AWS Certified SysOps Administrator – Associate practice questions
200 free questions with answers and explanations.
- 151.A SysOps team manages a critical application running on multiple Amazon EC2 instances behind an Application Load Balancer (ALB). They observe that during peak traffic, users report slow response times, but CPU utilization on EC2 instances remains low. The team needs to identify the bottleneck. Which monitoring metric and service should they investigate first?Monitoring, Logging, and Remediation
- 152.A SysOps administrator needs to troubleshoot an intermittent issue with an application running on an EC2 instance. The issue occurs randomly and is difficult to reproduce. The administrator wants to capture a full memory dump of the EC2 instance when the issue occurs, without manual intervention. Which AWS service can facilitate this?Monitoring, Logging, and Remediation
- 153.A financial institution needs to ensure that all Amazon S3 buckets containing sensitive customer data are encrypted at rest with AWS Key Management Service (KMS) and are not publicly accessible. Any deviation from these requirements must be automatically remediated. Which AWS service and configuration can achieve this with the least administrative effort?Monitoring, Logging, and Remediation
- 154.A SysOps administrator needs to troubleshoot network connectivity issues between an Amazon EC2 instance in a private subnet and an Amazon RDS database instance in a different private subnet within the same VPC. The application logs indicate connection timeouts. Which AWS service is best suited to quickly identify network path issues, such as missing security group rules or incorrect route table entries?Monitoring, Logging, and Remediation
- 155.A SysOps administrator needs to analyze network traffic flowing to and from Amazon EC2 instances within a VPC to diagnose connectivity issues and identify potential security risks. Which AWS feature should they enable to capture detailed information about IP traffic?Monitoring, Logging, and Remediation
- 156.A SysOps administrator is managing an Amazon RDS for PostgreSQL database. They observe intermittent spikes in database load and slow queries during specific periods. They need a tool to quickly identify the root cause of these performance issues, including specific SQL queries, waiting events, and active sessions, without requiring extensive manual log analysis. Which AWS service should be used?Monitoring, Logging, and Remediation
- 157.A company operates a critical application on AWS. They need to ensure that specific AWS resources (e.g., EC2 instances, S3 buckets, RDS databases) conform to internal security policies, such as having encryption enabled, specific tags applied, or not being publicly accessible. They also need to be alerted automatically if any resource deviates from these policies. Which AWS service is best suited for continuous auditing and compliance enforcement in this scenario?Monitoring, Logging, and Remediation
- 158.A company is experiencing intermittent performance issues with its web application. They suspect the database might be the bottleneck. The database runs on an Amazon RDS for MySQL instance. The SysOps team needs to collect detailed performance metrics, including SQL queries, query execution plans, and wait events, to diagnose the problem without significantly impacting database performance. Which AWS service and feature should they use?Monitoring, Logging, and Remediation
- 159.A SysOps administrator is troubleshooting an intermittent application issue that manifests as slow responses only during peak hours. The application runs on Amazon EC2 instances behind an Application Load Balancer (ALB). The administrator needs to identify if the latency is introduced by the ALB, the EC2 instances, or the backend database. What is the most effective approach to pinpoint the source of latency?Monitoring, Logging, and Remediation
- 160.A security team requires real-time alerts whenever a user attempts to log in to an AWS account using root credentials. The alerts must be sent to an Amazon SNS topic for multiple subscribers. How can a SysOps administrator configure this monitoring and alerting solution?Monitoring, Logging, and Remediation
- 161.A SysOps administrator needs to proactively identify and respond to security threats within their AWS environment, such as unauthorized access, unusual API calls, or compromised instances. Which AWS service is specifically designed for continuous security monitoring and threat detection?Monitoring, Logging, and Remediation
- 162.A company is running a critical application on Amazon EC2 instances that are part of an Auto Scaling group. They need to be notified immediately if any instance in the group fails its health checks and is marked as unhealthy by Auto Scaling. Which AWS service and configuration should a SysOps administrator use to meet this requirement with the lowest operational overhead?Monitoring, Logging, and Remediation
- 163.A SysOps administrator needs to monitor the CPU utilization of an EC2 instance and automatically perform an action if it consistently exceeds 80% for five consecutive minutes. The action should involve stopping the instance to prevent runaway costs from over-provisioning. Which AWS service combination should be used to achieve this?Monitoring, Logging, and Remediation
- 164.A company requires a robust solution for auditing all AWS account activity, including API calls, resource changes, and security events, across multiple AWS accounts. The audit logs must be stored securely, centrally, and encrypted, with integrity validation enabled. Which combination of AWS services should be used to meet these requirements?Monitoring, Logging, and Remediation
