A company uses a large number of Linux based Amazon EC2 instances to run business operations such as ordering, fulfillment, and billing. The company uses AWS Systems Manager to manage the EC2 instances. The company wants to ensure that the Systems Manager Agent (SSM Agent) is always up to date with the latest version.
Which solution will meet this requirement in the MOST operationally efficient way?
A. Enable the Auto update SSM Agent setting in Systems Manager Fleet Manager.
B. Subscribe to SSM Agent notifications on Github. Configure the subscription events to invoke an Amazon SNS topic. Configure the SNS topic to run a custom AWS Lambda function to update the SSM Agent by using the Systems Manager Run Command API.
C. Enable the Auto update SSM Agent setting in Systems Manager Patch Manager.
D. Subscribe to SSM Agent notifications on Github. Configure the subscription events to invoke an Amazon SNS topic. Configure the topic to run a custom AWS Lambda function to update the SSM Agent by using a Systems Manager Automation document.
Show Answer
Correct Answer: A
Explanation: Fleet Manager provides a built-in automatic SSM Agent update capability that creates and manages the necessary State Manager association to keep the SSM Agent current with minimal operational effort. The GitHub/SNS/Lambda options add unnecessary custom infrastructure, and Patch Manager is for OS/application patching rather than the native SSM Agent auto-update feature.
Question 34
A company has AWS accounts in an organization in AWS Organizations. The company has built an AWS Lambda function in one account. The Lambda function needs to retrieve a list of Amazon EC2 instances that are running in another account.
Which solution will provide this access MOST securely?
A. Create an IAM user in the account where the EC2 instances are running. Collect access keys from the user. Store these credentials in AWS Systems Manager Parameter Store in the account of the Lambda function. Configure the Lambda function to use the access key and the secret key.
B. Configure the Lambda function's execution role to assume a cross-account IAM role in the account where the EC2 instances are running. Modify the trust policy of the cross-account role to allow the Lambda function to assume the role. Add the AWS STS AssumeRole API operation to the Lambda function's code.
C. From the management account in the organization, call the Organizations CreatePolicy API operation to create a new service control policy (SCP). Configure the SCP to grant lambda:InvokeFunction permission. Assign the SCP to the organization root.
D. Create a new resource-based policy for the Lambda function. In the policy, set the Principal to "*" and set the Action to lambda:InvokeFunction. Create a condition on the policy to allow access when the value of the aws:PrincipalOrgID condition key matches the organization's ID.
Show Answer
Correct Answer: B
Explanation: Configure the Lambda execution role to assume a role in the account that owns the EC2 instances. Grant the target role only the required EC2 read permissions, such as `ec2:DescribeInstances`, and trust the Lambda execution role to assume it. STS provides temporary credentials. The other options use long-term access keys, misuse an SCP, or control who can invoke the Lambda function rather than access EC2.
Question 35
A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The company needs an AWS Lambda function to perform a custom recovery procedure on the application server when the application returns an HTTP 500 status code.
A CloudOps engineer needs to design a solution that detects HTTP 500 status codes and runs the Lambda function reliably when errors are detected.
Which solution will meet these requirements?
A. Configure an Amazon CloudWatch alarm on the HTTPCode_Target_5XX_Count ALB target group metric. Set the alarm action to run the Lambda function.
B. Deploy a new Lambda function that continuously scans the ALB access logs in Amazon S3 to detect HTTP 500 status codes and then invokes the existing lambda function.
C. Enable AWS CloudTrail on the application instances. Configure Amazon CloudWatch Logs metric filters to detect HTTP 500 status codes and run the Lambda function.
D. Create an Amazon EventBridge rule for all ALB request events that invokes the Lambda function. Configure the Lambda function to filter for HTTP 500 status codes internally.
Show Answer
Correct Answer: A
Explanation: The ALB publishes the HTTPCode_Target_5XX_Count metric to Amazon CloudWatch. A CloudWatch alarm can monitor this metric and use a Lambda function as the alarm action, providing a managed and reliable way to trigger custom recovery when target-generated HTTP 500 errors occur. The other options rely on log scanning, CloudTrail (which does not capture HTTP response codes), or EventBridge events that do not exist for individual ALB requests.
Question 35
A company uses AWS Organizations to manage multiple AWS accounts. Corporate policy mandates that only specific AWS Regions can be used to store and process customer data. A CloudOps engineer must prevent the provisioning of Amazon EC2 instances in unauthorized Regions by anyone in the company.
What is the MOST operationally efficient solution that meets these requirements?
A. Configure AWS CloudTrail in all Regions to record all API activity. Create an Amazon EventBridge rule in all unauthorized Regions for ec2:RunInstances events. Use AWS Lambda to terminate the launched EC2 instances.
