{"id":15873,"date":"2026-09-18T10:08:13","date_gmt":"2026-09-18T10:08:13","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=15873"},"modified":"2026-09-18T10:08:13","modified_gmt":"2026-09-18T10:08:13","slug":"amazon-aws-certified-devops-engineer-professional-dop-c02-practice-test-questions-and-exam-dumps-part-14-q261-280","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/amazon-aws-certified-devops-engineer-professional-dop-c02-practice-test-questions-and-exam-dumps-part-14-q261-280\/","title":{"rendered":"Amazon AWS Certified DevOps Engineer &#8211; Professional DOP-C02 Practice Test Questions and Exam Dumps Part 14 Q261-280"},"content":{"rendered":"<h1><\/h1>\n<p><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/aws-certified-devops-engineer-professional-dop-c02-exam-dumps\"><b>Amazon AWS Certified DevOps Engineer &#8211; Professional DOP-C02 Exam Dumps<\/b><\/a><b> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Question 261. Which IAM condition can restrict access based on request attributes?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> IAM policy condition<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> ECR lifecycle rule<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> CloudWatch dashboard<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> ECS task definition<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. IAM policy condition<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IAM policy conditions allow permissions to be granted only when specified conditions are satisfied. Conditions can evaluate attributes associated with a request, such as the requested resource, source IP address, MFA status, encryption requirements, or specific AWS service context. This provides more precise authorization than simply allowing or denying an action for a principal. For example, an organization could require MFA for sensitive actions or restrict access based on specific request characteristics. Conditions are an important part of least-privilege security because they can narrow when a permission is usable. They should be tested carefully because overly restrictive conditions can unintentionally prevent legitimate automation.<\/span><\/p>\n<h3><b>Question 262. What does an IAM role trust policy define?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Which resources are encrypted<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Who can assume the role<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Which Docker images are retained<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> How long CloudWatch logs remain<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Who can assume the role<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">An IAM role trust policy defines which principals are trusted to assume the role. This is different from the permissions policy attached to the role, which defines what actions the role can perform after it has been assumed. In a CI\/CD environment, a trust policy might allow a specific AWS service, IAM principal, or role from another AWS account to assume the role. Cross-account automation depends heavily on correctly configured trust relationships. The trust policy should be as restrictive as practical because allowing an unintended principal to assume a powerful role can create a significant security exposure. Separating trust from permissions helps administrators reason clearly about both identity access and role capabilities.<\/span><\/p>\n<h3><b>Question 263. Which AWS service provides temporary security credentials for role assumption?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Amazon ECR<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> AWS CloudFormation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> AWS Security Token Service<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Amazon CloudWatch<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3. AWS Security Token Service<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Security Token Service, commonly called AWS STS, provides temporary security credentials that can be used to access AWS resources. These credentials are particularly useful for automation, cross-account access, and applications that should not rely on long-lived access keys. IAM roles can be assumed through STS, resulting in temporary credentials with defined permissions and session durations. Using temporary credentials generally reduces the risks associated with permanently stored credentials. In DevOps environments, services such as CodeBuild, deployment automation, and cross-account workflows can use IAM roles and STS to obtain the access required for specific operations. Permissions should still follow least-privilege principles.<\/span><\/p>\n<h3><b>Question 264. What does an AWS Organizations SCP control?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Maximum permissions available to accounts in an organization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Docker image size<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Lambda memory allocation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> CloudWatch metric resolution<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Maximum permissions available to accounts in an organization<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Organizations Service Control Policies, or SCPs, establish permission guardrails for accounts within an AWS Organization. An SCP does not directly grant permissions to users or roles. Instead, it defines the maximum set of permissions that can be available to principals in affected accounts when combined with their identity- or resource-based policies. For example, an organization can use an SCP to prevent accounts from using particular AWS services or performing specific actions. This is useful for centralized governance and security enforcement. Careful testing is important because an SCP can affect many workloads at once. SCPs are particularly valuable in multi-account DevOps environments where consistent organizational controls are required.<\/span><\/p>\n<h3><b>Question 265. Which S3 feature can help prevent accidental deletion or overwriting of important artifacts?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Bucket website hosting<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Object Lock<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Transfer Acceleration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Static routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Object Lock<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Amazon S3 Object Lock can help protect objects from deletion or modification for a configured retention period. It is designed around a write-once-read-many model and can support retention requirements where important data must remain unchanged. For CI\/CD and audit-related storage, Object Lock may be useful when organizations need stronger protection against accidental or unauthorized deletion of critical records. Object Lock should not be treated as a replacement for IAM permissions, encryption, versioning, or other security controls. Teams should also understand retention modes and governance requirements before enabling it because retained objects may not be removable in the same way as ordinary S3 objects.