Incident and Event Response Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Incident and Event Response flashcards as text
An AWS Systems Manager OpsCenter OpsItem is created automatically when a CloudWatch alarm enters ALARM state. Which Systems Manager feature is responsible for this integration?
Answer: OpsCenter EventBridge rule
An EventBridge rule targeting OpsCenter is used to automatically create OpsItems when CloudWatch alarms fire.
During an incident, an operator needs to execute a pre-approved set of remediation steps across 500 EC2 instances simultaneously. Which AWS service provides the fastest path to do this with full audit logging?
Answer: AWS Systems Manager Run Command
Systems Manager Run Command executes commands across many instances simultaneously and automatically logs output to S3 and CloudWatch Logs.
A DevOps team wants CloudWatch to automatically restart an EC2 instance when CPU utilization stays at 100% for 15 minutes. What is the correct alarm action to configure?
Answer: EC2 reboot action
CloudWatch EC2 reboot alarm actions restart the instance OS, which clears CPU-bound processes.
A pipeline failure event must trigger both a PagerDuty alert and an internal Slack notification simultaneously. What is the most scalable architecture for this requirement?
Answer: EventBridge rule → SNS topic with two subscriptions (HTTPS endpoints)
An SNS topic with multiple HTTPS subscriptions fans out a single event to multiple endpoints simultaneously without additional Lambda overhead.
What does AWS Systems Manager Incident Manager's 'engagement plan' define?
Answer: The ordered list of contacts and escalation timing for notifying responders
An engagement plan specifies which contacts to notify, in what order, and after how many minutes to escalate if there is no acknowledgment.
A team needs to capture all API calls made during an incident for a forensic audit. Which AWS service provides a tamper-evident, continuous record of API activity?
Answer: AWS CloudTrail with log file validation enabled
CloudTrail with log file validation uses SHA-256 hashing to detect if log files were modified or deleted after delivery.
Which AWS X-Ray feature helps identify which downstream service is causing latency spikes during a live incident in a microservices architecture?
Answer: Service map with response time distribution
The X-Ray service map visually shows each service node's average latency and error rate, making it easy to pinpoint the bottleneck.