AWS practice questions: 849 questions with full explanations
- Questions on the exam
- about 75 — vendor indicates, no fixed count published
- Time allowed
- 180 minutes format →
849 practice questions for AWS Certified DevOps Engineer – Professional, grouped by exam domain. Every question below shows all four options, which one is correct, and why each of the other three is not — the wrong answers are where most candidates lose marks.
Not sure where you stand? Take the free 5-min AWS readiness check →
AWS certification: requirements, cost and exam format → · AWS exam format → ·
Questions by domain
- 1: SDLC Automation — 187 questions →
- 2: Configuration Management and IaC — 144 questions →
- 6: Security and Compliance — 144 questions →
- 3: Resilient Cloud Solutions — 128 questions →
- 4: Monitoring and Logging — 127 questions →
- 5: Incident and Event Response — 119 questions →
Sample questions
Use one CodePipeline and CodeBuild: Which design best satisfies these requirements?
- Create separate CodePipelines in every account, rebuild from the shared repository independently, and use account-local keys without cross-account role assumptions.Separate pipelines increase management overhead, independent builds can differ, and the design lacks the required auditable cross-account access model.
- Use a shared S3 artifact bucket with default encryption, grant deployment accounts broad bucket administration, and deploy from copied artifacts.Default encryption and broad bucket administration do not provide the required customer-managed key controls or least-privilege auditable access.
- Use one CodePipeline and CodeBuild, build once, encrypt artifacts with a customer-managed KMS key, use scoped cross-account roles, and approve production before deployment. ✓The centralized pipeline creates one artifact, encrypts it with a customer-managed key, and promotes it through cross-account roles. A manual approval before the production action provides the required control without rebuilding.
- Store deployment credentials in encrypted repository variables, rebuild the application in each target account, and approve production after deployment starts.Repository credentials remain long-lived secret material, independent builds violate identical-artifact promotion, and approval occurs too late.
All 187 1: SDLC Automation questions →
Use service-managed StackSets: Which design should the platform team implement?
- Use separate CodePipeline actions for each account and Region.This requires custom orchestration and does not inherently enroll future organizational accounts or provide StackSet operation controls.
- Create a nested stack in the management account and export resources to member accounts.Nested stacks remain within the owning account and cannot provision resources across member accounts and Regions.
- Use self-managed StackSets with manually created administrator and execution roles.Self-managed StackSets can deploy across accounts but require the manual role administration explicitly excluded by the scenario.
- Use service-managed StackSets. ✓Service-managed StackSets support Organizations targeting, automatic deployments, regional ordering, failure tolerance, and AWS-managed cross-account role setup.
All 144 2: Configuration Management and IaC questions →
Give each ECS task a narrowly scoped task role and block: Which design best enforces least privilege?
- Attach administrator permissions to the task role, then use deployment pipelines and review approvals to control when tasks can exercise them.Approval processes do not enforce runtime least privilege, and administrative task credentials remain available if a container is compromised.
- Give each ECS task a narrowly scoped task role and block access to instance-profile credentials. ✓The task role can limit S3 resources and KMS actions, while instance metadata protections prevent a compromised task from obtaining the broader EC2 profile.
- Attach the S3 and KMS permissions to the ECS task execution role and omit an application task role.The execution role supports ECS operations such as image retrieval and logging; application API calls require a separate task role.
- Use the broad instance profile for all task API calls and block only selected S3 actions.A shared instance profile exposes host-level permissions to every task and does not isolate workload credentials or narrowly scope KMS access.
All 144 6: Security and Compliance questions →
Run active-active services with DynamoDB global tables: Which deployment design best satisfies the resiliency
- Run one Region with Multi-AZ compute, RDS Multi-AZ, and daily S3 backups.These measures address Availability Zone or point-in-time recovery scenarios, not active traffic and rapid recovery after complete Regional failure.
- Run active-active services with DynamoDB global tables for changing metadata, S3 cross-Region replication for video, and health-based traffic routing. ✓This removes regional dependencies from compute, mutable metadata, immutable content, and traffic routing. The design still requires validating replication lag and failover timing.
- Use CloudFront with one Regional origin and origin failover between Availability Zone endpoints.This can improve content delivery availability, but it does not provide a second active Region or replicate entitlement and session state.
- Run active-active compute with health-based routing, but retain entitlements and session metadata in the primary Region.The secondary Region remains dependent on the failed Region for changing state, violating the Regional recovery and RPO requirements.
All 128 3: Resilient Cloud Solutions questions →
Centralize logs in CloudWatch Logs for 14 days: Which design best satisfies these requirements?
- Create a cross-account OpenSearch domain, grant developers read access, and retain indexed records for seven years.OpenSearch supports searching but requires cluster operations and its index retention and access controls do not by themselves provide immutable compliance retention.
