WorksheetsACT3_CONSOLIDATED_AWS_VALIDATED_2025
Total questions: 51
Worksheet time: 4hrs 15mins
Name
Class
Date
1.
(G4) A company operates an API on EC2 instances within an Auto Scaling group. They need to deploy a new application version without affecting ongoing traffic, ensuring that all new instances run the updated version while old instances continue serving users until traffic shifts. They also require the ability to roll back immediately if errors appear after deployment.
a)
Use an in-place deployment with CodeDeploy and allow traffic to drain gradually
b)
Use blue/green deployments with two Auto Scaling groups and switch traffic using ALB target groups
c)
Update the AMI of the existing Auto Scaling group and perform a rolling update
d)
Deploy manually via SSH to each active EC2 instance
2.
(G4) A security team requires long-term storage of application logs generated by EC2 instances in a dynamic Auto Scaling group. Instances can be replaced frequently, and logs must remain available even if the underlying instances are terminated. They want a solution that minimizes maintenance and removes the need to manage shared file systems.
a)
Use CloudWatch Logs to stream logs from each instance automatically
b)
Attach a shared EFS file system to every instance and store logs there
c)
Store logs on instance store volumes and copy them hourly to S3
d)
Use a single EBS volume with Multi-Attach enabled across all instances
3.
(G4) A development team launches new EC2 instances several times a day as part of their testing workflow. Each instance must install dependencies, retrieve environment configuration files, and register itself with a metrics collector on startup. They need these steps to happen automatically without rebuilding AMIs frequently.
a)
Add initialization commands to the EC2 user data script
b)
Adopt Systems Manager Session Manager to run commands after launch
c)
Manually SSH into each instance to perform setup tasks
d)
Store initialization files on instance store volumes pre-launch
4.
(G4) A research team runs tightly coupled simulations on EC2 that require extremely high network throughput and low latency between nodes. The instances must run in the same Availability Zone, and the application performance decreases significantly if nodes are spread too far apart or across different subnets.
a)
Use a cluster placement group to place EC2 instances close together
b)
Distribute instances across multiple AZs for redundancy
c)
Use spread placement groups to ensure maximum fault tolerance
d)
Deploy an ALB in front of all EC2 instances to balance traffic
5.
(G4) A company deploys a dynamic website using EC2 instances behind an ALB, which is then fronted by CloudFront. Security requirements state that no user should be able to bypass CloudFront and reach the ALB directly, as all requests must pass through CloudFront caching, logging, and WAF rules.
a)
Enable CloudFront signed cookies to restrict access
b)
Restrict inbound traffic on the ALB security group to CloudFront IP ranges only
c)
Configure AWS Shield Advanced to block unwanted requests
d)
Add Route 53 health checks to deny direct ALB access
6.
(G4) A media company runs short-lived rendering jobs on EC2. Rendering tasks can tolerate interruption, but reprocessing entire tasks wastes time and money. The company wants to reduce compute costs while ensuring that work progress is not lost when instances are reclaimed.
a)
Run everything on On-Demand instances to avoid interruptions
b)
Use Spot Instances and implement checkpointing on interruption signals
c)
Move all workloads to instance store volumes for faster rendering
d)
Use Scheduled Reserved Instances to lower compute cost
7.
(G4) An analytics application running on EC2 across multiple AZs needs a shared file system where many nodes can read and write concurrently. The team requires POSIX compatibility, automatic scaling with workload size, and low operational complexity, without managing storage servers manually.
a)
Use Amazon EFS as a fully managed NFS file system
b)
Store all files in Amazon S3 and mount them with a custom FUSE driver
c)
Use EBS Multi-Attach in each AZ for shared access
d)
Configure instance store volumes and replicate them between nodes
8.
(G4) A background processing system uses EC2 workers to consume messages from a custom job queue. CPU usage is not a reliable scaling indicator, so the team wants to scale EC2 instances based on custom metrics like queue depth and pending job count, and the scaling must occur automatically without human intervention.
a)
Publish custom CloudWatch metrics and create target-tracking scaling policies
b)
Use scheduled scaling rules based on predictions
c)
Increase EC2 instance size to handle more jobs per worker
d)
Use AWS CLI scripts to scale manually on demand
9.
