Certification136 problems· 17 reviewed

AWS Solutions Architect Associate

136 incident response problems that help with AWS Solutions Architect Associate prep.

All problems (136)

SECURITY-032KMS alias resolves correctly but decrypt still fails for the app roleThe application can discover the key alias and reach KMS, yet decrypt operations fail because the key policy and IAM policy do not grant the same effective path.SecurityAdvanced26 minProCICD-029Monorepo path filter misses shared library changesMonorepo path filter misses shared library changes is a hands-on troubleshooting drill. Only some services rebuild because the path filter ignores a shared package that affects multiple deployments. GitHub Rollback and Rollout needs to be checked by narrowing scope, recent cha...CI/CDAdvanced26 minProCICD-036CodeDeploy rollback alarm never firesThe blue-green deployment partially shifts traffic, but the rollback condition never triggers because the health alarm watches only the stable target group.CI/CDAdvanced27 minProSECURITY-037Least-privilege refactor breaks cross-account accessA role assumption path worked before the permission cleanup, but third-party or cross-account access now fails because the new trust conditions no longer align with the expected external ID flow.SecurityAdvanced27 minProK8S-026PriorityClass keeps critical jobs alive but starves batch queueThe urgent workload policy solves one problem and silently creates another by preventing lower-priority queues from ever catching up.KubernetesAdvanced27 minProK8S-023Admission webhook blocks only one namespace pathAdmission webhook blocks only one namespace path is a hands-on troubleshooting drill. Most workloads apply normally, but a webhook policy rejects a specific namespace because labels and defaults diverge. Kubernetes Ingress and Traffic needs to be checked by narrowing scope, re...KubernetesAdvanced28 minProCICD-032OIDC subject condition mismatch denies AWS deploy role assumptionGitHub Actions reaches AWS STS, but the trust policy rejects the web identity token because the subject or audience condition no longer matches the branch and environment path.CI/CDAdvanced28 minProCICD-026Promotion pipeline deploys stale image from previous commitThe promotion stage uses an artifact reference that looks correct but resolves to an older image digest after registry cleanup.CI/CDAdvanced29 minProCICD-040Terraform apply succeeds in staging but production backend locks a different state tableThe same pipeline logic passes against one workspace, but production never converges because the remote backend, state lock table, or workspace mapping differs subtly.CI/CDAdvanced30 minProSECURITY-114A bucket policy blocks public reads, but the legacy website endpoint still exposes content through an old object ACLThe new policy appears strict, yet one access path bypasses it because object-level permissions were left behind from the static site era.SecurityAdvanced17 minProSECURITY-158A cross-account access analyzer stays green, but a new resource policy grants a service principal wildcard that the analyzer scope does not flag in this org layoutVisibility tooling is present, yet its scope is narrower than the real exposure surface.SecurityAdvanced17 minProSECURITY-144A new KMS grant allows the backup role to decrypt snapshots, but the grant was created in one region and cross-region restore still failsThe permission exists, just not in the control-plane scope the recovery workflow actually uses.SecurityAdvanced17 minProCICD-393A release artifact is immutable while the runtime startup still downloads a policy pack from a bucket with newly narrowed cross-account access during a staged decommissionThe artifact did not change, but its boot dependency contract did. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.CI/CDAdvanced17 minProCICD-158An IaC drift detector ignores a tag-only difference, but the omitted tag controls an SCP exception and the next deploy fails in production onlyThe infrastructure looks equivalent in shape, yet one governance-relevant tag changed the allowed behavior.CI/CDAdvanced17 minProCICD-375An infrastructure drift policy ignores deleted optional resources while a recovery run still expects their outputs to exist for rollback wiring during a staged decommissionThe live state looks acceptable until rollback tries to consume outputs from deleted optional blocks. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.CI/CDAdvanced17 minProCICD-011Branch protection rules exist, but the deploy workflow pushes directly to mainCovers a deployment-policy problem where code-review protection exists but the automation account becomes a bypass path.CI/CDBeginner17 minProSECURITY-128S3 encryption enforcement is enabled, but a legacy multipart client omits the required KMS context and uploads start failing midstreamThe bucket policy is correct, yet one older client implementation cannot satisfy the newer encryption contract.SecurityAdvanced17 minProCICD-234A release candidate passes smoke tests in one region while traffic warmup happens against another region during a failover rehearsalValidation says the build is safe, but the workload that receives real traffic is not the one the tests exercised. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.CI/CDIntermediate18 minProCICD-147A Terraform destroy plan targets the right workspace, but the provider alias resolution shifted and the plan now points at the shared services accountReviewers looked at the expected stack, yet runtime provider wiring changed the real blast radius.CI/CDAdvanced18 minProCICD-128A Terraform plan file is generated with one provider plugin version and applied later with another, producing an unexpected drift errorThe change was reviewed correctly, but the saved plan no longer matches the provider behavior available at apply time.CI/CDAdvanced18 minPro