{"id":15868,"date":"2026-09-18T10:09:27","date_gmt":"2026-09-18T10:09:27","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15868"},"modified":"2026-09-18T10:09:27","modified_gmt":"2026-09-18T10:09:27","slug":"amazon-aws-certified-devops-engineer-professional-dop-c02-practice-test-questions-and-exam-dumps-part-9-q161-180","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/amazon-aws-certified-devops-engineer-professional-dop-c02-practice-test-questions-and-exam-dumps-part-9-q161-180\/","title":{"rendered":"Amazon AWS Certified DevOps Engineer &#8211; Professional DOP-C02 Practice Test Questions and Exam Dumps Part 9 Q161-180"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aws-certified-devops-engineer-professional-dop-c02-exam-dumps\"><b>Amazon AWS Certified DevOps Engineer &#8211; Professional DOP-C02 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 161. What controls permissions for AWS resources?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> IAM policies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> CloudWatch dashboards<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> ECR tags<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> CodeBuild reports<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. IAM policies<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Identity and Access Management policies define what actions principals are allowed or denied to perform on AWS resources. Policies can be attached to users, groups, roles, or resources depending on the authorization model being used. In DevOps environments, IAM policies are essential for controlling access to deployment pipelines, build systems, repositories, infrastructure services, and production resources. Following least-privilege principles helps reduce unnecessary permissions. Policies can also use conditions to restrict access based on factors such as resource tags, source identity, or requested AWS Region, providing more precise control over automated and human access.<\/span><\/p>\n<h3><b>Question 162. What restricts permissions delegated through an IAM role?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Security group<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Permission boundary<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> CloudFormation template<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> EventBridge rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Permission boundary<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An IAM permissions boundary defines the maximum permissions that an identity-based policy can grant to an IAM principal. It does not directly grant permissions by itself; instead, it establishes a limit on the permissions the principal can receive from other applicable identity policies. This is useful in large organizations where administrators need to delegate IAM role or user creation without allowing delegated administrators to create principals with unrestricted permissions. Permission boundaries can therefore provide an additional security control for CI\/CD environments and development teams that need to create or manage IAM roles while remaining within centrally defined authorization limits.<\/span><\/p>\n<h3><b>Question 163. What analyzes unintended AWS access paths?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS IAM Access Analyzer<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Amazon ECR<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> AWS CodeArtifact<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> CloudWatch Logs<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AWS IAM Access Analyzer<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IAM Access Analyzer helps organizations identify resources that are accessible from outside their intended trust boundaries. It can analyze resource-based policies and identify external access paths involving resources such as S3 buckets, IAM roles, KMS keys, and other supported services. This can help security and DevOps teams discover unintended cross-account or public access. Access Analyzer findings can then be reviewed and addressed by modifying resource policies or permissions. It complements normal IAM policy reviews by providing visibility into effective external access rather than requiring administrators to manually inspect every possible policy relationship.<\/span><\/p>\n<h3><b>Question 164. What provides temporary AWS credentials?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS STS<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Amazon ECR<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> CloudFormation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> CodeBuild<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AWS STS<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Security Token Service provides temporary security credentials that can be used to access AWS resources. Temporary credentials are particularly useful for automation, cross-account access, federated identities, and applications that should not rely on long-term access keys. In DevOps workflows, IAM roles can be assumed through STS to obtain temporary credentials for deployment or administrative operations. These credentials have a limited lifetime and include an access key ID, secret access key, and session token. Using temporary role credentials reduces the need to distribute permanent credentials across build systems, deployment servers, and automation scripts.<\/span><\/p>\n<h3><b>Question 165. What can restrict AWS accounts within an organization?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Service Control Policies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> CloudWatch alarms<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> ECR lifecycle policies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> CodeBuild projects<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Service Control Policies<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Organizations Service Control Policies, or SCPs, define the maximum available permissions for accounts within an organization or organizational unit. SCPs do not grant permissions directly; instead, they establish guardrails that restrict which AWS actions can be used by principals in affected accounts. For example, an organization can use SCPs to prevent accounts from disabling certain security services or using specific Regions. This makes SCPs useful for centralized governance. IAM policies still determine what individual principals can actually perform, but an SCP can prevent an otherwise permitted action from being available within the account.<\/span><\/p>\n<h3><b>Question 166. What stores application secrets centrally?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Secrets Manager<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Amazon CloudWatch<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> AWS CodeDeploy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Amazon Route 53<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AWS Secrets Manager<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Secrets Manager provides centralized storage and management for sensitive information such as database credentials, API keys, and other application secrets. Applications and automation systems can retrieve secrets through controlled AWS APIs instead of embedding credentials directly in source code or configuration files. Secrets Manager also supports features such as encryption using AWS KMS and automated secret rotation for supported scenarios. In DevOps environments, integrating Secrets Manager with build and deployment processes helps reduce the risk of exposing credentials in repositories, scripts, or pipeline configuration while providing centralized access control.<\/span><\/p>\n<h3><b>Question 167. What identifies a specific secret version in Secrets Manager?