Certification942 problems· 22 reviewed

AWS DevOps Engineer Professional

942 incident response problems that help with AWS DevOps Engineer Professional prep.

All problems (942)

CICD-011Branch protection rules exist, but the deploy workflow pushes directly to mainCovers a deployment-policy problem where code-review protection exists but the automation account becomes a bypass path.CI/CDBeginner17 minProCICD-137Build provenance records the merge queue pseudo-ref, but the published tag points elsewhere and auditors cannot reconcile the releaseAll artifacts exist, yet traceability breaks because the build source ref and user-facing release ref diverged.CI/CDAdvanced17 minProCICD-125Git submodule authentication works during checkout, but the downstream Docker build context cannot re-fetch the private module and image creation failsThe workflow clone step succeeds, yet a later stage rebuilds context in an environment without the same credentials.CI/CDAdvanced17 minProCICD-084GitHub Environment protection waits foreverReviewers approve the release, but the gate never opens because the workflow reports status to a differently cased or aliased environment than the protected one.CI/CDAdvanced17 minProCICD-1294Parallel OIDC jobs fail sporadicallyA repository changes many workflow files at once and suddenly several OIDC-enabled jobs begin failing randomly.CI/CDAdvanced17 minProCICD-101Preview environment cleanup job deletes the release candidate namespace before smoke tests startA pull request environment vanishes moments before validation because the cleanup workflow no longer waits for the downstream smoke test status.CI/CDAdvanced17 minProCICD-1260Runner registration succeeds but later reconnects fail with access deniedRunner registration succeeds but later reconnects fail with access denied focuses on Identity And Access and asks the reader to isolate the key signal in GitHub. A token that can register a runner is not automatically sufficient for the runner's ste...CI/CDAdvanced17 minProCICD-118Secret-scanning allowlist suppresses detection of a real deploy key leak after the repository path pattern changedA known false positive rule is kept too broad, and once the repository layout changes it begins to hide a genuine credential leak in the new path.CI/CDAdvanced17 minProCICD-148The artifact retention job keeps the container image but deletes the detached attestation blob, and production admission starts blocking the next rolloutBuild and publish succeeded, yet the downstream verifier requires a side artifact that retention policy treated as optional.CI/CDAdvanced17 minProCICD-351A blue-green cutover validates HTTP health while background lease holders still point at the retiring environment during a staged decommissionThe front door is healthy, but a hidden ownership path keeps mutating state from the wrong side. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.CI/CDAdvanced18 minProCICD-1261A cache restore step works on hosted runners but fails on a self-hosted runnerCI/CD incident scenario used for structured troubleshooting practice.CI/CDAdvanced18 minProCICD-1266A cache restore step works on hosted runners but fails on a self-hosted runnerA self-hosted pipeline starts failing only on cache restore or save after a containerized or sudo-based build step was introduced.CI/CDAdvanced18 minProCICD-1289A canary deploy health check stays redA canary deployment begins failing only after a cluster or auth dependency upgrade, even though application code and rollout logic are unchanged.CI/CDAdvanced18 minProCICD-330A container build uses one CA bundle during image creation while the runtime base layer refreshes and trusts a different internal PKI root during a failover rehearsalThe built image and the later-executed image lineage no longer share the same trust store assumptions. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced18 minProCICD-1250A deployment concurrency rule exists but two production writes still overlapTeams split release and hotfix workflows and later discover both can deploy to the same target at once even though each workflow defines concurrency.CI/CDAdvanced18 minProCICD-1246A deployment preview updates successfully but one approval job still shows the previous commitA pull request preview deploy completes and reviewers still see links or status details bound to a previous commit's environment record.CI/CDAdvanced18 minProCICD-1265A Docker build pushes successfully but later pulls failCI/CD incident scenario used for structured troubleshooting practice.CI/CDAdvanced18 minProCICD-1270A Docker build pushes successfully but later pulls failA registry migration leaves CI green while production deploys fail or pull an unexpected image because the runtime host is still logged into the former registry.CI/CDAdvanced18 minProCICD-1238A private registry login works in setup but later restore still failsA workflow can authenticate to a private registry, but later pull operations fail only after the pipeline enters a composite helper action.CI/CDAdvanced18 minProCICD-1255A production approval exists but two deployment workflows still overlapA release workflow and a hotfix workflow both define concurrency and still deploy over one another on the same target.CI/CDAdvanced18 minPro