(G4) A financial company mandates that traffic must remain encrypted from the client to the load balancer and from the load balancer to each EC2 instance. They currently use HTTP listeners on their Application Load Balancer, and compliance auditors require encryption on every hop without exception.
a)
Keep HTTPS at the ALB but send HTTP to EC2
b)
Configure HTTPS listeners on the ALB and enable HTTPS on all EC2 instances
c)
Replace the ALB with an NLB that performs TCP passthrough
d)
Enable VPC Flow Logs to encrypt all traffic automatically
10.
(G4) A company deploys application updates using CodeDeploy in an in-place configuration on EC2 instances. During a recent update, several instances became unhealthy, and restoring service required manual intervention. The company wants a safer deployment pattern with fast rollback and minimal impact on production traffic.
a)
Adopt blue/green deployments using separate Auto Scaling groups
b)
Increase health check timeouts during in-place deployments
c)
Connect via SSH and deploy to each EC2 instance manually
d)
Store old application versions in S3 for manual redeployment
11.
(G1) A developer has created an application running on an EC2 instance that retrieves temporary credentials from the instance metadata service. After upgrading the EC2 instance to use IMDSv2, the application starts failing. What is the MOST likely cause?
a)
The instance profile is not attached to the instance
b)
The application is not using session tokens in its requests.
c)
The security group does not allow HTTPS access to the metadata endpoint
d)
The IAM role permissions do not include sts:GetSessionToken
12.
(G1) A high-performance workload runs on EC2 instances that use NVMe instance store volumes. After a sudden host failure, all cached data is lost. The architect must preserve performance but ensure data durability. What is the BEST solution?
a)
Switch to EBS gp3 volumes with provisioned IOPS.
b)
Use EC2 Auto Scaling with Lifecycle Hooks to snapshot instance stores regularly
c)
Configure RAID 0 across multiple instance stores
d)
Use instance store volumes with placement groups for redundancy
13.
(G1) A web service uses EC2 Auto Scaling to handle unpredictable traffic. Launching new instances during traffic spikes takes several minutes. How can the DevOps engineer improve response time while controlling cost?
a)
Use EC2 Spot Instances for faster provisioning
b)
Create a warm pool of pre-initialized instances in the Auto Scaling group.
c)
Switch to larger instance types
d)
Pre-bake AMIs using EC2 Image Builder weekly
14.
(G1) AWS notifies you of scheduled maintenance for EC2 instances in one Availability Zone. You must minimize downtime for a stateful workload. What should you do?
a)
Stop and start the affected instances during the maintenance window
b)
Reboot the instances after maintenance completes
c)
Migrate the instances to another AZ using AMI and launch templates.
d)
Enable hibernation on the instances
15.
(G1) A Lambda function retrieves database credentials from AWS Systems Manager Parameter Store and passes them to EC2 instances via user data. During deployment, some EC2 instances fail to get credentials. What’s the MOST likely reason?
a)
Parameter Store has reached the API request limit
b)
User data scripts execute before IAM instance role credentials are available.
c)
Lambda must encrypt the credentials using KMS before storing them
d)
EC2 instances cannot access Parameter Store from private subnets
16.
(G1) A compute cluster uses c6i.large instances, and performance tests reveal network bottlenecks. The cluster communicates heavily across nodes. What change will MOST effectively increase inter-instance throughput?
a)
Change to a spread placement group
b)
Upgrade to c6i.4xlarge within the same placement group.
c)
Attach additional ENIs to each instance
d)
Use multiple smaller placement groups per subnet
17.
(G1) An EC2 Auto Scaling group launches instances with a user data script that installs dependencies from the internet. Occasionally, new instances fail because a package mirror is unavailable. How can a developer ensure reliable provisioning?
a)
Create a golden AMI with dependencies preinstalled using EC2 Image Builder.
b)
Add retry logic in user data scripts
c)
Use AWS CodeDeploy for installation
d)
Store installation packages in Amazon S3
18.
(G1) A monitoring system detects that an EC2 instance is impaired but still running. The instance hosts a single-AZ application and must self-recover without manual intervention. Which approach meets the requirement?
a)
Enable EC2 Auto Recovery on the instance.
b)
Place the instance in an Auto Scaling group with one desired capacity
c)
Configure AWS Backup with continuous recovery
d)
Use a CloudWatch alarm with an SNS topic to notify administrators
19.