<\/span><\/p>\n<h3><b>Question 266. What does CloudTrail primarily record?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> AWS API activity and account events<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Docker build layers<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> ECS CPU utilization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> CodeArtifact package contents<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. AWS API activity and account events<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS CloudTrail records API activity and other supported events occurring within an AWS environment. These records can provide information about who performed an action, which API operation occurred, when it happened, and other request details. CloudTrail is therefore important for security auditing, troubleshooting, governance, and incident investigation. For example, if an infrastructure resource changes unexpectedly, CloudTrail records can help identify the API activity associated with the change. Organizations can configure trails for broader collection and centralized storage, including organization-level logging. CloudTrail should be combined with appropriate retention, access controls, and monitoring so that audit records remain protected and useful when investigations are required.<\/span><\/p>\n<h3><b>Question 267. Why use a CloudTrail organization trail?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> To build container images<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> To collect activity across organization accounts<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> To increase Lambda memory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> To manage ECS task definitions<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. To collect activity across organization accounts<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A CloudTrail organization trail allows an organization to create a centralized trail configuration that applies across member accounts within AWS Organizations. This can simplify auditing because security and compliance teams do not need to configure equivalent trails manually in every account. Organization-level logging can provide broader visibility into API activity and account events, helping identify changes, investigate incidents, and support governance requirements. Centralized logging should be protected from modification or deletion by unauthorized users. Organizations should also consider the destination bucket, encryption, retention requirements, and access permissions when designing the audit architecture. Consistent CloudTrail configuration is especially valuable in environments using many AWS accounts for development, testing, and production.<\/span><\/p>\n<h3><b>Question 268. What does CloudWatch Application Signals monitor?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Application performance and service health indicators<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> S3 bucket ownership only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> ECR repository names<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> IAM password expiration only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Application performance and service health indicators<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">CloudWatch Application Signals provides application-centric observability for supported applications and services. It focuses on important service-level indicators such as latency, availability, errors, and other performance characteristics so teams can understand whether applications are meeting expected operational behavior. This is different from monitoring only infrastructure metrics because an application may have healthy CPU and memory utilization while still returning errors or experiencing high latency. Application Signals can therefore help DevOps teams evaluate application health during and after deployments. When combined with deployment alarms and automated rollback mechanisms, application-level signals can provide useful evidence for determining whether a newly released version is behaving correctly.<\/span><\/p>\n<h3><b>Question 269. What does AWS X-Ray help trace?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Distributed application requests<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> S3 lifecycle rules<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> IAM password policies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> ECR storage limits<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Distributed application requests<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS X-Ray helps trace requests as they move through distributed applications and services. It can provide visibility into the path of a request, helping developers and operations teams identify where latency, errors, or failures occur. This is particularly useful in architectures that involve multiple services, APIs, databases, queues, or other components where a single user request may cross several systems. X-Ray can help correlate activity and provide a service map that makes dependencies easier to understand. In a DevOps environment, tracing can also support deployment validation by showing whether a new application version introduces increased latency or errors in particular parts of the request path.<\/span><\/p>\n<h3><b>Question 270. What is a major benefit of OpenTelemetry in AWS observability?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> It replaces IAM authorization<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> It provides standardized telemetry collection<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> It manages ECR lifecycle policies<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> It creates CloudFormation stacks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. It provides standardized telemetry collection<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">OpenTelemetry provides a vendor-neutral framework for collecting and exporting observability data such as traces, metrics, and logs. This can help organizations avoid designing application instrumentation around a single monitoring backend. Applications can generate standardized telemetry that can then be sent to supported observability destinations. In AWS environments, OpenTelemetry can complement services such as CloudWatch and X-Ray while providing a consistent instrumentation approach across different applications and technologies. This is particularly valuable in distributed systems where teams may use multiple programming languages and frameworks. Standardized telemetry can improve observability consistency and make it easier to analyze application behavior across service boundaries.<\/span><\/p>\n<h3><b>Question 271. What does AWS AppConfig help separate from application code?