Certification942 problems· 22 reviewed

AWS DevOps Engineer Professional

942 incident response problems that help with AWS DevOps Engineer Professional prep.

All problems (942)

CICD-089Multi-account deployment role trusts the pipeline account but not the delegated tooling role session name patternCross-account deploys worked before, but now fail because the trust policy still allows the source account while denying the actual delegated session identity format.CI/CDAdvanced20 minProCICD-069OIDC deploy role works on push events but fails on workflow_call reuseThe repository already deploys successfully on direct pushes, but the reusable workflow path now fails because the token subject pattern no longer matches the calling context.CI/CDAdvanced20 minProCICD-076Cross-region artifact replication lags and the disaster-recovery deploy uses a partial releaseThe promotion completed in the primary region, but the DR environment pulls an incomplete artifact set because replication finished for the manifest before every dependent object arrived.CI/CDAdvanced21 minProCICD-065ECR lifecycle cleanup deletes one architecture image and arm nodes start failing pullsThe repository still contains the expected tag, but multi-architecture pulls break on one platform because the manifest list points to a child image that was already expired.CI/CDAdvanced21 minProCICD-099Image signing succeeds in CI but the admission policy rejects the signature issuer after root rotationThe build publishes a signed image, yet cluster admission fails because the verifier still trusts the old signing root only.CI/CDAdvanced21 minProCICD-087Rollback Lambda succeeds but the Auto Scaling warm pool still serves the failed launch templateThe rollback path updates the group, yet instances continue to launch with the broken version because the warm capacity pool retained the earlier template state.CI/CDAdvanced21 minProCICD-085CloudFormation import succeeds but later drift repair wants to replace the manually retained resourceThe stack stabilizes after import, yet a future update becomes dangerous because the imported resource shape still differs from what the template assumes is replaceable.CI/CDAdvanced22 minProSECURITY-031IAM role trust policy rejects GitHub OIDC tokenThe workflow reaches the cloud provider, but the trust policy denies the token because the expected audience or subject does not match the actual issuer claims.SecurityIntermediate22 minProCICD-093Terraform drift fix replaces a subnet that still holds the canary target group routeThe plan appears corrective, but applying it would cut live traffic because one supposedly stale subnet still anchors an active canary path.CI/CDAdvanced22 minProCICD-073Terraform plan looks safe but apply recreates IAM roles after a for_each key renameNo obvious destructive change is noticed in review, yet apply replaces active roles because the stable key used by for_each changed during a refactor.CI/CDAdvanced22 minProCICD-071Argo CD prune deletes a shared secretThe sync itself succeeds, but a cleanup step removes a namespace-scoped secret that another workload still depends on because ownership boundaries were not encoded safely.CI/CDAdvanced23 minProCICD-008Deployments passing without verificationA scenario that narrows down the root cause, centered on designing governance that enforces the verification step before deployment approval, in the situation of deployments passing without verification because a smoke-test conditional is wrong.CI/CDAdvanced23 minProCICD-080Feature flag migration step runs before the dependent schema change reaches every shardThe rollout script succeeds centrally, but one shard still serves the old schema and the new flag path begins calling a column that does not exist everywhere yet.CI/CDAdvanced23 minProCICD-083Schema migration succeeds on the writer but read replicas still serve incompatible shape to canary trafficThe migration log looks successful, yet the canary still fails because replica lag leaves part of the traffic reading the old schema path.CI/CDAdvanced23 minProCICD-063Terraform remote state lock survives a killed apply in a cross-account backendA failed apply no longer holds any active process, but every later run still stops on the lock because the backend cleanup path never completed across accounts.CI/CDAdvanced23 minProCICD-075Blue-green node group cutover drains the only log shipper before the replacement path is readyThe new nodes are healthy for the app, but operational visibility disappears because the drain order removed a cluster-wide DaemonSet before the replacement fleet was fully attached.CI/CDAdvanced24 minProCICD-090Canary bake time is shorter than the queue visibility window and failure signals arrive after promotionThe rollout passes its bake stage, but hidden worker failures appear only after the queue timeout window elapses, long after traffic has fully shifted.CI/CDAdvanced24 minProCICD-066CodeDeploy validation hook times outThe deployment itself is healthy, but the lifecycle validation keeps failing because the hook Lambda cannot reach the internal API it uses to prove readiness.CI/CDAdvanced24 minProCICD-058Production environment review waits foreverThe environment requires human approval on paper, but tagged releases stall indefinitely because the reviewer and branch rules were designed only for branch-based promotion.CI/CDAdvanced24 minProCICD-029Monorepo path filter misses shared library changesMonorepo path filter misses shared library changes is a hands-on troubleshooting drill. Only some services rebuild because the path filter ignores a shared package that affects multiple deployments. GitHub Rollback and Rollout needs to be checked by narrowing scope, recent cha...CI/CDAdvanced26 minPro