DOP-C02 Sample Questions

DOP-C02 Sample Questions & Answers

Automating the software delivery lifecycle with CI/CD pipelines carries the top share, ahead of security automation tied with infrastructure as code, building fault-tolerant and highly available systems, monitoring and logging, and responding to incidents.

Launch the full DOP-C02 simulator →

Showing 10 of 20 free samples.

  1. Question 1Intermediate

    SDLC Automation · Build and manage artifacts.

    A DevOps engineer is optimizing a CI/CD pipeline in AWS CodePipeline. The build stage, using AWS CodeBuild, takes a long time because it downloads a large number of dependencies on every run. The engineer wants to speed up the build process by caching these dependencies. The build environment must remain clean for each run, ensuring no stale files from previous builds interfere with the current one. Which caching mode in CodeBuild should be used?

    Show answer & explanation

    Correct answer: C

    Amazon S3 caching mode is the best choice here. It allows you to store a cache in an S3 bucket. At the beginning of a build, the cache is downloaded to the local build environment. At the end, the cache is re-uploaded with any changes. This persists dependencies between builds. Local caching (source cache) reuses the Docker container on the build host, which can lead to stale file issues if not managed carefully, violating the 'clean environment' requirement. The Docker layer cache option is for caching layers of a Docker image being built, not general dependencies. 'No cache' is the current slow behavior.

  2. Question 2Advanced

    Monitoring and Logging · Audit, monitor, and analyze logs and metrics to detect issues.

    A financial analytics platform runs on Amazon EC2 instances within an Auto Scaling group. During end-of-day processing, these instances experience very high CPU utilization. The operations team needs to receive an alert if the average CPU utilization across the fleet exceeds 90% for a continuous period of 5 minutes. However, to avoid false alarms during initial instance startup, the alarm should not consider data points from instances that are less than 10 minutes old. How can this be achieved using a single Amazon CloudWatch alarm?

    Show answer & explanation

    Correct answer: D

    This problem requires advanced CloudWatch functionality. A simple alarm will include all instances. A Lambda function adds complexity. The most elegant solution is to use CloudWatch metric math. By creating an expression like AVG(IF(AGE(m1) > 600, m1)), you can create a dynamic alarm. The METRICS() function can be used to select all CPUUtilization metrics from the Auto Scaling group. The AGE() function returns the age of a metric's latest datapoint in seconds. The IF statement then includes only metrics older than 600 seconds (10 minutes) in the final AVG calculation. This allows a single alarm to dynamically adjust to the fleet while ignoring new instances for a specified period.

  3. Question 3Beginner

    SDLC Automation · Implement deployment strategies for instance, container, and serverless environments.

    True or False: When using AWS CodeDeploy with an EC2/On-Premises compute platform, the appspec.yml file must be placed at the root of the application revision directory structure.

    Show answer & explanation

    Correct answer: A

    This is true. For EC2/On-Premises deployments, AWS CodeDeploy requires the Application Specification File (AppSpec file), which must be named appspec.yml or appspec.yaml, to be located in the root of the directory structure of an application's source code.

  4. Question 4Intermediate

    Security and Compliance · Deploy automation to create, onboard, and secure AWS accounts in a multi-account or multi-Region environment.

    An organization is using AWS Control Tower to manage a multi-account environment. A new compliance requirement dictates that all Amazon EBS volumes created must be of the gp3 type to ensure a baseline level of performance and cost-efficiency. Any attempt to create a volume of a different type (e.g., gp2, io1) must be denied. The enforcement must be proactive. How should a DevOps engineer implement this control across the entire organization?

    Show answer & explanation

    Correct answer: B

    Service Control Policies (SCPs) are the correct tool for proactively enforcing permissions boundaries across an entire AWS Organization. By creating an SCP with a Deny effect for the ec2:CreateVolume action and using a condition key aws:RequestTag/ebs:VolumeType with StringNotEquals for gp3, you can prevent the creation of any non-compliant EBS volumes before they are even provisioned. This is a proactive control. AWS Config is a detective control; it detects non-compliance after the resource is created. CloudFormation hooks are specific to CloudFormation and won't prevent manual creation. IAM permissions boundaries apply to entities but are not as broad as SCPs for organizational enforcement.

  5. Question 5Intermediate

    SDLC Automation · Implement CI/CD pipelines

    A DevOps engineer needs to deploy a serverless application defined using the AWS Serverless Application Model (AWS SAM). The deployment process must be fully automated through AWS CodePipeline. The pipeline needs to package the SAM application, generate a change set for review, and then execute the change set after a manual approval step. Which sequence of actions in CodePipeline is correct for this workflow?