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Runtime configuration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> IAM root credentials<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> EC2 hardware<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> CloudTrail history<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Runtime configuration<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS AppConfig allows application configuration to be managed separately from application code. This can include settings such as feature flags, operational parameters, thresholds, or other values that may need to change without rebuilding and redeploying the application itself. Separating configuration from code can make operational changes faster while still allowing controlled deployment strategies, validation, monitoring, and rollback. AppConfig can gradually release configuration changes and integrate with alarms to detect problems during deployment. This is useful for reducing the risk associated with configuration changes because teams can treat configuration updates as controlled releases rather than making unmanaged changes directly inside application binaries or source code.<\/span><\/p>\n<h3><b>Question 272. Which AppConfig feature can automatically stop a problematic configuration rollout?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Deployment alarms<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> ECR lifecycle rules<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> IAM permission boundaries<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> S3 replication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Deployment alarms<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS AppConfig deployment alarms can monitor CloudWatch alarm states during a configuration deployment. If configured alarms enter a failure state according to the deployment configuration, AppConfig can stop or roll back the deployment rather than continuing to expose the problematic configuration to additional clients. This provides an automated safety mechanism for configuration changes. For example, an alarm could monitor application error rates, latency, or another relevant operational metric. The effectiveness of this approach depends on selecting meaningful metrics and setting appropriate alarm thresholds. Deployment alarms should complement configuration validation and gradual rollout strategies so that both configuration correctness and runtime behavior are evaluated.<\/span><\/p>\n<h3><b>Question 273. What does Systems Manager State Manager automate?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Maintaining desired instance configuration<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Creating ECR images<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Managing DNS records<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Building CodePipeline artifacts<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Maintaining desired instance configuration<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Systems Manager State Manager helps automate the process of keeping managed instances in a desired configuration state. Administrators can define associations that specify actions or configurations to be applied to targeted instances according to a schedule or defined conditions. This can support tasks such as ensuring software settings, configuration files, or management agents remain in the required state. State Manager is useful when organizations need consistent configuration across fleets rather than relying on manual administration. It can also help detect and correct configuration changes that would otherwise create drift. Proper targeting and IAM permissions are important so that associations affect only the intended instances and environments.<\/span><\/p>\n<h3><b>Question 274. What does Systems Manager Automation execute?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Automated operational runbooks<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> SQL database queries only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> ECR image scans only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> DNS health checks<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Automated operational runbooks<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">AWS Systems Manager Automation executes predefined or custom runbooks that automate operational tasks across AWS resources. A runbook can contain multiple steps that perform actions such as modifying resources, running commands, invoking AWS APIs, or validating conditions. Automation is useful for repetitive operational procedures because it turns manual processes into controlled and auditable workflows. It can also be triggered by events, schedules, or other automation systems. In a DevOps environment, Systems Manager Automation can support remediation, deployment preparation, incident response, and infrastructure maintenance. Parameters and permissions should be carefully configured so that the automation has sufficient access to perform its tasks without receiving unnecessary administrative privileges.<\/span><\/p>\n<h3><b>Question 275. Which Systems Manager feature runs commands on managed instances?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Session Manager<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Run Command<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> State Manager only<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Parameter Store<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Run Command<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Systems Manager Run Command allows administrators and automation workflows to execute commands on managed instances without requiring direct interactive access through traditional remote login mechanisms. Commands can be sent to one or many targeted instances according to tags, instance identifiers, or other supported targeting mechanisms. This makes Run Command useful for operational maintenance, configuration changes, software installation, troubleshooting, and automated remediation. Execution results can be monitored through Systems Manager and related AWS services. Because Run Command can affect many systems simultaneously, targeting and IAM permissions should be carefully controlled. It is particularly valuable in automated DevOps workflows where repeatable fleet operations are required.<\/span><\/p>\n<h3><b>Question 276. What is Systems Manager Session Manager primarily used for?