Courseiva
← Back to AWS Certified SysOps Administrator Associate SOA-C02 questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise AWS Certified SysOps Administrator Associate SOA-C02 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

15
scenario questions
SOA-C02
exam code
Amazon Web Services
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related SOA-C02 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1mediummultiple choice
Full question →

Refer to the exhibit. An IAM user has this policy attached. The user tries to start an EC2 instance that has no tags. What will happen?

Exhibit

Refer to the exhibit.

IAM Policy JSON:
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "ec2:RunInstances",
        "ec2:TerminateInstances",
        "ec2:StartInstances",
        "ec2:StopInstances"
      ],
      "Resource": "arn:aws:ec2:us-east-1:123456789012:instance/*",
      "Condition": {
        "StringEquals": {
          "ec2:ResourceTag/Environment": "Production"
        }
      }
    }
  ]
}
Question 2mediummultiple choice
Full question →

Refer to the exhibit. A SysOps administrator creates an IAM policy to allow an EC2 instance to upload objects to an S3 bucket. However, the instance is unable to upload objects. What is the MOST likely reason?

Exhibit

Refer to the exhibit.

```
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:PutObject",
      "Resource": "arn:aws:s3:::my-bucket/*"
    }
  ]
}
```
Question 3mediummultiple choice
Full question →

Refer to the exhibit. An EC2 instance is running the CloudWatch Logs agent and uses the IAM policy shown. The agent is configured to send logs to the log group 'MyAppLogGroup'. However, logs are not appearing. What is the MOST likely cause?

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "logs:PutLogEvents",
      "Resource": "arn:aws:logs:us-east-1:123456789012:log-group:MyAppLogGroup:*"
    },
    {
      "Effect": "Allow",
      "Action": "logs:CreateLogStream",
      "Resource": "arn:aws:logs:us-east-1:123456789012:log-group:MyAppLogGroup:*"
    }
  ]
}
Question 4easymultiple choice
Full question →

Refer to the exhibit. A SysOps administrator runs the 'list-metrics' command for CPUUtilization. Based on the output, what can the administrator conclude?

Network Topology
$ aws cloudwatch list-metricsnamespace AWS/EC2metric-name CPUUtilizationRefer to the exhibit.```"Metrics": ["Namespace": "AWS/EC2","MetricName": "CPUUtilization","Dimensions": ["Name": "InstanceId","Value": "i-1234567890abcdef0"},"Value": "i-0abcdef1234567890"
Question 5mediummultiple choice
Full question →

Refer to the exhibit. A SysOps administrator creates the CloudWatch Alarm shown. However, the alarm never enters ALARM state even though the CPU utilization of the EC2 instance is consistently above 90%. What is the most likely reason?

Exhibit

Refer to the exhibit.

CloudWatch Alarm configuration:
{
  "AlarmName": "HighCPU",
  "AlarmDescription": "Alarm if CPU exceeds 90% for 5 minutes",
  "MetricName": "CPUUtilization",
  "Namespace": "AWS/EC2",
  "Statistic": "Average",
  "Period": 60,
  "EvaluationPeriods": 5,
  "Threshold": 90,
  "ComparisonOperator": "GreaterThanThreshold",
  "AlarmActions": ["arn:aws:sns:us-east-1:123456789012:MyTopic"]
}
Question 6easymultiple choice
Full question →

Refer to the exhibit. An IAM role has the trust policy shown. Which entity can assume this role?

Network Topology
$ aws iam get-rolerole-name MyRoleRefer to the exhibit.AWS CLI output:"Role": {"Path": "/","RoleName": "MyRole","Arn": "arn:aws:iam::123456789012:role/MyRole","AssumeRolePolicyDocument": {"Version": "2012-10-17","Statement": ["Effect": "Allow","Principal": {"AWS": "arn:aws:iam::123456789012:root"},"Action": "sts:AssumeRole","Condition": {}"CreateDate": "2023-01-01T00:00:00Z"
Question 7mediummultiple choice
Full question →

Refer to the exhibit. A Lambda function is unable to write logs to CloudWatch Logs. The IAM role attached to the Lambda function includes the policy shown. What is the issue?

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "logs:PutLogEvents",
      "Resource": "arn:aws:logs:us-east-1:123456789012:log-group:/aws/lambda/MyFunction:*"
    }
  ]
}
Question 8hardmultiple choice
Full question →

Refer to the exhibit. A SysOps administrator runs the command and sees the output. The administrator then creates a CloudWatch alarm on the CPUUtilization metric for this instance, but the alarm state remains 'INSUFFICIENT_DATA'. What is a likely cause?

Network Topology
$ aws cloudwatch list-metricsnamespace AWS/EC2metric-name CPUUtilizationdimensions Name=InstanceIdRefer to the exhibit."Metrics": ["Namespace": "AWS/EC2","MetricName": "CPUUtilization","Dimensions": ["Name": "InstanceId","Value": "i-0abcd1234efgh5678"
Question 9mediummultiple choice
Full question →

A SysOps administrator is creating a CloudFormation stack and receives the error shown in the exhibit. The template snippet for the Auto Scaling group is:

"MyAutoScalingGroup": {
  "Type": "AWS::AutoScaling::AutoScalingGroup",
  "Properties": {
    "MinSize": "1",
    "MaxSize": "5",
    "DesiredCapacity": "2",

...

