AWS Certified SysOps Administrator – Associate practice questions

200 free questions with answers and explanations.

Practice test
  1. 101.A company policy mandates that all EC2 instances must be automatically terminated if they are found to be non-compliant with a specific security group configuration (e.g., allowing SSH from 0.0.0.0/0). The SysOps team needs to implement a solution that continuously monitors the EC2 instances and automatically enforces this termination policy. Which AWS service should be used?Security and Compliance
  2. 102.An organization uses Amazon S3 for storing critical data. They need to automate the replication of objects from a source S3 bucket in one AWS account to a destination S3 bucket in a different AWS account for disaster recovery purposes. The replication must be asynchronous and maintain object metadata. Which S3 feature should be configured?Deployment, Provisioning, and Automation
  3. 103.A company is using Amazon DynamoDB for its core application's data storage. The application experiences predictable spikes in access patterns every hour on the hour, requiring significantly higher write capacity for a short duration. The current provisioned capacity is set to handle average traffic, leading to throttling errors during these spikes. The SysOps Administrator needs to ensure that DynamoDB can handle these predictable, hourly bursts of write traffic without over-provisioning capacity for the entire hour. Which DynamoDB feature should be configured?Cost and Performance Optimization
  4. 104.A manufacturing company uses an AWS IoT Core solution to ingest telemetry data from thousands of factory sensors. The data is then processed by an AWS Lambda function and stored in Amazon DynamoDB. The SysOps team observes that the Lambda function is occasionally throttling, leading to delayed data processing. The Lambda function processes data in batches and has variable invocation rates due to bursty sensor data. Which action should the SysOps Administrator take to ensure consistent processing performance and optimize costs?Cost and Performance Optimization
  5. 105.A data analytics team uses Amazon S3 to store raw data files that are frequently accessed by analytical jobs for the first week, then become infrequently accessed over the next month, and eventually are rarely accessed for long-term archiving. The access patterns are highly variable and unpredictable, making it difficult to set fixed lifecycle policies. The company wants to optimize storage costs without manual intervention. Which S3 storage class is best suited for this scenario?Cost and Performance Optimization
  6. 106.A startup is launching a new mobile gaming application that is expected to have highly variable and unpredictable usage patterns, with potential for sudden, massive spikes in demand. The backend is built using serverless AWS Lambda functions. The startup needs to ensure minimal latency for users during these spikes while keeping costs optimized. Which Lambda feature should they implement?Cost and Performance Optimization
  7. 107.A company is using several Amazon EC2 instances to run a legacy application that requires a specific operating system and license that is only available through a BYOL (Bring Your Own License) model. They need to ensure that these instances always run on dedicated physical servers for licensing compliance and want to minimize their costs over a 3-year period. Which EC2 purchasing option is most suitable?Cost and Performance Optimization
  8. 108.A large enterprise is migrating a critical on-premises database to Amazon RDS for PostgreSQL. The database is highly transactional and requires extremely low latency and high throughput for both reads and writes. The current on-premises storage uses enterprise-grade SSDs with millions of IOPS. Which Amazon RDS storage type should be selected to meet these performance requirements on AWS?Cost and Performance Optimization
  9. 109.A company is using Amazon EBS gp2 volumes for their Amazon EC2 instances. They observe that a specific application server is experiencing I/O bottlenecks, with consistent high latency and low throughput, even though the provisioned IOPS for the gp2 volume should theoretically be sufficient for the average workload. Upon further investigation, it's found that the application performs frequent, small, random I/O operations. The current gp2 volume size is 200 GB. Which action should the SysOps Administrator take to improve I/O performance most effectively and cost-efficiently?Cost and Performance Optimization
  10. 110.A company is using an Amazon EC2 instance running a custom application. They need to ensure that the instance is always available and running, even in the event of an underlying hardware failure. The application state is stored on an Amazon EBS volume, which must persist independently of the instance. Which EC2 feature should be used to meet these requirements with minimal operational overhead?Cost and Performance Optimization
  11. 111.A company operates a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application experiences predictable daily traffic spikes between 9 AM and 5 PM, Monday to Friday. Outside these hours, traffic is significantly lower. The company wants to ensure optimal performance during peak times and minimize costs during off-peak hours. Which Auto Scaling Group feature should be used to manage EC2 instance capacity?Cost and Performance Optimization
