Skip to content

DevOps Engineer - Professional Practice Questions

Prepare for DOP-C02 with more than an answer.

286 questions in the full set20 sample questionsUpdated Feb 3, 2026

Unlock the full exam and previous versions

  • v1Version 1 286 questions Current
  • DOP-C01Legacy AWS DevOps Engineer Professional 264 questions Locked
Exam fee
$300 USD
Level
Professional
Valid for
3 years
Domains covered on the exam 6
  1. SDLC Automation22%
  2. Configuration Management and Infrastructure as Code17%
  3. Resilient Cloud Solutions15%
  4. Monitoring and Logging15%
  5. Incident and Event Response14%
  6. Security and Compliance17%
  1. 1

    A gaming company is deploying a new version of its backend application, which runs on Amazon EC2 instances managed by an Auto Scaling group. The deployment is handled by AWS CodeDeploy using a blue/green strategy. The DevOps team wants to monitor a key application metric, ActivePlayerSessions, during the deployment. If this metric drops below a certain threshold on the new 'green' instances after traffic is shifted, the deployment should automatically roll back. Which steps are necessary to configure this automated rollback? (Select TWO)

    Show answer details

    Correct answer: B, C

  2. 2

    A DevOps team is managing a stateful application on a fleet of Amazon EC2 instances. The team uses AWS Systems Manager Patch Manager to apply security patches during a weekly maintenance window. After a recent patching operation, several instances failed to reboot correctly, causing an application outage. The root cause was a conflict between a patch and the application's startup service. The team needs to prevent this from happening again. What is the most effective way to add a verification step to the patching process?

    Show answer details

    Correct answer: C

    The AWS-RunPatchBaseline document in Systems Manager has built-in support for pre- and post-patching hooks. By specifying a script for the post-reboot hook, the team can automate the verification of the application's health immediately after the instance reboots from patching. If this verification script fails (returns a non-zero exit code), the overall patching task for that instance will fail, making it easy to identify problematic instances in the execution history. This is the most integrated and direct way to add verification to the existing Patch Manager workflow.

  3. 3

    A DevOps engineer is configuring a centralized logging solution. Logs from multiple AWS accounts are streamed to a central Amazon Kinesis Data Firehose in a dedicated logging account. The engineer needs to transform the incoming log data to a standardized JSON format and enrich it with metadata before delivering it to Amazon S3 for analysis with Amazon Athena. The solution must be serverless and scale automatically. What should be configured in Kinesis Data Firehose to meet these requirements?

    Show answer details

    Correct answer: C

    Kinesis Data Firehose has a built-in feature for data transformation that integrates directly with AWS Lambda. You can enable this feature and provide a Lambda function that Firehose will invoke for each batch of records. The Lambda function receives the records, performs the necessary transformation (like converting to JSON and adding metadata), and returns the transformed records to Firehose. Firehose then delivers the processed data to the destination. This is a fully managed, serverless, and scalable solution for real-time data processing within the stream. Record format conversion is limited to converting between JSON and Parquet/ORC and cannot perform custom enrichment.

  4. 4

    A company has a legacy monolithic application deployed on a single, large Amazon EC2 instance. Due to licensing constraints, the application cannot be horizontally scaled. The business requires an automated recovery solution with a Recovery Time Objective (RTO) of less than 5 minutes if the instance or its Availability Zone (AZ) fails. The solution must be as cost-effective as possible. What is the most appropriate solution?

    Show answer details

    Correct answer: B

    Using an Auto Scaling group with min/max/desired capacity of 1 across multiple AZs is the standard and most effective pattern for ensuring the resilience of a single-instance application. If the instance fails its health check (either EC2 status checks or ELB health checks if one is used), the Auto Scaling group will automatically terminate it and launch a new replacement instance in one of the configured AZs. If an entire AZ fails, the Auto Scaling group will launch the replacement in a healthy AZ. This provides both instance-level and AZ-level automated recovery. The EC2 recover action only works for underlying hardware failures and does not protect against AZ failure. A warm standby is more expensive. A Lambda function adds unnecessary complexity for a standard use case.

  5. 5

    A DevOps team is using AWS CodeArtifact to manage Python package dependencies for their applications. They need to ensure that their AWS CodeBuild projects can reliably access packages from both their internal CodeArtifact repository and the public PyPI repository. The solution should prevent interruptions if the public PyPI repository is unavailable and should provide centralized control over which public packages are used. What is the correct way to configure this?

    Show answer details

    Correct answer: B

    The correct and recommended pattern is to configure the internal CodeArtifact repository with an upstream connection to the public repository (e.g., pypi-store). When CodeBuild (or a developer) requests a package, it queries only the internal CodeArtifact repository. If the package is not found locally, CodeArtifact will fetch it from the upstream public repository and cache it. Subsequent requests for the same package will be served from the CodeArtifact cache, ensuring availability even if the public repository is down and providing a centralized audit trail. Configuring two index URLs in pip can lead to unpredictable behavior and doesn't provide the caching and control benefits.

