Step2Study
IT & TechnologyDOP-C02100% Free

AWS Certified DevOps Engineer – Professional

Practice bank
209 Qs
Real exam
75 Qs
Time limit
180 min
Passing
Scaled score of 750 out of 1,000

Exam blueprint

SDLC Automation
22%
Configuration Management and Infrastructure as Code
19%
Resilient Cloud Solutions
18%
Monitoring and Logging
17%
Incident and Event Response
14%
Security and Compliance
10%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 216 min · pass 75% · 209 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Study with friends

Challenge a friend to beat your score.

AWS Certified DevOps Engineer – Professional practice test questions

Sample questions from the 209-question bank, with answers and explanations.

All questions
  1. 1. A company is migrating a critical application to AWS Lambda functions and Amazon API Gateway. They need to implement distributed tracing to monitor the performance of individual Lambda invocations and their interactions with downstream services, such as Amazon DynamoDB and external APIs. The solution should provide a visual service map and detailed trace data to identify latency bottlenecks. The developers want to minimize manual instrumentation. Which approach should be used?

    Monitoring and Logging

    • A. Enable CloudWatch Logs for Lambda and API Gateway, and use CloudWatch Logs Insights to analyze invocation durations.
    • B. Configure API Gateway to enable X-Ray tracing and enable active tracing for Lambda functions.
    • C. Instrument each Lambda function with custom code to send trace data to an external OpenTelemetry collector.
    • D. Deploy custom metrics to CloudWatch using the Embedded Metric Format (EMF) for each Lambda function and DynamoDB table.
    Show answer

    B. Configure API Gateway to enable X-Ray tracing and enable active tracing for Lambda functions.

    AWS X-Ray is purpose-built for distributed tracing across serverless and microservices architectures. By enabling X-Ray tracing directly on API Gateway and setting Lambda functions to 'active tracing,' X-Ray automatically captures trace data, generates a service map, and provides detailed timing information for each segment, including calls to downstream AWS services like DynamoDB, with minimal manual instrumentation.

  2. 2. A software development company uses AWS CodeBuild for its continuous integration pipeline. They want to receive real-time notifications in their Slack channel whenever a build fails or succeeds, including details about the build status and a link to the build logs. The solution must be simple to configure and require minimal custom code. Which AWS service should they use?

    Monitoring and Logging

    • A. Create a custom webhook in CodeBuild to send build status updates directly to Slack.
    • B. Use AWS Chatbot to integrate AWS CodeBuild notifications directly with their Slack workspace.
    • C. Configure an Amazon CloudWatch Event Rule to detect CodeBuild state changes and trigger an AWS Lambda function to send a Slack message.
    • D. Set up an Amazon SNS topic for CodeBuild events and subscribe the Slack channel to the SNS topic.
    Show answer

    B. Use AWS Chatbot to integrate AWS CodeBuild notifications directly with their Slack workspace.

    AWS Chatbot is designed to integrate AWS services with chat platforms like Slack or Amazon Chime. It can be configured to receive notifications from AWS services (including CodeBuild via Amazon EventBridge) and relay them directly to a Slack channel with rich formatting and links, requiring minimal configuration and no custom code, making it the ideal solution for this scenario.

  3. 3. A media company uses AWS Step Functions to orchestrate complex video processing workflows. They need to analyze the execution history of these workflows, identify states with high latency, and visualize the overall flow to optimize performance and troubleshoot failures. The solution should provide detailed insights into individual step executions and transitions.

    Monitoring and Logging

    • A. Build custom metrics in CloudWatch based on Step Functions events and create a CloudWatch dashboard.
    • B. Enable Step Functions logging to CloudWatch Logs and use CloudWatch Logs Insights to query execution data.
    • C. Configure Step Functions to send execution events to Amazon Kinesis Data Firehose and then to Amazon Redshift for analysis.
    • D. Use AWS X-Ray to trace Step Functions workflow executions and visualize the service map and timeline.
    Show answer

    D. Use AWS X-Ray to trace Step Functions workflow executions and visualize the service map and timeline.

    AWS X-Ray seamlessly integrates with AWS Step Functions to provide end-to-end tracing of workflow executions. It visualizes the entire workflow as a service map, shows the latency of each state and transition, and allows drilling down into individual step executions, which is crucial for identifying bottlenecks and troubleshooting complex workflows.

  4. 4. A financial services company is migrating its legacy monolithic application to a microservices architecture on AWS. They require a robust solution for collecting and analyzing highly sensitive audit logs from all microservices, which are deployed as Docker containers on Amazon ECS. The solution must ensure data encryption at rest and in transit, support long-term retention for 7 years, and provide granular access controls over who can view specific log data. Performance and scalability are critical due to high log volumes. Which combination of AWS services is the most appropriate for these requirements?

    Monitoring and Logging

    • A. Utilize Amazon Kinesis Data Firehose for ingestion, Amazon S3 for long-term storage with SSE-KMS, and Amazon OpenSearch Service (with fine-grained access control) for real-time analysis.
    • B. Amazon CloudWatch Logs for collection and storage, with KMS encryption and IAM policies for access control. Use CloudWatch Logs Insights for analysis.
    • C. Configure AWS CloudTrail to capture all API calls, store them in Amazon S3 with SSE-KMS, and use Amazon GuardDuty for anomaly detection.
    • D. Implement a custom Fluentd agent on each ECS container to send logs directly to Amazon S3 with server-side encryption, and use Amazon Athena for querying.
    Show answer

    A. Utilize Amazon Kinesis Data Firehose for ingestion, Amazon S3 for long-term storage with SSE-KMS, and Amazon OpenSearch Service (with fine-grained access control) for real-time analysis.