  12. 112.A retail company uses Amazon Redshift as its data warehouse for business intelligence reporting. Analysts frequently run complex queries that involve large joins and aggregations on multiple tables. During peak business hours, these queries often compete for resources, leading to increased query execution times and frustrated users. The company needs to improve query performance and ensure critical reports are processed efficiently. Which Redshift feature should they configure and optimize?Cost and Performance Optimization
  13. 113.A SysOps Administrator is reviewing the AWS bill for a fleet of Amazon EC2 instances. They notice that many instances are running 24/7 but have low average CPU utilization (under 15%) for most of the day, with occasional spikes. These instances are critical for a proprietary batch processing application that runs intermittently throughout the day. The company wants to reduce costs without impacting the application's ability to process batches when needed. Which EC2 purchasing option should be recommended?Cost and Performance Optimization
  14. 114.A company is running a web application on several Amazon EC2 instances behind an Application Load Balancer (ALB). Users are reporting slow loading times, particularly for static assets like images, CSS, and JavaScript files. The EC2 instances are showing high CPU utilization, suggesting they are spending too much time serving these static files. Which AWS service should a SysOps Administrator implement to improve performance and reduce the load on the EC2 instances?Cost and Performance Optimization
  15. 115.A financial company is running a highly sensitive application on AWS. They need to ensure that all network traffic between their on-premises data center and their Amazon VPC is encrypted and routed through a dedicated, private connection. They currently use AWS Direct Connect for the private connection but need to add the encryption layer for all traffic. Which solution should a SysOps Administrator implement?Cost and Performance Optimization
  16. 116.A financial institution is running a mission-critical, high-transaction application on an Amazon RDS for MySQL database. The application experiences unpredictable spikes in write traffic, leading to performance degradation and increased latency during peak hours. The current configuration uses a single Provisioned IOPS (PIOPS) volume. What is the MOST effective strategy to improve write performance and handle the unpredictable spikes?Cost and Performance Optimization
  17. 117.A company is running an application on Amazon EC2 instances within an Auto Scaling group. The application experiences predictable spikes in traffic every weekday morning from 9 AM to 11 AM, requiring additional capacity. The current Auto Scaling policy uses target tracking based on CPU utilization, which often reacts too slowly to these sudden spikes, leading to performance degradation. The company wants to ensure sufficient capacity is available proactively and cost-effectively during these peak hours without overprovisioning for the entire day. Which Auto Scaling scaling policy should a SysOps Administrator implement?Cost and Performance Optimization
  18. 118.A data analytics team is using an Amazon Redshift cluster for their data warehousing needs. They frequently run complex analytical queries that involve large joins and aggregations, which sometimes cause query performance to degrade due to contention for resources. The cluster currently uses a single node type with default WLM (Workload Management) settings. The SysOps Administrator needs to improve query performance, especially for critical analytical queries, without significantly increasing the overall cluster size. What is the most effective approach?Cost and Performance Optimization
  19. 119.A media company uses Amazon S3 to store large video files. They are experiencing high costs due to frequent data retrieval from S3 Standard-IA, as their video editing team often needs to access older files for re-edits or archival review. The access pattern is unpredictable; some older files might be accessed multiple times within a month, while others remain untouched for months. The company wants to optimize storage costs without significantly compromising retrieval performance or incurring high retrieval fees for unpredictable access. Which S3 storage class is most suitable?Cost and Performance Optimization
  20. 120.A global e-commerce company hosts its primary web application on Amazon EC2 instances in the `us-east-1` region. They are experiencing high latency for users in Europe and Asia. The company wants to improve the user experience for these global customers by routing their requests to the nearest optimal AWS endpoint, without replicating the entire application stack to multiple regions. Which AWS service should they use?Cost and Performance Optimization
  21. 121.A data engineering team is running a batch processing workload on Amazon EC2 instances. The workload can tolerate interruptions and has flexible start and end times. The team wants to significantly reduce compute costs while ensuring the jobs complete eventually. Which EC2 purchasing option should they primarily consider?Cost and Performance Optimization
  22. 122.A company is using an Amazon RDS for PostgreSQL database instance that is experiencing high CPU utilization during peak hours. The current instance type is db.m5.large. The database load is primarily read-heavy. A SysOps Administrator needs to optimize performance without significantly increasing costs or downtime for write operations. What is the most effective solution?Cost and Performance Optimization
