DOP-C02 sample questions with answers

10 free practice questions for the AWS Certified DevOps Engineer – Professional exam. Try each one, then open the answer to see why the right option wins and every other option loses.

Question 1SDLC Automation

A SaaS company builds a large Java container image with AWS CodeBuild on every commit and pushes it to a private Amazon ECR repository in the same account. The image build takes 14 minutes, mostly spent downloading Maven dependencies and rebuilding unchanged Docker layers. The company also wants builds to run inside its VPC so that an internal Nexus mirror is reachable, and it wants the CodeBuild project to push images without any static registry password in the buildspec. The build environment currently uses a standard image with privileged mode disabled, and the last run failed with 'Cannot connect to the Docker daemon'.

Which combination of changes should the DevOps engineer make to fix the failure and reduce build time? (Choose THREE.)

Choose 3.

  1. A.

    Authenticate to ECR in the pre_build phase with aws ecr get-login-password piped to docker login, using the CodeBuild service role's permissions.

  2. B.

    Enable privileged mode on the CodeBuild project so the Docker daemon can run inside the build container.

  3. C.

    Store the ECR registry password as a PLAINTEXT environment variable so the docker push command can authenticate non-interactively.

  4. D.

    Move the build to AWS Lambda compute in CodeBuild so the Docker daemon starts faster.

  5. E.

    Increase the compute type to the largest available and disable all caching, because cache restoration adds latency to every build.

  6. F.

    Enable Amazon S3 caching for the Maven local repository directory and Docker layer caching (LOCALDOCKERLAYER_CACHE) on the project.

Show answer

Answer: A, B, F

Privileged mode fixes the Docker daemon error, S3 plus local Docker layer caching removes the repeated downloads, and get-login-password uses the service role instead of a static password.

  • A. get-login-password issues a short-lived token from the service role, so no static credential lives in the buildspec.
  • B. Docker-in-Docker builds require privileged mode; the daemon error is the direct symptom of it being disabled.
  • C. ECR does not use static passwords, and a PLAINTEXT variable would be a stored secret in the project.
  • D. Lambda compute for CodeBuild does not support Docker image builds or privileged mode.
  • E. Larger compute does not avoid re-downloading dependencies; disabling caching makes the problem worse.
  • F. S3 caching persists Maven dependencies and local Docker layer caching reuses unchanged layers across builds.
Question 2SDLC Automation

A bank operates workloads in 12 AWS accounts across three Regions. A central platform team must produce a hardened Amazon Linux 2023 AMI every month that includes the CloudWatch agent, the company's CIS-based hardening, and the latest security patches. Each AMI must pass an automated vulnerability check before it is shared, must appear in every workload account and Region, and must be published under a stable identifier so that Auto Scaling launch templates in workload accounts can reference the newest approved image without being edited on every rebuild. Building must happen without an engineer logging in to instances.

Which combination of steps meets these requirements? (Choose THREE.)

Choose 3.

  1. A.

    Launch an EC2 instance manually each month, apply the hardening script over SSH, create an AMI from it, and copy it to each Region with the console.

  2. B.

    Configure the Image Builder distribution settings to copy the output AMI to the three Regions and share it with the 12 account IDs or the organization.

  3. C.

    In each workload account, create a Lambda function that runs nightly, calls DescribeImages, and updates every launch template with the newest AMI ID.

  4. D.

    Share the AMI through an AWS Resource Access Manager resource share of the Image Builder recipe so each account builds its own copy.

  5. E.

    Use the distribution configuration's launch template setting or an AWS Systems Manager Parameter Store public parameter reference so launch templates resolve the AMI ID through a parameter such as resolve:ssm:/golden/al2023/latest.

  6. F.

    Create an EC2 Image Builder pipeline with a monthly schedule, a recipe containing the AWS-managed update and CloudWatch agent components plus a custom hardening component, and a test component that fails the build on vulnerability findings.

Show answer

Answer: B, E, F

An Image Builder pipeline with build and test components, multi-Region and multi-account distribution, and an SSM parameter-based AMI reference deliver an automated golden AMI flow.

