AWS Certified DevOps Engineer - Professional Free Sample Questions

20 free sample questions286 in the full practice test Other version: DOP-C01(264)

Try simulator

DOP-C02 Sample Questions

  1. Question 1

    A financial services company is modernizing its application deployment strategy. They are using AWS CodePipeline and AWS CodeDeploy for blue/green deployments to an Amazon ECS cluster fronted by an Application Load Balancer (ALB). A critical requirement is to run a suite of integration tests against the new 'green' environment before any production traffic is shifted. These tests are invoked via an API call and can take up to 10 minutes to complete. If the tests fail, the deployment must be automatically rolled back without any traffic ever reaching the new version. Which configuration in the CodeDeploy AppSpec file will achieve this?

    Answer and explanation

    Correct answer: B

    The AfterAllowTestTraffic hook is specifically designed for running tests in a blue/green deployment after the test listener is active but before production traffic is shifted. Triggering a Lambda function from this hook allows for external test suites to be run. If the Lambda function exits with an error (non-zero exit code), CodeDeploy will automatically initiate a rollback, preventing the faulty green environment from serving production traffic. BeforeInstall is too early in the lifecycle. AfterInstall happens before the task set is stable and ready for testing. BeforeAllowTraffic is for tasks just before the test listener traffic is allowed, which is also too early for end-to-end tests.

  2. Question 2

    A large enterprise uses AWS Organizations and has a mandate that all Amazon S3 buckets must block public access and have versioning enabled for compliance. A DevOps engineer needs to implement an automated, scalable solution to enforce this policy across all existing and future member accounts. The solution must automatically remediate any non-compliant S3 buckets. Which approach provides the most scalable and centrally managed solution?

    Answer and explanation

    Correct answer: B

    AWS Config conformance packs are designed for this exact purpose. They allow you to package a collection of AWS Config rules and remediation actions that can be easily deployed as a single entity across an entire organization from the management account. This is more scalable and maintainable than managing individual StackSets for EventBridge rules and Lambda functions. Service-managed SCPs can prevent certain actions but cannot remediate existing resources. A single Lambda function in the management account would require complex cross-account permissions to remediate resources in member accounts.

  3. Question 3

    A media company processes large video files using a fleet of Amazon EC2 instances. The processing workflow is orchestrated by AWS Step Functions. A key step involves an AWS Lambda function that analyzes video metadata. This function occasionally fails due to transient network issues when calling an external service. The DevOps team needs to implement a robust retry mechanism for this specific Lambda function within the Step Functions state machine, but simple retries are not sufficient. The retries should occur with an increasing delay, and the rate of increase should be less aggressive than the default exponential backoff. Which Retry block configuration should be used in the state machine definition to achieve this?

    Answer and explanation

    Correct answer: C

    In AWS Step Functions, the Retry block allows for fine-grained control over error handling. To achieve an increasing delay that is less aggressive than the default exponential backoff (which has a BackoffRate of 2.0), you must specify a BackoffRate between 1.0 and 2.0. A value of 1.5 will cause the interval to increase by 50% after each attempt, which is less aggressive than the default doubling. A BackoffRate of 2.0 is the default exponential backoff. Not specifying a BackoffRate also defaults to 2.0. ErrorEquals: ["States.TaskFailed"] is appropriate for catching failures within the Lambda function execution.

  4. Question 4

    A DevOps team is managing a microservices application where services communicate via Amazon SNS topics and Amazon SQS queues. They are observing that some messages sent to an SQS queue are being processed multiple times, causing data duplication. The SQS queue is a standard queue, and the consumer is an AWS Lambda function. The team has determined that the Lambda function occasionally times out while processing a message, which leads to the message becoming visible again in the queue and being re-processed. What is the most effective solution to prevent duplicate processing while minimizing changes to the overall architecture?

    Answer and explanation

    Correct answer: D

    Standard SQS queues provide at-least-once delivery, which can result in duplicate messages, especially during consumer failures. FIFO queues provide exactly-once processing (within a 5-minute deduplication interval) and preserve message order. By enabling content-based deduplication, SQS will use a SHA-256 hash of the message body to generate the message deduplication ID, automatically preventing duplicate messages from being sent. This is the most direct and architecturally sound way to solve the duplicate processing issue at the source without complex application logic. While making the Lambda idempotent is a good practice, changing the queue to FIFO is a more robust solution provided by the infrastructure itself.