    This solution provides a comprehensive, scalable, and secure logging pipeline. Kinesis Data Firehose efficiently ingests high volumes of log data. OpenSearch Service offers powerful real-time analysis, search, dashboards, and crucial fine-grained access control for sensitive data. S3 with SSE-KMS ensures encrypted, durable, and cost-effective long-term retention for 7 years. Data in transit is secured via Firehose and OpenSearch's HTTPS endpoints. This meets all requirements for encryption, retention, granular access, performance, and scalability for sensitive audit logs.

  5. 5. A financial services company uses AWS Lambda functions for processing sensitive customer data. Due to strict compliance requirements, all invocations of these Lambda functions must be logged, and the logs must be retained for seven years in an immutable state. The solution must also allow for centralized access and analysis by authorized personnel while minimizing operational overhead.

    Monitoring and Logging

    • A. Configure Lambda functions to send logs to CloudWatch Logs, create a subscription filter to stream logs to an S3 bucket, and enable S3 object lock.
    • B. Use CloudWatch Logs with a custom retention policy of seven years and configure IAM policies for centralized access.
    • C. Configure Lambda functions to send logs to Amazon S3 directly, then enable S3 object lock for immutability and lifecycle policies for retention.
    • D. Enable AWS CloudTrail data events for Lambda, configure CloudTrail to deliver logs to an S3 bucket with S3 object lock, and use Athena for analysis.
    Show answer

    D. Enable AWS CloudTrail data events for Lambda, configure CloudTrail to deliver logs to an S3 bucket with S3 object lock, and use Athena for analysis.

    AWS CloudTrail data events capture API calls and resource activities, including Lambda function invocations. Delivering these logs to an S3 bucket with S3 Object Lock ensures immutability and long-term retention for compliance. Amazon Athena can then be used for efficient, centralized analysis of these logs without operational overhead.

  6. 6. A company is migrating its on-premises applications to AWS. They have a hybrid environment where some applications will remain on-premises, and others will move to Amazon EC2. The security team requires a centralized logging solution for both on-premises application logs (Apache, Nginx, custom app logs) and EC2 instance logs, with real-time alerting capabilities. The solution must minimize operational overhead. Which approach should the DevOps team take?

    Monitoring and Logging

    • A. Configure AWS CloudTrail to capture API calls from on-premises applications and EC2 instances, sending them to CloudWatch Logs.
    • B. Use AWS Kinesis Data Firehose to ingest logs from on-premises and EC2 instances, then stream them to Amazon S3 for archival.
    • C. Deploy the CloudWatch Agent to all on-premises servers and EC2 instances, configuring it to send logs to Amazon CloudWatch Logs.
    • D. Install a custom Fluentd agent on all on-premises and EC2 instances to send logs to a self-managed Amazon OpenSearch Service cluster.
    Show answer

    C. Deploy the CloudWatch Agent to all on-premises servers and EC2 instances, configuring it to send logs to Amazon CloudWatch Logs.

    The CloudWatch Agent is specifically designed for collecting logs and metrics from both Amazon EC2 instances and on-premises servers. By deploying and configuring it on all instances, logs from both environments can be centrally sent to Amazon CloudWatch Logs. CloudWatch Logs provides real-time alerting, log analytics (Logs Insights), and minimizes operational overhead by being a fully managed service, directly addressing all requirements.

  7. 7. A media streaming company uses Amazon CloudFront to deliver content globally. They need to analyze user behavior, content popularity, and identify potential bot activity by examining access logs. The volume of logs is extremely high, and the analysis needs to be performed ad-hoc using standard SQL queries without provisioning or managing any servers. Which solution should they choose?

    Monitoring and Logging

    • A. Stream CloudFront access logs to Amazon Kinesis Data Firehose and then to Amazon OpenSearch Service for analysis.
    • B. Enable CloudFront access logs to an S3 bucket and use Amazon Athena to query the logs.
    • C. Use AWS WAF to block malicious traffic and analyze its logs with AWS CloudTrail.
    • D. Configure CloudFront to send access logs to Amazon CloudWatch Logs and use CloudWatch Logs Insights.
    Show answer

    B. Enable CloudFront access logs to an S3 bucket and use Amazon Athena to query the logs.

    Enabling CloudFront access logs to an S3 bucket is the standard way to store these logs. Amazon Athena is a serverless query service that allows running standard SQL queries directly on data stored in S3, making it ideal for ad-hoc analysis of large volumes of CloudFront logs without managing any infrastructure. This solution is cost-effective and meets the requirements for SQL-based ad-hoc analysis.

  8. 8. A DevOps team requires a comprehensive monitoring solution for their containerized application running on Amazon EKS. They need to collect metrics at the node, pod, and container level, analyze application logs, and visualize the health and performance of their Kubernetes cluster. The solution should be scalable, cost-effective, and provide deep insights into the EKS environment. Which combination of AWS services and open-source tools is most suitable?

