AWS: 849 practice questions with explanations
48 hours only — 15% off every course with code SAVE15. Browse courses →48h · 15% off all courses · code SAVE15 →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

AWS practice questions: 849 questions with full explanations

6 domains 849 questions 180 min exam
Questions on the exam
about 75 — vendor indicates, no fixed count published
Time allowed
180 minutes format →

849 practice questions for AWS Certified DevOps Engineer – Professional, grouped by exam domain. Every question below shows all four options, which one is correct, and why each of the other three is not — the wrong answers are where most candidates lose marks.

Not sure where you stand? Take the free 5-min AWS readiness check →

AWS certification: requirements, cost and exam format → ·  AWS exam format →  · 

Questions by domain

Sample questions

Use one CodePipeline and CodeBuild: Which design best satisfies these requirements?

1: SDLC Automation Easy
A regulated financial service centralizes its pipeline in a tooling account and deploys to separate development, test, and production accounts. Artifacts must be immutable, encrypted, and promoted without rebuilding. Production requires an approval before deployment, while the security team prohibits long-lived credentials and source-code secrets. The platform team wants the fewest independently managed components while preserving auditable cross-account access. Which design best satisfies these requirements?
  1. Create separate CodePipelines in every account, rebuild from the shared repository independently, and use account-local keys without cross-account role assumptions.
    Separate pipelines increase management overhead, independent builds can differ, and the design lacks the required auditable cross-account access model.
  2. Use a shared S3 artifact bucket with default encryption, grant deployment accounts broad bucket administration, and deploy from copied artifacts.
    Default encryption and broad bucket administration do not provide the required customer-managed key controls or least-privilege auditable access.
  3. Use one CodePipeline and CodeBuild, build once, encrypt artifacts with a customer-managed KMS key, use scoped cross-account roles, and approve production before deployment. ✓
    The centralized pipeline creates one artifact, encrypts it with a customer-managed key, and promotes it through cross-account roles. A manual approval before the production action provides the required control without rebuilding.
  4. Store deployment credentials in encrypted repository variables, rebuild the application in each target account, and approve production after deployment starts.
    Repository credentials remain long-lived secret material, independent builds violate identical-artifact promotion, and approval occurs too late.
The trap
Mistakes storage encryption and broad access for complete cross-account authorization. Uses encrypted source settings and duplicated builds instead of runtime roles and immutable promotion. Optimizes for account-local ownership while violating the single-artifact and fewest-components requirements.

All 187 1: SDLC Automation questions →

Use service-managed StackSets: Which design should the platform team implement?

2: Configuration Management and IaC Medium
A global media service maintains baseline logging and security resources in dozens of AWS accounts across three Regions. Accounts belong to one AWS Organizations organization, and new accounts should receive the baseline automatically after joining designated organizational units. Operations must deploy Regions sequentially and stop after a configured failure tolerance, while avoiding manual creation of cross-account IAM roles. Which design should the platform team implement?
  1. Use separate CodePipeline actions for each account and Region.
    This requires custom orchestration and does not inherently enroll future organizational accounts or provide StackSet operation controls.
  2. Create a nested stack in the management account and export resources to member accounts.
    Nested stacks remain within the owning account and cannot provision resources across member accounts and Regions.
  3. Use self-managed StackSets with manually created administrator and execution roles.
    Self-managed StackSets can deploy across accounts but require the manual role administration explicitly excluded by the scenario.
  4. Use service-managed StackSets. ✓
    Service-managed StackSets support Organizations targeting, automatic deployments, regional ordering, failure tolerance, and AWS-managed cross-account role setup.
The trap
Independent actions do not automatically track OU membership or provide the required StackSet semantics. This is a valid StackSet model with the wrong permissions-management tradeoff. This confuses template composition with cross-account deployment.

All 144 2: Configuration Management and IaC questions →

Give each ECS task a narrowly scoped task role and block: Which design best enforces least privilege?

6: Security and Compliance Medium
A production container fleet runs on Amazon ECS. Tasks need read-only access to one S3 prefix and decrypt access to one KMS key. Developers deploy frequently, but task roles must not gain administrative permissions. Security also requires that a compromised task cannot reuse the EC2 container instance profile to access unrelated resources. Which design best enforces least privilege?
  1. Attach administrator permissions to the task role, then use deployment pipelines and review approvals to control when tasks can exercise them.
    Approval processes do not enforce runtime least privilege, and administrative task credentials remain available if a container is compromised.
  2. Give each ECS task a narrowly scoped task role and block access to instance-profile credentials. ✓
    The task role can limit S3 resources and KMS actions, while instance metadata protections prevent a compromised task from obtaining the broader EC2 profile.
  3. Attach the S3 and KMS permissions to the ECS task execution role and omit an application task role.
    The execution role supports ECS operations such as image retrieval and logging; application API calls require a separate task role.
  4. Use the broad instance profile for all task API calls and block only selected S3 actions.
    A shared instance profile exposes host-level permissions to every task and does not isolate workload credentials or narrowly scope KMS access.
The trap
Uses host credentials instead of workload-specific authorization. Confuses ECS control-plane permissions with application workload permissions. Replaces authorization boundaries with procedural deployment controls.

