AWS Certified SysOps Administrator – Associate practice questions

200 free questions with answers and explanations.

Practice test
  1. 1.A SysOps administrator is troubleshooting intermittent connectivity issues for an EC2 instance in a private subnet. The instance should be able to access an Amazon S3 bucket for data storage. The administrator suspects network configuration issues. Which of the following is the MOST appropriate sequence of steps the administrator should take to diagnose the connectivity problem?Networking and Content Delivery
  2. 2.A company is using an Application Load Balancer (ALB) to distribute traffic to EC2 instances. They want to ensure that only authenticated users can access a specific path of their application (e.g., /admin/*) and that users are redirected to an identity provider (IdP) for authentication if they are not authenticated. Which ALB feature should be configured?Networking and Content Delivery
  3. 3.A SysOps administrator is configuring a new VPC and needs to ensure that EC2 instances in a private subnet can download operating system patches from the internet, but cannot be directly accessed from the internet. The solution must be highly available and managed by AWS. Which networking component should be used?Networking and Content Delivery
  4. 4.A SysOps administrator needs to configure a highly available and scalable network architecture for a new application. The application will serve dynamic content and requires SSL/TLS termination at the load balancer. It also needs to distribute incoming traffic across multiple EC2 instances in different Availability Zones within a VPC. Which AWS service should the administrator use to meet these requirements?Networking and Content Delivery
  5. 5.A company is deploying a new application that will process sensitive customer data. The application requires dedicated network performance and a consistent network experience between its on-premises data center and the AWS Cloud. The existing internet VPN connection is not meeting the performance and reliability requirements. Which AWS service should the company use to establish this connection?Networking and Content Delivery
  6. 6.A company is hosting a static website on Amazon S3 and wants to ensure that users access the content over HTTPS. They also need to improve performance by caching content at edge locations globally. Which AWS service should the company use to achieve these requirements?Networking and Content Delivery
  7. 7.A developer has deployed a new application on EC2 instances within a private subnet. The application needs to securely access Amazon S3 and Amazon DynamoDB without traversing the public internet. Which AWS networking component should the SysOps administrator configure to meet this requirement?Networking and Content Delivery
  8. 8.An application is served globally via Amazon CloudFront, with an Amazon S3 bucket as its origin. Users are reporting occasional '403 Access Denied' errors when trying to access specific objects. The S3 bucket policy allows public read access. What is the MOST likely cause of these errors?Networking and Content Delivery
  9. 9.A company is migrating a legacy application to AWS. The application uses UDP port 5000 for inter-service communication and requires extremely low latency and high throughput. The SysOps administrator needs to distribute UDP traffic to a fleet of EC2 instances. Which AWS service is the most appropriate for this requirement?Networking and Content Delivery
  10. 10.A company is deploying a new web application in an AWS VPC. The application requires high availability across multiple Availability Zones and needs to distribute incoming HTTP/HTTPS traffic to backend EC2 instances. The application also needs to support path-based routing. Which AWS service should the SysOps administrator use to meet these requirements?Networking and Content Delivery
  11. 11.A SysOps administrator is managing an Amazon CloudFront distribution that serves static content from an Amazon S3 bucket. The company has a strict security policy requiring that users can ONLY access the content through CloudFront and are explicitly prevented from accessing the S3 bucket directly via its public URL. Which CloudFront feature should the administrator implement to enforce this policy?Networking and Content Delivery
  12. 12.A SysOps administrator needs to deploy a new security appliance (e.g., firewall, intrusion detection system) within a VPC. This appliance must inspect all north-south (internet-bound) and east-west (VPC internal) traffic between specific subnets. The appliance should be highly available, scalable, and transparently inserted into the network path without requiring manual route table changes for every new subnet or instance. Which AWS networking service is designed for this transparent traffic inspection and routing?Networking and Content Delivery
  13. 13.A SysOps administrator needs to configure a highly available and scalable DNS solution for an application running on EC2 instances behind an Application Load Balancer (ALB). The solution must route traffic based on latency to the nearest region and perform health checks on the endpoints. Which AWS service should be used?Networking and Content Delivery
