AWSProfessional

AWS Certified DevOps Engineer – Professional

DOP-C02

Provision, operate and manage distributed systems and CI/CD on AWS.

Duration
180 min
Exam questions
75
Passing score
750 / 1000
Exam fee
$300
Question formats:Multiple choiceMultiple response
Free plan
3 free papers
Free account
Mocks locked
Pro only
Upgrade to Pro
Every paper and mock exam.
See Pro

Start with free papers Free

You get 3 free practice papers with your plan.

Free
Mixed paper 1
Domain 1 · 25 questions
Free
Mixed paper 2
Domain 1 · 25 questions
Free
Mixed paper 3
Domain 1 · 25 questions

Domain papers 523 questions

Free
Mixed paper 1
25 questions · 60 min
Free
Mixed paper 2
25 questions · 60 min
Free
Mixed paper 3
25 questions · 60 min
Pro
Mixed paper 4
14 questions · 34 min
Pro
Mixed paper 5
14 questions · 34 min

Mock exams Pro

Full-length, exam-like practice tests. Available with Pro.

Mock exam 1
75 questions · 180 min
Mock exam 2
75 questions · 180 min
Mock exam 3
75 questions · 180 min

Try a sample question

All 10 sample questions →
Question 1SDLC Automation

A SaaS company builds a large Java container image with AWS CodeBuild on every commit and pushes it to a private Amazon ECR repository in the same account. The image build takes 14 minutes, mostly spent downloading Maven dependencies and rebuilding unchanged Docker layers. The company also wants builds to run inside its VPC so that an internal Nexus mirror is reachable, and it wants the CodeBuild project to push images without any static registry password in the buildspec. The build environment currently uses a standard image with privileged mode disabled, and the last run failed with 'Cannot connect to the Docker daemon'.

Which combination of changes should the DevOps engineer make to fix the failure and reduce build time? (Choose THREE.)

Choose 3.

  1. A.

    Authenticate to ECR in the pre_build phase with aws ecr get-login-password piped to docker login, using the CodeBuild service role's permissions.

  2. B.

    Enable privileged mode on the CodeBuild project so the Docker daemon can run inside the build container.

  3. C.

    Store the ECR registry password as a PLAINTEXT environment variable so the docker push command can authenticate non-interactively.

  4. D.

    Move the build to AWS Lambda compute in CodeBuild so the Docker daemon starts faster.

  5. E.

    Increase the compute type to the largest available and disable all caching, because cache restoration adds latency to every build.

  6. F.

    Enable Amazon S3 caching for the Maven local repository directory and Docker layer caching (LOCALDOCKERLAYER_CACHE) on the project.

Show answer

Answer: A, B, F

Privileged mode fixes the Docker daemon error, S3 plus local Docker layer caching removes the repeated downloads, and get-login-password uses the service role instead of a static password.

  • A. get-login-password issues a short-lived token from the service role, so no static credential lives in the buildspec.
  • B. Docker-in-Docker builds require privileged mode; the daemon error is the direct symptom of it being disabled.
  • C. ECR does not use static passwords, and a PLAINTEXT variable would be a stored secret in the project.
  • D. Lambda compute for CodeBuild does not support Docker image builds or privileged mode.
  • E. Larger compute does not avoid re-downloading dependencies; disabling caching makes the problem worse.
  • F. S3 caching persists Maven dependencies and local Docker layer caching reuses unchanged layers across builds.

What's on the exam

6 domains · 19 task statements, straight from the official exam guide (as of 2026-09-29).

  1. 1.1Implement CI/CD pipelines
    • Software development lifecycle (SDLC) concepts, phases, and models
    • Pipeline deployment patterns for single- and multi-account environments
    • Configuring code, image, and artifact repositories
    • Using version control to integrate pipelines with application environments
    • Setting up build processes (for example, AWS CodeBuild)
    • Managing build and deployment secrets (for example, AWS Secrets Manager, AWS Systems Manager Parameter Store)
    • Determining appropriate deployment strategies (for example, AWS CodeDeploy)
  2. 1.2Integrate automated testing into CI/CD pipelines
    • Different types of tests (for example, unit tests, integration tests, acceptance tests, user interface tests, security scans)
    • Reasonable use of different types of tests at different stages of the CI/CD pipeline
    • Running builds or tests when generating pull requests or code merges (for example, CodeBuild)
    • Running load/stress tests, performance benchmarking, and application testing at scale
    • Measuring application health based on application exit codes
    • Automating unit tests and code coverage
    • Invoking AWS services in a pipeline for testing
  3. 1.3Build and manage artifacts
    • Artifact use cases and secure management
    • Methods to create and generate artifacts
    • Artifact lifecycle considerations
    • Creating and configuring artifact repositories (for example, AWS CodeArtifact, Amazon S3, Amazon ECR)
    • Configuring build tools for generating artifacts (for example, CodeBuild, AWS Lambda)
    • Automating Amazon EC2 instance and container image build processes (for example, EC2 Image Builder)
  4. 1.4Implement deployment strategies for instance, container, and serverless environments
    • Deployment methodologies for various platforms (for example, Amazon EC2, Amazon ECS, Amazon EKS, Lambda)
    • Application storage patterns (for example, Amazon EFS, Amazon S3, Amazon EBS)
    • Mutable deployment patterns in contrast to immutable deployment patterns
    • Tools and services available for distributing code (for example, CodeDeploy, Image Builder)
    • Configuring security permissions to allow access to artifact repositories (for example, IAM, CodeArtifact)
    • Configuring deployment agents (for example, CodeDeploy agent)
    • Troubleshooting deployment issues
    • Using different deployment methods (for example, blue/green, canary)

Outline reproduced from the vendor's public exam guide for study reference.Official guide

DOP-C02 practice — frequently asked questions

Are these real DOP-C02 exam questions?

No. Every question on CertifyCloudx is original, written by us against Amazon Web Services's publicly available DOP-C02 exam guide to rehearse the skills it lists. None are actual exam questions, and CertifyCloudx is not affiliated with or endorsed by Amazon Web Services.

How many DOP-C02 practice questions are there?

523 practice questions, including 3 full-length timed mock exams and 54 domain papers of up to 25 questions (mixed and by topic). Every question has a detailed explanation of why the right answer wins and why each distractor loses.

Is the content up to date with the current DOP-C02 exam guide?

The questions are written against the DOP-C02 exam guide dated 2026-09-29, and we revise them when Amazon Web Services updates the guide.

What question formats are covered?

The same formats the real DOP-C02 uses: Multiple choice, Multiple response. Each is rendered and graded the way the exam does it.

How long is the DOP-C02 exam and how many questions does it have?

According to Amazon Web Services's published exam details: 75 questions, 180 minutes, passing score 750 / 1000. Our mock exams use the same time limit and question count. Always confirm current details with Amazon Web Services before booking.

Can I practise DOP-C02 for free?

Yes. 3 papers are free, with up to 10 questions a day on the free plan and no card needed. Pro unlocks every paper and mock exam with no daily limit.

Does CertifyCloudx guarantee that I will pass?

No practice material can guarantee a result. CertifyCloudx helps you find and close your weak areas — accuracy by exam-guide domain and topic shows what to study next.