    Monitoring and Logging

    • A. Utilize Amazon CloudWatch Container Insights for metrics and logs, and Amazon Managed Service for Prometheus (AMP) for Prometheus-compatible metrics.
    • B. Use Amazon CloudWatch Logs for all logs, and deploy a self-managed Prometheus and Grafana stack outside the EKS cluster for metrics.
    • C. Implement AWS Distro for OpenTelemetry (ADOT) with Prometheus receiver for metrics and OTLP exporter for logs to CloudWatch Logs.
    • D. Deploy Prometheus and Grafana on an EC2 instance within the EKS cluster for metrics, and use Fluentd to send logs to CloudWatch Logs.
    Show answer

    A. Utilize Amazon CloudWatch Container Insights for metrics and logs, and Amazon Managed Service for Prometheus (AMP) for Prometheus-compatible metrics.

    Amazon CloudWatch Container Insights is specifically designed for monitoring containerized applications, providing automated collection and aggregation of metrics and logs at the cluster, node, pod, and container levels for EKS. Integrating with Amazon Managed Service for Prometheus (AMP) allows for collecting Prometheus-compatible metrics at scale without managing the Prometheus infrastructure, offering a comprehensive, scalable, and cost-effective solution for EKS monitoring.

  9. 9. A DevOps team is responsible for a mission-critical microservices application deployed on Amazon EKS. They need to gain deep insights into the performance and health of their Kubernetes clusters, including node, pod, and container-level metrics, and also collect application logs. The solution must provide a single pane of glass for monitoring and allow for historical analysis. How should the team implement this monitoring solution?

    Monitoring and Logging

    • A. Configure Prometheus and Grafana on a separate EC2 instance to scrape metrics from EKS and visualize them.
    • B. Use AWS X-Ray to trace requests across the microservices and capture pod-level metrics.
    • C. Enable CloudWatch Container Insights for the EKS cluster to automatically collect, aggregate, and summarize metrics and logs.
    • D. Deploy the CloudWatch Agent to each EC2 instance in the EKS cluster to send system metrics and logs to CloudWatch.
    Show answer

    C. Enable CloudWatch Container Insights for the EKS cluster to automatically collect, aggregate, and summarize metrics and logs.

    CloudWatch Container Insights is specifically designed for monitoring containerized applications, including Amazon EKS. It automatically collects, aggregates, and summarizes metrics and logs from clusters, nodes, pods, and containers, providing a 'single pane of glass' experience with pre-built dashboards and enabling historical analysis. This directly addresses the requirement for deep insights into EKS performance and health.

  10. 10. A DevOps team is developing a new serverless application using AWS Lambda functions. They need to collect custom application metrics, such as the number of successful order placements and the duration of specific business transactions, directly from their Lambda functions. These metrics should be available in CloudWatch for dashboarding and alarming, and the developers want to achieve this with minimal code complexity and overhead. Which method is most efficient for publishing these custom metrics?

    Monitoring and Logging

    • A. Deploy a custom Prometheus node exporter within the Lambda environment to push metrics to Amazon Managed Service for Prometheus (AMP).
    • B. Send custom metrics as log events to CloudWatch Logs and then create CloudWatch Log Metric Filters.
    • C. Use the CloudWatch PutMetricData API call directly within the Lambda function code for each metric.
    • D. Employ the CloudWatch Embedded Metric Format (EMF) to publish structured log events from Lambda.
    Show answer

    D. Employ the CloudWatch Embedded Metric Format (EMF) to publish structured log events from Lambda.

    The CloudWatch Embedded Metric Format (EMF) is specifically designed for publishing custom metrics from serverless applications with minimal overhead. Developers can embed metric data within structured log events, and CloudWatch automatically extracts and ingests these metrics without requiring explicit PutMetricData API calls for each metric, reducing code complexity and improving efficiency compared to direct API calls or log metric filters for multiple metrics.

  11. 11. A security team needs to monitor access to sensitive data stored in Amazon S3 buckets. They require real-time alerts for specific access patterns, such as an unusual number of 'GetObject' requests from an unapproved IP range, or a 'DeleteObject' operation on a critical bucket. The solution must be highly available and integrate with existing security operations tools.

    Monitoring and Logging

    • A. Enable S3 server access logging, deliver logs to a separate S3 bucket, and use AWS Lambda functions to analyze logs and send alerts.
    • B. Configure CloudTrail data events for S3, send logs to CloudWatch Logs, and create CloudWatch Alarms based on metric filters for specific events.
    • C. Use Amazon Macie to detect sensitive data and automatically generate alerts for unusual access patterns.
    • D. Integrate S3 with AWS Security Hub to aggregate findings and trigger alerts for suspicious activities.
    Show answer

    B. Configure CloudTrail data events for S3, send logs to CloudWatch Logs, and create CloudWatch Alarms based on metric filters for specific events.

    CloudTrail data events capture S3 object-level API actions (like GetObject, DeleteObject). Sending these to CloudWatch Logs allows for real-time analysis using metric filters to identify specific patterns (e.g., source IP, event name). CloudWatch Alarms can then trigger immediate notifications, fulfilling the real-time alerting requirement and integrating with existing tools via SNS.

  12. 12. A DevOps team wants to implement a robust log archival strategy for compliance requirements. They need to store application logs from various EC2 instances for 10 years in the most cost-effective manner. The logs are initially collected by the CloudWatch Agent and sent to CloudWatch Logs. After a short period (e.g., 30 days) for immediate operational analysis, the logs should be moved to long-term, immutable storage. Which solution provides the most cost-effective and compliant archival?

