DOP-C02 Exam Questions
498 real DOP-C02 exam questions with expert-verified answers and explanations. Page 6 of 10.
- Question #253Security & Compliance
A company is migrating its container-based workloads to an AWS Organizations multi-account environment. The environment consists of application workload accounts that the company u...
Container image securityECRAWS CodePipelineVulnerability scanning - Question #254Security & Compliance
A company uses an Amazon Elastic Kubernetes Service (Amazon EKS) cluster to deploy its web applications on containers. The web applications contain confidential data that cannot be...
AWS Secrets ManagerAWS KMSKMS Key PolicyIAM Roles for Service Accounts (IRSA) - Question #255Resilient Cloud Solutions
A company is migrating its product development teams from an on-premises data center to a hybrid environment. The new environment will add four AWS Regions and will give the develo...
Hybrid storageFSx for NetApp ONTAPMulti-Region replicationData migration - Question #256Security & Compliance
A company has an application that stores data that includes personally identifiable information (PII) in an Amazon S3 bucket. All data is encrypted with AWS Key Management Service...
PII AnonymizationS3 ReplicationAWS KMSCloudFormation - Question #258Monitoring and Logging
A company's application has an API that retrieves workload metrics. The company needs to audit, analyze, and visualize these metrics from the application to detect issues at scale....
Metrics ingestionData catalogingServerless ETLData visualization - Question #259Configuration Management and Infrastructure as Code
A DevOps engineer is building the infrastructure for an application. The application needs to run on an Amazon Elastic Kubernetes Service (Amazon EKS) cluster that includes Amazon...
EKS storageEFS CSI driverSecurity groupsIAM roles for service accounts - Question #260Security and Compliance
A company deploys an application on on-premises devices in the company's on-premises data center. The company uses an AWS Direct Connect connection between the data center and the...
Hybrid connectivityEFS on-premises accessPrivateLink for EFSCertificate authentication - Question #261SDLC Automation
A DevOps engineer is setting up an Amazon Elastic Container Service (Amazon ECS) blue/green deployment for an application by using AWS CodeDeploy and AWS CloudFormation. During the...
CloudFormationCodeDeployECS Blue/GreenTraffic Shifting - Question #262Security and Compliance
A company uses an organization in AWS Organizations to manage its AWS accounts. The company's DevOps team has developed an AWS Lambda function that calls the Organizations API to c...
AWS OrganizationsIAM RolesCross-Account AccessLambda Security - Question #263Resilient Cloud Solutions
A company has deployed an application in a single AWS Region. The application backend uses Amazon DynamoDB tables and Amazon S3 buckets. The company wants to deploy the application...
Cross-Region ReplicationS3Multi-Region ArchitectureData Synchronization - Question #264Monitoring and Logging
A company has configured Amazon RDS storage autoscaling for its RDS DB instances. A DevOps team needs to visualize the autoscaling events on an Amazon CloudWatch dashboard. Which s...
Event-driven automationAmazon EventBridgeRDS autoscaling eventsCloudWatch dashboards - Question #265SDLC Automation
A company uses containers for its applications. The company learns that some container images are missing required security configurations. A DevOps engineer needs to implement a s...
Container image buildingEC2 Image BuilderMulti-Region image distributionImage security - Question #266Configuration Management and Infrastructure as Code
A DevOps engineer needs to implement a solution to install antivirus software on all the Amazon EC2 instances in an AWS account. The EC2 instances run the most recent version of Am...
Systems Manager State ManagerEC2 automationSoftware installationConfiguration compliance - Question #267Security and Compliance
A company needs to increase the security of the container images that run in its production environment. The company wants to integrate operating system scanning and programming la...
Container image scanningECR enhanced scanningCI/CD securityEvent-driven security enforcement - Question #268Security and Compliance
A company's DevOps team manages a set of AWS accounts that are in an organization in AWS Organizations. The company needs a solution that ensures that all Amazon EC2 instances use...
AWS ConfigConformance PacksAWS OrganizationsSecurity Compliance - Question #269Security and Compliance
A company gives its employees limited rights to AWS. DevOps engineers have the ability to assume an administrator role. For tracking purposes, the security team wants to receive a...
EventBridgeCloudTrailSecurity MonitoringReal-time Alerting - Question #270Reliability & Resilience
A company needs a strategy for failover and disaster recovery of its data and application. The application uses a MySQL database and Amazon EC2 instances. The company requires a ma...
