Incident and Event Response Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Incident and Event Response flashcards as text
Your team wants CodeDeploy to automatically roll back a deployment when the application error rate exceeds 5%. How do you enable this?
Answer: Configure automatic rollback in the CodeDeploy Deployment Group triggered by a CloudWatch alarm
CodeDeploy Deployment Groups support automatic rollback when specified CloudWatch alarms breach their thresholds, such as an error rate exceeding 5%.
During an incident, your team suspects high latency in a microservices call chain. Which AWS service provides distributed tracing and a service map to pinpoint the bottleneck?
Answer: AWS X-Ray
AWS X-Ray traces requests across your distributed application, generating service maps and detailed trace timelines that identify where latency is introduced.
In an event-driven remediation architecture, a Lambda function may receive the same event multiple times due to retries. What design approach prevents duplicate side effects?
Answer: Idempotent Lambda function design combined with SQS visibility timeout
Idempotent functions produce the same result whether invoked once or multiple times with the same input; combined with SQS visibility timeout, this prevents duplicate processing during Lambda retry scenarios.
Which Systems Manager document type should you create to define a multi-step automated remediation runbook with conditional branching and AWS API calls?
Answer: Automation document
Systems Manager Automation documents support multi-step orchestration workflows with conditional branching, loops, AWS API integrations, and approvals — making them suitable for complex remediation runbooks.
A critical CloudWatch alarm must notify a ticketing system, a Slack channel, and an email list simultaneously. Which architecture is most scalable and maintainable?
Answer: CloudWatch Alarm → EventBridge rule per target
EventBridge supports multiple rules routing a single event to different targets (Lambda, API Destinations, SNS, etc.) without custom fan-out code, providing clean separation and easy target management.
During a scale-in event, Auto Scaling terminates an instance that is still processing a long-running job. Which Auto Scaling feature prevents this service disruption?
Answer: Lifecycle Hooks
Auto Scaling Lifecycle Hooks pause the termination process, sending a notification so your code can drain connections or complete work before the instance is terminated.
Which AWS service aggregates security findings from GuardDuty, Amazon Inspector, and Amazon Macie into a single dashboard for incident prioritization?
Answer: AWS Security Hub
AWS Security Hub collects, normalizes, and prioritizes security findings from multiple AWS services and third-party tools, giving teams a unified security posture view for incident triage.