  5. Question 5

    Multiple answers

    A development team uses AWS CloudFormation to manage their serverless application, which consists of AWS Lambda functions and an Amazon API Gateway. They need to securely manage database connection strings for different environments (dev, staging, prod) without hardcoding them in the CloudFormation template or committing them to source control. The solution must allow for automatic rotation of credentials in the future. Which combination of services provides the most secure and manageable solution? (Select TWO)

    Answer and explanation

    Correct answers: A, D

  6. Question 6

    A DevOps engineer is optimizing a CI/CD pipeline in AWS CodePipeline. The build stage, using AWS CodeBuild, takes a long time because it downloads a large number of dependencies on every run. The engineer wants to speed up the build process by caching these dependencies. The build environment must remain clean for each run, ensuring no stale files from previous builds interfere with the current one. Which caching mode in CodeBuild should be used?

    Answer and explanation

    Correct answer: C

    Amazon S3 caching mode is the best choice here. It allows you to store a cache in an S3 bucket. At the beginning of a build, the cache is downloaded to the local build environment. At the end, the cache is re-uploaded with any changes. This persists dependencies between builds. Local caching (source cache) reuses the Docker container on the build host, which can lead to stale file issues if not managed carefully, violating the 'clean environment' requirement. The Docker layer cache option is for caching layers of a Docker image being built, not general dependencies. 'No cache' is the current slow behavior.

  7. Question 7

    A financial analytics platform runs on Amazon EC2 instances within an Auto Scaling group. During end-of-day processing, these instances experience very high CPU utilization. The operations team needs to receive an alert if the average CPU utilization across the fleet exceeds 90% for a continuous period of 5 minutes. However, to avoid false alarms during initial instance startup, the alarm should not consider data points from instances that are less than 10 minutes old. How can this be achieved using a single Amazon CloudWatch alarm?

    Answer and explanation

    Correct answer: D

    This problem requires advanced CloudWatch functionality. A simple alarm will include all instances. A Lambda function adds complexity. The most elegant solution is to use CloudWatch metric math. By creating an expression like AVG(IF(AGE(m1) > 600, m1)), you can create a dynamic alarm. The METRICS() function can be used to select all CPUUtilization metrics from the Auto Scaling group. The AGE() function returns the age of a metric's latest datapoint in seconds. The IF statement then includes only metrics older than 600 seconds (10 minutes) in the final AVG calculation. This allows a single alarm to dynamically adjust to the fleet while ignoring new instances for a specified period.

  8. Question 8

    True or False: When using AWS CodeDeploy with an EC2/On-Premises compute platform, the appspec.yml file must be placed at the root of the application revision directory structure.

    Answer and explanation

    Correct answer: A

    This is true. For EC2/On-Premises deployments, AWS CodeDeploy requires the Application Specification File (AppSpec file), which must be named appspec.yml or appspec.yaml, to be located in the root of the directory structure of an application's source code.

  9. Question 9

    An organization is using AWS Control Tower to manage a multi-account environment. A new compliance requirement dictates that all Amazon EBS volumes created must be of the gp3 type to ensure a baseline level of performance and cost-efficiency. Any attempt to create a volume of a different type (e.g., gp2, io1) must be denied. The enforcement must be proactive. How should a DevOps engineer implement this control across the entire organization?

    Answer and explanation

    Correct answer: B

    Service Control Policies (SCPs) are the correct tool for proactively enforcing permissions boundaries across an entire AWS Organization. By creating an SCP with a Deny effect for the ec2:CreateVolume action and using a condition key aws:RequestTag/ebs:VolumeType with StringNotEquals for gp3, you can prevent the creation of any non-compliant EBS volumes before they are even provisioned. This is a proactive control. AWS Config is a detective control; it detects non-compliance after the resource is created. CloudFormation hooks are specific to CloudFormation and won't prevent manual creation. IAM permissions boundaries apply to entities but are not as broad as SCPs for organizational enforcement.

  10. Question 10

    A DevOps engineer needs to deploy a serverless application defined using the AWS Serverless Application Model (AWS SAM). The deployment process must be fully automated through AWS CodePipeline. The pipeline needs to package the SAM application, generate a change set for review, and then execute the change set after a manual approval step. Which sequence of actions in CodePipeline is correct for this workflow?

    Answer and explanation

    Correct answer: C

    The correct workflow for deploying a SAM application with a manual review step is as follows: 1. Source: Get the SAM template and code. 2. Build: Use AWS CodeBuild to run sam package. This command packages the application artifacts, uploads them to S3, and produces a new template file (packaged.yaml) with S3 references. 3. Deploy (Create Change Set): Use the AWS CloudFormation provider in CodePipeline with the action CREATE_CHANGESET. This uses the packaged.yaml to create a change set, which shows the proposed changes without applying them. 4. Manual Approval: A manual approval gate is inserted for review. 5. Deploy (Execute Change Set): After approval, use another AWS CloudFormation action with EXECUTE_CHANGESET to apply the previously created changes.

Register free to unlock 10 more sample questions

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 550 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon