AWS Certified DevOps Engineer – Professional practice questions

209 free questions with answers and explanations.

Practice test
  1. 1.A company is migrating a critical application to AWS Lambda functions and Amazon API Gateway. They need to implement distributed tracing to monitor the performance of individual Lambda invocations and their interactions with downstream services, such as Amazon DynamoDB and external APIs. The solution should provide a visual service map and detailed trace data to identify latency bottlenecks. The developers want to minimize manual instrumentation. Which approach should be used?Monitoring and Logging
  2. 2.A global gaming company uses Amazon DynamoDB for storing user profiles. They need to monitor DynamoDB's performance in real-time, specifically tracking read/write capacity utilization, latency, and throttled requests. They also require automated alerts if these metrics exceed predefined thresholds. The solution must be cost-effective and provide granular visibility.Monitoring and Logging
  3. 3.A DevOps team manages a critical application running on Amazon EC2 instances. They need to collect detailed system-level metrics, such as memory utilization and disk I/O, that are not available by default in Amazon CloudWatch. The solution must be cost-effective and integrate seamlessly with existing CloudWatch dashboards and alarms. Which AWS service or tool should the team use to meet these requirements?Monitoring and Logging
  4. 4.A company uses AWS CodeBuild for its CI/CD pipeline. They want to ensure that all build failures trigger an immediate notification to a Slack channel, including details about the build project, status, and a link to the CodeBuild console for quick investigation. The solution must be highly available and require minimal custom code. Which approach should a DevOps engineer implement?Monitoring and Logging
  5. 5.A DevOps team requires a comprehensive monitoring solution for their containerized application running on Amazon EKS. They need to collect metrics at the node, pod, and container level, analyze application logs, and visualize the health and performance of their Kubernetes cluster. The solution should be scalable, cost-effective, and provide deep insights into the EKS environment. Which combination of AWS services and open-source tools is most suitable?Monitoring and Logging
  6. 6.A company is migrating its on-premises applications to AWS. They have a hybrid environment where some applications will remain on-premises, and others will move to Amazon EC2. The security team requires a centralized logging solution for both on-premises application logs (Apache, Nginx, custom app logs) and EC2 instance logs, with real-time alerting capabilities. The solution must minimize operational overhead. Which approach should the DevOps team take?Monitoring and Logging
  7. 7.A media streaming company uses Amazon CloudFront to deliver content globally. They need to analyze user behavior, content popularity, and identify potential bot activity by examining access logs. The volume of logs is extremely high, and the analysis needs to be performed ad-hoc using standard SQL queries without provisioning or managing any servers. Which solution should they choose?Monitoring and Logging
  8. 8.A security team needs to monitor access to sensitive data stored in Amazon S3 buckets. They require real-time alerts for specific access patterns, such as an unusual number of 'GetObject' requests from an unapproved IP range, or a 'DeleteObject' operation on a critical bucket. The solution must be highly available and integrate with existing security operations tools.Monitoring and Logging
  9. 9.A large enterprise uses AWS Organizations to manage hundreds of AWS accounts. They need to ensure that all security-related logs, such as VPC Flow Logs, DNS query logs (Route 53 Resolver query logs), and AWS WAF logs, are centrally collected, retained for 7 years, and made immediately searchable for incident response and forensic analysis. The solution must be cost-effective and scalable to petabytes of data without operational overhead. Which architecture should the DevOps team implement?Monitoring and Logging
  10. 10.A DevOps team is responsible for a mission-critical microservices application deployed on Amazon EKS. They need to gain deep insights into the performance and health of their Kubernetes clusters, including node, pod, and container-level metrics, and also collect application logs. The solution must provide a single pane of glass for monitoring and allow for historical analysis. How should the team implement this monitoring solution?Monitoring and Logging
  11. 11.A company is looking to centralize monitoring for its hybrid cloud environment, which includes applications running on AWS EC2 instances and on-premises servers. They need to collect operating system metrics (CPU, memory, disk I/O) and application-specific metrics from both environments, and visualize them on a unified dashboard. The solution should be scalable and leverage existing AWS monitoring capabilities as much as possible. Which approach provides the most integrated and scalable solution?Monitoring and Logging
  12. 12.A DevOps team wants to implement a robust log archival strategy for compliance requirements. They need to store application logs from various EC2 instances for 10 years in the most cost-effective manner. The logs are initially collected by the CloudWatch Agent and sent to CloudWatch Logs. After a short period (e.g., 30 days) for immediate operational analysis, the logs should be moved to long-term, immutable storage. Which solution provides the most cost-effective and compliant archival?Monitoring and Logging
  13. 13.A global e-commerce company uses AWS Lambda functions for its serverless backend. They need to monitor the performance and errors of these functions, including invocation counts, errors, duration, and throttles, to identify and troubleshoot issues quickly. The solution should provide pre-built dashboards and allow for custom alarms. Which AWS service is best suited for this requirement?Monitoring and Logging