- 165.A media streaming application uses Amazon S3 for storing video assets. Due to increasing demand, the application frequently experiences '503 Slow Down' errors from S3, indicating that S3 is temporarily unable to handle the request rate for specific prefixes. The SysOps Administrator needs to optimize S3 performance to eliminate these errors. Which design principle or S3 feature should be applied?Reliability and Business Continuity
- 166.A global e-commerce company uses AWS for its application infrastructure. The company's legal department mandates that all customer data must be stored and processed within the customer's home region (data residency requirement), but the application needs to provide a consistent global user experience. The SysOps Administrator is tasked with designing a solution for data storage that meets these requirements while ensuring high availability and disaster recovery. Which storage strategy should be recommended?Reliability and Business Continuity
- 167.A SysOps Administrator needs to ensure that critical application data stored in an Amazon S3 bucket is protected against accidental deletion or modification. The data is accessed frequently and must be recoverable to any previous version. What S3 features should be enabled and configured to meet these requirements with minimal operational overhead?Reliability and Business Continuity
- 168.A company operates a mission-critical web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application spans two Availability Zones. During peak traffic, the database (Amazon RDS for MySQL) becomes a bottleneck, leading to increased latency and failed transactions. The SysOps Administrator needs to improve the database's read performance and resilience without changing the application code. Which solution should be implemented?Reliability and Business Continuity
- 169.A company's production environment runs on Amazon EC2 instances in a private subnet. These instances need to securely download software updates from public repositories on the internet. The security team mandates that no direct internet access is allowed for these instances, and all outbound traffic must be inspected. Which solution allows the instances to download updates while meeting security requirements?Reliability and Business Continuity
- 170.A security team requires that all data stored in Amazon EBS volumes attached to EC2 instances must be encrypted at rest. The SysOps Administrator needs to automate this for new volumes and ensure compliance. Which approach will meet this requirement with the least administrative effort?Reliability and Business Continuity
- 171.A media company uses Amazon EC2 instances to process large video files. These instances retrieve source files from an Amazon S3 bucket, process them, and then upload the processed files back to another S3 bucket. Due to the large data transfer volumes, the company is incurring significant NAT Gateway data processing charges. The SysOps Administrator needs to optimize costs while maintaining connectivity for instances in private subnets to S3. Which solution should be implemented?Reliability and Business Continuity
- 172.An application relies on an Amazon SQS queue for asynchronous processing. The application's design requires that messages are processed exactly once and in the order they are sent, even during high-throughput scenarios. The SysOps Administrator needs to configure the SQS queue to meet these strict requirements while minimizing operational overhead. Which SQS queue type and configuration should be used?Reliability and Business Continuity
- 173.A company is running a critical application on Amazon EC2 instances in a single Availability Zone. The application processes real-time financial transactions and requires high availability. The company wants to improve the application's resilience to Availability Zone failures without significantly re-architecting the application. Which AWS service or feature should a SysOps Administrator recommend?Reliability and Business Continuity
- 174.A company uses AWS Backup to manage backups for Amazon RDS databases, Amazon EC2 instances, and Amazon EBS volumes. The compliance team requires that all backups must be retained for 7 years and immutable for the first 3 months to protect against accidental deletion or ransomware. How should the SysOps Administrator configure AWS Backup to meet these requirements?Reliability and Business Continuity
- 175.A financial institution uses an Amazon EC2 instance running a custom application to generate daily reports. These reports are stored on an attached 500 GB gp2 EBS volume. The application needs to complete the report generation within a specific 2-hour window every day. Recently, the report generation time has increased significantly, indicating an I/O bottleneck on the EBS volume. The SysOps Administrator observes that the volume's I/O operations per second (IOPS) are consistently hitting their maximum. Which action should the administrator take to immediately improve the EBS volume's performance and ensure the reports are generated on time?Reliability and Business Continuity
- 176.A company is implementing a disaster recovery (DR) strategy for its critical application hosted on AWS. The Recovery Time Objective (RTO) is 4 hours, and the Recovery Point Objective (RPO) is 1 hour. The application uses EC2 instances, an Amazon RDS database, and Amazon S3 for static content. The SysOps Administrator needs to select a DR strategy that meets these objectives cost-effectively. Which strategy is most appropriate?Reliability and Business Continuity