  • A. Manual SSH-based builds are what the requirement forbids and do not scale to three Regions.
  • B. Distribution settings copy the AMI across Regions and share it with accounts or the organization.
  • C. Custom nightly template rewrites in every account are unnecessary when templates can resolve an SSM parameter.
  • D. Sharing the recipe makes each account build and test separately instead of consuming one approved image.
  • E. A resolve:ssm reference gives a stable identifier that always points at the newest approved AMI.
  • F. Pipeline schedule, managed and custom components, and test components give unattended build and validation.
Question 3SDLC Automation

An e-commerce company keeps its microservices in a GitHub organization. Developers open many pull requests each day, and the team wants unit tests and a static application security test (SAST) to run automatically whenever a pull request is opened or updated, with the result posted back to the pull request so the merge button is blocked on failure. Integration and load tests are expensive and must run only after the merge to main. The team wants to avoid running a CodePipeline execution for every pull request, because pipeline executions are serialized per stage and would queue behind each other. The tests take about six minutes.

Which solution meets these requirements MOST efficiently?

  1. A.

    Schedule an Amazon EventBridge rule every five minutes that starts CodeBuild for every open pull request found through the GitHub API.

  2. B.

    Create an AWS CodeBuild project with a webhook filter for PULLREQUESTCREATED and PULLREQUESTUPDATED events that runs the unit and SAST tests and reports status to GitHub, and keep integration and load tests in the CodePipeline that triggers on pushes to main.

  3. C.

    Configure the CodePipeline source action to trigger on pull request events through the AWS CodeConnections trigger filter, run the unit and SAST tests in the pipeline's first stage, and add a Manual approval action after those tests so reviewers can block the merge before it reaches main.

  4. D.

    Run all tests, including integration and load tests, in a single CodeBuild project triggered on every push to any branch so results are always complete.

Show answer

Answer: B

A standalone CodeBuild project with pull request webhook filters runs fast tests per PR and reports status to GitHub, while the pipeline on main runs the expensive stages.

  • A. Polling every five minutes adds latency and custom code where a webhook exists.
  • B. CodeBuild webhook filters give concurrent per-PR runs with commit status reporting, and the pipeline keeps the expensive stages.
  • C. Pipeline executions serialize per stage and a Manual approval action cannot gate a GitHub merge.
  • D. Running load tests on every branch push wastes resources and slows PR feedback.
Question 4SDLC Automation

A fintech company runs a central tooling account that hosts AWS CodePipeline, AWS CodeBuild, and an Amazon S3 artifact bucket. Application workloads run in separate development, staging, and production accounts, each in its own AWS Organizations OU. The security team requires that the tooling account never holds long-lived credentials for the workload accounts, that pipeline artifacts remain encrypted with a customer managed key, and that the production deployment action is executed with permissions scoped inside the production account. A DevOps engineer must design the cross-account deployment pattern so that a single pipeline in the tooling account can deploy to all three workload accounts.

Which combination of configuration steps meets these requirements with the LEAST operational overhead?

  1. A.

    Replicate the artifact bucket to each workload account with S3 Cross-Region Replication, and create a separate CodePipeline in each account that triggers when replicated objects arrive.

  2. B.

    Attach an AWS Organizations service control policy that allows the tooling account's pipeline role to act in every member account, and keep the artifact bucket encrypted with an AWS managed key.

  3. C.

    Create a cross-account IAM role in each workload account trusted by the tooling account, reference that role in the deploy action's roleArn, and grant the role and the pipeline service role access to the artifact bucket and the customer managed KMS key.

  4. D.

    Create an IAM user in each workload account with deploy permissions, store the access keys in AWS Secrets Manager in the tooling account, and have CodeBuild read the keys before each deploy stage.

Show answer

Answer: C

A cross-account role referenced in the deploy action plus bucket and KMS key policies that trust that role is the standard CodePipeline multi-account pattern with no long-lived credentials.

