Skip to content
BytePatterns

DVA-C02 · Domain 3: Deployment · 24% of the exam

Task 3.4: Deploy code by using AWS Continuous Integration and Continuous Delivery (CI/CD) services

Releasing through a pipeline: Lambda packaging, API Gateway stages and custom domains, CodePipeline, CodeBuild and CodeDeploy, updating templates, branches and tags, stage variables, and deployment strategies (all at once, rolling, blue/green, canary, linear) with their rollbacks.

Study it

  • Packaging: .zip archives, layers and container images

    Partly covered by: Images, Layers & Multi-Stage Builds

  • API Gateway stages, stage variables and custom domains

    Lesson coming

  • Lambda versions and aliases for approved releases

    Lesson coming

  • CloudFormation and the CDK: templates, change sets and updates

    Lesson coming

  • Pipelines: CodePipeline, CodeBuild buildspec and CodeDeploy appspec

    Lesson coming

  • Deployment strategies and rollbacks: all at once, rolling, blue/green, canary and linear

    Partly covered by: Scheduling & Rolling Updates

  • Elastic Beanstalk, Amplify and Amazon ECS deployments

    Partly covered by: ECS vs EKS vs Fargate

Sample questions

Try each one before opening the answer. Every option is explained, with the AWS documentation page that proves it.

Question 1 · choose 1

AWS CodeDeploy performs in-place deployments of a web application to Amazon EC2 instances. After the new version has been installed and started, a script must call the application's /health endpoint on each instance and fail the deployment if the check does not pass. In which AppSpec lifecycle event hook should the developer run this script?

  1. ABeforeInstall
  2. BValidateService
  3. CAfterInstall
  4. DApplicationStop
Show the answer and why
  • ABeforeInstall

    Incorrect

    BeforeInstall runs preinstall tasks, such as decrypting files or backing up the current version, before the new revision is in place.

  • BValidateService

    Correct

    ValidateService is the last deployment lifecycle event and is used to verify that the deployment completed successfully.

  • CAfterInstall

    Incorrect

    AfterInstall is for tasks such as configuring the application or changing file permissions. It runs before ApplicationStart, so the new version is not running yet.

  • DApplicationStop

    Incorrect

    ApplicationStop runs even before the revision is downloaded, to stop the running application gracefully.

The scriptable hooks of an in-place EC2 deployment include, in order, ApplicationStop, BeforeInstall, AfterInstall, ApplicationStart and ValidateService; health checks belong in the last one.

Question 2 · choose 1

An AWS Elastic Beanstalk environment runs six instances behind a load balancer. For the next application version, the environment must keep full capacity during the deployment, the instances that run the current version must not be modified, and if the new version fails its health checks, rolling back must only mean terminating the new instances. The environment URL must not change. Which deployment policy should the developer choose?

  1. AAll at once
  2. BRolling with additional batch
  3. CBlue/green, with a CNAME swap to a cloned environment
  4. DImmutable
Show the answer and why
  • AAll at once

    Incorrect

    All at once deploys to every instance at the same time, and all instances are out of service for a short time.

  • BRolling with additional batch

    Incorrect

    This keeps full capacity, but it updates the existing instances batch by batch, which can leave a partially completed rolling deployment when the new version fails.

  • CBlue/green, with a CNAME swap to a cloned environment

    Incorrect

    Blue/green deploys to a separate environment and then swaps the environment URLs, which the requirement rules out.

  • DImmutable

    Correct

    An immutable deployment launches a full set of new instances in a separate Auto Scaling group alongside the old ones. If it fails, rollback only terminates the new instances.

Immutable deployments never touch the running instances: new ones are added, checked, and either kept or terminated.

Question 3 · choose 1

A V2 pipeline in AWS CodePipeline uses a GitHub repository as its source through a connection, and it starts on every push to the main branch. The team wants a separate production pipeline that starts only when a release tag such as v2.3.0 is pushed, and never for ordinary commits. What should the developer configure on the production pipeline?

  1. AThe source action's BranchName set to a branch named release
  2. BA manual approval action in front of the production deploy stage
  3. CA push trigger with a Git tag filter that includes v*
  4. DA pull request trigger filtered on the main branch
Show the answer and why
  • AThe source action's BranchName set to a branch named release

    Incorrect

    BranchName defines a single branch, so every ordinary commit pushed to that branch would still start the pipeline.

  • BA manual approval action in front of the production deploy stage

    Incorrect

    An approval action stops a running execution until someone approves or rejects it. The pipeline would still start for every commit.

  • CA push trigger with a Git tag filter that includes v*

    Correct

    Push triggers can be filtered on Git tags, so the pipeline starts only when a matching tag is pushed.

