AWS Certified DevOps Engineer – Professional practice questions
209 free questions with answers and explanations.
- 151.A financial institution requires that all application configurations, including database connection strings and API keys, are securely managed and rotated automatically. They are using AWS CodePipeline for their CI/CD and AWS Lambda for their serverless applications. How can the DevOps team integrate secure configuration management and rotation into their pipeline?SDLC Automation
- 152.A large enterprise is migrating hundreds of applications to AWS. They need a standardized and reusable CI/CD pipeline template that can be easily provisioned for each new application, ensuring consistency in build, test, and deployment stages. The template should allow for parameterization of application-specific details without requiring manual recreation of the pipeline for every new project. What is the most efficient AWS native approach to achieve this?SDLC Automation
- 153.A financial institution requires strict governance and auditability for all changes to their AWS infrastructure. They are implementing Infrastructure as Code (IaC) using AWS CloudFormation. How can they ensure that all CloudFormation stack updates are reviewed and approved by a change management board before execution?SDLC Automation
- 154.A DevOps team is setting up a CI/CD pipeline for an application that uses multiple environment-specific configuration files (e.g., `appsettings.dev.json`, `appsettings.prod.json`). They want to ensure that the correct configuration is automatically injected into the application artifact during the build process, based on the target deployment environment, without hardcoding sensitive information. How can they achieve this securely and efficiently within an AWS CodeBuild project?SDLC Automation
- 155.A development team wants to implement a robust testing strategy for their web application. They need to verify the application's functionality from a user's perspective, interacting with the UI and backend services as a real user would. These tests should run automatically as part of the CI/CD pipeline after deployment to a staging environment. Which type of testing is most appropriate for this requirement?SDLC Automation
- 156.A media company is using AWS Elemental MediaConvert to process video files uploaded to an S3 bucket. They want to automate the entire workflow: detect new video uploads, trigger MediaConvert jobs, and store the output in another S3 bucket, all integrated into a CI/CD-like flow for infrastructure and job definition updates. Which architecture pattern should the company implement?SDLC Automation
- 157.A software development team is adopting trunk-based development with frequent, small commits to the main branch. They want to ensure that every commit triggers a full suite of automated tests, including unit, integration, and static analysis, to maintain a high level of code quality and prevent regressions. The CI/CD pipeline should execute these tests quickly to provide rapid feedback. Which approach for test execution in AWS CodePipeline would best support this strategy?SDLC Automation
- 158.A DevOps team is adopting a trunk-based development model with frequent, small commits to a single main branch. Their CI/CD pipeline includes a comprehensive suite of unit, integration, and E2E tests, which currently run sequentially and take over an hour to complete. This long feedback loop is hindering developer productivity. How can the team significantly reduce the time developers wait for test results?SDLC Automation
- 159.A development team uses AWS CodePipeline to automate their software releases. They have a stage that deploys to a staging environment, and before it can proceed to production, a senior engineer must manually approve the deployment. How can they implement this requirement within CodePipeline?SDLC Automation
- 160.A DevOps team is responsible for managing application configurations and secrets across multiple environments (development, staging, production) for a new microservice. They need a secure, centralized, and version-controlled way to store database connection strings, API keys, and other sensitive parameters, ensuring that these are only accessible by authorized services and users. Which AWS service is best suited for this requirement?SDLC Automation
- 161.A financial institution is migrating its legacy monolithic application to a microservices architecture on AWS. They need to ensure that application dependencies, including third-party libraries and internal shared components, are managed securely and efficiently across all microservices. The solution must provide versioning, access control, and integration with existing CI/CD pipelines. Which AWS service should they use?SDLC Automation
- 162.A large e-commerce company is migrating its monolithic application to a microservices architecture. Each microservice has its own independent CI/CD pipeline using AWS CodePipeline. The company wants to ensure that all microservices consuming a particular shared library always use the latest compatible version of that library, and that updates to the shared library automatically trigger a rebuild and retest of all dependent microservices. How can they implement this dependency management and automated triggering using AWS services?SDLC Automation
- 163.A large enterprise has a complex application composed of hundreds of microservices. Each microservice has its own Git repository and CI/CD pipeline using AWS CodePipeline. The security team requires that all container images built by these pipelines undergo automated vulnerability scanning before deployment to Amazon EKS. Where should this scanning be integrated into the CI/CD pipeline to ensure compliance and prevent vulnerable images from reaching production?SDLC Automation
