DevOps Automation Tools & Scripting Techniques Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 DevOps Automation Tools & Scripting Techniques flashcards as text
A DevOps team stores Ansible playbooks in CodeCommit and wants to auto-trigger playbook runs on every commit. What is the most straightforward AWS-native approach?
Answer: Configure a CodePipeline with a CodeBuild action that runs ansible-playbook
CodePipeline with a CodeBuild action is the native CI/CD approach: CodeCommit triggers the pipeline, and the CodeBuild stage executes the ansible-playbook command.
Which AWS service provides a managed Terraform state backend, allowing teams to store and lock state files without managing an S3+DynamoDB setup manually?
Answer: Terraform Cloud (not AWS-native)
Terraform Cloud provides a managed remote state backend with locking, though it is HashiCorp's service rather than a native AWS service; on AWS the standard approach is S3+DynamoDB.
In an AWS CodeBuild buildspec.yml, which phase should be used to install operating system packages and language runtimes before the build begins?
Answer: install
The 'install' phase is specifically designed for installing packages, runtimes, and build tools before any build logic runs.
A script needs to assume an IAM cross-account role and then call S3 APIs using the temporary credentials. Which boto3 call sequence is correct?
Answer: sts.assume_role() → extract Credentials → s3 client with AccessKeyId/SecretAccessKey/SessionToken
sts.assume_role() returns temporary credentials (AccessKeyId, SecretAccessKey, SessionToken) that must be explicitly passed when creating the S3 client.
A CloudFormation stack update is failing because a resource replacement would cause data loss. Which CloudFormation stack policy action prevents accidental replacement of a production database?
Answer: Apply a stack policy that denies Replace actions on the database resource
A stack policy with an explicit Deny on the Replace action for specific resources prevents CloudFormation from replacing those resources during updates.
Which Systems Manager document type is designed to run Ansible playbooks directly on managed EC2 instances without installing Jenkins or CodeBuild?
Answer: AWS-ApplyAnsiblePlaybooks
AWS-ApplyAnsiblePlaybooks is the official SSM document that downloads and executes Ansible playbooks on managed instances via Run Command.
A DevOps engineer wants to enforce that all EC2 instances in an AWS account must be launched with an approved AMI. Which AWS service enforces this at resource-creation time?
Answer: AWS Service Control Policies (SCPs)
SCPs applied at the AWS Organizations level can deny ec2:RunInstances requests that don't specify approved AMI IDs, blocking non-compliant launches before they occur.