- Centralize logs in CloudWatch Logs, set 14-day retention, and restrict log-group deletion to the platform team.This provides search and access control but does not provide immutable or tamper-resistant retention because an authorized administrator can still delete records or log groups.
- Send logs to a security-owned S3 bucket with versioning and use CloudWatch Logs Insights only when investigators need searches.Versioning supports recovery from some overwrites or deletions but does not establish immutable retention, and S3 alone does not provide the required convenient 14-day log search experience.
- Centralize logs in CloudWatch Logs for 14 days, and deliver a copy to a security-owned S3 bucket using Object Lock in compliance mode with the required retention period. ✓CloudWatch Logs provides managed short-term search and preserves centralized source context. A security-owned S3 bucket with Object Lock in compliance mode provides protected retention that application teams cannot shorten or delete.
All 127 4: Monitoring and Logging questions →
Use an SQS event source mapping: Which design should the team choose?
- Write a Lambda poller that receives each message, processes it, and deletes it after success.This is executable, but custom polling violates the managed-polling requirement and requires the team to implement scaling and retry handling.
- Publish each job to SNS and invoke Lambda asynchronously, relying on Lambda’s service retries alone.This replaces the requested SQS consumer workflow and does not provide SQS visibility and redrive handling for the existing queue.
- Use an EventBridge rule with a target DLQ, then invoke Lambda directly for each submitted job.An EventBridge target DLQ records delivery failures, not failures after Lambda accepts and processes an SQS job.
- Use an SQS event source mapping, align visibility with processing time, and configure an SQS redrive policy. ✓The event source mapping provides managed polling and scaling. Visibility settings allow retries, and the redrive policy moves repeatedly failed messages to a durable DLQ.
All 119 5: Incident and Event Response questions →
Trigger CodePipeline from an immutable commit: Which deployment design is most appropriate?
- Trigger CodePipeline from a branch head, retrieve tenant settings from Secrets Manager, and rebuild the image separately for each environment.A mutable branch head and separate environment builds do not reliably identify the exact staged commit or preserve the validated binary.
- Trigger CodePipeline from an immutable commit, build once, retrieve tenant settings from Secrets Manager, and promote that artifact. ✓This identifies the revision, externalizes tenant configuration, promotes one immutable artifact, and supports rollback by redeploying an earlier artifact.
- Use Git tags to trigger CodeBuild, embed tenant settings during compilation, and deploy each environment from its own image.Embedding tenant settings violates the requirement that configuration not be committed, and environment-specific images prevent identical-artifact promotion.
- Create one pipeline per tenant, rebuild from the selected commit for every environment, and store deployment credentials in repository configuration.Per-environment rebuilds violate identical-artifact promotion, while repository configuration is an inappropriate location for deployment credentials.
All 187 1: SDLC Automation questions →
Use Systems Manager for patching: Which design is most appropriate?
- Use Systems Manager for patching, inventory, and commands; AppConfig for gradual runtime configuration; and AWS Config for resource compliance. ✓Systems Manager provides managed-instance operations, AppConfig supports validated staged configuration deployment and rollback, and AWS Config evaluates resource configuration compliance without performing the rollout.
- Use Secrets Manager rotation for nonsecret settings and Systems Manager only for inventory.Secrets Manager rotation targets secrets, and limiting Systems Manager to inventory omits required patching and remote command operations.
- Use CloudFormation updates for patching and runtime configuration, replacing instances when required.CloudFormation manages infrastructure changes but is not the appropriate routine fleet-operations or gradual runtime-configuration service.
- Use AWS Config remediation for patch installation and AppConfig only for compliance reporting.Config can evaluate compliance and initiate remediation, but AppConfig is the configuration rollout service, not the compliance reporting service.
All 144 2: Configuration Management and IaC questions →
AWS exam: the facts
How many questions are on the AWS exam?
Around 75. The vendor does not publish a fixed count for AWS, so this is the figure it indicates rather than a guaranteed number.
How long is the AWS exam?
180 minutes. Across 75 questions that is about 144 seconds per question.
What topics does the AWS exam cover?
6 domains: 1: SDLC Automation, 2: Configuration Management and IaC, 6: Security and Compliance, 3: Resilient Cloud Solutions, 4: Monitoring and Logging, 5: Incident and Event Response. Weights: 1: SDLC Automation 22%, 2: Configuration Management and IaC 17%, 6: Security and Compliance 17%, 3: Resilient Cloud Solutions 15%, 4: Monitoring and Logging 15%, 5: Incident and Event Response 14%.
How many AWS practice questions does Certsqill have?
849, spread across 6 exam domains. Every one shows all options, which is correct, and why each of the others is not.
Would you pass AWS today?
Five minutes, and you get a score per domain — not one number, but which section to open tonight.
Test your AWS readiness — free