AWS Certified DevOps Engineer – Professional practice questions

209 free questions with answers and explanations.

Practice test
  1. 51.A healthcare provider is deploying a new patient portal application on AWS. Due to HIPAA compliance, all sensitive patient data must be encrypted in transit and at rest, and only authorized internal users and services should be able to access the application. The DevOps team needs to ensure that the application's API endpoints are exposed securely, allowing only authenticated and authorized traffic, and preventing common web vulnerabilities. Which combination of AWS services should be used to achieve secure API exposure and access control?Security and Compliance
  2. 52.A financial services company is migrating its legacy applications to AWS. They have strict change management policies requiring all infrastructure modifications to be thoroughly reviewed and approved by a security team before being applied to production. They use AWS CloudFormation for infrastructure provisioning. Which CloudFormation feature allows them to preview the exact impact of a proposed stack update on their resources and get explicit approval before execution, without actually applying the changes?Configuration Management and Infrastructure as Code
  3. 53.A company is implementing a new application that will use a shared Amazon RDS database instance. The application is deployed via AWS CodePipeline. The database credentials need to be dynamically retrieved by the application at runtime and rotated regularly without requiring application code changes. The security team mandates that credentials must never be exposed in plaintext in any configuration file or environment variable within the CI/CD pipeline or on the EC2 instances. Which combination of AWS services should be used to meet these requirements?Configuration Management and Infrastructure as Code
  4. 54.A global software company maintains a large number of AWS accounts for development, testing, and production environments across various regions. Each account requires a standardized set of foundational resources, including specific IAM roles, network configurations (VPCs, subnets, route tables), and security groups. The company needs to provision and manage these identical stacks consistently across all accounts and regions, ensuring that any updates to the foundational infrastructure are propagated automatically. Which AWS CloudFormation feature is designed for this specific use case?Configuration Management and Infrastructure as Code
  5. 55.A financial services company is migrating its critical transaction processing application to AWS. The application requires extremely low latency and high availability across multiple Availability Zones. Data consistency is paramount, and the company needs to ensure that in the event of a regional disaster, recovery time objectives (RTO) and recovery point objectives (RPO) are minimized to less than 15 minutes. The current on-premises setup uses a synchronous replication database. Which AWS database and replication strategy best meets these requirements?Resilient Cloud Solutions
  6. 56.A large enterprise is adopting a multi-account strategy on AWS, with hundreds of accounts organized into an AWS Organizations structure. The security team needs to enforce a baseline set of security policies, such as disallowing public S3 buckets, requiring encryption for EBS volumes, and restricting specific IAM actions across ALL accounts, including newly created ones. These policies must be mandatory and apply to all IAM users and roles within those accounts. Which AWS feature is the MOST effective for implementing these preventative, mandatory controls at scale across the organization?Security and Compliance
  7. 57.A development team is building a serverless application using AWS Lambda functions and Amazon API Gateway. They need to ensure that their Lambda functions can handle sudden, large increases in invocation requests without performance degradation or error, maintaining consistent response times. Which architectural pattern should they consider for their Lambda functions?Resilient Cloud Solutions
  8. 58.A financial services company is building a new application that will store highly sensitive customer data. The application must meet stringent regulatory compliance requirements for data immutability and long-term retention, preventing any modification or deletion of records for seven years, even by privileged users. Which AWS storage solution and configuration should be used to meet these requirements with the highest level of assurance?Resilient Cloud Solutions
  9. 59.A large enterprise is migrating its legacy monolithic application to a microservices architecture on AWS. They need to ensure that their new microservices, deployed using Amazon ECS with Fargate, can scale independently and handle varying loads efficiently. The developers are concerned about potential cascading failures if one microservice becomes overloaded. They also want to ensure that upstream services are not negatively impacted by slow responses from downstream services. Which architectural pattern should the enterprise implement to enhance resilience between their microservices?Resilient Cloud Solutions