    Monitoring and Logging

    • A. Set a CloudWatch Logs retention policy for 10 years.
    • B. Create a CloudWatch Logs subscription filter to stream logs to Amazon Kinesis Data Firehose, which delivers them to Amazon S3 Glacier Deep Archive.
    • C. Set a CloudWatch Logs retention policy for 30 days and configure a lifecycle policy on the CloudWatch Logs log group to automatically transition older logs to S3 Intelligent-Tiering.
    • D. Configure a CloudWatch Logs export task to regularly move logs to an Amazon S3 bucket with a lifecycle policy to transition to S3 Glacier Deep Archive.
    Show answer

    D. Configure a CloudWatch Logs export task to regularly move logs to an Amazon S3 bucket with a lifecycle policy to transition to S3 Glacier Deep Archive.

    To achieve cost-effective, long-term (10 years) immutable archival, logs should be moved from CloudWatch Logs to Amazon S3, and then transitioned to Amazon S3 Glacier Deep Archive. CloudWatch Logs export tasks (or subscription filters to Kinesis Firehose) are mechanisms to move logs out of CloudWatch Logs. An S3 lifecycle policy then automates the transition to S3 Glacier Deep Archive, which is the most cost-effective storage class for data accessed rarely over very long periods, satisfying the 10-year retention and cost-effectiveness requirements.

  13. 13. A global e-commerce company uses AWS Lambda functions for its serverless backend. They need to monitor the performance and errors of these functions, including invocation counts, errors, duration, and throttles, to identify and troubleshoot issues quickly. The solution should provide pre-built dashboards and allow for custom alarms. Which AWS service is best suited for this requirement?

    Monitoring and Logging

    • A. AWS CloudTrail
    • B. AWS X-Ray
    • C. Amazon CloudWatch
    • D. Amazon S3
    Show answer

    C. Amazon CloudWatch

    Amazon CloudWatch automatically collects and displays metrics for AWS Lambda functions, including invocation counts, errors, duration, and throttles. It provides pre-built dashboards and allows users to create custom alarms based on these metrics, meeting all the specified requirements for monitoring Lambda performance and errors.

  14. 14. A DevOps team manages a high-traffic web application where performance is critical. They need to analyze user request patterns, identify performance bottlenecks, and detect anomalies in real-time. The application uses Amazon API Gateway, AWS Lambda, and Amazon DynamoDB. The solution must provide end-to-end visibility of requests and automatically identify deviations from normal behavior. Which combination of AWS services should the team implement?

    Monitoring and Logging

    • A. AWS X-Ray for distributed tracing, Amazon CloudWatch for metrics and logs, and CloudWatch Anomaly Detection.
    • B. AWS Budgets for cost monitoring, Amazon SNS for notifications, and AWS Step Functions for workflow orchestration.
    • C. AWS CloudTrail for API activity, Amazon S3 for log storage, and AWS Config for resource changes.
    • D. Amazon Kinesis Data Firehose for log ingestion, Amazon OpenSearch Service for log analysis, and AWS WAF for security.
    Show answer

    A. AWS X-Ray for distributed tracing, Amazon CloudWatch for metrics and logs, and CloudWatch Anomaly Detection.

    AWS X-Ray provides end-to-end visibility and distributed tracing for requests across API Gateway, Lambda, and DynamoDB, helping identify performance bottlenecks. Amazon CloudWatch collects metrics and logs from these services. CloudWatch Anomaly Detection automatically identifies deviations from normal patterns in metrics, fulfilling the requirement to detect anomalies in real-time. This combination provides comprehensive monitoring and anomaly detection for the described serverless application.

  15. 15. A company is migrating its on-premises applications to AWS. They have a requirement to centralize all application and system logs from both their existing on-premises servers and new Amazon EC2 instances into a single AWS service for unified monitoring and analysis. The solution must support real-time ingestion and querying capabilities.

    Monitoring and Logging

    • A. Send on-premises logs to an S3 bucket and EC2 logs to CloudWatch Logs, then use Amazon Athena to query all logs.
    • B. Deploy a custom Fluentd/Fluent Bit cluster on-premises and within AWS to collect logs and forward them to Amazon OpenSearch Service.
    • C. Install the CloudWatch agent on both on-premises servers and EC2 instances to send logs to CloudWatch Logs, then use CloudWatch Logs Insights for querying.
    • D. Use AWS DataSync to transfer on-premises logs to Amazon EFS, and configure EC2 instances to write logs directly to EFS.
    Show answer

    C. Install the CloudWatch agent on both on-premises servers and EC2 instances to send logs to CloudWatch Logs, then use CloudWatch Logs Insights for querying.

    The CloudWatch agent is specifically designed to collect logs and metrics from both on-premises servers and EC2 instances and send them to CloudWatch Logs. CloudWatch Logs provides real-time ingestion, and CloudWatch Logs Insights offers powerful, serverless querying capabilities across all centralized log data, fulfilling all requirements with a native AWS solution.

  16. 16. A development team has deployed a new microservices application on Amazon EKS. They observe intermittent latency spikes and errors, but traditional log analysis makes it difficult to pinpoint the root cause across distributed services. They need a solution to visualize the request flow end-to-end, identify bottlenecks, and understand service dependencies without extensively modifying their application code.