  • A. Cross-Region Replication is not a cross-account deployment control; three pipelines triple the operational overhead.
  • B. SCPs cannot grant permissions, and the AWS managed S3 key policy cannot be modified to allow cross-account decryption.
  • C. Cross-account roles, a customer managed KMS key, and bucket policy access are exactly the documented CodePipeline multi-account design.
  • D. Uses long-lived IAM user access keys, which the security team explicitly prohibits and which require rotation work.
Question 5SDLC Automation

A mobile gaming studio publishes a leaderboard API on AWS Lambda behind Amazon API Gateway, deployed with AWS SAM. A recent release introduced a latent bug that only appeared under real traffic and affected every player for 20 minutes before the rollback. The studio now requires that new versions receive 10 percent of invocations for 10 minutes, that the shift to 100 percent happens automatically only if a CloudWatch alarm on the function's Errors metric for the new version stays OK, and that rollback needs no human action. The API Gateway stage must continue to point at the same Lambda alias.

Which SAM configuration meets these requirements?

  1. A.

    Set AutoPublishAlias on the function and a DeploymentPreference of type Canary10Percent10Minutes with the alarm listed under Alarms, so CodeDeploy shifts alias weights and rolls back when the alarm enters ALARM.

  2. B.

    Set a DeploymentPreference of type AllAtOnce and attach a PreTraffic hook that sleeps for 10 minutes while checking the Errors metric before allowing traffic.

  3. C.

    Set a DeploymentPreference of type Linear10PercentEvery10Minutes, which moves 10 percent of traffic every 10 minutes until complete, and add the alarm as a CloudWatch Events trigger to redeploy the previous version.

  4. D.

    Create two Lambda functions, old and new, and use an API Gateway canary release setting on the stage to send 10 percent of requests to the new function, then promote manually after 10 minutes.

Show answer

Answer: A

Canary10Percent10Minutes with an alias and an alarm in the DeploymentPreference gives a single 10 percent step, automatic promotion, and alarm-driven rollback through CodeDeploy.

  • A. Canary10Percent10Minutes plus alarms gives one 10 percent step, timed promotion, and automatic alias rollback.
  • B. AllAtOnce sends all traffic at once and a PreTraffic hook cannot observe production invocations.
  • C. Linear shifts repeatedly rather than one held step, and the custom trigger duplicates built-in rollback.
  • D. API Gateway canary requires manual promotion and changes the integration away from the single alias.
Question 6SDLC Automation

A ticketing platform must verify before each production release that its checkout API sustains 20,000 requests per second for 15 minutes with p99 latency under 400 ms. The load must originate from several hundred concurrent workers to reach that rate, the test target is a staging environment deployed by the same AWS CodePipeline, and the release stage must be blocked automatically if the latency objective is missed. AWS CodeBuild is limited to a single container per build, so a single build cannot generate the required load. The team wants the load test to be started and evaluated by the pipeline without an engineer polling for completion.

Which solution meets these requirements?

  1. A.

    Add a Manual approval action and ask an engineer to run the load test from a bastion host, then approve the stage if the numbers look acceptable.

  2. B.

    Add an AWS Step Functions invoke action that starts a state machine which launches hundreds of Amazon ECS Fargate load-generator tasks, waits for them, computes p99 from CloudWatch metrics, and returns a failure state if the objective is missed.

  3. C.

    Add a Lambda invoke action that starts the load generators and immediately returns success, and configure a CloudWatch alarm on p99 latency to send an email to the release manager.

  4. D.

    Add a CodeBuild action that runs a load-testing tool in a loop for 15 minutes with the largest compute type, and parse its output to decide whether to exit non-zero.

Show answer

Answer: B

A Step Functions state machine invoked from the pipeline can fan out Fargate load generators, wait for completion, evaluate p99, and fail the pipeline stage automatically.

