Courseiva

CCNA Soa Deployment Provisioning Questions

75 of 182 questions · Page 1/3 · Soa Deployment Provisioning topic · Answers revealed

1
MCQhard

A SysOps Administrator attempted to update a CloudFormation stack. The stack update failed and is now in UPDATE_ROLLBACK_IN_PROGRESS state as shown in the exhibit. What should the administrator do to recover the stack to a stable state?

A.Wait for the rollback to complete and then investigate the failure reason.
B.Delete the stack and recreate it.
C.Manually update the Auto Scaling group to correct the issue.
D.Execute a change set to fix the failed resource.
AnswerA

While the stack is in UPDATE_ROLLBACK_IN_PROGRESS, CloudFormation is automatically reverting resources to the last known good state. Any attempt to modify the stack—whether via delete, update, or change set execution—will be rejected because the stack is in a transient state. Once the rollback reaches UPDATE_ROLLBACK_COMPLETE, the Events tab in the AWS Console or describe-stack-events will show the exact failure reason (e.g., a parameter validation error or an EC2 resource failure). This diagnostic information is essential for correcting the template and retrying the update safely.

Why this answer

When a CloudFormation stack update fails and enters UPDATE_ROLLBACK_IN_PROGRESS, AWS CloudFormation is automatically rolling back the stack to its last known stable state. The administrator should wait for this rollback to complete, which will result in the stack returning to UPDATE_ROLLBACK_COMPLETE (or UPDATE_ROLLBACK_FAILED if rollback fails). After that, they can investigate the failure reason using stack events and then retry the update with corrections.

Exam trap

SOA-C02 often tests the misconception that manual intervention is needed during an in-progress rollback, when the correct action is to wait for CloudFormation to complete the rollback automatically.

How to eliminate wrong answers

Option B is wrong because deleting and recreating the stack would cause downtime and loss of resources, and it is unnecessary since CloudFormation can recover automatically. Option C is wrong because manually updating the Auto Scaling group would interfere with CloudFormation's management and could cause drift, making the stack inconsistent. Option D is wrong because executing a change set is not possible while the stack is in UPDATE_ROLLBACK_IN_PROGRESS; the stack must first reach a stable state.

2
MCQeasy

A SysOps administrator maintains an AWS CloudFormation stack that deploys an Amazon EC2 instance. The administrator needs to change the instance type from t2.micro to t3.micro. The administrator wants to review the proposed changes before applying them to ensure no unexpected resource replacement occurs. Which CloudFormation feature should the administrator use?

A.Use the AWS CloudFormation console to directly update the stack with the new instance type and monitor the events.
B.Create a change set from the updated template, review the changes, and then execute the change set.
C.Use the AWS CloudFormation drift detection feature to check for differences between the stack and the template.
D.Modify the CloudFormation template locally and use the AWS CLI to validate it with 'aws cloudformation validate-template'.
AnswerB

A change set is generated from an updated template against the current stack, providing a detailed, resource-by-resource summary of whether CloudFormation will add, modify, or replace resources. Because changing an EC2 instance type typically requires replacement, the change set would explicitly flag a "Replace" action, letting the administrator assess the impact and even cancel before executing. Only after reviewing and confirming the change set is it executed, and the execution applies the exact changes that were previewed.

Why this answer

A change set allows the administrator to review the proposed modifications (including whether any resource replacement will occur) before applying them. By creating a change set from the updated template, the administrator can inspect the list of changes, such as the instance type update, and confirm that no unexpected resource replacement (e.g., a new EC2 instance being created) will happen. Only after reviewing the change set can the administrator safely execute it to apply the changes.

Exam trap

The trap here is that candidates confuse change sets with drift detection or template validation, not realizing that change sets are specifically designed to preview the impact of stack updates before execution.

How to eliminate wrong answers

Option A is wrong because directly updating the stack via the console applies changes immediately without a review step, so the administrator cannot preview whether resource replacement will occur. Option C is wrong because drift detection compares the current stack resources against the expected template configuration to identify manual changes, not to preview proposed updates before applying them. Option D is wrong because 'aws cloudformation validate-template' only checks the syntax of the template, not the impact of changes on existing resources or whether replacement will occur.

3
MCQmedium

A company uses AWS CodeDeploy to deploy a web application to an Auto Scaling group. The deployment fails with the error 'The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available for deployment, or some instances in your deployment group are experiencing problems.' The deployment group has a minimum of 2 healthy instances. The Auto Scaling group has 4 instances. What should the SysOps administrator check first?

A.Review the deployment configuration to ensure it allows enough time for deployment.
B.Verify that the AppSpec file includes the correct hooks.
C.Check the Auto Scaling group's health check type and ensure it is set to ELB.
D.Check the IAM role for CodeDeploy to ensure it has sufficient permissions.
AnswerC

When CodeDeploy deploys to an Auto Scaling group, it relies on the group's health check type to determine whether each instance is healthy and to maintain the minimum healthy instance count. If the health check type is left as EC2 (the default), an instance is considered healthy solely because it is in the 'running' state — even if the deployed web application is not responding on the Elastic Load Balancer. Setting the health check to ELB forces the Auto Scaling group to use the load balancer's target health checks, which validate the actual application response. This directly affects the 'insufficient healthy instances' error, so checking and correcting this setting is the correct first step.

Why this answer

The error message indicates that too few healthy instances are available for deployment. In an Auto Scaling group integrated with CodeDeploy, the health check type must be set to ELB to allow CodeDeploy to use Elastic Load Balancing health checks to determine instance health. If the health check type is set to EC2 (default), CodeDeploy may consider instances healthy even when they are not passing ELB health checks, causing the deployment to fail due to insufficient healthy instances.

Exam trap

The trap here is that candidates often assume the error is due to a misconfigured AppSpec file or insufficient permissions, overlooking the critical integration between CodeDeploy and the Auto Scaling group's health check type, which directly controls how CodeDeploy counts healthy instances during deployment.

How to eliminate wrong answers

Option A is wrong because the error is about insufficient healthy instances, not about deployment timeout; adjusting the deployment configuration timeout would not resolve a health check mismatch. Option B is wrong because the AppSpec file hooks control lifecycle events (e.g., BeforeInstall, AfterInstall) but do not affect how CodeDeploy determines instance health or the minimum healthy hosts requirement. Option D is wrong because insufficient IAM permissions would typically result in an access denied or authorization error, not the specific 'too few healthy instances' error described.

4
MCQmedium

A SysOps administrator needs to deploy a web application across multiple AWS Regions for disaster recovery. The application uses Amazon RDS for MySQL and requires a secondary database in a different Region. What is the MOST cost-effective and automated solution to keep the databases synchronized?

A.Create a cross-Region read replica of the primary RDS instance in the secondary Region
B.Use AWS Database Migration Service (DMS) with ongoing replication
C.Set up a cron job on an EC2 instance to export the database and import it into the secondary Region
D.Enable Multi-AZ on the primary RDS instance and configure a read replica in the secondary Region
AnswerA

Amazon RDS cross-Region read replicas use asynchronous replication to continuously copy data from the primary MySQL instance to a read-only instance in a second AWS Region. In a disaster, you can promote the replica to become a standalone primary, providing a low RPO and RTO without custom scripts or manual database dumps. This is the managed, native, and cost-effective mechanism for cross-Region disaster recovery of RDS.

Why this answer

A cross-Region read replica of the primary RDS instance is the most cost-effective and automated solution because RDS natively replicates data asynchronously to the replica in another Region with minimal configuration. It requires no additional replication infrastructure or ongoing management, and it can be promoted to a standalone database during disaster recovery. This meets the requirement for automated, cost-effective cross-Region synchronization.

Exam trap

SOA-C02 often tests the confusion between Multi-AZ (same-Region HA) and cross-Region read replicas (DR), so candidates must recognize that Multi-AZ does not provide cross-Region replication.

How to eliminate wrong answers

Option B is wrong because AWS DMS with ongoing replication is more complex and costly, requiring replication instances and ongoing management, and is typically used for heterogeneous migrations or when native replication is unavailable. Option C is wrong because a cron job with export/import is manual, error-prone, not automated, and introduces significant data loss and downtime. Option D is wrong because Multi-AZ is a synchronous standby within the same Region for high availability, not cross-Region disaster recovery; adding a read replica in another Region is part of the correct solution but Multi-AZ itself does not provide cross-Region replication.

5
MCQhard

A team uses AWS CodeDeploy with a deployment configuration of CodeDeployDefault.OneAtATime to deploy a web application to an Auto Scaling group. Instances are behind an Application Load Balancer. The deployment fails with 'The overall deployment failed because too many individual instances failed deployment.' What is the most likely cause?

A.The health check grace period on the Auto Scaling group is too short.
B.The target group deregistration delay is too long.
C.The CodeDeploy agent is not installed on the instances.
D.The deployment group is configured to skip the ELB health check.
AnswerA

The health check grace period on the Auto Scaling group is too short. When a deployment launches new instances, the ASG considers an instance healthy only after the grace period expires; if the period is shorter than the time CodeDeploy needs to install the application and pass its own validation, the ASG will prematurely flag the instance as failing ELB health checks. Auto Scaling then terminates and replaces the instance mid-deployment, which CodeDeploy sees as a failed deployment ("too many individual instances"), and the cycle repeats for each new replacement. The correct fix is to increase the grace period to exceed the typical deployment duration.

Why this answer

The deployment fails because the health check grace period on the Auto Scaling group is too short. When CodeDeploy deploys one instance at a time (CodeDeployDefault.OneAtATime), the instance is taken out of service, updated, and then returned to the load balancer. If the grace period expires before the instance passes its health checks, the Auto Scaling group marks it as unhealthy and terminates it, causing the deployment to fail with 'too many individual instances failed.'

Exam trap

The trap here is that candidates often confuse the health check grace period with the deregistration delay or assume the issue is with the CodeDeploy agent, but the specific error 'too many individual instances failed' points to Auto Scaling terminating instances due to health check failures, not a deployment script or agent problem.

How to eliminate wrong answers

Option B is wrong because a long target group deregistration delay would cause traffic to continue flowing to instances being replaced, but it would not cause instances to be terminated by the Auto Scaling group; it delays the removal of instances from the target group but does not trigger deployment failure. Option C is wrong because if the CodeDeploy agent were not installed, the deployment would fail immediately with an agent connectivity error, not with 'too many individual instances failed' after partial success. Option D is wrong because skipping the ELB health check would prevent the load balancer from routing traffic to the instances, but it would not cause the Auto Scaling group to terminate instances; the deployment would likely succeed but with no traffic, not fail with this specific error.

6
MCQmedium

A company uses AWS CodePipeline to automate the deployment of a web application. The pipeline consists of a source stage (AWS CodeCommit) and a deploy stage (AWS CodeDeploy) that deploys to an Auto Scaling group. The SysOps administrator needs to add a stage to run automated unit tests before the deployment proceeds. The tests must be executed in an isolated environment, and if they fail, the pipeline must stop and notify the development team. Which action should the administrator take?

A.Add a manual approval action between the source and deploy stages. The development team will manually run the tests on their local machines and then approve the pipeline to proceed.
B.Insert a test stage after the source stage with an AWS CloudFormation action that deploys a test stack and runs tests using a custom resource Lambda function.
C.Add a stage between source and deploy that uses an AWS CodeBuild action to run unit tests defined in a buildspec file. The pipeline will automatically stop if the build action fails.
D.Add a Lambda function as an action in the pipeline that runs the unit tests. The Lambda function writes the test results to an S3 bucket, and a subsequent approval action checks the results.
AnswerC

CodeBuild is the ideal service for running automated tests in a controlled environment. It integrates natively with CodePipeline: if the CodeBuild build fails, the pipeline transitions to a failed state, stopping further execution and optionally sending notifications via Amazon SNS.

Why this answer

AWS CodeBuild is natively integrated with CodePipeline to run automated tests defined in a buildspec file. When the build action fails, CodePipeline automatically stops the pipeline execution and can send notifications via Amazon SNS, meeting the requirement for an isolated test environment and automatic failure notification without manual intervention.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing CloudFormation or Lambda, overlooking that CodeBuild is the native, simplest, and most cost-effective service for running automated tests within a CodePipeline.

How to eliminate wrong answers

Option A is wrong because it relies on manual approval and local test execution, which violates the requirement for automated tests in an isolated environment and does not provide automatic pipeline stop on test failure. Option B is wrong because using a CloudFormation action to deploy a test stack and run tests via a custom Lambda function adds unnecessary complexity, cost, and latency; it also does not natively integrate with CodePipeline's failure handling as cleanly as CodeBuild. Option D is wrong because a Lambda function action in CodePipeline cannot directly run unit tests in an isolated environment; it would require custom orchestration, and the subsequent approval action would not automatically stop the pipeline on failure—it would only pause for manual review.

7
Multi-Selecthard

An organization uses AWS CloudFormation to manage its infrastructure. The SysOps administrator is implementing a change management process that requires all stack updates to be reviewed and approved before execution. The administrator wants to use CloudFormation change sets to preview changes. Which THREE steps are necessary to implement this process? (Choose THREE.)

Select 3 answers
A.Use the 'Detect Drift' feature to compare the stack with the new template.
B.Update the stack directly using the updated template.
C.Review the change set in the CloudFormation console.
D.Execute the change set after approval.
E.Create a change set from the updated template.
AnswersC, D, E

Reviewing the change set in the CloudFormation console provides a human-readable summary of each resource action (add, modify, or delete) and whether a resource will be replaced. This step allows the administrator to spot potential risks like data loss from deletion or replacement before approving the change set. It is the required review step in a change management workflow, and it directly informs the decision to execute or reject the change set.

Why this answer

To implement a review-and-approval process using CloudFormation change sets, the necessary steps are: create a change set from the updated template (E), review the change set in the CloudFormation console (C), and execute the change set after approval (D). Option A is incorrect because the 'Detect Drift' feature is used to check if the actual stack resources have drifted from the template, not to preview changes. Option B is incorrect because updating the stack directly bypasses the review process, which defeats the purpose of change management.

8
MCQeasy

A CloudFormation template launches an EC2 instance with the user data script shown. The instance launches successfully but the web server does not serve PHP pages. What is the MOST likely reason?

A.The script does not install PHP.
B.The script does not have execute permissions.
C.The CloudFormation template is missing a DependsOn clause for the instance.
D.The user data script is not base64 encoded correctly.
AnswerA

The script does not install PHP. The user data script likely installs and starts the Apache HTTP server, but it omits the installation of the PHP package (or the Apache PHP module). Without the PHP package, Apache cannot interpret and execute PHP files; it will either serve them as plain text or offer them for download, resulting in the PHP page not rendering correctly. The correct fix is to add a command that installs PHP, such as `yum install php` or `apt install php`, and then restart the Apache service so the module loads.

Why this answer

The user data script installs Apache (httpd) and starts the service but never installs PHP or the PHP module for Apache. Without PHP installed, Apache cannot serve .php files — it will either download them as plain text or return a 500 error. This makes option A the most likely reason.

Exam trap

SOA-C02 often tests whether candidates confuse user data execution mechanics (root, auto base64, cloud-init) with actual application configuration gaps — the script ran fine, it just didn't install PHP.

How to eliminate wrong answers

Option B is wrong because user data scripts on EC2 run as root via cloud-init, so execute permissions are not an issue — the script clearly ran since httpd was installed and started. Option C is wrong because DependsOn controls CloudFormation resource creation order, not in-instance software configuration; the instance launched successfully, so ordering is not the problem. Option D is wrong because CloudFormation automatically base64-encodes user data when passed via the AWS::EC2::Instance UserData property — manual encoding errors would prevent the script from running at all, but the script did run.

9
MCQhard

An organization has a requirement to automatically scale its web application based on a custom metric that measures the number of active user sessions stored in Amazon ElastiCache. The metric is published to CloudWatch every minute. The Auto Scaling group currently uses a simple scaling policy based on CPU utilization. What is the most effective way to implement scaling based on this custom metric?

A.Create a target tracking scaling policy that uses the custom metric as a target.
B.Create a step scaling policy that adjusts capacity based on the magnitude of the metric breach.
C.Create a scheduled scaling policy that increases capacity during peak hours.
D.Create a simple scaling policy that adds instances when the custom metric exceeds a threshold and removes when below.
AnswerA

With a target tracking scaling policy, you first publish a custom metric to CloudWatch (for example, ActiveUserSessions) and then define the policy with a target value such as 1000 sessions per instance. Amazon EC2 Auto Scaling continuously computes the required capacity to keep the metric near that target, proactively adding or removing instances without static thresholds or manually tuned cooldowns. This makes it ideal for a dynamic, session-based workload where the relationship between load and capacity is stable and predictable.