    Monitoring and Logging

    • A. Configure AWS App Mesh to automatically collect metrics and logs for inter-service communication.
    • B. Implement Amazon CloudWatch Container Insights to collect performance metrics and logs from the EKS cluster.
    • C. Enable AWS X-Ray tracing for the services running in EKS by deploying the X-Ray daemon as a sidecar.
    • D. Use Amazon CloudWatch Logs Insights to query and analyze application logs from all microservices.
    Show answer

    C. Enable AWS X-Ray tracing for the services running in EKS by deploying the X-Ray daemon as a sidecar.

    AWS X-Ray is designed for end-to-end tracing of requests as they traverse distributed applications. By deploying the X-Ray daemon as a sidecar in EKS, services can send trace data, allowing visualization of service maps, latency analysis, and identification of bottlenecks without significant code changes.

  17. 17. A global gaming company uses Amazon DynamoDB for storing user profiles. They need to monitor DynamoDB's performance in real-time, specifically tracking read/write capacity utilization, latency, and throttled requests. They also require automated alerts if these metrics exceed predefined thresholds. The solution must be cost-effective and provide granular visibility.

    Monitoring and Logging

    • A. Implement custom Lambda functions to periodically poll DynamoDB metrics via API and push them to CloudWatch.
    • B. Export DynamoDB streams to Amazon Kinesis Data Firehose and then to Amazon OpenSearch Service for real-time dashboards.
    • C. Enable DynamoDB Contributor Insights to identify frequently accessed or throttled partitions.
    • D. Use CloudWatch Alarms directly on DynamoDB's built-in metrics to monitor performance and send notifications.
    Show answer

    D. Use CloudWatch Alarms directly on DynamoDB's built-in metrics to monitor performance and send notifications.

    Amazon DynamoDB automatically sends a rich set of performance metrics (like ConsumedReadCapacityUnits, ThrottledRequests, SuccessfulRequestLatency) to Amazon CloudWatch by default. CloudWatch Alarms can be directly configured on these metrics to monitor thresholds and trigger alerts, providing real-time, granular, and cost-effective monitoring without additional services.

  18. 18. A company is looking to centralize monitoring for its hybrid cloud environment, which includes applications running on AWS EC2 instances and on-premises servers. They need to collect operating system metrics (CPU, memory, disk I/O) and application-specific metrics from both environments, and visualize them on a unified dashboard. The solution should be scalable and leverage existing AWS monitoring capabilities as much as possible. Which approach provides the most integrated and scalable solution?

    Monitoring and Logging

    • A. Install the CloudWatch Agent on all EC2 instances and on-premises servers to send metrics to Amazon CloudWatch, and create custom CloudWatch Dashboards.
    • B. Use AWS Systems Manager Agent for EC2 instances and a custom script for on-premises servers to push metrics to Amazon Kinesis Data Firehose, then to CloudWatch.
    • C. Set up a self-managed ELK stack (Elasticsearch, Logstash, Kibana) on EC2 instances to collect and visualize metrics from both environments.
    • D. Deploy custom Prometheus exporters on all servers (EC2 and on-premises) and use Amazon Managed Service for Prometheus (AMP) with Amazon Managed Grafana (AMG) for visualization.
    Show answer

    A. Install the CloudWatch Agent on all EC2 instances and on-premises servers to send metrics to Amazon CloudWatch, and create custom CloudWatch Dashboards.

    The CloudWatch Agent is designed to collect OS-level metrics and application metrics from both EC2 instances and on-premises servers, sending them directly to Amazon CloudWatch. This provides a unified data source for metrics across hybrid environments. CloudWatch Dashboards can then be used to visualize these metrics, leveraging existing AWS monitoring capabilities and offering a scalable, integrated solution without needing to manage additional open-source monitoring infrastructure.

  19. 19. A company uses AWS CodeBuild for its CI/CD pipeline. They want to ensure that all build failures trigger an immediate notification to a Slack channel, including details about the build project, status, and a link to the CodeBuild console for quick investigation. The solution must be highly available and require minimal custom code. Which approach should a DevOps engineer implement?

    Monitoring and Logging

    • A. Use AWS Chatbot to integrate CodeBuild notifications directly with Slack, configuring a CloudWatch Event Rule to filter for build failures.
    • B. Configure a CloudWatch Event Rule to detect CodeBuild state changes, target an SNS topic, and subscribe a Lambda function to format and send the message to Slack.
    • C. Enable CodeBuild notifications directly within the CodeBuild project settings, configuring an SNS topic as the target for build failure events and subscribing an HTTP endpoint to Slack.
    • D. Create a custom Python script running on an EC2 instance that polls CodeBuild project status every minute and sends a notification to Slack when a failure is detected.
    Show answer

    A. Use AWS Chatbot to integrate CodeBuild notifications directly with Slack, configuring a CloudWatch Event Rule to filter for build failures.

    AWS Chatbot provides direct integration with Slack and Amazon Chime for AWS service notifications. By configuring a CloudWatch Event Rule for CodeBuild state changes and targeting AWS Chatbot, build failure notifications can be sent to Slack with minimal configuration and no custom code.

  20. 20. A global e-commerce company uses Amazon CloudFront to distribute its web content. They need to monitor user behavior analytics, such as page views, unique visitors, and geographic distribution, for their marketing and product teams. The solution must be serverless, scalable, and enable ad-hoc querying of historical data without managing complex infrastructure.

