AWS Certified DevOps Engineer – Professional practice questions

209 free questions with answers and explanations.

Practice test
  1. 101.A security-conscious organization is implementing a new CI/CD pipeline. They need to ensure that no hardcoded credentials or sensitive information are committed to their source code repositories. The pipeline should automatically scan code for these patterns before deployment. Which best practice should they implement, and what tool could assist in this process?Configuration Management and Infrastructure as Code
  2. 102.A large enterprise is adopting Infrastructure as Code (IaC) with AWS CloudFormation across hundreds of accounts and multiple regions. They need a scalable and centralized way to deploy and manage common infrastructure components (e.g., VPCs, IAM roles, security groups) consistently across all accounts and regions. Updates to these components must be propagated efficiently. Which AWS service is designed to address this complex multi-account, multi-region IaC deployment challenge?Configuration Management and Infrastructure as Code
  3. 103.A large enterprise is adopting a multi-account strategy with a centralized security team responsible for defining baseline security configurations for all AWS accounts. They use AWS CloudFormation for infrastructure provisioning. They need to ensure that every new EC2 instance across all development and production accounts automatically gets a specific set of security groups and an IAM instance profile defined by the security team, without developers having to explicitly include them in their CloudFormation templates. How can this requirement be met with the LEAST operational overhead?Configuration Management and Infrastructure as Code
  4. 104.A company operates a critical web application that serves customers globally. The application uses Amazon EC2 instances in an Auto Scaling group behind an Application Load Balancer (ALB). To minimize latency for users in different geographic regions, the company has deployed the application in multiple AWS Regions. They need a robust disaster recovery strategy that automatically routes traffic to a healthy region if the primary region becomes unavailable. Which AWS service combination should be used to achieve this goal with automatic failover?Resilient Cloud Solutions
  5. 105.A financial analytics company uses Amazon Redshift as its data warehouse. They frequently load large datasets from Amazon S3 into Redshift tables. During data loading, they need to ensure that the entire batch of data is either completely committed or completely rolled back if any error occurs, maintaining data consistency. Which Redshift command and best practice should they use to achieve this transactional integrity during data loading?Resilient Cloud Solutions
  6. 106.A development team is using AWS CloudFormation to provision an Amazon RDS database. The database requires an administrator password that must be generated dynamically at deployment time, stored securely, and automatically rotated periodically. The team wants to avoid hardcoding the password in the CloudFormation template or passing it directly as a plaintext parameter. How can they achieve this using CloudFormation with secure secrets management best practices?Configuration Management and Infrastructure as Code
  7. 107.A DevOps team is deploying a new web application behind an Application Load Balancer (ALB) and needs to ensure that all traffic between the ALB and the EC2 instances is encrypted. The application uses HTTPS, and the EC2 instances are running Apache. Which configuration step is MOST critical to achieve this requirement?Security and Compliance
  8. 108.A global SaaS company provides a critical API service to its customers. The API uses an Amazon Aurora PostgreSQL database as its backend. To meet a Recovery Point Objective (RPO) of near-zero and a Recovery Time Objective (RTO) of less than 5 minutes during a regional disaster, the company has implemented an Aurora Global Database. In the event of a primary region failure, what is the most appropriate and fastest way to promote a secondary region to become the new primary?Resilient Cloud Solutions
  9. 109.A software company is developing a new SaaS application that requires strong isolation between customer environments. Each customer's data and compute resources must be logically separated to prevent cross-tenant data leakage. The DevOps team needs to design an architecture that provides this isolation while maintaining operational efficiency. Which approach BEST achieves logical isolation and scalability for multi-tenant SaaS applications on AWS?Security and Compliance
  10. 110.A DevOps team is using AWS CloudFormation to manage their infrastructure. They have a core network stack that defines VPCs, subnets, and route tables, which is deployed once per region. Multiple application stacks in the same region need to reference specific subnet IDs and security group IDs from this core network stack. The team wants to ensure that these references are dynamically linked and updated if the core network stack changes, without hardcoding values or manual input. Which CloudFormation feature should they use?Configuration Management and Infrastructure as Code
  11. 111.A company is automating its infrastructure provisioning using AWS CloudFormation. They want to prevent sensitive data, such as database passwords or API keys, from being directly written into the CloudFormation templates, even if encrypted. The solution must allow for easy parameterization and referencing of these values during stack creation. Which CloudFormation intrinsic function or feature is most appropriate for securely passing sensitive values as parameters to a stack without exposing them in the template or CloudFormation console events?Configuration Management and Infrastructure as Code
