Sign In
Home/AWS/Associate SOA-C03: AWS Certified CloudOps Engineer - Associate SOA-C03/Free questions

AWS Certified CloudOps Engineer - Associate SOA-C03: AWS Certified CloudOps Engineer - Associate SOA-C03 — Free Practice Questions

10 free sample questions from a bank of 10, with the correct answers and explanations. No signup required — start practising right now.

1A CloudOps engineer is examining the following AWS CloudFormation template: Why will the stack creation fail?
AWS Certified CloudOps Engineer - Associate SOA-C03: AWS Certified CloudOps Engineer - Associate SOA-C03 question 1
  • The Outputs section of the CloudFormation template was omitted.
  • The Parameters section of the CloudFormation template was omitted.
  • The PrivateDnsName cannot be sot from a CloudFormation template.
  • The VPC was not specified in the CloudFormation template.
Answer: C
2A company applies user-defined tags to resources that are associated with the company's AWS workloads. Twenty days after applying the tags, the company notices that it cannot use the tags to filter views in the AWS Cost Explorer console. What is the reason for this issue?
  • It takes at least 30 days to be able to use tags to filter views in Cost Explorer.
  • The company has not activated the user-defined tags for cost allocation.
  • The company has not created an AWS Cost and Usage Report.
  • The company has not created a usage budget in AWS Budgets.
Answer: B
3An environment consists of 100 Amazon EC2 Windows instances. The Amazon CloudWatch agent is deployed and running on all EC2 instances with a baseline configuration file to capture log files. There is a new requirement to capture the DHCP log files that exist on 50 of the instances. What is the MOST operationally efficient way to meet this new requirement?
  • Create an additional CloudWatch agent configuration filo to capture the DHCP logs. Use the AWS Systems Manager Run Command to restart the CloudWatch agent on each EC2 instance with the append-config option to apply the additional configuration file.
  • Log in to each EC2 instance with administrator rights. Create a PowerShell script to push the needed baseline log files and DHCP log files to CloudWatch.
  • Run the CloudWatch agent configuration file wizard on each EC2 instance. Verify that the baseline log files are included and add the DHCP log files during the wizard creation process.
  • Run the CloudWatch agent configuration file wizard on each EC2 instance and select the advanced detail level. This will capture the operating system log files.
Answer: A
4A company is storing backups in an Amazon S3 bucket. The backups must not be deleted for at least 3 months after the backups are created. What should a CloudOps engineer do to meet this requirement?
  • Configure an IAM policy that denies the s3:DeleteObject action for all users. Three months after an object is written, remove the policy.
  • Enable S3 Object Lock on a new S3 bucket in compliance mode. Place all backups in the new S3 bucket with a retention period of 3 months.
  • Enable S3 Versioning on the existing S3 bucket. Configure S3 Lifecycle rules to protect the backups.
  • Enable S3 Object Lock on a new S3 bucket in governance mode. Place all backups in the new S3 bucket with a retention period of 3 months.
Answer: B
5A company's CloudOps engineer is troubleshooting communication between the components of an application. The company configured VPC flow logs to be published to Amazon CloudWatch Logs However, there are no logs in CloudWatch Logs. What could be blocking the VPC flow logs from being published to CloudWatch Logs?
  • The IAM policy that is attached to the IAM role for the flow log is missing the logs:CreateLogGroup permission.
  • The IAM policy that is attached to the IAM role for the flow log is missing the logs:CreateExportTask permission.
  • The VPC is configured for IPv6 addresses.
  • The VPC is peered with another VPC in the AWS account
Answer: A
6A company is migrating a legacy application to AWS. The company manually installs and configures the legacy application on Amazon EC2 instances across multiple Availability Zones. The company sets up an Application Load Balancer (ALB) for the application. The company sets the target group routing algorithm to weighted random. The application requires session affinity. After the company deploys the application, users report random application errors that were not present in the legacy version of the application. The target group health checks do not show any failures. The company must resolve the application errors. Which solution will meet this requirement?
