Associate Certified SysOps Administrator - Associate Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Associate Certified SysOps Administrator - Associate flashcards as text
A production RDS MySQL instance is experiencing high CPU utilization. The DBA confirms that long-running read queries are the cause. Which solution offloads reads with the least downtime?
Answer: Create one or more RDS Read Replicas and direct read traffic to them
RDS Read Replicas asynchronously replicate data from the primary and can serve SELECT queries, reducing CPU load on the primary instance with no downtime to create.
A SysOps Administrator wants to enforce that all EC2 instances must have a specific tag (Environment) before they can be launched. Which service enforces this?
Answer: IAM policy with a condition on ec2:RunInstances requiring the tag
An IAM policy with a Condition block using aws:RequestTag can deny ec2:RunInstances if the required tag is not present at launch time.
An Elastic Load Balancer's access logs show a high number of HTTP 502 errors. What is the most common cause?
Answer: The target instances are returning invalid responses or are unhealthy
HTTP 502 (Bad Gateway) from an ALB indicates the load balancer received an invalid response from the target instance, often caused by an unhealthy or misconfigured application.
A company uses AWS Organizations with Service Control Policies. Developers report they cannot create resources in us-west-1 even though their IAM permissions allow it. What is the cause?
Answer: An SCP applied to the account or OU restricts API calls to allowed regions only
SCPs act as guardrails and can restrict which AWS regions member accounts can use; if us-west-1 is not in the allow list, IAM permissions in that account cannot override the SCP.
A SysOps Administrator needs to securely store and automatically rotate database credentials used by an EC2 application. Which AWS service is purpose-built for this?
Answer: AWS Secrets Manager with automatic rotation enabled
AWS Secrets Manager stores credentials, supports automatic rotation using Lambda functions, and integrates natively with RDS for seamless credential rotation.
A CloudFormation stack update fails and rolls back. The SysOps Administrator needs to understand exactly which resource caused the failure. Where should they look first?
Answer: The CloudFormation stack events tab filtered by FAILED status
The CloudFormation stack events tab shows a chronological log of each resource's status; filtering for FAILED events identifies which resource caused the rollback and displays the error message.
A SysOps Administrator needs to ensure that objects uploaded to an S3 bucket are always encrypted at rest, even if the uploader forgets to specify encryption. Which bucket setting enforces this?
Answer: Enable S3 default encryption on the bucket (SSE-S3 or SSE-KMS)
S3 default encryption automatically encrypts all new objects uploaded to the bucket using SSE-S3 or SSE-KMS even if the request doesn't specify an encryption header.