Why this answer

Target tracking scaling policies are purpose-built for metric-driven scaling: you specify a target value for a custom CloudWatch metric (e.g., active sessions per instance) and Auto Scaling automatically creates and manages the required CloudWatch alarms and scaling adjustments. This is the most effective approach because it continuously adjusts capacity to keep the metric at target, requires no manual alarm or step definition, and works with any metric published to CloudWatch, including custom ElastiCache session metrics.

Exam trap

SOA-C02 often tests the misconception that step scaling is 'more granular' and therefore better for custom metrics — the trap is overlooking that target tracking eliminates manual alarm/step management and is the recommended default for metric-driven scaling.

How to eliminate wrong answers

Option B is wrong because step scaling requires you to manually define CloudWatch alarms and step adjustments, adding operational overhead and not automatically tracking a target — it only reacts to breaches you pre-specify. Option C is wrong because scheduled scaling is time-based, not metric-based, so it cannot respond to real-time session counts. Option D is wrong because simple scaling is the legacy policy type that uses a single adjustment and cooldown, lacks the responsiveness of target tracking, and still requires manual alarm configuration.

10
MCQmedium

A company is deploying a new web application using AWS Elastic Beanstalk. The application requires a custom Amazon Machine Image (AMI) with specific software pre-installed. The SysOps administrator creates a custom AMI and configures Elastic Beanstalk to use it. However, during deployment, the instances fail to pass the health check. The health check endpoint is a simple 'index.html' file. What is the MOST likely cause?

A.The Elastic Beanstalk environment was created before the custom AMI was registered.
B.The custom AMI does not have a web server installed and configured to serve the application.
C.The custom AMI is not registered with the same account that owns the Elastic Beanstalk environment.
D.The custom AMI does not have the latest patches, causing the instance to fail the EC2 status checks.
AnswerB

The health check performed by Elastic Beanstalk is an HTTP request to the environment's health check path (typically / on port 80). If the custom AMI lacks a web server or the web server isn't configured to serve the application, the ELB health check receives a connection refused or non-2xx response, causing the instance to be marked unhealthy. Simply having a running EC2 instance is insufficient; the AMI must include the same web server and configuration as the standard Elastic Beanstalk platform AMI to serve traffic.

Why this answer

Elastic Beanstalk relies on the platform's web server (Apache, Nginx, IIS) to serve the application and respond to the health check endpoint. When you supply a custom AMI, you must ensure it includes the same web server and configuration that the chosen Beanstalk platform expects. If the AMI lacks a running web server on the expected port (e.g., port 80 for the default health check path '/'), the ELB health check will fail and instances will be marked unhealthy.

Exam trap

SOA-C02 often tests the misconception that health check failures are caused by patching, account ownership, or resource ordering, when in fact they almost always stem from the application or web server not responding on the expected port and path.

How to eliminate wrong answers

Option A is wrong because the timing of environment creation relative to AMI registration does not affect whether the instance can serve HTTP traffic; Beanstalk validates the AMI at launch time regardless of when the environment was created. Option C is wrong because AMIs are region-scoped but can be used across accounts within the same region if permissions allow; cross-account AMI usage is supported and would produce a launch error, not a health check failure. Option D is wrong because missing patches do not cause EC2 status checks or ELB health checks to fail — status checks verify hypervisor and network reachability, and the health check endpoint tests application response, neither of which depends on patch level.

11
MCQeasy

A SysOps administrator needs to deploy a new version of a web application to Amazon EC2 instances using AWS Elastic Beanstalk. The administrator wants to deploy the new version with zero downtime and validate the new version before routing production traffic to it. Which deployment policy should be used?

A.All at once
B.Rolling
C.Immutable
D.Traffic splitting
AnswerC

The immutable deployment policy launches a completely new set of instances with the new application version. Once healthy, the environment's CNAME is switched to the new instances, providing zero downtime and the ability to validate the new version before traffic is routed.

Why this answer

Immutable deployment is correct because it launches a completely new set of EC2 instances in a separate Auto Scaling group, deploys the new application version to them, and passes health checks before swapping the environment's CNAME record to point to the new instances. This ensures zero downtime and allows validation of the new version before any production traffic is routed to it, as the old instances remain untouched until the swap is complete.

Exam trap

The trap here is that candidates confuse 'Traffic splitting' with 'canary testing' and assume it allows pre-validation, but in Elastic Beanstalk, traffic splitting immediately routes a percentage of live traffic to the new version, whereas immutable deployment keeps all traffic on the old version until the new version is fully validated and swapped.

How to eliminate wrong answers

Option A is wrong because All at once deploys the new version to all instances simultaneously, causing downtime during the deployment and no ability to validate before traffic is routed. Option B is wrong because Rolling deploys the new version in batches across existing instances, which can cause a brief period of reduced capacity and does not allow full validation of the new version before all traffic is switched; it also does not guarantee zero downtime if health checks fail mid-batch. Option D is wrong because Traffic splitting (canary deployment) routes a percentage of traffic to the new version immediately, which does not allow validation before any production traffic is sent; it is designed for gradual traffic shifting, not pre-validation with zero initial traffic.

12
MCQeasy

A SysOps administrator wants to automate the creation of an AWS Lambda function and its associated IAM role using infrastructure as code. Which AWS service should be used?

A.AWS CloudFormation
B.AWS Elastic Beanstalk
C.AWS CodeDeploy
D.AWS Systems Manager
AnswerA

AWS CloudFormation is the native infrastructure-as-code service that lets you define the Lambda function, IAM role, and every related resource in a declarative JSON or YAML template. CloudFormation automatically handles resource dependencies, creation order, and rollback on failure, making it ideal for automating repeatable, consistent environments. It is the correct tool because you need to provision the resources themselves, not just deploy code to existing infrastructure.

Why this answer

AWS CloudFormation is the correct service because it allows you to define both the Lambda function and its IAM role as infrastructure as code using a template (JSON or YAML). CloudFormation handles the creation, updating, and deletion of these resources in an orderly, repeatable manner, ensuring the IAM role is created before the Lambda function due to dependency management.

Exam trap

The trap here is that candidates often confuse AWS CodeDeploy (which can deploy Lambda code) with the ability to create the Lambda function and its IAM role, but CodeDeploy does not provision the underlying infrastructure resources—it only handles the deployment of the code to an existing function.

How to eliminate wrong answers

Option B (AWS Elastic Beanstalk) is wrong because it is a PaaS service designed for deploying and scaling web applications, not for creating individual Lambda functions and IAM roles via infrastructure as code. Option C (AWS CodeDeploy) is wrong because it automates code deployments to EC2, Lambda, or on-premises instances, but it does not provision the underlying IAM roles or Lambda function resources; it only deploys the code. Option D (AWS Systems Manager) is wrong because it provides operational management and automation for AWS resources (e.g., patching, runbooks), but it is not designed for declarative infrastructure provisioning of Lambda functions and IAM roles.

13
MCQhard

A SysOps administrator updates a CloudFormation stack to change the EC2 instance type from t2.micro to t3.medium. The update fails with the error shown. What is the MOST likely cause?

A.The account does not have service limits to launch a t3.medium instance.
B.The AMI used does not support the t3.medium instance type.
C.The CloudFormation template has a parameter constraint that rejects t3.medium.
D.The t3.medium instance type is not available in the specified Availability Zone.
AnswerD

The error is exactly what AWS returns when you attempt to launch an EC2 instance with an instance type that is not available in the selected Availability Zone. Instance types are rolled out to AZs non-uniformly, so a t3.medium may exist in us-east-1a but not us-east-1b, for example. This is a resource-level launch failure rather than a template, account, or AMI problem.

Why this answer

The error indicates that the t3.medium instance type is not available in the specified Availability Zone (AZ). AWS instance types are offered on a per-AZ basis, and not all instance types are available in every AZ. When a CloudFormation stack update fails with this error, it typically means the template explicitly or implicitly specifies an AZ that does not support the target instance type.

Exam trap

The trap here is that candidates often confuse 'unavailable in AZ' with 'service limit exceeded' or 'AMI incompatibility', but the specific error message about instance type availability points directly to an AZ constraint.

How to eliminate wrong answers

Option A is wrong because service limits would cause a different error (e.g., 'LimitExceeded' or 'InsufficientInstanceCapacity'), not an 'unavailable instance type' error. Option B is wrong because AMI compatibility with instance types is generally about driver support (e.g., ENA or NVMe), and the error message does not reference AMI issues; an incompatible AMI would produce a launch failure, not an 'unavailable' error. Option C is wrong because parameter constraints in CloudFormation templates are evaluated during stack creation or update validation, and a constraint violation would produce a validation error (e.g., 'Value failed to satisfy constraint'), not an AZ availability error.

14
MCQmedium

A company is using AWS CloudFormation to manage infrastructure. They have a stack that creates an EC2 instance and an Elastic IP. The instance is in a VPC with an internet gateway. The stack creation succeeds, but the instance does not have internet connectivity. What is the most likely cause?

A.The subnet's route table does not have a route to the internet gateway.
B.The instance does not have a public IP address.
C.The instance is in a private subnet.
D.The security group does not allow outbound traffic.
AnswerA

Even when an instance has an Elastic IP and the VPC contains an internet gateway, the subnet's route table must include a default route (0.0.0.0/0) with the internet gateway as the target. Without that route, the instance cannot send traffic out to the internet because the IGW is the only mechanism that forwards VPC traffic to the outside world. In CloudFormation, if you create a custom route table but forget to add the IGW route or forget to associate the route table with the subnet, the subnet will use the VPC's main route table, which may not have the required route. This is the most direct and common cause of unreachable internet connectivity despite having a public IP.

Why this answer

For an EC2 instance in a VPC to reach the internet, three things are required: a public IP (or Elastic IP), an internet gateway attached to the VPC, and a route in the subnet's route table pointing 0.0.0.0/0 to that IGW. The question states the instance has an Elastic IP and the VPC has an IGW, so the missing piece is the route table entry. Without a 0.0.0.0/0 route to igw-xxxx, traffic from the instance has no path off the subnet regardless of the EIP.

Exam trap

SOA-C02 often tests the misconception that attaching an Internet Gateway to a VPC automatically gives subnets internet access — candidates forget that a 0.0.0.0/0 route in the subnet's route table is a separate, mandatory step.

How to eliminate wrong answers

Option B is wrong because the scenario explicitly states an Elastic IP is attached, which provides the public IP needed for internet-bound traffic. Option C is wrong because being in a 'private subnet' is defined by the absence of a route to an IGW — the question already establishes an IGW exists, so the real issue is the missing route, not the subnet classification. Option D is wrong because security groups are stateful and allow all outbound traffic by default; even if egress were restricted, the symptom would be connection timeouts rather than the complete lack of a routing path implied here.

15
MCQmedium

A company is using AWS CloudFormation to deploy a stack that includes an Amazon RDS DB instance. The database password is stored in AWS Secrets Manager. The CloudFormation template references the secret using a dynamic reference. However, the stack creation fails with an error that the secret cannot be retrieved. What is the most likely cause?

A.The secret is in a different AWS Region.
B.The stack name does not match the secret name.
C.The template uses the wrong dynamic reference syntax.
D.The CloudFormation service role lacks permissions to read the secret.
AnswerD

When a CloudFormation stack operation uses a service role, all AWS API calls, including reading secrets, are made using that role's credentials. The role must be granted the 'secretsmanager:GetSecretValue' action and, if the secret uses a customer-managed KMS key, the 'kms:Decrypt' permission as well. Without these permissions, CloudFormation is denied access to the secret and returns an error that the secret cannot be retrieved, even though the secret exists and the reference syntax is valid.

Why this answer

To use dynamic references, the CloudFormation service role must have permission to read the secret. The stack name and parameters are not related to secret retrieval. The secret must be in the same region.

The template syntax might be incorrect, but the most common issue is missing permissions.

16
MCQeasy

An administrator deploys a CloudFormation template that includes the snippet shown in the exhibit. Later, the administrator deletes the stack. What happens to the S3 bucket?

A.The bucket is deleted only if it contains no objects
B.The bucket is emptied and then deleted
C.The bucket is deleted along with the stack
D.The bucket is retained but no longer managed by CloudFormation
AnswerD

When a CloudFormation stack is deleted, resources with a DeletionPolicy of Retain are left in place in the AWS account. CloudFormation disassociates the resource from the stack, meaning it no longer tracks or manages the bucket through stack operations. The bucket remains fully functional and accessible, but subsequent stack updates or deletions will not affect it.

Why this answer

The DeletionPolicy attribute set to 'Retain' on the S3 bucket resource causes CloudFormation to preserve the bucket when the stack is deleted. The bucket will still exist in the account but will no longer be under CloudFormation management. Therefore, option D is correct.

Option A is incorrect because the bucket is retained regardless of its contents. Option B is incorrect because the bucket is not emptied or deleted. Option C is incorrect because the bucket is not deleted along with the stack.

17
MCQmedium

A company uses AWS CodeDeploy to deploy applications to an Auto Scaling group. The deployment fails with the error: 'The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available for deployment, or some instances in your deployment group are experiencing problems.' The SysOps administrator checks the deployment logs and finds that the application installation script exits with a non-zero exit code. What is the MOST likely cause?

A.The Auto Scaling group does not have enough instances to meet the minimum capacity.
B.The security group for the instances blocks outbound traffic to CodeDeploy endpoints.
C.The AppSpec file contains a lifecycle hook that fails.
D.The CodeDeploy agent is outdated on the instances.
AnswerC

A lifecycle hook in the AppSpec file that exits non-zero aborts the deployment on each instance, producing the reported failure threshold error. CodeDeploy surfaces the script's non-zero exit code directly, confirming the hook itself is the failing installation step.

Why this answer

A non-zero exit code from an AppSpec lifecycle hook (e.g., ApplicationStop, BeforeInstall, AfterInstall, ApplicationStart, ValidateService) during the deployment process causes the overall deployment to fail. The error message indicates that individual instances failed deployment, and the installation script exiting with a non-zero exit code is a direct sign of a lifecycle hook failure. Option A is incorrect because insufficient instances in the Auto Scaling group would trigger a different error related to minimum capacity, not a script exit code.

Option B is incorrect because the security group blocking outbound traffic would prevent the CodeDeploy agent from communicating with the service, resulting in a connection error, not a script exit code issue. Option D is incorrect because an outdated CodeDeploy agent would typically produce agent-specific errors or version mismatch warnings, not a non-zero exit code from the installation script.

18
Multi-Selectmedium

A SysOps administrator is automating the deployment of a web application using AWS CloudFormation. The application requires an Application Load Balancer (ALB) and an Auto Scaling group. The administrator wants to ensure that the Auto Scaling group registers instances with the ALB automatically. Which of the following are required? (Choose TWO.)

Select 2 answers
A.A launch template or launch configuration that defines the AMI and instance type.
B.A health check grace period set in the Auto Scaling group.
C.A security group that allows traffic from the ALB.
D.A target group ARN specified in the Auto Scaling group's configuration.
E.An Application Load Balancer created in the same stack.
AnswersA, D

A launch template or configuration is mandatory because the Auto Scaling group must know which Amazon Machine Image (AMI), instance type, key pair, and other instance settings to use when scaling out. Without a template, the ASG has no blueprint for creating EC2 instances, so it cannot launch or register anything with a load balancer. This is the fundamental instance-provisioning requirement, not merely an optional convenience.

Why this answer

A launch template or launch configuration is required because it defines the AMI, instance type, and other configuration details that the Auto Scaling group uses to launch EC2 instances. Without it, the Auto Scaling group cannot provision instances to register with the ALB.

Exam trap

The trap here is that candidates often think the ALB must be in the same CloudFormation stack or that a health check grace period is mandatory, when in fact only the launch template/configuration and target group ARN are required for automatic registration.

19
MCQmedium

An organization needs to enforce that all Amazon EC2 instances launched in a specific AWS account are created from a baseline Amazon Machine Image (AMI) that includes required security patches. The AMI ID is ami-0abcdef1234567890. What is the MOST efficient way to enforce this requirement?