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Version stage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> ECR digest<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Deployment group<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> CloudFormation stack ID<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Version stage<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Secrets Manager uses version stages to identify the role of different versions of a secret. Common stages include AWSCURRENT and AWSPREVIOUS, which help applications and rotation workflows determine which secret version should currently be used. During rotation, staging labels can move between versions as the new credential becomes active. This allows applications to retrieve the current secret without having to hard-code a specific version identifier. Version staging is especially useful in automated rotation workflows because the active credential can change while applications continue requesting the current staged version.<\/span><\/p>\n<h3><b>Question 168. What encrypts Secrets Manager secret values?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS KMS<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> CloudFront<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> CodePipeline<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Systems Manager Inventory<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AWS KMS<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Secrets Manager encrypts secret values at rest using AWS Key Management Service keys. By default, Secrets Manager can use an AWS managed KMS key, while organizations can also configure a customer managed KMS key when they require additional control over key policies and lifecycle management. Access to the secret and the associated encryption key must both be appropriately authorized. Using KMS provides centralized cryptographic controls while Secrets Manager handles secret storage and retrieval. This separation allows organizations to manage sensitive credentials without exposing their plaintext values in application source code or ordinary configuration files.<\/span><\/p>\n<h3><b>Question 169. What can store non-secret configuration parameters?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Systems Manager Parameter Store<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> CodeDeploy deployment group<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> ECR image digest<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> CloudTrail trail<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Systems Manager Parameter Store<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Systems Manager Parameter Store provides centralized storage for configuration parameters and can also store sensitive values as SecureString parameters. It is useful for values such as application settings, environment-specific configuration, URLs, feature settings, and other parameters that should not be hard-coded into applications or deployment scripts. Parameters can be organized using hierarchical names, making it easier to separate values by application and environment. IAM policies control who or what can retrieve parameters. Parameter Store is commonly integrated with CodeBuild, ECS, Lambda, and other AWS services to provide configuration at runtime or during deployment.<\/span><\/p>\n<h3><b>Question 170. What creates a CloudWatch metric from matching log text?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Metric filter<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> StackSet<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Deployment group<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> IAM role<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Metric filter<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A CloudWatch Logs metric filter searches incoming log events for a defined pattern and publishes the number of matching events as a CloudWatch metric. This allows operational information contained in application logs to become measurable and usable with dashboards and alarms. For example, an organization could create a metric filter that counts occurrences of a particular error message and then configure an alarm when the count exceeds an acceptable threshold. Metric filters are useful when applications already produce meaningful log messages but do not expose dedicated metrics for every operational condition that needs to be monitored.<\/span><\/p>\n<h3><b>Question 171. What centralizes AWS API activity records?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS CloudTrail<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> AWS CodeArtifact<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Amazon ECR<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> AWS AppConfig<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AWS CloudTrail<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS CloudTrail records API activity and other supported account events, providing visibility into actions performed against AWS resources. CloudTrail records can include information about the identity that made a request, the service involved, the action performed, and other event details. Organizations use these records for auditing, security investigations, troubleshooting, and operational monitoring. In larger environments, an organization trail can provide centralized logging across multiple AWS accounts. Protecting the resulting log files is important because CloudTrail records may contain evidence needed to understand configuration changes or investigate unexpected activity.<\/span><\/p>\n<h3><b>Question 172. What lets CloudFormation manage existing resources?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Resource import<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Deployment alarm<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> CodeBuild cache<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> ECR replication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Resource import<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">CloudFormation resource import allows supported existing AWS resources to be brought under CloudFormation management without necessarily recreating them. This can help organizations transition manually created infrastructure into an infrastructure-as-code model. During an import operation, the resource must meet the requirements for the relevant resource type and be described appropriately in the CloudFormation template. Once successfully imported, the resource becomes associated with the stack and can be managed through subsequent CloudFormation operations. Resource import can therefore help teams gradually move existing environments toward consistent declarative infrastructure management.<\/span><\/p>\n<h3><b>Question 173. What controls parallelism during StackSets operations?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Operation preferences<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Buildspec phases<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> IAM access keys<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> ECR lifecycle rules<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Operation preferences<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">CloudFormation StackSets operation preferences control how StackSet operations are performed across target accounts and Regions. These settings can influence deployment concurrency and failure behavior, allowing administrators to control how aggressively changes are rolled out. Managing concurrency is important when deploying infrastructure across a large number of accounts because simultaneously changing every environment can increase operational impact. StackSets can use deployment strategies that gradually process targets and stop or continue based on configured failure tolerances. Operation preferences therefore provide important control over the scale and pace of centralized infrastructure deployments.<\/span><\/p>\n<h3><b>Question 174. What service can orchestrate multi-step automation workflows?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Systems Manager Automation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Amazon Route 53<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> ECR<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> CloudWatch Dashboard<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Systems Manager Automation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Systems Manager Automation allows organizations to define and execute automated operational workflows using Automation runbooks. A runbook can contain multiple steps that perform tasks such as modifying AWS resources, running commands, invoking other AWS services, or validating conditions. Automation is useful for repeatable operational procedures because the workflow can be standardized rather than performed manually each time. It can also be invoked by other AWS services and integrated into remediation processes. Organizations can use Automation for deployment-related operations, incident response, patching workflows, infrastructure maintenance, and other routine administrative activities.