  23. 123.A company is using Amazon EC2 instances to host a stateless web application. The application's traffic fluctuates significantly throughout the day, with peak usage during business hours and very low usage overnight. The SysOps Administrator wants to minimize EC2 costs while ensuring the application can handle peak loads and automatically scale down during off-peak times. Which combination of EC2 features should be implemented?Cost and Performance Optimization
  24. 124.A development team is using an Amazon S3 bucket to store application logs. They need to analyze these logs using Amazon Athena, but are concerned about the cost of storing infrequently accessed older logs in S3 Standard. The retention policy dictates that logs older than 30 days are accessed very rarely, but must be retained for compliance for 7 years. Logs older than 1 year are almost never accessed. Which S3 lifecycle policy configuration would be most cost-effective while meeting these requirements?Cost and Performance Optimization
  25. 125.A company is deploying a new service that processes sensitive customer data. They need to ensure that all API calls made to AWS services within their account are logged, immutable, and retained for seven years for compliance purposes. Which solution best meets these requirements?Monitoring, Logging, and Remediation
  26. 126.A company requires a cost-effective solution for long-term archiving of audit logs from various AWS services (CloudTrail, VPC Flow Logs, S3 Access Logs) for compliance purposes. The logs need to be retained for 10 years, with infrequent access expected after the first year. Which storage solution is most appropriate?Monitoring, Logging, and Remediation
  27. 127.A financial institution needs to ensure that all Amazon S3 buckets containing sensitive customer data are encrypted at rest using AWS Key Management Service (KMS) with customer-managed keys (CMKs). They also need to automatically remediate any non-compliant buckets. Which AWS service combination provides this capability?Monitoring, Logging, and Remediation
  28. 128.A company uses a serverless application consisting of AWS Lambda functions, Amazon API Gateway, and Amazon DynamoDB. They need to trace requests end-to-end to identify performance bottlenecks and errors across these services. The solution should provide a visual service map and detailed trace data for each request. Which AWS service is best suited for this requirement?Monitoring, Logging, and Remediation
  29. 129.A security team needs to receive real-time notifications whenever an Amazon S3 bucket's access control list (ACL) is modified, as this could indicate a security vulnerability. The solution must be automated and integrate with existing notification channels. Which AWS services should be used?Monitoring, Logging, and Remediation
  30. 130.A SysOps administrator is investigating a sudden spike in network traffic from an application's EC2 instances to an unknown external IP address. They need to quickly identify the source process on the EC2 instances responsible for this outbound traffic without logging into each instance manually. The solution should work across multiple instances. Which AWS service can help achieve this?Monitoring, Logging, and Remediation
  31. 131.A SysOps administrator needs to collect detailed system-level metrics (e.g., memory utilization, disk space, process list) from a fleet of Amazon EC2 instances running a custom application. These metrics are not available by default in Amazon CloudWatch. The solution should be scalable and easily deployable across new instances. What is the most appropriate solution?Monitoring, Logging, and Remediation
  32. 132.A development team has deployed a new microservice on Amazon ECS. They need to collect application logs from the containers and centralize them for analysis and long-term storage. The solution must be cost-effective and scalable without requiring manual intervention for log rotation or storage management. Which logging configuration meets these requirements?Monitoring, Logging, and Remediation
  33. 133.A SysOps administrator needs to set up a dashboard to visualize the health and performance of an application running on Amazon EC2 instances. The dashboard should display CPU utilization, network I/O, application-specific metrics (e.g., request count, error rates from logs), and custom alarms. The solution must be easy to configure and provide a unified view. Which AWS service is best suited for creating this dashboard?Monitoring, Logging, and Remediation
  34. 134.A media company streams video content using Amazon CloudFront. They are experiencing complaints about slow video loading times from users in specific geographic regions. The SysOps administrator needs to quickly determine if the latency is due to CloudFront edge locations, the origin server, or network routes between them. Which monitoring approach will provide the most relevant insights?Monitoring, Logging, and Remediation
  35. 135.A SysOps administrator needs to monitor the network performance and security of an Amazon VPC. Specifically, they want to log all accepted and rejected IP traffic flows to and from network interfaces in the VPC for forensic analysis and troubleshooting connectivity issues. Which AWS service should be enabled?Monitoring, Logging, and Remediation
  36. 136.A SysOps administrator needs to analyze the performance of a new web application deployed on Amazon EC2 instances. The application uses a custom logging format and generates high volumes of logs. The administrator wants to centralize these logs for real-time analysis and historical archiving without managing any servers for the logging solution. Which AWS service combination should be used?Monitoring, Logging, and Remediation