A.Use an AWS Config rule to mark non-compliant instances and automatically terminate them.
B.Use an AWS Lambda function that is triggered by EC2 launch events to terminate non-compliant instances.
C.Use AWS CloudTrail to monitor and alert on any instance launched with a different AMI.
D.Use an IAM policy that denies the ec2:RunInstances action unless the AMI ID matches the approved one.
AnswerD

An IAM policy can use the ec2:ImageId condition key to deny ec2:RunInstances for any AMI that is not the approved one. Because IAM policies are evaluated during API authorization, this acts as a hard, pre-emptive block: the request is denied by AWS before any instance resource is created. This is a true preventive control and meets the organization's enforcement requirement directly. To implement it, add a statement with Effect: Deny, Action: ec2:RunInstances, and Condition: StringNotEquals on the ec2:ImageId key.

Why this answer

An IAM policy with a condition that denies ec2:RunInstances unless the AMI ID matches the approved one (ami-0abcdef1234567890) prevents non-compliant instances from being launched at all. This is the most efficient approach as it enforces the requirement proactively at the API level, avoiding the need for reactive detection or termination.

Exam trap

The trap here is that candidates often choose reactive solutions (like AWS Config or Lambda) because they seem more flexible, but the question asks for the 'MOST efficient' way, which is preventive enforcement via IAM policies at the API level.

How to eliminate wrong answers

Option A is wrong because AWS Config rules can mark non-compliant instances and trigger remediation (e.g., termination), but this is reactive—instances are launched before being detected and terminated, which wastes resources and may cause disruption. Option B is wrong because an AWS Lambda function triggered by EC2 launch events (via CloudTrail or EventBridge) also reacts after the instance is launched, leading to unnecessary resource consumption and potential race conditions. Option C is wrong because AWS CloudTrail only logs API calls for auditing and alerting; it cannot enforce or prevent the launch of non-compliant instances, making it purely detective and not preventive.

20
MCQhard

A company uses AWS CloudFormation to deploy a stack that includes an Amazon RDS DB instance with automated backups enabled. The stack is deleted and then recreated. The administrator wants to restore data from the backup of the original DB instance. How can this be achieved?

A.Restore from the latest automated backup stored in S3.
B.Restore from the automated backup snapshot that is retained after deletion.
C.Use the RDS recycle bin to recover the deleted DB instance.
D.Data cannot be restored because automated backups are deleted when the DB instance is deleted.
AnswerD

When an RDS DB instance is deleted, all automated backups—including system snapshots and transaction logs—are also deleted by default, unless you had previously chosen to create a final snapshot. Since the CloudFormation stack deletion did not specify that a final snapshot was taken, the automated backups were lost along with the instance. Therefore, the data cannot be restored because no independent backup artifact survives the instance deletion.

Why this answer

When an RDS DB instance is deleted, its automated backups are deleted along with it — they are tied to the instance's lifecycle and are not retained independently. Because the CloudFormation stack deletion removed the original DB instance, the automated backups no longer exist, so there is nothing to restore from. Unless a manual snapshot was taken beforehand, the data is unrecoverable.

Exam trap

SOA-C02 often tests the misconception that automated backups persist after instance deletion like manual snapshots do — candidates must remember automated backups die with the instance unless explicitly retained.

How to eliminate wrong answers

Option A is wrong because RDS automated backups are not stored as user-accessible objects in S3; they live in RDS-managed backup storage and cannot be restored directly from an S3 bucket. Option B is wrong because automated backup snapshots are deleted when the DB instance is deleted — they are not retained after deletion (only manual snapshots persist). Option C is wrong because RDS has no 'recycle bin' feature; that concept does not exist in RDS, so there is no mechanism to recover a deleted instance that way.

21
Multi-Selecteasy

A SysOps administrator is implementing an automated backup solution for Amazon RDS databases. The solution must support point-in-time recovery and cross-region disaster recovery. Which TWO AWS services or features should be used?

Select 2 answers
A.Manual DB snapshots.
B.Cross-region read replicas.
C.Automated backups with a retention period.
D.Amazon S3 lifecycle policies.
E.Automated cross-region snapshot copy.
AnswersC, E

Automated backups with a retention period enable RDS to automatically perform daily backups and capture transaction logs every five minutes, allowing point-in-time recovery to any second within the configured retention window (default 7 days, maximum 35 days). This option is technically valid for automated backups, but it is confined to a single Region; it does not provide cross-Region durability or disaster recovery, so it fails the specific requirement for a backup copy stored in a different geographical location.

Why this answer

Option C (Automated backups with a retention period) is correct because RDS automated backups capture daily snapshots plus transaction logs, enabling point-in-time recovery (PITR) to any second within the retention window (up to 35 days), which directly satisfies the PITR requirement. Option E (Automated cross-region snapshot copy) is correct because configuring RDS to automatically copy snapshots to a target region provides the cross-region disaster recovery capability, allowing restoration of the database in another region if the primary region fails. Together, C and E cover both stated requirements: PITR via automated backups and DR via cross-region snapshot replication.

Option A (Manual DB snapshots) is not suitable because manual snapshots do not support point-in-time recovery and must be triggered manually, so they cannot form an automated PITR solution. Option B (Cross-region read replicas) provides read scaling and can be promoted, but it is not a backup mechanism and does not deliver point-in-time recovery. Option D (Amazon S3 lifecycle policies) manages object storage transitions/expiration and has no role in RDS backup or recovery.

Exam trap

The trap is choosing cross-region read replicas for DR because they sound like replication; candidates must distinguish read replicas (performance/availability) from automated backups plus cross-region snapshot copy (point-in-time recovery and DR).

22
MCQeasy

A SysOps administrator needs to deploy a set of AWS Lambda functions and an Amazon API Gateway API using infrastructure as code. The administrator wants to manage the deployment across multiple environments (dev, test, prod) with consistent resource configurations. Which AWS service should the administrator use?

A.AWS CloudFormation
B.AWS CodeDeploy
C.AWS Elastic Beanstalk
D.AWS OpsWorks
AnswerA

AWS CloudFormation is the correct choice because it is a declarative infrastructure-as-code service that provisions and manages AWS resources through a template. You can define Lambda functions, API Gateway REST APIs, IAM roles, and all related dependencies in a single stack template, then deploy them consistently across development, test, and production environments. CloudFormation also handles resource ordering, rollback on failure, and drift detection, giving you repeatable and auditable deployments.

Why this answer

AWS CloudFormation is the correct choice because it is an Infrastructure as Code (IaC) service that allows you to define and provision AWS resources, including Lambda functions and API Gateway APIs, using templates. It supports managing deployments across multiple environments (dev, test, prod) by using parameters, mappings, and stacks, ensuring consistent resource configurations through repeatable, version-controlled templates.

Exam trap

The trap here is that candidates often confuse AWS CodeDeploy (which deploys application code) with CloudFormation (which provisions infrastructure), leading them to choose CodeDeploy because they think of 'deploying' Lambda functions, but the question specifically requires managing infrastructure as code across environments, which is CloudFormation's role.

How to eliminate wrong answers

Option B (AWS CodeDeploy) is wrong because it is a deployment service for automating code deployments to compute services like EC2, Lambda, or ECS, but it does not manage the provisioning of infrastructure resources like API Gateway or Lambda functions themselves; it focuses on deploying application code, not defining the underlying infrastructure. Option C (AWS Elastic Beanstalk) is wrong because it is a Platform as a Service (PaaS) that abstracts infrastructure management for web applications, but it does not provide the granular, template-based control over individual resources like Lambda and API Gateway that IaC requires; it is designed for application deployment, not for defining and versioning infrastructure components. Option D (AWS OpsWorks) is wrong because it is a configuration management service that uses Chef or Puppet to manage EC2 instances and on-premises servers, but it is not designed for defining serverless resources like Lambda functions or API Gateway APIs; it focuses on server-based configurations, not declarative IaC for serverless services.

23
MCQmedium

A company manages multiple AWS accounts under AWS Organizations. The SysOps administrator needs to deploy a baseline set of AWS Config rules and an Amazon SNS topic to each account in the organization. The deployment must be centrally managed from the management account and automatically applied to any new member account added in the future. Which solution should the administrator use?

A.Create an AWS CloudFormation StackSet with the template containing the AWS Config rules and SNS topic. Configure the StackSet to deploy to the organization and enable automatic deployment to new accounts.
B.Use AWS Service Catalog to create a product that bundles the AWS Config rules and SNS topic. Grant each account access to launch the product.
C.Configure AWS Config conformance packs in the management account and use AWS Resource Access Manager to share them with member accounts.
D.Create an AWS Organizations Service Control Policy (SCP) that enforces the creation of AWS Config rules and SNS topics in every account.
AnswerA

StackSets deploy a single CloudFormation template across every account in AWS Organizations from the management account, and the automatic deployment setting propagates it to accounts added later. This satisfies both the central management and future-account constraints without per-account scripting.

Why this answer

AWS CloudFormation StackSets can be deployed to an entire AWS Organizations organization or organizational units (OUs), and they support automatic deployment to new accounts added to the organization. By creating a StackSet with a template that defines the AWS Config rules and SNS topic, and enabling automatic deployment, the administrator ensures that every current and future member account receives the baseline configuration without manual intervention.

Exam trap

The trap here is that candidates often confuse Service Control Policies (SCPs) with resource enforcement, not realizing that SCPs only control permissions and cannot create or configure resources like AWS Config rules or SNS topics.

How to eliminate wrong answers

Option B is wrong because AWS Service Catalog requires each account to manually launch the product, which does not provide automatic deployment to new accounts and is not centrally enforced. Option C is wrong because AWS Config conformance packs can be deployed to multiple accounts via StackSets, but AWS Resource Access Manager (RAM) is used to share resources like subnets or license configurations, not to deploy conformance packs; conformance packs themselves are deployed using StackSets or directly per account. Option D is wrong because Service Control Policies (SCPs) are used to restrict permissions and cannot enforce the creation of specific resources like AWS Config rules or SNS topics; they only control what actions are allowed or denied.

24
MCQhard

A SysOps administrator is troubleshooting a failed AWS CloudFormation stack creation. The stack includes an Amazon RDS DB instance with a custom DB parameter group. The error message states: 'The following resource(s) failed to create: [DBParameterGroup].' The administrator checks the CloudFormation template and sees that the DBParameterGroup resource has a property 'Parameters' with a list of parameters. What is the MOST likely reason for the failure?

A.The parameter group name contains invalid characters.
B.The parameter group is configured with parameters that are not compatible with the DB engine version.
C.The DB subnet group specified for the DB instance does not exist.
D.The VPC does not have an RDS VPC endpoint enabled.
AnswerB

When you associate a custom DB parameter group with a new DB instance, RDS verifies that the parameter group's family matches the target engine and version, and that every parameter value is valid for that engine. If the parameter group was created for a different engine version (e.g., a MySQL 5.7 group attached to MySQL 8.0) or contains parameters that were removed/renamed in the target version, RDS aborts the creation with an error referencing the parameter group. This is the most common cause of a failed launch when the parameter group name, subnet group, and network configuration are otherwise correct.

Why this answer

Custom DB parameter groups must be configured with parameters that are compatible with the DB engine and version specified for the RDS instance. If the parameter group includes parameters that are not supported by the chosen engine version, the stack creation will fail with an error for the DBParameterGroup resource. In this case, the most likely cause is that one or more parameters in the 'Parameters' list are incompatible with the DB engine version.

Option B is correct. Option A is incorrect because parameter group names can contain letters, numbers, and hyphens; they are not restricted. Option C is incorrect because the DB subnet group is not related to parameter group creation failure.

Option D is incorrect because RDS does not require a VPC endpoint to create a parameter group.

25
MCQmedium

A company uses AWS CodePipeline to automate its software release process. The pipeline includes a source stage (Amazon S3), a build stage (AWS CodeBuild), and a deploy stage (AWS CodeDeploy). Recently, a developer committed a change that broke the build. The pipeline failed and the developer fixed the code. The developer wants to rerun the pipeline from the source stage without making another commit. What should the developer do?

A.Create a new commit with an empty message to trigger the pipeline.
B.Use the 'Release change' button in the CodePipeline console to manually rerun the pipeline.
C.Wait for the pipeline to automatically retry after the failure.
D.Re-upload the same artifact to the source S3 bucket to trigger the pipeline.
AnswerB

Using the 'Release change' button in the CodePipeline console manually reruns the pipeline from the source stage, using the latest source revision. This is the correct action because it triggers a new execution without requiring a new commit.

Why this answer

AWS CodePipeline provides a 'Release change' button in the console that manually triggers the pipeline to run from the source stage using the latest commit. This allows the developer to rerun the pipeline without making a new commit. The pipeline will fetch the latest source revision and proceed through the stages.

Exam trap

SOA-C02 often tests the misconception that you need to make a new commit or re-upload artifacts to rerun a pipeline, rather than using the built-in 'Release change' feature.

How to eliminate wrong answers

Option A is wrong because creating an empty commit adds unnecessary noise to the repository and is not the intended way to rerun a pipeline. Option C is wrong because CodePipeline does not automatically retry after a failure; it requires manual intervention. Option D is wrong because re-uploading the same artifact to the S3 bucket may not trigger the pipeline if the object key and version are unchanged; CodePipeline triggers on new object versions or changes.

26
Multi-Selecteasy

A SysOps administrator is creating a CloudFormation template to provision an Amazon S3 bucket with versioning enabled and server access logging. Which TWO properties must be configured in the AWS::S3::Bucket resource?

Select 2 answers
A.Tags
B.VersioningConfiguration
C.LoggingConfiguration
D.LifecycleConfiguration
E.AccessControl
AnswersB, C

VersioningConfiguration is the required property in an AWS::S3::Bucket template to actually enable S3 versioning. Without this property, the bucket is created with versioning disabled (the default), even if other properties like LoggingConfiguration are present. You must set Status to 'Enabled' inside this property; note that versioning can later be suspended but never fully reset to the original default, so enabling it is a one-way configuration decision.

Why this answer

The `VersioningConfiguration` property must be set to `Enabled` to enable versioning on the S3 bucket. Option C is correct because the `LoggingConfiguration` property must specify the target bucket and prefix to enable server access logging. Both are explicit properties of the `AWS::S3::Bucket` resource in CloudFormation.

Exam trap

The trap here is that candidates often confuse `LoggingConfiguration` with `AccessControl` or assume `LifecycleConfiguration` is required for logging, when in fact only `VersioningConfiguration` and `LoggingConfiguration` are mandatory for the stated requirements.

27
MCQhard

A company uses AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment strategy is set to CodeDeployDefault.HalfAtATime. The lifecycle hooks for the Auto Scaling group include a test hook that runs during instance launch. During a recent deployment, the deployment failed because the new instances failed the test hook and were not marked as healthy. The SysOps administrator needs to ensure that failed instances are automatically terminated and replaced with new ones from the Auto Scaling group. Which configuration change should the administrator make?

A.Modify the Auto Scaling group's health check type to ELB
B.Modify the CodeDeploy deployment configuration to use an increased minimum healthy instance count
C.Modify the Auto Scaling group's health check grace period to a lower value
D.Modify the CodeDeploy deployment to ignore the lifecycle hook failure
AnswerA

When the health check type is set to ELB, the Auto Scaling group uses the Application Load Balancer's health checks. If the test hook fails, the instance will be marked unhealthy by the ALB, and the Auto Scaling group will terminate and replace it, ensuring only healthy instances remain.

Why this answer

Setting the Auto Scaling group's health check type to ELB (Elastic Load Balancer) ensures that the Auto Scaling group uses the ELB's health check status to determine instance health. When the test lifecycle hook fails, the new instances are not marked as healthy by the ELB, causing the Auto Scaling group to automatically terminate and replace them. This aligns with the requirement to automatically replace failed instances, as the default EC2 health check only considers instance status (e.g., running vs. stopped) and does not reflect application-level health.

Exam trap

The trap here is that candidates often assume the default EC2 health check is sufficient for detecting application-level failures, but it only monitors instance status (e.g., running/stopped), not the success of lifecycle hooks or application health, so the ELB health check type is required to trigger automatic replacement.