- 164.A DevOps team manages a critical application with a complex release process. They use AWS CodePipeline and need to perform a series of custom actions, such as running proprietary security scans and updating external configuration management databases, between the 'Test' and 'Deploy' stages. These actions require specific tools and environments not available in standard CodeBuild images. How can they integrate these custom actions efficiently into their CodePipeline?SDLC Automation
- 165.A DevOps team is adopting a trunk-based development model with frequent, small commits to the main branch. Their current CI/CD pipeline runs a comprehensive suite of unit, integration, and end-to-end tests sequentially, taking over 45 minutes to complete. This long feedback loop is hindering developer productivity. How can they reduce the total execution time of their test suite without sacrificing test coverage?SDLC Automation
- 166.A company is migrating its monolithic application to a microservices architecture on AWS. They want to ensure that each microservice's CI/CD pipeline automatically builds, tests, and deploys changes when code is committed to its respective Git repository. The solution must be fully automated, scalable, and provide clear visibility into the pipeline's status. Which AWS services should be combined to achieve this?SDLC Automation
- 167.A global e-commerce company uses multiple AWS accounts (development, staging, production) and regions. They need to manage common application dependencies, such as internal libraries and third-party packages, consistently across all environments. Developers should be able to securely retrieve these dependencies without manual configuration. Which AWS service is best suited for this requirement?SDLC Automation
- 168.A software company uses AWS CodeBuild for its CI/CD pipelines. Developers frequently commit small changes, leading to many builds. They've noticed that builds are taking longer than desired due to repeated downloads of dependencies and recompilation of unchanged code. How can the team optimize CodeBuild performance and reduce build times?SDLC Automation
- 169.A company is using AWS CodePipeline for its CI/CD workflow. They need to ensure that every deployment to the production environment requires explicit approval from a senior engineer before proceeding. The approval process should be integrated directly into the pipeline and prevent automated progression without human intervention. How can this be implemented using native AWS services?SDLC Automation
- 170.A development team is deploying a new web application using AWS CodeDeploy. They want to minimize downtime during deployments and be able to quickly revert to the previous version if issues arise. The application runs on Amazon EC2 instances behind an Application Load Balancer (ALB). Which CodeDeploy deployment type and traffic routing configuration should the team choose?SDLC Automation
- 171.A company is developing a serverless application using AWS Lambda and Amazon API Gateway. They need to ensure that their CI/CD pipeline automatically includes security scans for common vulnerabilities in their Lambda function code before deployment. The scans should be fast and integrate seamlessly into their build process. Which security testing approach is most suitable for this requirement?SDLC Automation
- 172.A company is developing a critical web application and needs to integrate security testing early in the development lifecycle. They want to identify potential vulnerabilities in their custom code, such as SQL injection, cross-site scripting (XSS), and insecure direct object references, before the code is even deployed or run. Which type of security testing should be integrated into their CI/CD pipeline for this purpose?SDLC Automation
- 173.A media company is using AWS Elemental MediaConvert to process video files. They want to automate the entire workflow, from video upload to processing and notification. When a new video file is uploaded to an S3 bucket, it should trigger a MediaConvert job, and upon job completion (success or failure), a notification should be sent to a Slack channel. Which AWS services should be used to build this event-driven automation pipeline?SDLC Automation
- 174.A global e-commerce company uses multiple AWS accounts (development, staging, production) for its microservices architecture. They need to manage application dependencies, including private libraries and third-party packages, consistently across all accounts and environments. They also want to ensure that developers only use approved versions of these dependencies. Which AWS service should they use to centralize and control their application dependencies?SDLC Automation
- 175.A development team is using AWS CodePipeline to automate their software releases. They have a stage that deploys an application to an Amazon EC2 Auto Scaling group. The team wants to ensure that new deployments are only considered successful if the application passes a suite of health checks and is serving traffic correctly before terminating old instances. Which deployment strategy should they implement to achieve this with minimal downtime and automatic rollback capabilities?SDLC Automation
- 176.A company wants to introduce security scanning into their CI/CD pipeline for a Java application. They need to analyze their source code for common vulnerabilities and coding flaws before the build stage. The scan should be automated and provide actionable feedback to developers. Which type of security testing should be integrated into the pipeline at this early stage?SDLC Automation
- 177.A software company uses AWS CodeBuild for its CI/CD pipelines. Developers frequently commit small changes, and build times are becoming a bottleneck due to repeated downloading of dependencies and recompilation of unchanged code. Which CodeBuild feature can significantly reduce build times in this scenario?SDLC Automation
