dc dotCreds
AWS Certified DevOps Engineer - Professional Practice Test

AWS DevOps Engineer Professional Practice Test

Start today’s free 10-question AWS DevOps Engineer Professional set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 22, 2026, 10:19 PM CDT

Go Pro - One Time Unlock

Unlock the full DOP-C02 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 AWS DevOps Engineer Professional questions

Use this AWS DevOps Engineer Professional practice test to review AWS Certified DevOps Engineer - Professional. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Task 2.1: Define cloud infrastructure and reusable components to provision and manage systems throughout their lifecycle Configuration Management and Infrastructure as Code (17%)

A global retailer needs to preview exactly which stack resources CloudFormation plans to add, modify, or replace before a production update is executed. Which implementation is the most defensible choice?

Concept tested:
Question 2 of 10
Objective Task 5.3: Troubleshoot system and application failures Incident and Event Response (14%)

A manufacturing company has a CloudFormation update that stopped partway through. The team needs to determine which resource operation failed and the service error returned by AWS. Which implementation is the most defensible choice?

Concept tested:
Question 3 of 10
Objective Task 3.3: Implement automated recovery Resilient Cloud Solutions (15%)

Auditors require evidence that backups are actually restorable, not merely that backup jobs complete. The organization wants recurring automated restore exercises with results that can be reviewed. Which AWS Backup feature best fits?

Concept tested:
Question 4 of 10
Objective Task 4.1: Configure the collection, aggregation, and storage of logs and metrics Monitoring and Logging (15%)

A global retailer needs operating-system and application telemetry that is not included in the default EC2 service metrics. The data must be sent to CloudWatch. Which implementation is the most defensible choice?

Concept tested:
Question 5 of 10
Objective Task 1.2: Integrate automated testing into CI/CD pipelines SDLC Automation (22%)

A global retailer must add performance testing before a high-traffic release. The test must exercise the application at scale rather than only verify individual functions. What is the BEST next configuration change?

Concept tested:
Question 6 of 10
Objective Task 6.2: Apply automation for security controls and data protection Security and Compliance (17%)

A landing-zone requirement says member accounts must be prevented from performing a prohibited action, rather than merely detected after the action occurs. Which Control Tower control behavior should be selected?

Concept tested:
Question 7 of 10
Objective Task 5.2: Implement configuration changes in response to events Incident and Event Response (14%)

An AWS Config managed rule identifies S3 buckets that violate a required configuration. When a bucket becomes NON_COMPLIANT, the organization wants an approved Systems Manager Automation document invoked automatically. Which feature should be configured?

Concept tested:
Question 8 of 10
Objective Task 2.2: Deploy automation to create, onboard, and secure AWS accounts in a multi-account or multi-Region environment Configuration Management and Infrastructure as Code (17%)

Security Hub administration should be performed from a security member account instead of the Organizations management account. The service supports delegated administration. What should the organization configure first?

Concept tested:
Question 9 of 10
Objective Task 4.3: Automate monitoring and event management of complex environments Monitoring and Logging (15%)

A logistics company needs to route a specific class of AWS service events to an automated remediation target only when event fields match the documented failure condition. What should be configured to meet the requirement?

Concept tested:
Question 10 of 10
Objective Task 1.3: Build and manage artifacts SDLC Automation (22%)

A golden AMI must be rebuilt every week to pick up updated base images and components, with no operator launching the build. Which service feature should the platform team use?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
DOP-C02 Pro $4.99 one-time

Unlock all 200 AWS DevOps Engineer Professional questions, explanations, review tools, and exam-style practice.

50 Exam Practice Test $1.99 one-time

A 50-question DOP-C02 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

AWS Access Bundle $6.99/month

AWS practitioner, architect, and machine learning practice in one monthly unlock.

What’s includedAWS AI Practitioner, AWS Cloud Practitioner, AWS Developer Associate, AWS Advanced Networking Specialty, AWS Security Specialty, AWS ML Engineer Associate, AWS SAA-C03, AWS Data Engineer Associate, AWS DevOps Engineer Professional

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full DOP-C02 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily DOP-C02 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily AWS DevOps Engineer Professional set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A global retailer needs to preview exactly which stack resources CloudFormation plans to add, modify, or replace before a production update is executed. Which implementation is the most defensible choice?