- 177.A media company uses Amazon S3 to store petabytes of video content. Most of this content is accessed frequently for the first 30 days after upload, then occasionally for the next 90 days, and rarely thereafter, but must be retained indefinitely. To optimize storage costs, the SysOps Administrator needs to implement an automated lifecycle policy. Which S3 storage class transition policy provides the most cost-effective solution for this access pattern?Reliability and Business Continuity
- 178.A global e-commerce application uses Amazon DynamoDB for its product catalog. The application experiences unpredictable traffic spikes, with reads occasionally exceeding 100,000 RCU and writes up to 20,000 WCU during peak sales events. The company needs to ensure consistent low-latency performance for both reads and writes, even during these spikes, without over-provisioning capacity unnecessarily during off-peak times. Which DynamoDB capacity mode should the SysOps Administrator recommend?Reliability and Business Continuity
- 179.A global media company uses Amazon EC2 instances to process large video files. These instances require high-bandwidth, low-latency access to a shared file system for input and output data. The file system must be accessible concurrently by hundreds of EC2 instances across multiple Availability Zones within the same AWS Region. Which storage service should the SysOps Administrator recommend?Reliability and Business Continuity
- 180.A client is running a critical application on Amazon EC2 instances within a private subnet. To ensure high availability, the EC2 instances are distributed across multiple Availability Zones and managed by an Auto Scaling group. The application needs to communicate with a third-party API over the internet. To minimize latency and improve resilience for outbound internet access, which networking component should the SysOps Administrator configure?Reliability and Business Continuity
- 181.A company is implementing a disaster recovery strategy for its critical application, which runs on EC2 instances across multiple Availability Zones in a single region. The application relies on an Amazon Aurora PostgreSQL database. In the event of a regional disaster, the company needs to restore the entire application stack, including the Aurora database, in a different AWS Region. The RTO target is 2 hours, and the RPO target is 15 minutes. Which disaster recovery approach should the SysOps Administrator choose?Reliability and Business Continuity
- 182.A healthcare company needs to back up its critical Amazon RDS PostgreSQL database. The backup strategy must ensure point-in-time recovery to any second within the last 35 days, and daily backups must be retained for 7 years to meet regulatory requirements. The SysOps Administrator wants to implement this solution with minimal operational overhead. Which AWS services and configurations should be used?Reliability and Business Continuity
- 183.A company operates a critical application on Amazon EC2 instances in a single AWS Region. To improve the application's resilience and minimize downtime during a regional outage, they decide to implement a multi-region active-passive disaster recovery strategy. They need a cost-effective solution that allows for quick failover to a secondary region. Which AWS service should they use to manage the global routing of traffic to either the primary or secondary region based on the health of the application endpoints?Reliability and Business Continuity
- 184.A company uses Amazon Aurora MySQL for its critical database. They require a disaster recovery solution that can recover the database in a different AWS Region with a Recovery Point Objective (RPO) of seconds and a Recovery Time Objective (RTO) of minutes. The solution must also allow for a quick failover with minimal data loss. Which Aurora feature should the SysOps Administrator configure?Reliability and Business Continuity
- 185.A development team uses an Amazon SQS queue for asynchronous processing of orders. Due to a bug in the processing application, some messages are being consistently rejected and returned to the queue, causing a processing loop. The team needs a mechanism to isolate these problematic messages for later inspection and prevent them from blocking the processing of valid messages. Which SQS feature should the SysOps Administrator implement?Reliability and Business Continuity
- 186.A SysOps Administrator needs to configure a new Amazon S3 bucket to store critical application logs. Due to compliance requirements, the logs must be immutable and retained for a minimum of 7 years, and no one, including the root user, should be able to delete or modify them during this period. Which S3 Object Lock retention mode should be applied to meet these stringent requirements?Reliability and Business Continuity
- 187.A company is running a critical application on Amazon EC2 instances connected to an Amazon RDS MySQL database. The database is configured for Multi-AZ deployment. The application experiences occasional read-heavy spikes, causing increased latency on the primary database instance. The SysOps Administrator needs to offload read traffic from the primary database to improve application performance during peak loads, without increasing the cost excessively during off-peak times. Which solution should be implemented?Reliability and Business Continuity
- 188.A SysOps Administrator needs to ensure that critical configuration data stored in an Amazon S3 bucket is replicated to a different AWS account for disaster recovery purposes. The data must be encrypted at rest and in transit. The replication should happen automatically and asynchronously whenever new objects are added to the source bucket. Which S3 feature should be configured?Reliability and Business Continuity
