Free DOP-C02 Practice Test Questions and Answers (2026)
Q: 1
A development team is using AWS CodeCommit to version control application code and AWS
CodePipeline to orchestrate software deployments. The team has decided to use a remote main
branch as the trigger for the pipeline to integrate code changes. A developer has pushed code
changes to the CodeCommit repository, but noticed that the pipeline had no reaction, even after 10
minutes.
Which of the following actions should be taken to troubleshoot this issue?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
A company uses an AWS CodeArtifact repository to store Python packages that the company
developed internally. A DevOps engineer needs to use AWS CodeDeploy to deploy an application to
an Amazon EC2 instance. The application uses a Python package that is stored in the CodeArtifact
repository. A BeforeInstall lifecycle event hook will install the package.
The DevOps engineer needs to grant the EC2 instance access to the CodeArtifact repository.
Which solution will meet this requirement?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
A DevOps team uses AWS CodePipeline, AWS CodeBuild, and AWS CodeDeploy to deploy an
application. The application is a REST API that uses AWS Lambda functions and Amazon API Gateway
Recent deployments have introduced errors that have affected many customers.
The DevOps team needs a solution that reverts to the most recent stable version of the application
when an error is detected. The solution must affect the fewest customers possible.
Which solution Will meet these requirements With the MOST operational efficiency?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
A company is building a new pipeline by using AWS CodePipeline and AWS CodeBuild in a build
account. The pipeline consists of two stages. The first stage is a CodeBuild job to build and package
an AWS Lambda function. The second stage consists of deployment actions that operate on two
different AWS accounts a development environment account and a production environment account.
The deployment stages use the AWS Cloud Format ion action that CodePipeline invokes to deploy
the infrastructure that the Lambda function requires.
A DevOps engineer creates the CodePipeline pipeline and configures the pipeline to encrypt build
artifacts by using the AWS Key Management Service (AWS KMS) AWS managed key for Amazon S3
(the aws/s3 key). The artifacts are stored in an S3 bucket When the pipeline runs, the Cloud
Formation actions fail with an access denied error.
Which combination of actions must the DevOps engineer perform to resolve this error? (Select
TWO.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
A DevOps engineer has automated a web service deployment by using AWS CodePipeline with the
following steps:
1) An AWS CodeBuild project compiles the deployment artifact and runs unit tests.
2) An AWS CodeDeploy deployment group deploys the web service to Amazon EC2 instances in the
staging environment.
3) A CodeDeploy deployment group deploys the web service to EC2 instances in the production
environment.
The quality assurance (QA) team requests permission to inspect the build artifact before the
deployment to the production environment occurs. The QA team wants to run an internal
penetration testing tool to conduct manual tests. The tool will be invoked by a REST API call.
Which combination of actions should the DevOps engineer take to fulfill this request? (Choose two.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
A company has deployed an application in a production VPC in a single AWS account. The application
is popular and is experiencing heavy usage. The company’s security team wants to add additional
security, such as AWS WAF, to the application deployment. However, the application's product
manager is concerned about cost and does not want to approve the change unless the security team
can prove that additional security is necessary.
The security team believes that some of the application's demand might come from users that have
IP addresses that are on a deny list. The security team provides the deny list to a DevOps engineer. If
any of the IP addresses on the deny list access the application, the security team wants to receive
automated notification in near real time so that the security team can document that the application
needs additional security. The DevOps engineer creates a VPC flow log for the production VPC.
Which set of additional steps should the DevOps engineer take to meet these requirements MOST
cost-effectively?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
A company that runs many workloads on AWS has an Amazon EBS spend that has increased over
time. The DevOps team notices there are many unattached
EBS volumes. Although there are workloads where volumes are detached, volumes over 14 days old
are stale and no longer needed. A DevOps engineer has been tasked with creating automation that
deletes unattached EBS volumes that have been unattached for 14 days.
Which solution will accomplish this?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
A company has multiple development teams in different business units that work in a shared single
AWS account All Amazon EC2 resources that are created in the account must include tags that specify
who created the resources. The tagging must occur within the first hour of resource creation.
A DevOps engineer needs to add tags to the created resources that Include the user ID that created
the resource and the cost center ID The DevOps engineer configures an AWS Lambda function With
the cost center mappings to tag the resources. The DevOps engineer also sets up AWS CloudTrail in
the AWS account. An Amazon S3 bucket stores the CloudTrail event logs
Which solution will meet the tagging requirements?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
A production account has a requirement that any Amazon EC2 instance that has been logged in to
manually must be terminated within 24 hours. All applications in the production account are using
Auto Scaling groups with the Amazon CloudWatch Logs agent configured.
How can this process be automated?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 10
A company is using AWS CodePipeline to automate its release pipeline. AWS CodeDeploy is being
used in the pipeline to deploy an application to Amazon Elastic Container Service (Amazon ECS) using
the blue/green deployment model. The company wants to implement scripts to test the green
version of the application before shifting traffic. These scripts will complete in 5 minutes or less. If
errors are discovered during these tests, the application must be rolled back.