    Show answer & explanation

    Correct answer: C

    The correct workflow for deploying a SAM application with a manual review step is as follows: 1. Source: Get the SAM template and code. 2. Build: Use AWS CodeBuild to run sam package. This command packages the application artifacts, uploads them to S3, and produces a new template file (packaged.yaml) with S3 references. 3. Deploy (Create Change Set): Use the AWS CloudFormation provider in CodePipeline with the action CREATE_CHANGESET. This uses the packaged.yaml to create a change set, which shows the proposed changes without applying them. 4. Manual Approval: A manual approval gate is inserted for review. 5. Deploy (Execute Change Set): After approval, use another AWS CloudFormation action with EXECUTE_CHANGESET to apply the previously created changes.

  6. Question 6Intermediate

    Resilient Cloud Solutions · Implement automated recovery processes to meet RTO and RPO requirements.

    An application is deployed across multiple AWS Regions for high availability and low latency. The architecture uses Amazon Route 53 with latency-based routing to direct users to the nearest region. Each region has an Application Load Balancer (ALB) and an Auto Scaling group of Amazon EC2 instances. To ensure resilience, if the application in one region becomes unhealthy, all traffic must be automatically directed to the other healthy regions. How should the health checks be configured in Route 53 to achieve this failover behavior?

    Show answer & explanation

    Correct answer: B

    When you use an alias record to point to an Elastic Load Balancer, Route 53 can use the health checks that are part of the load balancer itself. By setting Evaluate Target Health to true on the alias record, Route 53 will consider the record healthy only if the ALB is healthy (i.e., it has at least one healthy target instance). If the ALB in a region becomes unhealthy, Route 53 will automatically stop sending traffic to it, effectively failing over to the next-best latency region that is healthy. This is the most direct and efficient way to integrate ALB health with Route 53 routing decisions.

  7. Question 7Intermediate

    Security and Compliance · Implement security monitoring and auditing solutions.

    A company's security team requires a centralized, immutable log of all API calls made to sensitive services like AWS KMS and IAM across all accounts in their AWS Organization. A DevOps engineer has configured AWS CloudTrail in the management account to create an organization trail, logging all events to a central Amazon S3 bucket. To meet the immutability requirement, which S3 feature should be enabled on the central logging bucket?

    Show answer & explanation

    Correct answer: C

    S3 Object Lock is the AWS feature designed to meet Write-Once-Read-Many (WORM) requirements. When enabled on a bucket, you can set retention periods on objects. In Compliance mode, a protected object version can't be overwritten or deleted by any user, including the root user in your AWS account, for the duration of the retention period. This provides the strongest guarantee of immutability. Governance mode is similar but allows users with special permissions to bypass the lock. MFA Delete adds a layer of protection against accidental deletion but doesn't provide true immutability like Object Lock.

  8. Question 8Beginner

    Configuration Management and IaC · Define cloud infrastructure and reusable components to provision and manage systems throughout their lifecycle.

    A team is managing their infrastructure using AWS CloudFormation. They have noticed that on several occasions, out-of-band changes were made to resources directly through the AWS Console, causing the stack's state to be inconsistent with the actual infrastructure. They need a way to identify these unauthorized changes automatically before applying any further stack updates. What CloudFormation feature should they use?

    Show answer & explanation

    Correct answer: C

    CloudFormation Drift Detection is the feature specifically designed to solve this problem. It allows you to detect whether a stack's actual configuration has 'drifted' from its expected configuration as defined in the template. Running drift detection will show which resources have been modified, added, or deleted outside of CloudFormation's control. Change Sets are for previewing changes before updating a stack, and Stack Policies are for preventing certain updates to stack resources.

  9. Question 9AdvancedSelect 2

    SDLC Automation · Implement deployment strategies for instance, container, and serverless environments.

    A gaming company is deploying a new version of its backend application, which runs on Amazon EC2 instances managed by an Auto Scaling group. The deployment is handled by AWS CodeDeploy using a blue/green strategy. The DevOps team wants to monitor a key application metric, ActivePlayerSessions, during the deployment. If this metric drops below a certain threshold on the new 'green' instances after traffic is shifted, the deployment should automatically roll back. Which steps are necessary to configure this automated rollback? (Select TWO)

    Show answer & explanation

    Correct answers: B, C

  10. Question 10Intermediate

    Configuration Management and IaC · Design and build automated solutions for complex tasks and large-scale environments.

    A DevOps team is managing a stateful application on a fleet of Amazon EC2 instances. The team uses AWS Systems Manager Patch Manager to apply security patches during a weekly maintenance window. After a recent patching operation, several instances failed to reboot correctly, causing an application outage. The root cause was a conflict between a patch and the application's startup service. The team needs to prevent this from happening again. What is the most effective way to add a verification step to the patching process?

    Show answer & explanation

    Correct answer: C

    The AWS-RunPatchBaseline document in Systems Manager has built-in support for pre- and post-patching hooks. By specifying a script for the post-reboot hook, the team can automate the verification of the application's health immediately after the instance reboots from patching. If this verification script fails (returns a non-zero exit code), the overall patching task for that instance will fail, making it easy to identify problematic instances in the execution history. This is the most integrated and direct way to add verification to the existing Patch Manager workflow.

Ready for the real thing?

The full DOP-C02 simulator has every exam-style question, timed mode, and instant scoring.