How to eliminate wrong answers

Option B is wrong because increasing the minimum healthy instance count in the CodeDeploy deployment configuration (e.g., using CodeDeployDefault.AllAtOnce or a custom configuration) does not cause failed instances to be terminated and replaced; it only adjusts the number of instances that must remain healthy during the deployment, which could actually reduce the deployment's tolerance for failures. Option C is wrong because reducing the health check grace period would cause the Auto Scaling group to check instance health sooner, but it does not change the health check type; with the default EC2 health check, the test hook failure is not detected, so a shorter grace period has no effect on terminating failed instances. Option D is wrong because ignoring the lifecycle hook failure would allow the deployment to proceed despite the test failure, but it would not trigger automatic termination and replacement of the failed instances; the instances would remain in service, potentially causing application issues.

28
MCQhard

A company runs a critical web application on a fleet of EC2 instances behind an Application Load Balancer (ALB) across multiple Availability Zones. The application is deployed using AWS Elastic Beanstalk with a rolling update deployment policy. Recently, the development team pushed a new application version that introduced a memory leak. Within minutes, the instances started failing health checks, and Elastic Beanstalk initiated a replacement of the instances. However, during the replacement, the application experienced downtime because the new instances were not passing health checks, and the old instances were already terminated. The SysOps Administrator must modify the deployment to prevent downtime during future failed deployments. Which solution should the administrator implement?

A.Increase the Auto Scaling group's minimum and maximum size to handle more instances.
B.Implement a Blue/Green deployment using a separate Elastic Beanstalk environment and swap CNAMEs after testing.
C.Replace the ALB with a Classic Load Balancer to reduce complexity.
D.Change the deployment policy to All at once to speed up the deployment.
AnswerB

Blue/green keeps the original environment serving traffic until the new environment passes health checks, then swaps CNAMEs. This prevents downtime when a bad version fails health checks, unlike rolling updates that terminate old instances first.

Why this answer

Blue/Green deployment with Elastic Beanstalk creates a separate environment running the new version. Health checks validate the new instances before swapping the CNAME. If the new environment fails, the old environment continues serving traffic, eliminating downtime.

Option A is wrong because increasing Auto Scaling sizes does not change the deployment policy; it only affects scaling limits. Option C is wrong because Classic Load Balancer lacks advanced health check features and does not address the deployment strategy. Option D is wrong because All at once deployment would replace all instances simultaneously, causing downtime even without failure, and does not provide a rollback mechanism.

29
MCQhard

A company has a CloudFormation stack that creates an Amazon EC2 instance with a user data script that installs software from the internet. The stack creation is failing with a timeout. The SysOps administrator suspects that the user data script is taking too long or failing. How can the administrator configure the stack to wait for the user data script to complete successfully before marking the instance as CREATE_COMPLETE?

A.Add a CreationPolicy with a resource signal to the EC2 instance resource and have the user data script send a success signal using cfn-signal.
B.Add a DependsOn attribute to the EC2 instance resource to wait for another resource.
C.Add an UpdatePolicy with a resource signal to the EC2 instance resource.
D.Add a WaitCondition resource and a WaitHandle, and have the user data script send a signal to the WaitHandle.
AnswerA

A CreationPolicy on the EC2 instance resource makes CloudFormation hold the stack creation in the CREATE_IN_PROGRESS state until it receives the specified number of success signals. The user data script must invoke cfn-signal after completing its configuration steps, which directly ties the instance's readiness to the stack creation workflow. This is the only option that explicitly synchronizes CloudFormation with the completion of the user data script during initial stack creation.

Why this answer

A CreationPolicy with a resource signal tells CloudFormation to wait for a success signal (via cfn-signal) from the EC2 instance before marking it CREATE_COMPLETE. The user data script calls cfn-signal after the software installation succeeds, ensuring the stack only proceeds when the instance is truly ready.

Exam trap

SOA-C02 often tests whether candidates confuse CreationPolicy (initial creation wait) with UpdatePolicy (update-time rolling behavior) — the question's 'stack creation is failing' keyword points to CreationPolicy.

How to eliminate wrong answers

Option B is wrong because DependsOn only controls resource creation order — it does not wait for user data scripts or application readiness. Option C is wrong because UpdatePolicy governs how resources are updated during stack updates (e.g., AutoScalingRollingUpdate), not initial creation wait behavior. Option D is wrong because WaitCondition + WaitHandle is the older, more manual pattern — CreationPolicy with cfn-signal is the modern, recommended approach for EC2 instances and is what the question asks for.

30
MCQmedium

A SysOps administrator is creating a CloudFormation stack that requires an IAM role to be passed to EC2 instances. The administrator is using the IAM policy shown in the exhibit. The stack creation fails with an error indicating insufficient permissions to pass the role. What is the most likely cause?

A.The cloudformation:* action does not include permission to create stacks.
B.The policy does not include the cloudformation:CreateStack action.
C.The ec2:RunInstances permission is missing from the policy.
D.The iam:PassRole permission is restricted to a specific role ARN that does not match the role the administrator is trying to pass.
AnswerD

The correct explanation is that the iam:PassRole permission in the policy is scoped to a specific role ARN (e.g., arn:aws:iam::123456789012:role/Admin), but the CloudFormation stack is configured to use a different IAM role, such as a dedicated stack role or a role named 'StackRole'. When CloudFormation attempts to pass that role to the EC2 instances or other resources, IAM evaluates the PassRole action and denies it because the ARN does not match the one allowed. This is a classic IAM PassRole mismatch error and is precisely why the stack creation fails.

Why this answer

The IAM policy likely includes an iam:PassRole action restricted to a specific role ARN (e.g., 'arn:aws:iam::account:role/Admin'), but the CloudFormation stack is attempting to pass a different role. This causes an insufficient permissions error because the PassRole permission is scoped to that specific role. Option A is incorrect because cloudformation:* includes all CloudFormation actions, including creating stacks.

Option B is incorrect because the policy uses cloudformation:*, which implicitly includes CreateStack. Option C is incorrect because ec2:RunInstances is not required for passing an IAM role; the necessary permission is iam:PassRole.

31
Multi-Selecthard

A CloudFormation stack update fails and enters UPDATE_ROLLBACK_FAILED. Which two actions are appropriate next steps? (Choose 2.)

Select 2 answers
A.Review stack events to identify the resource that blocked rollback.
B.Use continue-update-rollback after resolving the underlying issue or specifying resources to skip when appropriate.
C.Delete the CloudFormation service role from IAM.
D.Rename the stack to force rollback completion.
AnswersA, B

Stack events expose the precise CloudFormation status of each logical resource during the failed update and subsequent rollback attempt, including the exact API error that caused the rollback to stall—for example, an EC2 security group dependency that could not be evaluated. By reviewing the most recent event entries, you can pinpoint whether a resource is stuck in CLEANUP_IN_PROGRESS or UPDATE_ROLLBACK_IN_PROGRESS and read the underlying failure message. This diagnosis determines whether you can safely run continue-update-rollback without skipping resources.

Why this answer

When a CloudFormation stack update fails and enters UPDATE_ROLLBACK_FAILED, the stack events provide detailed error messages for each resource that failed during rollback. Reviewing these events is essential to identify the specific resource that blocked the rollback, such as a resource that could not be deleted or updated due to permissions, dependencies, or configuration issues. This diagnosis is the first step before attempting a continue-update-rollback operation.

Exam trap

The trap here is that candidates may think deleting the service role or renaming the stack are valid recovery actions, but AWS CloudFormation requires explicit rollback continuation or manual intervention via the continue-update-rollback API, not workarounds that break IAM or naming conventions.

32
MCQhard

A company runs a critical application on a fleet of EC2 instances in an Auto Scaling group. The application is deployed using a blue/green deployment strategy with AWS CodeDeploy. The green environment fails immediately after deployment, and the deployment is automatically rolled back. However, the rollback also fails because the original blue environment's Auto Scaling group has been scaled down. What should the SysOps administrator do to prevent this issue in future deployments?

A.Configure the deployment to automatically delete the green environment after rollback.
B.Increase the minimum size of the Auto Scaling group.
C.Change the deployment type to in-place.
D.Set the original environment termination delay to a longer duration in the CodeDeploy deployment group.
AnswerD

In AWS CodeDeploy blue/green deployments, the original instances (the blue environment) are kept alive for a configured 'original environment termination delay' before being terminated. Extending this delay preserves the blue fleet for a longer period, allowing you to roll back by rerouting traffic back to the original instances if the new deployment proves faulty. This is the proper mechanism to ensure the original environment remains available for rollback, either automatically or through manual intervention.

Why this answer

Setting the original environment termination delay in the CodeDeploy deployment group ensures that the blue Auto Scaling group instances are not terminated immediately after a successful deployment. This delay keeps the blue environment available during the rollback window, preventing the rollback failure that occurs when the original environment has already been scaled down. The termination delay is a configurable setting in CodeDeploy that holds the old instances for a specified period, allowing a safe fallback if the new environment fails.

Exam trap

The trap here is that candidates often assume increasing the Auto Scaling group's minimum size (Option B) will preserve the blue environment, but they miss that CodeDeploy explicitly terminates the old instances as part of the blue/green deployment lifecycle, regardless of the minimum size setting.

How to eliminate wrong answers

Option A is wrong because automatically deleting the green environment after rollback does not address the root cause—the blue environment being unavailable; it only cleans up the failed environment. Option B is wrong because increasing the minimum size of the Auto Scaling group does not prevent the blue group from being scaled down during the deployment lifecycle; it only ensures a minimum number of instances are always running, but the blue group's instances are still terminated by CodeDeploy after the deployment completes. Option C is wrong because changing the deployment type to in-place would cause downtime and does not solve the rollback issue; in-place deployments update existing instances without preserving a separate blue environment, making rollback even more difficult.

33
MCQeasy

A development team uses AWS CloudFormation to deploy infrastructure. They want to update a stack but first need to review how the changes will impact existing resources before applying them. Which CloudFormation feature should they use?

A.Change sets
B.Stack policies
C.Condition functions
D.Custom resources
AnswerA

Change sets in AWS CloudFormation let you create a summary of proposed modifications to a stack without applying them. They provide a preview of exactly which resources will be added, modified, or removed, and indicate whether a change will cause replacement or simple updates. This review capability is especially valuable for production stacks, as it lets you catch unintended destructive actions before they execute.

Why this answer

Change sets allow you to preview how proposed changes to a CloudFormation stack will affect your running resources before you apply them. They generate a summary of the changes (additions, modifications, deletions) based on the new template and parameters, enabling you to assess impact such as resource replacement or updates without executing the changes. This directly addresses the team's requirement to review changes before applying them.

Exam trap

The trap here is that candidates confuse stack policies (which guard resources during updates) with change sets (which preview changes), or assume condition functions or custom resources can simulate change impact, but only change sets provide a declarative diff before execution.

How to eliminate wrong answers

Option B is wrong because stack policies are used to prevent accidental updates or deletions of specific stack resources during a stack update, not to preview changes. Option C is wrong because condition functions (e.g., Fn::If) control whether certain resources are created or properties are set based on conditions in the template, but they do not provide a preview of change impact. Option D is wrong because custom resources allow you to handle provisioning logic for resources not natively supported by CloudFormation, but they do not offer a mechanism to review changes before an update.

34
MCQhard

A SysOps administrator is troubleshooting a failed AWS CloudFormation stack creation. The stack includes an AWS::Lambda::Function resource. The error message states: 'The runtime parameter of nodejs8.10 is no longer supported.' The administrator needs to resolve this with minimal changes. What should the administrator do?

A.Modify the Lambda function code to use Python 3.8.
B.Manually update the runtime in the AWS Lambda console after the stack creation fails.
C.Update the CloudFormation template to use a supported Node.js runtime, such as nodejs14.x.
D.Wait for AWS to re-enable the nodejs8.10 runtime.
AnswerC

Updating the CloudFormation template's Runtime property from nodejs8.10 to a supported version like nodejs14.x directly resolves the deprecation error and lets AWS re-validate the template successfully. This is the minimal configuration change that preserves the existing Node.js code while making the stack deployable. After updating the template, the stack can be recreated or updated without further code modifications.

Why this answer

Updating the CloudFormation template to use a supported Node.js runtime (e.g., nodejs14.x) is the minimal-change fix because the error is caused by an unsupported runtime parameter in the template. Changing the template and redeploying resolves the stack creation failure.

Exam trap

SOA-C02 often tests whether candidates choose manual console fixes or code rewrites when the root cause is a deprecated runtime in the CloudFormation template — the minimal fix is updating the template.

How to eliminate wrong answers

Option A is wrong because rewriting the function code in Python is a major change and unnecessary when only the runtime version is the issue. Option B is wrong because manually updating the runtime in the console after a failed stack creation does not fix the template and will cause drift or future failures. Option D is wrong because AWS does not re-enable deprecated runtimes; nodejs8.10 is permanently deprecated.

35
MCQmedium

A company uses AWS CloudFormation to deploy infrastructure. The SysOps administrator has a template that creates an Amazon EC2 instance and an Amazon RDS DB instance. The administrator needs to reuse the same template for development, test, and production environments, where the only differences are the EC2 instance type and the RDS DB instance class. Which CloudFormation feature should be used to define these environment-specific values?

A.Nested stacks
B.Parameters
C.Mappings
D.Conditions
AnswerB

Parameters are the native CloudFormation feature designed to accept external input at stack creation or update time. By defining a parameter for the instance type and another for the DB class, the exact same template can be reused across dev, test, and production with different values supplied via the console, CLI, or API. This makes Params the most direct and maintainable way to achieve environment-specific resource configuration without editing the template.

Why this answer

Parameters are the correct CloudFormation feature because they allow you to pass environment-specific values (such as EC2 instance type and RDS DB instance class) into the template at stack creation or update time. This enables reuse of the same template across development, test, and production environments without modifying the template itself, simply by providing different parameter values for each environment.

Exam trap

The trap here is that candidates often confuse Mappings (which are static and cannot be changed per stack instance) with Parameters (which are dynamic and input at runtime), leading them to incorrectly choose Mappings for environment-specific values that must vary per deployment.

How to eliminate wrong answers

Option A is wrong because nested stacks are used to compose infrastructure from multiple templates or to isolate reusable components, not to inject environment-specific variable values into a single template. Option C is wrong because mappings provide static lookup tables (e.g., mapping environment names to instance types) but cannot be overridden at runtime; they are hardcoded in the template and not suitable for values that must change per deployment. Option D is wrong because conditions control whether a resource or property is created or omitted based on a condition (e.g., deploy a resource only in production), but they do not define or pass variable values like instance type or DB class.

36
MCQmedium

A SysOps administrator ran the above AWS CLI command to update an existing CloudFormation stack. The command failed with the error shown. What is the most likely cause?

A.The template file has a syntax error.
B.The stack is in a failed state from a previous operation and must be deleted or rollback continued.
C.The parameter values provided are invalid.
D.The IAM role specified lacks permissions.
AnswerB

This is the correct answer because the UpdateStack API explicitly rejects any stack whose current status is ROLLBACK_COMPLETE with a ValidationError stating the stack is in that state and cannot be updated. ROLLBACK_COMPLETE is a terminal failed state typically reached after a failed stack creation rolled back all resources, leaving the stack with no usable resources. To recover, you must delete the stack and recreate it, or if the rollback was incomplete, use ContinueUpdateRollback to reach an updatable state.

Why this answer

When a CloudFormation stack is in a failed state (e.g., UPDATE_ROLLBACK_FAILED or ROLLBACK_COMPLETE), any subsequent update operation is rejected with an error stating the stack is in a state that does not permit updates. The administrator must either continue the rollback (ContinueUpdateRollback) or delete and recreate the stack before another update can proceed. This matches the typical 'Stack is in UPDATE_ROLLBACK_FAILED state and can not be updated' error returned by the CLI.

Exam trap

SOA-C02 often tests whether candidates can distinguish between template/parameter validation errors and stack lifecycle state errors — the misleading options all describe plausible failure causes, but only the stack-state explanation matches a CLI error that explicitly references the stack's current status.

How to eliminate wrong answers

Option A is wrong because a template syntax error would produce a validation error during the change set or template parsing phase, not a stack-state rejection. Option C is wrong because invalid parameter values would fail parameter validation with a specific message about the parameter, not a stack-state error. Option D is wrong because insufficient IAM permissions would return an AccessDenied or authorization error, not a stack-state failure message.

