AWS Certified SysOps Administrator – Associate practice questions
200 free questions with answers and explanations.
- 51.A security team requires that all new Amazon EC2 instances launched in a specific VPC automatically join the corporate Active Directory domain. This process must be fully automated at instance launch. Which AWS service and configuration would best achieve this requirement?Deployment, Provisioning, and Automation
- 52.A global enterprise needs to ensure that all data stored in Amazon S3 buckets across all its AWS accounts is encrypted at rest using server-side encryption with KMS keys. The security team wants to enforce this policy universally and prevent any account from deploying S3 buckets without this encryption. What is the MOST effective way to achieve this across all accounts managed by AWS Organizations?Security and Compliance
- 53.A security engineer needs to implement a solution to automatically detect and alert on unusual and potentially unauthorized activities within an AWS account, such as API calls from unusual geographic locations, attempts to disable logging, or port scanning activities. The solution must be fully managed and provide intelligent threat detection. Which AWS service is best suited for this requirement?Security and Compliance
- 54.A company requires that all data stored in Amazon S3 buckets is automatically encrypted at rest. They want to enforce this rule across all new and existing buckets without requiring users to manually specify encryption settings during bucket creation or object upload. What is the most effective and compliant way to achieve this?Deployment, Provisioning, and Automation
- 55.A company is required to encrypt all data at rest for a new application deployed on Amazon EC2 instances using EBS volumes. The encryption keys must be managed by the company, and the solution must be scalable and easy to implement across multiple instances. Which approach should the SysOps administrator use?Security and Compliance
- 56.A development team uses AWS CodeCommit for source control and AWS CodePipeline for their CI/CD workflow. They need to automatically trigger a new pipeline execution whenever code is pushed to a specific branch in their CodeCommit repository. How can this be achieved with minimal configuration overhead?Deployment, Provisioning, and Automation
- 57.A company is deploying a new microservices application using AWS Lambda functions. They need to manage and deploy these serverless applications efficiently, ensuring that all components (Lambda functions, API Gateway, DynamoDB tables, etc.) are provisioned and updated as a single unit. Which AWS service provides a framework for defining, deploying, and managing serverless applications?Deployment, Provisioning, and Automation
- 58.A company is implementing a new data classification scheme for all data stored in Amazon S3. They need to ensure that objects tagged as 'Confidential' cannot be deleted by any user or role for a period of 90 days after creation, even by the root user, to comply with data retention regulations. Which S3 feature should the SysOps administrator configure?Security and Compliance
- 59.A SysOps Administrator needs to ensure that all Amazon EC2 instances launched in a specific VPC automatically join a corporate Active Directory domain. This process must be fully automated and executed immediately after the instance starts. Which AWS service and feature combination can achieve this reliably?Deployment, Provisioning, and Automation
- 60.A company is using AWS CloudFormation to manage its infrastructure. They have a requirement to ensure that specific sensitive resources, like Amazon RDS databases, are not accidentally deleted or replaced during stack updates. How can a SysOps Administrator prevent unintended deletion or replacement of these critical resources?Deployment, Provisioning, and Automation
- 61.A financial institution is migrating its on-premises applications to AWS. Due to strict regulatory requirements, all access to AWS resources must be authenticated against their existing corporate Active Directory. Furthermore, users should only be granted the minimum necessary permissions based on their job function. Which combination of AWS services should the SysOps administrator use to meet these requirements?Security and Compliance
- 62.A company is deploying a new containerized application on Amazon ECS using AWS Fargate. They need to ensure that the application's environment variables, such as API keys and database connection strings, are securely injected into the containers at runtime without exposing them in the task definition or source code. The solution must be highly secure and support rotation of credentials. Which AWS service should be used to manage and inject these sensitive configuration values?Deployment, Provisioning, and Automation
- 63.A data analytics team uses AWS Glue for ETL jobs. They need to ensure that new Glue jobs are deployed automatically after code changes are committed to a Git repository, and that job execution can be triggered on a schedule or by data arrival. Which AWS services should be integrated to create this automated deployment and triggering mechanism?Deployment, Provisioning, and Automation
