Courseiva

CCNA Deployment, Provisioning, and Automation Questions

32 of 182 questions · Page 3/3 · Deployment, Provisioning, and Automation · Answers revealed

151
MCQmedium

A SysOps administrator is automating the deployment of a three-tier web application using AWS CloudFormation. The administrator wants to ensure that the database tier is created before the application tier. How should the administrator define this dependency in the CloudFormation template?

A.Use the Conditions section to check if the database exists before creating the application tier.
B.Use the Outputs section to export the database endpoint and import it in the application tier.
C.Use the DependsOn attribute on the application tier resources to reference the database tier resources.
D.Use the Parameters section to pass the database instance identifier to the application stack.
AnswerC

The DependsOn attribute is the explicit way to tell AWS CloudFormation that one resource must be created before another, overriding the template's otherwise optional logical ordering. When you apply DependsOn to the application-tier resources and reference the database-tier logical IDs, CloudFormation guarantees the database stack resources are created first, and will also roll back the application tier if the database creation fails. This is necessary when the dependencies are not implicit, such as when the application code only knows the database endpoint from a parameter or discovery service rather than a Ref/GetAtt call. Therefore, DependsOn is the correct and direct mechanism for enforcing the creation sequence.

Why this answer

CloudFormation supports the DependsOn attribute to specify resource dependencies. The application tier resources must wait for the database tier resources to be created. Option A is wrong because the Conditions section determines whether resources are created based on conditions, not the creation order.

Option B is wrong because the Outputs section exports values for use in other stacks, but does not control the order of creation within the same stack. Option D is wrong because the Parameters section defines input values passed to the template, not dependencies.

Exam trap

A common trap is to confuse the purpose of Conditions and Outputs with dependency management. Conditions only control if a resource is created, not when. Outputs are for exporting values, not for ordering.

152
MCQhard

A DevOps engineer is designing a CI/CD pipeline for a microservices application hosted on Amazon ECS with Fargate. The team wants to deploy updates to the services without downtime. The current pipeline builds a Docker image, pushes it to Amazon ECR, and updates the ECS service using AWS CodeDeploy with a blue/green deployment. However, during the deployment, the new tasks fail to start due to an incorrect environment variable. The engineer wants to validate the task definition before the actual deployment. What should the engineer do?

A.Use Amazon CloudWatch Synthetics canaries to monitor the health of the new tasks after deployment.
B.Run the Docker container locally using 'docker run' with the same environment variables to verify the configuration.
C.Use Amazon ECS Service Auto Scaling to gradually increase the number of tasks and monitor CPU utilization.
D.Configure CodeDeploy to use a validation hook with an AWS Lambda function that tests the new task definition before shifting traffic.
AnswerD

This is correct because CodeDeploy for Amazon ECS uses an AppSpec file that can define a `BeforeAllowTraffic` lifecycle hook, which invokes an AWS Lambda function after the new task set is registered with the target group but before any production traffic is shifted. The Lambda can perform an HTTP health check against the new task's endpoint, verify the container is listening on the expected port, or check internal state, and if it fails, CodeDeploy aborts the deployment and rolls back to the original task set. This provides a true pre-flight validation gate for the task definition within the actual Fargate environment, ensuring that only valid task definitions ever receive traffic.

Why this answer

AWS CodeDeploy for ECS supports lifecycle event hooks, including a BeforeAllowTraffic hook that runs an AWS Lambda function before traffic is shifted to the replacement task set. The Lambda can inspect the new task definition, verify environment variables, and fail the deployment if validation fails, preventing the bad configuration from ever receiving production traffic. This directly addresses the requirement to validate the task definition before the actual deployment.

Exam trap

The trap is that candidates focus on 'monitoring' or 'scaling' as the safety mechanism, missing that the question explicitly asks for pre-deployment validation, which only a CodeDeploy lifecycle hook can provide.

How to eliminate wrong answers

Option A is wrong because CloudWatch Synthetics canaries monitor endpoints after deployment — they detect problems post-traffic-shift, not before, so downtime could still occur. Option B is wrong because running the container locally does not validate the ECS task definition, IAM roles, secrets, or Fargate-specific configuration, and it is not part of the automated pipeline. Option C is wrong because ECS Service Auto Scaling adjusts task count based on load metrics; it has nothing to do with validating a task definition and would not catch a bad environment variable.

153
MCQeasy

A company uses AWS OpsWorks to manage a stack of web servers. They need to deploy a configuration change that updates the /etc/nginx/nginx.conf file on all instances. Which OpsWorks feature should be used?

A.Custom Chef recipes
B.OpsWorks layers
C.Lifecycle events
D.Custom cookbooks
AnswerA

A custom Chef recipe is the executable configuration unit in OpsWorks Stacks: when assigned to a layer lifecycle event, it runs on the instance and uses Chef resources (file, template, package, service, execute) to actually change configuration, such as updating an application configuration file. This is why the scenario—applying a specific configuration change to web servers—maps directly to custom recipes, not to broader constructs.

Why this answer

Custom Chef recipes are the correct choice because OpsWorks uses Chef to manage configuration, and deploying a specific file change like /etc/nginx/nginx.conf requires a custom recipe that directly modifies the file using Chef resources (e.g., template or file resource). This allows precise, idempotent configuration management across all instances in the stack.

Exam trap

The trap here is confusing lifecycle events (the trigger) with the actual configuration logic (the recipe), leading candidates to pick 'Lifecycle events' when the question asks for the feature that performs the file update.

How to eliminate wrong answers

Option B is wrong because OpsWorks layers define the structure and services of a stack (e.g., load balancer, application server), but they do not directly execute configuration changes to specific files like nginx.conf. Option C is wrong because lifecycle events (e.g., Setup, Configure, Deploy) trigger Chef runs but are not themselves a feature that deploys configuration changes; they are the timing mechanism, not the content. Option D is wrong because custom cookbooks are the collection of recipes, attributes, and templates, but the question asks for the feature used to deploy the change, and the specific executable unit within a cookbook is a recipe.

154
MCQeasy

A company uses AWS Elastic Beanstalk to deploy a web application. After updating the environment configuration, the deployment fails and the environment health turns red. The SysOps administrator checks the logs and finds a permission error related to the EC2 instance profile. What should the administrator do to resolve the issue?

A.Rebuild the environment from scratch using a saved configuration template.
B.Update the IAM instance profile associated with the environment to include the required permissions.
C.Modify the security group attached to the environment to allow outbound traffic.
D.Update the application version to the latest build.
AnswerB

Elastic Beanstalk environments use an IAM instance profile to grant permissions to the underlying EC2 instances. To resolve permission errors where the application cannot access required AWS services or resources, you must attach a policy that includes the necessary actions to the instance profile role. After updating the role, perform an environment update or restart so the running instances pick up the new permissions; this directly addresses the root cause because instance profile permissions govern what the application can do on AWS.

Why this answer

Elastic Beanstalk uses an IAM instance profile for the EC2 instances. The instance profile must have the necessary permissions to access resources like S3 buckets or DynamoDB tables. Updating the instance profile with the required permissions resolves the issue.

Option A is wrong because rebuilding the environment from scratch using a saved configuration template does not address the underlying permission issue; it would only recreate the same problem. Option C is wrong because the security group controls network access, not IAM permissions; modifying it would not resolve the permission error. Option D is wrong because updating the application version does not fix permission issues; the application version itself does not grant or modify IAM permissions.

155
MCQeasy

A company uses AWS Systems Manager to automate patching of EC2 instances. The instances are in an Auto Scaling group. The company wants to ensure that patching does not affect application availability. Which feature should be used?