B. In each AWS account, create a managed IAM policy that uses a Region condition to deny the ec2:RunInstances action in all unauthorized Regions. Attach this policy to all IAM groups in each AWS account.
C. In each AWS account, create an IAM permissions boundary policy that uses a Region condition to deny the ec2:RunInstances action in all unauthorized Regions. Attach the permissions boundary policy to all IAM users in each AWS account.
D. Create a service control policy (SCP) in AWS Organizations to deny the ec2:RunInstances action in all unauthorized Regions. Attach this policy to the root level of the organization.
Show Answer
Correct Answer: D
Explanation: An SCP attached at the organization root centrally denies EC2 instance launches in unauthorized Regions across member accounts, including current and future accounts under that root. Unlike reactive remediation, it prevents the launches; unlike account-by-account IAM policies or permissions boundaries, it is operationally efficient and broadly enforced.
Question 36
A retail company runs a web application. The application uses an Application Load Balancer (ALB) to distribute traffic across multiple Amazon EC2 instances in two Availability Zones. The application experiences high traffic during flash sales. The company needs to ensure even distribution of requests across all healthy instances. Additionally, the company requires session persistence for shopping cart functionality.
Which configuration will meet these requirements with the LEAST administrative effort?
A. Configure the ALB target group to use the round robin algorithm. Enable stickiness and cross-zone load balancing.
B. Switch the ALB to a Network Load Balancer. Modify the target group to use the least outstanding requests algorithm. Enable stickiness. Disable cross-zone load balancing.
C. Configure the ALB target group to use the weighted round robin algorithm. Implement session persistence by using AWS Lambda functions to store session data in Amazon DynamoDB.
D. Configure the ALB listener with path-based routing to direct shopping cart requests to a dedicated target group with sticky sessions. Use the round robin algorithm without stickiness for a second target group.
Show Answer
Correct Answer: A
Explanation: An Application Load Balancer supports round robin request distribution, target group stickiness for session persistence, and cross-zone load balancing to distribute requests evenly across healthy targets in all enabled Availability Zones. This satisfies the requirements with native ALB features and the least administrative effort. The other options either use an inappropriate load balancer, add unnecessary custom components, or do not ensure stickiness across all application traffic.
Question 36
A compliance team requires all administrator passwords for Amazon RDS DB instances to be changed at least annually.
Which solution meets this requirement in the MOST operationally efficient manner?
A. Store the database credentials in AWS Secrets Manager. Configure automatic rotation for the secret every 365 days.
B. Store the database credentials as a parameter in the RDS parameter group. Create a database trigger to rotate the password every 365 days.
C. Store the database credentials in a private Amazon S3 bucket. Schedule an AWS Lambda function to generate a new set of credentials every 365 days.
D. Store the database credentials in AWS Systems Manager Parameter Store as a secure string parameter. Configure automatic rotation for the parameter every 365 days.
Show Answer
Correct Answer: A
Explanation: AWS Secrets Manager has built-in integration for managing and automatically rotating Amazon RDS credentials. Setting rotation to every 365 days meets the annual requirement without custom code or infrastructure, making it the most operationally efficient option.
Question 37
A company hosts an ecommerce website on a fleet of Nitro-based Amazon EC2 Linux instances. During a recent sales event, some customers reported HTTP timeout errors.
To help identify the root cause of the errors, a CloudOps engineer needs more detailed network metrics from the Elastic Network Adapter (ENA) driver. The CloudOps engineer must obtain the conntrack_allowance_available metric and the conntrack_allowance_exceeded metric.
Which solution will provide these metrics with the MOST operational efficiency?
A. Install the Amazon CloudWatch agent on the instances. Filter by the conntrack_allowance_available metric and the conntrack_allowance_exceeded metric.
B. Install the collectd daemon and the Amazon CloudWatch agent on the EC2 instances. Filter by the conntrack_allowance_available metric and the conntrack_allowance_exceeded metric.
C. Enable VPC Flow Logs. Filter by the conntrack_allowance_available metric and the conntrack_allowance_exceeded metric.
D. Enable Performance Insights for the instances. Use Amazon CloudWatch to view the conntrack_allowance_available metric and the conntrack_allowance_exceeded metric.
Show Answer
Correct Answer: A
Explanation: The Amazon CloudWatch agent can collect ENA ethtool metrics from Nitro-based EC2 instances, including conntrack_allowance_available and conntrack_allowance_exceeded, and publish them to CloudWatch. This is the most operationally efficient approach because it requires only the CloudWatch agent. collectd is unnecessary for these ENA metrics, VPC Flow Logs do not expose ENA driver conntrack allowance metrics, and Performance Insights is an RDS feature, not applicable to EC2 instances.
