QuestionQ1
Security and ComplianceA company uses an AWS Organizations organization to manage its 500 AWS accounts. All features are enabled in the organization, and the AWS accounts reside in a single OU. Developers must use the CostCenter tag key for every resource in the organization's member accounts. Some teams do not use the CostCenter tag key when tagging their Amazon EC2 instances.
The cloud team created a script that scans all EC2 instances in the organization's member accounts. When an EC2 instance lacks a CostCenter tag key, the script notifies the AWS account administrators. To prevent receiving this notification, some developers apply the CostCenter tag key with an arbitrary string as its tag value.
The cloud team must ensure that every EC2 instance in the organization uses a CostCenter tag key with the correct cost center value.
Which solution meets these requirements?
QuestionQ2
SDLC AutomationA company uses a series of separate Amazon CloudFormation templates to deploy its multi-Region applications. The templates must be deployed in a particular order. The company is making more template changes than it previously anticipated and wants to deploy new templates more efficiently. In addition, the data engineering team must receive notification of every template change.
What should the company do to meet these goals?
Community Discussion
QuestionQ3
Security and ComplianceA company’s security team mandates that every external Application Load Balancer (ALB) and Amazon API Gateway API be associated with an AWS WAF web ACL. The company has hundreds of AWS accounts, all contained in one AWS Organizations organization. The company has enabled AWS Config for the organization. During an audit, the company discovers that some internet-facing ALBs have no associated AWS WAF web ACLs.
Which combination of actions should a DevOps engineer take to prevent future violations?
Community Discussion
QuestionQ4
Monitoring and LoggingA company uses a continuous integration pipeline in which it builds container images with AWS CodeBuild. The generated images are stored in Amazon Elastic Container Registry (Amazon ECR).
Reviewing and remediating image vulnerabilities is taking the company too long. The company needs to rapidly identify image vulnerabilities and notify the security team about them.
Which combination of steps meets these requirements with the LEAST operational overhead?
Community Discussion
QuestionQ5
Resilient Cloud SolutionsA DevOps engineer manages a Java-based application running in an Amazon Elastic Container Service (Amazon ECS) cluster on AWS Fargate. Auto scaling is not configured for the application.
The DevOps engineer has identified the Java Virtual Machine (JVM) thread count as a good indicator for when the application should scale. The application serves customer traffic on port 8080 and exposes JVM metrics on port 9404.
Application usage has recently increased. The DevOps engineer must configure auto scaling for the application.
Which solution meets these requirements with the LEAST operational overhead?


Community Discussion