Certification942 problems· 22 reviewed

AWS DevOps Engineer Professional

942 incident response problems that help with AWS DevOps Engineer Professional prep.

All problems (942)

CICD-1312A GitHub deployment uses OIDC successfully and Terraform still failsA team migrates to OIDC and still sees Terraform acting as an old IAM principal in only one workflow path.CI/CDAdvanced16 minProCICD-1297A nested package publish with OIDC fails only in the monorepo release jobA monorepo package publishes fine locally and later fails only in the centralized CI release workflow.CI/CDAdvanced16 minProCICD-1370A policy-as-code gate passes in staging and fails in prodA policy-as-code gate passes in staging and fails in prod focuses on Deployment Governance and asks the reader to isolate the key signal in hashicorp. Policy failures can reveal stack-generation drift rather than a bad policy.CI/CDAdvanced16 minProCICD-1304A remote state lock looks cleared in DynamoDB but the next plan still refuses to runAn interrupted deployment unblocks the lock table but later runs still refuse to proceed with a lock-style error.CI/CDAdvanced16 minProCICD-1292A required deployment check never goes greenA team modularizes CI with reusable workflows and later finds that branch protection blocks every merge.CI/CDAdvanced16 minProCICD-1262A reusable workflow deploys correctly in the caller but silently loses its secret in the called workflowCI/CD incident scenario used for structured troubleshooting practice.CI/CDAdvanced16 minProCICD-357A reusable workflow signs container images correctly while downstream promotion retags an unsigned digest from a side repository during a staged decommissionSupply-chain controls protect the main path, but a side promotion lane bypasses the signed artifact. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.CI/CDIntermediate16 minProCICD-1380A Sentinel or OPA gate passes in staging and fails in prodA Sentinel or OPA gate passes in staging and fails in prod focuses on Deployment Governance and asks the reader to isolate the key signal in hashicorp. Policy failures often reveal stack-generation drift rather than a bad rule.CI/CDAdvanced16 minProCICD-1308A speculative Terraform plan in VCS succeeds but the real apply failsA team trusts green speculative plans and later finds applies failing only when merged through the VCS trigger path.CI/CDAdvanced16 minProCICD-1338A Terraform apply deadlocks a rolloutA governance policy seems correct across most stacks and later one workspace category becomes permanently queued before apply.CI/CDAdvanced16 minProCICD-1372A Terraform Cloud apply works in lower environments and fails in productionA Terraform Cloud apply works in lower environments and fails in production focuses on Deployment Governance and asks the reader to isolate the key signal in hashicorp. Remote apply divergence often lives in workspace inheritance l...CI/CDAdvanced16 minProCICD-1362A Terraform Cloud apply works in staging and fails in prodA multi-environment Terraform setup behaves consistently until production alone begins creating resources in the wrong region after a variable-set refactor.CI/CDAdvanced16 minProCICD-1314A Terraform Cloud run queue backs upA governance rollout adds policy checks and later certain workspaces become permanently queued despite valid plans.CI/CDAdvanced16 minProCICD-1332A Terraform Cloud run succeeds on plan and fails on applyA Terraform Cloud run succeeds on plan and fails on apply focuses on Deployment Governance and asks the reader to isolate the key signal in hashicorp. Terraform review quality depends on freezing more than the code revision alone.CI/CDAdvanced16 minProCICD-1352A Terraform module upgrade succeeds in plan and fails in applyA Terraform module upgrade succeeds in plan and fails in apply focuses on Deployment Governance and asks the reader to isolate the key signal in hashicorp. Provider upgrades can break implicit data contracts even when schemas do not change.CI/CDAdvanced16 minProCICD-1360A Terraform policy check fails only in productionA Terraform policy check fails only in production focuses on Deployment Governance and asks the reader to isolate the key signal in hashicorp. Policy failures can expose module-generation drift rather than policy mistakes.CI/CDAdvanced16 minProCICD-1342A Terraform run applies cleanly and the next destroy failsA Terraform codebase is refactored into wrapper modules and later destroy or drift remediation affects the wrong target only for one resource family.CI/CDAdvanced16 minProCICD-1208Editor lint says the local reusable workflow path is invalid while GitHub still runs it correctlyThe workflow executes in GitHub, but local tooling reports the reference as missing and pushes engineers toward the wrong cleanup work.CI/CDAdvanced16 minProCICD-1303Terraform init succeeds but apply failsA team refactors shared credentials logic and later only apply fails while init and state refresh continue to work.CI/CDAdvanced16 minProCICD-1323Terraform reads remote state fine and module fetch failsA configuration works from engineers laptops and later fails only in the remote execution environment when a private module source is introduced.CI/CDAdvanced16 minPro