  10. 60.A global gaming company uses Amazon DynamoDB for storing player profiles and game state. To ensure high availability and low latency for players worldwide, they have deployed their application in multiple AWS Regions. They need to ensure that player data is automatically replicated across these regions and remains consistent, even during regional outages, with minimal RPO and RTO. Which DynamoDB feature should the company leverage?Resilient Cloud Solutions
  11. 61.A company operates a critical e-commerce application on AWS. During a peak sales event, an unexpected surge in traffic causes several backend services to become unresponsive, leading to customer complaints. The DevOps team needs to quickly identify the root cause of the performance degradation. Which AWS service should they prioritize for analyzing logs and metrics to pinpoint the bottleneck?Incident and Event Response
  12. 62.A financial institution is deploying a new critical application to AWS. They use AWS CloudFormation for infrastructure provisioning. Due to strict compliance requirements, all infrastructure changes must be reviewed and approved before deployment, and any deviation from the approved template must be prevented. The security team also mandates that no resource can be accidentally deleted. Which AWS CloudFormation feature should be implemented to meet these requirements effectively?Configuration Management and Infrastructure as Code
  13. 63.A global e-commerce company uses AWS CloudFront to deliver its web content. To protect against common web exploits and unwanted bot traffic, the security team requires a solution that inspects incoming web requests and blocks malicious traffic before it reaches the origin servers. This solution must be highly available and integrate seamlessly with CloudFront. Which AWS service should the DevOps engineer implement?Security and Compliance
  14. 64.A DevOps team is developing a new application that will process highly sensitive customer data. The application will run on Amazon EC2 instances within a private subnet. The security team mandates that all outgoing internet traffic from these instances must be inspected and filtered by a third-party firewall appliance running in an inspection VPC before reaching the public internet to ensure compliance with data exfiltration policies. How can this network architecture be implemented MOST effectively?Security and Compliance
  15. 65.A global company operates a mission-critical web application distributed across multiple AWS regions. They need to ensure continuous availability and resilience against regional outages. The application uses Amazon Route 53 to resolve DNS. In the event of a primary region becoming unhealthy, traffic must be automatically routed to a healthy secondary region. What Route 53 routing policy and health check configuration should be used?Resilient Cloud Solutions
  16. 66.A media company uses Amazon EC2 instances to transcode video files. These instances are part of an Auto Scaling group and process jobs from an Amazon SQS queue. The transcoding process is CPU-intensive, and new jobs are consistently added to the queue throughout the day. The company wants to ensure that the transcoding instances scale out quickly enough to keep the SQS queue backlog at a manageable level, minimizing processing delays while avoiding over-provisioning. Which Auto Scaling policy type is best suited for this scenario?Resilient Cloud Solutions
  17. 67.A development team is using AWS CloudFormation to provision an Amazon RDS database. The database credentials (username and password) need to be securely stored and automatically rotated. When provisioning the RDS instance via CloudFormation, these credentials should be passed without hardcoding them in the template, and the application should retrieve them dynamically at runtime. Which AWS service integration with CloudFormation best supports this requirement?Configuration Management and Infrastructure as Code
  18. 68.A DevOps team needs to implement a solution to automatically identify and flag exposed access keys, sensitive data in plain text, and other credentials that might be accidentally pushed to public or private GitHub repositories. This solution must integrate with AWS services and provide alerts to the security team. Which AWS service is specifically designed for this type of secret detection in code repositories?Security and Compliance
  19. 69.A team is developing a new serverless application using AWS Lambda functions that process millions of events daily. These events are highly variable, with unpredictable spikes in volume. The team observes that during these spikes, new Lambda invocations experience high latency due to cold starts. They need to minimize cold start latency for critical functions to maintain a consistent user experience. What is the most effective solution?Resilient Cloud Solutions
  20. 70.A company operates a web application using Amazon EC2 Auto Scaling groups behind an Application Load Balancer (ALB). During peak traffic, the application experiences performance bottlenecks. Upon investigation, it's observed that while EC2 instances are scaling out, the database (Amazon RDS for MySQL) becomes overloaded. The DevOps team needs to improve the resiliency and scalability of the database layer to handle traffic spikes more effectively without re-architecting the application to use a NoSQL database. Which strategy should they implement?Resilient Cloud Solutions