  37. 137.A SysOps team manages several AWS accounts. They need to establish a centralized logging solution for all AWS API calls across these accounts to meet compliance requirements and simplify security auditing. The solution must ensure that logs are immutable and can be stored for seven years. What is the most robust and cost-effective solution?Monitoring, Logging, and Remediation
  38. 138.A company uses a serverless application consisting of Amazon API Gateway, AWS Lambda functions, and Amazon DynamoDB. They are experiencing performance issues and errors, but the logs in CloudWatch Logs are fragmented across multiple Lambda functions, making it difficult to trace the full request flow. They need a solution to visualize the end-to-end request path and identify bottlenecks or errors across these services.Monitoring, Logging, and Remediation
  39. 139.A SysOps administrator needs to ensure that all Amazon S3 buckets containing sensitive customer data are encrypted at rest. If a new bucket is created without encryption, the administrator wants it to be automatically remediated to enforce encryption. Which AWS service combination should be used to achieve this auto-remediation?Monitoring, Logging, and Remediation
  40. 140.A SysOps administrator is managing a fleet of EC2 instances running a custom application. They need to ensure that the application process is always running. If the process stops, they want to automatically restart it and receive a notification. Which AWS services should be combined to achieve this?Monitoring, Logging, and Remediation
  41. 141.A SysOps team manages a fleet of EC2 instances and needs to collect custom application metrics (e.g., number of active users, queue depth) and logs from these instances. They require a single, unified agent that can send both metrics and logs to AWS CloudWatch. Which agent should they deploy?Monitoring, Logging, and Remediation
  42. 142.A SysOps administrator needs to create a unified view of the health and performance of their entire AWS infrastructure, including metrics from EC2 instances, RDS databases, and custom application metrics. The view should be customizable and provide real-time updates. Which AWS service is best suited for this requirement?Monitoring, Logging, and Remediation
  43. 143.A SysOps administrator is troubleshooting an application running on an EC2 instance that is experiencing high latency. They suspect network connectivity issues between the EC2 instance and an external service. They need to verify the network path, identify any dropped packets, and measure latency along the path without installing additional agents on the EC2 instance or modifying security groups. Which AWS service can provide this diagnostic capability?Monitoring, Logging, and Remediation
  44. 144.A SysOps administrator needs to analyze detailed application logs from multiple Amazon EC2 instances for troubleshooting and compliance, including logs that are not automatically collected by CloudWatch (e.g., custom application logs in specific directories). The solution must centralize these logs and allow for real-time querying. Which approach is most suitable?Monitoring, Logging, and Remediation
  45. 145.A security team needs to be notified whenever a security group's ingress or egress rules are modified in any AWS account within their organization. The notification should include details of the change and the affected resource. The solution must be automated and operate in near real-time.Monitoring, Logging, and Remediation
  46. 146.A SysOps administrator needs to perform a diagnostic check on an Amazon EC2 instance that is experiencing high CPU utilization but is not responding to SSH connections. The administrator needs to retrieve system logs and run a custom script to analyze processes without direct interactive access. Which AWS service can be used to achieve this?Monitoring, Logging, and Remediation
  47. 147.A SysOps administrator needs to proactively detect potential security threats within their AWS environment. They require a service that continuously monitors for malicious activity, unauthorized access, and unusual behavior across various data sources like VPC Flow Logs, DNS logs, and CloudTrail events, without requiring manual deployment or configuration of security agents. Which AWS service should be used?Monitoring, Logging, and Remediation
  48. 148.A financial services company needs to ensure that all data stored in Amazon S3 buckets is encrypted at rest using customer-managed keys (CMKs) from AWS Key Management Service (KMS). They also need to automatically remediate any S3 bucket that is not configured with the required KMS encryption. Which AWS services should be combined to achieve this continuous compliance and auto-remediation?Monitoring, Logging, and Remediation
  49. 149.A SysOps administrator is observing high latency and error rates for a new microservices application deployed on AWS. The application consists of multiple Lambda functions, API Gateway endpoints, and DynamoDB tables. The administrator needs a consolidated view to trace requests across these services and identify the component causing the performance degradation. Which AWS service is designed for this purpose?Monitoring, Logging, and Remediation
  50. 150.A company is migrating its on-premises application logs to AWS. They need a cost-effective solution to ingest logs from various sources, including custom applications and operating systems, into a centralized location for long-term archiving and occasional analysis. The solution should minimize operational overhead.Monitoring, Logging, and Remediation