36 practice questions for Domain 2 of the AWS Certified DevOps Engineer - Professional (DOP-C02) exam, which makes up 17% of its scored content. Your answers count towards one score and one timer for the whole exam.
Domain 2: Configuration Management and Infrastructure as Code
52. An AWS CloudFormation stack must not report creation complete until the application on its instances signals readiness. Which solution meets these requirements?
Answer and explanation
Answer: C. A CreationPolicy makes CloudFormation wait for success signals from cfn-signal before marking the resource complete. DependsOn orders creation without waiting for application readiness. DeletionPolicy governs stack deletion. A post-stack document runs after the stack has already reported complete.
53. An Auto Scaling group defined in CloudFormation must replace its instances in batches during a stack update, waiting for signals from each batch. Which solution meets these requirements?
Answer and explanation
Answer: C. AutoScalingRollingUpdate controls batch size, pause time, and the success threshold for replacing instances during an update. A CreationPolicy applies to initial creation. A stack policy prevents the update rather than controlling how it proceeds. DependsOn orders creation.
54. Infrastructure patterns must be published so application teams provision approved configurations without holding the underlying creation permissions. Which solution meets these requirements?
Answer and explanation
Answer: A. Service Catalog products with launch constraints let users provision approved patterns while the launch role holds the permissions rather than the user. A shared repository relies on teams choosing the right template and still requires them to hold the permissions. Granting the service actions is the permission being avoided. Modules aid template authoring without controlling who may provision.
55. A production database resource must be protected from modification or replacement during any stack update. Which solution meets these requirements?
Answer and explanation
Answer: D. A stack policy is evaluated during updates and can deny modification or replacement of named logical resources. DeletionPolicy governs stack deletion. An IAM deny may not stop CloudFormation acting through its service role. Termination protection prevents stack deletion rather than resource updates.
56. An organization must automate account creation with a consistent security baseline as it scales to hundreds of accounts. Which solution meets these requirements?
Answer and explanation
Answer: A. Control Tower automates landing zone setup, account provisioning, and consistent controls, which is purpose-built for this scale. A custom function recreates that capability at high maintenance cost. A checklist depends on human consistency. Manual creation with a template drifts between accounts.
57. A standard logging and monitoring stack must be deployed to every account in an organizational unit, including accounts added later. Which solution meets these requirements?
Answer and explanation
Answer: C. StackSets targeting an organizational unit with automatic deployment apply the stack to accounts as they join, with no per-account action. Manual deployment misses new accounts. Service Catalog makes a product available for someone to launch. A custom event-driven deployer recreates a built-in capability.
58. Member accounts must be prevented from disabling CloudTrail, regardless of local administrator permissions. Which solution meets these requirements?
Answer and explanation
Answer: B. A service control policy caps permissions in a member account and cannot be removed from inside it. An IAM deny attached to administrators can be detached by those administrators. A remediation rule acts after logging has stopped. Log file validation proves integrity of delivered files rather than preventing the trail being stopped.
59. A security tooling account must administer GuardDuty, Security Hub, and Config for the whole organization without using the management account. Which solution meets these requirements?
Answer and explanation
Answer: B. Delegated administration gives a member account organization-wide control of a security service while the management account stays reserved for organization operations. Cross-account roles into every account grant far more than administering the service requires. Sharing management credentials violates every credential guideline. Manual aggregation does not scale.
60. A package must remain installed and a service running across a fleet, with drift corrected automatically. Which solution meets these requirements?
Answer and explanation
Answer: B. State Manager reapplies an association on a schedule, restoring the desired configuration whenever it drifts. Run Command performs a one-time action. User data runs only at launch. A Config rule detects non-compliance and needs separate remediation to fix it.
61. A complex operational task requires several AWS API calls with branching and error handling, and each step must be visible. Which solution meets these requirements?
Answer and explanation
Answer: C. Step Functions expresses branching, retries, and error handling declaratively with a visible execution history per step. One large function hides the logic and has no per-step visibility. Chained functions are fragile and hard to observe. Fixed-interval scheduling cannot express dependencies between steps.