  14. 14.A company is deploying a multi-tier application in an AWS VPC. The web tier is in public subnets, and the application and database tiers are in private subnets. The application tier needs to connect to the database tier, and both need to connect to an external logging service over the internet. The SysOps administrator wants to simplify network management and routing between these tiers and to the internet, avoiding complex peering connections between multiple VPCs if the architecture scales. Which AWS networking service provides a centralized hub for this connectivity?Networking and Content Delivery
  15. 15.A SysOps administrator needs to configure a highly available and scalable DNS solution for a new web application. The application will be accessed by users globally. The administrator wants to use a custom domain name (example.com) and ensure that if the primary application endpoint becomes unhealthy, traffic is automatically routed to a secondary, healthy endpoint in another region. Which Amazon Route 53 routing policy should be used to achieve this failover capability?Networking and Content Delivery
  16. 16.A SysOps administrator is designing a network architecture for a new application that requires very high throughput and low latency between EC2 instances in different subnets within the same VPC. The application is sensitive to network jitter. What is the MOST suitable networking feature to ensure optimal performance between these instances?Networking and Content Delivery
  17. 17.A company is using AWS Transit Gateway to connect multiple VPCs and on-premises networks. A SysOps administrator needs to ensure that traffic between two specific VPCs (VPC A and VPC B) connected to the Transit Gateway never traverses the public internet, even if they are in different AWS regions. Which Transit Gateway feature is required?Networking and Content Delivery
  18. 18.A SysOps administrator needs to configure a highly available and scalable network architecture for a web application. The application will be hosted on Amazon EC2 instances in a private subnet, and users must access it via a public IP address. Security requirements dictate that only HTTP and HTTPS traffic should reach the application instances. Which combination of AWS services should be used?Networking and Content Delivery
  19. 19.A SysOps administrator is configuring a highly available DNS solution for a critical web application. The application is hosted on EC2 instances behind an Application Load Balancer (ALB) in multiple AWS regions. The administrator needs to direct users to the nearest healthy endpoint based on their geographic location. If the primary region becomes unhealthy, traffic should automatically fail over to a healthy secondary region. Which Amazon Route 53 routing policy should be used?Networking and Content Delivery
  20. 20.A company is experiencing intermittent connectivity issues to an EC2 instance in a private subnet from an on-premises data center connected via AWS Direct Connect. The network team has verified that the Direct Connect connection itself is stable, and the on-premises router has the correct routes for the VPC CIDR. However, ping and SSH to the instance fail. What is the MOST likely cause of this issue?Networking and Content Delivery
  21. 21.A SysOps administrator needs to establish a secure and dedicated network connection between an on-premises data center and an AWS VPC. The connection must offer consistent network performance and lower latency than an internet-based VPN connection. The company requires a private connection for transferring large datasets frequently. Which AWS service should the administrator recommend?Networking and Content Delivery
  22. 22.A SysOps administrator needs to establish a secure and dedicated network connection between an on-premises data center and an AWS VPC. The connection must offer consistent network performance and lower network costs compared to IPsec VPN over the public internet. Which AWS service should be used?Networking and Content Delivery
  23. 23.A SysOps administrator is configuring a new web application that requires very low latency and high packet per second (PPS) performance for network traffic between EC2 instances. The application performs intensive in-memory caching and real-time analytics. Which EC2 networking feature should the administrator ensure is enabled and configured to meet these demanding performance requirements?Networking and Content Delivery
  24. 24.A SysOps administrator needs to securely access EC2 instances in a private subnet without exposing them to the internet and without using a bastion host or VPN. The instances need to receive commands and software updates from AWS Systems Manager. Which solution should the administrator implement?Networking and Content Delivery
  25. 25.A SysOps administrator needs to configure a new Amazon CloudFront distribution to serve static content from an Amazon S3 bucket. To enhance security, the administrator wants to ensure that users can only access the content through CloudFront and not directly from the S3 bucket URL. Which CloudFront feature should be used?Networking and Content Delivery