Answer choices

  1. A. Delete the production stack and recreate it to see what changes occur.
  2. B. Create and review a CloudFormation change set before executing the stack update.
  3. C. Use an S3 Inventory report as the update preview.
  4. D. Increase the stack timeout and execute the update directly.

Correct answer

Create and review a CloudFormation change set before executing the stack update.

A change-set workflow is the CloudFormation mechanism for reviewing planned changes before applying them.

Wrong-answer review

  • A. Delete the production stack and recreate it to see what changes occur.: Deleting production resources is not a safe preview mechanism.
  • C. Use an S3 Inventory report as the update preview.: S3 Inventory reports objects; it does not model CloudFormation stack changes.
  • D. Increase the stack timeout and execute the update directly.: Timeout settings do not provide a preview of resource changes.

Extra learning features

Interview question

Q: Given the DOP-C02 IaC task includes change-management processes for IaC platforms and composing and deploying CloudFormation templates, what is the most defensible approach to previewing changes before execution? Strong answer: A change-set workflow is the CloudFormation mechanism for reviewing planned changes before applying them.

  • change-set workflow
  • CloudFormation mechanism
  • reviewing planned changes
  • applying them

Caution: Do not restate the multiple-choice stem or ask the learner merely to name a product, rule, or term.

Why this matters

Failing to use a change-set workflow before executing a CloudFormation stack update could result in unintended modifications to production systems, leading to service disruptions and significant financial losses for the retailer. This understanding directly impacts the ability to confidently manage infrastructure changes and minimize operational risks. The consequence is a potential outage and lost revenue.

Objective/domain: Configuration Management and Infrastructure as Code (17%)

Source: AWS Certified DevOps Engineer - Professional Exam Guide (DOP-C02)

Question 2 A manufacturing company has a CloudFormation update that stopped partway through. The team needs to determine which resource operation failed and the service error returned by AWS. Which implementation is the most defensible choice?

Answer choices

  1. A. Change the stack's DeletionPolicy before reading the failure.
  2. B. Inspect the CloudFormation stack events for the failed resource and its status reason.
  3. C. Create an EventBridge archive and assume it contains the stack failure reason.
  4. D. Inspect CodeArtifact package versions.

Correct answer

Inspect the CloudFormation stack events for the failed resource and its status reason.

Objective/domain: Incident and Event Response (14%)

Source: What is AWS CloudFormation?

Question 3 Auditors require evidence that backups are actually restorable, not merely that backup jobs complete. The organization wants recurring automated restore exercises with results that can be reviewed. Which AWS Backup feature best fits?

Answer choices

  1. A. Use AWS Backup Audit Manager to confirm backup jobs completed and treat that as restore proof.
  2. B. Configure AWS Backup restore testing plans.
  3. C. Enable Vault Lock so backups cannot be deleted and skip restore exercises.
  4. D. Run backup jobs more frequently and infer recoverability from successful backup status.

Correct answer

Configure AWS Backup restore testing plans.

Objective/domain: Resilient Cloud Solutions (15%)

Source: Restore testing with AWS Backup

Question 4 A global retailer needs operating-system and application telemetry that is not included in the default EC2 service metrics. The data must be sent to CloudWatch. Which implementation is the most defensible choice?

Answer choices

  1. A. Use CloudFormation drift detection to collect process metrics.
  2. B. Install and configure the CloudWatch agent on the instances to collect the required guest metrics and logs.
  3. C. Use a CodeDeploy deployment configuration as a metrics collector.
  4. D. Assume the default EC2 metrics include every process-level and memory metric.

Correct answer

Install and configure the CloudWatch agent on the instances to collect the required guest metrics and logs.

Objective/domain: Monitoring and Logging (15%)

Source: Amazon CloudWatch User Guide

Question 5 A global retailer must add performance testing before a high-traffic release. The test must exercise the application at scale rather than only verify individual functions. What is the BEST next configuration change?

