Skip to content
BytePatterns

SOA-C03 · Domain 3: Deployment, Provisioning, and Automation · 22% of the exam

Task 3.1: Provision and maintain cloud resources.

Building resources the repeatable way: AMIs and container images with EC2 Image Builder, CloudFormation and the CDK, fixing failed deployments, sharing across accounts and Regions with StackSets and AWS RAM, deployment strategies, and third-party tools such as Terraform.

Study it

  • Images: AMIs, EC2 Image Builder and container images in Amazon ECR

    Partly covered by: Images, Layers & Multi-Stage Builds

  • CloudFormation and the CDK: stacks, change sets, drift and failed deployments

    Lesson coming

  • Across accounts and Regions: StackSets and AWS RAM

    Lesson coming

  • Deployment strategies: rolling, blue/green and canary

    Partly covered by: Scheduling & Rolling Updates

  • Third-party tools: Terraform and Git

    Lesson coming

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

Every month an operations team must produce a hardened Amazon Linux AMI: start from the latest base image, apply operating system updates, install the company's agents, run tests on the result, and make the AMI available in three AWS Regions and to two other AWS accounts. The team wants this to run automatically with the least custom work. What should the team use?

  1. AAn Amazon Data Lifecycle Manager AMI policy that targets a reference instance
  2. BAn EC2 Image Builder pipeline with a recipe, test components, a schedule and distribution settings
  3. CAmazon ECR replication rules that copy the image to the three Regions and two accounts
  4. DA monthly CopyImage call from the console for each target Region after patching an instance by hand
Show the answer and why
  • AAn Amazon Data Lifecycle Manager AMI policy that targets a reference instance

    Incorrect

    Data Lifecycle Manager creates, retains and deletes EBS-backed AMIs of existing instances. It does not install updates or run tests.

  • BAn EC2 Image Builder pipeline with a recipe, test components, a schedule and distribution settings

    Correct

    Image Builder pipelines build, test and schedule images, and distribution settings copy the output AMI to other Regions and share it with other accounts.

  • CAmazon ECR replication rules that copy the image to the three Regions and two accounts

    Incorrect

    ECR replication copies container images between registries. It does not build or distribute AMIs.

  • DA monthly CopyImage call from the console for each target Region after patching an instance by hand

    Incorrect

    Copying an AMI to each Region works, but the patching, testing and copying would all stay manual.

Build, test, schedule and distribute in one managed pipeline is what EC2 Image Builder is for.

Question 2 · choose 1

An engineer has edited the AWS CloudFormation template of a production stack, including properties of its Amazon RDS DB instance. Before anything changes, the change approval board must know whether the update will replace or delete the database. Nothing may be modified until the board approves. What should the engineer do?

  1. ARun drift detection on the stack and share the drift results with the board
  2. BTurn on termination protection for the stack before updating it
  3. CCreate a change set from the edited template and review it before executing
  4. DValidate the edited template with the validate-template command
Show the answer and why
  • ARun drift detection on the stack and share the drift results with the board

    Incorrect

    Drift detection compares the resources with the stack's current template. It says nothing about what the edited template would change.

  • BTurn on termination protection for the stack before updating it

    Incorrect

    Termination protection only makes stack deletion fail. It does not show the effect of an update.

  • CCreate a change set from the edited template and review it before executing

    Correct

    A change set previews how the update would affect running resources, including whether it deletes or replaces any, and nothing changes until someone executes it.

  • DValidate the edited template with the validate-template command

    Incorrect

    validate-template checks only the template's syntax. It does not determine what the update would do to existing resources.

Change sets are CloudFormation's preview: create, review, and execute only after approval.

Question 3 · choose 1

An AWS CloudFormation stack update failed, and the rollback failed too. The stack is now in the UPDATE_ROLLBACK_FAILED state because the rollback tries to return to a resource that someone deleted outside CloudFormation. The operations team cannot update the stack. What should the team do to get the stack back to a working state?

  1. ADelete the stack and recreate it from the last known good template
  2. BRun drift detection so that the deleted resource is reported as drifted
  3. CTurn on termination protection and retry the original stack update
  4. DContinue update rollback, skipping the stuck resource
Show the answer and why
  • ADelete the stack and recreate it from the last known good template

    Incorrect

    CloudFormation deletes all resources in a stack when the stack is deleted, unless a deletion policy retains them. That is far more than the problem needs.