  12. 112.A company is designing a new microservices architecture where services communicate asynchronously. They need a highly available and durable messaging queue that can decouple services, handle message surges, and ensure that messages are processed exactly once, even if a consumer fails and retries. Which AWS service and configuration should the company choose?Resilient Cloud Solutions
  13. 113.A DevOps team is managing an application that runs on Amazon EC2 instances. They use AWS Systems Manager to automate operational tasks. To ensure that all EC2 instances are consistently configured with the necessary agents (e.g., CloudWatch agent, custom monitoring scripts) and that these configurations are automatically applied to new instances and maintained on existing ones, even if they drift, which Systems Manager capability should be utilized?Configuration Management and Infrastructure as Code
  14. 114.A DevOps team is managing a critical application that uses Amazon RDS for its database. The application needs to connect to the database securely, and the security team requires that all database access credentials are automatically rotated every 90 days. Which AWS service combination would BEST meet this requirement with minimal operational overhead?Security and Compliance
  15. 115.A global e-commerce company uses AWS CloudFormation StackSets to deploy foundational infrastructure (e.g., VPCs, IAM roles) across hundreds of AWS accounts in multiple regions. They need to update a critical security patch in an IAM role that is part of a StackSet. The update must be applied to all existing stack instances across all accounts and regions without manual intervention. Which CloudFormation StackSet operation should be used for this purpose?Configuration Management and Infrastructure as Code
  16. 116.A DevOps team is deploying a serverless application using AWS Lambda and API Gateway. The team needs to ensure that the Lambda functions can only be invoked by the specific API Gateway endpoint and no other source. How can this be achieved with the MOST granular and secure permissions?Security and Compliance
  17. 117.A development team is deploying a new microservice to AWS using AWS CloudFormation. They need to ensure that database connection strings, API keys, and other sensitive configuration data are securely managed and rotated without being exposed in the CloudFormation templates or application code. The solution must integrate seamlessly with existing AWS services and provide auditability. Which AWS service should the team use to store and retrieve these sensitive parameters?Configuration Management and Infrastructure as Code
  18. 118.A software development company is adopting a microservices architecture on AWS. Each microservice is deployed as an AWS Lambda function and requires specific, fine-grained permissions to interact with other AWS services (e.g., read from a specific S3 bucket, publish to a specific SQS queue). The company wants to ensure that these permissions are defined inline with the Lambda function's definition within the AWS Serverless Application Model (SAM) template, following the principle of least privilege and making the permissions easily discoverable and managed alongside the function code. Which SAM template construct should be used to achieve this?Configuration Management and Infrastructure as Code
  19. 119.A company is building a new serverless application using AWS Lambda functions that process real-time data streams from Amazon Kinesis. During peak load, the Lambda functions experience throttling, leading to data processing delays and increased Kinesis shard iterator age. The developers want to ensure that Lambda has sufficient concurrency to process the Kinesis stream efficiently without manual intervention, even during sudden spikes, and avoid cold starts as much as possible for critical functions. Which Lambda feature should they implement?Resilient Cloud Solutions
  20. 120.A financial institution requires a highly resilient and durable storage solution for audit logs that must be retained for 7 years. These logs are infrequently accessed but critical for compliance and forensic analysis. The solution must ensure data integrity and protect against accidental or malicious alterations, including by privileged users. Which AWS storage service and feature combination meets these requirements most effectively?Resilient Cloud Solutions
  21. 121.A DevOps team is managing an application that processes highly sensitive customer data. To meet compliance requirements, all access to this data must be logged, and any attempts at unauthorized access must trigger an immediate alert to the security team. The logs must be immutable and retained for seven years. Which combination of AWS services should the team use to meet these auditing and alerting requirements efficiently?Security and Compliance
  22. 122.A DevOps team is responsible for a serverless application consisting of AWS Lambda functions, Amazon API Gateway, and Amazon DynamoDB. They need to analyze performance bottlenecks and service dependencies during an incident to quickly identify the root cause of high latency. The solution must provide a visual representation of the request flow through all services. Which AWS service should they use?Incident and Event Response
  23. 123.A media company uses Amazon S3 to store large volumes of user-uploaded content. They need to implement a mechanism to automatically scan newly uploaded files for malware and inappropriate content before they are made public. The solution must be event-driven, scalable, and minimize operational overhead. Which architecture should the DevOps team recommend?Incident and Event Response
