Certification136 problems· 17 reviewed

AWS Solutions Architect Associate

136 incident response problems that help with AWS Solutions Architect Associate prep.

All problems (136)

SECURITY-282A trust policy validates the new OIDC issuer while one condition key still matches the old claim path during a failover rehearsalThe provider migration is half-complete and federated access still fails on the detail that matters. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-210An authorization token is valid for one delivery host while the content path crosses into another during a failover rehearsalAuthorization is scoped correctly and the asset path does not stay where the token applies. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-111CloudTrail shows the access denies, but the missing service-linked role auto-creation was never logged in the regional trail you checkedThe permissions symptom is real, yet the causal event lives in a different audit scope than the one the team has been searching.SecurityAdvanced18 minProSECURITY-216Runtime credential caches keep serving access long after central revocation completed during a failover rehearsalThe security team acts quickly and the runtime still lives in the past. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityAdvanced18 minProSECURITY-079Secrets Manager rotation succeeds but the application keeps reading the old current version stageThe rotation Lambda finishes, yet the service still fails login because the stage labels and the consumer refresh path are out of sync.SecurityAdvanced18 minProSECURITY-099Security group egress hardening blocks the OCSP responder and only strict TLS clients fail validationCertificates are current, yet a subset of clients fail because the server-side environment can no longer complete revocation checks through the hardened egress policy.SecurityAdvanced18 minProCICD-204A blue-green cutover moves public ingress while internal service discovery stays on the previous stack during a failover rehearsalPublic traffic shifts cleanly but batch or backend callers continue writing into the old environment. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDAdvanced19 minProCICD-068CloudFront keeps serving stale index.html after a blue-green cutoverThe new environment is healthy, but users still load references to the old asset set because cache invalidation and origin switch ordering were not coordinated.CI/CDAdvanced19 minProCICD-079Mutable image tag makes an ECS rollback pull a newer build than the failed releaseThe rollback logic points at the previous task definition, yet the service still launches the wrong container because both revisions refer to the same mutable image tag.CI/CDAdvanced19 minProCICD-091Release manifest points at a digest that exists only in the staging registryThe promotion metadata looks valid, but production cannot pull the image because the referenced digest was never replicated to the target registry.CI/CDAdvanced19 minProSECURITY-093Secrets rotation updates the database user but leaves a cached connection pool authenticating with the old passwordThe new credential is valid, yet outages continue because the application pool never discarded existing sessions that still reuse the previous password flow.SecurityAdvanced19 minProCICD-078Canary analysis passes against cached CDN responses instead of the origin traffic it was meant to judgeThe rollout looks healthy by metric, but the analysis is reading cache-hit behavior and not the new origin path that users will actually exercise after promotion.CI/CDAdvanced20 minProSECURITY-072IAM permission boundary blocks emergency admin role assumption despite the attached allow policyThe incident role seems fully privileged, but assumption still fails because the boundary silently caps effective access below the attached policy intent.SecurityAdvanced20 minProSECURITY-083KMS grant allows encrypt but one rotated alias points the application to a key without decrypt permissionThe secret path still looks valid, yet runtime failures begin because the alias now resolves to a different key than the policy and grants were built for.SecurityAdvanced20 minProCICD-089Multi-account deployment role trusts the pipeline account but not the delegated tooling role session name patternCross-account deploys worked before, but now fail because the trust policy still allows the source account while denying the actual delegated session identity format.CI/CDAdvanced20 minProK8S-090Node reboot storm leaves CSI node plugin healthy but volume mounts failThe plugin pods appear up after recovery, but mounts still fail because kubelet is looking for a registration endpoint that the updated plugin no longer exposes in the same path.KubernetesAdvanced20 minProK8S-086Cluster Autoscaler ignores pending podsPods stay pending and autoscaling never reacts because the requested local storage profile cannot fit any node shape in the expansion group.KubernetesAdvanced21 minProCICD-076Cross-region artifact replication lags and the disaster-recovery deploy uses a partial releaseThe promotion completed in the primary region, but the DR environment pulls an incomplete artifact set because replication finished for the manifest before every dependent object arrived.CI/CDAdvanced21 minProK8S-097CSI snapshot restore completes but the filesystem UUID collision confuses the bootstrap scriptStorage comes back online, yet the app still fails because the restored filesystem identity collides with a value the startup logic treats as unique.KubernetesAdvanced21 minProCICD-065ECR lifecycle cleanup deletes one architecture image and arm nodes start failing pullsThe repository still contains the expected tag, but multi-architecture pulls break on one platform because the manifest list points to a child image that was already expired.CI/CDAdvanced21 minPro