A.State Manager
B.Maintenance Windows
C.Patch Manager
D.Run Command
AnswerB

Maintenance Windows are the Systems Manager feature designed to schedule time-bounded administrative actions, such as patching, during approved maintenance periods. They let you register Patch Manager tasks, Run Command commands, or Automation workflows, and control execution with rate limits and concurrency thresholds. This scheduling capability directly answers the need for automated patching with minimal business impact.

Why this answer

Systems Manager Maintenance Windows allow scheduling patching during specific time windows, and can be configured to work with Auto Scaling to maintain availability by ensuring instances are patched without affecting the overall application availability. Option A is wrong because State Manager is used for maintaining consistent configuration of instances, not for scheduling patching. Option C is wrong because Patch Manager is the service that applies patches, but it is typically run within a Maintenance Window to control timing and availability.

Option D is wrong because Run Command is for executing ad-hoc commands and scripts, not for scheduled patching with availability considerations.

156
Multi-Selecthard

A company deploys microservices on Amazon ECS using Fargate. The deployment is managed by AWS CodePipeline. The administrator notices that deployments sometimes fail because the new task definition is not registered before the deployment. Which THREE steps should the administrator take to resolve this issue? (Choose THREE.)

Select 3 answers
A.Ensure that the task definition is registered in the CodePipeline build stage before the deploy stage.
B.Manually update the ECS service with the new task definition after the pipeline runs.
C.Use the ECS deploy action in CodePipeline which automatically registers the task definition.
D.Add a step in the pipeline to register the task definition using the AWS CLI or SDK.
E.Store the task definition in Amazon ECR alongside the container image.
AnswersA, C, D

In CodePipeline, the Deploy stage's ECS deployment action expects an ARN of an already-registered task definition, typically passed via artifacts from the Build stage. If the build stage does not explicitly register the task definition (e.g., using aws ecs register-task-definition or the ECS deploy action's automatic registration), the deploy action may reference a stale or nonexistent revision, causing the deployment to fail or roll back. Registration must happen before the deploy stage consumes the artifact, ensuring the action has a valid family:revision to run.

Why this answer

The issue is that the task definition must be registered before the ECS service update. Option A is correct because registering the task definition in the build stage ensures it is available for the deploy stage. Option C is correct because the ECS deploy action in CodePipeline automatically handles task definition registration and service update.

Option D is correct because adding a CLI or SDK step explicitly registers the task definition. Option B is incorrect because the task definition should be registered automatically, not manually. Option E is incorrect because ECR stores container images, not task definitions.

157
MCQmedium

A SysOps administrator uses AWS CloudFormation to manage a stack that includes an Amazon RDS DB instance. The administrator needs to update the stack by changing a parameter that, if applied directly, would replace the database. The administrator wants to prevent accidental replacement during the update. Which CloudFormation feature should the administrator use?

A.Change sets
B.Stack policy
C.Resource-level permissions
D.Stack sets
AnswerB

A stack policy is the correct safeguard because it is a JSON-based policy attached to the CloudFormation stack that explicitly denies specific update actions on specific resources. By adding a rule such as a Deny on 'Update:Replace' for the RDS logical resource ID, the stack update will fail and the RDS instance will be protected from replacement even if an S3 event or trusted user attempts an update. This provides a hard guard that is enforced by CloudFormation before any changes are applied, without preventing other non-replacing updates.

Why this answer

A stack policy is a CloudFormation feature that defines which stack resources can be updated or replaced during a stack update. By setting a stack policy that explicitly denies replacement updates on the RDS DB instance, the administrator can prevent accidental replacement while still allowing other updates. This is the correct approach because it directly controls the update behavior at the resource level without requiring manual intervention.

Exam trap

The trap here is that candidates often confuse change sets (which only preview changes) with stack policies (which actually enforce update restrictions), leading them to select change sets as a safety mechanism when they only provide visibility, not prevention.

How to eliminate wrong answers

Option A is wrong because change sets allow you to preview the changes that will be made to a stack, including whether a resource will be replaced, but they do not prevent the replacement from occurring; they only show what will happen. Option C is wrong because resource-level permissions (via IAM policies) control who can perform actions on resources, not what specific update actions (like replacement) are allowed or denied during a CloudFormation stack update. Option D is wrong because stack sets are used to deploy stacks across multiple accounts and regions, not to control update behavior or prevent replacement of individual resources within a single stack.

158
MCQeasy

A company uses AWS Elastic Beanstalk to deploy a web application. The environment is running low on memory, and the administrator needs to change the instance type from t2.micro to t3.small. What is the correct way to perform this change with minimal downtime?

A.Modify the instance type in the Elastic Beanstalk environment's configuration.
B.Terminate the environment and create a new one with the desired instance type.
C.Create a new environment and perform a swap URL.
D.Manually modify the Auto Scaling group's launch configuration.
AnswerA

Modify the instance type by updating the 'Instances' or 'Capacity' configuration in the Elastic Beanstalk environment's management console, EB CLI, or API. Elastic Beanstalk then performs a rolling update, replacing EC2 instances in batches to keep the application available, and automatically updates the Auto Scaling group's launch configuration. This is the fully supported path for resizing compute resources in a running environment.

Why this answer

Modifying the instance type in the Elastic Beanstalk environment's configuration triggers a rolling update or immutable update, which replaces instances with the new type while keeping the environment running. This approach minimizes downtime because Elastic Beanstalk manages the instance replacement process automatically, ensuring that traffic continues to be served during the transition.

Exam trap

The trap here is that candidates often think manual changes to the Auto Scaling group (Option D) are acceptable, but Elastic Beanstalk treats such manual modifications as configuration drift, which can cause the environment to become out of sync and fail subsequent managed updates.

How to eliminate wrong answers

Option B is wrong because terminating the environment and creating a new one causes complete downtime and loses environment configuration, which is unnecessary when a simple configuration change can be applied. Option C is wrong because creating a new environment and performing a swap URL (CNAME swap) is a blue/green deployment strategy that introduces additional complexity and cost, and is not the minimal-downtime approach for a simple instance type change. Option D is wrong because manually modifying the Auto Scaling group's launch configuration does not update running instances; it only affects new instances launched in the future, and it bypasses Elastic Beanstalk's managed updates, potentially causing drift and inconsistent state.

159
MCQmedium

A company uses AWS CodeDeploy to deploy a new version of an application to EC2 instances in an Auto Scaling group behind an Application Load Balancer. The company requires zero downtime during the deployment. Which deployment configuration should be used?

A.CodeDeployDefault.AllAtOnce
B.CodeDeployDefault.OneAtATime
C.CodeDeployDefault.EC2/OnPremises: BlueGreenDeployment
D.Create a blue/green deployment by configuring CodeDeploy to launch new instances and shift traffic after validation.
AnswerD

A blue/green deployment with CodeDeploy provisions a new, separate fleet of EC2 instances (green) and installs the new revision on them while the original fleet (blue) continues to serve traffic. After validation of the green instances—through health checks, tests, or a manual approval—you can shift traffic from the blue fleet to the green fleet using an Application Load Balancer. This approach isolates the new version from production traffic until it is verified, and if a problem arises you can instantly reroute traffic back to the blue fleet, ensuring zero downtime.

Why this answer

A blue/green deployment with CodeDeploy, where new instances are launched and traffic is shifted only after validation, ensures zero downtime by keeping the old environment (blue) fully serving traffic until the new environment (green) is verified healthy. This approach avoids any in-place updates that could temporarily reduce capacity or cause service disruption, meeting the requirement for zero downtime during deployment.