  26. 26.A company is deploying a multi-tier application in a VPC. The web tier is in public subnets, and the application and database tiers are in private subnets. All tiers need to communicate with each other, and the application tier needs to connect to the internet for third-party APIs. The company plans to expand to multiple VPCs in the future and wants a centralized network hub for inter-VPC and on-premises connectivity. Which AWS service provides a scalable and centralized solution for connecting these VPCs and enabling internet access for the application tier?Networking and Content Delivery
  27. 27.An organization relies on an Application Load Balancer (ALB) to route traffic to its web application. The security team has mandated that all user sessions must be authenticated using corporate credentials before reaching the backend application. The SysOps administrator needs to configure the ALB to handle this authentication requirement seamlessly. Which ALB feature should be utilized?Networking and Content Delivery
  28. 28.A SysOps administrator is troubleshooting intermittent connectivity issues for an EC2 instance in a private subnet. The instance needs to connect to an external API over the internet. The security groups and network ACLs are correctly configured. The instance has no public IP address. What is the most likely missing component that prevents the instance from reaching the internet?Networking and Content Delivery
  29. 29.A SysOps administrator needs to configure a custom domain name (example.com) for a static website hosted on Amazon S3 and delivered via Amazon CloudFront. The domain name is managed by Amazon Route 53. Which type of Route 53 record should be created to point the custom domain name to the CloudFront distribution?Networking and Content Delivery
  30. 30.A company is deploying a new web application that requires high availability across multiple Availability Zones and wants to distribute incoming HTTP/HTTPS traffic to targets based on URL paths. Which type of load balancer should the SysOps administrator choose?Networking and Content Delivery
  31. 31.A SysOps administrator is configuring a new VPC and needs to ensure that EC2 instances in a private subnet can initiate outbound connections to the internet for software updates and patches, but external hosts cannot initiate inbound connections to these instances. Which AWS networking component should be deployed in a public subnet to allow this?Networking and Content Delivery
  32. 32.A company is deploying a new web application in a VPC. The application's EC2 instances are in a private subnet, and an Application Load Balancer (ALB) is in a public subnet. The security team requires that all outbound internet traffic from the EC2 instances be inspected by a third-party firewall appliance running on another EC2 instance, also in a private subnet. Which AWS service is best suited to route all outbound internet traffic from the application instances through the firewall appliance?Networking and Content Delivery
  33. 33.A company is hosting a multi-tier application in a VPC. The web tier is in public subnets, and the application and database tiers are in private subnets. The application tier needs to connect to the database tier, and both tiers need to be able to communicate with backend services hosted in another VPC in the same AWS Region. The solution must be highly available and support transitive routing. Which AWS service should be used to connect the two VPCs?Networking and Content Delivery
  34. 34.A SysOps administrator is configuring a new VPC and needs to ensure that EC2 instances in a private subnet can download patches and updates from the internet but cannot receive unsolicited inbound connections from the internet. Which TWO AWS networking components must be configured to achieve this securely and efficiently?Networking and Content Delivery
  35. 35.A compliance team requires that all Amazon S3 buckets are configured with server access logging enabled to a centralized logging bucket. This policy must be automatically enforced across all new and existing S3 buckets in specific AWS accounts, and non-compliant buckets must be automatically remediated. Which combination of AWS services provides the most robust and automated solution for both detection and remediation?Deployment, Provisioning, and Automation
  36. 36.A large enterprise is adopting a multi-account strategy with AWS Organizations. They need to ensure that all new AWS accounts created within the organization automatically have a baseline set of CloudWatch alarms, IAM roles, and VPC configurations applied. This initial setup must be consistent and automated to reduce operational overhead and ensure compliance from day one. Which AWS service is best suited for provisioning these baseline resources across new accounts?Deployment, Provisioning, and Automation
  37. 37.A security audit reveals that several Amazon EC2 instances in a production environment are running with overly permissive IAM roles, granting access to services they do not require. The SysOps administrator needs to identify these instances and automatically reduce their permissions to the minimum necessary level. Which approach is the MOST efficient and compliant for continuous enforcement?Security and Compliance
  38. 38.A data analytics team needs to process large datasets stored in Amazon S3. The processing involves multiple sequential steps, including data extraction, transformation, and loading (ETL), with conditional logic and error handling between steps. Each step might involve different AWS services like AWS Lambda, AWS Glue, or Amazon EC2. Which AWS service is best suited for orchestrating this complex, multi-step workflow?Deployment, Provisioning, and Automation