  • DA pull request trigger filtered on the main branch

    Incorrect

    Pull request triggers react to pull requests being opened, updated or closed, and they filter on branches and file paths, not tags.

V2 pipelines support trigger filters on branches, file paths and Git tags, which is how tags drive release pipelines.

Question 4 · choose 2

An AWS SAM template defines an AWS Lambda function that already has AutoPublishAlias set to live. For each release, 10 percent of traffic should move to the new version first and the remaining 90 percent ten minutes later. If the function's error alarm goes off during the shift, traffic must return to the previous version automatically. Which TWO settings should the developer add to the function? (Choose TWO.)

  1. AA DeploymentPreference with Type set to Linear10PercentEvery10Minutes
  2. BA DeploymentPreference with Type set to Canary10Percent10Minutes
  3. CDeploymentPreference Alarms that list the function's error alarm
  4. DA ProvisionedConcurrencyConfig for the live alias
  5. ERemoval of AutoPublishAlias so that traffic goes straight to $LATEST
Show the answer and why
  • AA DeploymentPreference with Type set to Linear10PercentEvery10Minutes

    Incorrect

    A linear configuration shifts 10 percent every 10 minutes until all traffic has moved, which takes far longer than one ten-minute step.

  • BA DeploymentPreference with Type set to Canary10Percent10Minutes

    Correct

    This canary configuration shifts 10 percent of traffic first and the remaining 90 percent ten minutes later.

  • CDeploymentPreference Alarms that list the function's error alarm

    Correct

    CodeDeploy watches the listed CloudWatch alarms during the deployment and rolls back automatically if one of them is triggered.

  • DA ProvisionedConcurrencyConfig for the live alias

    Incorrect

    Provisioned concurrency keeps execution environments initialized. It does not control how traffic moves between versions.

  • ERemoval of AutoPublishAlias so that traffic goes straight to $LATEST

    Incorrect

    AWS SAM gradual deployments shift traffic on the alias that AutoPublishAlias creates and points at each new version, so removing it works against the requirement.

In AWS SAM, AutoPublishAlias plus DeploymentPreference (type, alarms, optional hooks) hands traffic shifting and rollback to CodeDeploy.

Question 5 · choose 1

A developer changes the TableName property of an AWS::DynamoDB::Table in an AWS CloudFormation template. A change set shows that the update will replace the table. The team wants to go ahead with the update, but the existing table and its data must be kept in the account instead of being deleted when CloudFormation replaces it. What should the developer add to the table resource before executing the change set?

  1. ADeletionPolicy set to Retain
  2. BTermination protection turned on for the stack
  3. CA stack policy that denies Update:Replace on the table
  4. DUpdateReplacePolicy set to Retain
Show the answer and why
  • ADeletionPolicy set to Retain

    Incorrect

    DeletionPolicy applies when a resource is deleted from the stack, for example when it is removed from the template. It does not apply to a resource that is replaced during an update.

  • BTermination protection turned on for the stack

    Incorrect

    Termination protection only blocks deleting the stack. It does not keep a resource that an update replaces.

  • CA stack policy that denies Update:Replace on the table

    Incorrect

    A stack policy prevents the replacement from happening at all, so the update the team wants could not go ahead.

  • DUpdateReplacePolicy set to Retain

    Correct

    UpdateReplacePolicy keeps (or, in some cases, backs up) the existing physical resource when an update replaces it, so the old table stays in the account.

DeletionPolicy covers deletion from the stack; UpdateReplacePolicy covers replacement during an update. Changing TableName requires replacement.

Question 6 · choose 1

A front-end team builds a single-page web application in a Git repository. It wants every push to the main branch to build and publish the site to a global CDN automatically, with a separate environment for a staging branch, without building its own pipeline. Which service should the developer use?

  1. AAWS Amplify Hosting connected to the repository and its branches
  2. BAmazon S3 static website hosting with manual uploads
  3. CAWS Elastic Beanstalk with a single-instance environment
  4. DAn Amazon EC2 instance running a web server, updated over SSH after each push
Show the answer and why
  • AAWS Amplify Hosting connected to the repository and its branches

    Correct

    Amplify Hosting provides a Git-based workflow with continuous deployment to a global CDN, and branches can map to environments.

  • BAmazon S3 static website hosting with manual uploads

    Incorrect

    Manual uploads are not continuous deployment, and a website endpoint alone is not a global CDN.

  • CAWS Elastic Beanstalk with a single-instance environment

    Incorrect

    Beanstalk runs application servers; it is not a Git-based CDN hosting workflow for static front ends.