  • A. Manual execution and eyeballing results is neither automated nor repeatable.
  • B. Step Functions fans out Fargate tasks, waits, evaluates p99, and its failure fails the pipeline stage automatically.
  • C. Returning success immediately lets the release proceed before the test completes; email is not a gate.
  • D. One CodeBuild container cannot generate load from hundreds of concurrent workers.
Question 7SDLC Automation

A travel company runs a serverless booking API built with AWS SAM. Integration tests must run against real AWS resources because they exercise DynamoDB conditional writes and Step Functions callbacks that mocks have repeatedly failed to reproduce. Currently a shared 'test' stack is used by every pipeline execution, which causes flaky results when two executions run at once and leaves orphaned test data. The team wants each pipeline execution to test against isolated resources, wants the resources removed after the tests regardless of pass or fail, and wants the production deploy to happen only if integration tests pass. Cost must stay low.

Which combination of steps should the DevOps engineer implement? (Choose TWO.)

Choose 2.

  1. A.

    Place the integration test action in a stage that precedes the production deploy stage, so a failed test action stops the pipeline before production changes are applied.

  2. B.

    Replace the integration tests with unit tests using in-memory mocks of DynamoDB and Step Functions so no AWS resources are needed.

  3. C.

    Run integration tests in parallel with the production deploy action in the same stage to reduce total pipeline duration, and roll back production if the tests fail.

  4. D.

    In a CodeBuild action, deploy the SAM template to a stack whose name includes the CODEBUILDRESOLVEDSOURCEVERSION, run the integration tests against its outputs, and delete the stack in a postbuild phase that runs even if the build phase fails.

  5. E.

    Provision one permanent test stack per developer and assign pipeline executions to developers by round robin to reduce collisions.

Show answer

Answer: A, D

Ephemeral per-execution stacks created and torn down in one CodeBuild action give isolation and cleanup, and placing that action before the production stage makes it a true gate.

  • A. Stages run sequentially, so a failing test action in an earlier stage prevents the production deploy.
  • B. The stem states mocks have failed to reproduce the behavior, so removing integration tests loses coverage.
  • C. Actions in the same stage run concurrently, so production changes begin before tests finish.
  • D. A uniquely named ephemeral stack per build with deletion in post_build gives isolation and guaranteed cleanup at serverless cost.
  • E. Permanent per-developer stacks still share state across executions and cost money while idle.
Question 8SDLC Automation

Twelve teams each created their own AWS CodeArtifact domain with one repository, and every domain has an external connection to the public npm registry. Most teams depend on the same popular packages, and the monthly CodeArtifact storage charge has grown steadily. No team is willing to give up its own repository.

Which change will reduce storage cost MOST effectively?

  1. A.

    Consolidate the twelve repositories into a single domain, because CodeArtifact stores each unique package asset once per domain and bills domain storage for that single copy however many repositories in the domain reference it.

  2. B.

    Keep the twelve domains and enable a customer managed AWS KMS key on each one, because customer-managed encryption allows CodeArtifact to compress stored assets more aggressively than the default encryption does.

  3. C.

    Keep the twelve domains and replace each external connection with a shared Amazon S3 bucket holding a mirror of the npm registry, so that only one copy of each package exists across the whole company.

  4. D.

    Keep the twelve domains and add a lifecycle rule to each repository that deletes cached packages from the external connection after 30 days, so each domain stores only recently used packages.

Show answer

Answer: A

CodeArtifact deduplicates package assets at the domain level, so twelve domains hold twelve copies of the same popular packages and consolidating into one domain removes the duplication.

  • A. Assets are deduplicated and billed per domain, so consolidating twelve domains into one collapses twelve copies of shared packages into one.
  • B. The encryption key choice controls who manages the key and has no effect on stored asset size.
  • C. A self-managed S3 mirror discards authentication, upstream resolution and package version status handling in exchange for infrastructure to run.
  • D. Periodic cache deletion trims each domain but leaves the duplication across the twelve domains in place and forces repeated upstream fetches.
Question 9SDLC Automation

A regulated company must be able to prove, for every AMI it uses in production, that a CIS hardening baseline was applied, that the image was scanned for vulnerabilities before release, and that no production account can launch an AMI that failed the scan. Images are produced by EC2 Image Builder in a central account, and production accounts currently have launch permissions on every AMI the central account publishes. Roughly 30 images are produced each month and the evidence must be retrievable per image.