Disaster recoveryRPO/RTOAurora Global DatabaseRoute 53 failover - Question #271SDLC Automation
A developer is using the AWS Serverless Application Model (AWS SAM) to create a prototype for an AWS Lambda function. The AWS SAM template contains an AWS::Serverless::Function res...
AWS SAMServerless deploymentLambda functionsCI/CD deployment commands - Question #272Security and Compliance
A company runs its container workloads in AWS App Runner. A DevOps engineer manages the company's container repository in Amazon Elastic Container Registry (Amazon ECR). The DevOps...
Container image securityVulnerability remediationECR scanningEC2 Image Builder pipelines - Question #273Configuration Management and Infrastructure as Code
A company wants to use AWS Systems Manager documents to bootstrap physical laptops for developers. The bootstrap code is stored in GitHub. A DevOps engineer has already created a S...
Systems Manager documentsHybrid environment managementRemote executionOn-premises bootstrapping - Question #274Configuration Management and Infrastructure as Code
A company's development team uses AWS CloudFormation to deploy its application resources. The team must use CloudFormation for all changes to the environment. The team cannot use t...
IAM RolesCloudFormationInfrastructure as Code EnforcementLeast Privilege - Question #275Configuration Management and Infrastructure as Code
A company is developing a web application's infrastructure using AWS CloudFormation. The database engineering team maintains the database resources in a CloudFormation template, an...
CloudFormationstack exportscross-stack referencingIaC - Question #276Security & Compliance
A company has an organization in AWS Organizations. A DevOps engineer needs to maintain multiple AWS accounts that belong to different OUs in the organization. All resources, inclu...
AWS OrganizationsSCPsIAM policiesS3 bucket policy - Question #277SDLC Automation
A company has an organization in AWS Organizations for its multi-account environment. A DevOps engineer is developing an AWS CodeArtifact based strategy for application package man...
AWS CodeArtifactMulti-account strategyPackage ManagementAWS Organizations - Question #278SDLC Automation
A company deploys an application to Amazon EC2 instances. The application runs Amazon Linux 2 and uses AWS CodeDeploy. The application has the following file structure for its code...
CodeDeployappspec.ymldeployment configurationfile management - Question #279Security & Compliance
A company has set up AWS CodeArtifact repositories with public upstream repositories. The company's development team consumes open source dependencies from the repositories in the...
CodeArtifactpackage securityvulnerability managementorigin control - Question #280Resilient Cloud Solutions
A company is running a custom-built application that processes records. All the components run on Amazon EC2 instances that run in an Auto Scaling group. Each record's processing i...
AWS Step Functionsworkflow automationfault toleranceserverless architecture - Question #281Resilient Cloud Solutions
A company is migrating its on-premises Windows applications and Linux applications to AWS. The company will use automation to launch Amazon EC2 instances to mirror the on-premises...
FSx for NetApp ONTAPSMB/NFSdisaster recoverymulti-Region replication - Question #282Resilient Cloud Solutions
A company's application uses a fleet of Amazon EC2 On-Demand Instances to analyze and process data. The EC2 instances are in an Auto Scaling group. The Auto Scaling group is a targ...
Auto Scaling groupswarm poolscost optimizationworkload separation - Question #283Monitoring & Logging
A company recently migrated its application to an Amazon Elastic Kubernetes Service (Amazon EKS) cluster that uses Amazon EC2 instances. The company configured the application to a...
EKSCloudWatch AgentContainer Insightsmemory metrics - Question #284Security & Compliance
A company's video streaming platform usage has increased from 10,000 users each day to 50,000 users each day in multiple countries. The company deploys the streaming platform on Am...
EKS securityGuardDutyAmazon Detectivethreat detection - Question #285Security & Compliance
A company uses AWS Organizations to manage hundreds of AWS accounts. The company has a team that is responsible for AWS Identity and Access Management (IAM). The IAM team wants to...
IAM Identity CenterAWS Organizationsleast privilegeidentity management - Question #286Security & Compliance
A company uses an organization in AWS Organizations that has all features enabled. The company uses AWS Backup in a primary account and uses an AWS Key Management Service (AWS KMS)...
AWS BackupKMScross-account replicationaccess policies - Question #287Resilient Cloud Solutions
A company runs an application that uses an Amazon S3 bucket to store images. A DevOps engineer needs to implement a multi-Region strategy for the objects that are stored in the S3...