All 144 6: Security and Compliance questions →

Run active-active services with DynamoDB global tables: Which deployment design best satisfies the resiliency

3: Resilient Cloud Solutions Hard
A global media service must continue serving viewers after a complete AWS Region failure. The business requires an RTO under five minutes, an RPO under one minute, and active traffic in both Regions. Video objects are immutable, while viewing entitlements and session metadata change continuously. Which deployment design best satisfies the resiliency requirements?
  1. Run one Region with Multi-AZ compute, RDS Multi-AZ, and daily S3 backups.
    These measures address Availability Zone or point-in-time recovery scenarios, not active traffic and rapid recovery after complete Regional failure.
  2. Run active-active services with DynamoDB global tables for changing metadata, S3 cross-Region replication for video, and health-based traffic routing. ✓
    This removes regional dependencies from compute, mutable metadata, immutable content, and traffic routing. The design still requires validating replication lag and failover timing.
  3. Use CloudFront with one Regional origin and origin failover between Availability Zone endpoints.
    This can improve content delivery availability, but it does not provide a second active Region or replicate entitlement and session state.
  4. Run active-active compute with health-based routing, but retain entitlements and session metadata in the primary Region.
    The secondary Region remains dependent on the failed Region for changing state, violating the Regional recovery and RPO requirements.
The trap
Confuses zonal high availability and backups with Regional continuity. Replicates compute but not required application state. Treats content-delivery failover as complete application failover.

All 128 3: Resilient Cloud Solutions questions →

Centralize logs in CloudWatch Logs for 14 days: Which design best satisfies these requirements?

4: Monitoring and Logging Easy
A shared developer platform centralizes application and audit logs from 30 AWS accounts. Security requires tamper-resistant retention, developers need searchable logs for 14 days, and the platform team must prevent application teams from deleting centralized records. The design should minimize operational maintenance and preserve account and Region attribution. Which design best satisfies these requirements?
  1. Create a cross-account OpenSearch domain, grant developers read access, and retain indexed records for seven years.
    OpenSearch supports searching but requires cluster operations and its index retention and access controls do not by themselves provide immutable compliance retention.
  2. Centralize logs in CloudWatch Logs, set 14-day retention, and restrict log-group deletion to the platform team.
    This provides search and access control but does not provide immutable or tamper-resistant retention because an authorized administrator can still delete records or log groups.
  3. Send logs to a security-owned S3 bucket with versioning and use CloudWatch Logs Insights only when investigators need searches.
    Versioning supports recovery from some overwrites or deletions but does not establish immutable retention, and S3 alone does not provide the required convenient 14-day log search experience.
  4. Centralize logs in CloudWatch Logs for 14 days, and deliver a copy to a security-owned S3 bucket using Object Lock in compliance mode with the required retention period. ✓
    CloudWatch Logs provides managed short-term search and preserves centralized source context. A security-owned S3 bucket with Object Lock in compliance mode provides protected retention that application teams cannot shorten or delete.
The trap
It confuses administrative separation with WORM protection. It treats versioning as equivalent to Object Lock. It substitutes a search cluster for protected archival storage.

All 127 4: Monitoring and Logging questions →

Use an SQS event source mapping: Which design should the team choose?

5: Incident and Event Response Medium
A production container fleet submits asynchronous image jobs to Amazon SQS. Each job invokes Lambda, which calls a third-party image service that may be unavailable for several minutes. The design must retain messages during transient failures, move permanently invalid jobs aside after bounded attempts, preserve an operator-visible record, and avoid custom polling. Which design should the team choose?
  1. Write a Lambda poller that receives each message, processes it, and deletes it after success.
    This is executable, but custom polling violates the managed-polling requirement and requires the team to implement scaling and retry handling.
  2. Publish each job to SNS and invoke Lambda asynchronously, relying on Lambda’s service retries alone.
    This replaces the requested SQS consumer workflow and does not provide SQS visibility and redrive handling for the existing queue.
  3. Use an EventBridge rule with a target DLQ, then invoke Lambda directly for each submitted job.
    An EventBridge target DLQ records delivery failures, not failures after Lambda accepts and processes an SQS job.
  4. Use an SQS event source mapping, align visibility with processing time, and configure an SQS redrive policy. ✓
    The event source mapping provides managed polling and scaling. Visibility settings allow retries, and the redrive policy moves repeatedly failed messages to a durable DLQ.
The trap
Confuses target-delivery failure with consumer-processing failure. Treats asynchronous Lambda retries as equivalent to SQS redrive. Uses custom consumer logic when an event source mapping is required.

