AWS DOP-C02 Multiple choice 75 questions 3 hours

AWS Certified DevOps Engineer - Professional

The professional-level AWS exam for delivery and operations: pipelines and deployment strategies, infrastructure as code across many accounts, resilience, monitoring, incident response and security automation. Long scenarios where several answers work and one fits the constraints best.

The blueprint

A mock exam here has 75 questions in 3 hours, split across the domains in the same proportions as the official exam guide. The official pass mark is 750 of 1,000 (scaled). FixOps scores practice against a target of 77%.

  1. 01

    SDLC Automation

    22%

  2. 02

    Configuration Management and IaC

    17%

  3. 03

    Resilient Cloud Solutions

    15%

  4. 04

    Monitoring and Logging

    15%

  5. 05

    Incident and Event Response

    14%

  6. 06

    Security and Compliance

    17%

Sample questions

Three of the 10 questions in the free diagnostic. Open one to see the answer and why.

A team keeps its code in GitHub and wants CodePipeline to start on every push to main, without storing a personal access token anywhere. Which source configuration fits?
  • A Lambda function that clones the repository with a token from its environment
  • A scheduled EventBridge rule that polls the repository every five minutes
  • A source action that uses a connection (AWS CodeConnections) to the repository
  • An S3 source action fed by a developer uploading a ZIP file after each push

Answer: A source action that uses a connection (AWS CodeConnections) to the repository. A connection authorises AWS to a third-party provider through an installed app, with no token to store, and the source action starts the pipeline on changes it is notified of. Polling is slower and wasteful, and tokens in environment variables are long-lived secrets to manage.

A pipeline has build, deploy-to-test, deploy-to-staging and deploy-to-production stages. Where do unit tests and full load tests belong?
  • Both after the production deployment, as a final check
  • Both in the build stage, before any environment exists
  • Unit tests against production; load tests in the build stage
  • Unit tests in the build stage; load tests against staging

Answer: Unit tests in the build stage; load tests against staging. Fast, isolated tests run earliest so that failures cost the least: unit tests and static analysis in the build stage. Tests that need a running system come after a deployment: integration tests in the test environment, load and acceptance tests in a production-like staging environment. Finding defects only in production defeats the pipeline.

A baseline IAM role must exist in every account of an organisational unit, including accounts that join it later, with nobody creating roles in each account first. Which approach fits?
  • A nested stack inside a template in the management account
  • A stack created by hand in each account as it joins
  • A stack set with self-managed permissions and a list of account IDs
  • A stack set with service-managed permissions, targeting the OU

Answer: A stack set with service-managed permissions, targeting the OU. With service-managed permissions, StackSets uses AWS Organizations to create the roles it needs and can target organisational units. Automatic deployment adds stack instances to accounts that join the OU and removes them when accounts leave. Self-managed permissions need administration and execution roles to be created in every account beforehand.

Revision notes: SDLC Automation

The notes for one domain, free to read here and in the app. FixOps Pro has them for all 6 domains.

Pipelines from commit to production across accounts, tests at the right stage, artifacts that are built once and kept safe, and deployment strategies for instances, containers and functions.

Pipelines

  • A source action with a connection starts the pipeline on a push without stored tokens; V2 triggers can filter on branches, tags and paths.
  • Cross-account actions assume a role in the target account. The artifact bucket needs a customer managed KMS key that role can use; the default aws/s3 key cannot be shared.
  • A cross-Region action needs an artifact bucket in that Region.
  • Approving is the PutApprovalResult permission, which can be granted per approval action.
  • Execution modes: SUPERSEDED lets a newer run overtake a waiting one, QUEUED processes every run in order, PARALLEL runs them independently.
  • A V2 stage can roll back automatically to its last successful execution.

Builds and tests

  • CodeBuild fails a phase on a non-zero exit code. Secrets come from Secrets Manager or Parameter Store references, never plaintext variables.
  • Webhook filters on pull request events build every pull request and report the status back.
  • A cache for the dependency directory shortens builds. A VPC configuration reaches private resources and then needs a NAT gateway for the internet.
  • The reports section publishes test results and code coverage per build.
  • Unit tests and static analysis run in the build stage; integration tests after deploying to a test environment; load tests against a production-like staging environment.

Artifacts and images

  • Build once and promote the same artifact through every stage.
  • CodeArtifact: domain and repository policies grant cross-account access (aws:PrincipalOrgID covers an organisation); clients need GetAuthorizationToken and sts:GetServiceBearerToken; package origin controls stop dependency confusion.
  • ECR: lifecycle policies expire old images, enhanced scanning uses Inspector continuously, replication copies images to other Regions and accounts, a pull-through cache mirrors public registries.
  • EC2 Image Builder builds, tests and distributes AMIs on a schedule. A launch template can read the current AMI ID from a Systems Manager parameter.
  • Code signing for Lambda rejects packages that were not signed by the approved profile.

Deployment strategies

  • CodeDeploy on EC2: in place with OneAtATime, HalfAtATime or AllAtOnce, or blue/green with a replacement Auto Scaling group.
  • The agent on the instance downloads the revision with the instance profile, which needs S3 and KMS access. Hook script output is in the agent's logs on the instance.
  • An instance launched during a deployment receives the last successful revision, so the fleet can end up mixed.
  • ECS blue/green uses two target groups and a test listener; the rolling type has a deployment circuit breaker with rollback.
  • Lambda releases shift traffic on an alias, canary or linear, and roll back when a CloudWatch alarm on the deployment group fires.
  • Immutable deployments replace instances from a new image; nothing is patched in place, so there is no drift and rollback is the previous image.
  • Shared files across instances belong on EFS or S3, not on one instance's EBS volume. Versioned file names make new static assets take effect at once.

Easy to mix up

  • The CodeDeploy service role calls AWS for the service; the instance profile is what downloads the bundle.
  • QUEUED keeps every execution; SUPERSEDED may skip one.
  • Blue/green rolls back by switching traffic; rolling rolls back by deploying again.
  • A lifecycle policy removes images; tag immutability stops a tag from moving.

Practice questions written by FixOps from the public DOP-C02 exam guide. They are not real exam questions. FixOps is not affiliated with or endorsed by Amazon Web Services.

Your pager is ready.

Free, instant, and it works on your phone. No signup: start as a guest and save your progress later.