  24. 124.A security team requires that all container images deployed to Amazon Elastic Kubernetes Service (EKS) clusters must be scanned for vulnerabilities before deployment. If vulnerabilities are found, the deployment should be blocked, and the development team notified. Which AWS service should be integrated into the CI/CD pipeline to meet this requirement efficiently?SDLC Automation
  25. 125.A DevOps team supports a critical application running on AWS EC2 instances, which generates a high volume of operational metrics. They need to establish a centralized monitoring system that can ingest custom metrics from applications, aggregate them, and provide real-time dashboards and alerting. The solution must be highly scalable, durable, and offer flexible query capabilities. Which AWS service is best suited for this purpose?Incident and Event Response
  26. 126.A software company needs to ensure that their CI/CD pipelines always use the latest security patches for their build environments. They use custom Docker images for AWS CodeBuild projects. What is the most effective strategy to keep these custom Docker images updated with the latest patches and integrate this into their CI/CD process?SDLC Automation
  27. 127.A DevOps team needs to implement an automated system to perform post-incident analysis on EC2 instances. This involves collecting forensic data (e.g., memory dumps, disk images, log files) from a potentially compromised instance, storing it securely, and then isolating the instance. The process must be initiated on demand and ensure data integrity. Which combination of AWS services should be used?Incident and Event Response
  28. 128.A highly regulated enterprise manages multiple AWS accounts and needs to enforce a strict policy that prevents the creation of public S3 buckets across all accounts, without exception. Any attempt to create a public S3 bucket must be denied at the API level. Which AWS service should the DevOps team use to implement this preventative control?Incident and Event Response
  29. 129.A DevOps team manages a critical microservices application deployed on Amazon ECS. They need to ensure that if a container experiences a high number of restarts or crashes, an automated remediation process is triggered to replace the unhealthy container and notify the operations team. Which approach should they implement to achieve this?Incident and Event Response
  30. 130.A media company uses Amazon S3 to store large volumes of user-uploaded content. They need to implement an automated workflow to ensure that newly uploaded video files are immediately transcoded into multiple formats for different device compatibility. This process should be highly available, scalable, and cost-effective. Which solution BEST meets these requirements?Incident and Event Response
  31. 131.A financial institution uses AWS for its critical transaction processing systems. They need to ensure that any unauthorized changes to security group rules are immediately detected and remediated. The solution must be automated, high-fidelity, and minimize human intervention to comply with strict regulatory requirements. Which combination of AWS services should the DevOps team implement to meet these requirements?Incident and Event Response
  32. 132.A company is developing a microservices architecture. Each microservice has its own codebase, build process, and deployment lifecycle. They need to ensure that when a developer pushes changes to a microservice's repository, only that specific microservice is rebuilt, tested, and deployed, without affecting other services. Which strategy should be implemented to achieve this efficient and isolated CI/CD process?SDLC Automation
  33. 133.A global e-commerce company uses AWS Lambda functions for its serverless backend. During a recent incident, a critical Lambda function experienced a sudden increase in invocation errors, leading to degraded customer experience. The DevOps team needs to implement a proactive monitoring and alerting mechanism that can detect such anomalies in real-time and trigger automated remediation. The solution must be able to identify deviations from normal behavior rather than fixed thresholds. Which AWS service and feature should be used?Incident and Event Response
  34. 134.A company uses AWS Organizations to manage multiple AWS accounts and has a strict security policy requiring all S3 buckets to be encrypted at rest. They need to implement a mechanism that automatically identifies non-compliant S3 buckets across all accounts and remediates them by enabling default encryption. The solution must be centrally managed and scalable. Which combination of AWS services should be used?Incident and Event Response
  35. 135.A company is using AWS CodePipeline for their CI/CD workflows. They have a stage that deploys an application to an Amazon S3 bucket. Before releasing the new version to production, a manual approval from a manager is required. How can this manual approval step be most effectively integrated into the CodePipeline?SDLC Automation
  36. 136.A company uses Amazon Aurora MySQL for its critical database. They need to analyze slow query performance and identify resource bottlenecks during peak traffic periods. The solution must provide detailed insights into SQL queries, execution plans, and wait events without significantly impacting database performance. Which AWS service should the DevOps team enable and configure?Incident and Event Response
