Certification942 problems· 22 reviewed

AWS DevOps Engineer Professional

942 incident response problems that help with AWS DevOps Engineer Professional prep.

All problems (942)

CICD-115Blue-green cutover updates ingress weights but the background cron target still writes into the old database schemaUser traffic looks healthy after the switch, yet scheduled jobs still point at the old stack and corrupt data alignment across environments.CI/CDAdvanced20 minProCICD-1200Cache hit makes CI look healthy while one private dependency was never refreshed after token rotationThe pipeline remains fast and green until the cache is cold, because a private dependency path still depends on an old token that only surfaces when fresh fetches happen.CI/CDIntermediate20 minProCICD-1193Fork pull request validation cannot read required secrets and the pipeline fails for the wrong reasonThe workflow itself is healthy, but pull_request runs from forks cannot access the same secret path as internal branches, causing misleading failures in preview jobs.CI/CDIntermediate20 minProCICD-1203Manual rerun fixes the pipelineA public CI pattern generates environment state during the job. The first run consumes it too early, but reruns appear healthy because cached or leftover state exists by then.CI/CDIntermediate20 minProCICD-053OCI Helm chart publish succeeds but cluster still pulls the previous chartThe registry receives the new chart artifact, yet the deployment job keeps resolving the previous digest because the chart reference and version bump were not updated together.CI/CDIntermediate20 minProCICD-105Rollback restores the app chart but not the migration job image and the database contract stays ahead of the codeA release rollback appears complete, yet application errors continue because the migration runner image remained on the newer schema contract.CI/CDAdvanced20 minProCICD-033Selected actions policy blocks reusable workflow from organization catalogA repository can still run local workflows, but a central reusable workflow fails because organization policy only allows selected actions and patterns.CI/CDIntermediate20 minProCICD-1209Self-hosted runner says a required secret is missing after the workflow moved behind a reusable callThe secret exists centrally, but the called workflow still fails because the new call contract no longer matches how the secret is declared.CI/CDIntermediate20 minProCICD-667A preview environment uses feature flags from production defaults and hides...A preview environment uses feature flags from production defaults and hides... focuses on ci-cd-workflow-debugging and asks the reader to isolate Permission Denied in AWS. 실무에서는 ci-cd-workflow-debugging 문제를 볼 때 실패 단계만 보지 말고 최근 변경, 이미지 태그, 시크릿 주입, 롤백 가능 여부를 먼저 함께 확인하는 편이 빠릅니다.CI/CDIntermediate21 minProCICD-081Approval workflow promotes the wrong artifactThe review step is followed correctly, but the production deployment still uses the wrong image because the artifact reference is re-evaluated after a newer build already exists.CI/CDAdvanced21 minProCICD-055CodeBuild local cache reuses stale base layer after package repository changedBuild time looks great, but the produced image quietly carries an older package baseline because local Docker layer cache survives a repository-side base image update.CI/CDIntermediate21 minProCICD-1183Release note generation failsA public release-notes snippet works locally but fails in CI because the runner cannot see the full tag history.CI/CDIntermediate21 minProCICD-1201Reusable workflow output exists in logs but the caller job still reads it as emptyThe called workflow clearly sets an output, yet the parent pipeline sees an empty value because the output contract is not exposed on the boundary the caller is actually reading.CI/CDIntermediate21 minProCICD-017Unsigned images get mixed in and are blocked by the deployment approval policyA situation where the security policy is correct but a missing image-signing scheme blocks releases for only certain services.CI/CDIntermediate21 minProCICD-1196Checkout succeeds but dependency fetch from a private submodule still fails under the package managerThe repository itself checks out, yet the build fails when a package manager attempts to read a private submodule path with a different auth path than the initial checkout.CI/CDIntermediate22 minProCICD-025Parallel integration jobs overwrite the same test databaseParallel integration jobs overwrite the same test database is a hands-on troubleshooting drill. Test isolation is missing, so matrix jobs race each other and make the pipeline fail only under parallel load. GitHub GitHub Actions Workflows needs to be checked by narrowing scope...CI/CDIntermediate22 minProCICD-1185Protected environment exists but deploy still bypasses manual approvalA dynamic environment-selection branch path resolves to a target that is not actually covered by the intended approval gate.CI/CDIntermediate22 minProCICD-006Wrong artifacts deployedA scenario that narrows down the root cause, centered on designing how to guarantee output boundaries between parallel jobs, in the situation of wrong artifacts being deployed because matrix build results get mixed up.CI/CDIntermediate22 minProCICD-726A preview environment uses feature flags from production defaults and hides...A preview environment uses feature flags from production defaults and hides... focuses on ci-cd-workflow-debugging and asks the reader to isolate Permission Denied in AWS. 실무에서는 ci-cd-workflow-debugging 문제를 볼 때 실패 단계만 보지 말고 최근 변경, 이미지 태그, 시크릿 주입, 롤백 가능 여부를 먼저 함께 확인하는 편이 빠릅니다.CI/CDIntermediate23 minProCICD-1186Reusable deploy workflow breaks after repository default token scope was hardenedA shared deploy workflow worked for months, then started failing after default GitHub token permissions were reduced at the repository level.CI/CDIntermediate23 minPro