Exam trap

The trap here is that candidates confuse the predefined deployment configurations (like AllAtOnce or OneAtATime) with the blue/green deployment method, not realizing that blue/green is a separate deployment type configured in the deployment group settings, not a predefined configuration name.

How to eliminate wrong answers

Option A is wrong because CodeDeployDefault.AllAtOnce deploys to all instances simultaneously, which can cause downtime if the new version fails or requires a restart, as there is no gradual traffic shifting or rollback capability. Option B is wrong because CodeDeployDefault.OneAtATime deploys to one instance at a time, which minimizes risk but still involves in-place updates that can cause brief interruptions if the application requires a restart or health check failure during deployment. Option C is wrong because CodeDeployDefault.EC2/OnPremises: BlueGreenDeployment is not a valid predefined deployment configuration name; CodeDeploy does not have a built-in configuration with that exact string, and blue/green deployments must be explicitly configured via the deployment group settings, not selected as a predefined configuration.

160
MCQmedium

Operators have been making direct changes to AWS resources (security group rules, IAM policy modifications) that were originally created by CloudFormation stacks. The team wants to identify which stacks and specific resources have drifted from their template definitions. What is the correct tool and operation sequence?

A.Run drift detection on each CloudFormation stack; review the results in the Drift status panel to see which resources have MODIFIED or DELETED status
B.Enable AWS Config conformance packs that check CloudFormation stack compliance against desired template states
C.Re-deploy all stacks with the original templates using CloudFormation update-stack to overwrite any manual changes
D.Use AWS Trusted Advisor to identify resources that have been modified outside of their originating CloudFormation stacks
AnswerA

Drift detection calls AWS APIs to read the current configuration of each resource and compares it to the template. Resources with live configurations differing from the template are marked MODIFIED. Deleted resources outside the stack are marked DELETED. The results show the exact property-level differences, enabling targeted remediation.

Why this answer

AWS CloudFormation drift detection is the correct tool because it directly compares the current state of resources in a stack (including security group rules and IAM policies) against the stack's template definitions. Running drift detection on each stack and reviewing the Drift status panel reveals which resources have been modified or deleted outside of CloudFormation, providing the exact identification the team needs.

Exam trap

The trap here is that candidates may confuse drift detection with compliance checks (AWS Config) or remediation actions (update-stack), but the question specifically asks for identification of drifted stacks and resources, not remediation or compliance evaluation.

How to eliminate wrong answers

Option B is wrong because AWS Config conformance packs evaluate resource compliance against rules, not against CloudFormation template states; they cannot detect drift from a specific stack template. Option C is wrong because re-deploying stacks with update-stack overwrites manual changes but does not identify which stacks or resources have drifted; it is a remediation action, not a detection tool. Option D is wrong because AWS Trusted Advisor checks for best practices and cost optimization, not for drift between CloudFormation templates and actual resource configurations.

161
MCQmedium

A company uses AWS CloudFormation to deploy a three-tier web application. The template includes an Amazon RDS DB instance. The SysOps administrator needs to ensure that the database password is not exposed in the template or in the stack outputs. The password should be stored securely and rotated automatically every 90 days. Which solution should the administrator use?

A.Store the password as a plaintext parameter in the CloudFormation template and mark it as NoEcho.
B.Use AWS Systems Manager Parameter Store to store the password as a SecureString and reference it using the dynamic reference {{resolve:ssm-secure:password}} in the template.
C.Use AWS Secrets Manager to store the password and reference it using the dynamic reference {{resolve:secretsmanager:secretId:secretString:password}} in the CloudFormation template. Enable automatic rotation.
D.Hardcode the password in a userdata script that is passed to the EC2 instances.
AnswerC

Secrets Manager is a purpose-built secret management service with managed automatic rotation via a configurable Lambda rotation function, so the database password is rotated on a schedule without custom code. The dynamic reference {{resolve:secretsmanager:secretId:secretString:password}} fetches the current secret value at CloudFormation stack creation/update time without ever putting the password in the template. This combines secure storage, seamless retrieval, and automated rotation, making it the correct choice.

Why this answer

AWS Secrets Manager is designed to securely store secrets like database passwords, supports automatic rotation (including a 90-day schedule), and can be referenced in CloudFormation templates using the dynamic reference {{resolve:secretsmanager:secretId:secretString:password}}. This ensures the password is never exposed in the template or stack outputs, and rotation is handled automatically without manual intervention.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (which can store SecureStrings but lacks native rotation) with AWS Secrets Manager (which is purpose-built for secrets with automatic rotation), leading them to choose Option B instead of C.

How to eliminate wrong answers

Option A is wrong because marking a parameter as NoEcho only hides it from console output and logs, but the plaintext value is still stored in the template and can be retrieved by anyone with access to the template or stack metadata; it does not provide secure storage or automatic rotation. Option B is wrong because AWS Systems Manager Parameter Store (SecureString) stores the password securely but does not natively support automatic rotation; you would need to build a custom rotation solution, and the dynamic reference {{resolve:ssm-secure:password}} does not trigger rotation. Option D is wrong because hardcoding the password in a userdata script exposes it in plaintext within the EC2 instance metadata and logs, violating security best practices and providing no rotation capability.

162
MCQhard

A SysOps administrator is using AWS OpsWorks to manage a stack of web servers. The administrator wants to automate the installation of custom software on all new instances that are added to the layer. What is the best approach?

A.Assign a custom Chef recipe to the layer's Setup lifecycle event.
B.Use AWS CloudFormation to install software on new instances.
C.Create a custom AMI with the software pre-installed and use that in the layer.
D.Use EC2 user data scripts in the layer configuration.
AnswerA

In AWS OpsWorks, the Setup lifecycle event runs on every new instance immediately after it finishes booting and before the Deploy event. Assigning a custom Chef recipe to Setup gives the OpsWorks agent an idempotent, declarative way to install and configure required software, ensuring consistent state across all instances. This is the native OpsWorks mechanism for bootstrapping software and is fully integrated with the stack's configuration management.

Why this answer

AWS OpsWorks uses Chef to manage configuration. Assigning a custom Chef recipe to the layer's Setup lifecycle event ensures the recipe runs automatically on every new instance when it boots, installing the custom software consistently. This is the native, best-practice approach within OpsWorks for automating software installation on new instances.

Exam trap

The trap here is that candidates may confuse OpsWorks lifecycle events with EC2 user data or CloudFormation, not realizing that OpsWorks has its own built-in Chef-based automation for instance configuration.

How to eliminate wrong answers

Option B is wrong because AWS CloudFormation is an infrastructure-as-code service for provisioning resources, not for running configuration management on instances within an existing OpsWorks stack; it would require additional orchestration and does not integrate with OpsWorks lifecycle events. Option C is wrong because while a custom AMI pre-installs software, it bypasses OpsWorks's configuration management capabilities and makes updates harder to manage; it is not the 'best approach' for automation within OpsWorks. Option D is wrong because EC2 user data scripts are executed only at first boot of an EC2 instance, but OpsWorks manages instances through Chef and lifecycle events; user data is not the intended mechanism for OpsWorks-managed instances and would not integrate with OpsWorks's lifecycle hooks.

163
MCQeasy

A SysOps administrator needs to deploy a web application stack consisting of an Amazon EC2 instance, an Amazon RDS database, and an Application Load Balancer. The administrator wants to define the infrastructure as code and version control it. Which AWS service should the administrator use?

A.AWS Elastic Beanstalk
B.AWS CloudFormation
C.AWS OpsWorks
D.AWS CodeDeploy
AnswerB

AWS CloudFormation is an Infrastructure-as-Code service that lets you define every AWS resource—VPCs, subnets, EC2 instances, IAM roles, RDS databases, and application-specific components—in a declarative YAML or JSON template. Templates are stored in version control, so deployments are fully repeatable and auditable, and change sets let you preview modifications before executing them. CloudFormation also manages rollbacks on failure and stack lifecycle, making it the most complete and precise tool for provisioning a web application environment from scratch. This is why it is the correct answer for a sysops administrator who needs deterministic, fully controlled deployment.

