26 practice questions for Domain 3 of the AWS Certified CloudOps Engineer - Associate (SOA-C03) exam, which makes up 22% of its scored content. Your answers count towards one score and one timer for the whole exam.
Domain 3: Deployment, Provisioning, and Automation
82. Before applying an AWS CloudFormation stack update, a team must see exactly which resources would be replaced. Which solution meets these requirements?
Answer and explanation
Answer: D. A change set previews the additions, modifications, and replacements an update would cause without applying anything. Drift detection compares live resources against the template and does not preview a pending change. Reviewing events after applying is too late. Nested stacks organise templates and preview nothing.
83. An operations team must roll out a new AMI to an Auto Scaling group so that instances are replaced gradually and the rollout stops if replacements fail health checks. Which solution meets these requirements?
Answer and explanation
Answer: C. An instance refresh replaces instances in batches, honours a minimum healthy percentage, and can pause at checkpoints so a failing rollout stops before the whole group is replaced. Terminating instances forces immediate simultaneous replacement with no health gate. Raising desired capacity adds new instances without removing old ones. A parallel group is a manual cutover with no gradual replacement or automatic stop.
84. An operations team maintains infrastructure with the AWS CDK and must review exactly which resources a change would alter before it is applied. Which solution meets these requirements?
Answer and explanation
Answer: A. cdk diff compares the synthesized template with the deployed stack and reports the resource-level changes, which is the review step required before applying. Reviewing events during a deploy happens after changes are being made. cdk synth produces the template without comparing it to what is deployed. Destroying and redeploying causes an outage and does not review anything.
85. A production database resource must not be modified or replaced during any AWS CloudFormation stack update. Which solution meets these requirements?
Answer and explanation
Answer: C. A stack policy is evaluated during updates and can deny modification or replacement of named logical resources. DeletionPolicy governs behaviour when the stack is deleted. An IAM deny may not stop CloudFormation acting through its own service role. Termination protection prevents stack deletion rather than resource updates.
86. An AWS CloudFormation stack update has failed and the stack is in UPDATE_ROLLBACK_FAILED. Which action should the team take?
Answer and explanation
Answer: C. Continue Update Rollback resumes the rollback and can skip resources that cannot revert, returning the stack to a stable state. Deleting the stack destroys resources that may be in production. Retrying the same update fails for the same reason. Termination protection does nothing to resolve a failed rollback.
87. An engineer must identify every resource in a stack whose live configuration no longer matches its template definition. Which solution meets these requirements?
Answer and explanation
Answer: A. Drift detection compares each resource's actual configuration with the template's expected values and reports the differences. A change set previews a proposed change rather than reporting existing manual edits. An update with no changes fails with no changes to perform. A linter checks syntax.
88. An organization must deploy a standard VPC and logging stack into every account in an organizational unit, including accounts created later. Which solution meets these requirements?
Answer and explanation
Answer: B. StackSets targeting an organizational unit with automatic deployment apply the stack to accounts as they join, with no per-account action. Manual creation is inconsistent and misses new accounts. Service Catalog makes a product available for someone to launch. A custom function recreates a built-in capability with more failure modes.
89. A StackSet operation across 200 accounts must stop early if failures accumulate and must deploy to several accounts at once. Which solution meets these requirements?
Answer and explanation
Answer: B. Operation preferences set how many account failures are tolerated before the operation stops and how many accounts deploy concurrently. Stack policies govern resource updates within a stack. Conditions control which resources a template creates. A permissions boundary caps role permissions without controlling rollout.
90. An organization must build and distribute a hardened, patched AMI on a monthly schedule through a repeatable pipeline. Which solution meets these requirements?
Answer and explanation
Answer: D. Image Builder defines a recipe, runs build and test components on a schedule, and distributes the resulting AMI to accounts and Regions. Patch Manager patches running instances rather than producing images. CodeDeploy delivers application code. Service Catalog publishes products downstream of image creation.
91. Two AWS CloudFormation stacks must share a VPC identifier, and the exporting stack must not be deletable while the value is in use. Which solution meets these requirements?
Answer and explanation
Answer: A. Cross-stack export and import creates a dependency CloudFormation enforces, blocking deletion of the exporting stack while the value is imported. A manually passed parameter creates no dependency. A Parameter Store value is shared but the link is invisible to CloudFormation. Duplicated mappings drift silently.
92. An AWS CloudFormation deployment fails because the target subnet has too few available IP addresses for the requested instances. Which action resolves the failure?
Answer and explanation
Answer: D. Subnet exhaustion is resolved by providing address space, which means adding a secondary CIDR and a suitably sized subnet. A larger maximum group size requests more addresses from the same exhausted subnet. Auto-assign public addressing allocates public addresses and does not create private ones. Retrying fails identically.
93. A company must let developers provision only approved infrastructure patterns in a sandbox account without granting broad creation permissions. Which solution meets these requirements?