  39. 39.A company is using AWS Lambda functions for several microservices. They need to ensure that all Lambda functions are deployed with consistent configurations, including environment variables, memory settings, and timeout values, and that updates are applied in a controlled manner. Which AWS service can help automate the deployment and configuration management of these Lambda functions?Deployment, Provisioning, and Automation
  40. 40.A financial institution is migrating its on-premises applications to AWS. Due to strict regulatory requirements, all access to AWS resources must be authenticated against their existing corporate Active Directory. Furthermore, users should only be granted the minimum necessary permissions based on their job function. Which combination of AWS services should the SysOps administrator use to meet these requirements?Security and Compliance
  41. 41.A company is deploying a new microservices application using AWS Lambda functions. They need to manage and deploy these serverless applications efficiently, ensuring that all components (Lambda functions, API Gateway, DynamoDB tables, etc.) are provisioned and updated as a single unit. Which AWS service provides a framework for defining, deploying, and managing serverless applications?Deployment, Provisioning, and Automation
  42. 42.A company policy mandates that all EC2 instances must be automatically terminated if they are found to be non-compliant with security configurations, such as having an open security group port (e.g., SSH from 0.0.0.0/0). The SysOps administrator needs to implement an automated remediation action without manual intervention. Which combination of AWS services should be used?Security and Compliance
  43. 43.A healthcare provider is storing patient records in an Amazon S3 bucket. Due to HIPAA compliance requirements, all access to these records must be logged and monitored for suspicious activity. The SysOps administrator needs a solution that automatically detects unusual or potentially unauthorized access patterns to the S3 bucket and alerts the security team. Which AWS service is best suited for this task?Security and Compliance
  44. 44.A security engineer needs to implement a solution to automatically detect and alert on unusual and potentially unauthorized activities within an AWS account, such as port scanning, crypto-currency mining, or unusual API calls from a compromised instance. The solution should be intelligent and learn from normal behavior. Which AWS service is BEST suited for this requirement?Security and Compliance
  45. 45.A company is deploying a new web application on AWS that will handle sensitive customer data. The security team has mandated that all data in transit between the application servers and the database must be encrypted. The database is hosted on Amazon RDS for PostgreSQL. Which AWS service or feature should the SysOps administrator use to ensure this requirement is met with minimal operational overhead?Security and Compliance
  46. 46.A security engineer needs to implement a solution to automatically detect and alert on unusual and potentially unauthorized activities within an AWS account, such as API calls from unusual geographic locations, attempts to disable logging, or port scanning activities. The solution must be fully managed and provide intelligent threat detection. Which AWS service is best suited for this requirement?Security and Compliance
  47. 47.A global enterprise needs to ensure that all data stored in Amazon S3 buckets across all its AWS accounts is encrypted at rest using server-side encryption with KMS keys. The security team wants to enforce this policy universally and prevent any account from deploying S3 buckets without this encryption. What is the MOST effective way to achieve this across all accounts managed by AWS Organizations?Security and Compliance
  48. 48.A company is storing highly sensitive financial transaction records in an Amazon S3 bucket. A new regulation requires that all data access events for this bucket must be logged, including who accessed what, when, and from where. These logs must be retained for 10 years and be auditable for compliance purposes. Which AWS service should be enabled and configured specifically for this S3 bucket to meet these requirements?Security and Compliance
  49. 49.A company requires that all data stored in Amazon S3 buckets is automatically encrypted at rest. They want to enforce this rule across all new and existing buckets without requiring users to manually specify encryption settings during bucket creation or object upload. What is the most effective and compliant way to achieve this?Deployment, Provisioning, and Automation
  50. 50.A company is using AWS CloudFormation to provision its infrastructure. They want to ensure that all CloudFormation templates adhere to specific security and compliance standards before deployment. This includes checks for insecure configurations, proper tagging, and resource limits. Which AWS service can be integrated into the CI/CD pipeline to automate these checks?Deployment, Provisioning, and Automation