}
}
Network Topology
$ aws cloudformation describe-stack-eventsstack-name my-stackRefer to the exhibit."StackEvents": ["StackId": "arn:aws:cloudformation:us-east-1:123456789012:stack/my-stack/...","EventId": "Event-1","ResourceStatus": "CREATE_FAILED","ResourceType": "AWS::AutoScaling::AutoScalingGroup","Timestamp": "2024-01-01T00:00:00.000Z"
Question 10hardmultiple choice
Full question →

Refer to the exhibit. A SysOps administrator needs to restore the database 'mydb' to the most recent restorable time shown. However, the administrator cannot restore to that time. What is the MOST likely reason?

Network Topology
$ aws rds describe-db-instancesdb-instance-identifier mydbRefer to the exhibit.```"DBInstances": ["DBInstanceIdentifier": "mydb","DBInstanceClass": "db.t3.medium","Engine": "mysql","DBInstanceStatus": "available","MultiAZ": false,"ReadReplicaDBInstanceIdentifiers": [],"BackupRetentionPeriod": 0,"PreferredBackupWindow": "03:00-04:00","LatestRestorableTime": "2024-01-01T04:00:00Z","InstanceCreateTime": "2024-01-01T00:00:00Z"
Question 11easymultiple choice
Full question →

Refer to the exhibit. An application running on EC2 is using the AWS SDK to publish custom metrics to CloudWatch. The application fails to publish metrics. The IAM role attached to the EC2 instance has this policy. What is the issue?

Exhibit

Refer to the exhibit.

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Action": "cloudwatch:PutMetricData",
            "Resource": "*",
            "Condition": {
                "StringEquals": {
                    "cloudwatch:namespace": "MyApp"
                }
            }
        }
    ]
}
Question 12mediummultiple choice
Full question →

Refer to the exhibit. A SysOps administrator ran the commands shown. What is the state of the EC2 instance?

Network Topology
Command: aws ec2 describe-instancesinstance-ids i-1234567890abcdef0query 'Reservations[0].Instances[0].State'query 'InstanceStatuses[0].SystemStatus'Refer to the exhibit.Output:"Code": 16,"Name": "running""Status": "impaired","Details": ["Name": "reachability"
Question 13mediummultiple choice
Full question →

Refer to the exhibit. A company has a CloudTrail trail in us-east-1 that logs events for that region only. The company operates in multiple regions and wants to ensure all API calls from all regions are logged. What is the most efficient way to achieve this?

Network Topology
$ aws cloudtrail describe-trailstrail-name-list MyTrailRefer to the exhibit."trailList": ["Name": "MyTrail","S3BucketName": "my-cloudtrail-bucket","IncludeGlobalServiceEvents": true,"IsMultiRegionTrail": false,"HomeRegion": "us-east-1","TrailARN": "arn:aws:cloudtrail:us-east-1:123456789012:trail/MyTrail","LogFileValidationEnabled": true,"CloudWatchLogsLogGroupArn": "arn:aws:logs:us-east-1:123456789012:log-group:MyCloudTrailLogGroup:*","CloudWatchLogsRoleArn": "arn:aws:iam::123456789012:role/CloudTrail_CloudWatchLogs_Role","KmsKeyId": "arn:aws:kms:us-east-1:123456789012:key/abc12345-...","HasCustomEventSelectors": false,"IsOrganizationTrail": false
Question 14mediummultiple choice
Full question →

Refer to the exhibit. A SysOps administrator is troubleshooting a CloudFront distribution that serves content from an S3 bucket. Users are receiving 'Access Denied' errors when trying to access objects. The exhibit shows the distribution configuration. What is the most likely cause?

Network Topology
$ aws cloudfront get-distribution-configid E1A2B3C4D5E6F7Refer to the exhibit.```"ETag": "E3QEXAMPLE","DistributionConfig": {"CallerReference": "my-distribution","Aliases": {"Quantity": 1,"Items": ["www.example.com"]},"Origins": {"Items": ["Id": "my-origin","DomainName": "my-bucket.s3.us-east-1.amazonaws.com","S3OriginConfig": {"OriginAccessIdentity": """DefaultCacheBehavior": {"TargetOriginId": "my-origin","ViewerProtocolPolicy": "redirect-to-https","AllowedMethods": {"Quantity": 2,"Items": ["GET", "HEAD"],"CachedMethods": {"Items": ["GET", "HEAD"]"Compress": true"Enabled": true
Question 15mediummultiple choice
Full question →

Refer to the exhibit. The output shows the health status of two targets in a target group. One target is unhealthy with a 502 error. What is the most likely cause?

Network Topology
$ aws elbv2 describe-target-healthtarget-group-arn arn:aws:elasticloadbalancing:us-east-1:123456789012:targetgroup/my-tg/1234567890123456Refer to the exhibit.```"TargetHealthDescriptions": ["Target": {"Id": "i-0abcd1234efgh5678","Port": 80},"HealthCheckPort": "80","TargetHealth": {"State": "unhealthy","Id": "i-0abcd1234efgh5679","State": "healthy"

These SOA-C02 practice questions are part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style SOA-C02 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.