  14. 14.A DevOps team manages a high-traffic web application where performance is critical. They need to analyze user request patterns, identify performance bottlenecks, and detect anomalies in real-time. The application uses Amazon API Gateway, AWS Lambda, and Amazon DynamoDB. The solution must provide end-to-end visibility of requests and automatically identify deviations from normal behavior. Which combination of AWS services should the team implement?Monitoring and Logging
  15. 15.A company is migrating its on-premises applications to AWS. They have a requirement to centralize all application and system logs from both their existing on-premises servers and new Amazon EC2 instances into a single AWS service for unified monitoring and analysis. The solution must support real-time ingestion and querying capabilities.Monitoring and Logging
  16. 16.A development team has deployed a new microservices application on Amazon EKS. They observe intermittent latency spikes and errors, but traditional log analysis makes it difficult to pinpoint the root cause across distributed services. They need a solution to visualize the request flow end-to-end, identify bottlenecks, and understand service dependencies without extensively modifying their application code.Monitoring and Logging
  17. 17.A media company uses AWS Step Functions to orchestrate complex video processing workflows. They need to analyze the execution history of these workflows, identify states with high latency, and visualize the overall flow to optimize performance and troubleshoot failures. The solution should provide detailed insights into individual step executions and transitions.Monitoring and Logging
  18. 18.A DevOps team is deploying a new serverless application using AWS Lambda functions and Amazon API Gateway. They need to ensure that detailed performance metrics and trace data are collected for all invocations to monitor application health and troubleshoot issues. The solution must be easy to implement and minimize overhead for the Lambda functions.Monitoring and Logging
  19. 19.A financial services company is migrating its legacy monolithic application to a microservices architecture on AWS. They require a robust solution for collecting and analyzing highly sensitive audit logs from all microservices, which are deployed as Docker containers on Amazon ECS. The solution must ensure data encryption at rest and in transit, support long-term retention for 7 years, and provide granular access controls over who can view specific log data. Performance and scalability are critical due to high log volumes. Which combination of AWS services is the most appropriate for these requirements?Monitoring and Logging
  20. 20.A DevOps team is developing a new serverless application using AWS Lambda functions. They need to collect custom application metrics, such as the number of successful order placements and the duration of specific business transactions, directly from their Lambda functions. These metrics should be available in CloudWatch for dashboarding and alarming, and the developers want to achieve this with minimal code complexity and overhead. Which method is most efficient for publishing these custom metrics?Monitoring and Logging
  21. 21.A financial services company needs to ensure that all administrative activities and API calls across their AWS accounts are logged and immutable for auditing and compliance purposes. They also require a centralized view of these logs across multiple accounts. What is the most effective and compliant solution?Monitoring and Logging
  22. 22.A global e-commerce company uses Amazon CloudFront to distribute its web content. They need to monitor user behavior analytics, such as page views, unique visitors, and geographic distribution, for their marketing and product teams. The solution must be serverless, scalable, and enable ad-hoc querying of historical data without managing complex infrastructure.Monitoring and Logging
  23. 23.A financial services company uses AWS Lambda functions for processing sensitive customer data. Due to strict compliance requirements, all invocations of these Lambda functions must be logged, and the logs must be retained for seven years in an immutable state. The solution must also allow for centralized access and analysis by authorized personnel while minimizing operational overhead.Monitoring and Logging
  24. 24.A software development company uses AWS CodeBuild for its continuous integration pipeline. They want to receive real-time notifications in their Slack channel whenever a build fails or succeeds, including details about the build status and a link to the build logs. The solution must be simple to configure and require minimal custom code. Which AWS service should they use?Monitoring and Logging
  25. 25.A development team is deploying a new microservices application on AWS using Amazon ECS and AWS Fargate. They need a centralized logging solution that can collect logs from multiple containers, store them durably, and allow for real-time analysis and querying. The solution should also be cost-effective and require minimal operational overhead. Which AWS service combination best meets these requirements?Monitoring and Logging
  26. 26.A DevOps team manages a critical application running on Amazon EC2 instances. They want to proactively detect when the CPU utilization of an EC2 instance significantly deviates from its normal historical pattern, rather than relying on static thresholds. This detection should trigger an alert to the operations team. Which CloudWatch feature should they use?Monitoring and Logging
