Skip to content

DevOps Engineer - Professional Practice Questions

Prepare for DOP-C02 with more than an answer.

286 questions in the full set20 sample questionsUpdated Feb 3, 2026

Unlock the full exam and previous versions

  • v1Version 1 286 questions Current
  • DOP-C01Legacy AWS DevOps Engineer Professional 264 questions Locked
Exam fee
$300 USD
Level
Professional
Valid for
3 years
Domains covered on the exam 6
  1. SDLC Automation22%
  2. Configuration Management and Infrastructure as Code17%
  3. Resilient Cloud Solutions15%
  4. Monitoring and Logging15%
  5. Incident and Event Response14%
  6. Security and Compliance17%
  1. 1

    A DevOps engineer is configuring a centralized logging solution. Logs from multiple AWS accounts are streamed to a central Amazon Kinesis Data Firehose in a dedicated logging account. The engineer needs to transform the incoming log data to a standardized JSON format and enrich it with metadata before delivering it to Amazon S3 for analysis with Amazon Athena. The solution must be serverless and scale automatically. What should be configured in Kinesis Data Firehose to meet these requirements?

    Show answer details

    Correct answer: C

    Kinesis Data Firehose has a built-in feature for data transformation that integrates directly with AWS Lambda. You can enable this feature and provide a Lambda function that Firehose will invoke for each batch of records. The Lambda function receives the records, performs the necessary transformation (like converting to JSON and adding metadata), and returns the transformed records to Firehose. Firehose then delivers the processed data to the destination. This is a fully managed, serverless, and scalable solution for real-time data processing within the stream. Record format conversion is limited to converting between JSON and Parquet/ORC and cannot perform custom enrichment.

  2. 2

    A company has a legacy monolithic application deployed on a single, large Amazon EC2 instance. Due to licensing constraints, the application cannot be horizontally scaled. The business requires an automated recovery solution with a Recovery Time Objective (RTO) of less than 5 minutes if the instance or its Availability Zone (AZ) fails. The solution must be as cost-effective as possible. What is the most appropriate solution?

    Show answer details

    Correct answer: B

    Using an Auto Scaling group with min/max/desired capacity of 1 across multiple AZs is the standard and most effective pattern for ensuring the resilience of a single-instance application. If the instance fails its health check (either EC2 status checks or ELB health checks if one is used), the Auto Scaling group will automatically terminate it and launch a new replacement instance in one of the configured AZs. If an entire AZ fails, the Auto Scaling group will launch the replacement in a healthy AZ. This provides both instance-level and AZ-level automated recovery. The EC2 recover action only works for underlying hardware failures and does not protect against AZ failure. A warm standby is more expensive. A Lambda function adds unnecessary complexity for a standard use case.

  3. 3

    A DevOps team is using AWS CodeArtifact to manage Python package dependencies for their applications. They need to ensure that their AWS CodeBuild projects can reliably access packages from both their internal CodeArtifact repository and the public PyPI repository. The solution should prevent interruptions if the public PyPI repository is unavailable and should provide centralized control over which public packages are used. What is the correct way to configure this?

    Show answer details

    Correct answer: B

    The correct and recommended pattern is to configure the internal CodeArtifact repository with an upstream connection to the public repository (e.g., pypi-store). When CodeBuild (or a developer) requests a package, it queries only the internal CodeArtifact repository. If the package is not found locally, CodeArtifact will fetch it from the upstream public repository and cache it. Subsequent requests for the same package will be served from the CodeArtifact cache, ensuring availability even if the public repository is down and providing a centralized audit trail. Configuring two index URLs in pip can lead to unpredictable behavior and doesn't provide the caching and control benefits.

  4. 4

    True or False: An AWS CloudFormation StackSet allows you to create, update, or delete stacks across multiple AWS accounts and Regions with a single operation, but it requires that the target accounts all belong to the same AWS Organization.

    Show answer details

    Correct answer: B

    This is false. AWS CloudFormation StackSets have two permission models: service-managed and self-service. Service-managed permissions integrate with AWS Organizations and are the easier way to manage deployments within an organization. However, self-service permissions allow you to deploy StackSets to accounts outside of your organization by creating the necessary IAM roles in the administrator and target accounts manually. Therefore, belonging to the same organization is not a strict requirement.

  5. 5

    An application is experiencing performance degradation under heavy load. The DevOps team used AWS X-Ray to trace requests and generated the following service map. The trace data indicates that calls from the Auth Service Lambda to the Users DB (Amazon DynamoDB) are a significant bottleneck. What specific information within the X-Ray trace details for a slow request would most effectively help a developer pinpoint the root cause of the DynamoDB latency?

    graph TD User --> API[API Gateway] API --> AuthService[Auth Service - Lambda] AuthService --> UsersDB[(Users DB - DynamoDB)] API --> OrderService[Order Service - Lambda] OrderService --> OrdersDB[(Orders DB - DynamoDB)]

    Show answer details

    Correct answer: C

    AWS X-Ray captures detailed information in subsegments for calls to AWS services. For a DynamoDB call, the subsegment will contain the exact API operation used (like GetItem, Query, or Scan), the table name, and crucial performance data like ConsumedCapacity. High ConsumedCapacity or an inefficient operation like Scan would be a clear indicator of the performance issue's root cause, allowing a developer to optimize the query or provision more capacity. The status code would likely be 200 (OK) even for a slow query. Annotations are for custom filtering and don't explain latency. The Lambda cold start time is a separate issue.