Why this answer

AWS CloudFormation is the correct choice because it is an Infrastructure as Code (IaC) service that allows you to define and provision AWS resources—such as EC2 instances, RDS databases, and Application Load Balancers—using declarative templates (JSON or YAML). These templates can be version-controlled in a repository like Git, enabling repeatable, auditable deployments. Elastic Beanstalk abstracts infrastructure management but does not give you the same level of granular control over individual resources as CloudFormation.

Exam trap

The trap here is that candidates often confuse AWS Elastic Beanstalk (a PaaS that automates deployment) with Infrastructure as Code, but Elastic Beanstalk does not allow you to version-control the raw infrastructure definition; CloudFormation is the dedicated IaC service for that purpose.

How to eliminate wrong answers

Option A is wrong because AWS Elastic Beanstalk is a Platform as a Service (PaaS) that automates deployment and scaling of applications but does not provide native version control for the underlying infrastructure definition; it manages resources behind the scenes, not as a user-defined IaC template. Option C is wrong because AWS OpsWorks is a configuration management service based on Chef and Puppet, designed for managing server configurations and application stacks, not for declaratively provisioning and version-controlling infrastructure resources like EC2, RDS, and ALB as code. Option D is wrong because AWS CodeDeploy is a deployment automation service that handles code deployment to compute services (e.g., EC2, Lambda) but does not define or provision the underlying infrastructure resources themselves.

164
MCQhard

An organization uses AWS OpsWorks for configuration management. The SysOps administrator notices that a stack's instances are not receiving the updated custom cookbooks after a new deployment. The cookbooks are stored in a private GitHub repository. What is the most likely cause?

A.The cookbooks are not stored in an S3 bucket.
B.The OpsWorks agent is not running on the instances.
C.The instances do not have internet access.
D.The SSH key for the Git repository is not configured in the stack.
AnswerD

Correct. AWS OpsWorks uses the SSH key stored in the stack configuration to authenticate with private GitHub repositories. If the key is missing or invalid, the instances cannot download the updated cookbooks, causing the failure.

Why this answer

The most likely cause is that the SSH key for the Git repository is not configured in the stack. AWS OpsWorks uses SSH keys to authenticate to private Git repositories when deploying custom cookbooks. Without the correct key, the instances cannot pull the updated cookbooks, resulting in deployment failures or outdated cookbooks.

Exam trap

The trap is assuming that internet access alone is sufficient for private repository access, overlooking the need for authentication credentials like SSH keys.

How to eliminate wrong answers

Option A is wrong because OpsWorks supports custom cookbooks from Git repositories, not just S3; storing in S3 is not a requirement. Option B is wrong because if the OpsWorks agent were not running, the instances would not be managed at all, and other symptoms like missing lifecycle events would occur. Option C is wrong because instances can access the internet via NAT or other means, but even with internet access, authentication to a private repository requires the SSH key; lack of internet would cause broader connectivity issues.

165
MCQmedium

A company uses AWS CloudFormation to manage infrastructure. A developer accidentally deletes a resource from the stack template, and the next stack update attempts to delete the resource. The SysOps administrator wants to prevent accidental deletion of critical resources. Which CloudFormation feature should be used?

A.Enable termination protection on the stack.
B.Stack policy to deny delete actions.
C.Set a DeletionPolicy attribute to 'Retain' on the resource.
D.Attach an IAM policy that denies cloudformation:DeleteStack.
AnswerC

Setting the DeletionPolicy attribute to 'Retain' is the correct mechanism. It instructs CloudFormation to keep the resource and its contents when the resource is removed from the stack template, whether during an update or a stack deletion. The resource is simply orphaned from CloudFormation management, allowing you to preserve data such as an S3 bucket or RDS database for later use or manual cleanup.

Why this answer

The DeletionPolicy attribute set to 'Retain' on a resource ensures that CloudFormation will preserve the resource even if it is removed from the stack template or the stack itself is deleted. This directly prevents accidental deletion of critical resources during stack updates. It is a resource-level safeguard, not a stack-level one.

Exam trap

SOA-C02 often tests the difference between stack-level protections (termination protection, IAM policies) and resource-level protections (DeletionPolicy), causing candidates to choose stack-level options when the question asks about preventing deletion of a specific resource.

How to eliminate wrong answers

Option A is wrong because termination protection only prevents deletion of the entire stack, not individual resources removed from the template. Option B is wrong because a stack policy can deny update actions on specific resources, but it does not prevent deletion when the resource is removed from the template; it only blocks updates that would modify or delete the resource, but the resource would still be deleted if the policy allows it. Option D is wrong because an IAM policy denying cloudformation:DeleteStack only prevents stack deletion, not resource deletion during a stack update.

166
MCQeasy

An organization is using AWS CloudFormation to manage its infrastructure. The SysOps administrator wants to update a stack that includes an Amazon RDS DB instance. The update requires changing the DB instance class. However, the administrator wants to minimize downtime. What should the administrator do?

A.Use CloudFormation's 'DeletionPolicy' attribute to retain the database during updates.
B.Enable Multi-AZ on the DB instance (if not already enabled) before performing the stack update.
C.Update the stack directly with 'ApplyImmediately' set to true.
D.Create a read replica, promote it, and then delete the original DB instance.
AnswerB

Enabling Multi-AZ gives the DB instance a standby replica in a different Availability Zone, which RDS can fail over to during maintenance. When a stack update changes the DB instance class, RDS applies the modification to the standby first, performs a failover, and then updates the former primary—this keeps the database available during the transition. Because the failover only causes a brief connection interruption rather than a full shutdown, Multi-AZ is the correct way to minimize downtime during an instance class update.

Why this answer

Enabling Multi-AZ allows the RDS instance to have a standby in a different Availability Zone. When updating the DB instance class, CloudFormation can modify the standby first, then fail over to it, minimizing downtime. Options A, C, and D are incorrect: A (DeletionPolicy) controls resource retention on stack deletion, not updates; C (ApplyImmediately) may cause a brief outage; D (read replica promotion) is for scaling reads, not for minimizing downtime during instance class changes.

167
MCQmedium

A SysOps administrator ran a CloudFormation stack update that failed and rolled back. The stack status is UPDATE_ROLLBACK_FAILED. The administrator needs to fix the issue and bring the stack to a stable state. What should the administrator do FIRST?

A.Identify and resolve the resource issue that caused the rollback failure, then continue the rollback.
B.Wait for CloudFormation to automatically retry the rollback.
C.Execute a new stack update to overwrite the failed resources.
D.Delete the stack and recreate it from the template.
AnswerA

The correct first action is to inspect the stack events and any associated resource status reasons to identify why the rollback itself failed. CloudFormation will not proceed past the UPDATE_ROLLBACK_FAILED state until the underlying resource issue is resolved, because resources that could not be rolled back remain in a state that blocks further stack operations. After fixing the resource problem, such as deleting a non-CloudFormation-managed dependency or manually updating an unresponsive resource, you can use the "Continue update rollback" operation to drive the stack to a stable UPDATE_ROLLBACK_COMPLETE state. This is the only recovery path that preserves the stack and any successfully rolled-back resources without forcing a destructive teardown.