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Interactive shell access to managed instances<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Container image replication<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> CloudFormation template transformation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> S3 lifecycle management<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Interactive shell access to managed instances<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Systems Manager Session Manager provides interactive access to managed instances without requiring users to expose inbound SSH or RDP ports to the network. Authorized users can establish sessions through Systems Manager, while access is controlled using IAM permissions. This can reduce the need for bastion hosts and externally accessible management ports. Session activity can also be integrated with logging and auditing mechanisms depending on the configuration. Session Manager is therefore useful for secure operational troubleshooting and administration. It should still be governed through least-privilege permissions, appropriate instance roles, and logging controls so that interactive access remains accountable and restricted to authorized personnel.<\/span><\/p>\n<h3><b>Question 277. What can Systems Manager Maintenance Windows schedule?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Recurring operational tasks<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> IAM root account creation<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> ECR repository encryption<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> CloudFormation syntax validation<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Recurring operational tasks<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Systems Manager Maintenance Windows allow organizations to schedule operational tasks during defined time periods. These tasks can include patching, running commands, executing Automation runbooks, or performing other supported maintenance activities against targeted resources. Maintenance windows help organizations coordinate disruptive or resource-intensive operations with planned schedules instead of running them unpredictably during business-critical periods. Targets and task permissions should be configured carefully to ensure that maintenance operations affect only the intended resources. They can be particularly useful for large fleets where manual scheduling would be difficult. Combined with Patch Manager and Automation, Maintenance Windows can form an important part of a repeatable infrastructure maintenance process.<\/span><\/p>\n<h3><b>Question 278. Which Systems Manager feature provides software and inventory information?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Inventory<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> EventBridge<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> CloudTrail<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> AppConfig<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Inventory<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Systems Manager Inventory collects information about managed instances and their installed software, applications, files, network configuration, and other supported inventory data. This information helps operations and security teams understand what is deployed across an instance fleet. Inventory can support compliance reviews, troubleshooting, software management, and vulnerability-management processes by providing centralized visibility into installed components. It is especially useful in environments where administrators need to answer questions about software versions or instance configurations across many systems. Inventory does not itself replace vulnerability scanning or patch management, but it provides valuable data that can support those activities and improve overall infrastructure visibility.<\/span><\/p>\n<h3><b>Question 279. Which deployment strategy sends a new version to a small percentage first?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> All-at-once<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Canary<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Immediate replacement<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Static deployment<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2. Canary<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A canary deployment introduces a new application version to a small percentage of users, traffic, or infrastructure before expanding the rollout. This creates an opportunity to observe the new version under real operating conditions while limiting the number of users exposed if a problem occurs. Metrics such as error rates, latency, health checks, and application-specific indicators can be monitored during the canary phase. If the results meet defined expectations, additional traffic can be shifted to the new version. If problems are detected, the rollout can be stopped or rolled back. Canary strategies are therefore useful for reducing deployment risk while preserving an automated and measurable release process.<\/span><\/p>\n<h3><b>Question 280. What is the primary purpose of a blue\/green deployment?<\/b><\/h3>\n<ol>\n<li><b><\/b><span style=\"font-weight: 400;\"> Maintain separate old and new environments for controlled traffic switching<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2.<\/b><span style=\"font-weight: 400;\"> Remove all monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3.<\/b><span style=\"font-weight: 400;\"> Disable automated testing<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4.<\/b><span style=\"font-weight: 400;\"> Store package dependencies<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1. Maintain separate old and new environments for controlled traffic switching<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A blue\/green deployment maintains two application environments: the currently active environment and a separate environment containing the new version. The new environment can be tested and validated before production traffic is shifted to it. Traffic switching can be performed all at once or through a controlled strategy depending on the deployment architecture. If the new environment causes problems, traffic can potentially be returned to the previous environment, providing a straightforward rollback path. Blue\/green deployments are especially useful when teams need strong separation between the old and new versions. They require sufficient infrastructure capacity and careful management of stateful resources, databases, configuration, and traffic routing.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Amazon AWS Certified DevOps Engineer &#8211; Professional DOP-C02 Exam Dumps and Practice Test Dumps &nbsp; Question 261. Which IAM condition can restrict access based on request attributes? IAM policy condition 2. ECR lifecycle rule 3. CloudWatch dashboard 4. ECS task definition Correct Answer: 1. IAM policy condition Explanation: IAM policy conditions allow permissions [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15873"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=15873"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15873\/revisions"}],"predecessor-version":[{"id":15929,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/15873\/revisions\/15929"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=15873"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=15873"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=15873"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}