  21. 71.A company is implementing a new CI/CD pipeline for their applications deployed on Amazon EC2 instances. They want to ensure that all EC2 instances are patched with the latest security updates regularly and automatically. Furthermore, the patching process must be non-disruptive to the running application and allow for a controlled rollout across different environments (dev, test, prod). Which AWS service combination, integrated with their CI/CD pipeline, provides the MOST robust solution for this requirement?Configuration Management and Infrastructure as Code
  22. 72.A large e-commerce platform relies on a critical microservice that processes customer orders. This microservice is deployed across multiple EC2 instances within an Auto Scaling group, behind an Application Load Balancer (ALB). The team needs to ensure that during deployments, new code is rolled out gradually, and any issues are detected and automatically rolled back without impacting active customer orders. Which deployment strategy and associated AWS services should be used to achieve this?Resilient Cloud Solutions
  23. 73.A startup is rapidly expanding its application on AWS and frequently deploys new features to its production environment. They use AWS CloudFormation for infrastructure as code. To minimize downtime and ensure a smooth transition between application versions, they want to implement a deployment strategy that gradually shifts traffic from the old version to the new one, with an easy rollback mechanism if issues arise. Which CloudFormation resource type, when integrated with CodeDeploy, best supports this requirement?Configuration Management and Infrastructure as Code
  24. 74.A global e-commerce company experiences seasonal traffic spikes, particularly during holiday sales events. Their current application runs on Amazon EC2 instances within an Auto Scaling group, fronted by an Application Load Balancer (ALB). During peak times, customers report slow loading pages and occasional service unavailability, even though the Auto Scaling group is configured to scale out. The operations team observes that the EC2 instances are often CPU-bound before new instances become available to handle the increased load. Which strategy should the company implement to proactively address the performance degradation during anticipated traffic surges?Resilient Cloud Solutions
  25. 75.A large enterprise uses multiple Amazon VPCs across several AWS accounts to host various applications. They need to establish secure and highly available network connectivity between these VPCs and their on-premises data centers. Furthermore, they require centralized network management and routing control. The current solution involves multiple Site-to-Site VPN connections, which are becoming difficult to manage and scale. Which AWS networking service should they implement to simplify and centralize their network architecture?Resilient Cloud Solutions
  26. 76.A company uses Amazon Aurora MySQL for its critical relational database. To enhance disaster recovery capabilities and minimize data loss (RPO) and downtime (RTO) in the event of a regional outage, they want to establish a cross-Region disaster recovery solution. They also need to be able to promote the secondary database to primary with minimal data loss and downtime. Which Aurora feature should they implement?Resilient Cloud Solutions
  27. 77.A global e-commerce company uses AWS CloudFormation StackSets to deploy foundational infrastructure (e.g., VPC, IAM roles) across hundreds of AWS accounts and multiple AWS regions. The security team has identified a critical vulnerability in a default setting of an S3 bucket policy defined in one of these foundational StackSet templates. They need to update this specific S3 bucket policy across all deployed StackSet instances immediately without affecting other resources in the stack and with minimal disruption. What is the MOST efficient way to achieve this?Configuration Management and Infrastructure as Code
  28. 78.A software-as-a-service (SaaS) provider uses Amazon S3 to store customer-uploaded files. These files are critical for their business and must be highly durable and available. The company wants to ensure that, in the event of an AWS Region-wide outage, their customers can still access their files with minimal disruption. They also need to minimize the Recovery Time Objective (RTO) and Recovery Point Objective (RPO) for this data. Which solution provides the most resilient and fault-tolerant architecture for S3 data across regions?Resilient Cloud Solutions
  29. 79.A company uses a fleet of Amazon EC2 instances to run a batch processing application. This application is designed to be fault-tolerant, meaning individual instance failures do not affect the overall job completion. The company wants to minimize costs while ensuring that enough capacity is available to process jobs within a given timeframe. The workload can tolerate occasional interruptions. Which EC2 purchasing option is most cost-effective for this scenario?Resilient Cloud Solutions
  30. 80.A company is migrating its on-premises applications to AWS. They want to adopt an Infrastructure as Code (IaC) approach for managing their AWS resources. The team needs a solution that allows them to define their infrastructure in a declarative way, supports version control, and can be used to deploy resources consistently across multiple environments (development, staging, production). Which AWS service is best suited for this requirement?Configuration Management and Infrastructure as Code