Answer choices

  1. A. Add an automated load or stress test stage before production promotion.
  2. B. Run only an IAM policy simulation before deployment.
  3. C. Increase the Auto Scaling group maximum size and skip testing.
  4. D. Replace unit tests with static linting only.

Correct answer

Add an automated load or stress test stage before production promotion.

Objective/domain: SDLC Automation (22%)

Source: AWS Certified DevOps Engineer - Professional Exam Guide (DOP-C02)

Question 6 A landing-zone requirement says member accounts must be prevented from performing a prohibited action, rather than merely detected after the action occurs. Which Control Tower control behavior should be selected?

Answer choices

  1. A. Use a detective control that reports the violation after the resource/action exists.
  2. B. Use a proactive control that evaluates supported CloudFormation resources before provisioning but does not cover the prohibited runtime API action.
  3. C. Use an applicable preventive control so the prohibited action is blocked through its enforcement mechanism.
  4. D. Create the equivalent SCP manually outside Control Tower and do not enable the Control Tower control.

Correct answer

Use an applicable preventive control so the prohibited action is blocked through its enforcement mechanism.

Objective/domain: Security and Compliance (17%)

Source: How AWS Control Tower controls work

Question 7 An AWS Config managed rule identifies S3 buckets that violate a required configuration. When a bucket becomes NON_COMPLIANT, the organization wants an approved Systems Manager Automation document invoked automatically. Which feature should be configured?

Answer choices

  1. A. Send NON_COMPLIANT Config events to EventBridge and invoke a custom Lambda that reimplements the fix.
  2. B. Configure AWS Config automatic remediation for the rule using the Systems Manager Automation remediation action.
  3. C. Use a Systems Manager State Manager association on every possible resource regardless of Config compliance state.
  4. D. Use a Config conformance pack only and rely on its compliance report without remediation actions.

Correct answer

Configure AWS Config automatic remediation for the rule using the Systems Manager Automation remediation action.

Objective/domain: Incident and Event Response (14%)

Source: Remediating noncompliant AWS resources with AWS Config

Question 8 Security Hub administration should be performed from a security member account instead of the Organizations management account. The service supports delegated administration. What should the organization configure first?

Answer choices

  1. A. Move the security account to the organization root.
  2. B. Attach AdministratorAccess to every account user.
  3. C. Enable trusted access for the service and register the security account as a delegated administrator.
  4. D. Create an IAM access key for the management account and share it with the security team.

Correct answer

Enable trusted access for the service and register the security account as a delegated administrator.

Objective/domain: Configuration Management and Infrastructure as Code (17%)

Source: Delegated administrator for AWS services with Organizations

Question 9 A logistics company needs to route a specific class of AWS service events to an automated remediation target only when event fields match the documented failure condition. What should be configured to meet the requirement?

Answer choices

  1. A. Send every event to the remediation target and filter inside each resource manually.
  2. B. Use CloudFormation DeletionPolicy attributes as event filters.
  3. C. Create an EventBridge rule with an event pattern that matches the required event fields and configure the remediation target.
  4. D. Configure a CodeArtifact repository policy to match service events.

Correct answer

Create an EventBridge rule with an event pattern that matches the required event fields and configure the remediation target.

Objective/domain: Monitoring and Logging (15%)

Source: What is Amazon EventBridge?

Question 10 A golden AMI must be rebuilt every week to pick up updated base images and components, with no operator launching the build. Which service feature should the platform team use?

Answer choices

  1. A. Use an Image Builder pipeline configured for manual execution only and trigger it from an operator calendar.
  2. B. Use a scheduled Image Builder pipeline but omit an image recipe and components.
  3. C. Use a scheduled CodeBuild project that creates AMIs with custom CLI commands instead of an Image Builder pipeline.
  4. D. Configure a scheduled EC2 Image Builder image pipeline.

Correct answer

Configure a scheduled EC2 Image Builder image pipeline.

Objective/domain: SDLC Automation (22%)

Source: Manage custom image creation through Image Builder pipelines

Where to go after the daily web set

How are AWS DevOps Engineer Professional questions generated?

dotCreds builds AWS DevOps Engineer Professional practice questions from public exam objectives and AWS certification and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start AWS DevOps Engineer Professional practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.