S3 replicationS3 Multi-Region Access PointsS3 RTCdisaster recovery - Question #288SDLC Automation
A company uses the AWS Cloud Development Kit (AWS CDK) to define its application. The company uses a pipeline that consists of AWS CodePipeline and AWS CodeBuild to deploy the CDK...
AWS CDKCodePipelineCodeBuildinfrastructure testing - Question #289Resilient Cloud Solutions
A company has an application that runs on Amazon EC2 instances behind an Application Load Balancer (ALB). The EC2 instances are in multiple Availability Zones. The application was...
ALBcross-zone load balancingRoute 53 Application Recovery ControllerAZ isolation - Question #290Monitoring & Logging
A company sends its AWS Network Firewall flow logs to an Amazon S3 bucket. The company then analyzes the flow logs by using Amazon Athena. The company needs to transform the flow l...
Kinesis Data FirehoseAWS Lambdadata transformationflow logs - Question #291SDLC Automation
A DevOps engineer needs to implement integration tests into an existing AWS CodePipeline CI/CD workflow for an Amazon Elastic Container Service (Amazon ECS) service. The CI/CD work...
CodePipelineECS deploymentintegration testingAWS Lambda - Question #292Configuration Management and Infrastructure as Code
A company runs applications on Windows and Linux Amazon EC2 instances. The instances run across multiple Availability Zones in an AWS Region. The company uses Auto Scaling groups f...
FSx for NetApp ONTAPshared storageAuto Scaling groupsinstance refresh - Question #293Security & Compliance
A company uses an organization in AWS Organizations that a security team and a DevOps team manage. Both teams access the accounts by using AWS IAM Identity Center. A dedicated grou...
AWS OrganizationsIAM Identity CenterService Control Policies (SCPs)Permission SetsAccess Control - Question #294Configuration Management and Infrastructure as Code
An Amazon EC2 Auto Scaling group manages EC2 instances that were created from an AMI. The AMI has the AWS Systems Manager Agent installed. When an EC2 instance is launched into the...
AWS Systems ManagerState ManagerOS configurationAuto Scaling groups - Question #295Security and Compliance
A company uses AWS Organizations to manage its AWS accounts. The organization root has a child OU that is named Department. The Department OU has a child OU that is named Engineeri...
AWS OrganizationsService Control Policies (SCPs)IAM policy evaluationLeast privilege - Question #296Monitoring and Logging
A company manages AWS accounts in AWS Organizations. The company needs a solution to send Amazon CloudWatch Logs data to an Amazon S3 bucket in a dedicated AWS account. The solutio...
CloudWatch LogsKinesis Data FirehoseCentralized loggingAWS Organizations - Question #297Resilient Cloud Solutions
A DevOps engineer manages a Java-based application that runs in an Amazon Elastic Container Service (Amazon ECS) cluster on AWS Fargate. Auto scaling has not been configured for th...
Custom metricsApplication auto scalingCloudWatch agentECS FargatePrometheus - Question #298Resilient Cloud Solutions
A company has an application that runs in a single AWS Region. The application runs on an Amazon Elastic Kubernetes Service (Amazon EKS) cluster and connects to an Amazon Aurora My...
ECR Cross-Region ReplicationAurora Global DatabaseDisaster RecoveryMulti-region deployments - Question #299Resilient Cloud Solutions
A company is building a serverless application that uses AWS Lambda functions to process data. A BeginResponse Lambda function initializes data in response to specific application...
Serverless architecturesAWS LambdaAmazon SQSFan-out patternConcurrency control - Question #300Resilient Cloud Solutions
A company operates a globally deployed product out of multiple AWS Regions. The company's DevOps team needs to use Amazon API Gateway to deploy an API to support the product. The A...
API Gateway regional endpointsMulti-region architectureGlobal availabilityCustom domainsRoute 53 - Question #301SDLC Automation
A DevOps engineer uses AWS CodeBuild to frequently produce software packages. The CodeBuild project builds large Docker images that the DevOps engineer can use across multiple buil...
AWS CodeBuildDocker image cachingAmazon ECRBuild performance optimization - Question #302Security and Compliance
A large company recently acquired a small company. The large company invited the small company to join the large company's existing organization in AWS Organizations as a new OU. A...
AWS OrganizationsService Control Policies (SCPs)IAM conditionsEC2 instance typesRegional restrictions - Question #303Monitoring and Logging
A DevOps team manages infrastructure for an application. The application uses long-running processes to process items from an Amazon Simple Queue Service (Amazon SQS) queue. The ap...
Amazon SQSCloudWatch AlarmsQueue monitoringBacklog detection