62. Operating system patches must be applied on a defined schedule with per-instance compliance reporting. Which solution meets these requirements?
Answer and explanation
Answer: D. Patch Manager defines which patches are approved, a maintenance window constrains when they are applied, and the service reports per-instance compliance. User data runs only at launch. A daily function ignores the schedule and reports nothing. A Config rule reports without applying patches.
63. An inventory of installed software across hundreds of instances must be queryable without connecting to each one. Which solution meets these requirements?
Answer and explanation
Answer: B. Systems Manager Inventory collects installed application and configuration data from managed instances and makes it queryable. Config records AWS resource configuration rather than in-guest software. Inspector reports vulnerabilities rather than a general inventory. Tags record what a person asserted.
64. A CloudFormation update must be reviewed for its effect on existing resources before it is applied. Which solution meets these requirements?
Answer and explanation
Answer: B. A change set reports which resources will be added, modified, or replaced before anything changes. A copy of the stack may not reproduce the same drift or dependencies. A template diff shows what changed in the file rather than what will happen to resources. Applying and monitoring is the risk being avoided.
65. A reusable component must be published so teams consume it as a versioned CloudFormation resource type. Which approach is appropriate?
Answer and explanation
Answer: C. Registry publication gives a versioned, discoverable component consumers pin to a release. Copying a template forks it immediately. An S3 URL without versioning changes under consumers. A wiki records the pattern without making it consumable.
66. An architect must decide between AWS CDK and raw CloudFormation templates for a large platform. Which consideration favours CDK?
Answer and explanation
Answer: A. CDK's value is expressing repetition and abstraction in a programming language and sharing it as constructs. CDK synthesises CloudFormation, so the deployed description is the same either way. CDK introduces a synthesis step. A team without programming experience is better served by templates.
67. An application's configuration must change without redeploying the application, with a gradual rollout and automatic rollback. Which solution meets these requirements?
Answer and explanation
Answer: D. AppConfig delivers configuration with gradual rollout and reverts automatically when a monitored alarm fires. Parameter Store read at startup requires a restart. Environment variables require a deployment. A bundled file requires a redeployment to change.
68. A StackSet deployment fails in a subset of accounts while succeeding elsewhere. Which cause should be investigated first?
Answer and explanation
Answer: B. Partial failure points to per-account conditions such as a missing execution role or a name conflict with an existing resource. A size limit or absent trusted access would fail everywhere rather than in a subset. Account count does not cause selective failure.
69. An organization must ensure new accounts receive a security baseline before any workload is deployed into them. Which approach is appropriate?
Answer and explanation
Answer: D. Applying the baseline during account creation leaves no window in which the account is ungoverned. A nightly StackSet run leaves up to a day. Team-applied baselines are inconsistent. Waiting for the first workload means the account exists unprotected until then.
70. An organization must delegate permission management to teams without allowing them to exceed their own permissions. Which solution meets these requirements?
Answer and explanation
Answer: D. Requiring a boundary on created roles is what makes delegation safe, since no created role can exceed the boundary. Full IAM access permits escalation. A central queue is the bottleneck being removed. A published standard relies on compliance.
71. An automation must run a script on hundreds of instances and report which succeeded. Which solution meets these requirements?
Answer and explanation
Answer: C. Run Command executes across a targeted fleet without inbound access and records per-instance status and output. Manual connection does not scale. User data runs at launch and restarting is disruptive. Distributing a script relies on people running it.
72. An automation workflow must handle a step that occasionally fails transiently and a step that must never be retried. Which approach is appropriate?
Answer and explanation
Answer: C. Per-step retry configuration matches the policy to each step's characteristics. A single policy either retries something that must not be repeated or forgoes retries where they would help. Disabling retries entirely fails on transient errors. Restarting the workflow repeats steps already completed.
73. An automation must maintain software compliance across a fleet and report which instances deviate. Which solution meets these requirements?
Answer and explanation
Answer: C. Systems Manager evaluates instances against a defined state and reports compliance per instance. A logging script records without evaluating. Inspector reports vulnerabilities rather than compliance with a defined state. A tag records intent rather than actual state.