- 64.A SysOps team manages hundreds of Amazon EC2 instances across multiple AWS accounts and regions. They need to ensure that a specific set of security agents and monitoring tools are installed and configured consistently on all new and existing Linux EC2 instances. The solution should be automated, idempotent, and report compliance status. Which AWS service is best suited for this task?Deployment, Provisioning, and Automation
- 65.A company is developing a new application that processes sensitive customer data. The application will store session tokens, API keys, and database credentials. The security team requires these secrets to be automatically rotated every 90 days and encrypted at rest and in transit. Which AWS service is BEST suited for managing these requirements?Security and Compliance
- 66.A company is using AWS CloudFormation to provision its infrastructure. They want to ensure that all CloudFormation templates adhere to specific security and compliance standards before deployment. This includes checks for insecure configurations, proper tagging, and resource limits. Which AWS service can be integrated into the CI/CD pipeline to automate these checks?Deployment, Provisioning, and Automation
- 67.A security engineer needs to implement a solution to automatically detect and alert on unusual and potentially unauthorized activities within an AWS account, such as port scanning, crypto-currency mining, or unusual API calls from a compromised instance. The solution should be intelligent and learn from normal behavior. Which AWS service is BEST suited for this requirement?Security and Compliance
- 68.A company is using AWS Lambda functions for several microservices. They need to ensure that all Lambda functions are deployed with consistent configurations, including environment variables, memory settings, and timeout values, and that updates are applied in a controlled manner. Which AWS service can help automate the deployment and configuration management of these Lambda functions?Deployment, Provisioning, and Automation
- 69.A security audit reveals that several Amazon EC2 instances in a production environment are running with overly permissive IAM roles, granting access to services they do not require. The SysOps administrator needs to identify these instances and automatically reduce their permissions to the minimum necessary level. Which approach is the MOST efficient and compliant for continuous enforcement?Security and Compliance
- 70.A company is migrating an on-premises application to AWS. This application relies on a critical configuration file that must be distributed to all new Amazon EC2 instances upon launch and maintained consistently. The company needs an automated solution to ensure this file is always present and correctly configured across a dynamic fleet of instances, without requiring manual intervention or baking it into AMIs. Which AWS Systems Manager capability should the SysOps team use?Deployment, Provisioning, and Automation
- 71.A financial services company needs to deploy a new critical application to AWS. The application requires highly consistent and rapid deployments with minimal downtime. The deployment process must be fully automated, including infrastructure provisioning, code deployment, and post-deployment validation. Which AWS service is best suited to meet these requirements for comprehensive automation?Deployment, Provisioning, and Automation
- 72.A healthcare provider is storing patient records in an Amazon S3 bucket. Due to HIPAA compliance, the data must be protected from accidental deletion or modification for a specific retention period. The solution must ensure that even root users cannot delete or alter the objects during this period. Which S3 feature should be enabled and configured on the bucket?Security and Compliance
- 73.A global enterprise uses multiple AWS accounts managed under AWS Organizations. The security team needs to enforce a policy that restricts all IAM users and roles in member accounts from creating or updating S3 buckets that are not configured with default encryption. This policy must apply to all new and existing accounts within the organization. Which AWS service should the security team use to implement this control?Security and Compliance
- 74.A financial services company is migrating its on-premises data warehouse to Amazon Redshift. Due to strict regulatory compliance, all data at rest in Redshift must be encrypted using customer-managed keys (CMKs) from AWS Key Management Service (KMS). The security team also requires that these CMKs are protected by a FIPS 140-2 Level 3 validated hardware security module (HSM). Which approach meets these requirements?Security and Compliance
- 75.A company is using Amazon RDS for PostgreSQL databases to store sensitive customer data. Due to compliance requirements, all connections to the database must be encrypted in transit. Additionally, the company needs to ensure that only authenticated clients can connect to the database. What is the MOST secure way to meet these requirements?Security and Compliance