  27. 27.A DevOps team requires a dashboard to visualize the health and performance of their distributed microservices application running on AWS Fargate. The dashboard needs to display key metrics like CPU and memory utilization per service, network I/O, application logs, and custom business metrics. The solution should be easy to set up and provide a unified view without requiring extensive custom development.Monitoring and Logging
  28. 28.A DevOps team manages several critical applications deployed on Amazon EC2 instances. They need to create a robust alerting system that notifies on-call engineers via SMS and PagerDuty when CPU utilization exceeds 90% for more than 5 minutes on any instance, or when a critical application log message (e.g., 'ERROR: Database connection failed') appears. The system must also automatically create a JIRA ticket for investigation. What is the most effective and integrated AWS solution?Monitoring and Logging
  29. 29.A DevOps team manages a high-traffic e-commerce application on AWS, utilizing Amazon EC2 instances within an Auto Scaling group behind an Application Load Balancer (ALB). They observe intermittent latency spikes and need to pinpoint whether the issue originates from the ALB, the EC2 instances, or the backend database. To achieve this, they want to establish end-to-end transaction tracing without modifying application code significantly. Which tracing solution is most effective for this scenario?Monitoring and Logging
  30. 30.A large enterprise uses AWS Organizations to manage multiple AWS accounts. The security team requires that all CloudWatch Logs for critical applications across all accounts are centralized into a single, dedicated security account for long-term archival and analysis. The solution must be scalable, secure, and ensure that logs are not accidentally deleted.Monitoring and Logging
  31. 31.A company operates a critical serverless application composed of AWS Lambda functions, Amazon DynamoDB, and Amazon SQS. They need to monitor the application's health and performance by tracking key metrics such as Lambda invocation errors, DynamoDB throttled requests, and SQS message visibility timeouts. It is crucial to have custom dashboards combining these metrics and to receive alerts when anomalies occur, rather than fixed thresholds. Which solution best meets these requirements?Monitoring and Logging
  32. 32.A DevOps team is responsible for a critical application running on Amazon EC2 instances. They need to collect detailed operating system-level metrics, such as memory utilization, disk I/O, and process-level metrics, and send them to Amazon CloudWatch for monitoring and alarming. The solution must be cost-effective and easy to deploy across a fleet of instances.Monitoring and Logging
  33. 33.A DevOps team manages a fleet of Amazon EC2 instances running a critical web application. They need to be notified immediately if any instance's CPU utilization exceeds 90% for five consecutive minutes. The notification should be sent to a specific Slack channel, and an automated action should be triggered to scale out the Auto Scaling Group. How should they configure this monitoring and alerting solution?Monitoring and Logging
  34. 34.A security team requires that all API calls made to AWS services within their accounts are logged and immutable for auditing purposes. They need to analyze these logs to detect unusual activity, such as unauthorized API calls or changes to critical resources. The solution must ensure log integrity and long-term retention. Which AWS service is primarily responsible for fulfilling these requirements?Monitoring and Logging
  35. 35.A DevOps team is deploying a containerized application to Amazon ECS. The application needs to interact with various AWS services, such as DynamoDB and SQS. The security team insists that the application containers should never have hardcoded AWS credentials and must adhere to the principle of least privilege. What is the most secure and recommended way to grant AWS permissions to the ECS tasks running the application containers?Security and Compliance
  36. 36.A healthcare provider is deploying a new patient portal application on AWS. Due to HIPAA compliance, all sensitive patient data must be encrypted in transit and at rest, and only authorized internal users and services should be able to access the application. The DevOps team needs to ensure that the application's API endpoints are exposed securely, allowing only authenticated and authorized traffic, and preventing common web vulnerabilities. Which combination of AWS services should be used to achieve secure API exposure and access control?Security and Compliance
  37. 37.A global e-commerce company uses AWS CloudFront to deliver its web content. The security team has observed an increase in SQL injection and cross-site scripting (XSS) attacks. They need to implement a solution that can identify and block these common web exploits at the edge, before they reach the origin servers, without modifying the application code. Which AWS service should a DevOps engineer implement?Security and Compliance
  38. 38.A large enterprise is adopting a multi-account strategy with a centralized security team responsible for defining and enforcing approved infrastructure patterns. Development teams need to provision common services (e.g., standard EC2 instances, S3 buckets with specific tagging and encryption policies, standardized databases) in their respective accounts without deviating from these approved patterns. The solution must allow developers to self-service these resources while ensuring compliance. Which AWS service is best suited to meet these requirements?Configuration Management and Infrastructure as Code
  39. 39.A financial services company is migrating its legacy applications to AWS. They have strict change management policies requiring all infrastructure modifications to be thoroughly reviewed and approved by a security team before being applied to production. They use AWS CloudFormation for infrastructure provisioning. Which CloudFormation feature allows them to preview the exact impact of a proposed stack update on their resources and get explicit approval before execution, without actually applying the changes?Configuration Management and Infrastructure as Code
