Certification136 problems· 17 reviewed

AWS Solutions Architect Associate

136 incident response problems that help with AWS Solutions Architect Associate prep.

All problems (136)

K8S-018GPU workloads stay Pending even though the cluster autoscaler is onGPU workloads stay Pending even though the cluster autoscaler is on is a hands-on troubleshooting drill. A situation where the autoscaler is working but the workload waits because of a special node-group condition. Kubernetes Scheduling and Capacity needs to be checked by narr...KubernetesAdvanced29 minProK8S-014An overly aggressive liveness probe keeps restarting even healthy PodsAn overly aggressive liveness probe keeps restarting even healthy Pods is a hands-on troubleshooting drill. A situation where the liveness criteria become too tight during periods of high application load. Kubernetes Config and Rollouts needs to be checked by narrowing scope,...KubernetesIntermediate19 minProCICD-005Jobs waiting forever due to a self-hosted runner label mismatchJobs waiting forever (Auth and Session Failure) is a hands-on troubleshooting drill. A scenario for tracking labels, groups, and permission scope when the runner is alive but jobs are not picked up. GitHub GitHub Actions Workflows needs to be checked by narrowing scope, recent...CI/CDIntermediate19 minProCICD-020Only nightly builds failing due to a package registry rate limitA situation where it is fine during the day, but parallel builds pile up at certain hours and hit an external package registry limit.CI/CDIntermediate22 minProK8S-020After a secret rotation, only certain Pods keep using the old credentialA situation where the secret was rotated but, with no rollout trigger, only some workloads still reference the old value.KubernetesIntermediate23 minProSECURITY-098CloudFront signed cookie scope excludes the websocket upgrade host and only the browser terminal loses authStatic pages load normally, but the interactive browser tool fails because the signed cookie domain or path does not cover the upgraded endpoint host.SecurityAdvanced16 minProCICD-097S3 static site deploy uploads the new assets but old signed URLs stay embedded in the manifestThe files exist in the bucket, yet clients keep failing because the generated manifest still references stale signed asset URLs from the previous build.CI/CDAdvanced16 minProSECURITY-149A CloudFront signed URL policy covers the main asset host, but a redirect to the image host drops the signature scope and private media leaks a 403 loopThe control is present, yet the delivery path crosses hostnames that do not share the same authorization contract.SecurityAdvanced17 minProSECURITY-381A snapshot policy copies encrypted data correctlyA snapshot policy copies encrypted data correctly focuses on cloud-security-and-governance and asks the reader to isolate Permission Denied in AWS. 실무에서는 permission-denied 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다.SecurityAdvanced17 minProSECURITY-135An AWS IAM permissions boundary copied from a template blocks kms:Decrypt in the break-glass role and recovery automation fails during an incidentThe emergency role exists, yet one inherited boundary quietly removes the exact permission the runbook requires.SecurityAdvanced17 minProSECURITY-154An IAM role trust policy is updated for the new OIDC issuer, but the condition key still references the old provider path and federated deploys failThe identity provider appears swapped successfully, yet the claim-matching logic is still anchored to the previous issuer structure.SecurityAdvanced17 minProSECURITY-150An incident containment playbook revokes the VM role, but the host's metadata proxy cache keeps serving old credentials for several minutesThe control plane moved fast, yet runtime revocation lag created a dangerous grace period.SecurityAdvanced17 minProSECURITY-096AWS IAM role session policy shrinks access below the base role and only one Lambda path fails decryptThe role seems correct, yet decryption still fails because the assumed session adds a restrictive inline policy at invocation time.SecurityAdvanced17 minProSECURITY-318A backup or snapshot path is readable while cross-account or cross-region recovery still lacks the exact decrypt or restore permission it needs during a failover rehearsalThe artifact exists and the recovery scope where it matters is still unauthorized. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-234A backup snapshot restores while the copy role still lacks the right to re-encrypt in the target account during a failover rehearsalDisaster recovery looks viable until the protected copy has to become live elsewhere. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProCICD-133A blue-green DNS cutover succeeds, but the CDN origin pin remains on the old backend and a percentage of traffic never movesThe authoritative name points correctly, yet cached origin metadata upstream still holds users on the retired stack.CI/CDAdvanced18 minProCICD-155A blue-green switch updates the public ALB target group, but internal service discovery still resolves to the blue stack and background jobs keep writing thereThe front door moved cleanly, yet internal callers remain on the previous environment because they use a different discovery source.CI/CDAdvanced18 minProSECURITY-180A cloud permission exists in one region while the recovery workflow executes in another scope during a failover rehearsalThe right grant is present and absent at the same time depending on where the workflow actually runs. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-124A presigned URL is valid, but the CDN cache key ignores one scoping parameter and content becomes reusable outside the intended request contextObject access control is strong at origin, yet the edge cache weakens it by collapsing distinct authorization contexts.SecurityAdvanced18 minProSECURITY-104A rotated KMS key policy omits the legacy alias and historical backup decrypt operations fail during recoveryNew encrypt operations work, but restore testing fails because the recovery path still references an alias that the new policy no longer permits.SecurityAdvanced18 minPro