- 76.A large e-commerce company uses AWS Auto Scaling groups for its web application. They need to ensure that when new EC2 instances are launched, they automatically register with a specific Application Load Balancer (ALB) target group, download the latest application code from an S3 bucket, and start the web server. This entire process must be fully automated and resilient to instance failures. Which AWS service can be used to achieve this automated instance initialization and configuration?Deployment, Provisioning, and Automation
- 77.A company is deploying a new web application on AWS that requires all data at rest to be encrypted. The security team mandates that encryption keys must be rotated annually and that they must have full control over the key's lifecycle, including deletion. Which AWS service and key management option should be used to meet these requirements?Security and Compliance
- 78.A company is storing highly sensitive financial transaction records in an Amazon S3 bucket. A new regulation requires that all data access events for this bucket must be logged, including who accessed what, when, and from where. These logs must be retained for 10 years and be auditable for compliance purposes. Which AWS service should be enabled and configured specifically for this S3 bucket to meet these requirements?Security and Compliance
- 79.A company is deploying a new web application on AWS that will handle sensitive customer data. The security team has mandated that all data in transit between the application servers and the database must be encrypted. The database is hosted on Amazon RDS for PostgreSQL. Which AWS service or feature should the SysOps administrator use to ensure this requirement is met with minimal operational overhead?Security and Compliance
- 80.A healthcare provider is storing patient records in an Amazon S3 bucket. Due to HIPAA compliance requirements, all access to these records must be logged and monitored for suspicious activity. The SysOps administrator needs a solution that automatically detects unusual or potentially unauthorized access patterns to the S3 bucket and alerts the security team. Which AWS service is best suited for this task?Security and Compliance
- 81.A company policy mandates that all EC2 instances must be automatically terminated if they are found to be non-compliant with security configurations, such as having an open security group port (e.g., SSH from 0.0.0.0/0). The SysOps administrator needs to implement an automated remediation action without manual intervention. Which combination of AWS services should be used?Security and Compliance
- 82.A company needs to restrict access to an S3 bucket containing sensitive organizational documents. Only users from specific IP ranges within the corporate network should be able to download objects from this bucket. Additionally, public access to the bucket must be explicitly denied. Which combination of S3 access controls should the SysOps administrator configure?Security and Compliance
- 83.A data analytics team needs to process large datasets stored in Amazon S3. The processing involves multiple sequential steps, including data extraction, transformation, and loading (ETL), with conditional logic and error handling between steps. Each step might involve different AWS services like AWS Lambda, AWS Glue, or Amazon EC2. Which AWS service is best suited for orchestrating this complex, multi-step workflow?Deployment, Provisioning, and Automation
- 84.A large enterprise is adopting a multi-account strategy with AWS Organizations. They need to ensure that all new AWS accounts created within the organization automatically have a baseline set of CloudWatch alarms, IAM roles, and VPC configurations applied. This initial setup must be consistent and automated to reduce operational overhead and ensure compliance from day one. Which AWS service is best suited for provisioning these baseline resources across new accounts?Deployment, Provisioning, and Automation
- 85.A company is deploying a new web application that uses Amazon EC2 instances behind an Application Load Balancer (ALB). They need to ensure that new code deployments are rolled out with minimal downtime and can be quickly rolled back if issues arise. Which deployment strategy, integrated with AWS services, would best meet these requirements?Deployment, Provisioning, and Automation
- 86.A SysOps engineer needs to automate the process of collecting logs from Amazon EC2 instances and sending them to Amazon CloudWatch Logs. The solution must be easy to deploy and manage across a fleet of instances, support both existing and newly launched instances, and handle log rotation. Which AWS service and agent combination is recommended?Deployment, Provisioning, and Automation
- 87.A company is migrating its on-premises applications to Amazon EC2. They need to ensure that application dependencies, such as specific software packages and configurations, are consistently installed and maintained across all instances. The solution must support both Windows and Linux instances and allow for centralized management of configurations. Which AWS service is best suited for this task?Deployment, Provisioning, and Automation
- 88.A compliance team requires that all data stored in Amazon S3 buckets is automatically encrypted at rest using a customer-managed key (CMK) from AWS Key Management Service (KMS). This encryption policy must be enforced for all new and existing objects in specific buckets, and any attempt to upload unencrypted objects or objects encrypted with a different key should be rejected. Which S3 feature should be configured?Deployment, Provisioning, and Automation