37
MCQmedium

A SysOps administrator is troubleshooting a failed AWS CloudFormation stack creation. The error message indicates that an IAM role creation failed because the role already exists. The administrator wants to ensure the stack creation can proceed without manual intervention. What should the administrator do?

A.Modify the template to use a unique name for the IAM role.
B.Use the 'Retain' deletion policy on the IAM role resource.
C.Manually delete the existing IAM role and retry the stack creation.
D.Use a stack policy to prevent the creation of the IAM role.
AnswerA

CloudFormation IAM roles with an explicit RoleName property must be unique within the account and Region. If a role with that name already exists, stack creation fails with a resource conflict error. By appending the stack name or a random suffix to the RoleName, you ensure uniqueness without manual cleanup; this is the standard automated fix and aligns with AWS best practices for avoiding namespace collisions.

Why this answer

The error indicates a naming conflict: the IAM role name in the template already exists in the account. By modifying the template to use a unique name (e.g., appending a random string or using `AWS::NoValue` with `Fn::Sub`), CloudFormation can create the role without conflicting with the existing resource. This approach avoids manual intervention and allows the stack creation to proceed automatically.

Exam trap

The trap here is that candidates may confuse deletion policies (which affect resource lifecycle after deletion) with creation-time conflicts, or mistakenly think stack policies can block resource creation when they only govern updates and deletions.

How to eliminate wrong answers

Option B is wrong because the 'Retain' deletion policy only controls what happens to the resource when the stack is deleted; it does not prevent a creation failure caused by a duplicate name. Option C is wrong because it requires manual intervention, which the administrator wants to avoid, and it does not address the root cause of the naming conflict for future stack creations. Option D is wrong because a stack policy controls update or deletion actions on stack resources, not the creation of new resources; it cannot prevent the IAM role creation failure.

38
MCQhard

An organization is using AWS OpsWorks for Chef Automate to manage configuration of EC2 instances. The administrator notices that a new cookbook version is not being applied to existing instances in a layer. The cookbook is stored in a private Amazon S3 bucket and the instances have an instance profile that allows read access. What is the MOST likely reason for this issue?

A.The cookbook version is not being automatically downloaded because the instances are not rebooted.
B.The S3 bucket policy does not grant the necessary permissions to the instance profile.
C.The 'Update Cookbooks' stack command needs to be run manually to apply the new cookbook version to existing instances.
D.The Chef client on the instances is not configured to run automatically.
AnswerC

Correct. In AWS OpsWorks, cookbooks are only automatically applied during initial setup or when a Configure lifecycle event occurs. To apply a new cookbook version to existing instances, the administrator must manually run the 'Update Cookbooks' stack command.

Why this answer

In OpsWorks, cookbooks are not automatically applied to existing instances when a new version is published. To force an update on existing instances, the administrator must run the 'Update Cookbooks' stack command. Option A is incorrect because rebooting instances does not automatically download or apply new cookbook versions.

Option B is incorrect because the instance profile already has read access to the S3 bucket as stated, so the bucket policy is not the issue. Option D is incorrect because the Chef client runs automatically, but it does not fetch new cookbooks unless told to do so via the Update Cookbooks command.

39
MCQhard

A SysOps administrator is deploying a CloudFormation stack that includes an AWS::ECS::Service resource. The service uses a task definition that references a container image stored in Amazon ECR. The stack creation fails with the error: 'Unable to assume the service-linked role.' What is the MOST likely cause?

A.The task execution role does not have permissions to pull the container image from ECR.
B.The CloudFormation service role does not have permission to create ECS resources.
C.The ECR repository policy does not grant access to the ECS service.
D.The ECS service-linked role does not exist in the account.
AnswerD

ECS requires the `AWSServiceRoleForECS` service-linked role so that the ECS service can manage resources such as ENIs, load balancer targets, and Auto Scaling groups on your behalf. If this role has never been created in the account, CloudFormation's calls to create the cluster or service return an error indicating that the service-linked role is not found, causing the stack to roll back. The role can be created with `iam:CreateServiceLinkedRole` or by a prior ECS console/API call; CloudFormation will not create it automatically for you.

Why this answer

The error 'Unable to assume the service-linked role' indicates that the ECS service-linked role (AWSServiceRoleForECS) does not exist in the account. CloudFormation attempts to create the ECS service, which requires this role to manage resources on your behalf. If the role is missing, the stack creation fails.

The most likely cause is that the role has not been created, perhaps because ECS was never used in this account before.

Exam trap

SOA-C02 often tests IAM roles and permissions, and candidates may confuse the task execution role with the service-linked role; the trap is assuming the error is due to missing ECR permissions when it's actually about the ECS service-linked role.

How to eliminate wrong answers

Option A is wrong because if the task execution role lacked ECR permissions, the error would be about pulling the image, not assuming a service-linked role. Option B is wrong because if the CloudFormation service role lacked permissions to create ECS resources, the error would be an authorization failure for CloudFormation, not a service-linked role assumption issue. Option C is wrong because the ECR repository policy controls access to the repository, but the error is specifically about assuming a service-linked role, which is unrelated to ECR permissions.

40
MCQmedium

A company uses AWS CloudFormation to manage infrastructure. They have a stack that creates an Amazon RDS DB instance. The database is in a VPC with public and private subnets. The DB instance is in a private subnet. When the stack is created, the DB instance is not accessible from an EC2 instance in the same VPC. What is the most likely cause?

A.The DB subnet group does not include the correct subnets.
B.The security group for the DB instance does not allow inbound traffic from the EC2 instance.
C.The VPC does not have an internet gateway attached.
D.The DB instance does not have a public IP address.
AnswerB

RDS security groups are stateful firewalls that deny all inbound traffic by default. The DB instance's security group must have a custom inbound rule for the database port (e.g., TCP 3306 for MySQL) with a source referencing the EC2 instance's security group ID, not a CIDR from memory. Without this explicit allow, the EC2 instance cannot reach the DB even when both are in the same VPC and subnet, making this the classic cause of 'same VPC, still can't connect'.

Why this answer

The most likely cause is that the security group attached to the RDS DB instance does not permit inbound traffic from the EC2 instance's security group or IP address on the database port. In a VPC, security groups act as virtual firewalls, and even if the DB is in the same VPC, traffic is blocked unless explicitly allowed. CloudFormation stack creation would succeed, but connectivity would fail.

Exam trap

SOA-C02 often tests the misconception that an internet gateway or public IP is required for internal VPC communication, when in fact security group rules are the typical culprit for connectivity failures between EC2 and RDS.

How to eliminate wrong answers

Option A is wrong because if the DB subnet group did not include the correct subnets, the RDS instance would not be placed in the private subnet as intended, but the question states the DB is in a private subnet, implying the subnet group is correct. Option C is wrong because an internet gateway is not required for internal VPC communication between an EC2 instance and an RDS instance; they communicate using private IP addresses. Option D is wrong because a public IP address is not needed for internal VPC access; RDS instances in private subnets are accessed via their private IPs.

41
MCQeasy

A company wants to automatically start and stop an EC2 instance on a schedule to reduce costs. The instance runs a critical application that must be available from 8 AM to 6 PM weekdays. Which AWS service should be used to implement this scheduling?

A.AWS Instance Scheduler
B.AWS OpsWorks
C.AWS Systems Manager Automation
D.AWS CloudFormation
AnswerA

AWS Instance Scheduler is an AWS Solutions Library reference implementation that deploys a scheduled stop/start framework using CloudFormation, Amazon EventBridge, and AWS Lambda. It reads user-defined tags such as Schedule=Weekdays-7am-7pm from EC2 and RDS instances, evaluates the current time against the defined periods in a DynamoDB table, and automatically transitions instances between the stopped and started states. It also supports time zones, types such as EC2 and RDS, and cross-account/region execution, making it the purpose-built solution for this exact requirement.

Why this answer

AWS Instance Scheduler is a purpose-built solution (deployed via CloudFormation) that uses Lambda, DynamoDB, and EventBridge to start and stop EC2 instances and RDS databases on customizable schedules. It supports period-based and schedule-based tagging, making it the correct choice for automatically starting/stopping an instance on a weekday 8 AM–6 PM schedule. The other services can be cobbled together to achieve scheduling, but none is designed specifically for this cost-optimization use case.

Exam trap

SOA-C02 often tests whether candidates recognize that Instance Scheduler is a distinct AWS solution (not a core service) and confuse it with Systems Manager Automation or CloudFormation, which require more manual configuration.

How to eliminate wrong answers

Option B is wrong because AWS OpsWorks is a configuration management service (Chef/Puppet-based) for deploying and managing applications, not a scheduling service for starting/stopping instances. Option C is wrong because AWS Systems Manager Automation can run documents on a schedule via maintenance windows, but it requires custom automation documents and is not a turnkey instance-scheduling solution like Instance Scheduler. Option D is wrong because AWS CloudFormation is an infrastructure-as-code provisioning service; while Instance Scheduler itself is deployed via CloudFormation, CloudFormation alone does not provide scheduling logic.

42
MCQeasy

A DevOps engineer needs to automate the creation of an Amazon RDS for MySQL DB instance in a VPC. The solution must use infrastructure as code. Which AWS service should be used to provision the database?

A.AWS OpsWorks
B.AWS Elastic Beanstalk
C.AWS CloudFormation
D.EC2 Auto Scaling
AnswerC

AWS CloudFormation is an Infrastructure as Code service that lets you define resources declaratively in a JSON or YAML template. You can specify an AWS::RDS::DBInstance resource, along with all its properties such as engine, instance class, storage, and security groups, and CloudFormation will create the database reproducibly and manage its lifecycle. It supports change sets, rollback on failure, and drift detection, making it the ideal service for automating RDS provisioning.

Why this answer

AWS CloudFormation is the infrastructure-as-code service that allows you to define and provision AWS resources, including RDS DB instances, using declarative templates. It supports the full lifecycle management of RDS instances, including creation, updates, and deletion, and integrates with other AWS services for automation. The other options are not designed for general-purpose infrastructure as code provisioning of databases.

Exam trap

SOA-C02 often tests the distinction between infrastructure-as-code services and application deployment or configuration management services, causing candidates to confuse Elastic Beanstalk or OpsWorks with CloudFormation for provisioning databases.

How to eliminate wrong answers

Option A is wrong because AWS OpsWorks is a configuration management service that uses Chef and Puppet to automate server configuration, but it is not primarily an infrastructure-as-code service for provisioning AWS resources like RDS; it focuses on EC2 instances and applications. Option B is wrong because AWS Elastic Beanstalk is a PaaS service for deploying and scaling web applications, and while it can provision an RDS instance as part of an environment, it is not an infrastructure-as-code tool and does not provide the declarative, version-controlled template approach required. Option D is wrong because EC2 Auto Scaling is a service for automatically adjusting the number of EC2 instances in a fleet, and it has no capability to provision RDS databases.

43
MCQeasy

A company needs to deploy a set of microservices using Docker containers on AWS. The deployment should be automated and support scaling based on demand. Which AWS service should be used to orchestrate the containers?

A.AWS Lambda
B.AWS Elastic Beanstalk
C.Amazon ECS
D.AWS CodeDeploy
AnswerC

Amazon ECS is a fully managed container orchestration service purpose-built for running Docker containers at scale. It lets you define task definitions, control scheduling and placement, and integrates natively with Application Load Balancer, IAM, CloudWatch, and VPC networking, making it the right choice for deploying and operating a set of microservices as containers on AWS.

Why this answer

Amazon ECS is a fully managed container orchestration service that integrates with Auto Scaling and CloudWatch to automate deployment and scaling of Docker containers. Option A (Lambda) is for serverless functions, not containers. Option B (Elastic Beanstalk) can deploy containers but is less flexible for microservices orchestration.

Option D (CodeDeploy) is for application deployments, not container orchestration.

44
MCQeasy

A SysOps administrator is creating an AWS CloudFormation template to deploy a web server. The template must define an Amazon EC2 instance, a security group, and an Elastic IP. In which section of the template should these resources be declared?

A.Parameters
B.Resources
C.Outputs
D.Mappings
AnswerB

The Resources section is the mandatory core of any AWS CloudFormation template and the only place where you define actual AWS infrastructure objects, such as EC2 instances, S3 buckets, or IAM roles. Each resource declaration includes a logical ID, an AWS::Service::Type string, and a Properties block that specifies configuration and dependencies. CloudFormation reads this section to orchestrate the creation, updating, and deletion of the stack's resources, so all real-world infrastructure must be declared here.

Why this answer

In an AWS CloudFormation template, the Resources section is the mandatory block where all AWS resources (such as EC2 instances, security groups, and Elastic IPs) are declared and configured. The template's logic for creating, updating, and deleting these infrastructure components is defined exclusively within this section, making B the correct choice.

Exam trap

The trap here is that candidates confuse the purpose of the Parameters section (input values) with the Resources section (resource definitions), often thinking that resources like EC2 instances are 'parameters' because they require configuration values like instance type or AMI ID.

How to eliminate wrong answers

Option A is wrong because the Parameters section is used to accept runtime input values (e.g., instance type, AMI ID) from the user, not to define the resources themselves. Option C is wrong because the Outputs section is used to export information about created resources (e.g., instance public IP) for use by other stacks or users, not to declare the resources. Option D is wrong because the Mappings section is used to create static lookup tables (e.g., mapping AWS regions to AMI IDs) for conditional values, not to define resources.

45
MCQhard

A company uses AWS CloudFormation to deploy a stack that includes an Amazon RDS DB instance with Multi-AZ enabled. During a stack update, the database engine version is changed. The update fails with a rollback. What is the most likely cause?

A.The engine version upgrade is not supported for Multi-AZ deployments.
B.The DB instance class is not available for the new engine version.
C.The storage type is not compatible with the new engine version.
D.The DB subnet group does not have enough IP addresses.
AnswerA

Amazon RDS rejects certain major engine version upgrades on Multi-AZ deployments because the in-place upgrade path is not available for all database engine versions when a standby replica is present. CloudFormation surfaces this as a generic engine version upgrade failure, but the root cause is a service-side limitation, not a misconfigured resource property. To complete the upgrade, you must typically create a snapshot, restore from it, promote the restored instance, or use a blue/green deployment, after which you can update the CloudFormation stack to reference the new instance.

Why this answer

Changing the database engine version on a Multi-AZ RDS instance is not supported directly through a CloudFormation stack update without additional steps. Multi-AZ deployments require both primary and standby instances to be upgraded, and if the new engine version is not compatible or the upgrade path is not supported, the update fails and triggers a rollback. Option B is incorrect because instance class availability is not the primary issue; the error relates to the engine version change, not the instance class.

Option C is incorrect because storage type compatibility is not the relevant factor; the storage type remains unchanged. Option D is incorrect because the DB subnet group is not involved in engine version upgrades, and IP address availability is not a typical cause for this failure.

46
MCQeasy

A company uses AWS CloudFormation to deploy a web application. The template currently hard-codes the EC2 instance type (e.g., t3.medium). The SysOps administrator wants to make the instance type configurable so that different environments (dev, test, prod) can use different instance types without modifying the template each time. Which CloudFormation feature enables this?

A.Parameters
B.Mappings
C.Conditions
D.Outputs
AnswerA

Parameters are the only CloudFormation construct here that accept runtime input. When you create or update a stack, you supply values, either interactively, via CLI, or via a stack template, and those values are referenced with Ref to set resource properties. Because the same template can be reused with different parameter values, parameters are the correct way to make a stack deployable to multiple environments with different configuration.

Why this answer

CloudFormation Parameters allow you to pass custom values into a template at stack creation or update time. By defining a parameter for the instance type (e.g., with allowed values like t3.micro, t3.medium, t3.large), you can reuse the same template across dev, test, and prod environments without editing the template file itself.

Exam trap

The trap here is that candidates often confuse Mappings (which are static and environment-agnostic) with Parameters (which are dynamic and user-supplied), leading them to incorrectly choose Mappings as the way to make values configurable.

How to eliminate wrong answers

Option B is wrong because Mappings are static lookup tables (e.g., mapping environment names to instance types) that are hard-coded in the template and cannot be overridden at deployment time; they do not accept runtime input. Option C is wrong because Conditions control whether certain resources are created based on logical expressions (e.g., create a larger instance only in prod), but they do not make the instance type configurable as a deploy-time variable. Option D is wrong because Outputs are used to return information about deployed resources (e.g., instance ID or public IP) after stack creation; they do not accept input values.