<\/span><\/p>\n<h3><b>Question 175. What feature automatically fixes certain AWS Config violations?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Config remediation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> CodePipeline approval<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> ECR replication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> CloudWatch dashboard<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Config remediation<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Config remediation allows organizations to automatically or manually invoke corrective actions when resources violate defined Config rules. Remediation actions can use Systems Manager Automation documents to perform standardized corrective operations. For example, an organization may configure remediation to address a resource that does not meet a required security configuration. Automated remediation can reduce the time between detecting a configuration problem and correcting it. However, remediation actions should be tested carefully because an incorrect automated response could modify production resources unexpectedly. Appropriate IAM permissions, rule conditions, and remediation parameters are important parts of a safe implementation.<\/span><\/p>\n<h3><b>Question 176. What checks resources against defined configuration rules?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS Config<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> CodeBuild<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> CodeArtifact<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Lambda aliases<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AWS Config<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Config continuously records supported resource configuration information and can evaluate resources against defined configuration rules. These rules can assess whether resources meet organizational requirements, such as security or operational standards. Config provides historical configuration information as well, allowing teams to investigate how resource settings changed over time. In DevOps environments, Config can be integrated with remediation workflows so that detected violations can trigger corrective actions. This makes Config useful not only for visibility but also for continuous governance of infrastructure that is created or modified through automated deployment processes.<\/span><\/p>\n<h3><b>Question 177. What helps monitor application latency and errors in CloudWatch?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Application Signals<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> ECR lifecycle policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Stack policy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> CodeArtifact upstream<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Application Signals<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon CloudWatch Application Signals provides application performance monitoring capabilities focused on key application health indicators. It can help teams understand service performance through measurements such as latency, availability, and error-related behavior. This visibility is valuable during deployments because teams need to determine whether a newly released version is performing as expected. Application Signals can complement logs, metrics, traces, and deployment alarms by providing service-level views of application health. When integrated into an operational workflow, these signals can help teams identify degradation and connect application behavior with changes introduced during software delivery.<\/span><\/p>\n<h3><b>Question 178. What provides distributed tracing for applications?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS X-Ray<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> CodeArtifact<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> ECR<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> IAM Access Analyzer<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AWS X-Ray<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS X-Ray provides distributed tracing that helps developers and operations teams analyze requests as they move through multiple components of an application. A single request may pass through services such as API endpoints, Lambda functions, databases, and other components, making traditional logs difficult to correlate. X-Ray traces can help identify where latency or errors occur within the request path. This is useful for troubleshooting microservices and distributed applications, particularly after deployments. Tracing information can complement CloudWatch metrics and logs by providing a more connected view of the application&#8217;s request flow.<\/span><\/p>\n<h3><b>Question 179. What manages application configuration independently from code?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS AppConfig<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> CodeDeploy<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> ECR<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> CloudTrail<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AWS AppConfig<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS AppConfig allows applications to retrieve and use configuration data separately from the application code itself. This can include feature flags, operational settings, tuning parameters, and other values that may need to change without rebuilding the application. AppConfig provides controlled deployment mechanisms so configuration changes can be gradually introduced and monitored. Separating configuration from code can make operational changes faster and reduce unnecessary application deployments. It also provides mechanisms for validation and rollback, helping organizations reduce the risk of configuration errors affecting all application users simultaneously.<\/span><\/p>\n<h3><b>Question 180. What helps prevent excessive permissions in CI\/CD roles?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Least privilege<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> AllAtOnce deployment<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> ECR tag naming<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> CloudWatch dashboard<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Least privilege<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The principle of least privilege means granting a CI\/CD role only the permissions required to perform its intended tasks. For example, a build role may need permission to read source dependencies and write build artifacts, while a deployment role may need access to specific deployment resources. Avoiding broad permissions reduces the potential impact if credentials or automation components are compromised. IAM policies, permission boundaries, resource policies, and role separation can all support least-privilege designs. In DevOps environments, reviewing permissions regularly is important because pipelines evolve and may accumulate access that is no longer necessary.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Amazon AWS Certified DevOps Engineer &#8211; Professional DOP-C02 Exam Dumps and Practice Test Dumps &nbsp; Question 161. What controls permissions for AWS resources? IAM policies 2. CloudWatch dashboards 3. ECR tags 4. CodeBuild reports Correct Answer: 1. IAM policies Explanation: AWS Identity and Access Management policies define what actions principals are allowed or [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15868"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15868"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15868\/revisions"}],"predecessor-version":[{"id":15934,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15868\/revisions\/15934"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15868"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15868"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15868"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}