Which strategy will meet these requirements?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 11
A company is using an organization in AWS Organizations to manage multiple AWS accounts. The
company's development team wants to use AWS Lambda functions to meet resiliency requirements
and is rewriting all applications to work with Lambda functions that are deployed in a VPC. The
development team is using Amazon Elastic Pile System (Amazon EFS) as shared storage in Account A
in the organization.
The company wants to continue to use Amazon EPS with Lambda Company policy requires all
serverless projects to be deployed in Account B.
A DevOps engineer needs to reconfigure an existing EFS file system to allow Lambda functions to
access the data through an existing EPS access point.
Which combination of steps should the DevOps engineer take to meet these requirements? (Select
THREE.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
A company's application development team uses Linux-based Amazon EC2 instances as bastion
hosts. Inbound SSH access to the bastion hosts is restricted to specific IP addresses, as defined in the
associated security groups. The company's security team wants to receive a notification if the
security group rules are modified to allow SSH access from any IP address.
What should a DevOps engineer do to meet this requirement?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
A company deploys its corporate infrastructure on AWS across multiple AWS Regions and Availability
Zones. The infrastructure is deployed on Amazon EC2 instances and connects with AWS loT
Greengrass devices. The company deploys additional resources on on-premises servers that are
located in the corporate headquarters.
The company wants to reduce the overhead involved in maintaining and updating its resources. The
company's DevOps team plans to use AWS Systems Manager to implement automated management
and application of patches. The DevOps team confirms that Systems Manager is available in the
Regions that the resources are deployed m Systems Manager also is available in a Region near the
corporate headquarters.
Which combination of steps must the DevOps team take to implement automated patch and
configuration management across the company's EC2 instances loT devices and on-premises
infrastructure? (Select THREE.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
A company is developing an application that will generate log events. The log events consist of five
distinct metrics every one tenth of a second and produce a large amount of data The company needs
to configure the application to write the logs to Amazon Time stream The company will configure a
daily query against the Timestream table.
Which combination of steps will meet these requirements with the FASTEST query performance?
(Select THREE.)
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
A company has many AWS accounts. During AWS account creation the company uses automation to
create an Amazon CloudWatch Logs log group in every AWS Region that the company operates in.
The automaton configures new resources in the accounts to publish logs to the provisioned log
groups in their Region.
The company has created a logging account to centralize the logging from all the other accounts. A
DevOps engineer needs to aggregate the log groups from all the accounts to an existing Amazon S3
bucket in the logging account.
Which solution will meet these requirements in the MOST operationally efficient manner?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 16
To run an application, a DevOps engineer launches an Amazon EC2 instance with public IP addresses
in a public subnet. A user data script obtains the application artifacts and installs them on the
instances upon launch. A change to the security classification of the application now requires the
instances to run with no access to the internet. While the instances launch successfully and show as
healthy, the application does not seem to be installed.
Which of the following should successfully install the application while complying with the new rule?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 17
A company has chosen AWS to host a new application. The company needs to implement a multi-
account strategy. A DevOps engineer creates a new AWS account and an organization in AWS
Organizations. The DevOps engineer also creates the OU structure for the organization and sets up a
landing zone by using AWS Control Tower.
The DevOps engineer must implement a solution that automatically deploys resources for new
accounts that users create through AWS Control Tower Account Factory. When a user creates a new
account, the solution must apply AWS CloudFormation templates and SCPs that are customized for
the OU or the account to automatically deploy all the resources that are attached to the account. All
the OUs are enrolled in AWS Control Tower.
Which solution will meet these requirements in the MOST automated way?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 18
A company manages a web application that runs on Amazon EC2 instances behind an Application
Load Balancer (ALB). The EC2 instances run in an Auto Scaling group across multiple Availability
Zones. The application uses an Amazon RDS for MySQL DB instance to store the dat
a. The company has configured Amazon Route 53 with an alias record that points to the ALB.
A new company guideline requires a geographically isolated disaster recovery (DR> site with an RTO
of 4 hours and an RPO of 15 minutes.
Which DR strategy will meet these requirements with the LEAST change to the application stack?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 19
A development team uses AWS CodeCommit, AWS CodePipeline, and AWS CodeBuild to develop
and deploy an application. Changes to the code are submitted by pull requests. The development
team reviews and merges the pull requests, and then the pipeline builds and tests the application.
Over time, the number of pull requests has increased. The pipeline is frequently blocked because of
failing tests. To prevent this blockage, the development team wants to run the unit and integration
tests on each pull request before it is merged.
Which solution will meet these requirements?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 20
A company runs an application on one Amazon EC2 instance. Application metadata is stored in
Amazon S3 and must be retrieved if the instance is restarted. The instance must restart or relaunch
automatically if the instance becomes unresponsive.
Which solution will meet these requirements?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20