Answer and explanation
Answer: A. Service Catalog publishes curated products with launch constraints, so users provision approved patterns without holding broad creation permissions. Granting the underlying actions is the broad permission being avoided. Config reports non-compliance after resources exist. A shared repository relies on developers choosing the right template.
94. A network account must share subnets with several application accounts so those accounts can launch resources into them. Which solution meets these requirements?
Answer and explanation
Answer: C. AWS RAM shares subnets so participant accounts create resources in them while the owner retains control of the network. Peering and Transit Gateway connect separate VPCs that each account would still administer. Copying the configuration creates separate networks rather than sharing one.
95. An operations team uses Terraform for some workloads and must keep that state consistent when resources are also managed elsewhere. Which practice meets these requirements?
Answer and explanation
Answer: C. Single ownership per resource prevents two tools fighting over the same configuration, and remote state with locking prevents concurrent applies corrupting it. Dual management guarantees conflicting changes. Wholesale migration may be desirable eventually but is not what keeps state consistent day to day. Disabling locking invites state corruption.
96. An Auto Scaling group must launch instances from a configuration supporting several instance types and both Spot and On-Demand purchasing. Which solution meets these requirements?
Answer and explanation
Answer: D. Launch templates support versioning and a mixed instances policy combining several instance types with a Spot and On-Demand split. Launch configurations support neither. Separate groups per type fragment capacity management. User data runs after the instance type has already been chosen.
97. An AWS CloudFormation stack fails to create a resource because the deploying role lacks a required permission. Which action resolves the failure?
Answer and explanation
Answer: D. When a service role is specified CloudFormation acts with that role, so the missing action must be added there. Granting the initiating user the action does not change what the service role may do. Disabling rollback preserves a broken stack without resolving the permission. Permissions are not Region-specific in the way implied.
98. A command must be run on 300 EC2 instances without opening inbound ports or distributing SSH keys. Which solution meets these requirements?
Answer and explanation
Answer: A. Run Command executes documents on managed instances through the SSM agent using IAM permissions, with no inbound ports and no key distribution. A bastion reintroduces keys and inbound access. Connecting instance by instance does not scale to 300. User data runs at launch and would require rebooting every instance.
99. A specific package must remain installed and a service must remain running on all instances, with drift corrected automatically. Which solution meets these requirements?
Answer and explanation
Answer: A. State Manager reapplies an association on a schedule, restoring the desired configuration whenever it drifts. Run Command performs a one-off action. User data runs only at launch. A Config rule detects non-compliance and needs separate remediation to fix it.
100. Operating system patches must be applied to production instances only during a Sunday maintenance window, with compliance reporting. Which solution meets these requirements?
Answer and explanation
Answer: A. Patch Manager defines which patches are approved through a baseline, a maintenance window constrains when they are applied, and the service reports per-instance compliance. User data only runs at launch. A daily function ignores the required window and reports nothing. A Config rule reports without applying patches.
101. An object uploaded to Amazon S3 must automatically start a processing workflow. Which solution meets these requirements?
Answer and explanation
Answer: B. Event notifications and EventBridge rules invoke a target as objects arrive, which is the event-driven pattern required. A scheduled association introduces delay and repeated listing. A polling function adds cost and latency where an event path exists. The object count metric is reported at daily granularity.
102. A team must know which of 400 EC2 instances have a specific application version installed, without connecting to each one. Which solution meets these requirements?
Answer and explanation
Answer: B. Systems Manager Inventory collects installed application, package, and configuration data from managed instances and makes it queryable. Config records AWS resource configuration rather than in-guest software. Inspector reports vulnerabilities rather than a general inventory. Tags record what a person asserted rather than what is installed.
103. An AMI must be shared with another account in the same organization. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: A, D. Both the AMI launch permission and the backing snapshot permissions are required for the target account to launch from it. Making it public exposes it broadly. Copying to a Region does not share it. IAM permissions on an ARN do not substitute for launch permissions.
104. A Systems Manager patch baseline must approve patches only after they have been available for seven days. Which configuration is appropriate?
Answer and explanation
Answer: B. An auto-approval delay holds patches for the configured period before they become approved. Scheduling a window per release does not scale. Manual review is not automated. Compliance level governs reporting severity.
105. An EC2 instance's root volume must be increased in size without replacing the instance. Which steps are required?
Answer and explanation
Answer: C. Modifying the volume increases the block device, and the partition and file system must then be extended in the guest. The file system is not extended automatically. Instance type does not govern volume size. Replacing the root device requires stopping and detaching.
106. A repeated operational task must be captured so it runs identically each time and its execution is recorded. Which approach is appropriate?
Answer and explanation
Answer: D. An Automation runbook executes identically and records each step. A document, a designated operator, and a reminder all rely on human execution.
107. An operational automation must be applied to instances as they launch, without modifying the machine image. Which approach is appropriate?
Answer and explanation
Answer: B. A tag-targeted State Manager association applies to instances as they launch and reapplies on drift. User data modifies the launch template rather than the image but runs only once. Rebuilding the image is what the requirement excludes. Manual Run Command depends on someone acting.