AWS Solutions Architect Associate
136 incident response problems that help with AWS Solutions Architect Associate prep.
먼저 읽을 가이드
추천 문제
All problems (136)
CICD-087Rollback Lambda succeeds but the Auto Scaling warm pool still serves the failed launch templateThe rollback path updates the group, yet instances continue to launch with the broken version because the warm capacity pool retained the earlier template state.CI/CDAdvanced21 minProSECURITY-075An SCP allows the recovery service but blocks the dependent KMS decrypt call during restoreThe incident playbook launches correctly, but restore still fails because the organization policy forgot the downstream KMS permission the service actually needs.SecurityAdvanced22 minProCICD-085CloudFormation import succeeds but later drift repair wants to replace the manually retained resourceThe stack stabilizes after import, yet a future update becomes dangerous because the imported resource shape still differs from what the template assumes is replaceable.CI/CDAdvanced22 minProSECURITY-087CloudTrail organization trail exists but one delegated admin account writes to an unmonitored bucket in another regionAudit coverage seems complete, yet one privileged path is effectively invisible because the delegated admin is using a destination outside the monitored collection pattern.SecurityAdvanced22 minProK8S-028Node drain hangs on long-lived connection podsMaintenance starts correctly, but eviction never finishes because connection draining and termination hooks take too long.KubernetesIntermediate22 minProCICD-093Terraform drift fix replaces a subnet that still holds the canary target group routeThe plan appears corrective, but applying it would cut live traffic because one supposedly stale subnet still anchors an active canary path.CI/CDAdvanced22 minProCICD-073Terraform plan looks safe but apply recreates IAM roles after a for_each key renameNo obvious destructive change is noticed in review, yet apply replaces active roles because the stable key used by for_each changed during a refactor.CI/CDAdvanced22 minProK8S-076VolumeSnapshot restore binds to the wrong PVC lineage after a cloned recovery testThe snapshot data is valid, but a later restore attaches to the wrong expectation chain because snapshot content and clone naming were reused too casually during testing.KubernetesAdvanced22 minProCICD-008Deployments passing without verificationA scenario that narrows down the root cause, centered on designing governance that enforces the verification step before deployment approval, in the situation of deployments passing without verification because a smoke-test conditional is wrong.CI/CDAdvanced23 minProSECURITY-063KMS policy lets backup jobs encrypt but restore jobs cannot decrypt in the recovery accountBackups complete successfully, yet every restore attempt fails because the disaster-recovery account was never granted the full decrypt path for the same key.SecurityAdvanced23 minProCICD-083Schema migration succeeds on the writer but read replicas still serve incompatible shape to canary trafficThe migration log looks successful, yet the canary still fails because replica lag leaves part of the traffic reading the old schema path.CI/CDAdvanced23 minProK8S-062Stale VolumeAttachment object blocks PVC reattach after a node lossThe replacement node is ready, but the workload never mounts its volume because the storage control path still believes the old attachment is active.KubernetesAdvanced23 minProCICD-063Terraform remote state lock survives a killed apply in a cross-account backendA failed apply no longer holds any active process, but every later run still stops on the lock because the backend cleanup path never completed across accounts.CI/CDAdvanced23 minProCICD-075Blue-green node group cutover drains the only log shipper before the replacement path is readyThe new nodes are healthy for the app, but operational visibility disappears because the drain order removed a cluster-wide DaemonSet before the replacement fleet was fully attached.CI/CDAdvanced24 minProSECURITY-038CDN caches an authenticated error pageThe login path itself is correct, but one personalized failure response gets cached at the edge and leaks confusing content to later users.SecurityAdvanced24 minProCICD-066CodeDeploy validation hook times outThe deployment itself is healthy, but the lifecycle validation keeps failing because the hook Lambda cannot reach the internal API it uses to prove readiness.CI/CDAdvanced24 minProK8S-069Cross-node gRPC calls failIntra-node traffic is clean, but larger cross-node requests hang because one node pool uses a smaller effective MTU than the other path expects.KubernetesAdvanced24 minProSECURITY-069Organization-wide CloudTrail is enabled but one region never uses the expected KMS keyAudit logging exists everywhere, yet one region violates the encryption standard because replication and key policy assumptions drifted apart over time.SecurityAdvanced24 minProK8S-071PodDisruptionBudget and topology spread leave no legal recovery layout after an AZ outageThe workload had enough replicas before the outage, but after one zone disappears the remaining rules make every recovery option violate either spread or disruption guarantees.KubernetesAdvanced24 minProSECURITY-060GuardDuty member onboarding failsThe delegated admin path looks correct, but one child account never enables the detector because organizational guardrails deny the role creation needed by the service.SecurityAdvanced26 minPro