- 178.A large enterprise is migrating its legacy applications to AWS. They need a standardized and repeatable way to provision and manage their infrastructure across multiple AWS accounts and regions. The solution must support version control, prevent configuration drift, and integrate with their existing CI/CD pipelines. Which AWS service or approach should they adopt?SDLC Automation
- 179.A company is developing a serverless application using AWS Lambda and Amazon API Gateway. They want to implement automated integration tests as part of their CI/CD pipeline. These tests should be run against a deployed, but pre-production, version of the application before promoting it to production. Which AWS service or feature is best suited to manage and orchestrate these integration tests within a CodePipeline workflow?SDLC Automation
- 180.A development team is using AWS CodePipeline for their CI/CD workflow. They need to ensure that their application's dependencies (e.g., npm packages, Maven artifacts) are automatically kept up-to-date with the latest security patches and minor version releases without manual intervention. This process should also trigger a new pipeline execution to validate the updated dependencies. Which approach should they use?SDLC Automation
- 181.A global software company is developing a new SaaS product that will be deployed across multiple AWS regions. They need to ensure that their database schema changes are applied consistently and safely across all environments (development, staging, production) and regions as part of their CI/CD pipeline. The solution must support rollbacks and prevent unauthorized or inconsistent schema modifications. Which approach should the DevOps team implement?SDLC Automation
- 182.A global e-commerce company uses AWS CloudFormation StackSets to deploy foundational infrastructure (e.g., VPCs, IAM roles) across hundreds of AWS accounts and multiple AWS Regions. The security team recently updated an IAM policy that needs to be reflected in all existing StackSet instances. The company requires a way to update these StackSet instances without causing downtime to the production applications running in those accounts. Which approach should the DevOps team take?Configuration Management and Infrastructure as Code
- 183.A financial services company is deploying a new critical application to AWS. They use AWS CloudFormation to manage their infrastructure. The security team has mandated that certain core resources, such as the production database and critical IAM roles, must not be accidentally deleted or updated without explicit, controlled processes. How can the DevOps team best implement this requirement using CloudFormation?Configuration Management and Infrastructure as Code
- 184.A DevOps team is managing an application that runs on Amazon EC2 instances. They use AWS Systems Manager State Manager to ensure consistent configuration across their fleet. A recent security audit requires that all EC2 instances must have a specific anti-malware agent installed and running, and its configuration file checked daily for compliance. How can the team achieve this using AWS Systems Manager?Configuration Management and Infrastructure as Code
- 185.A global e-commerce company uses AWS Lambda functions for its serverless backend. During peak shopping seasons, the application experiences intermittent performance degradation, but the root cause is difficult to pinpoint due to the distributed nature of the microservices. The DevOps team needs a solution to aggregate logs, metrics, and traces from all Lambda functions and related services to quickly identify bottlenecks and errors. Which AWS service is best suited to meet these requirements?Incident and Event Response
- 186.A large enterprise is adopting a multi-account strategy with a centralized security team responsible for defining and enforcing approved AWS resources and configurations. Development teams across various business units need to provision infrastructure frequently, but only using pre-approved, compliant CloudFormation templates. They also require a self-service portal where developers can provision these resources without needing direct IAM permissions to create underlying AWS services. Which AWS service is best suited to meet these requirements?Configuration Management and Infrastructure as Code
- 187.A development team is implementing a new microservice architecture on AWS. Each microservice needs its own AWS Lambda function, and these functions require specific, fine-grained access permissions to other AWS services (e.g., S3, DynamoDB, SQS). The team uses AWS Serverless Application Model (AWS SAM) to define their serverless applications. They want to define the IAM policies for each Lambda function directly within their SAM templates, ensuring that permissions are automatically deployed and updated with the function, adhering to the principle of least privilege. Which SAM template property should they use to achieve this?Configuration Management and Infrastructure as Code
- 188.A DevOps team manages a critical microservices application deployed on Amazon EKS. They need to ensure that if any pod in a specific deployment fails its readiness probe or becomes unhealthy, it is automatically replaced with a new, healthy pod to maintain application availability. The team wants to leverage native Kubernetes features for this self-healing capability. Which Kubernetes component is primarily responsible for ensuring the desired number of healthy pods are running for a deployment?Incident and Event Response
- 189.A DevOps team is managing a critical application that runs on Amazon EC2 instances. They use AWS Systems Manager (SSM) State Manager to enforce a baseline configuration, including installing specific agents and hardening settings. Recently, a new security patch for the operating system was released, and the team needs to apply it to all instances immediately. They want to use SSM for this, but also ensure that the patch application process is carefully controlled and does not conflict with the existing State Manager associations. Which SSM capability should they use for this ad-hoc, controlled patching without altering the State Manager baseline?Configuration Management and Infrastructure as Code
