โ† All AWS Flashcard Decks

Container Services Flashcards

7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Container Services flashcards as text
  1. Which ECR feature can automatically delete untagged images older than 30 days to control storage costs?

    Answer: ECR lifecycle policies

    ECR lifecycle policies define rules that automatically expire and delete images based on age, tag status, or image count thresholds.

  2. In an ECS blue/green deployment via CodeDeploy, what does the 'test listener' port allow you to do before traffic shifts?

    Answer: Run automated smoke tests against the green environment before routing production traffic

    The test listener routes a portion of traffic (or test tools) to the green task set so you can validate the new version before full cutover.

  3. Which kubectl command would a DevOps engineer use to perform a rolling update of a container image in an EKS Deployment?

    Answer: kubectl set image deployment/myapp myapp=myrepo:v2

    kubectl set image updates the container image in the Deployment spec, triggering a rolling update that replaces pods incrementally.

  4. What does enabling ECR tag immutability prevent?

    Answer: Overwriting an existing image tag with a different image digest

    Tag immutability ensures that once an image tag (e.g., 'v1.0') is pushed, subsequent pushes with the same tag are rejected, preventing silent overwrites.

  5. A containerized application on ECS needs to access an RDS password stored in AWS Secrets Manager. What is the recommended approach?

    Answer: Pass the secret ARN as an environment variable in the task definition referencing Secrets Manager

    ECS task definitions support native Secrets Manager and SSM Parameter Store integration, injecting secrets as environment variables at task launch without exposing them in code.

  6. Which EKS feature lets you run Kubernetes pods on AWS Fargate without managing EC2 worker nodes?

    Answer: EKS Fargate profiles

    EKS Fargate profiles define namespaces and label selectors that determine which pods are scheduled on Fargate's serverless infrastructure.

  7. In Amazon ECS, which scheduling strategy places one task on each active container instance in a cluster?

    Answer: DAEMON

    The DAEMON scheduling strategy deploys exactly one task per EC2 instance, useful for monitoring agents or log collectors.