All 119 5: Incident and Event Response questions →

Trigger CodePipeline from an immutable commit: Which deployment design is most appropriate?

1: SDLC Automation Easy
A SaaS application uses a trunk-based Git repository and serves enterprise tenants from development, staging, and production environments. A release manager requires every production deployment to identify the exact commit and use the artifact validated in staging. Developers currently trigger deployments manually from local workstations, and tenant-specific configuration must never be committed. The team wants rollback to a previous release without rebuilding or changing application binaries. Which deployment design is most appropriate?
  1. Trigger CodePipeline from a branch head, retrieve tenant settings from Secrets Manager, and rebuild the image separately for each environment.
    A mutable branch head and separate environment builds do not reliably identify the exact staged commit or preserve the validated binary.
  2. Trigger CodePipeline from an immutable commit, build once, retrieve tenant settings from Secrets Manager, and promote that artifact. ✓
    This identifies the revision, externalizes tenant configuration, promotes one immutable artifact, and supports rollback by redeploying an earlier artifact.
  3. Use Git tags to trigger CodeBuild, embed tenant settings during compilation, and deploy each environment from its own image.
    Embedding tenant settings violates the requirement that configuration not be committed, and environment-specific images prevent identical-artifact promotion.
  4. Create one pipeline per tenant, rebuild from the selected commit for every environment, and store deployment credentials in repository configuration.
    Per-environment rebuilds violate identical-artifact promotion, while repository configuration is an inappropriate location for deployment credentials.
The trap
A tag identifies source, but it does not provide configuration isolation or identical promotion. External secrets alone do not solve mutable revisions and rebuilds. Separate pipelines do not require separate binaries, and repository settings are not a secrets store.

All 187 1: SDLC Automation questions →

Use Systems Manager for patching: Which design is most appropriate?

2: Configuration Management and IaC Medium
A shared developer platform operates hundreds of EC2 instances and several production services. The platform team needs centralized patching, inventory, and remote command execution for instances, while application teams need to release runtime configuration gradually with validation and rollback. Configuration changes must not require replacing instances or rebuilding images. The team also needs a service that reports general resource compliance, but that service should not perform runtime configuration rollout. Which design is most appropriate?
  1. Use Systems Manager for patching, inventory, and commands; AppConfig for gradual runtime configuration; and AWS Config for resource compliance. ✓
    Systems Manager provides managed-instance operations, AppConfig supports validated staged configuration deployment and rollback, and AWS Config evaluates resource configuration compliance without performing the rollout.
  2. Use Secrets Manager rotation for nonsecret settings and Systems Manager only for inventory.
    Secrets Manager rotation targets secrets, and limiting Systems Manager to inventory omits required patching and remote command operations.
  3. Use CloudFormation updates for patching and runtime configuration, replacing instances when required.
    CloudFormation manages infrastructure changes but is not the appropriate routine fleet-operations or gradual runtime-configuration service.
  4. Use AWS Config remediation for patch installation and AppConfig only for compliance reporting.
    Config can evaluate compliance and initiate remediation, but AppConfig is the configuration rollout service, not the compliance reporting service.
The trap
Uses infrastructure provisioning for operational patching and application rollout. Reverses the roles of compliance evaluation and runtime delivery. Applies a secret-lifecycle feature to general runtime configuration.

All 144 2: Configuration Management and IaC questions →

AWS exam: the facts

How many questions are on the AWS exam?

Around 75. The vendor does not publish a fixed count for AWS, so this is the figure it indicates rather than a guaranteed number.

How long is the AWS exam?

180 minutes. Across 75 questions that is about 144 seconds per question.

What topics does the AWS exam cover?

6 domains: 1: SDLC Automation, 2: Configuration Management and IaC, 6: Security and Compliance, 3: Resilient Cloud Solutions, 4: Monitoring and Logging, 5: Incident and Event Response. Weights: 1: SDLC Automation 22%, 2: Configuration Management and IaC 17%, 6: Security and Compliance 17%, 3: Resilient Cloud Solutions 15%, 4: Monitoring and Logging 15%, 5: Incident and Event Response 14%.

How many AWS practice questions does Certsqill have?

849, spread across 6 exam domains. Every one shows all options, which is correct, and why each of the others is not.

Would you pass AWS today?

Five minutes, and you get a score per domain — not one number, but which section to open tonight.

Test your AWS readiness — free
Certsqill AWS question bank · 849 questions across 6 domains · Every answer, right and wrong, comes with its own explanation.