โ† All AWS Flashcard Decks

Associate Certified SysOps Administrator - Associate Flashcards

7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Associate Certified SysOps Administrator - Associate flashcards as text
  1. A SysOps Administrator needs to patch all EC2 instances in a fleet during a maintenance window without writing custom scripts. Which AWS service automates this?

    Answer: AWS Systems Manager Patch Manager with a maintenance window

    Systems Manager Patch Manager scans instances for missing patches and installs them during a defined maintenance window using Run Command.

  2. CloudWatch Logs are not appearing for an EC2 instance. The CloudWatch agent is installed. What is the most likely cause?

    Answer: The IAM instance profile lacks the CloudWatchAgentServerPolicy permission

    The CloudWatch agent requires the IAM instance profile to have permissions (typically CloudWatchAgentServerPolicy) to publish logs and metrics to CloudWatch.

  3. A SysOps Administrator wants to receive an alert when AWS costs exceed $500 in a single month. Which combination of services achieves this?

    Answer: AWS Budgets with an SNS alert action

    AWS Budgets allows you to define a cost threshold and trigger an SNS notification or email alert when actual or forecasted costs exceed the budget.

  4. An application deployed across three AZs shows that one AZ is receiving significantly more traffic than the others through an Application Load Balancer. What should the administrator check?

    Answer: Enable cross-zone load balancing on the ALB

    Cross-zone load balancing distributes requests evenly across all registered instances regardless of AZ, preventing uneven distribution when AZs have different instance counts.

  5. Which feature of AWS CloudFormation allows a SysOps Administrator to preview the changes that will be made to a stack before executing an update?

    Answer: Change set

    A CloudFormation change set shows a preview of how proposed changes will modify existing stack resources before the update is actually applied.

  6. A SysOps Administrator needs to grant temporary AWS console access to a third-party auditor without creating an IAM user. Which approach is correct?

    Answer: Create a role with a trust policy for the auditor's AWS account and use AssumeRole

    Creating an IAM role with a cross-account trust policy allows the auditor to assume the role using their own AWS credentials via AssumeRole, providing temporary scoped access.

  7. An S3 bucket is configured for static website hosting. Users report intermittent 403 errors on specific files. The bucket policy allows public read. What is the most likely cause?

    Answer: The individual object ACLs are set to private, overriding the bucket policy

    Object-level ACLs set to private can override the bucket policy's public-read grant, causing 403 errors for those specific objects.