  • Set the routing algorithm of the target group to least outstanding requests.
  • Turn on anomaly mitigation for the target group.
  • Turn off the cross-zone load balancing attribute of the target group.
  • Increase the deregistration delay attribute of the target group.
Answer: A
7A company is using an Amazon Aurora MySQL DB cluster that has point-in-time recovery, backtracking, and automatic backup enabled. A CloudOps engineer needs to be able to roll back the DB cluster to a specific recovery point within the previous 72 hours. Restores must be completed in the same production DB cluster. Which solution will meet these requirements?
  • Create an Aurora Replica. Promote the replica to replace the primary DB instance.
  • Create an AWS Lambda function to restore an automatic backup to the existing DB cluster.
  • Use backtracking to rewind the existing DB cluster to the desired recovery point.
  • Use point-in-time recovery to restore the existing DB duster to the desired recovery point.
Answer: C
8A CloudOps engineer is troubleshooting an AWS CloudFormation stack creation that failed. Before the CloudOps engineer can identify the problem, the stack and its resources are deleted. For future deployments, the CloudOps engineer must preserve any resources that CloudFormation successfully created. What should the CloudOps engineer do to meet this requirement?
  • Set the value of the DisableRollback parameter to False during stack creation.
  • Set the value of the OnFailure parameter to DO_NOTHING during stack creation.
  • Specify a rollback configuration that has a rollback trigger of DO_NOTHING during stack creation
  • Set the value of the OnFailure parameter to ROLLBACK during stack creation.
Answer: B
9A company plans to run a public web application on Amazon EC2 instances behind an Elastic Load Balancing (ELB) load balancer. The company’s security team wants to protect the website by using AWS Certificate Manager (ACM) certificates. The load balancer must automatically redirect any HTTP requests to HTTPS. Which solution will meet these requirements?
  • Create an Application Load Balancer that has one HTTPS listener on port 80. Attach an SSL/TLS certificate to listener port 80. Create a rule to redirect requests from HTTP to HTTPS.
  • Create an Application Load Balancer that has one HTTP listener on port 80 and one HTTPS protocol listener on port 443. Attach an SSL/TLS certificate to listener port 443. Create a rule to redirect requests from port 80 to port 443.
  • Create an Application Load Balancer that has two TCP listeners on port 80 and port 443. Attach an SSL/TLS certificate to listener port 443. Create a rule to redirect requests from port 80 to port 443.
  • Create a Network Load Balancer that has two TCP listeners on port 80 and port 443. Attach an SSL/TLS certificate to listener port 443. Create a rule to redirect requests from port 80 to port 443.
Answer: B
10A company uses AWS Organizations to manage a set of AWS accounts. The company has set up organizational units (OUs) in the organization. An application OU supports various applications. A CloudOps engineer must prevent users from launching Amazon EC2 instances that do not have a CostCenter-Project tag into any account in the application OU. The restriction must apply only to accounts in the application OU. Which solution will meet these requirements?
  • Create an IAM group that has a policy that allows the ec2:RunInstances action when the CostCenter-Project tag is present. Place all IAM users who need access to the application accounts in the IAM group.
  • Create a service control policy (SCP) that denies the oc2:RunInstances action when the CostCenter-Project tag is missing. Attach the SCP to the application OU.
  • Create an IAM role that has a policy that allows the oc2:RunInstances action when the CostCenter-Project tag is present. Attach the IAM role to the IAM users that are in the application OU accounts.
  • Create a service control policy (SCP) that denies the ec2:RunInstances action when the CostCenter-Project tag is missing. Attach the SCP to the root OU.
Answer: B

Want the full bank of 10 questions for AWS Certified CloudOps Engineer - Associate SOA-C03: AWS Certified CloudOps Engineer - Associate SOA-C03? See all practice exams.