  • DAn Amazon EC2 instance running a web server, updated over SSH after each push

    Incorrect

    This needs manual server management and gives no automatic deployment on push.

Amplify Hosting gives front-end teams Git-based continuous deployment with per-branch environments.

Question 7 · choose 1

A team releases a web application on AWS Elastic Beanstalk. For the next version, it wants a canary release: a small share of client traffic should go to new instances running the new version for a period of time, with the rest on the current version, before the release completes. Which deployment policy fits?

  1. ARolling
  2. BAll at once
  3. CTraffic splitting
  4. DRolling with additional batch
Show the answer and why
  • ARolling

    Incorrect

    Rolling updates existing instances batch by batch; it does not send a set share of traffic to new instances for a test period.

  • BAll at once

    Incorrect

    All instances switch at the same time, with no canary period.

  • CTraffic splitting

    Correct

    Traffic splitting sends a percentage of client traffic to new instances for an evaluation period before completing the deployment.

  • DRolling with additional batch

    Incorrect

    This keeps full capacity during a rolling update but does not split traffic by percentage.

Elastic Beanstalk traffic splitting provides canary testing as part of a deployment.

Question 8 · choose 1

Developers push to a repository several times an hour. In the team's AWS CodePipeline V2 pipeline, newer executions overtake older ones, so some commits are never deployed on their own, which breaks the team's audit process. Every commit must go through the pipeline, one execution at a time and in order. What should the developer configure?

  1. AThe SUPERSEDED execution mode
  2. BThe PARALLEL execution mode
  3. CA manual approval action at the start of each stage
  4. DThe QUEUED execution mode
Show the answer and why
  • AThe SUPERSEDED execution mode

    Incorrect

    In SUPERSEDED mode, the default, a more recent execution can overtake an older one, which is the current problem.

  • BThe PARALLEL execution mode

    Incorrect

    PARALLEL runs executions at the same time and independently, not one at a time in order.

  • CA manual approval action at the start of each stage

    Incorrect

    Approvals pause executions for people; they do not change how executions are ordered.

  • DThe QUEUED execution mode

    Correct

    In QUEUED mode, executions are processed one by one in the order they are queued; it requires a V2 pipeline.

CodePipeline execution modes control whether executions are superseded, queued or run in parallel.

Question 9 · choose 1

A team defines its application with the AWS CDK and wants a delivery pipeline that is also defined in the CDK app. When developers add a new stage or stack to the app, the pipeline should reconfigure itself to deploy it, without anyone editing the pipeline by hand. What should the developer use?

  1. AA CodePipeline pipeline created by hand in the console
  2. BCDK Pipelines
  3. CA cron job that runs cdk deploy on a build server every hour
  4. DCloudFormation drift detection on the application stacks
Show the answer and why
  • AA CodePipeline pipeline created by hand in the console

    Incorrect

    A hand-built pipeline must be edited by hand when new stages or stacks are added.

  • BCDK Pipelines

    Correct

    CDK Pipelines are self-updating; when stages or stacks are added, the pipeline reconfigures itself to deploy them.

  • CA cron job that runs cdk deploy on a build server every hour

    Incorrect

    A scheduled job deploys on a timer rather than on changes, and it lacks pipeline stages.

  • DCloudFormation drift detection on the application stacks

    Incorrect

    Drift detection finds manual changes to deployed resources; it does not deploy anything.

CDK Pipelines keep the pipeline definition in code and update the pipeline as the app grows.

Question 10 · choose 1

A pipeline in AWS CodePipeline in account A must deploy, through AWS CodeDeploy, to EC2 instances in account B. The pipeline's artifact bucket uses the pipeline's default encryption key. The deploy action in account B cannot read the artifacts. What should the developer change about the artifact encryption?

  1. ATurn off encryption for the artifact bucket
  2. BCopy the artifacts into a bucket in account B with a script after each build
  3. CUse a customer managed KMS key that account B may use
  4. DTurn on automatic rotation of the default key
Show the answer and why
  • ATurn off encryption for the artifact bucket

    Incorrect

    Removing encryption weakens security and is not the documented way to share artifacts across accounts.

  • BCopy the artifacts into a bucket in account B with a script after each build

    Incorrect

    A copy step adds work outside the pipeline; the documented approach shares the artifacts through a key both accounts can use.

  • CUse a customer managed KMS key that account B may use

    Correct

    Cross-account pipelines use a customer managed KMS key in place of the default key, with permissions for the other account to use it.

  • DTurn on automatic rotation of the default key

    Incorrect

    Rotation does not change who may use the key.

For cross-account deployments, encrypt pipeline artifacts with a customer managed key that the target account is allowed to use.

Practise domain 3 →Practise all domains →