What changes should be recommended to comply with AWS security best practices?

A DevOps engineer is working on a project that is hosted on Amazon Linux and has failed a security review. The DevOps manager has been asked to review the company buildspec. yaml die for an AWS CodeBuild project and provide recommendations. The buildspec. yaml file is configured as follows: What...

May 9, 2025 No Comments READ MORE +

Which solution will resolve this issue?

A company uses AWS CloudFormation stacks to deploy updates to its application. The stacks consist of different resources. The resources include AWS Auto Scaling groups, Amazon EC2 instances, Application Load Balancers (ALBs), and other resources that are necessary to launch and maintain independent stacks. Changes to application resources outside of...

May 8, 2025 No Comments READ MORE +

Which combination of steps will meet the company’s requirements?

A company runs an application on Amazon EC2 instances. The company uses a series of AWS CloudFormation stacks to define the application resources. A developer performs updates by building and testing the application on a laptop and then uploading the build output and CloudFormation stack templates to Amazon S3. The...

May 8, 2025 No Comments READ MORE +

Which additional set of actions should the DevOps engineer take to gather the required metrics?

A company has a mobile application that makes HTTP API calls to an Application Load Balancer (ALB). The ALB routes requests to an AWS Lambda function. Many different versions of the application are in use at any given time, including versions that are in testing by a subset of users....

May 7, 2025 No Comments READ MORE +

Which SCP will meet these requirements?

A company manages multiple AWS accounts in AWS Organizations. The company's security policy states that AWS account root user credentials for member accounts must not be used. The company monitors access to the root user credentials. A recent alert shows that the root user in a member account launched an...

May 6, 2025 No Comments READ MORE +

Which solution will meet these requirements in the MOST automated way?

A company has chosen AWS to host a new application. The company needs to implement a multi-account strategy. A DevOps engineer creates a new AWS account and an organization in AWS Organizations. The DevOps engineer also creates the OU structure for the organization and sets up a landing zone by...

May 5, 2025 No Comments READ MORE +

Which solution will meet these requirements?

A company hosts a security auditing application in an AWS account. The auditing application uses an IAM role to access other AWS accounts. All the accounts are in the same organization in AWS Organizations. A recent security audit revealed that users in the audited AWS accounts could modify or delete...

May 5, 2025 No Comments READ MORE +

Which approach will meet these requirements and quickly provide consistent AWS environments for developers?

A rapidly growing company wants to scale for developer demand for AWS development environments. Development environments are created manually in the AWS Management Console. The networking team uses AWS CloudFormation to manage the networking infrastructure, exporting stack output values for the Amazon VPC and all subnets. The development environments have...

May 5, 2025 No Comments READ MORE +

What should the DevOps engineer do with the CloudFormation template so that IPv6 clients can access the web service?

A DevOps engineer is creating an AWS CloudFormation template to deploy a web service. The web service will run on Amazon EC2 instances in a private subnet behind an Application Load Balancer (ALB). The DevOps engineer must ensure that the service can accept requests from clients that have IPv6 addresses....

May 5, 2025 No Comments READ MORE +

Which combination of actions should be performed to enable this replication?

A DevOps engineer needs to back up sensitive Amazon S3 objects that are stored within an S3 bucket with a private bucket policy using S3 cross-Region replication functionality. The objects need to be copied to a target bucket in a different AWS Region and account. Which combination of actions should...

May 4, 2025 No Comments READ MORE +