(G1) A DevOps team runs a web tier on an Auto Scaling group using EC2 Launch Templates. They want to reduce cost by combining On-Demand and Spot capacity automatically. How can this be achieved?
a)
Create multiple launch configurations for each instance type
b)
Use EC2 Fleet with static instance distribution
c)
Use EC2 savings plans for cost reduction
d)
Use a Mixed Instances Policy in the Auto Scaling group with weighted capacity.
20.
(G6) A critical application currently runs in a single Availability Zone (AZ). The client requires higher availability without adding major operational complexity. What should you recommend?
a)
Create hourly snapshots of the EC2 instance
b)
Deploy EC2 instances across multiple AZs and use an Application Load Balancer.
c)
Use a larger EC2 instance in the same AZ
d)
Place a CloudFront distribution in front of the EC2 instance
21.
(G6) A developer hardcoded IAM access keys inside an application running on EC2 to access an S3 bucket. The security team reports this as a vulnerability. What is the best practice to fix this issue?
a)
Encrypt the keys and store them on the EC2 instance
b)
Use AWS Secrets Manager to retrieve the keys at runtime
c)
Attach an IAM Role to the EC2 instance with the necessary S3 permissions.
d)
Store the keys in a configuration file within the application
22.
(G6) Your company runs several EC2 instances used only Monday through Friday from 9 AM to 5 PM. Currently, the instances remain running 24/7, generating unnecessary costs. What is the most cost-effective solution that keeps the instances available during business hours?
a)
Switch to Spot Instances
b)
Use AWS Instance Scheduler to start and stop instances based on a Schedule.
c)
Migrate the application to AWS Lambda
d)
Purchase 1-year Reserved Instances
23.
(G6) A developer is testing a new REST API hosted on an Amazon EC2 instance. The API needs to access data in an Amazon DynamoDB table. Currently, the developer is storing AWS credentials in the application’s configuration file, but the security team requires removing these hardcoded credentials. What is the most secure and efficient way to allow the EC2 instance to access DynamoDB?
a)
Store the credentials in AWS Secrets Manager and retrieve them at runtime
b)
Encrypt credentials with AWS KMS and store them in an environment variable
c)
Create an IAM Role with permissions to DynamoDB and attach it to the EC2 instance.
d)
Use an AWS Lambda function as a proxy between EC2 and DynamoDB
24.
(G6) A startup is running a web application on Amazon EC2 instances using instance store volumes for storage. After a system reboot, the application loses all uploaded files. The Solutions Architect must design a solution that preserves data even if the instance stops, reboots, or is terminated. Which change should be made?
a)
Use Amazon EBS volumes for persistent storage instead of instance store
b)
Configure instance store volumes for automatic replication across AZs
c)
Store uploaded files in Amazon S3 instead of EC2 storage.
d)
Enable EC2 automatic recovery to prevent reboot data loss
25.
(G9) A monolithic application running on a single EC2 instance is experiencing performance issues. The "order processing" component is slow and causes user requests to time out. A developer wants to decouple this component. Question: Which AWS service should be used to asynchronously process the "order" tasks from the main application?
a)
Amazon SNS to send order notifications
b)
Amazon SQS to hold order messages between the application and a separate processing service.
c)
AWS Lambda to directly process the orders from the main application
d)
Amazon EC2 Auto Scaling to add more instances of the monolithic application
26.
(G9) An application on an EC2 instance needs to know its own public IP address to register with a service discovery system. Question: How can the application dynamically retrieve its own public IP address?
a)
Use the AWS CLI command aws ec2 describe-instances and parse the output
b)
Query the instance metadata service at http://169.254.169.254/latest/meta-data/.
c)
Make a public DNS query to checkip.amazonaws.com
d)
Read the IP address from a tag placed on the EC2 instance by a startup script
27.
(G9) A company needs to launch 100 EC2 instances for a short-term batch processing job (24 hours). The instances require a standard Amazon Linux 2 AMI with no special performance needs for the root volume. Question: Which Amazon EBS volume type provides the lowest cost for the root volumes?
a)
Provisioned IOPS SSD (io2 Block Express)
b)
Throughput Optimized HDD (st1)
c)
General Purpose SSD (gp3).
d)
Cold HDD (sc1)
28.
