AWS DevOps Engineer Professional sample questions with answers
10 free AWS DevOps Engineer Professional sample questions across the exam's domains, each with its answer and an explanation. No account needed.
AWS DevOps Engineer Professional sample questions
AWS Certified DevOps Engineer – Professional, Amazon Web Services (AWS).
Question 1
Domain: SDLC Automation
Which AppSpec hook runs validation after the new Lambda version receives traffic, allowing CodeDeploy to roll back if validation fails?
- BeforeAllowTraffic
- ValidateService
- AfterAllowTraffic
- ApplicationStart
Show the answer
Answer: C. AfterAllowTraffic
Lambda deployments support two hooks, BeforeAllowTraffic and AfterAllowTraffic, each a Lambda function that reports Succeeded or Failed through PutLifecycleEventHookExecutionStatus; AfterAllowTraffic runs once traffic has shifted. ValidateService is a real hook, but only for EC2/on-premises deployments, so it is not available in a Lambda AppSpec.
Checked against: https://docs.aws.amazon.com/codedeploy/latest/userguide/reference-appspec-file-structure-hooks.html
Question 2
Domain: SDLC Automation
An in-place CodeDeploy deployment targets 10 EC2 instances behind a load balancer. At least 9 instances must serve traffic at all times during the deployment.
Which deployment configuration meets the requirement with the least custom work?
- CodeDeployDefault.HalfAtATime
- CodeDeployDefault.OneAtATime
- CodeDeployDefault.AllAtOnce
- CodeDeployDefault.LambdaAllAtOnce
Show the answer
Answer: B. CodeDeployDefault.OneAtATime
OneAtATime takes a single instance out of service at a time, so nine of ten stay available throughout the in-place deployment. HalfAtATime is tempting because it is faster, but it allows up to half the fleet (five instances) to be updating at once.
Checked against: https://docs.aws.amazon.com/codedeploy/latest/userguide/deployment-configurations.html
Question 3
Domain: Configuration Management and IaC
A StackSet update to 300 accounts in 4 Regions takes most of a day because it deploys to one account at a time, one Region after another.
Which StackSets operation preferences reduce the rollout time while stopping early if too many accounts fail?
- Raise the maximum concurrent accounts, set a failure tolerance, and use parallel Region concurrency
- Enable automatic deployment on the stack set and retain stacks when accounts are removed from OUs
- Switch the stack set to self-managed permissions and grant each target account an execution role
- Split the template into nested stacks and deploy each nested stack as a separate stack set operation
Show the answer
Answer: A. Raise the maximum concurrent accounts, set a failure tolerance, and use parallel Region concurrency
Maximum concurrent accounts and Region concurrency control how many stack instances run at once, and failure tolerance sets how many failures are accepted before StackSets stops the operation. Automatic deployment only affects accounts joining OUs later; it does not speed up an update to existing accounts.
Checked against: https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/stacksets-concepts.html
Question 4
Domain: Configuration Management and IaC
A risky configuration change must be rolled out with Run Command to 400 instances. The team wants it to reach only a small share of instances at a time and to stop if a couple of instances fail.
Which Run Command settings limit the blast radius?
- Set TimeoutSeconds to 60 and the output S3 bucket
- Set the document version to $LATEST and enable CloudWatch output
- Set MaxConcurrency to 100 percent and MaxErrors to 0
- Set MaxConcurrency to 10 percent and MaxErrors to 2
Show the answer
Answer: D. Set MaxConcurrency to 10 percent and MaxErrors to 2
MaxConcurrency limits how many targets run the command at once and MaxErrors stops sending to new targets once that many have failed. MaxErrors of 0 with 100 percent concurrency is the trap: every instance has already received the command before the first error can stop anything.
Checked against: https://docs.aws.amazon.com/systems-manager/latest/userguide/send-commands-multiple.html
Question 5
Domain: Resilient Cloud Solutions
An application runs active-active in two Regions and each Region must be able to write user profiles locally with low latency.
Which DynamoDB feature supports this design?
- DynamoDB Streams with a Lambda copier
- Global tables
- Point-in-time recovery
- DynamoDB Accelerator (DAX)
Show the answer
Answer: B. Global tables
Global tables replicate a table across chosen Regions and let applications read and write in every replica Region, which suits active-active designs. A Streams-and-Lambda copier is the tempting do-it-yourself version, but it requires custom conflict handling and operational code that global tables provide natively.
