
Simula la experiencia real del examen con 75 preguntas y un límite de tiempo de 180 minutos. Practica con respuestas verificadas por IA y explicaciones detalladas.
Impulsado por IA
Cada respuesta es verificada de forma cruzada por 3 modelos de IA líderes para garantizar la máxima precisión. Obtén explicaciones detalladas por opción y análisis profundo de cada pregunta.
A company operates 10 Amazon OpenSearch Service domains with Auto-Tune enabled across 2 AWS Regions and needs to visualize every Auto-Tune action (for example, memory or shard rebalancing adjustments) on an Amazon CloudWatch dashboard at 1-minute resolution for the last 24 hours; which solution will meet this requirement?
A logistics enterprise operates a multi-OU AWS Organizations setup across two AWS Regions with 68 member accounts and has acquired a fintech startup that uses 11 standalone AWS accounts with separate billing; the platform team must centralize administration under a single management account while retaining break-glass full administrative control across all imported accounts and must centrally aggregate and group security findings across the entire environment with new accounts automatically included as they are onboarded; which combination of actions should the platform team take to meet these requirements with minimal operational overhead? (Choose two.)
A DevOps engineer is building a data-forwarding service where an AWS Lambda function reads batched records from an Amazon Kinesis Data Streams shard and forwards them to an internal ERP SOAP endpoint over a VPC. Roughly 12% of incoming records fail validation and must be handled manually; the Lambda event source mapping is configured with an Amazon SQS dead-letter queue (DLQ) as an on-failure destination, and the function uses batch processing with retries enabled. During load testing, the engineer observes that the DLQ contains many records that have no data issues and were already accepted by the ERP service, indicating that successful items from partially failing batches are being retried and eventually sent to the DLQ along with the failures. Which event source configuration change should the engineer implement to reduce the number of error-free records sent to the DLQ while preserving current throughput and retry behavior?
A global media company uses AWS Organizations with two OUs (root and analytics); the root OU has a single SCP that contains one Allow statement for all actions on all resources, while the analytics OU (which contains four accounts including the ext-ml account, ID 222222222222) has an SCP that allows only s3:* and glue:* and explicitly denies all other actions by using a Deny statement with NotAction [s3:, glue:] on all resources; in the ext-ml account, a DevOps engineer's IAM user has the AdministratorAccess policy attached, and when the engineer attempts in us-east-1 to create an Amazon RDS db.m6g.large instance via the console and AWS CLI (rds:CreateDBInstance), the request fails with AccessDeniedException indicating it was blocked by an organization service control policy. Which change will allow the engineer to successfully create the RDS instance in the ext-ml account?
A media streaming startup operates a multi-account environment in AWS Organizations with all features enabled. The operations (source) account uses AWS Backup in us-west-2 to protect 120 Amazon EBS volumes and encrypts recovery points with a customer managed KMS key (alias/ops-backup). To meet DR requirements, the company configured cross-account copy in the management account, created a backup vault named dr-vault and a customer managed KMS key (alias/dr-backup) in a newly created DR account, and then updated the backup plan in the operations account to copy all recovery points to the DR account's dr-vault. When a backup job runs in the operations account, recovery points are created successfully in the operations account, but no copies appear in the DR account's dr-vault. Which combination of steps will allow AWS Backup to copy recovery points to the DR account's vault? (Choose two.)
¿Quieres practicar todas las preguntas en cualquier lugar?
Descarga Cloud Pass gratis — incluye exámenes de práctica, seguimiento de progreso y más.
A global logistics company ingests telemetry from 12,000 handheld scanners across 3 AWS Regions; each device type writes to a dedicated Amazon CloudWatch Logs log group per Region, totaling about 90 log groups. Over the past 14 days, CloudWatch Logs ingestion charges have increased by 68% with no planned changes. A DevOps engineer must quickly determine which device types or Regions are driving the spike in ingestion to prioritize remediation. Which solution is the MOST operationally efficient?
A DevOps engineer deploys an Auto Scaling group of 8 Amazon EC2 instances without public IPs across two private subnets (10.20.1.0/24 and 10.20.2.0/24) in us-east-2; due to a new FedRAMP High control, the VPC has no internet gateway or NAT gateway and all internet egress is prohibited, and the user data uses the AWS CLI to download artifacts from s3://company-artifacts-prod/builds/2.7.4/app.tar.gz at boot, yet while the instances report healthy status checks the application is not installed because the download fails. Which action will install the application while complying with the no-internet egress requirement?
A university consortium uses AWS Organizations across two Regions with four OUs and a delegated administrator account named platform-ops, and the research OU (58 AWS accounts) must ensure that, before any AWS CloudFormation stack create or update runs in us-east-1 or eu-west-1, every Amazon EBS volume and Amazon SQS queue defined in the stack has server-side encryption enabled with the KMS key alias alias/research-default and that this control is enforced consistently across all accounts in that OU—what solution will enforce this policy prior to CloudFormation stack operations in those accounts?
A telemedicine company's real-time consultation platform has grown from 8,000 daily active users to 60,000 across 7 countries, its microservices run on Amazon Elastic Kubernetes Service (Amazon EKS) that scales up to 2,500 nodes during 20-minute peak windows, and security reviews show sporadic unauthorized sign-in attempts and abrupt session drops, so the company requires platform-wide additional protections and a single summarized view across all AWS accounts that shows login attempts, API calls, and network traffic, permits network traffic analysis while minimizing raw log management overhead, and enables rapid investigation of potentially malicious activity involving the EKS workload—what solution best meets these requirements?
A healthcare company uses customer managed AWS KMS keys with automatic rotation disabled due to imported key material requirements and performs manual rotation, and the security team wants to receive an alert if any active key in us-east-1 or eu-west-1 has not been rotated within the last 120 days; which solution will accomplish this?
Periodo de estudio: 2 months
앱의 문제들 3번이나 반복해서 풀고 떨어지면 어떡하지 불안했었는데 시험에서 문제들이 굉장히 유사하게 많이 나와서 쉽게 풀 수 있었어요. 감사해요!
Periodo de estudio: 1 month
After going through a Udemy course, I wanted to do some practice exams before taking the real exam. Cloud pass is good resource for exam. I didn't complete every questions, i only completed 70% questions. But i passed! Thanks cloud pass
Periodo de estudio: 1 month
A lot of the questions in this app questions indeed appeared on the exam, very helpful.
Periodo de estudio: 1 month
Passed the exam DOP-C02 Oct 2025. These practice questions were essential for my preparation. The services covered in the test practices match the exam content very well.
Periodo de estudio: 1 month
passed the dop exam with the help of Cloud pass questions. The real exam is full of tricky questions and these sets helped me prepared for it.
Obtén la app gratis