(G9) You are designing a three-tier web application with public web servers, application servers, and a database. The application servers in the middle tier should only accept traffic from the web servers and should not have direct internet access. Question: Which combination of steps provides this security? (Select TWO)
a)
Place the web servers in a public subnet and the application servers in a private subnet.
b)
Place both the web servers and application servers in the same public subnet
c)
Use a Network ACL to block all inbound traffic to the application servers except from the web servers' security group
d)
Configure the application servers' security group to allow inbound traffic from the web servers' security group.
29.
(G9) You are responsible for ensuring that all EC2 instances in your VPC are patched for critical security vulnerabilities with minimal manual intervention and downtime. Question: Which AWS service provides automated, scheduled patching for EC2 instances?
a)
Create a custom Lambda function that uses AWS Systems Manager Run Command to apply patches
b)
Use AWS OpsWorks to manage patches for the instances
c)
Use AWS Systems Manager Patch Manager to create a patch baseline and a maintenance window.
d)
Use AWS Config to check for non-compliant instances and manually patch them
30.
(G9) You need EC2 instances in an Auto Scaling group to install multiple software packages, configure a custom monitoring agent, and download a large configuration file from S3 upon launch. Question: What is the most robust and maintainable way to accomplish this?
a)
Use EC2 User Data to write a shell script that performs all the necessary steps
b)
Create a custom AMI with all the software pre-installed and use User Data only for the dynamic S3 download.
c)
Use AWS Systems Manager State Manager to define an association that runs after the instance launches
d)
Use a combination of a custom AMI and AWS OpsWorks for configuration management
31.
(G5) A company is developing a backend API that runs on Amazon EC2 instances in a single Availability Zone. The development team needs automatic instance replacement if an EC2 instance fails, but the number of instances must remain constant at all times. Which solution meets the requirement with the least operational effort?
a)
Create a launch template and use EC2 Auto Scaling with a desired capacity of 1.
b)
Create a CloudWatch alarm that triggers an SNS notification when an instance fails
c)
Use AWS Systems Manager to run a script that recreates failed instances manually
d)
Use an Elastic Load Balancer with health checks and replace instances manually
32.
(G5) A DevOps team needs to automate configuration and patching of Amazon EC2 instances across multiple environments (dev, test, prod). Which AWS service should they use?
a)
AWS Backup
b)
AWS Systems Manager State Manager.
c)
Amazon Inspector
d)
AWS CloudFormation
33.
(G5) A developer needs to securely store sensitive application credentials used by an EC2 instance. The credentials must rotate automatically. What is the best solution?
a)
Store credentials in user-data and base64 encode them
b)
Store credentials in AWS Secrets Manager and attach an IAM role to the EC2 instance.
c)
Store credentials in an encrypted EBS volume
d)
Store credentials in an S3 bucket with bucket policies
34.
(G5) A company runs batch processing workloads on EC2 instances during off-peak hours. They want to reduce compute costs while still ensuring jobs run successfully. What instance purchasing option should they choose?
a)
On-Demand Instances
b)
Spot Instances with a fallback to On-Demand.
c)
Reserved Instances
d)
Dedicated Hosts
35.
(G5) A company needs to allow SSH access to EC2 instances for administrators. The access must be logged, audited, and must not require opening port 22 to the internet. What should they use?
a)
Open port 22 on the security group and restrict to public IPs
b)
Use AWS Systems Manager Session Manager.
c)
Use a bastion host with public IP
d)
Use EC2 Instance Connect and allow 0.0.0.0/0
36.
(G5) A DevOps engineer needs immutable infrastructure when deploying new versions of an app running on EC2. No instance should ever be updated in place. What deployment strategy should be used?
a)
In-place deployment
b)
Blue/Green deployment.
c)
Rolling update
d)
Reboot deployment
37.
(G5) A team wants to share AMIs between AWS accounts securely for EC2 deployments. What is the correct way?
a)
Upload the AMI to S3 and share the bucket
b)
Use AWS Resource Access Manager to share the AMI.
c)
Copy the AMI by exporting it to local disk
d)
Attach the AMI as an EBS snapshot and email the link
38.
(G5) A workload runs on EC2 and must automatically recover if the instance becomes impaired, but it must retain its same instance ID, private IP, and EBS volumes. What should be used?
a)
EC2 Auto Scaling
b)
EC2 Instance Recovery.
c)
CloudWatch alarm + SNS email
d)
Reboot the instance remotely
39.