47
MCQmedium

A SysOps administrator is using AWS CloudFormation to deploy a stack that includes an Amazon EC2 instance and an Amazon RDS DB instance. The administrator needs to ensure that updates to the stack do not accidentally replace the RDS instance if the RDS configuration is changed in a way that would require replacement. Which CloudFormation attribute should be added to the RDS resource?

A.UpdateReplacePolicy with Retain
B.DeletionPolicy with Retain
C.StackPolicy
D.CreationPolicy
AnswerA

During a stack update, if a property change requires CloudFormation to replace a resource, the default behavior is to create a new resource and then delete the old one. UpdateReplacePolicy with Retain overrides this by preserving the existing RDS instance and its data, even after the replacement occurs. This is essential for stateful resources like databases, where the old instance contains critical data that would otherwise be lost.

Why this answer

The `UpdateReplacePolicy` attribute with `Retain` tells CloudFormation to preserve the existing RDS DB instance if a stack update would otherwise require its replacement. This prevents accidental deletion and recreation of the RDS instance when its configuration changes in a way that forces a new physical resource, such as modifying the DB engine version or storage type. The `UpdateReplacePolicy` is specifically designed for update scenarios, unlike `DeletionPolicy` which only applies during stack deletion.

Exam trap

The trap here is that candidates confuse `DeletionPolicy` (which only applies to stack deletion) with `UpdateReplacePolicy` (which applies during stack updates), leading them to choose Option B instead of A.

How to eliminate wrong answers

Option B is wrong because `DeletionPolicy` with `Retain` only protects the RDS instance from being deleted when the entire stack is deleted, not during an update that would replace the resource. Option C is wrong because `StackPolicy` controls permissions for stack-level updates (e.g., who can modify resources), not the lifecycle behavior of individual resources during replacement. Option D is wrong because `CreationPolicy` is used to wait for signals or resource creation completion (e.g., with `cfn-signal`), and has no effect on update or replacement behavior.

48
MCQhard

A containerized API runs on Amazon ECS with an Application Load Balancer. The team wants to deploy new container versions with zero downtime, automatically route traffic to the new version only after health checks pass, and automatically roll back if error rates spike within 10 minutes of the shift. Which deployment strategy and configuration implements all three requirements?

A.Use CodeDeploy with the ECS blue/green deployment type, configure a Canary or Linear traffic shifting strategy, and attach a CloudWatch alarm for error rate as a deployment alarm
B.Update the ECS service with a rolling update deployment configuration and set the minimum healthy percent to 100
C.Create a second ECS service with the new task definition and use Route 53 weighted routing to shift traffic at the DNS level
D.Enable ECS circuit breaker on the service to roll back failed deployments automatically
AnswerA

The ECS blue/green deployment starts the green task set, registers it with a second target group, and uses ALB weighted routing to shift traffic progressively. The deployment alarm monitors a 5xx error rate metric. If the alarm enters ALARM state at any point during traffic shifting or the bake period, CodeDeploy automatically shifts traffic back to the original blue target group. The team defines the 10-minute bake window via the deployment configuration's terminationWaitTimeInMinutes.

Why this answer

CodeDeploy's ECS blue/green deployment type supports canary or linear traffic shifting, which automatically routes traffic to the new version only after health checks pass. By attaching a CloudWatch alarm for error rate as a deployment alarm, CodeDeploy can automatically trigger a rollback if error rates spike within the specified monitoring period (e.g., 10 minutes), meeting all three requirements: zero downtime, health-check-gated traffic shifting, and automatic rollback on error rate spikes.

Exam trap

The trap here is that candidates often confuse the ECS circuit breaker (which only handles task-level failures during deployment) with the need for post-deployment error rate monitoring and traffic shifting, leading them to select Option D without realizing it lacks the canary/linear traffic shifting and CloudWatch alarm integration required for automatic rollback based on error spikes.

How to eliminate wrong answers

Option B is wrong because a rolling update with minimum healthy percent set to 100 does not provide automatic rollback based on error rate spikes; it only ensures availability during the update but lacks the traffic-shifting and alarm-based rollback capabilities. Option C is wrong because using Route 53 weighted routing at the DNS level does not provide health-check-gated traffic shifting at the application layer, and DNS caching can cause delayed or uneven traffic distribution, failing to ensure zero downtime and immediate rollback on error spikes. Option D is wrong because the ECS circuit breaker only rolls back a service if tasks fail to start or become unhealthy during deployment, but it does not monitor post-deployment error rates or support canary/linear traffic shifting.

49
Matchingmedium

Match each AWS support plan to its key feature.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Account and billing support only

Business hours email access

24/7 phone, chat, and email; <1 hour response

Concierge support team; <30 min response

Technical Account Manager; <15 min response

Why these pairings

Basic provides community access, Developer provides business hours email, Business provides 24/7 support with 1-hour response, and Enterprise adds a TAM and faster response. Common confusions include swapping Business and Enterprise features.

50
MCQeasy

A SysOps administrator needs to automate the deployment of a three-tier web application. The application consists of an Application Load Balancer, a fleet of EC2 instances running a web server, and an Amazon RDS MySQL database. The administrator must ensure that the database credentials are securely stored and automatically rotated. The administrator also needs to version the infrastructure configuration. Which combination of AWS services should the administrator use?

A.AWS CloudFormation for infrastructure and AWS Systems Manager Parameter Store for secrets.
B.AWS OpsWorks for infrastructure and AWS Secrets Manager for secrets.
C.AWS CodeCommit for infrastructure versioning and AWS KMS for secrets.
D.AWS CloudFormation for infrastructure and AWS Secrets Manager for secrets.
AnswerD

CloudFormation is the correct infrastructure tool because it provisions AWS resources from declarative templates that can be versioned, reviewed, and rolled back, enabling automated and repeatable deployment. Secrets Manager is the correct secrets tool because it natively supports automatic rotation of RDS credentials through a built-in Lambda rotation function, and CloudFormation can securely reference those secrets using dynamic references. Together they satisfy automated deployment and credential rotation in a single operational pipeline.

Why this answer

AWS CloudFormation is used to automate infrastructure deployment and version the configuration as code. AWS Secrets Manager securely stores database credentials and provides automatic rotation. Together, they meet the requirements for secure credential management and infrastructure versioning.

Exam trap

SOA-C02 often tests the difference between Parameter Store and Secrets Manager, particularly around automatic rotation, leading candidates to choose Parameter Store for secrets that require rotation.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Parameter Store can store secrets but does not provide automatic rotation natively; rotation requires custom Lambda functions. Option B is wrong because AWS OpsWorks is a configuration management service that is not primarily used for infrastructure as code versioning; CloudFormation is more suitable. Option C is wrong because AWS CodeCommit is a source control service for code, not specifically for infrastructure versioning, and AWS KMS is a key management service, not a secrets manager with rotation.

51
MCQmedium

A company uses AWS Systems Manager to manage a fleet of EC2 instances. The Security Team requires that all instances have a specific security patch installed. A SysOps administrator needs to verify compliance across all instances. What is the MOST efficient way to accomplish this?

A.Use AWS Config rules to check for the patch.
B.Use AWS Systems Manager State Manager to enforce the patch.
C.Use AWS Systems Manager Inventory to collect software inventory.
D.Use AWS Systems Manager Patch Manager to scan and generate a compliance report.
AnswerD

Patch Manager integrates with the SSM Agent to apply operating system patches and automatically generates compliance reports by default when used with Patch Manager scan operations. These reports classify instances as compliant or non-compliant, list missing patches, and support filtering by severity and patch baseline, exactly matching the need to scan and generate a compliance report. As a native Systems Manager capability, it provides the most direct and correct mechanism for assessing patch compliance across EC2 instances.

Why this answer

AWS Systems Manager Patch Manager can scan instances for missing patches and generate a compliance report showing which instances are compliant or non-compliant with the patch baseline. This directly addresses the requirement to verify compliance across the fleet efficiently. It uses the patch baseline to define approved patches and reports on compliance status.

Exam trap

SOA-C02 often tests the confusion between enforcing a patch (State Manager) and verifying compliance (Patch Manager); candidates must remember that Patch Manager can both scan and report on compliance.

How to eliminate wrong answers

Option A is wrong because AWS Config rules can check for patch compliance only if the patch state is published as a configuration item, which is not automatic; it is less direct and efficient than Patch Manager. Option B is wrong because State Manager enforces a desired state (e.g., installing the patch) but does not itself verify compliance across the fleet; it ensures the patch is applied but does not report on compliance status. Option C is wrong because Inventory collects software inventory but does not specifically verify patch compliance against a baseline.

52
MCQhard

A SysOps administrator is troubleshooting a CodeDeploy deployment that uploads artifacts to an S3 bucket. The deployment fails with an 'AccessDenied' error. The IAM policy for the CodeDeploy service role includes the statement shown in the exhibit. What is the most likely cause of the failure?

A.The upload does not set the ACL to 'bucket-owner-full-control'.
B.The resource ARN does not include the bucket itself.
C.The policy does not allow encryption headers.
D.The policy does not allow the s3:PutObject action.
AnswerA

The upload is denied because CodeDeploy's S3 upload does not include the 'x-amz-acl' header set to 'bucket-owner-full-control'. The bucket policy's condition explicitly requires this ACL value for any PutObject request, and because the header is absent or set differently, S3 evaluates the condition as false and returns AccessDenied. This is the exact mismatch the policy is designed to catch, making the fix to add --acl bucket-owner-full-control to the upload command.

Why this answer

The policy includes a condition that requires the object's ACL to be set to 'bucket-owner-full-control'. If the upload does not specify this ACL in the request, the condition is not met, and the request fails with AccessDenied. Therefore, option A is correct.

Option B is incorrect because the resource ARN does include the bucket (the policy grants access to objects within the bucket). Option C is incorrect because the policy does not mention encryption headers; the condition is about ACL. Option D is incorrect because the s3:PutObject action is allowed by the policy; the failure is due to the condition on ACL.

53
Multi-Selecteasy

A SysOps Administrator needs to automate the deployment of a three-tier web application on AWS. The application consists of a web tier, application tier, and database tier. The administrator wants to use AWS CloudFormation to provision the infrastructure. Which TWO resources should be included in the CloudFormation template to ensure the application is highly available across multiple Availability Zones?

Select 2 answers
A.Auto Scaling group
C.Amazon S3 bucket
D.Amazon Route 53 hosted zone
E.Application Load Balancer
AnswersA, E

An Auto Scaling group is capacity management that spans multiple Availability Zones, launching and terminating instances to maintain a desired count and to replace unhealthy ones automatically. By distributing instances across AZs, it ensures that the application tier remains available even if an entire AZ becomes unavailable, providing fault tolerance and elasticity.

Why this answer

Option A (Auto Scaling group) is correct because it distributes EC2 instances across multiple Availability Zones within a region and automatically replaces unhealthy instances, providing high availability and elasticity for the web and application tiers. Option E (Application Load Balancer) is correct because it is a regional, multi-AZ load balancer that routes traffic to healthy targets in multiple Availability Zones, which is essential for a highly available three-tier architecture. Option B (NAT Gateway) only provides outbound internet access for private subnets and does not by itself deliver multi-AZ high availability.

Option C (Amazon S3 bucket) is object storage and is not the mechanism for achieving multi-AZ compute availability. Option D (Amazon Route 53 hosted zone) provides DNS resolution and can support failover routing, but it is not the resource that ensures the application's tiers are highly available across Availability Zones.

Exam trap

SOA-C02 often tests the distinction between resources that provide HA (ASG, multi-AZ ALB) and resources that are merely supporting infrastructure (NAT Gateway, S3, Route 53) — candidates over-select supporting services thinking they add redundancy.

54
MCQmedium

A SysOps administrator needs to deploy the same AWS CloudFormation template across multiple AWS accounts and Regions in a single operation. The administrator wants to manage the deployment from a single management account. Which AWS service should the administrator use?

A.AWS CodeDeploy
B.AWS Elastic Beanstalk
C.AWS CloudFormation StackSets
D.AWS Service Catalog
AnswerC

AWS CloudFormation StackSets is the correct service because it extends the capability of CloudFormation to deploy stacks across multiple AWS accounts and multiple Regions from a single administrator account. You define a CloudFormation template once, and StackSets creates and manages stack instances in target accounts/Regions, propagating updates and handling automatic rollback if any deployment fails. This provides the centralized, repeatable, and cross-account infrastructure deployment exactly as the sysops administrator needs.

Why this answer

AWS CloudFormation StackSets extends the functionality of CloudFormation by allowing you to deploy the same template across multiple accounts and Regions from a single management account. StackSets uses a self-managed or service-managed permission model to create, update, and delete stacks across target accounts in a single operation, making it the correct choice for this multi-account, multi-Region deployment requirement.

Exam trap

The trap here is that candidates often confuse AWS Service Catalog (which can provision CloudFormation stacks but only within a single account or via StackSets integration) with the native multi-account deployment capability of CloudFormation StackSets, leading them to select Service Catalog as the answer.

How to eliminate wrong answers

Option A is wrong because AWS CodeDeploy is a service for automating code deployments to EC2 instances, on-premises instances, or Lambda functions, not for deploying CloudFormation templates across multiple accounts and Regions. Option B is wrong because AWS Elastic Beanstalk is a PaaS service for deploying and scaling web applications, not for managing multi-account, multi-Region infrastructure deployments via CloudFormation templates. Option D is wrong because AWS Service Catalog allows you to create and manage a catalog of approved IT services (including CloudFormation products), but it does not natively deploy a single template across multiple accounts and Regions in one operation; it requires additional orchestration or StackSets integration for that capability.

55
MCQeasy

A SysOps administrator is tasked with automating the deployment of an application across multiple AWS accounts. Which AWS service should be used to orchestrate the deployment across accounts?

A.AWS CodeDeploy
B.AWS CloudFormation StackSets
C.AWS Service Catalog
D.AWS Systems Manager
AnswerB

AWS CloudFormation StackSets extends AWS CloudFormation to deploy and manage stacks across multiple accounts and regions from a single administrator account, which exactly matches the requirement to automate infrastructure deployment across accounts. StackSets use a stack set to define a template and a list of target accounts, then create, update, or delete stacks in each account and region in a single operation, with automatic rollback if any stack fails. You can also integrate StackSets with AWS Organizations to automatically deploy to all accounts in an organization, and use a delegated administrator for centralized management. This makes StackSets the correct choice for the stated automation scenario.

Why this answer

AWS CloudFormation StackSets allows a single CloudFormation template to be deployed across multiple AWS accounts and regions from a central administrator account. It is purpose-built for cross-account orchestration, using a service-managed or self-managed permission model to push stacks to target OUs or accounts. This makes it the correct service for automating multi-account deployments.

Exam trap

The trap is confusing application deployment services (CodeDeploy) or instance management (Systems Manager) with infrastructure orchestration across accounts — the key phrase 'across multiple AWS accounts' points specifically to CloudFormation StackSets.

How to eliminate wrong answers

Option A is wrong because AWS CodeDeploy automates application deployments to EC2, Lambda, or on-premises instances but does not orchestrate infrastructure deployments across multiple AWS accounts. Option C is wrong because AWS Service Catalog lets organizations create and manage approved product portfolios for users, but it does not itself orchestrate cross-account deployments (though it can reference StackSets). Option D is wrong because AWS Systems Manager manages instances and operations (patching, run commands) but is not designed for cross-account infrastructure orchestration.

56
MCQhard

A company uses AWS Elastic Beanstalk to deploy a web application. During a deployment, the environment's health turns from Green to Red, and the deployment fails. The logs show 'ERROR: Failed to download the application version from Amazon S3.' What is the MOST likely cause?

A.The EC2 instance profile does not have an IAM policy granting s3:GetObject on the application version
B.The Elastic Beanstalk service role does not have permissions to access S3
C.The S3 bucket is in a different AWS Region
D.The S3 bucket containing the application version has public read access disabled
AnswerA

In Elastic Beanstalk, the EC2 instances that form your environment rely on the instance profile (an IAM role) to retrieve the application source bundle from Amazon S3 during deployment. If that instance profile is missing a policy permitting s3:GetObject on the bucket or object containing the application version, the instances receive an Access Denied error and the deployment fails. This is the classic root cause because many assume the service role handles this, but the service role is only used by the Elastic Beanstalk service itself.