Why this answer

When a CloudFormation stack is in UPDATE_ROLLBACK_FAILED, the rollback itself failed because a resource could not be reverted. The administrator must first identify and resolve the underlying resource issue (e.g., a deleted S3 bucket, a modified IAM role, or a resource in an inconsistent state), then use the ContinueUpdateRollback API to resume the rollback and bring the stack to UPDATE_ROLLBACK_COMPLETE.

Exam trap

The trap is assuming CloudFormation will self-heal or that a new update can override the failure — candidates often pick 'wait' or 'delete and recreate,' but the correct first step is always to fix the resource and continue the rollback.

How to eliminate wrong answers

Option B is wrong because CloudFormation does not automatically retry a failed rollback — the stack remains stuck in UPDATE_ROLLBACK_FAILED until manual intervention. Option C is wrong because you cannot perform a new stack update while the stack is in UPDATE_ROLLBACK_FAILED; the stack must first be returned to a stable state. Option D is wrong because deleting and recreating the stack is destructive, loses resource state, and is unnecessary when the rollback can be continued after fixing the resource.

168
MCQhard

A company runs a critical production workload on a fleet of EC2 instances managed by an Auto Scaling group. The instances are behind an Application Load Balancer (ALB). Recently, the company experienced a regional outage that caused all instances to become unhealthy. The SysOps administrator must design a solution to automatically recover from such an outage with minimal downtime. The solution must be cost-effective and not require manual intervention. The administrator considers four options. Which option meets the requirements?

A.Configure the Auto Scaling group to launch instances across multiple Availability Zones and configure the ALB to route traffic to healthy targets.
B.Increase the desired capacity of the Auto Scaling group and use larger instance types to absorb the load during failover.
C.Create a warm standby environment in another AWS Region with a smaller Auto Scaling group. Use Route53 failover routing to switch traffic.
D.Use AWS Lambda to periodically check the health of instances and automatically relaunch failed instances in another region.
AnswerC

A warm standby in a second Region with a smaller Auto Scaling group keeps capacity running at reduced cost, and Route 53 failover routing redirects traffic automatically when health checks fail. This satisfies the regional-outage, minimal-downtime and no-manual-intervention requirements.

Why this answer

A regional outage takes down all Availability Zones in a Region, so only a cross-Region strategy can recover. A warm standby environment in another Region with a smaller Auto Scaling group, combined with Route 53 failover routing, provides automatic, low-downtime recovery without manual intervention. This is the AWS-recommended pattern for regional resilience and is more cost-effective than a fully active-active multi-Region deployment.

Exam trap

SOA-C02 often tests the misconception that multi-AZ equals multi-Region — candidates must recognize that only cross-Region designs survive a full regional outage.

How to eliminate wrong answers

Option A is wrong because spreading instances across multiple AZs within a single Region does not protect against a regional outage — all AZs in the affected Region would still be down. Option B is wrong because increasing capacity and instance size within the same Region does nothing for regional failure and increases cost without improving resilience. Option D is wrong because a Lambda health-checker that relaunches instances in another Region is not a supported or reliable failover mechanism — it lacks DNS integration, capacity pre-provisioning, and would introduce significant downtime and complexity.

169
MCQmedium

A company uses AWS CodePipeline to deploy a web application. The pipeline has a source stage (Amazon S3) and a deploy stage (AWS Elastic Beanstalk). The SysOps administrator needs to add a manual approval step before the deployment proceeds to the production environment. Which action should the administrator take?

A.Add an approval stage in the pipeline using the Amazon SNS topic as a notification method.
B.Add a manual approval action in the pipeline using the AWS CodePipeline approval action type.
C.Use an AWS CloudFormation change set to require manual approval.
D.Create a separate pipeline for production and trigger it manually.
AnswerB

CodePipeline has a native manual approval action with the category "Approval" that can be inserted into any stage. When configured, this action pauses the pipeline and waits for an authorized user to approve or reject the deployment via the console, CLI, or PutApprovalResult API call. You can optionally attach an SNS topic to send notifications to approvers, but the verification step is enforced by the Approval action itself, making this the correct way to implement a manual gate within the existing pipeline.

Why this answer

AWS CodePipeline natively supports a manual approval action type that can be added as a stage in the pipeline. This action pauses the pipeline execution until an authorized user manually approves or rejects the deployment, allowing the SysOps administrator to gate the deployment to the production environment without external services.

Exam trap

The trap here is that candidates may confuse notification mechanisms (like SNS) with the actual approval action, or assume that external tools like CloudFormation change sets can serve as manual approval gates within a pipeline.

How to eliminate wrong answers

Option A is wrong because while Amazon SNS can be used to notify approvers, the approval action itself must be the CodePipeline approval action type; adding an SNS topic alone does not create a manual approval gate. Option C is wrong because AWS CloudFormation change sets are used to review infrastructure changes before execution, not to add manual approval steps within a CodePipeline deployment workflow. Option D is wrong because creating a separate pipeline for production and triggering it manually bypasses the automated pipeline integration and does not add a manual approval step within the existing pipeline.

170
Multi-Selecthard

Which TWO actions should a SysOps administrator take to automate the deployment of a multi-tier application with AWS CloudFormation? (Choose two.)

Select 2 answers
A.Hardcode CIDR blocks and instance types to avoid parameter input
B.Use nested stacks to separate concerns such as network, app, and database
C.Use AWS::Include to reuse snippets instead of parameters
D.Use cross-stack references to pass outputs between stacks
E.Define all resources in a single template to simplify management
AnswersB, D

Nested stacks are the correct way to separate concerns because they allow you to break a large, monolithic infrastructure into smaller, reusable template components—for example, one nested stack for the VPC/network layer, another for the application layer, and another for the database layer. Each nested stack is treated as a CloudFormation resource within the root stack, so you can deploy, update, and roll back the entire architecture from a single root stack while still isolating failures and reusing templates across multiple environments. This modularity improves manageability, makes the stack more readable, and aligns with best practices for infrastructure as code.

Why this answer

Option B is correct because nested stacks let you decompose a multi-tier application into reusable, independently managed templates (for example, a network stack, an application stack, and a database stack), which CloudFormation deploys as a parent stack with AWS::CloudFormation::Stack resources and promotes separation of concerns and reuse. Option D is correct because cross-stack references via Export in an Outputs section and Fn::ImportValue allow one stack to consume another stack's outputs (such as a VPC ID or subnet IDs), enabling modular, loosely coupled templates that pass values between stacks without hardcoding. Option A is wrong because hardcoding CIDR blocks and instance types reduces reusability and portability; parameters (with defaults and constraints) are the proper mechanism for environment-specific inputs.

Option C is wrong because AWS::Include is a transform for inserting template snippets from S3 at deployment time, not a substitute for parameters, and it does not by itself provide the modular stack separation needed here. Option E is wrong because defining every resource in a single template creates a monolithic, hard-to-maintain stack and prevents the independent lifecycle management that nested stacks and cross-stack references provide.

Exam trap

SOA-C02 often tests the confusion between AWS::Include (snippet reuse) and nested stacks (full stack modularity), leading candidates to pick AWS::Include when separation of concerns is required.

171
MCQmedium

Refer to the exhibit. A SysOps administrator ran the describe-stack-events command for a CloudFormation stack named 'my-stack'. The stack creation failed with 'Resource creation cancelled'. What is the most likely reason?

A.The stack creation was manually cancelled by the administrator.
B.The IAM role for the stack does not have sufficient permissions.
C.The nested stack creation failed due to an invalid template.
D.The nested stack creation timed out and was cancelled.
AnswerD

Nested stacks can specify a TimeoutInMinutes property, and if the nested stack does not complete within that window, CloudFormation cancels the in-progress creation. When this happens, the event stream for the nested stack resource in the parent stack shows a 'Resource creation cancelled' status, which then triggers a rollback of the parent stack. This exactly matches the exhibited event pattern, making it the correct interpretation.