74. A CloudFormation template must create a resource only in production accounts. Which construct is appropriate?
Answer and explanation
Answer: C. A Condition controls whether a resource is created. A Mapping looks up values rather than gating creation. DependsOn orders creation. Outputs export values.
75. A CloudFormation stack must reference a value exported by another stack in the same account and Region. Which function is appropriate?
Answer and explanation
Answer: D. ImportValue reads a cross-stack export. GetAtt and Ref operate within the same stack. Sub performs string substitution.
76. A CDK application must define a reusable pattern that several teams instantiate with different parameters. Which construct level is appropriate?
Answer and explanation
Answer: C. A custom construct encapsulates a pattern with typed properties for reuse. Raw resources duplicate the pattern. Separate applications multiply maintenance. Generated templates lose type safety and composability.
77. A CloudFormation deployment must prevent accidental deletion of a stack. Which configuration is appropriate?
Answer and explanation
Answer: D. Termination protection blocks stack deletion. DeletionPolicy retains resources when the stack is deleted rather than preventing deletion. A stack policy governs updates. Removing delete permissions broadly is disruptive and can be reversed.
78. A StackSet must deploy to accounts as they join an organizational unit. Which configuration is required?
Answer and explanation
Answer: A. Service-managed permissions with automatic deployment apply the stack to accounts that join. Self-managed permissions require per-account roles and manual addition. Manual redeployment and per-account StackSets do not scale.
79. An organization must apply a tagging standard so that untagged resources cannot be created. Which combination of steps meets these requirements? (Select TWO.)
Answer and explanation
Answer: B, D. A tag policy defines the standard and a service control policy with a tag condition prevents non-compliant creation. A Config rule reports after creation. Onboarding requests rely on compliance. Cost allocation activation makes tags billable rather than enforcing them.
80. An organization must ensure a new account cannot be used until its baseline controls are applied. Which approach is appropriate?
Answer and explanation
Answer: C. Applying the baseline during creation leaves no ungoverned window. Applying on request, auditing later, and relying on organization policies alone all leave the account partially unprotected on day one.
81. An automation must run across accounts and Regions from a single invocation. Which capability is appropriate?
Answer and explanation
Answer: C. Automation supports multi-account and multi-Region execution from one invocation. Manual per-account Run Command does not scale. Per-account Lambda invocations require orchestration. A StackSet deploys resources rather than executing an automation.
82. A long-running automation must be resumable if it fails at a late step. Which design is appropriate?
Answer and explanation
Answer: A. Discrete states allow resumption from the failure point. A monolithic script restarts everything. Fewer steps does not make failure resumable. A longer timeout tolerates duration rather than failure.
83. An operational task must run on instances that have no inbound network access and no SSH keys. Which approach is appropriate?
Answer and explanation
Answer: A. Systems Manager works through the agent's outbound connection with no inbound access. Opening SSH, deploying a bastion, and assigning public addresses all create inbound exposure.
84. An organization must prevent a member account's resources from being created outside approved Regions during onboarding. Which approach is appropriate?
Answer and explanation
Answer: D. Applying the restriction before handover leaves no unrestricted window. Post-deployment application, weekly audit, and requests all permit resources in unapproved Regions first.
85. An organization must roll out a new service control policy without breaking existing workloads. Which approach is appropriate?
Answer and explanation
Answer: A. Analysing recorded activity and staging the rollout identifies breakage before it affects production. Immediate root application and apply-then-revert both cause outages. Applying only to new accounts leaves existing ones ungoverned.
86. An automation must apply a configuration change only to instances matching specific tags. Which approach is appropriate?
Answer and explanation
Answer: B. Tag targeting selects instances dynamically. Enumerated identifiers and manual lists go stale. Applying to everything wastes execution and risks unintended changes.
87. An automated task must run on instances that may be stopped at the time it is scheduled. Which approach is appropriate?
Answer and explanation
Answer: A. Desired state configuration applies when the instance becomes available. Starting every instance is disruptive and costly, skipping leaves them unconfigured, and more frequent runs still miss instances that remain stopped.