- 89.A development team is using AWS CodePipeline to automate their CI/CD process. They need to integrate a custom security scanning tool that runs as a Docker container into the build stage. This tool requires specific environment variables and access to the source code artifact. How can this be efficiently achieved within CodePipeline?Deployment, Provisioning, and Automation
- 90.A company is developing a new serverless application using AWS Lambda functions. The application processes highly sensitive customer data, and the security team requires that all Lambda function invocations and their outcomes are logged and audited for compliance purposes. The logs must be retained for at least 7 years. Which AWS service combination should the SysOps administrator implement to meet these requirements efficiently?Security and Compliance
- 91.A company is migrating its existing data warehouse to Amazon Redshift. The security team has mandated that all data loaded into Redshift must be encrypted at rest, and the encryption keys must be managed by the company, not AWS. Additionally, an audit trail of all key usage must be maintained. Which encryption option for Amazon Redshift should the SysOps administrator choose?Security and Compliance
- 92.A company is using AWS Secrets Manager to store database credentials. The security team wants to ensure that applications retrieve these secrets securely and that the secrets are automatically rotated every 90 days without requiring manual intervention. Which feature of AWS Secrets Manager should the SysOps administrator configure?Security and Compliance
- 93.A security team needs to enforce strict network configurations for all newly provisioned AWS accounts within their organization. Specifically, they want to prevent any new account from creating S3 buckets that are publicly accessible. This policy must apply to all accounts, even those created in the future, and cannot be overridden by individual account administrators. Which AWS Organizations feature should be used?Deployment, Provisioning, and Automation
- 94.A media company uses Amazon S3 to store large video files. They need to ensure that when a new video file is uploaded to a specific S3 bucket, it automatically triggers a serverless function to transcode the video into multiple formats. This process must be highly scalable and cost-effective. Which AWS service combination provides the most efficient solution for this automated workflow?Deployment, Provisioning, and Automation
- 95.A company is developing a new serverless application using AWS Lambda functions. Due to strict compliance requirements, all logs generated by these Lambda functions must be retained for 7 years and immutable. Which AWS service and configuration should the SysOps administrator use to meet these requirements?Security and Compliance
- 96.A company is required to encrypt all data at rest for a new application deployed on Amazon EC2. The application stores data on Amazon EBS volumes. The security team mandates that the encryption keys must be managed by the customer and automatically rotated annually. Additionally, the keys must be regionally isolated. Which solution should the SysOps administrator implement?Security and Compliance
- 97.A financial services company needs to deploy a new critical application to AWS. The application deployment process involves several stages: source, build, test, and production deployment. Each stage requires specific approvals from different teams (e.g., security, QA, operations) before proceeding to the next stage. Which AWS service can automate this continuous delivery workflow while incorporating manual approval steps?Deployment, Provisioning, and Automation
- 98.A global enterprise uses multiple AWS accounts managed under AWS Organizations. The security team needs to enforce a policy that prevents any IAM user or role in any account from creating EC2 instances outside of approved AWS Regions (e.g., only `us-east-1` and `eu-west-1`). This policy must apply to all existing and newly created accounts within the organization. Which AWS service should the SysOps administrator use to implement this control?Security and Compliance
- 99.A data analytics team needs to process large datasets stored in Amazon S3. They want to automate the execution of complex data transformation jobs, where each job consists of multiple sequential steps, some of which are parallelizable. They also require robust error handling, retry logic, and the ability to visualize the workflow progress. Which AWS service is best suited for orchestrating these data processing workflows?Deployment, Provisioning, and Automation
- 100.A security auditor has identified that several Amazon S3 buckets containing sensitive customer data are publicly accessible. The company needs to implement a preventative measure to ensure that no S3 bucket can ever be made publicly accessible, regardless of individual bucket policies or ACLs, across all AWS accounts in their organization. Which solution would achieve this MOST effectively?Security and Compliance