Checked against: https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/GlobalTables.html
Question 6
Domain: Resilient Cloud Solutions
An internal invoicing application runs on EC2 with an RDS for MySQL database in eu-west-1. The business sets an RPO of 1 hour and an RTO of 8 hours for a Regional failure, and asks for the most cost-effective design. All infrastructure is already defined in CloudFormation.
Which disaster recovery approach meets these requirements?
- Warm standby with a scaled-down copy of the application and a cross-Region read replica running in eu-central-1
- Pilot light with an Aurora global database secondary and stopped application instances in eu-central-1
- Backup and restore, with hourly AWS Backup copies to eu-central-1 and the stack redeployed from CloudFormation
- Multi-site active-active with the application serving traffic from both Regions behind Route 53
Show the answer
Answer: C. Backup and restore, with hourly AWS Backup copies to eu-central-1 and the stack redeployed from CloudFormation
With an 8 hour RTO and a 1 hour RPO, hourly backups copied to the recovery Region plus redeploying the stack from templates meets both targets at the lowest running cost. Warm standby and pilot light keep resources running in the second Region for targets this loose. Multi-site is the most expensive strategy and is meant for near-zero RTO.
Checked against: https://docs.aws.amazon.com/whitepapers/latest/disaster-recovery-workloads-on-aws/disaster-recovery-options-in-the-cloud.html
Question 7
Domain: Monitoring and Logging
Which of these EC2 metrics requires the CloudWatch agent (or another custom publisher) rather than being available by default?
- CPU utilization
- Network packets in
- Memory utilization
- Status check failed
Show the answer
Answer: C. Memory utilization
The hypervisor-level metrics EC2 publishes by default include CPU, network, disk operations for instance store and status checks, but not memory or file-system usage, which require the CloudWatch agent inside the guest OS. CPU utilization is the familiar distractor because it is the headline default metric.
Checked against: https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/Install-CloudWatch-Agent.html
Question 8
Domain: Incident and Event Response
How can AWS Config fix a noncompliant resource automatically when a rule evaluates it as NON_COMPLIANT?
- Attach an automatic remediation action that runs a Systems Manager Automation runbook
- Attach a CloudFormation stack to the rule so that it redeploys the noncompliant resource
- Enable the rule's periodic trigger so that it re-evaluates the resource every hour
- Create a conformance pack that includes the rule and an SNS notification for the owner
Show the answer
Answer: A. Attach an automatic remediation action that runs a Systems Manager Automation runbook
AWS Config remediation actions run Systems Manager Automation documents against noncompliant resources, either manually or automatically with retry settings. A periodic trigger only changes how often the rule evaluates; re-evaluating never changes the resource.
Checked against: https://docs.aws.amazon.com/config/latest/developerguide/remediation.html
Question 9
Domain: Security and Compliance
A role's identity policy allows s3:* on a bucket and all of its objects. The role's permissions boundary allows only s3:GetObject and s3:ListBucket. The account's SCPs allow all actions. There is no bucket policy.
Which S3 actions can the role perform on bucket objects?
- Only s3:GetObject
- All S3 actions
- s3:GetObject and s3:PutObject
- No S3 actions
Show the answer
Answer: A. Only s3:GetObject
Effective permissions are the intersection of what the identity policy, the permissions boundary and the SCPs all allow, and here only s3:GetObject is allowed by all three. All S3 actions is the tempting answer if you forget that a boundary caps the identity policy even when the SCP allows everything.
Checked against: https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_evaluation-logic.html
Question 10
Domain: Security and Compliance
A compliance rule states that all access to a bucket holding customer data must use encrypted connections.
Which bucket policy statement enforces this requirement?
- Allow all S3 actions when the condition aws:SecureTransport is true
- Deny all S3 actions when the condition s3:x-amz-server-side-encryption is absent
- Deny all S3 actions when the condition aws:SourceVpce is absent
- Deny all S3 actions when the condition aws:SecureTransport is false
Show the answer
Answer: D. Deny all S3 actions when the condition aws:SecureTransport is false
A Deny when aws:SecureTransport is false blocks any request made over plain HTTP, regardless of what other policies allow. The Allow-when-true version is tempting, but other policies can still grant access over HTTP, so an Allow cannot enforce the requirement.
Checked against: https://docs.aws.amazon.com/AmazonS3/latest/userguide/security-best-practices.html
More practice
A 20-question practice sampler is free with an account; Pro adds the full question bank and timed mock exams.
AWS DevOps Engineer Professional course and practice exam: DOP-C02: the exam guide, with the format, cost, pass mark and domains from the vendor.