  37. 137.A DevOps team is managing a critical application deployed across multiple AWS regions using an active-active setup. They need to perform a database schema migration that requires a brief application downtime in each region. To minimize overall impact, they want to automate the process to perform the migration region-by-region, ensuring that the application in other regions remains fully operational during a regional migration. After successful migration and verification in one region, the process should automatically proceed to the next. Which deployment strategy and AWS services should be used?SDLC Automation
  38. 138.A team is deploying a new web application to EC2 instances using AWS CodeDeploy. They want to minimize deployment downtime by ensuring that traffic is only shifted to the new application version after it has passed a series of health checks. During the deployment, the old version should remain active to serve traffic. Which CodeDeploy deployment type should they choose to meet these requirements?SDLC Automation
  39. 139.A financial services company uses AWS for its critical applications. Regulatory compliance requires that all security incidents be handled according to a strict, auditable process. The security team wants to automate the initial containment and data collection for incidents involving Amazon EC2 instances that are flagged for suspicious network activity by Amazon GuardDuty. Which combination of AWS services provides the MOST effective and auditable automated response?Incident and Event Response
  40. 140.A DevOps team wants to implement a robust testing strategy for their web application. They need to ensure that the application's user interface (UI) and end-to-end functionality work correctly across different browsers and devices after every deployment to a staging environment. Which type of automated testing is best suited for this requirement?SDLC Automation
  41. 141.A DevOps team manages a critical application that processes sensitive customer data, running on EC2 instances. They need to ensure that all changes to the operating system, including package installations and configuration modifications, are immutable and auditable. If an unauthorized change occurs, the instance should be automatically terminated and replaced with a known good state. Which strategy should the team implement?Incident and Event Response
  42. 142.A team uses AWS CodeBuild to compile their application. They've noticed that builds are taking an excessively long time due to frequently changing dependencies that need to be downloaded at the start of every build. This impacts developer productivity and CI/CD pipeline efficiency. How can they optimize CodeBuild performance to reduce build times related to dependency downloads?SDLC Automation
  43. 143.A company is migrating its legacy application to AWS. The application has a complex database schema that evolves frequently. The DevOps team needs to automate database schema migrations as part of their CI/CD pipeline, ensuring that schema changes are applied incrementally, are reversible, and are tracked in version control. Which open-source tool is commonly integrated into CI/CD pipelines for this purpose, and how should it be used?SDLC Automation
  44. 144.A global e-commerce company uses AWS Lambda functions for its serverless backend. During peak sales events, the company experiences intermittent performance degradation that is difficult to trace. They need to implement a solution to monitor the performance of individual Lambda invocations, identify bottlenecks, and visualize the entire request flow across multiple services. Which AWS service is BEST suited for this requirement?Incident and Event Response
  45. 145.A development team is building a new application that will use a shared library published internally. They need a secure and efficient way to store, manage, and retrieve these private software packages (e.g., Maven, npm, PyPI packages) within their AWS CI/CD pipeline. What is the most appropriate AWS service to use for this purpose?SDLC Automation
  46. 146.A DevOps team manages a critical microservices application on Amazon EKS. They need to implement a robust solution for collecting, analyzing, and alerting on application logs to quickly identify and troubleshoot issues. The solution must be scalable, cost-effective, and provide near real-time insights across multiple clusters. Which approach should the team take?Incident and Event Response
  47. 147.A team is developing a critical financial application. They need to integrate automated security testing into their CI/CD pipeline to identify common web application vulnerabilities (e.g., SQL injection, XSS) before deployment. The testing should be performed against the running application in a staging environment. Which type of automated security testing is most suitable for this requirement?SDLC Automation
  48. 148.A software development company uses AWS CodePipeline for its CI/CD workflows. They have a requirement to automatically roll back a failed deployment to the previously successful version if any stage in the pipeline fails. The solution must be integrated with CodePipeline and minimize manual intervention. Which feature of AWS CodePipeline should be configured?Incident and Event Response
  49. 149.A development team is deploying a new serverless application consisting of AWS Lambda functions and Amazon API Gateway. They need to ensure that the deployment process minimizes downtime and allows for a quick rollback in case of issues. Which deployment strategy should they implement?SDLC Automation
  50. 150.A team is managing an application deployed on Amazon EKS using Helm charts. They want to implement a GitOps approach where all application and infrastructure configurations are stored in a Git repository, and changes are automatically synchronized to the EKS cluster. Which tool or service combination should they use to achieve this continuous synchronization and reconciliation?SDLC Automation