- 189.A global media company uses Amazon S3 to store petabytes of archived video and audio content. This content is rarely retrieved, but when it is, legal and compliance teams require that it be retrieved within 12 hours. The company needs to minimize storage costs as much as possible. Which S3 storage class should the SysOps Administrator recommend for this archived content?Reliability and Business Continuity
- 190.A company uses an Amazon RDS for PostgreSQL database as the backend for its critical e-commerce application. To meet a strict Recovery Time Objective (RTO) of less than 5 minutes and a Recovery Point Objective (RPO) of less than 1 minute in case of a regional disaster, the SysOps Administrator needs to implement a robust disaster recovery strategy. Which combination of RDS features provides the most effective solution?Reliability and Business Continuity
- 191.A SysOps Administrator is designing a backup strategy for an application that uses Amazon EC2 instances with attached Amazon EBS volumes. The application requires consistent backups of all EBS volumes attached to an instance at a specific point in time, without stopping the instance. What is the most efficient and consistent method to achieve this?Reliability and Business Continuity
- 192.A media company stores large video files in Amazon S3. These files are frequently accessed for the first 30 days after upload, then rarely accessed for the next 60 days, and finally need to be archived for long-term retention beyond 90 days. The company wants to minimize storage costs while maintaining accessibility according to this access pattern. Which S3 Lifecycle policy configuration should the SysOps Administrator implement?Reliability and Business Continuity
- 193.A company is using an Amazon EC2 instance to run a CPU-intensive data processing application. The application frequently writes small, random I/O operations to an attached Amazon EBS volume. The current gp2 volume is experiencing performance bottlenecks, causing the application to slow down. The SysOps Administrator needs to improve the throughput and IOPS of the EBS volume to reduce processing time. Which EBS volume type should the administrator migrate to?Reliability and Business Continuity
- 194.A company operates a critical web application that serves customers globally. The application is hosted on Amazon EC2 instances behind an Application Load Balancer (ALB) in a single AWS Region. The company wants to improve the application's fault tolerance and reduce recovery time in the event of a regional outage, aiming for a Recovery Time Objective (RTO) of less than 4 hours and a Recovery Point Objective (RPO) of less than 1 hour. Which disaster recovery strategy should the SysOps Administrator recommend?Reliability and Business Continuity
- 195.A company is migrating an on-premises application to AWS. The application uses a monolithic architecture and stores critical state information on local disk, making it difficult to scale and recover from failures. The SysOps Administrator needs to re-architect the application to be highly available and resilient across multiple Availability Zones (AZs) in a single Region, ensuring that state information is not lost during instance failures. Which of the following approaches should the administrator take?Reliability and Business Continuity
- 196.A financial services company needs to ensure that its critical application data stored in an Amazon S3 bucket is immutable for a period of 7 years to meet regulatory compliance. After the retention period, the data should be automatically deleted. The company also wants to prevent any user, including the root account, from deleting or modifying the objects during this period. Which S3 feature should the SysOps Administrator configure?Reliability and Business Continuity
- 197.A company is deploying a new containerized application that requires very low latency and high throughput between its services. These services are deployed across multiple EC2 instances within the same VPC. The application needs to handle millions of requests per second. Which type of Elastic Load Balancer (ELB) is best suited for this workload?Networking and Content Delivery
- 198.A SysOps administrator is configuring a new VPC and needs to ensure that EC2 instances in private subnets can initiate outbound connections to the internet for software updates, but prevent unsolicited inbound connections. Which AWS networking component should be deployed to achieve this requirement?Networking and Content Delivery
- 199.A media company is using Amazon S3 to store a vast archive of video and image assets. These assets are frequently accessed for the first 30 days after upload, then accessed infrequently for the next 90 days, and finally, rarely accessed but must be retained indefinitely for compliance reasons. The company wants to optimize storage costs while ensuring data availability and durability. Which S3 storage class strategy would best meet these requirements?Cost and Performance Optimization
- 200.A development team uses an Amazon RDS for PostgreSQL database for their analytics application. They are experiencing performance bottlenecks during peak reporting times, specifically due to complex read-heavy queries. The primary database instance is already provisioned with sufficient compute and memory. Which AWS service or feature would be most effective in offloading the read workload and improving the application's reporting performance?Cost and Performance Optimization