(G7) In the sitcom episode “Cheap First Launch”, the startup’s first release day uses one single t3.micro in a single AZ. The business survives launch day luck only because no AZ outage occurs that day. The postmortem of the episode asks the main technical question: what was the fundamental architecture risk?
a)
one AZ is a single point of failure.
b)
you need Reserved Instances to be fault toleran
c)
the OS is always out-of-date in a first launch
d)
EC2 cannot scale horizontally
40.
(G7) The sitcom shows that a services team put a transactional DB on instance store (ephemeral). When a host failure occurred, all DB state was gone. The postmortem clearly observed that persistent block storage should have been used. Which TWO options below are persistent block storage choices?
a)
EBS gp3.
b)
instance store
c)
S3 Standard
d)
EBS io2.
41.
(G7) An episode’s cost analyst shows a graph: On-Demand line is linear, and above budget, while batch compute jobs can be interrupted without business consequence. The retrospective asks: which pricing model fits best for cost optimization here?
a)
On-Demand
b)
Spot.
c)
Dedicated Hosts
d)
Outposts
42.
(G7) A performance analysis episode shows a latency spike exactly in first 2 minutes after scale-out events. A follow up test created a “warm pool” and the spike practically disappeared. which mechanism eliminated the cold boot penalty?
a)
Warm Pools.
b)
Lifecycle hooks
c)
EC2 Hibernate
d)
Lambda provisioned concurrency
43.
(G7) A compliance audit episode shows a diagram with 4 networks: public subnets, private subnets, NAT, and EC2 instances. The compliance report labels “Security Group” around the EC2 icons as the perimeter firewall for instance traffic. Which is the EC2 instance firewall?
a)
Security Group.
b)
NACL
c)
GuardDuty
d)
S3 bucket policy
44.
(G7) A global e-commerce platform experiences high latency when customers in Europe access its EC2-hosted application in the US. The company wants to reduce response time for European users. Which solution is BEST?
a)
Use Amazon CloudFront with the existing US-based EC2 origin
b)
Launch EC2 instances in an EU region and use Route 53 latency-based routing.
c)
Increase the EC2 instance size in the US
d)
Use AWS Direct Connect between the US and Europe
45.
(G7) An episode on “no SSH keys ever again” demonstrates that static SSH keys are operational risk. The systems registry lists two AWS-native approaches that avoid distributing SSH private keys. Which two?
a)
SSM Session Manager.
b)
EC2 Instance Connect.
c)
KMS GenerateDataKey
d)
IAM user password
46.
(G7) A high availability architecture test shows two AZs with ALB in front. During simulated AZ outage the ALB target group marks AZ1 nodes unhealthy, and traffic graphs show ALB routing only to AZ2. Which behavior is true?
a)
ALB sends to both zones even if unhealthy
b)
ALB sends only to healthy zone.
c)
ALB moves EBS volumes across Region
d)
ALB configures DNS failover automatically
47.
(G3) A web application runs on EC2 instances behind an ALB. When an instance becomes unhealthy, Auto Scaling takes too long to replace it. How can you improve recovery time?
a)
Use EC2 status checks only
b)
Enable ELB health checks for the Auto Scaling Group.
c)
Reduce the cooldown to 0
d)
Configure EC2 instance recovery
48.
(G3) An EC2 instance in a private subnet must access S3 without using the public internet. What should you use?
a)
Internet Gateway
b)
NAT Gateway
c)
VPC Gateway Endpoint for S3.
d)
VPC Peering
49.
(G3) A CPU-intensive app is single-threaded and performance does not improve when scaling out. What should you do?
a)
Add more EC2 instances
b)
Horizontal scale with Auto Scaling
c)
Use an EC2 instance type with higher single-core performance.
d)
Use Spot Instances
50.
(G3) A company wants automated daily backups of EC2 instances with fast recovery. What is the best solution?
a)
Use AWS Backup to automate daily EBS snapshots.
b)
Copy all files to S3 manually
c)
Enable versioning on EBS volumes
d)
Use CloudTrail to log changes
51.
(G3) A team needs zero-downtime deployments for an EC2-based application. What should they use?
a)
Reboot each instance manually
b)
Rolling update with 0 batch size
c)
Replace instances manually
d)
Blue/Green deployment using Auto Scaling Groups.
100 %