Why this answer

The error 'Failed to download the application version from Amazon S3' indicates that the EC2 instances in the Elastic Beanstalk environment cannot access the S3 bucket where the application version is stored. The most likely cause is that the EC2 instance profile (IAM role) lacks the necessary s3:GetObject permission on the application version object. Elastic Beanstalk uses the instance profile to download the application from S3 during deployment.

Exam trap

SOA-C02 often tests the difference between the instance profile and the service role, and candidates may incorrectly blame the service role for S3 access issues.

How to eliminate wrong answers

Option B is wrong because the Elastic Beanstalk service role is used by the service to manage resources, not by the instances to download the application; the instance profile is responsible for that. Option C is wrong because S3 buckets are region-specific, but Elastic Beanstalk can access buckets in other regions if permissions allow; cross-region access is possible and not the primary cause. Option D is wrong because public read access is not required; the instances use their IAM role for access, so disabling public access does not prevent downloads.

57
MCQhard

A company uses AWS CodePipeline with AWS CodeBuild to build and deploy a static website to an S3 bucket. The website is served via Amazon CloudFront. The deployment fails intermittently because the S3 bucket policy does not allow CloudFront access after the bucket is updated. What is the BEST way to automate the bucket policy update during the deployment?

A.Include an AWS CLI command in the buildspec to update the bucket policy after the build.
B.Use AWS CloudFormation to manage the S3 bucket and its policy, and update the stack as part of the pipeline.
C.Add a bucket policy statement in the S3 management console to grant CloudFront access.
D.Use a CloudFront origin access identity (OAI) and configure it in the bucket policy.
AnswerB

Using CloudFormation to manage the S3 bucket and its bucket policy is the recommended infrastructure-as-code practice. When the stack is updated as part of the CodePipeline execution, any policy changes are applied deterministically, with drift detection and automatic rollback on failure. This ensures the CloudFront origin access configuration and bucket policy remain in sync across every deployment, eliminating manual intervention and reducing the risk of misconfiguration.

Why this answer

AWS CloudFormation can manage the S3 bucket and its policy as part of the infrastructure. Using CloudFormation, the bucket policy can be updated automatically when the stack is updated, ensuring that CloudFront access is maintained. Option A is incorrect because including an AWS CLI command in the buildspec may work but is less robust and not as automated as using CloudFormation.

Option C is incorrect because manually adding a bucket policy statement in the S3 management console is not automated and prone to errors. Option D is incorrect because while using a CloudFront origin access identity (OAI) and configuring it in the bucket policy is a best practice, it does not automate the policy update during deployment; CloudFormation handles this automatically.

58
Multi-Selectmedium

A SysOps administrator needs to automate the provisioning of AWS resources using infrastructure as code. The administrator wants to ensure that the code is version-controlled and that changes are reviewed before deployment. Which TWO AWS services should the administrator use together to achieve this? (Choose TWO.)

Select 2 answers
A.AWS Config
B.AWS CloudFormation
C.AWS CodeCommit
D.AWS Service Catalog
E.AWS OpsWorks Stacks
AnswersB, C

AWS CloudFormation is the correct service for infrastructure provisioning because it implements infrastructure as code through declarative JSON or YAML templates. It orchestrates the creation, update, and deletion of entire stacks, managing dependencies, rollbacks, and change sets so resources are provisioned in a predictable and repeatable way. This makes it the core engine for automating the deployment of AWS environments.

Why this answer

AWS CloudFormation (B) is correct because it provides infrastructure as code, allowing the administrator to define and provision AWS resources declaratively through templates, which is exactly what is needed for automated provisioning. AWS CodeCommit (C) is correct because it is a fully managed Git-based version control service that stores the CloudFormation templates, enabling version control and supporting pull requests so changes can be reviewed before deployment. Together, CodeCommit holds and reviews the template code while CloudFormation deploys it, satisfying both the version-control and review requirements.

AWS Config (A) is incorrect because it is used for assessing, auditing, and evaluating resource configurations for compliance, not for provisioning or version-controlling code. AWS Service Catalog (D) is incorrect because it lets organizations create and manage approved product portfolios for end users, but it does not itself provide version control or code review. AWS OpsWorks Stacks (E) is incorrect because it is a configuration management service using Chef/Puppet for managing application stacks, not a Git-based version control or review service.

Exam trap

The trap is that candidates pick AWS Config or Service Catalog because they sound like governance/automation services, but the question specifically requires version control and code review, which only CodeCommit provides among the options.

59
MCQeasy

A company is using AWS CodeDeploy to deploy an application to an EC2 instances in an Auto Scaling group. The deployment fails because the instances are not reporting to CodeDeploy. What is the most likely cause?

A.The security group does not allow inbound traffic from CodeDeploy.
B.The instances do not have the correct IAM role to allow CodeDeploy to access them.
C.The application is not running on the instances.
D.The CodeDeploy agent is not installed on the instances.
AnswerD

The CodeDeploy agent is the on-instance software component responsible for all communication with the CodeDeploy service. It polls the CodeDeploy endpoint for queued deployments, downloads the application revision, runs the lifecycle event scripts defined in the AppSpec file, and reports success or failure back to the service. Without the agent installed on an instance, the instance cannot receive any deployment commands, and CodeDeploy will report that no instances are connected or that the deployment is stuck with zero healthy instances. This is the exact, direct reason why the deployment is not progressing; installing and starting the agent on each target instance would resolve the issue.

Why this answer

The most likely cause is that the CodeDeploy agent is not installed on the instances. The agent is required to communicate with the CodeDeploy service and execute deployments. Option A is incorrect because the security group needs to allow outbound traffic from the instances to CodeDeploy, not inbound.

Option B is incorrect because the IAM role is necessary for the instances to access CodeDeploy, but the immediate issue of not reporting is the agent. Option C is incorrect because the application not running is a symptom, not the cause of the reporting failure.

60
MCQhard

A company is using AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment fails because the instances in the Auto Scaling group are not registered with the target group of an Application Load Balancer. The SysOps administrator needs to ensure that new instances launched by the Auto Scaling group are automatically registered with the target group. What should the administrator do?

A.Use Amazon Inspector to automatically register instances with the target group.
B.Attach the target group to the Auto Scaling group.
C.Create a lifecycle hook in the Auto Scaling group to register instances with the target group.
D.Configure the Auto Scaling group to launch instances with a user data script that registers the instance with the target group.
AnswerB

Attaching the target group to the Auto Scaling group is the AWS-recommended managed integration: when the Auto Scaling group launches new instances, it automatically registers them with the attached target group, and when instances are terminated, it deregisters them. This ensures that CodeDeploy, which can deploy to instances registered with a target group, has a current and accurate list of deployment targets without custom scripting. This approach is the correct answer because it leverages native AWS orchestration to keep target group membership synchronized with the Auto Scaling group's instance lifecycle.

Why this answer

To ensure that instances launched by an Auto Scaling group are automatically registered with an Application Load Balancer target group, the target group must be attached to the Auto Scaling group. This is done by specifying the target group ARN in the Auto Scaling group's configuration (via the console, CLI, or CloudFormation). When attached, the Auto Scaling group automatically registers new instances with the target group and deregisters terminated ones.

Exam trap

SOA-C02 often tests whether candidates choose manual workarounds (user data scripts, lifecycle hooks) over native AWS integrations, so the trap is picking a more complex solution when a simple attachment exists.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability management service that scans instances for security issues; it has no capability to register instances with a target group. Option C is wrong because a lifecycle hook pauses instances during launch/termination for custom actions, but it does not automatically register instances with a target group; you would need a custom Lambda function, which is unnecessary when the native attachment exists. Option D is wrong because a user data script could call the ELB API to register the instance, but this is a manual, error-prone workaround; the native Auto Scaling group target group attachment is the correct, supported method.

61
MCQmedium

A DevOps engineer is troubleshooting a failed CloudFormation stack update. The stack includes an Auto Scaling group with a launch template. The update changed the AMI ID in the launch template, but the new instances launched with the old AMI. What is the most likely cause?

A.The Auto Scaling group is not configured to perform a rolling update.
B.The new AMI ID is invalid or not available in the region.
C.The CloudFormation stack update did not successfully complete.
D.The launch template version is not set to use the latest version.
AnswerD

When an Auto Scaling group uses a launch template, it references a specific version of that template through the Version property. Updating the AMI inside the CloudFormation stack creates a new version of the launch template, but the ASG may still point to the old default version or a fixed version number. If the Version is not set to $Latest or explicitly updated to the new version number, any new instances launched by the ASG will continue to use the old template, and therefore the old AMI. This is exactly the behavior described, so this is the correct root cause.

Why this answer

When a CloudFormation stack references a launch template by ID without pinning a version, the Auto Scaling group uses the template's default version. Updating the AMI in a new launch template version does not change the default version automatically, so the ASG continues launching instances from the old default version. The fix is to either set the new version as default or explicitly reference the version in the ASG's LaunchTemplate specification.

Exam trap

SOA-C02 often tests the misconception that editing a launch template automatically updates the Auto Scaling group — candidates forget that launch templates are versioned and the ASG may be pinned to `$Default` or a specific version, so new AMIs only take effect after the version reference is updated.

How to eliminate wrong answers

Option A is wrong because rolling update configuration affects how existing instances are replaced during a deployment, not which AMI new instances use — even with rolling updates, if the ASG references the old launch template version, new instances use the old AMI. Option B is wrong because an invalid or unavailable AMI would cause instance launch failures (e.g., InvalidAMIID.NotFound), not silent use of the old AMI. Option C is wrong because a failed stack update would roll back or leave the stack in UPDATE_ROLLBACK state, and the symptom described is successful launches with the wrong AMI, not a failed update.

62
Drag & Dropmedium

Drag and drop the steps to restore an Amazon RDS DB instance from a snapshot into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Restoration starts by selecting the snapshot, then configuring instance details, security, and parameters, then initiating the restore.

63
MCQmedium

A SysOps administrator is creating an IAM policy for automation. The policy is attached to an IAM role used by an automated deployment script. The script needs to launch EC2 instances of type t2.micro and describe all EC2 resources. However, the script fails when trying to launch instances. What is the MOST likely reason?

A.The Resource ARN for the instance is incorrect.
B.The policy does not include the 'ec2:DescribeInstances' action.
C.The policy does not grant permissions for additional resources required by RunInstances, such as images, network interfaces, and security groups.
D.The Condition key 'ec2:InstanceType' is misspelled.
AnswerC

RunInstances is a multi-resource API action: IAM evaluates it against every resource type that the new instance will create or use, including the AMI (image), network interface, security group, volume, and optionally subnet and key pair. A policy that only grants ec2:RunInstances on the instance ARN (e.g., arn:aws:ec2:region:account:instance/*) does not grant the needed permissions on those other resource types, so the request will be denied even though the instance ARN itself is correct. To allow the launch, you must either use Resource * for the ec2:RunInstances action or provide a separate statement with the appropriate ARNs for each resource type involved. This is the core reason the policy fails as written.

Why this answer

The RunInstances API action requires permissions for not only the EC2 instance resource itself but also for dependent resources such as Amazon Machine Images (AMI), network interfaces, security groups, and key pairs. If the IAM policy only grants ec2:RunInstances on the instance resource ARN but omits these supporting resources, the launch will fail with an 'unauthorized operation' error. Option C correctly identifies this missing dependency.

Exam trap

The trap here is that candidates assume granting ec2:RunInstances on the instance resource is sufficient, overlooking that AWS requires explicit permissions for all dependent resources that are implicitly created or modified during instance launch.

How to eliminate wrong answers

Option A is wrong because an incorrect Resource ARN would cause a failure for all actions referencing that ARN, but the script can describe EC2 resources, indicating the ARN is valid for DescribeInstances; the failure is specific to RunInstances. Option B is wrong because the script successfully describes EC2 resources, so ec2:DescribeInstances must be present in the policy. Option D is wrong because a misspelled Condition key would not cause a launch failure unless the condition was evaluated and rejected; the error is due to missing permissions, not a condition syntax issue.

64
MCQmedium

A SysOps administrator needs to deploy a new version of a Lambda function while minimizing downtime. The function is behind an API Gateway endpoint. What is the MOST effective approach?

A.Update the Lambda function code in-place and publish a new version
B.Create a new Lambda version, then use an alias with weighted routing to shift traffic gradually
C.Create a new Lambda version and update the API Gateway integration to point to it
D.Deploy a new Lambda function and use an Amazon Route 53 weighted record set to distribute traffic
AnswerB

This is the correct approach because it leverages Lambda's built-in alias weighting to implement a canary deployment. You first publish the updated code as a new immutable version, then configure the alias (e.g., the one referenced by API Gateway) with a weighted routing policy, sending a small percentage of traffic to the new version and gradually increasing it as confidence grows. Weighted aliases allow you to monitor error rates and latency, and instantly roll back by shifting weight back to the old version without redeploying code. Unlike the other options, this method preserves the ability to test new code with a fraction of real traffic while keeping the previous version fully available.

Why this answer

The most effective approach for zero-downtime Lambda deployment behind API Gateway is to publish a new version and use an alias with weighted routing (canary or linear). API Gateway integrates with the alias ARN, so traffic can be shifted gradually from the old version to the new one, allowing rollback if errors spike. This is the native, serverless-safe deployment pattern that minimizes downtime and risk.

Exam trap

SOA-C02 often tests the difference between DNS-level traffic shifting (Route 53) and Lambda alias-level traffic shifting, so candidates who pick Route 53 weighted records misunderstand that Lambda versions are not DNS-addressable.

How to eliminate wrong answers

Option A is wrong because updating the function code in-place (even with a new version) does not provide traffic shifting — the $LATEST or alias still points to the new code immediately, causing a hard cutover and potential downtime if the new code fails. Option C is wrong because pointing API Gateway directly to a new version creates an all-or-nothing switch with no gradual traffic shift and no easy rollback without reconfiguring the integration. Option D is wrong because Route 53 weighted records operate at the DNS layer and cannot distribute traffic between Lambda versions — Lambda is not addressed by DNS; API Gateway is the integration point, and Route 53 would only route to different API Gateway endpoints, not Lambda versions.

65
MCQeasy

A SysOps administrator needs to automate the provisioning of AWS resources using infrastructure as code. The solution must track changes and allow rollbacks. Which AWS service should the administrator use?

A.AWS CloudFormation
B.AWS Config
C.AWS Service Catalog
D.AWS OpsWorks
AnswerA

AWS CloudFormation is the core Infrastructure as Code (IaC) service on AWS. You define resources declaratively in JSON or YAML templates, and CloudFormation creates and updates those resources as stacks. It automatically rolls back changes on failure, providing safe, repeatable provisioning of entire environments. This makes it the correct choice for automating provisioning.

Why this answer

AWS CloudFormation provides infrastructure as code with change tracking and rollback capabilities. Option B (AWS Config) is for compliance and auditing, not provisioning. Option C (AWS Service Catalog) is for managing approved products, not general IaC.

Option D (AWS OpsWorks) is a configuration management service, not primarily IaC.

66
MCQmedium

A SysOps administrator is tasked with automating the creation of IAM roles and policies using AWS CloudFormation. The template includes an IAM role and a managed policy. The stack creation fails with the error 'Policy arn:aws:iam::123456789012:policy/MyManagedPolicy not found'. The policy is created in the same template. What is the MOST likely solution?

A.Add a 'DependsOn' clause to the IAM role resource for the managed policy, and reference the policy ARN using the 'Ref' intrinsic function.
B.Remove the policy document from the template and create the policy separately.
C.Use a custom resource to create the policy before the role.
D.Create the IAM role in a separate stack.
AnswerA

In CloudFormation, a DependsOn attribute forces the IAM role resource to wait for the managed policy resource to be fully created before proceeding. The Ref intrinsic function on an IAM managed policy returns its ARN by default, so you can directly pass that ARN into the role's ManagedPolicyArns property. Without DependsOn, CloudFormation may attempt to attach the policy before it exists, causing the 'policy not found' error. This native dependency declaration is the simplest, most reliable fix.

Why this answer

The error occurs because CloudFormation attempts to create the IAM role before the managed policy is fully created, even though both are defined in the same template. Adding a 'DependsOn' clause to the IAM role resource ensures that CloudFormation waits for the managed policy to be created first. Using the 'Ref' intrinsic function to reference the policy ARN is correct because 'Ref' for an AWS::IAM::ManagedPolicy returns the policy ARN, which is needed for the role's 'ManagedPolicyArns' property.