    Monitoring and Logging

    • A. Enable CloudFront access logs, deliver them to an S3 bucket, and use Amazon Athena to query the logs.
    • B. Integrate CloudFront with AWS AppSync to capture client-side events and store them in Amazon DynamoDB for analysis.
    • C. Implement custom Lambda@Edge functions to capture user data and push it to Amazon Kinesis Data Firehose, then to Amazon Redshift.
    • D. Configure CloudFront to send real-time logs to CloudWatch Logs, then use CloudWatch Logs Insights for analysis.
    Show answer

    A. Enable CloudFront access logs, deliver them to an S3 bucket, and use Amazon Athena to query the logs.

    CloudFront access logs contain rich information about user requests, including IP addresses, user agents, and requested URLs. Delivering these logs to S3 is cost-effective for long-term storage, and Amazon Athena provides a serverless, scalable way to perform ad-hoc SQL queries directly against the S3 data, perfectly fitting the requirements for user behavior analytics.

  21. 21. A large enterprise uses AWS Organizations to manage hundreds of AWS accounts. They need to ensure that all security-related logs, such as VPC Flow Logs, DNS query logs (Route 53 Resolver query logs), and AWS WAF logs, are centrally collected, retained for 7 years, and made immediately searchable for incident response and forensic analysis. The solution must be cost-effective and scalable to petabytes of data without operational overhead. Which architecture should the DevOps team implement?

    Monitoring and Logging

    • A. Configure each log source to send logs directly to Amazon S3, then use AWS Glue and Amazon Athena for querying.
    • B. Send all logs to Amazon CloudWatch Logs, configure cross-account log subscription filters to stream to a central Lambda function, and then write to a custom log analysis platform.
    • C. Stream all logs from their respective sources (VPC Flow Logs, Route 53, WAF) to Amazon Kinesis Data Firehose, which then delivers them to a central Amazon OpenSearch Service domain.
    • D. Enable AWS CloudTrail organization trail to a central S3 bucket and use CloudWatch Logs Insights for analysis.
    Show answer

    C. Stream all logs from their respective sources (VPC Flow Logs, Route 53, WAF) to Amazon Kinesis Data Firehose, which then delivers them to a central Amazon OpenSearch Service domain.

    This scenario requires centralized collection, petabyte-scale searchability, long-term retention, and minimal operational overhead. Streaming logs via Kinesis Data Firehose (a fully managed service) to a central Amazon OpenSearch Service domain (also managed) directly addresses these needs. OpenSearch Service provides immediate searchability and analysis capabilities for petabytes of data, Firehose handles ingestion and delivery, and data can be tiered to S3 within OpenSearch for cost-effective long-term retention. This architecture minimizes operational overhead while providing powerful analytics.

  22. 22. A financial services company needs to ensure that all administrative activities and API calls across their AWS accounts are logged and immutable for auditing and compliance purposes. They also require a centralized view of these logs across multiple accounts. What is the most effective and compliant solution?

    Monitoring and Logging

    • A. Use CloudWatch Logs to collect all application logs and configure cross-account log sharing.
    • B. Deploy a custom logging agent on all EC2 instances to send system logs to a central Elasticsearch cluster.
    • C. Configure S3 server access logging for all S3 buckets storing application data.
    • D. Enable AWS CloudTrail in each account, configure an organization trail, and deliver logs to a central S3 bucket in a logging account.
    Show answer

    D. Enable AWS CloudTrail in each account, configure an organization trail, and deliver logs to a central S3 bucket in a logging account.

    AWS CloudTrail is the primary service for auditing AWS API calls and administrative activities. By enabling an organization trail in AWS Organizations, all management events and optionally data events across all member accounts are automatically logged to a specified central S3 bucket. This ensures immutability (via S3 versioning and WORM policies) and provides a centralized, compliant view for auditing.

  23. 23. A DevOps team manages a critical application running on Amazon EC2 instances. They need to collect detailed system-level metrics, such as memory utilization and disk I/O, that are not available by default in Amazon CloudWatch. The solution must be cost-effective and integrate seamlessly with existing CloudWatch dashboards and alarms. Which AWS service or tool should the team use to meet these requirements?

    Monitoring and Logging

    • A. AWS Config
    • B. CloudWatch Agent
    • C. AWS CloudTrail
    • D. Amazon Inspector
    Show answer

    B. CloudWatch Agent

    The CloudWatch Agent is specifically designed to collect additional system-level metrics and logs from EC2 instances (and on-premises servers) which are not natively provided by CloudWatch. It integrates directly with CloudWatch, allowing for custom dashboards and alarms based on these collected metrics. This meets the requirements for detailed metrics, cost-effectiveness, and integration.

  24. 24. A DevOps team is deploying a new serverless application using AWS Lambda functions and Amazon API Gateway. They need to ensure that detailed performance metrics and trace data are collected for all invocations to monitor application health and troubleshoot issues. The solution must be easy to implement and minimize overhead for the Lambda functions.

    Monitoring and Logging

    • A. Enable AWS X-Ray active tracing for Lambda functions and API Gateway stages.
    • B. Enable CloudWatch Logs for Lambda and configure custom metrics using Embedded Metric Format (EMF).
    • C. Implement custom Python/Node.js scripts within each Lambda function to push metrics to CloudWatch and traces to a custom backend.
    • D. Use CloudWatch Container Insights to monitor the performance of Lambda functions.
    Show answer

    A. Enable AWS X-Ray active tracing for Lambda functions and API Gateway stages.

    AWS X-Ray active tracing for Lambda and API Gateway automatically collects detailed trace data, performance metrics, and service maps for each request. It provides end-to-end visibility across the serverless application, making it easy to identify bottlenecks and troubleshoot issues with minimal implementation effort.

