About the Exam

AWS Certified DevOps Engineer - Professional (DOP-C02) is a professional-level AWS certification exam for people in DevOps engineer roles. It validates technical expertise in provisioning, operating, and managing distributed application systems on AWS, including continuous delivery, infrastructure as code, monitoring and logging, incident response, security, and compliance. AWS recommends at least 2 years of experience in provisioning, operating, and managing AWS environments, plus experience with the software development lifecycle and scripting.

Exam Topics

  • SDLC Automation22%
  • Configuration Management and IaC17%
  • Resilient Cloud Solutions15%
  • Monitoring and Logging15%
  • Incident and Event Response14%
  • Security and Compliance17%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated July 6, 2026 at 10:42 PM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

Security and Compliance

A company uses AWS Organizations to manage multiple accounts. Information security policies require that every unencrypted Amazon EBS volume be designated as non-compliant. A DevOps engineer must deploy the solution automatically and ensure that this compliance check is always in place.

Which solution will accomplish this?

Explanation

AWS Config’s ENCRYPTED_VOLUMES managed rule reports attached EBS volumes as NON_COMPLIANT when they are unencrypted. An organization AWS Config rule centrally deploys the rule across member accounts, including accounts that subsequently join the organization. An SCP that denies actions to stop or delete AWS Config helps ensure the ongoing compliance evaluation cannot be disabled by member accounts.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Resilient Cloud Solutions

A company hosts a web application in an AWS Region. For disaster recovery, it uses a second Region as a standby. The disaster recovery requirements specify that session data must be replicated between Regions in near real time, and 1% of requests must be routed to the secondary Region to continuously validate system functionality. In addition, if service in the primary Region is disrupted, traffic must automatically route to the secondary Region, which must be able to scale to support all traffic.

How should a DevOps engineer satisfy these requirements?

Explanation

Amazon DynamoDB global tables automatically replicate table data across AWS Regions, providing the near-real-time multi-Region session-data replication required. Amazon Route 53 weighted routing sends traffic in specified proportions, so records weighted at 99% and 1% continuously exercise the secondary Region. When health checks mark the primary endpoint unhealthy, Route 53 stops returning that endpoint and routes traffic to the healthy secondary deployment. Elastic Beanstalk can host the application in each Region and scale the secondary environment as needed. DynamoDB global tables and Route 53 weighted routing support these capabilities.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Security and Compliance

A DevOps Engineer must back up sensitive Amazon S3 objects stored in an S3 bucket with a private bucket policy by using S3 Cross-Region Replication. The objects must be copied to a target bucket in another AWS Region and AWS account.

Which actions must be taken to enable this replication?

Choose three
Explanation

Cross-account S3 Cross-Region Replication uses an IAM replication role in the source account, a replication rule configured on the source bucket, and a destination-bucket policy that grants the source-account replication role permission to replicate objects into that bucket. S3 replication rules specify the destination from the source bucket; the destination does not need its own replication rule or replication role.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Resilient Cloud Solutions

A DevOps engineer configures two Amazon S3 event notifications for an S3 bucket through the S3 console. Both event notifications are invoked when an object PUT action takes place. One event notification invokes an AWS Lambda function when the file suffix is .csv. Another event notification invokes an Amazon Simple Notification Service (Amazon SNS) topic when the file suffix is .xlsx.

The DevOps engineer observes that files with the .csv suffix successfully invoke the Lambda function. However, files with the .xlsx suffix do not invoke the SNS topic.

Which reason explains why the SNS topic is not invoked when .xlsx files are added to the S3 bucket?

Explanation

Amazon S3 must have permission to publish event messages to an Amazon SNS topic. This permission is granted through an IAM resource policy on the destination SNS topic that allows the S3 service principal to perform sns:Publish, typically constrained to the source bucket and account. Lambda and SNS can both receive ObjectCreated:Put notifications, and separate non-overlapping suffix filters can coexist.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Resilient Cloud Solutions

A company runs an application that uses a MySQL-compatible Amazon Aurora Multi-AZ DB cluster for its database. A cross-Region read replica was created for disaster-recovery purposes. A DevOps engineer needs to automate promotion of the replica so that it becomes the primary database instance if a failure occurs.

Which solution will achieve this?

Explanation

Aurora MySQL cross-Region read replicas can be promoted to standalone DB clusters through the Amazon RDS promotion API. An EventBridge-triggered Lambda function can detect the failure and invoke that promotion, while updating the active endpoint in Systems Manager Parameter Store. Reloading that parameter after a database connection failure directs the application to the newly promoted cluster, satisfying both promotion and traffic redirection requirements. AWS documentation: Promoting a read replica to a DB cluster for Aurora MySQL

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home