Non-Destructive Testing Methods Flashcards
7 cards from real Architecting on AWS Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Non-Destructive Testing Methods flashcards as text
A company uses AWS Service Catalog to provision environments. Which practice ensures that test environment stacks are structurally identical to production stacks for valid non-destructive testing?
Answer: Use the same Service Catalog product version for both test and production environments
Sharing the same Service Catalog product version guarantees that test and production environments are provisioned from identical infrastructure-as-code definitions.
Which AWS feature allows you to test IAM permission changes before applying them to live roles or users?
Answer: IAM Access Analyzer policy validation and the IAM policy simulator
The IAM policy simulator evaluates existing or proposed policies against specific API actions so you can verify access changes without modifying live policies.
A team uses AWS CDK. Which command lets developers see the synthesized CloudFormation template and diff against a deployed stack before any changes are deployed?
Answer: cdk diff
`cdk diff` compares the locally synthesized template with the deployed stack and prints resource-level changes without making any modifications.
To test VPC security group rules without sending real traffic, an architect should use:
Answer: VPC Reachability Analyzer to verify logical connectivity between resources
VPC Reachability Analyzer performs a logical analysis of the network path between two endpoints and reports whether traffic would be allowed or blocked, without sending actual packets.
Which Elastic Beanstalk deployment policy swaps environment URLs only after the new environment passes health checks, enabling non-destructive testing of new application versions?
Answer: Blue/Green (URL swap)
Elastic Beanstalk blue/green deploys the new version to a cloned environment and only swaps the CNAME after health checks pass, leaving the old environment intact for rollback.
An architect wants to validate that an S3 bucket policy change won't accidentally deny access to an existing application. Which tool provides this pre-deployment check?
Answer: IAM Access Analyzer to analyze the updated resource policy for unintended access changes
IAM Access Analyzer evaluates S3 bucket policies and highlights whether a policy change would grant or revoke access relative to the current state.
Which approach lets you test a new ECS task definition revision without stopping the currently running tasks?
Answer: Run a standalone ECS task using the new task definition revision and validate it independently
Running a standalone task with the new revision lets you test it in the same cluster environment without touching the service's running tasks.