Question 37
A company has a non-production application that runs on an Amazon EC2 instance. The instance has an Amazon EBS volume attached. Each time an instance health check fails, a CloudOps engineer resolves the issue by rebooting the instance.
The CloudOps engineer must implement an automated solution to reboot the instance after a failed health check. The CloudOps engineer creates a service-linked IAM role for Amazon EventBridge.
What should the CloudOps engineer do next to meet the automation requirement?
A. Create an Amazon CloudWatch alarm for the HealthyHostCount metric. Include a search expression in the alarm that matches the instance. Configure the alarm to perform an EC2 reboot action when the metric value is greater than zero.
B. Create an Amazon CloudWatch alarm for the StatusCheckFailed_Instance metric. Include a search expression in the alarm that matches the instance. Configure the alarm to perform an EC2 recover action when the metric value is greater than zero.
C. Create an Amazon CloudWatch alarm for the StatusCheckFailed_Instance metric. Use the instance ID as a dimension. Configure the alarm to perform an EC2 reboot action when the metric value is greater than zero.
D. Configure detailed monitoring for the instance. Create an Amazon CloudWatch alarm for the StatusCheckFailed_Instance metric. Use the EC2 Amazon Machine Image (AMI) ID as a dimension. Configure the alarm to perform an EC2 stop instance operation and then an EC2 start instance operation when the metric value is greater than zero.
Show Answer
Correct Answer: C
Explanation: Create a CloudWatch alarm for the StatusCheckFailed_Instance metric, dimensioned by the instance ID, and configure it to reboot the instance when the metric is greater than zero. This targets the specific instance and matches the manual remediation. EC2 recover actions are intended for system status check failures, not instance status check failures.
Question 38
A CloudOps engineer has an Amazon S3 bucket and a new AWS Lambda function. The CloudOps engineer tries to configure a new event notification from the S3 bucket to the Lambda function by using the Lambda console. The configuration fails and returns the following error: "Unable to validate the following destination configurations."
The engineer confirms that the new Lambda function and the function's IAM role are correctly configured.
What is the cause of this error?
A. The maximum number of S3 event notification destinations has been exceeded for the S3 bucket.
B. The S3 bucket owner needs to grant the Lambda function explicit cross-account permissions by using a resource policy.
C. The new Lambda function's resource-based policy is missing the lambda:InvokeFunction permission for Amazon S3.
D. The S3 bucket has an existing stale event notification that points to a deleted or permission-deficient resource.
Show Answer
Correct Answer: D
Explanation: Amazon S3 validates all configured event notification destinations when a notification configuration is created or updated. If the bucket contains an existing stale notification that references a deleted resource or a destination with invalid permissions, validation fails with 'Unable to validate the following destination configurations,' even if the new Lambda function and its execution role are correctly configured. While Lambda does require a resource-based policy allowing S3 to invoke it, the scenario states the new function is correctly configured, making a stale existing notification the most likely cause.
Sources:
https://www.secexams.com/exams/Amazon/aws-certified-cloudops-engineer-associate-soa-c03/view/18
Question 38
A company's public website is hosted in an Amazon S3 bucket in the us-east-1 Region behind an Amazon CloudFront distribution. The company wants to ensure that the website is protected from DDoS attacks. A CloudOps engineer needs to deploy a solution that gives the company the ability to maintain control over the rate limit at which DDoS protections are applied.
Which solution will meet these requirements?
A. Deploy a global-scoped AWS WAF web ACL with an allow default action. Configure an AWS WAF rate-based rule to block matching traffic. Associate the web ACL with the CloudFront distribution.
B. Deploy an AWS WAF web ACL with an allow default action in us-east-1. Configure an AWS WAF rate-based rule to block matching traffic. Associate the web ACL with the S3 bucket.
C. Deploy a global-scoped AWS WAF web ACL with a block default action. Configure an AWS WAF rate-based rule to allow matching traffic. Associate the web ACL with the CloudFront distribution.
D. Deploy an AWS WAF web ACL with a block default action in us-east-1. Configure an AWS WAF rate-based rule to allow matching traffic. Associate the web ACL with the S3 bucket.
Show Answer
Correct Answer: A
Explanation: Use a global-scope AWS WAF web ACL associated with the CloudFront distribution. Set the default action to allow and configure a rate-based rule to block requests that exceed the chosen rate limit. This lets the company control the rate threshold while protecting the public site. AWS WAF is associated with CloudFront, not directly with the S3 bucket.
$19
Get all 194 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.