and recreating the stack would destroy the existing EC2 instance and create a new one, causing complete disruption and data loss (unless data is stored externally), which is far more disruptive than an in-place update.

147
MCQhard

A SysOps administrator is troubleshooting a failed AWS CloudFormation stack creation. The stack includes an AWS::Lambda::Function resource that depends on an AWS::IAM::Role. The error message is 'Resource handler returned message: "The role defined for the function cannot be assumed by Lambda" (Service: Lambda, Status Code: 400).' What is the most likely cause?

A.The Lambda function name conflicts with an existing function
B.The trust policy of the IAM role does not include 'lambda.amazonaws.com' as a trusted entity
C.The IAM role does not have sufficient permissions to execute the Lambda function
D.The Lambda function has a resource-based policy that denies access
AnswerB

The trust policy on an IAM role defines which entities, such as AWS services, are allowed to call sts:AssumeRole to temporarily obtain the role's credentials. For Lambda to execute, that policy must include the service principal lambda.amazonaws.com in the Principal element; otherwise, the AssumeRole call is denied and the invocation fails before the function code runs. Adding a permissions policy alone is insufficient, because Lambda must first be allowed to assume the role.

Why this answer

The error 'The role defined for the function cannot be assumed by Lambda' specifically indicates that the IAM role's trust policy (assume role policy document) does not list lambda.amazonaws.com as a trusted principal. When Lambda attempts to assume the execution role during function creation, the STS AssumeRole call fails because the trust relationship is missing or misconfigured. The fix is to update the role's trust policy to include the Lambda service principal.

Exam trap

The trap here is that candidates conflate the trust policy with the permissions policy — they see 'role cannot be assumed' and think 'the role lacks permissions,' but the error is specifically about the trust relationship, not the permission grants.

How to eliminate wrong answers

Option A is wrong because a Lambda function name conflict would produce a different error such as 'Function already exists' or a naming validation error, not a role assumption failure. Option C is wrong because insufficient permissions in the role's permission policy would cause runtime failures when the function executes (e.g., AccessDenied on S3 or DynamoDB), not a failure to assume the role at creation time. Option D is wrong because a resource-based policy on the Lambda function controls who can invoke the function, not whether Lambda can assume the execution role — and it would produce an authorization error on invocation, not on stack creation.

148
MCQmedium

A company is using AWS CloudFormation to deploy a multi-tier web application. After updating the stack template, the update fails with a stack creation rollback in progress error. The SysOps administrator needs to identify the specific resource that caused the failure. What is the MOST efficient way to accomplish this?

A.Use the AWS Management Console to view the stack status and check the stack policy.
B.Use the aws cloudformation describe-change-set command to review the proposed changes.
C.Check the CloudTrail logs for the UpdateStack API call to see the error message.
D.Run the AWS CLI command aws cloudformation describe-stack-events --stack-name <stack-name> and review the resource status reason.
AnswerD

Running aws cloudformation describe-stack-events --stack-name <stack-name> retrieves every event in the stack's lifecycle, including the most recent update attempt. Each event includes the LogicalResourceId, ResourceStatus (e.g., UPDATE_FAILED), and the ResourceStatusReason field, which contains the specific error message from the underlying AWS service that caused the failure. Reviewing the events in reverse chronological order lets you pinpoint exactly which resource failed and why, making this the definitive troubleshooting command for failed CloudFormation operations.

Why this answer

The describe-stack-events command returns a chronological list of every stack event, including each resource's status and the 'ResourceStatusReason' field that contains the exact error message from the failed resource. This is the fastest, most direct way to pinpoint which resource caused the rollback without digging through unrelated logs.

Exam trap

SOA-C02 often tests the confusion between change sets (which preview proposed changes) and stack events (which record actual execution results) — candidates pick describe-change-set thinking it shows failures, but it only shows what was planned.

How to eliminate wrong answers

Option A is wrong because the console stack status only shows a high-level state (e.g., ROLLBACK_IN_PROGRESS) and the stack policy governs update protections — neither reveals the specific failing resource. Option B is wrong because describe-change-set shows what changes were proposed before execution, not what actually failed during the update. Option C is wrong because CloudTrail records the UpdateStack API call itself but does not surface per-resource failure reasons; you would see the API invocation, not the resource-level error.

149
MCQmedium

A DevOps engineer is designing a CI/CD pipeline for a microservices application. The application consists of several Docker containers that run on Amazon ECS with Fargate launch type. The engineer wants to automate the deployment of new container versions. Which AWS service should be used to orchestrate the build, test, and deployment stages?

A.AWS CodeDeploy
B.AWS CodePipeline
C.AWS CloudFormation
D.AWS CodeBuild
AnswerB

AWS CodePipeline is the correct choice because it is a fully managed continuous delivery service that orchestrates the build, test, and deploy phases of a release process. It lets you model the entire workflow as a series of stages — Source, Build, Test, Deploy — with sequential or parallel actions, and automatically triggers each stage when the previous one succeeds. CodePipeline integrates natively with AWS CodeCommit, CodeBuild, CodeDeploy, Elastic Beanstalk, ECS, and third-party tools like GitHub and Jenkins, making it the central coordinator for a CI/CD pipeline rather than just a tool that executes a single step. Its pipeline structure and transition gates provide the end-to-end automation a DevOps engineer needs for a microservices delivery workflow.

Why this answer

AWS CodePipeline is a fully managed continuous delivery service that orchestrates the build, test, and deploy phases of the release process. Option A is wrong because AWS CodeDeploy is for deploying applications to compute services but does not orchestrate the entire pipeline. Option C is wrong because AWS CloudFormation is for infrastructure as code, not CI/CD orchestration.

Option D is wrong because AWS CodeBuild is for building and testing code, not for orchestrating the entire pipeline.

150
MCQhard

A SysOps administrator is troubleshooting a CloudFormation stack that failed to create. The stack includes an Amazon RDS DB instance. The error message indicates that the DB instance name already exists. The stack uses a parameter for the DB instance identifier. What should the administrator do to resolve this issue and create the stack?

A.Delete the failed stack, change the DB instance identifier parameter to a unique name, and recreate the stack.
B.Manually delete the DB instance from the AWS Management Console and then retry the stack creation.
C.Use the AWS CLI command aws cloudformation update-stack with a new parameter value.
D.Execute ContinueUpdateRollback on the stack to retry the creation.
AnswerA

Deleting the failed stack is the correct first step because CloudFormation creation failures can leave resources in a transient or partially rolled-back state, and the stack cannot be updated or reused while it is in ROLLBACK_COMPLETE. Then changing the DB instance identifier parameter to a globally/regionally unique name avoids the RDS naming conflict that caused the failure; RDS DB instance identifiers must be unique per account within a Region. Finally, recreating the stack with the new parameter allows CloudFormation to provision a fresh DB instance without colliding with an existing resource, so this is the only approach that directly addresses the root cause.

Why this answer

When a CloudFormation stack creation fails due to a naming conflict (e.g., DB instance identifier already exists), the failed stack must be deleted because it cannot be updated or continued. Changing the parameter to a unique name and recreating the stack resolves the conflict. Option B is incorrect because, while deleting the conflicting DB instance would resolve the name conflict, the failed stack still exists and must be deleted before recreating the stack; in addition, deleting an existing DB instance is not the recommended approach — you should use a unique identifier.

Option C is incorrect because `update-stack` cannot be applied to a failed stack creation; the stack is in a failed state and must be recreated. Option D is incorrect because `ContinueUpdateRollback` is used for update rollbacks, not for failed creations.

← PreviousPage 2 of 3 · 182 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Deployment, Provisioning, and Automation questions.