Why this answer

When a CloudFormation stack creation fails with 'Resource creation cancelled', it typically indicates that a nested stack creation was cancelled due to a timeout. CloudFormation sets a default timeout of 60 minutes for stack creation; if a nested stack does not complete within that period, the parent stack cancels the nested stack creation and reports this error. This is distinct from manual cancellation, which would show a different status.

Exam trap

The trap here is that candidates confuse 'Resource creation cancelled' with manual cancellation or permission errors, but the specific phrasing indicates a timeout scenario, which is a common pitfall in nested stack troubleshooting.

How to eliminate wrong answers

Option A is wrong because manual cancellation by the administrator would result in a 'DELETE_IN_PROGRESS' or 'ROLLBACK_IN_PROGRESS' status, not 'Resource creation cancelled'. Option B is wrong because insufficient IAM permissions would cause an 'AccessDenied' or 'InsufficientCapabilities' error, not a 'Resource creation cancelled' message. Option C is wrong because an invalid template in a nested stack would produce a 'TemplateValidationError' or 'ValidationError' during creation, not a timeout-based cancellation.

172
MCQhard

A CloudFormation stack manages an RDS database, an S3 bucket, and several Lambda functions. During a recent stack update, a property change caused CloudFormation to replace the RDS instance, deleting the database and re-creating it — resulting in data loss. The team wants to prevent any future stack update from replacing or deleting the RDS instance without an explicit override. What CloudFormation feature accomplishes this?

A.Set a stack policy that denies Replace and Delete actions on the RDS resource; require an override policy to be explicitly provided when a replacement is intentional
B.Enable deletion protection on the RDS instance to prevent CloudFormation from deleting it
C.Use CloudFormation change sets to preview the update and manually reject any change set that includes a replacement
D.Add a DeletionPolicy: Retain attribute to the RDS resource in the template
AnswerA

The stack policy evaluates each update action per resource. A Deny on Replace for the RDS logical resource ID prevents CloudFormation from completing any update that would recreate the database — the update fails with a clear policy error. A temporary override policy passed via --stack-policy-during-update can explicitly allow the replacement for a deliberate migration.

Why this answer

A CloudFormation stack policy can explicitly deny Update (which includes replacement) and Delete actions on specific resources, such as the RDS instance. To intentionally perform a replacement, the user must provide an override stack policy during the update that allows the action, ensuring that no accidental replacement occurs without explicit consent.

Exam trap

The trap here is that candidates confuse RDS deletion protection or DeletionPolicy: Retain with stack policies, mistakenly believing those features can block CloudFormation from replacing a resource during an update, when in fact they only protect against deletion in specific scenarios (e.g., stack deletion or direct API calls).

How to eliminate wrong answers

Option B is wrong because RDS deletion protection prevents the database from being deleted via the RDS API or console, but CloudFormation can still replace the instance (which involves creating a new one and deleting the old one) if the template triggers a replacement; deletion protection does not block CloudFormation from performing a replacement. Option C is wrong because change sets only provide a preview of changes and require manual approval, but they do not prevent a user from accidentally executing a change set that includes a replacement; the team wants a guardrail that blocks replacement without an explicit override, not just a manual review step. Option D is wrong because DeletionPolicy: Retain only preserves the resource when the stack is deleted, but it does not prevent CloudFormation from replacing the resource during a stack update; a replacement still deletes the original resource and creates a new one, and the Retain policy does not block that deletion.

173
MCQeasy

A SysOps administrator uses AWS CloudFormation to deploy a three-tier application. The administrator has a single template that can be used for development, test, and production environments. The only differences between environments are the EC2 instance type and the RDS DB instance class. Which CloudFormation feature should the administrator use to define these environment-specific values without duplicating the template?

A.Parameters
B.Conditions
C.Mappings
D.Outputs
AnswerA

Parameters are the only mechanism in CloudFormation that lets you pass custom values, such as instance types or DB classes, directly into a template at the time you create or update a stack. By declaring a parameter in the template, AWS CloudFormation prompts the user (or accepts from CLI/API) for a value, which can then be referenced using Ref or Fn::Sub within the template. This makes the same template reusable across multiple environments, like Development and Production, by simply supplying different parameter values on each deployment.

Why this answer

Parameters allow you to input environment-specific values (e.g., EC2 instance type, RDS DB instance class) at stack creation or update time without modifying the template. This is the correct feature because the question explicitly requires defining values that differ per environment while reusing a single template.

Exam trap

The trap here is that candidates confuse Conditions (which toggle resource creation) with Parameters (which supply variable values), leading them to think Conditions can handle environment-specific instance types when they cannot.

How to eliminate wrong answers

Option B (Conditions) is wrong because conditions control whether to create or include specific resources or properties based on a condition (e.g., environment type), but they cannot inject variable values like instance types; they only toggle existence. Option C (Mappings) is wrong because mappings provide static lookup tables (e.g., mapping environment names to instance types) but require hardcoded keys and values in the template, which still requires template duplication if the values change per deployment; parameters are more flexible for runtime input. Option D (Outputs) is wrong because outputs are used to return information about the stack (e.g., endpoint URLs) after creation, not to define input values for resources.

174
MCQeasy

An organization uses AWS Service Catalog to manage approved IT services. A SysOps administrator needs to update a CloudFormation template used by a product. The administrator wants to ensure that existing provisioned products are updated with the new template version. What step must the administrator take after updating the product?

A.Update the portfolio that contains the product.
B.Create a new product version and update the provisioned products to use the new version.
C.Update the product's CloudFormation template directly in the Service Catalog console.
D.Terminate the existing provisioned products and reprovision them.
AnswerB

To update an existing provisioned product, you must create a new product version in AWS Service Catalog, typically by uploading a new CloudFormation template. Once the version is available, you then use the console or AWS CLI to update each provisioned product to the new version, which triggers CloudFormation change sets to apply only the necessary modifications. This preserves the resource lifecycle and minimizes disruption while ensuring your approved infrastructure is updated consistently.

Why this answer

After updating a CloudFormation template used by an AWS Service Catalog product, the administrator must create a new product version and then update the existing provisioned products to use that new version. Service Catalog versions are immutable — you cannot edit an existing version in place. Existing provisioned products continue using the version they were launched with until explicitly updated, so the administrator must both publish the new version and perform the update on each provisioned product.

Exam trap

SOA-C02 often tests the misconception that editing a product or portfolio automatically updates existing provisioned products, when in fact Service Catalog requires explicit version creation and provisioned-product updates.

How to eliminate wrong answers

Option A is wrong because updating the portfolio only changes which products and principals have access; it does not push a new template version to existing provisioned products. Option C is wrong because you cannot edit a product's CloudFormation template directly in the Service Catalog console — templates are sourced from an S3 URL or CodeCommit, and changes require a new product version. Option D is wrong because terminating and reprovisioning would cause downtime and data loss, and it is not the required step; Service Catalog supports in-place updates to a new version.

175
MCQmedium

A SysOps administrator uses AWS CloudFormation to deploy infrastructure. The administrator has a template that creates an Amazon EC2 instance and an Amazon RDS DB instance. The administrator needs to reuse the same template for development, test, and production environments, where the only differences are the EC2 instance type and the RDS DB instance class. Which CloudFormation feature should be used to define these environment-specific values?