  25. 25. A development team is deploying a new microservices application on AWS using Amazon ECS and AWS Fargate. They need a centralized logging solution that can collect logs from multiple containers, store them durably, and allow for real-time analysis and querying. The solution should also be cost-effective and require minimal operational overhead. Which AWS service combination best meets these requirements?

    Monitoring and Logging

    • A. Amazon CloudWatch Logs for log collection and storage, and Amazon CloudWatch Logs Insights for querying.
    • B. Amazon Kinesis Data Firehose for log ingestion, Amazon OpenSearch Service for indexing and analysis, and Amazon S3 for archival.
    • C. AWS Systems Manager Agent for log collection, Amazon SQS for buffering, and a self-managed ELK stack on EC2 for analysis.
    • D. Amazon S3 for log storage, AWS Lambda for processing, and Amazon Athena for querying.
    Show answer

    A. Amazon CloudWatch Logs for log collection and storage, and Amazon CloudWatch Logs Insights for querying.

    Amazon CloudWatch Logs provides a fully managed service for centralizing logs from various AWS services, including ECS/Fargate. CloudWatch Logs Insights offers a powerful, interactive query engine for real-time analysis without needing to manage additional infrastructure.

AWS Certified DevOps Engineer – Professional flashcards

Tap a card to flip it. 153 flashcards in the full deck.

  • AWS X-Ray Active Tracing (Lambda)

    Flip card

    A setting for AWS Lambda functions that automatically instruments the function and its calls to other AWS services, sending trace data to X-Ray without explicit SDK calls in the function code.

    • Automatically traces invocations and downstream AWS service calls.
    • Generates segments for each part of the execution.
    • Requires minimal configuration, not manual SDK instrumentation.
    Study this card →
  • AWS Chatbot for CodeBuild Notifications

    Flip card

    AWS Chatbot integrates AWS CodeBuild notifications (via EventBridge) into chat platforms like Slack, providing real-time build status updates with minimal configuration.

    • Integrates AWS services with Slack/Chime.
    • Provides rich, formatted notifications with links.
    • Requires minimal setup, no custom code.
    Study this card →
  • AWS X-Ray for Step Functions

    Flip card

    AWS X-Ray provides end-to-end tracing and visualization for AWS Step Functions workflow executions, helping to identify performance bottlenecks and troubleshoot failures.

    • Visualizes the entire workflow as a service map.
    • Shows latency for each state and transition.
    • Allows drilling down into individual step executions.
    Study this card →
  • Amazon OpenSearch Service (Fine-Grained Access Control)

    Flip card

    A managed service that makes it easy to deploy, operate, and scale OpenSearch clusters. Its fine-grained access control feature allows for highly specific permissions on indices, types, documents, and fields.

    • Provides search, analysis, and visualization capabilities.
    • Built on OpenSearch (formerly Elasticsearch).
    • Fine-grained access control is crucial for sensitive data.
    Study this card →
  • CloudTrail Data Events for Lambda

    Flip card

    AWS CloudTrail can record data events for Lambda functions, capturing details of function invocations as API calls, distinct from runtime logs.

    • Captures 'Invoke' API calls for Lambda functions.
    • Logs are delivered to an S3 bucket.
    • Essential for compliance and auditing of function usage.
    Study this card →
  • CloudWatch Agent for Hybrid Logging

    Flip card

    The CloudWatch Agent centralizes log collection from both on-premises servers and Amazon EC2 instances into Amazon CloudWatch Logs for unified monitoring and analysis.

    • Single agent for hybrid environments.
    • Collects application logs (Apache, Nginx, custom) and system logs.
    • Integrates with CloudWatch Logs for analysis, retention, and alerting.
    Study this card →
  • CloudFront Logs with Athena

    Flip card

    A serverless solution for analyzing large volumes of Amazon CloudFront access logs stored in S3 using standard SQL queries with Amazon Athena.

    • CloudFront logs are delivered to S3.
    • Athena queries data directly in S3, no data movement.
    • Serverless, pay-per-query, ideal for ad-hoc analysis.
    Study this card →
  • Amazon CloudWatch Container Insights

    Flip card

    A feature of Amazon CloudWatch that collects, aggregates, and summarizes metrics and logs from containerized applications and microservices running on Amazon ECS, Amazon EKS, and AWS Fargate.

    • Provides deep visibility into container performance (CPU, memory, network).
    • Automatically collects metrics and logs at various granularities.
    • Includes dashboards and can create alarms.
    Study this card →
  • CloudWatch Container Insights

    Flip card

    A fully managed monitoring solution for containerized applications, collecting, aggregating, and summarizing metrics and logs from container environments like EKS.

    • Provides cluster, node, pod, and container-level metrics.
    • Automatically collects and aggregates data.
    • Offers pre-built dashboards and log analysis capabilities.
    Study this card →
  • CloudWatch Embedded Metric Format (EMF)

    Flip card

    A specification for publishing custom metrics to Amazon CloudWatch by embedding them within structured JSON log events. CloudWatch automatically extracts these metrics.

    • Embeds multiple metrics in a single log event.
    • Reduces API calls and overhead for custom metrics.
    • Simplifies metric publishing for serverless applications.
    Study this card →
  • CloudTrail Data Events for S3 Monitoring

    Flip card

    AWS CloudTrail can record S3 object-level API actions (data events), providing detailed audit trails for access to sensitive data within S3 buckets.

