About the Exam

Intended for CloudOps engineers and systems administrators with about one year of experience in deployment, management, networking, troubleshooting, and security on AWS. The exam validates the ability to deploy, manage, and operate AWS workloads, including monitoring, logging, remediation, security controls, networking, and business continuity. Passing demonstrates technical skills in day-to-day cloud operations on AWS in line with the Well-Architected Framework.

Exam Topics

  • Monitoring, Logging, Analysis, Remediation, and Performance Optimization22%
  • Reliability and Business Continuity22%
  • Deployment, Provisioning, and Automation22%
  • Security and Compliance16%
  • Networking and Content Delivery18%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated August 13, 2026 at 10:53 PM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

Security and Compliance

A company intends to host a public web application on Amazon EC2 instances behind an Elastic Load Balancing (ELB) load balancer. The company’s security team wants to secure the website with AWS Certificate Manager (ACM) certificates. The load balancer must automatically redirect all HTTP requests to HTTPS.

Which solution meets these requirements?

Explanation

An Application Load Balancer can use an ACM certificate on an HTTPS listener and can redirect requests received by an HTTP listener on port 80 to HTTPS on port 443. This provides TLS termination for the public website while enforcing HTTPS for clients.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Deployment, Provisioning, and Automation

A CloudOps engineer is reviewing the following AWS CloudFormation template:

Question Image

Why does creation of the stack fail?

Explanation

PrivateDnsName is not a supported configurable property of AWS::EC2::Instance; it is a read-only resource attribute that can be retrieved with Fn::GetAtt. The supported instance setting for hostname behavior is PrivateDnsNameOptions, so specifying PrivateDnsName in Properties causes CloudFormation validation to fail.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Reliability and Business Continuity

A company is implementing Cross-Region Replication (CRR) for its Amazon S3 buckets. The S3 buckets are in the us-east-1 Region. The company uses server-side encryption with Amazon S3 managed keys (SSE-S3) to protect the data in the buckets.

A CloudOps engineer creates a new AWS account to store backups in S3 buckets. All backup buckets are in the us-west-2 Region. The CloudOps engineer enables versioning on both the source buckets and destination buckets. The CloudOps engineer creates an IAM role in the source account for s3.amazonaws.com. The CloudOps engineer grants the IAM role permissions to perform read actions in the source buckets, replicate actions in the destination buckets, and encrypt actions using the destination bucket's key. The destination bucket policy allows the IAM role to perform replicate and read actions.

After completing the replication configuration, the CloudOps engineer notices that objects are not replicating.

What is the likely reason that the objects are not replicating?

Explanation

When cross-account replication is configured to transfer replica ownership to the destination bucket owner, the S3 replication role and the destination bucket policy must allow s3:ObjectOwnerOverrideToBucketOwner. SSE-S3 supports replication and does not require multi-Region KMS keys or SSE-KMS at the destination, and S3 replication does not require gateway VPC endpoints.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Security and Compliance

A CloudOps engineer needs to create an IAM policy for a developer who requires access to particular AWS services. Based on these requirements, the CloudOps engineer creates the following policy:

Question Image

Which actions are allowed by this policy?

Choose two
Explanation

The policy allows all Elastic Load Balancing actions through elasticloadbalancing:*, which includes DescribeLoadBalancers, and all AWS Lambda actions through lambda:*, which includes InvokeFunction. It does not allow Storage Gateway creation, IAM role creation, or SQS queue deletion because those actions do not match the permitted action patterns.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Networking and Content Delivery

A CloudOps engineer created a VPC containing a public subnet and a private subnet. Amazon EC2 instances launched in the private subnet cannot reach the internet. The default network ACL is active for every subnet in the VPC, and every security group permits all outbound traffic.

Which solution will give the EC2 instances in the private subnet internet access?

Explanation

A NAT gateway placed in a public subnet provides outbound internet connectivity for instances that have only private IP addresses. The private subnet’s route table must direct internet-bound traffic to that NAT gateway; the NAT gateway uses the public subnet’s route to the internet gateway.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home