  6. 6

    True or False: An AWS CloudFormation StackSet allows you to create, update, or delete stacks across multiple AWS accounts and Regions with a single operation, but it requires that the target accounts all belong to the same AWS Organization.

    Show answer details

    Correct answer: B

    This is false. AWS CloudFormation StackSets have two permission models: service-managed and self-service. Service-managed permissions integrate with AWS Organizations and are the easier way to manage deployments within an organization. However, self-service permissions allow you to deploy StackSets to accounts outside of your organization by creating the necessary IAM roles in the administrator and target accounts manually. Therefore, belonging to the same organization is not a strict requirement.

  7. 7

    An application is experiencing performance degradation under heavy load. The DevOps team used AWS X-Ray to trace requests and generated the following service map. The trace data indicates that calls from the Auth Service Lambda to the Users DB (Amazon DynamoDB) are a significant bottleneck. What specific information within the X-Ray trace details for a slow request would most effectively help a developer pinpoint the root cause of the DynamoDB latency?

    graph TD User --> API[API Gateway] API --> AuthService[Auth Service - Lambda] AuthService --> UsersDB[(Users DB - DynamoDB)] API --> OrderService[Order Service - Lambda] OrderService --> OrdersDB[(Orders DB - DynamoDB)]

    Show answer details

    Correct answer: C

    AWS X-Ray captures detailed information in subsegments for calls to AWS services. For a DynamoDB call, the subsegment will contain the exact API operation used (like GetItem, Query, or Scan), the table name, and crucial performance data like ConsumedCapacity. High ConsumedCapacity or an inefficient operation like Scan would be a clear indicator of the performance issue's root cause, allowing a developer to optimize the query or provision more capacity. The status code would likely be 200 (OK) even for a slow query. Annotations are for custom filtering and don't explain latency. The Lambda cold start time is a separate issue.

  8. 8

    A financial services company is modernizing its application deployment strategy. They are using AWS CodePipeline and AWS CodeDeploy for blue/green deployments to an Amazon ECS cluster fronted by an Application Load Balancer (ALB). A critical requirement is to run a suite of integration tests against the new 'green' environment before any production traffic is shifted. These tests are invoked via an API call and can take up to 10 minutes to complete. If the tests fail, the deployment must be automatically rolled back without any traffic ever reaching the new version. Which configuration in the CodeDeploy AppSpec file will achieve this?

    Show answer details

    Correct answer: B

    The AfterAllowTestTraffic hook is specifically designed for running tests in a blue/green deployment after the test listener is active but before production traffic is shifted. Triggering a Lambda function from this hook allows for external test suites to be run. If the Lambda function exits with an error (non-zero exit code), CodeDeploy will automatically initiate a rollback, preventing the faulty green environment from serving production traffic. BeforeInstall is too early in the lifecycle. AfterInstall happens before the task set is stable and ready for testing. BeforeAllowTraffic is for tasks just before the test listener traffic is allowed, which is also too early for end-to-end tests.

  9. 9

    A large enterprise uses AWS Organizations and has a mandate that all Amazon S3 buckets must block public access and have versioning enabled for compliance. A DevOps engineer needs to implement an automated, scalable solution to enforce this policy across all existing and future member accounts. The solution must automatically remediate any non-compliant S3 buckets. Which approach provides the most scalable and centrally managed solution?

    Show answer details

    Correct answer: B

    AWS Config conformance packs are designed for this exact purpose. They allow you to package a collection of AWS Config rules and remediation actions that can be easily deployed as a single entity across an entire organization from the management account. This is more scalable and maintainable than managing individual StackSets for EventBridge rules and Lambda functions. Service-managed SCPs can prevent certain actions but cannot remediate existing resources. A single Lambda function in the management account would require complex cross-account permissions to remediate resources in member accounts.

  10. 10

    A media company processes large video files using a fleet of Amazon EC2 instances. The processing workflow is orchestrated by AWS Step Functions. A key step involves an AWS Lambda function that analyzes video metadata. This function occasionally fails due to transient network issues when calling an external service. The DevOps team needs to implement a robust retry mechanism for this specific Lambda function within the Step Functions state machine, but simple retries are not sufficient. The retries should occur with an increasing delay, and the rate of increase should be less aggressive than the default exponential backoff. Which Retry block configuration should be used in the state machine definition to achieve this?

    Show answer details

    Correct answer: C

    In AWS Step Functions, the Retry block allows for fine-grained control over error handling. To achieve an increasing delay that is less aggressive than the default exponential backoff (which has a BackoffRate of 2.0), you must specify a BackoffRate between 1.0 and 2.0. A value of 1.5 will cause the interval to increase by 50% after each attempt, which is less aggressive than the default doubling. A BackoffRate of 2.0 is the default exponential backoff. Not specifying a BackoffRate also defaults to 2.0. ErrorEquals: ["States.TaskFailed"] is appropriate for catching failures within the Lambda function execution.

Create an account to continue.