Exam trap

The trap here is that candidates assume CloudFormation automatically detects all dependencies based on resource references, but it only does so for direct 'Ref' or 'Fn::GetAtt' calls, not for ARN strings passed as parameters or hardcoded values, leading to a race condition where the role is created before the policy.

How to eliminate wrong answers

Option B is wrong because creating the policy separately defeats the purpose of automation and does not resolve the dependency issue within the single template; it introduces manual steps and increases management overhead. Option C is wrong because using a custom resource is unnecessary and overly complex when a simple 'DependsOn' clause can resolve the dependency; custom resources are typically used for operations not natively supported by CloudFormation. Option D is wrong because creating the IAM role in a separate stack does not fix the dependency issue; it only shifts the problem to cross-stack references, which still require careful ordering and may introduce additional complexity.

67
MCQhard

A SysOps administrator is automating the creation of Amazon RDS DB instances using AWS CloudFormation. The template includes a DB instance with a Multi-AZ deployment. During a stack update, the administrator changes the DB instance class from db.t3.small to db.t3.medium. What is the expected behavior during the update?

A.RDS will create a new DB instance with the new class and delete the old one.
B.RDS will modify both instances simultaneously, causing a brief outage.
C.The update will fail because CloudFormation cannot modify a Multi-AZ DB instance class.
D.RDS will modify the standby instance first, then fail over to it, and finally modify the original primary, resulting in minimal downtime.
AnswerD

This is exactly how RDS handles instance-class changes for Multi-AZ DB instances. Because the primary and standby run in different Availability Zones, RDS first applies the new class to the standby while the primary continues to serve traffic. It then performs a failover—typically causing a short DNS/connection disruption of a few seconds—to promote the upgraded instance to primary, and finally applies the new class to the original primary, which is now the standby. This rolling pattern keeps downtime to a minimum and is the documented behavior for class modifications on Multi-AZ deployments.

Why this answer

When updating a Multi-AZ RDS DB instance class via CloudFormation, AWS performs a 'rolling upgrade' to minimize downtime. RDS first modifies the standby instance to the new class, then initiates a failover to make the standby the new primary, and finally modifies the original primary (now the standby) to the new class. This results in only a brief outage during the failover, typically lasting 60–120 seconds.

Exam trap

The trap here is that candidates assume any modification to a Multi-AZ instance causes a full replacement or simultaneous outage, but AWS specifically designed the Multi-AZ update process to minimize downtime by modifying the standby first and then failing over.

How to eliminate wrong answers

Option A is wrong because RDS does not create a new instance and delete the old one for a class modification; that would cause a full replacement with longer downtime. Option B is wrong because RDS does not modify both instances simultaneously; modifying both at once would cause a longer outage or data inconsistency. Option C is wrong because CloudFormation can modify a Multi-AZ DB instance class; the update does not fail, and AWS supports this operation with minimal downtime.

68
Multi-Selectmedium

A SysOps administrator is automating the creation of an Amazon ECS cluster with Fargate launch type using AWS CloudFormation. The template must define the task definition, service, and cluster. Which THREE resources are required to be in the template? (Choose THREE.)

Select 3 answers
A.AWS::EC2::VPC
B.AWS::ECS::TaskDefinition
C.AWS::ECS::Service
D.AWS::ECS::Cluster
E.AWS::ElasticLoadBalancingV2::LoadBalancer
AnswersB, C, D

A task definition is the core configuration document that ECS uses to launch containers. It specifies the Docker image, CPU and memory limits, port mappings, environment variables, logging configuration, and IAM roles. Without a task definition, ECS cannot start a container, making it the fundamental resource required for any ECS deployment.

Why this answer

For an Amazon ECS cluster using the Fargate launch type, the AWS CloudFormation template must define the cluster itself (AWS::ECS::Cluster), the task definition (AWS::ECS::TaskDefinition) that specifies the container image, CPU, memory, and networking configuration, and the service (AWS::ECS::Service) that maintains the desired count of tasks and optionally integrates with a load balancer. These three resources are the minimum required to create and run a Fargate-based ECS workload.

Exam trap

The trap here is that candidates often assume a VPC or load balancer is mandatory for ECS Fargate, but the exam tests that only the cluster, task definition, and service are strictly required, while networking resources can be supplied externally.

69
MCQmedium

A SysOps administrator uses AWS CloudFormation to deploy a stack that includes an Amazon EC2 instance. The administrator wants to ensure that if the stack is updated, the EC2 instance is not accidentally replaced if its properties change. The administrator wants the stack update to fail when a property change would require replacement. Which CloudFormation feature should the administrator use?

A.CreationPolicy
B.DeletionPolicy
C.StackPolicy
D.UpdateReplacePolicy
AnswerC

StackPolicy allows you to define update permissions for stack resources, including denying update actions that would cause replacement, effectively causing the update to fail if such changes are attempted. This meets the requirement.

Why this answer

StackPolicy, is correct because a stack policy is a JSON document that defines which stack resources can be updated or replaced during a stack update. By setting a Deny effect on update actions for the EC2 instance, the administrator can prevent any property change that would cause replacement, causing the update to fail instead of replacing the instance. This directly meets the requirement to block accidental replacement.

Exam trap

The trap here is that candidates often confuse UpdateReplacePolicy (which manages what happens to the old resource after replacement) with a mechanism to prevent replacement, but UpdateReplacePolicy does not block the update—it only controls the disposition of the replaced resource.

How to eliminate wrong answers

Option A is wrong because a CreationPolicy is used to wait for signals (e.g., from cfn-signal) before declaring the resource creation complete; it does not control update behavior or prevent replacement. Option B is wrong because a DeletionPolicy defines what happens to a resource when the stack is deleted (e.g., retain, snapshot, delete), not during an update. Option D is wrong because an UpdateReplacePolicy controls the behavior of a resource when it is replaced during an update (e.g., retain the old resource), but it does not prevent the update from occurring or failing; it only dictates what happens to the replaced resource.

70
MCQeasy

A company is using AWS OpsWorks for configuration management of their EC2 instances. The SysOps Administrator wants to migrate to AWS Systems Manager for a more modern approach. The administrator needs to ensure that existing instances running Amazon Linux 2 can be managed by Systems Manager without downtime. The instances are currently in a running state and are critical to operations. What should the administrator do?

A.Change the OpsWorks stack configuration to use Systems Manager instead of OpsWorks agent.
B.Create a custom AMI with the SSM Agent pre-installed and launch new instances from it.
C.Delete the OpsWorks stack and recreate it with Systems Manager integration.
D.Install the SSM Agent on the existing instances using a script or AWS Systems Manager Run Command.
AnswerD

Installing the SSM Agent directly on the existing instances, either by running an installation script or via AWS Systems Manager Run Command (once connectivity to the SSM service is available), is an in-place, non-destructive operation. It preserves the OpsWorks stack, all current configurations, and avoids instance replacement or downtime. This enables Systems Manager capabilities such as Run Command, Patch Manager, and Inventory to work alongside OpsWorks' existing configuration management.

Why this answer

The AWS Systems Manager Agent (SSM Agent) can be installed on existing running Amazon Linux 2 instances using a script or AWS Systems Manager Run Command, enabling management by Systems Manager without any downtime. Option A is incorrect because changing the OpsWorks stack configuration does not install the SSM Agent; the stack would still rely on the OpsWorks agent. Option B is incorrect because creating a custom AMI and launching new instances would require replacing the existing instances, causing downtime.

Option C is incorrect because deleting and recreating the OpsWorks stack would be disruptive and does not address the need to manage existing instances without downtime.

71
MCQeasy

A SysOps administrator wants to automate the creation of an Amazon RDS database instance using AWS CloudFormation. The database must be created in a specific VPC and must be Multi-AZ. Which CloudFormation resource property should the administrator configure to meet these requirements?

A.DBSubnetGroupName and MultiAZ
B.Engine
C.DBInstanceClass
D.DBInstanceIdentifier
AnswerA

DBSubnetGroupName specifies the VPC subnet group where the RDS instance will be provisioned, and MultiAZ (or Multi-AZ) enables a synchronous standby replica in a different Availability Zone. Together they are the required parameters for automating a Multi-AZ deployment across a defined network topology. Without a valid DBSubnetGroupName spanning at least two AZs, the MultiAZ setting cannot be properly fulfilled.

Why this answer

The DBSubnetGroupName property specifies the VPC subnets for the RDS instance, ensuring it is created in the desired VPC. The MultiAZ property enables Multi-AZ deployment for high availability. Other options: DBInstanceIdentifier (D) is only a name, Engine (B) defines the database engine type, and DBInstanceClass (C) specifies the instance size; none affect VPC placement or Multi-AZ functionality.

72
Multi-Selectmedium

A SysOps administrator is using AWS CodeDeploy to deploy a new version of an application to a fleet of Amazon EC2 instances. The deployment must minimize downtime and automatically roll back if any instance fails health checks. The administrator needs to configure the deployment group settings. Which two actions should the administrator take to meet these requirements? (Choose two.)

Select 2 answers
A.Configure the deployment configuration to use a custom deployment configuration with a minimum healthy hosts value of 0.
B.Associate the deployment group with an Application Load Balancer and enable load balancer health checks.
C.Configure the deployment configuration to use CodeDeployDefault.HalfAtATime.
D.Configure the deployment configuration to use CodeDeployDefault.OneAtATime.
E.Enable automatic rollback on deployment failure in the deployment group settings.
AnswersB, E

Associating the deployment group with an Application Load Balancer and enabling load balancer health checks allows CodeDeploy to validate the health of new instances before routing traffic to them. If an instance fails health checks, the deployment can be stopped and rolled back. This helps minimize downtime by ensuring only healthy instances serve traffic.

Why this answer

To minimize downtime and automatically roll back on failure, the administrator should enable automatic rollback in the deployment group and associate the deployment group with an Application Load Balancer with health checks. Automatic rollback ensures recovery from failures, while load balancer health checks ensure that only healthy instances receive traffic. Together, these settings provide a safe deployment with minimal downtime.

Exam trap

The trap here is focusing solely on deployment configuration (like OneAtATime) and overlooking that automatic rollback and load balancer health checks are separate settings that must be explicitly enabled.

73
MCQmedium

A company has multiple AWS accounts managed under AWS Organizations. The SysOps administrator needs to deploy a common AWS CloudFormation template to all accounts in a specific organizational unit (OU), ensuring consistent security group configurations across the organization. Which AWS service should the administrator use to perform this deployment?

A.AWS CloudFormation StackSets
B.AWS CodePipeline with cross-account actions
C.AWS Service Catalog portfolio
D.AWS Systems Manager Automation
AnswerA

AWS CloudFormation StackSets is the correct choice because it is purpose-built to deploy the same CloudFormation template across many accounts and regions from a single operation. With service-managed permissions, StackSets integrates natively with AWS Organizations, letting the sysops admin target entire organizational units (OUs) and automatically handle account addition/removal without custom roles or scripts. This delivers the least operational overhead for centralized, standardized stack deployment.

Why this answer

AWS CloudFormation StackSets extends the functionality of CloudFormation by allowing you to deploy a common template across multiple accounts and regions from a single management account. In this scenario, the administrator can target the specific organizational unit (OU) within AWS Organizations, ensuring consistent security group configurations are applied to all member accounts without manual intervention.

Exam trap

The trap here is that candidates often confuse AWS Service Catalog as a deployment mechanism for multi-account rollouts, but it is a governance tool for end-user provisioning, not an automated push deployment service like StackSets.

How to eliminate wrong answers

Option B is wrong because AWS CodePipeline with cross-account actions is a CI/CD service that orchestrates build, test, and deploy stages, but it does not natively support deploying a single template to multiple accounts in an OU with built-in drift detection and rollback; it would require custom scripting and manual account targeting. Option C is wrong because AWS Service Catalog portfolios allow you to create and manage a catalog of approved products (including CloudFormation templates) that users can launch, but it does not automatically deploy templates to all accounts in an OU; it relies on end-user self-service provisioning. Option D is wrong because AWS Systems Manager Automation is designed for operational tasks like patching, configuration management, and remediation across instances, not for deploying CloudFormation templates to multiple AWS accounts; it lacks the multi-account, multi-region orchestration capabilities of StackSets.

74
MCQmedium

A company uses AWS Elastic Beanstalk for a Java web application. The SysOps administrator needs to deploy a new version of the application with zero downtime and minimize the risk of failure. The administrator wants to deploy the new version to a completely new set of instances, test them, and then swap the environment's CNAME to point to the new instances. Which deployment policy should the administrator choose?

A.All at once
B.Rolling
C.Rolling with additional batch
D.Immutable
AnswerD

Immutable deployment creates a completely separate Auto Scaling group (with its own instances and target group) running the new application version, and Elastic Beanstalk performs health checks against that isolated stack before any traffic is shifted. Once the new instances pass all health checks, Elastic Beanstalk atomically swaps the environment's CNAME (or re-registers the target group) so all production traffic moves to the new version at once. If a health check fails or an alarm is triggered, the new Auto Scaling group is terminated and the old environment remains untouched, giving you a near-instant rollback and zero downtime. This is the most appropriate option when the requirement is to avoid any interruption and guarantee that a bad release never affects existing users.

Why this answer

The Immutable deployment policy (Option D) is correct because it launches a completely new set of instances in a separate Auto Scaling group, deploys the new application version to them, and then swaps the environment's CNAME to point to the new instances. This ensures zero downtime and minimizes risk by allowing full testing of the new instances before traffic is switched, and if the deployment fails, the original instances remain untouched.

Exam trap

The trap here is that candidates often confuse 'Rolling with additional batch' with creating a completely new set of instances, but it still modifies the existing fleet in batches rather than deploying to an entirely separate environment for a CNAME swap.

How to eliminate wrong answers

Option A is wrong because the 'All at once' deployment policy deploys the new version to all instances simultaneously, causing downtime and no ability to test before traffic is served. Option B is wrong because the 'Rolling' deployment policy updates instances in batches, which does not create a completely new set of instances and can cause partial downtime or mixed versions during the process. Option C is wrong because 'Rolling with additional batch' adds a temporary batch of instances during the rolling update, but it still updates existing instances in batches rather than deploying to a completely new set, and it does not perform a full CNAME swap.

75
MCQmedium

A company uses AWS CodePipeline to deploy a web application to Amazon EC2 instances behind an Application Load Balancer. During a deployment, the pipeline fails at the Deploy stage with an error indicating that the CodeDeploy agent is not responding. The instances are in an Auto Scaling group. What is the MOST likely cause of this issue?

A.The pipeline does not have a VPC endpoint to connect to the instances.
B.The IAM role attached to the instances does not have permissions for CodeDeploy.
C.The CodeDeploy agent is not installed on the EC2 instances.
D.The Application Load Balancer is not configured with a target group.
AnswerC

The CodeDeploy agent must be installed and running on every EC2 instance that participates in a CodeDeploy deployment. This background service registers the instance with CodeDeploy, polls for deployment instructions, runs the lifecycle events on the instance, and reports success or failure back to the service. When the agent is missing, no instance ever reports back, so CodePipeline fails with a message like 'No hosts received a command' or 'Overall deployment failed because no instances have been successfully registered.'

Why this answer

The CodeDeploy agent is a software package that must be installed and running on each EC2 instance to receive deployment instructions from the CodeDeploy service. If the agent is absent, the service cannot communicate with the instance, producing the 'agent not responding' error. Auto Scaling group instances launched from an AMI that lacks the agent will exhibit exactly this symptom.

Exam trap

SOA-C02 often tests the distinction between agent-level failures and IAM/network-level failures; candidates frequently pick the IAM role answer because permissions feel like the default cause, but 'agent not responding' specifically points to the agent software itself.

How to eliminate wrong answers

Option A is wrong because CodePipeline and CodeDeploy communicate with instances over the public AWS service endpoints (or via VPC endpoints if configured), but a missing VPC endpoint would cause a connectivity error, not an 'agent not responding' error. Option B is wrong because a missing IAM permission on the instance profile would produce an authorization/access-denied error, not an agent communication failure. Option D is wrong because an ALB target group misconfiguration affects traffic routing to the application, not the CodeDeploy agent's ability to receive deployment commands.

Page 1 of 3 · 182 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Soa Deployment Provisioning questions.