    • Captures 'GetObject', 'PutObject', 'DeleteObject', etc.
    • Provides source IP, user identity, timestamp, and bucket details.
    • Essential for security, compliance, and operational troubleshooting.
    Study this card →
  • Amazon S3 Glacier Deep Archive

    Flip card

    Amazon S3 storage class designed for long-term archival and digital preservation with the lowest cost storage in the cloud, suitable for data that is rarely or never accessed.

    • Lowest cost S3 storage class.
    • Retrieval times typically 12-48 hours.
    • Ideal for compliance and long-term archival (7-10+ years).
    Study this card →
  • CloudWatch for Lambda

    Flip card

    Amazon CloudWatch automatically monitors AWS Lambda functions, collecting key performance metrics and logs.

    • Provides invocation count, errors, duration, throttles.
    • Offers pre-built dashboards and custom alarms.
    • Essential for Lambda function health and performance.
    Study this card →
  • X-Ray, CloudWatch, Anomaly Detection Combo

    Flip card

    A powerful combination of AWS services for comprehensive monitoring: X-Ray for distributed tracing, CloudWatch for metrics/logs, and Anomaly Detection for automated deviation detection.

    • X-Ray visualizes end-to-end request flow and identifies latency.
    • CloudWatch collects all application and service metrics/logs.
    • Anomaly Detection automatically learns normal metric patterns and alerts on deviations.
    Study this card →
  • CloudWatch Agent for Hybrid Log Collection

    Flip card

    The CloudWatch agent is a unified agent that can collect logs and metrics from both AWS EC2 instances and on-premises servers, sending them to Amazon CloudWatch.

    • Supports Linux and Windows operating systems.
    • Collects application logs and system logs.
    • Enables centralized logging for hybrid environments.
    Study this card →
  • AWS X-Ray for Distributed Tracing

    Flip card

    AWS X-Ray helps developers analyze and debug distributed applications by collecting data about requests that your application serves.

    • Provides end-to-end request tracing.
    • Generates service maps to visualize connections and latency.
    • Supports various AWS services and custom applications.
    Study this card →
  • DynamoDB CloudWatch Metrics

    Flip card

    Amazon DynamoDB automatically publishes a comprehensive set of operational and performance metrics to Amazon CloudWatch, offering insights into table and index activity.

    • Metrics include read/write capacity, latency, throttled requests.
    • Published automatically, no agent or custom code needed.
    • Can be used with CloudWatch Alarms for real-time alerts.
    Study this card →
  • CloudWatch Agent (On-Premises)

    Flip card

    A unified agent that can be installed on both EC2 instances and on-premises servers to collect system-level metrics (CPU, memory, disk), custom metrics, and log files, sending them to Amazon CloudWatch.

    • Supports hybrid cloud environments (EC2 and on-premises).
    • Collects OS, custom metrics, and logs.
    • Simplifies metric and log collection into CloudWatch.
    Study this card →
  • AWS Chatbot

    Flip card

    A service that makes it easy to monitor and interact with your AWS resources from Slack or Amazon Chime. It can deliver notifications, run commands, and retrieve diagnostic information.

    • Integrates AWS services with Slack and Amazon Chime.
    • Delivers notifications from services like CloudWatch, SNS, Security Hub.
    • Allows running AWS CLI commands directly from chat.
    Study this card →
  • CloudFront Access Logs with Athena

    Flip card

    CloudFront access logs provide detailed records of every user request, which can be stored in S3 and queried serverlessly using Amazon Athena for analytics.

    • Logs contain IP address, user agent, requested URL, and more.
    • Stored in S3, enabling cost-effective long-term retention.
    • Athena allows ad-hoc SQL queries directly on S3 data.
    Study this card →
  • Kinesis Firehose to OpenSearch for Centralized Logging

    Flip card

    A managed architecture for centralizing and analyzing petabytes of security logs (VPC Flow, DNS, WAF) from multiple accounts using Kinesis Data Firehose for ingestion and Amazon OpenSearch Service for real-time search and analytics.

    • Kinesis Firehose for scalable, managed log ingestion.
    • OpenSearch Service for real-time, petabyte-scale search and analysis.
    • Supports long-term retention via OpenSearch data tiers (UltraWarm, Cold Storage) or S3 integration.
    Study this card →
  • CloudTrail Organization Trail

    Flip card

    A CloudTrail trail that logs management and data events for all AWS accounts in an AWS Organization, delivering logs to a centralized S3 bucket.

    • Centralizes logging for all member accounts.
    • Captures API calls and administrative actions.
    • Essential for auditing and compliance across organizations.
    Study this card →
  • CloudWatch Agent

    Flip card

    A unified agent for collecting metrics and logs from Amazon EC2 instances and on-premises servers, sending them to CloudWatch.

    • Collects custom metrics (e.g., memory, disk I/O) and logs.
    • Supports both EC2 and on-premises environments.
    • Unified agent for logs and metrics.
    Study this card →
  • AWS X-Ray Active Tracing for Lambda/API Gateway

    Flip card

    Enabling X-Ray active tracing for Lambda functions and API Gateway stages automatically collects detailed trace information for requests.

    • Provides end-to-end visibility for serverless applications.
    • Captures request segments, subsegments, and metadata.
    • Generates service maps to visualize connections and latency.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.