Which combination of steps should the DevOps engineer take to meet these requirements? (Choose TWO.)

Choose 2.

  1. A.

    Grant production accounts launch permissions on every image as they are built, and run a daily AWS Config rule in each production account that reports instances launched from an AMI with an open Inspector finding.

  2. B.

    Enable EC2 Image Builder's integration with Amazon Inspector so the build instance is scanned during the pipeline, and grant launch permissions in the distribution configuration only after the scan result is acceptable, so a failing image is never shared with production accounts.

  3. C.

    Replace the hardening components with a Systems Manager State Manager association that applies the CIS baseline to every running instance every 12 hours, and treat the association's compliance report as the evidence that the baseline was applied to the image.

  4. D.

    Add the AWS-managed CIS hardening build component to the image recipe and a test component that verifies the expected settings, so an image whose hardening did not apply fails before distribution.

  5. E.

    Encrypt each AMI's snapshots with a customer managed AWS KMS key and share the key only with production accounts, because an account that cannot decrypt the snapshot cannot launch the image and this substitutes for scan-based gating.

Show answer

Answer: B, D

Hardening and its verification belong in the recipe as build and test components, and Inspector scanning during the pipeline plus conditional distribution stops a failing image ever being shared with production.

  • A. Sharing every image first means production can launch a failing AMI while the daily report is still being produced.
  • B. Scanning during the pipeline and granting launch permissions only on an acceptable result makes the control preventive rather than detective.
  • C. Re-applying a baseline to running instances leaves them unhardened until the first association run and produces evidence about instances, not images.
  • D. A managed hardening build component plus a test component that verifies the settings produces the evidence and blocks an image whose hardening did not apply.
  • E. A restricted KMS key gates launching uniformly and does not distinguish images that passed the scan from those that failed.
Question 10SDLC Automation

A security team must roll out a third-party endpoint agent, packaged as an .rpm for Linux and an .msi for Windows, to 3,000 Amazon EC2 instances spread across 18 accounts and 4 Regions. The agent is updated by its vendor roughly monthly, the rollout must be staged so that a small group of instances receives a new version first, and the team wants a report of which instances are running which agent version. The application code on those instances is deployed separately by AWS CodeDeploy and must not be affected.

Which solution will meet these requirements?

  1. A.

    Store the installers in an Amazon S3 bucket and add a cron job to each instance's user data that downloads and installs the newest installer it finds every night, writing the installed version to a log file in the bucket.

  2. B.

    Publish the agent as a package in AWS Systems Manager Distributor, then use a State Manager association with rate control and a targeted first wave to install and update it, and read installed versions from Systems Manager Inventory.

  3. C.

    Bake the agent into the AMI with EC2 Image Builder and replace every instance through an instance refresh whenever the vendor publishes a new agent version, using the refresh's health check settings to stage the rollout.

  4. D.

    Create a CodeDeploy application and deployment group per account that deploys the agent packages as a revision alongside the application, using the OneAtATime deployment configuration to stage the rollout across the fleet.

Show answer

Answer: B

Systems Manager Distributor packages software for fleet-wide distribution, State Manager with rate control stages the rollout, and Inventory reports installed versions, all without touching the CodeDeploy application path.

  • A. User data cron jobs are unmanaged, fail silently, and a log file in a bucket is not an inventory of installed versions.
  • B. Distributor packages and versions the agent, State Manager with rate control stages the rollout, and Inventory reports installed versions across accounts and Regions.
  • C. Replacing the whole fleet monthly for an agent unrelated to the application is disproportionate and produces no per-instance version report.
  • D. It couples an infrastructure agent to the application release cycle, which the requirements exclude, and OneAtATime across 3,000 instances is impractically slow.

Keep going with 513 more DOP-C02 questions

Free papers every day, in the real exam formats, with progress by exam domain. Unlock every paper and timed mock exam when you are ready.

DOP-C02 sample questions with answers (10 free) · CertifyCloudx