  • BRun drift detection so that the deleted resource is reported as drifted

    Incorrect

    Drift detection only reports how resources differ from the template, including deleted ones. The stack stays in UPDATE_ROLLBACK_FAILED.

  • CTurn on termination protection and retry the original stack update

    Incorrect

    A stack in UPDATE_ROLLBACK_FAILED cannot be updated, and termination protection only blocks stack deletion.

  • DContinue update rollback, skipping the stuck resource

    Correct

    Continue update rollback brings the stack to UPDATE_ROLLBACK_COMPLETE. If the error cannot be fixed, the advanced option skips resources that CloudFormation cannot roll back.

UPDATE_ROLLBACK_FAILED is resolved with Continue update rollback: fix the cause if possible, otherwise skip the stuck resources, then make the stack and its resources consistent again before the next update.

Question 4 · choose 1

A company uses AWS Organizations. Every account in the Workloads organizational unit (OU) must have the same IAM role and AWS Config recorder settings in two AWS Regions, defined in one AWS CloudFormation template. Accounts that join the OU later must receive the stacks without anyone acting, and the team does not want to create IAM roles in each account for the deployment. What should the team do?

  1. AA service-managed StackSet that targets the OU, with automatic deployments
  2. BA self-managed StackSet that lists each current account ID as a target
  3. CA parent stack with one nested stack for each account in the OU
  4. DA resource share in AWS Resource Access Manager that shares the template file
Show the answer and why
  • AA service-managed StackSet that targets the OU, with automatic deployments

    Correct

    With service-managed permissions StackSets creates the IAM roles it needs, and automatic deployments add stacks to accounts when they join a target OU.

  • BA self-managed StackSet that lists each current account ID as a target

    Incorrect

    Self-managed permissions require the team to create the IAM roles in every account, and new accounts would need to be added by hand.

  • CA parent stack with one nested stack for each account in the OU

    Incorrect

    Nested stacks reuse templates inside one stack hierarchy. They do not deploy to other accounts.

  • DA resource share in AWS Resource Access Manager that shares the template file

    Incorrect

    AWS RAM shares supported resources such as subnets or transit gateways. CloudFormation templates are not among them, and sharing would not deploy anything.

Deploying one template to every account in an OU, including future ones, is the case for service-managed StackSets with automatic deployments.

Question 5 · choose 1

A central networking account in an AWS Organizations organization owns a VPC and its route tables. Application teams in other accounts of the same organization must launch their own Amazon EC2 instances and Amazon RDS databases directly into the private subnets of that VPC, while the network team keeps sole control of the VPC itself. What should the network team do?

  1. ACreate a VPC peering connection from each application account's VPC to the central VPC
  2. BShare the private subnets with those accounts through AWS RAM
  3. CAttach every application account's VPC to a transit gateway owned by the network account
  4. DPublish an endpoint service with AWS PrivateLink in the central VPC
Show the answer and why
  • ACreate a VPC peering connection from each application account's VPC to the central VPC

    Incorrect

    Peering routes traffic between two separate VPCs. The application teams would still launch resources in their own VPCs, not in the central one.

  • BShare the private subnets with those accounts through AWS RAM

    Correct

    In VPC sharing, the owner shares subnets with participant accounts in the same organization, and participants create and manage their own resources in those subnets.

  • CAttach every application account's VPC to a transit gateway owned by the network account

    Incorrect

    A transit gateway interconnects VPCs and on-premises networks. It does not let other accounts place resources in the central VPC's subnets.

  • DPublish an endpoint service with AWS PrivateLink in the central VPC

    Incorrect

    PrivateLink gives private access to a service or resource as if it were in the consumer's VPC; it does not let other accounts launch resources in the provider's subnets.

"Launch into our subnets, but we own the VPC" is VPC subnet sharing, set up with AWS RAM.

Question 6 · choose 2

An Auto Scaling group launches instances into two /26 subnets in different Availability Zones. During a scale-out, launches fail because the subnets have no free IP addresses left. The VPC has a single IPv4 CIDR block, 10.20.0.0/24, and all of it is already divided into subnets. The group must be able to grow by about 400 instances. Which steps should the operations team take? (Choose TWO.)