  6. 6

    A financial services company is modernizing its application deployment strategy. They are using AWS CodePipeline and AWS CodeDeploy for blue/green deployments to an Amazon ECS cluster fronted by an Application Load Balancer (ALB). A critical requirement is to run a suite of integration tests against the new 'green' environment before any production traffic is shifted. These tests are invoked via an API call and can take up to 10 minutes to complete. If the tests fail, the deployment must be automatically rolled back without any traffic ever reaching the new version. Which configuration in the CodeDeploy AppSpec file will achieve this?

    Show answer details

    Correct answer: B

    The AfterAllowTestTraffic hook is specifically designed for running tests in a blue/green deployment after the test listener is active but before production traffic is shifted. Triggering a Lambda function from this hook allows for external test suites to be run. If the Lambda function exits with an error (non-zero exit code), CodeDeploy will automatically initiate a rollback, preventing the faulty green environment from serving production traffic. BeforeInstall is too early in the lifecycle. AfterInstall happens before the task set is stable and ready for testing. BeforeAllowTraffic is for tasks just before the test listener traffic is allowed, which is also too early for end-to-end tests.

  7. 7

    A large enterprise uses AWS Organizations and has a mandate that all Amazon S3 buckets must block public access and have versioning enabled for compliance. A DevOps engineer needs to implement an automated, scalable solution to enforce this policy across all existing and future member accounts. The solution must automatically remediate any non-compliant S3 buckets. Which approach provides the most scalable and centrally managed solution?

    Show answer details

    Correct answer: B

    AWS Config conformance packs are designed for this exact purpose. They allow you to package a collection of AWS Config rules and remediation actions that can be easily deployed as a single entity across an entire organization from the management account. This is more scalable and maintainable than managing individual StackSets for EventBridge rules and Lambda functions. Service-managed SCPs can prevent certain actions but cannot remediate existing resources. A single Lambda function in the management account would require complex cross-account permissions to remediate resources in member accounts.

  8. 8

    A media company processes large video files using a fleet of Amazon EC2 instances. The processing workflow is orchestrated by AWS Step Functions. A key step involves an AWS Lambda function that analyzes video metadata. This function occasionally fails due to transient network issues when calling an external service. The DevOps team needs to implement a robust retry mechanism for this specific Lambda function within the Step Functions state machine, but simple retries are not sufficient. The retries should occur with an increasing delay, and the rate of increase should be less aggressive than the default exponential backoff. Which Retry block configuration should be used in the state machine definition to achieve this?

    Show answer details

    Correct answer: C

    In AWS Step Functions, the Retry block allows for fine-grained control over error handling. To achieve an increasing delay that is less aggressive than the default exponential backoff (which has a BackoffRate of 2.0), you must specify a BackoffRate between 1.0 and 2.0. A value of 1.5 will cause the interval to increase by 50% after each attempt, which is less aggressive than the default doubling. A BackoffRate of 2.0 is the default exponential backoff. Not specifying a BackoffRate also defaults to 2.0. ErrorEquals: ["States.TaskFailed"] is appropriate for catching failures within the Lambda function execution.

  9. 9

    A DevOps team is managing a microservices application where services communicate via Amazon SNS topics and Amazon SQS queues. They are observing that some messages sent to an SQS queue are being processed multiple times, causing data duplication. The SQS queue is a standard queue, and the consumer is an AWS Lambda function. The team has determined that the Lambda function occasionally times out while processing a message, which leads to the message becoming visible again in the queue and being re-processed. What is the most effective solution to prevent duplicate processing while minimizing changes to the overall architecture?

    Show answer details

    Correct answer: D

    Standard SQS queues provide at-least-once delivery, which can result in duplicate messages, especially during consumer failures. FIFO queues provide exactly-once processing (within a 5-minute deduplication interval) and preserve message order. By enabling content-based deduplication, SQS will use a SHA-256 hash of the message body to generate the message deduplication ID, automatically preventing duplicate messages from being sent. This is the most direct and architecturally sound way to solve the duplicate processing issue at the source without complex application logic. While making the Lambda idempotent is a good practice, changing the queue to FIFO is a more robust solution provided by the infrastructure itself.

  10. 10

    A development team uses AWS CloudFormation to manage their serverless application, which consists of AWS Lambda functions and an Amazon API Gateway. They need to securely manage database connection strings for different environments (dev, staging, prod) without hardcoding them in the CloudFormation template or committing them to source control. The solution must allow for automatic rotation of credentials in the future. Which combination of services provides the most secure and manageable solution? (Select TWO)

    Show answer details

    Correct answer: A, D

Create an account to continue.