A.Mappings
B.Conditions
C.Parameters
D.Outputs
AnswerC

Parameters are the CloudFormation feature designed to accept input values from the user at stack creation or update time. The template can reference parameters using the Ref intrinsic function, and you can define constraints such as AllowedValues, Default, and MinLength/MaxLength to control the input. By declaring parameters for the instance type and DB class, the SysOps administrator can deploy the same template to multiple environments simply by providing different parameter values, which is the most flexible and maintainable approach for this requirement.

Why this answer

Parameters are the correct CloudFormation feature to define environment-specific values because they allow you to input custom values (e.g., EC2 instance type and RDS DB instance class) at stack creation or update time without modifying the template. This enables reuse of the same template across development, test, and production environments by simply passing different parameter values for each environment.

Exam trap

The trap here is that candidates often confuse Parameters with Mappings, thinking Mappings can handle environment-specific values, but Mappings are static and cannot accept runtime input, whereas Parameters are designed exactly for this purpose.

How to eliminate wrong answers

Option A is wrong because Mappings are static lookup tables used to define fixed key-value pairs (e.g., mapping AWS regions to AMI IDs) and cannot accept dynamic user input per environment. Option B is wrong because Conditions control whether certain resources or properties are created based on logical expressions (e.g., create a resource only in production), but they do not define variable values like instance types. Option D is wrong because Outputs are used to return information about the created stack (e.g., endpoint URLs or resource IDs) and cannot be used to pass input values into the template.

176
MCQeasy

A SysOps administrator wants to automate the creation of an Amazon RDS MySQL instance using AWS CloudFormation. Which CloudFormation resource type should be used?

A.AWS::RDS::DBInstance
B.AWS::DynamoDB::Table
C.AWS::AppStream::DirectoryConfig
D.AWS::Redshift::Cluster
AnswerA

This CloudFormation resource directly creates and manages an Amazon RDS database instance, supporting engines such as MySQL, PostgreSQL, MariaDB, Oracle, and SQL Server. You can specify the DB engine, instance class, storage, Multi-AZ configuration, and network placement in a VPC, all within the resource properties. Because the goal is to automate provisioning of an RDS database, AWS::RDS::DBInstance is the correct resource type.

Why this answer

AWS CloudFormation uses resource types to define infrastructure components. For an Amazon RDS MySQL instance, the correct resource type is `AWS::RDS::DBInstance`, which directly maps to creating and configuring a relational database instance, including engine selection (MySQL), allocated storage, and backup settings. This resource type supports all RDS engines and is the standard way to provision RDS databases via CloudFormation.

Option A is correct because `AWS::RDS::DBInstance` is the appropriate resource for creating an RDS MySQL instance. Option B is incorrect because `AWS::DynamoDB::Table` is for Amazon DynamoDB, a NoSQL database service, not a relational MySQL database. Option C is incorrect because `AWS::AppStream::DirectoryConfig` is used for Amazon AppStream 2.0 directory configuration, unrelated to RDS.

Option D is incorrect because `AWS::Redshift::Cluster` is for Amazon Redshift, a data warehouse service, not a relational MySQL database.

Exam trap

The trap here is that candidates may confuse RDS with other database services like DynamoDB or Redshift, or incorrectly assume that a generic 'database' resource exists, when in fact each AWS database service has its own distinct CloudFormation resource type.

How to eliminate wrong answers

Option B is wrong because `AWS::DynamoDB::Table` is used for NoSQL tables in Amazon DynamoDB, not for relational MySQL databases. Option C is wrong because `AWS::AppStream::DirectoryConfig` is used to configure Active Directory for Amazon AppStream 2.0 streaming instances, unrelated to database provisioning. Option D is wrong because `AWS::Redshift::Cluster` provisions Amazon Redshift data warehouse clusters, which use a different engine (PostgreSQL-based) and are not suitable for a standard MySQL RDS instance.

177
MCQmedium

A SysOps administrator is troubleshooting a failed AWS Elastic Beanstalk environment update. The update changed the configuration of the EC2 instances in the Auto Scaling group, but the new instances fail to launch. The administrator checks the Auto Scaling group's scaling activities and sees a 'Failed' status with the message: 'Instance failed to reach the desired state.' What should the administrator check next?

A.Check the IAM role attached to the environment's EC2 instances for missing permissions.
B.Check the account service quotas for EC2 instances.
C.Check the CloudWatch logs for the failed instance to identify application or configuration errors.
D.Check the termination protection setting on the Auto Scaling group.
AnswerC

The Auto Scaling message indicates the instance launched but failed its health checks, so the fault lies in bootstrap or application configuration rather than capacity. CloudWatch logs from the failed instance expose those errors, satisfying the need to find why instances never reached the desired state.

Why this answer

When Elastic Beanstalk instances fail to launch with 'Instance failed to reach the desired state,' the next step is to examine the instance's logs (via CloudWatch Logs or the EB console's logs bundle) to identify configuration or application errors. This message typically indicates the instance launched but failed health checks or initialization, so logs reveal the root cause.

Exam trap

The trap is jumping to IAM or quota issues — the specific message 'failed to reach desired state' points to instance-level health/configuration problems best diagnosed via logs.

How to eliminate wrong answers

Option A is wrong because missing IAM permissions would typically cause a different error (e.g., launch failure at the API level), and the message indicates the instance reached a state but did not become healthy — logs are more direct. Option B is wrong because service quotas would prevent instance launch entirely with a quota-exceeded error, not a 'failed to reach desired state' message. Option D is wrong because termination protection affects instance termination, not launch or health state.

178
MCQeasy

A SysOps administrator needs to deploy a new application version to an Auto Scaling group without causing any downtime. The application runs on EC2 instances behind an Application Load Balancer. Which deployment method should the administrator use?

A.Perform an in-place update by updating the launch template and manually replacing instances one by one.
B.Use a rolling update with a batch size of 100% of the instances.
C.Use a rolling update with a batch size of 1 instance and enable the health check grace period.
D.Create a new Auto Scaling group with the new launch template and gradually shift traffic using a load balancer target group.
AnswerC

A rolling update with a batch size of one uses AWS Instance Refresh to replace one instance at a time while keeping the remaining instances online. The health check grace period delays the start of health checks for newly launched instances, preventing them from being terminated before the application has fully initialized. This approach maintains the group's desired capacity and availability throughout the deployment, satisfying the zero-downtime requirement. It is the AWS-recommended way to update an Auto Scaling group with a new launch template without manual intervention or traffic loss.

Why this answer

A rolling update with a batch size of 1 instance replaces instances one at a time, ensuring that the Auto Scaling group always maintains the desired capacity minus one, which prevents downtime. Enabling the health check grace period allows the new instance to pass the ALB health checks before the next instance is terminated, ensuring traffic is only sent to healthy instances.

Exam trap

The trap here is that candidates often confuse a rolling update with a batch size of 100% (which causes downtime) with a blue/green deployment (Option D), but the question specifically asks for a deployment to an existing Auto Scaling group, making the rolling update with a small batch size the correct choice.

How to eliminate wrong answers

Option A is wrong because manually replacing instances one by one is not a built-in Auto Scaling deployment method and risks downtime if the launch template update is applied without proper orchestration, as the Auto Scaling group does not automatically manage the replacement. Option B is wrong because a rolling update with a batch size of 100% of the instances terminates all instances at once, causing downtime since no instances remain to serve traffic during the replacement. Option D is wrong because creating a new Auto Scaling group and gradually shifting traffic using a load balancer target group is a blue/green deployment, which is valid but not the method specified in the question; the question asks for a deployment method to an existing Auto Scaling group, not a separate group.

179
MCQhard

A company uses AWS CloudFormation to deploy a multi-tier application. The template includes an AWS::RDS::DBInstance resource. The administrator wants to ensure that the database is not deleted when the stack is deleted. Which CloudFormation resource property should be set?