  40. 40.A company is implementing a new application that will use a shared Amazon RDS database instance. The application is deployed via AWS CodePipeline. The database credentials need to be dynamically retrieved by the application at runtime and rotated regularly without requiring application code changes. The security team mandates that credentials must never be exposed in plaintext in any configuration file or environment variable within the CI/CD pipeline or on the EC2 instances. Which combination of AWS services should be used to meet these requirements?Configuration Management and Infrastructure as Code
  41. 41.A data analytics company uses Amazon Redshift as its data warehouse. They frequently run large batch `COPY` operations to load data from Amazon S3 into Redshift tables. The data loading process must be atomic; either all rows from a `COPY` command are successfully loaded, or none are. If any error occurs during the `COPY` operation, the entire transaction should be rolled back without leaving partial data in the table. How can this requirement be met?Resilient Cloud Solutions
  42. 42.A large enterprise is adopting a multi-account strategy on AWS, with hundreds of accounts organized into an AWS Organizations structure. The security team needs to enforce a baseline set of security policies, such as disallowing public S3 buckets, requiring encryption for EBS volumes, and restricting specific IAM actions across ALL accounts, including newly created ones. These policies must be mandatory and apply to all IAM users and roles within those accounts. Which AWS feature is the MOST effective for implementing these preventative, mandatory controls at scale across the organization?Security and Compliance
  43. 43.A financial institution is migrating its applications to AWS and has strict requirements for data residency and isolation. They need to ensure that all data processed and stored by their applications remains within a specific geographic region and is logically separated from other customers' data within that region. Which AWS service and approach would BEST address these requirements?Security and Compliance
  44. 44.A financial services company is migrating its critical transaction processing application to AWS. The application requires extremely low latency and high availability across multiple Availability Zones. Data consistency is paramount, and the company needs to ensure that in the event of a regional disaster, recovery time objectives (RTO) and recovery point objectives (RPO) are minimized to less than 15 minutes. The current on-premises setup uses a synchronous replication database. Which AWS database and replication strategy best meets these requirements?Resilient Cloud Solutions
  45. 45.A media company uses Amazon EC2 instances to transcode video files. These instances are part of an Auto Scaling group and process jobs from an Amazon SQS queue. The transcoding process is CPU-intensive, and new jobs are consistently added to the queue throughout the day. The company wants to ensure that the transcoding instances scale out quickly enough to keep the SQS queue backlog at a manageable level, minimizing processing delays while avoiding over-provisioning. Which Auto Scaling policy type is best suited for this scenario?Resilient Cloud Solutions
  46. 46.A global software-as-a-service (SaaS) company needs to ensure its application is highly available and fault-tolerant across multiple AWS regions. The application consists of stateless web servers and a stateful database. The company requires an architecture that can automatically route users to the nearest healthy region and perform automated failover in case of a regional outage. Which combination of AWS services should be used to meet these requirements?Resilient Cloud Solutions
  47. 47.A company operates a web application using Amazon EC2 Auto Scaling groups behind an Application Load Balancer (ALB). During peak traffic, the application experiences performance bottlenecks. Upon investigation, it's observed that while EC2 instances are scaling out, the database (Amazon RDS for MySQL) becomes overloaded. The DevOps team needs to improve the resiliency and scalability of the database layer to handle traffic spikes more effectively without re-architecting the application to use a NoSQL database. Which strategy should they implement?Resilient Cloud Solutions
  48. 48.A financial services company is migrating its legacy applications to AWS. They have strict regulatory requirements that mandate all infrastructure changes be fully auditable and reversible. They are adopting Infrastructure as Code (IaC) using AWS CloudFormation. To meet the auditability and reversibility requirements, which CloudFormation feature should they leverage for managing changes to their production environments?Configuration Management and Infrastructure as Code
  49. 49.A development team is building a serverless application using AWS Lambda functions and Amazon API Gateway. They need to ensure that their Lambda functions can handle sudden, large increases in invocation requests without performance degradation or error, maintaining consistent response times. Which architectural pattern should they consider for their Lambda functions?Resilient Cloud Solutions
  50. 50.A global e-commerce company uses AWS CloudFront to deliver its web content. To protect against common web exploits and unwanted bot traffic, the security team requires a solution that inspects incoming web requests and blocks malicious traffic before it reaches the origin servers. This solution must be highly available and integrate seamlessly with CloudFront. Which AWS service should the DevOps engineer implement?Security and Compliance