  31. 81.A company is implementing a new CI/CD pipeline for its serverless applications using AWS CodePipeline. They need to ensure that all Lambda functions are scanned for common vulnerabilities and adherence to security best practices before deployment to production. The security team also requires that these scans are integrated seamlessly into the pipeline and can block deployments if critical issues are found. Which combination of AWS services should the DevOps engineer integrate into the CodePipeline for automated security scanning?Security and Compliance
  32. 82.A company is building a new microservices-based application using Amazon ECS Fargate. Each microservice needs to be highly available and capable of scaling independently based on demand. The DevOps team wants to ensure that the application can handle fluctuating traffic patterns efficiently while minimizing operational overhead. Which scaling strategy should be implemented for the ECS Fargate services?Resilient Cloud Solutions
  33. 83.A financial services company is migrating its legacy applications to AWS. They have strict regulatory requirements that mandate all infrastructure changes be fully auditable and reversible. They are adopting Infrastructure as Code (IaC) using AWS CloudFormation. To meet the auditability and reversibility requirements, which CloudFormation feature should they leverage for managing changes to their production environments?Configuration Management and Infrastructure as Code
  34. 84.A DevOps team is managing an application that uses several AWS services, including Amazon EC2 instances, Amazon RDS databases, and Amazon S3 buckets. They use AWS CloudFormation to provision and manage these resources. The team needs to ensure that all CloudFormation templates adhere to strict security and compliance policies before deployment. Specifically, they must prevent the deployment of EC2 instances with public IP addresses and S3 buckets without server-side encryption. What is the MOST efficient way to automate the enforcement of these policies during the CloudFormation stack creation or update process?Configuration Management and Infrastructure as Code
  35. 85.A DevOps team is managing several AWS accounts for different environments (dev, test, prod). They use AWS CloudFormation for provisioning resources. Over time, some resources in the 'test' account have been manually modified outside of CloudFormation, leading to configuration drift. The team wants to identify these deviations automatically and remediate them. Which AWS service combination would best help them detect and potentially revert these unauthorized changes?Configuration Management and Infrastructure as Code
  36. 86.A company is implementing a new application using AWS Lambda functions. These Lambda functions need to access specific S3 buckets and DynamoDB tables. The security team insists on granting only the minimum necessary permissions to each Lambda function. The DevOps team wants to automate the creation and management of these permissions as part of their Infrastructure as Code (IaC) pipeline using AWS SAM (Serverless Application Model). Which SAM resource type should they use to define these fine-grained permissions for their Lambda functions?Configuration Management and Infrastructure as Code
  37. 87.A security team needs to enforce that all Amazon S3 buckets across multiple AWS accounts in an organization are configured with default encryption using AWS Key Management Service (KMS) with customer-managed keys (CMKs). How can a DevOps engineer implement this compliance requirement at scale and prevent future non-compliant buckets from being created?Security and Compliance
  38. 88.A financial services company is migrating its on-premises applications to AWS. Due to strict regulatory requirements (e.g., PCI DSS, HIPAA), all data at rest must be encrypted, and all data in transit must use TLS 1.2 or higher. The DevOps team needs to automate the enforcement of these encryption standards across all newly provisioned AWS resources, such as S3 buckets, EBS volumes, and EC2 instances, and report on any non-compliant resources. Which AWS service should the team use to continuously monitor and automatically remediate non-compliant resources?Security and Compliance
  39. 89.A global banking application uses Amazon Aurora PostgreSQL as its primary database. The application requires exceptionally low latency for read operations, especially for users in different continents. Additionally, the architects need a robust disaster recovery strategy that ensures continuous availability with an RPO of zero and an RTO of near-zero in case of a regional database failure. Which Aurora feature provides both ultra-low latency global reads and a synchronous, zero-RPO disaster recovery solution?Resilient Cloud Solutions
  40. 90.A rapidly growing startup has its core application deployed on Amazon EC2 instances behind an Application Load Balancer (ALB). The application experiences unpredictable traffic spikes, sometimes increasing by 500% in minutes, which frequently leads to performance degradation and timeouts. The current Auto Scaling group uses simple scaling policies based on CPU utilization, but it's not reacting fast enough. How should the DevOps team optimize the Auto Scaling configuration to handle these sudden, steep traffic increases more effectively?Resilient Cloud Solutions