A.Set the 'DeletionPolicy' attribute to 'Retain' on the DBInstance resource.
B.Set the 'DeletionPolicy' attribute to 'Snapshot' on the DBInstance.
C.Set the 'RetainOnDeletion' property to 'true' on the DBInstance.
D.Set the 'DeletionProtection' property to 'true' on the DBInstance.
AnswerA

Setting the DeletionPolicy attribute to Retain on the AWS::RDS::DBInstance resource is the correct way to prevent CloudFormation from deleting the database when the stack is removed. With this attribute, CloudFormation simply abandons the resource, leaving the DB instance intact and running, though it no longer manages it. This is the intended mechanism for preserving RDS instances during stack teardown.

Why this answer

The 'DeletionPolicy' attribute in AWS CloudFormation controls what happens to a resource when its stack is deleted. Setting 'DeletionPolicy' to 'Retain' on the AWS::RDS::DBInstance resource ensures the database is preserved and not deleted when the stack is deleted. This is the standard mechanism for preventing accidental deletion of critical resources during stack teardown.

Exam trap

The trap here is that candidates confuse the RDS-specific 'DeletionProtection' property with CloudFormation's 'DeletionPolicy' attribute, assuming that enabling deletion protection on the database will prevent CloudFormation from deleting it, but CloudFormation's stack deletion bypasses that protection unless the DeletionPolicy is set to 'Retain'.

How to eliminate wrong answers

Option B is wrong because 'Snapshot' on the DeletionPolicy creates a final snapshot before deleting the DB instance, but it does not prevent deletion; the database is still removed. Option C is wrong because 'RetainOnDeletion' is not a valid CloudFormation resource property for AWS::RDS::DBInstance; the correct attribute is 'DeletionPolicy'. Option D is wrong because 'DeletionProtection' is a property of the RDS DB instance itself that prevents deletion via the console or API, but it does not override CloudFormation's stack deletion behavior; CloudFormation can still delete the resource if the DeletionPolicy is not set to 'Retain'.

180
Multi-Selecthard

A company is deploying a microservices application on AWS using Amazon ECS with Fargate launch type. The SysOps administrator needs to automate the deployment process so that when a new Docker image is pushed to Amazon ECR, the ECS service is updated with the new image. Which THREE AWS services should be used together to achieve this? (Choose THREE.)

Select 3 answers
A.AWS CloudFormation
B.AWS CodePipeline
C.Amazon Elastic Container Registry (ECR)
D.Amazon Elastic Container Service (ECS)
E.AWS Systems Manager
AnswersB, C, D

AWS CodePipeline is the fully managed CI/CD orchestrator for exactly this scenario. You can configure an ECR source action that listens for new image pushes, then run build/test stages, and finally use the ECS deployment action (with imagedefinitions.json) to update an ECS service. It automatically creates the task definition revision and applies rolling updates to containers, making it the correct component for continuous delivery.

Why this answer

The correct combination to automate deployment when a new Docker image is pushed to Amazon ECR is AWS CodePipeline, Amazon ECR, and Amazon ECS. CodePipeline orchestrates the CI/CD pipeline triggered by an ECR push event. ECR stores the Docker images.

ECS with Fargate runs the containers and updates the service with the new image. Option A (CloudFormation) is for infrastructure provisioning, not continuous deployment. Option E (Systems Manager) is for management and operations, not CI/CD.

181
MCQhard

A SysOps administrator wants to automate the deployment of an application to an EC2 instance. The instance is running, but the deployment script fails because the instance is not reachable via SSH. The administrator checks the instance state as shown in the exhibit. What should the administrator check NEXT to troubleshoot the SSH connectivity issue?

A.Check the security group rules to ensure SSH (port 22) is allowed from the administrator's IP.
B.Verify the instance is in a public subnet with an internet gateway.
C.Verify the instance ID is correct.
D.Check if the instance is in a stopped state.
AnswerA

Security groups act as a stateful virtual firewall at the instance level. If no inbound rule permits TCP 22 from your public IP address, all SSH packets are silently dropped, causing the connection to time out even when the instance is running, has a public IP, and is in a public subnet. The correct remediation is to add a rule that allows SSH (port 22) from your specific IP or CIDR block.

Why this answer

When an EC2 instance is running but SSH is unreachable, the most common cause is that the security group does not permit inbound TCP/22 from the administrator's source IP. Security groups are stateful virtual firewalls evaluated before traffic reaches the instance, so a missing or overly restrictive SSH rule silently drops the connection attempt. Checking the security group's inbound rules is the correct next troubleshooting step after confirming the instance is running.

Exam trap

SOA-C02 often tests the instinct to jump to subnet/IGW checks — the trap is overlooking that security groups are the first and most common blocker for SSH, and candidates pick the 'network architecture' answer when the simpler firewall rule check is correct.

How to eliminate wrong answers

Option B is wrong because although a public subnet with an internet gateway is required for direct SSH from the internet, the exhibit already shows the instance is running and the administrator is troubleshooting connectivity — verifying subnet/IGW is a secondary check and not the most likely cause when the instance is otherwise reachable. Option C is wrong because verifying the instance ID is a basic sanity check that would have surfaced immediately; an incorrect instance ID would mean the administrator is looking at the wrong resource entirely, not a connectivity problem. Option D is wrong because the question states the instance is running, so checking for a stopped state contradicts the given scenario and wastes a troubleshooting step.

182
MCQmedium

A company uses AWS Organizations with multiple member accounts. The SysOps administrator needs to deploy a common AWS CloudFormation template that creates an IAM role across all member accounts in the organization. Which AWS service should be used to deploy this template across accounts?

A.AWS CloudFormation StackSets
B.AWS CodePipeline with cross-account deployment actions
C.AWS CloudFormation cross-stack references
D.AWS Service Catalog
AnswerA

AWS CloudFormation StackSets is the correct answer because it is the native, purpose-built service for deploying the same CloudFormation template across multiple AWS accounts and Regions from a single operation. StackSets uses a delegated administrator account to create stack instances in target accounts with optional automatic deployment and drift detection, and it supports organizational unit (OU) targeting directly through AWS Organizations. This makes it the most efficient and maintainable way to enforce consistent infrastructure, such as security baselines, across an entire organization.

Why this answer

AWS CloudFormation StackSets is the correct service because it extends CloudFormation functionality to deploy templates across multiple accounts and regions from a single management account. StackSets uses a self-managed or service-managed permission model, and with AWS Organizations, it can automatically deploy to all member accounts in the organization or specified organizational units (OUs), making it ideal for deploying a common IAM role across all accounts.

Exam trap

The trap here is that candidates confuse AWS Service Catalog's ability to launch templates in individual accounts with automatic multi-account deployment, overlooking that StackSets is the only service designed for bulk, automated deployment across all organization accounts.

How to eliminate wrong answers

Option B (AWS CodePipeline with cross-account deployment actions) is wrong because CodePipeline orchestrates CI/CD pipelines and, while it can deploy to multiple accounts using cross-account actions, it requires manual setup of each target account and does not natively scale to all member accounts in an organization without additional custom logic. Option C (AWS CloudFormation cross-stack references) is wrong because cross-stack references (using Fn::ImportValue) allow sharing outputs between stacks within the same account or region, not deploying a template across multiple accounts. Option D (AWS Service Catalog) is wrong because Service Catalog enables end users to launch pre-approved products (CloudFormation templates) in their own accounts, but it does not automatically deploy a template across all member accounts; it requires users to provision the product individually.

← PreviousPage 3 of 3 · 182 questions total

Ready to test yourself?

Try a timed practice session using only Deployment, Provisioning, and Automation questions.