  1. AExpand the VPC's existing 10.20.0.0/24 CIDR block to 10.20.0.0/20
  2. BAssociate a secondary IPv4 CIDR block, such as 10.21.0.0/20, with the VPC
  3. CCreate larger subnets from the new block in each zone and add them to the group
  4. DRequest a higher quota for network interfaces in the Region
  5. ETurn on automatic public IPv4 address assignment for both of the existing subnets
Show the answer and why
  • AExpand the VPC's existing 10.20.0.0/24 CIDR block to 10.20.0.0/20

    Incorrect

    The size of an existing VPC CIDR block cannot be increased or decreased.

  • BAssociate a secondary IPv4 CIDR block, such as 10.21.0.0/20, with the VPC

    Correct

    After a VPC is created, additional IPv4 CIDR blocks can be associated with it, and a local route for each is added to the route tables.

  • CCreate larger subnets from the new block in each zone and add them to the group

    Correct

    New subnets can be as large as /16, and once the group can launch into them it has the addresses it needs.

  • DRequest a higher quota for network interfaces in the Region

    Incorrect

    The launches fail because the subnets' CIDR blocks are used up. A quota increase adds no addresses to a subnet.

  • ETurn on automatic public IPv4 address assignment for both of the existing subnets

    Incorrect

    That attribute only adds a public address to new network interfaces; each instance still needs a private address from the subnet's range.

A /26 holds 64 addresses, five of which AWS reserves. When the VPC's range is used up, add a secondary CIDR block and carve bigger subnets from it.

Question 7 · choose 1

An Auto Scaling group of 20 instances uses version 4 of a launch template. The team has created version 5 with a new AMI. The new version must reach every instance now, at least 90% of the group must stay healthy during the rollout, and the change must be reverted automatically if a CloudWatch alarm on the load balancer's 5XX errors goes into ALARM while it runs. What should the team do?

  1. APoint the group at version 5 and terminate the old instances by hand in batches of two
  2. BPoint the group at version 5 and let normal scaling replace the instances over time
  3. CStart an instance refresh to version 5 with 90% minimum healthy and an auto rollback
  4. DCreate a second Auto Scaling group on version 5 and delete the first group at once
Show the answer and why
  • APoint the group at version 5 and terminate the old instances by hand in batches of two

    Incorrect

    Manual batches can keep capacity up, but nothing would reverse the change on an alarm. Auto rollback is a feature of an instance refresh.

  • BPoint the group at version 5 and let normal scaling replace the instances over time

    Incorrect

    Existing instances keep running on the old AMI until something replaces them. AWS uses an instance refresh to roll an update out immediately.

  • CStart an instance refresh to version 5 with 90% minimum healthy and an auto rollback

    Correct

    An instance refresh replaces instances in batches that respect the minimum healthy percentage, and auto rollback reverses the deployment if a specified alarm goes into ALARM.

  • DCreate a second Auto Scaling group on version 5 and delete the first group at once

    Incorrect

    Deleting the old group at once offers no automatic way back if the alarm fires; reverting would be a manual rebuild.

Instance refresh is the rolling replacement built into Auto Scaling: healthy-percentage limits, checkpoints, and manual or automatic rollback.

Question 8 · choose 1

A team's AWS CDK app deploys without problems to its development account in us-east-1. The first cdk deploy of the same app to a new production account in eu-west-1 fails because the deployment cannot find the asset staging bucket and the IAM roles that the CDK expects to use there. What should the team do before deploying again?

  1. ARun cdk synth again so that the CloudFormation template is regenerated for the production account
  2. BRun cdk diff against the production account to compare the stacks
  3. CDelete the CDKToolkit stack in the development account so that it is recreated during the next deployment
  4. DBootstrap the production account in eu-west-1 by running cdk bootstrap
Show the answer and why
  • ARun cdk synth again so that the CloudFormation template is regenerated for the production account

    Incorrect

    cdk synth produces the cloud assembly and templates locally. It creates nothing in the target account.

  • BRun cdk diff against the production account to compare the stacks

    Incorrect

    cdk diff shows the differences between the app and deployed stacks. It does not provision anything.

  • CDelete the CDKToolkit stack in the development account so that it is recreated during the next deployment

    Incorrect

    CDKToolkit is the development environment's bootstrap stack. Deleting it does nothing for production and breaks deployments to development.

  • DBootstrap the production account in eu-west-1 by running cdk bootstrap

    Correct

    Every environment (account and Region) must be bootstrapped before a CDK stack is deployed into it; bootstrapping provisions the bucket and roles that the CDK uses.

CDK bootstrap resources live per account and Region. A new environment needs its own bootstrap stack before the first deployment.

Practise domain 3 →Practise all domains →