  41. 91.A security-conscious organization uses AWS CloudFormation to manage its infrastructure. They have a strict policy that all Amazon S3 buckets must have server-side encryption enabled and be configured with public access blocked. Before deploying any CloudFormation stack, they need an automated way to validate that the S3 bucket resources defined in the template adhere to these security policies, failing the deployment if they don't. Which CloudFormation feature can provide this proactive policy enforcement during template validation?Configuration Management and Infrastructure as Code
  42. 92.A DevOps team is managing an application that processes highly sensitive customer data. To meet compliance requirements, all access to this data must be logged, and any attempts at unauthorized access must trigger an immediate alert to the security team. The logs must be immutable and retained for seven years. Which combination of AWS services should the team use to meet these auditing and alerting requirements efficiently?Security and Compliance
  43. 93.A financial institution requires a highly resilient and durable storage solution for audit logs that must be retained for 7 years. These logs are infrequently accessed but critical for compliance and forensic analysis. The solution must ensure data integrity and protect against accidental or malicious alterations, including by privileged users. Which AWS storage service and feature combination meets these requirements most effectively?Resilient Cloud Solutions
  44. 94.A company is building a new serverless application using AWS Lambda functions that process real-time data streams from Amazon Kinesis. During peak load, the Lambda functions experience throttling, leading to data processing delays and increased Kinesis shard iterator age. The developers want to ensure that Lambda has sufficient concurrency to process the Kinesis stream efficiently without manual intervention, even during sudden spikes, and avoid cold starts as much as possible for critical functions. Which Lambda feature should they implement?Resilient Cloud Solutions
  45. 95.A software development company is adopting a microservices architecture on AWS. Each microservice is deployed as an AWS Lambda function and requires specific, fine-grained permissions to interact with other AWS services (e.g., read from a specific S3 bucket, publish to a specific SQS queue). The company wants to ensure that these permissions are defined inline with the Lambda function's definition within the AWS Serverless Application Model (SAM) template, following the principle of least privilege and making the permissions easily discoverable and managed alongside the function code. Which SAM template construct should be used to achieve this?Configuration Management and Infrastructure as Code
  46. 96.A development team is deploying a new microservice to AWS using AWS CloudFormation. They need to ensure that database connection strings, API keys, and other sensitive configuration data are securely managed and rotated without being exposed in the CloudFormation templates or application code. The solution must integrate seamlessly with existing AWS services and provide auditability. Which AWS service should the team use to store and retrieve these sensitive parameters?Configuration Management and Infrastructure as Code
  47. 97.A DevOps team is deploying a serverless application using AWS Lambda and API Gateway. The team needs to ensure that the Lambda functions can only be invoked by the specific API Gateway endpoint and no other source. How can this be achieved with the MOST granular and secure permissions?Security and Compliance
  48. 98.A global e-commerce company uses AWS CloudFormation StackSets to deploy foundational infrastructure (e.g., VPCs, IAM roles) across hundreds of AWS accounts in multiple regions. They need to update a critical security patch in an IAM role that is part of a StackSet. The update must be applied to all existing stack instances across all accounts and regions without manual intervention. Which CloudFormation StackSet operation should be used for this purpose?Configuration Management and Infrastructure as Code
  49. 99.A DevOps team is managing a critical application that uses Amazon RDS for its database. The application needs to connect to the database securely, and the security team requires that all database access credentials are automatically rotated every 90 days. Which AWS service combination would BEST meet this requirement with minimal operational overhead?Security and Compliance
  50. 100.A DevOps team is managing an application that runs on Amazon EC2 instances. They use AWS Systems Manager to automate operational tasks. To ensure that all EC2 instances are consistently configured with the necessary agents (e.g., CloudWatch agent, custom monitoring scripts) and that these configurations are automatically applied to new instances and maintained on existing ones, even if they drift, which Systems Manager capability should be utilized?Configuration Management and Infrastructure as Code