- 190.A development team is deploying a new microservice to AWS using AWS CloudFormation. They need to ensure that the Amazon S3 bucket used by the microservice is created with specific encryption settings and access policies to comply with corporate security standards. The team wants to prevent any manual changes to these critical S3 bucket properties once the stack is deployed. Which CloudFormation feature should they use to achieve this?Configuration Management and Infrastructure as Code
- 191.A startup is rapidly expanding its application on AWS and frequently deploys new features that require updates to existing Amazon EC2 Auto Scaling groups. They need a deployment strategy that minimizes downtime and allows for quick rollback in case of issues. The current deployment process uses AWS CloudFormation to manage the Auto Scaling group. They are considering a blue/green deployment strategy. Which CloudFormation resource type, when combined with AWS CodeDeploy, would best facilitate this strategy for their EC2 Auto Scaling groups?Configuration Management and Infrastructure as Code
- 192.A financial institution uses AWS Organizations to manage multiple accounts, with strict security and compliance requirements. They need to ensure that all critical S3 buckets across all accounts have encryption enabled by default and are not publicly accessible. If a new S3 bucket is created without these settings, it must be automatically remediated. Which combination of AWS services should the DevOps team implement to achieve this? (Select TWO correct answers, but only one option combines the two correct services.)Incident and Event Response
- 193.A financial institution is implementing a new CI/CD pipeline for its critical applications. The security team mandates that all code changes must undergo static application security testing (SAST) before being deployed to production. The pipeline uses AWS CodeCommit for source control, AWS CodeBuild for building, and AWS CodeDeploy for deployment. How can the DevOps team integrate SAST into this pipeline to meet the security requirement?Security and Compliance
- 194.A media company uses Amazon S3 to store large volumes of user-uploaded video content. They need to implement an automated workflow to process these videos (e.g., transcoding, thumbnail generation) as soon as they are uploaded to a specific S3 bucket. The processing should be serverless and scale automatically with the upload volume. Which AWS service combination is most appropriate for initiating this event-driven workflow?Incident and Event Response
- 195.A DevOps team is deploying a new containerized application to Amazon ECS. The application needs to securely fetch sensitive configuration parameters and credentials at runtime without embedding them directly into the container images or environment variables. The team wants to ensure that these secrets are retrieved from a centralized, secure store and are only accessible by authorized tasks. Which AWS service should the team use to store and retrieve these secrets?Security and Compliance
- 196.A large enterprise uses a multi-account strategy with AWS Organizations. They need to ensure that specific security groups, which only allow inbound SSH (port 22) and RDP (port 3389) from a restricted corporate IP range, are never modified to allow wider access. Any attempt to change these security groups to permit access from '0.0.0.0/0' must be explicitly denied, even by root users, and an alert must be sent to the security team. Which AWS Organizations feature can enforce this preventative control?Incident and Event Response
- 197.A large enterprise uses AWS Organizations to manage multiple AWS accounts. The security team wants to ensure that specific compliance requirements are met across all member accounts. Specifically, they need to prevent any IAM user or role in any account from creating S3 buckets that are publicly accessible. What is the most effective way to enforce this policy across all accounts in the organization?Security and Compliance
- 198.A global e-commerce company uses AWS CloudFormation StackSets to deploy foundational infrastructure (e.g., VPCs, IAM roles) across hundreds of AWS accounts and multiple AWS Regions. The security team has identified a critical vulnerability in a specific IAM policy attached to a role deployed by a StackSet. They need to update this IAM policy across all existing StackSet instances immediately without affecting other resources within the StackSet, and ensure that new deployments also receive the corrected policy. What is the most efficient and safest way to achieve this?Configuration Management and Infrastructure as Code
- 199.A DevOps team needs to implement a solution for collecting forensic data from Amazon EC2 instances immediately after a security incident is detected. The solution must be automated, non-intrusive, and capable of collecting memory dumps, disk images, and process lists without manual login to the compromised instance. The collected data should be stored securely for later analysis. Which AWS service or feature is best suited for this task?Incident and Event Response
- 200.A media streaming company uses Amazon EC2 instances to transcode video files. These instances are part of an Auto Scaling group. The transcoding jobs are published to an Amazon SQS queue, and the EC2 instances pull messages from this queue. The company observes that during peak hours, the queue backlog grows rapidly, leading to increased processing latency. During off-peak hours, many instances are idle, leading to unnecessary costs. The company needs a solution that automatically scales the EC2 instances based on the number of messages in the SQS queue to optimize costs and maintain low processing latency. Which Auto Scaling policy type should be configured?Resilient Cloud Solutions