Mock Exam · Set 4
This is practice paper four of five for AWS's DevOps Engineer Professional exam (DOP-C02), and it's built with a deliberate tilt. If you have limited study time left, the highest-leverage move isn't spreading it evenly across all six blueprint domains — it's mastering the three that together make up 56% of the real exam: SDLC Automation, Configuration Management & IaC, and Security & Compliance. This paper reflects that math directly: thirty scenario-based questions, and more than three-quarters of them come from those three domains rather than a proportional split. Sit the exam guide first if you haven't, and keep Set 5 sealed as your final, evenly-weighted dress rehearsal.
Imagine a test has six chapters, but three of them are worth more than half your grade combined, and you only have time to really study three chapters well before test day. Which three do you pick? Not "whichever three are easiest" — the three worth the most points. That's this whole paper: instead of one question from every chapter in a tidy row, it hands you extra practice on the three chapters that would hurt the most to walk in unprepared for, because on the real test those three chapters are worth fifty-six points out of a hundred.
Where Set 4 fits among the five DOP-C02 papers
☺ Like you're 10: Four practice papers built from the same blueprint, but this is the one where three chapters get most of the questions on purpose.
All five DOP-C02 papers on this site draw from the same six-domain blueprint and use scenario-based, single-best-answer questions in the same style as the real exam, so a score on one paper is genuinely comparable with a score on another — what changes across the set is the shape of the coverage, not the topics themselves. Sets 1 through 3 split their questions roughly proportional to the official blueprint weights, giving you broad, balanced practice across all six domains. Set 4 abandons that balance on purpose, concentrating repetitions on the three domains a time-constrained candidate should master first. Set 5 is held back as the closest thing to a genuine, evenly-weighted cold run.
| Paper | Character | Best sat |
|---|---|---|
| Set 1 | Balanced, blueprint-proportional coverage — first exposure to all six domains | End of your first pass through the six blueprint pages |
| Set 2 & Set 3 | Mixed reinforcement, still blueprint-proportional | In between, spaced a few days apart |
| Set 4 (this one) | Deliberately skewed — SDLC Automation, Configuration Management & IaC, and Security & Compliance carry 23 of 30 questions | When study time is short and you need to triage, or a week or two before the real sitting regardless |
| Set 5 | Sealed, blueprint-proportional — the closest thing to a genuine cold run | Days before your real exam, exam conditions, no peeking beforehand |
If you haven't yet worked through the six blueprint pages and at least one earlier paper, this is a defensible place to start rather than the wrong one — precisely because it concentrates your first pass on the highest-value material. But don't mistake a good Set 4 score for exam readiness by itself: it deliberately under-samples Resilient Cloud Solutions, Monitoring & Logging, and Incident & Event Response, which are still a combined 44% of the real exam. Follow it with Set 1 or Set 2 for the balanced coverage this paper intentionally skips, and see the study plan for where all five fit across your weeks of prep.
Exam conditions — sitting it for real
☺ Like you're 10: One clock, no notes, every question answered — the same rules the real exam actually uses.
A mock paper only measures what the conditions you sit it under allow it to measure. The real DOP-C02 exam is closed-book — no second monitor, no notes, no AWS documentation open in another tab — so a paper worked with a browser tab open somewhere else has measured your search skills, not your readiness.
- One timer, started once. The real exam runs 75 questions in 180 minutes — roughly 2.4 minutes per question. Thirty questions at that same pace is about 72 minutes; round up to 75 minutes and don't pause it once it starts.
- Leave the domain chips on "All 30". Filtering by domain during a sitting turns one paper into six easy little ones; use the chips afterward, for revision, not during.
- Answer every question. The real exam has no penalty for a wrong answer, and neither does this paper — an unanswered question is a guaranteed zero, while a considered guess between two options is a coin flip you were offered for free.
- Commit before you read the explanation. The reveal is instant and generous — read it before choosing and you've converted a test into a reading exercise.
- Write down every question where you eliminated correctly but still second-guessed yourself. That hesitation is exactly what answer triage & elimination is built to train away.
- Don't immediately re-sit. Go re-derive the two or three questions that stalled you against the actual AWS documentation, then come back and use Shuffle / reset — question order and option order both reshuffle, so you can't pass by remembering which button was green.
At the time this page was written, AWS's own exam guide describes the DevOps Engineer Professional exam (DOP-C02) as 75 questions (some unscored and not identified as such), 180 minutes, multiple-choice and multiple-response, with a scaled score from 100–1000 and a pass mark of 750 — a figure AWS explicitly states is not the same as "75% correct," since the scaling accounts for relative question difficulty across exam forms. The six domain weights used throughout this site — SDLC Automation 22%, Configuration Management & IaC 17%, Resilient Cloud Solutions 15%, Monitoring & Logging 15%, Incident & Event Response 14%, Security & Compliance 17% — come from AWS's own published exam guide for DOP-C02. Exam details are revised by AWS over time — question count, duration, pricing, domain weights, and the pass mark have all changed on past exam versions — so confirm everything current at the official AWS DevOps Engineer Professional certification page before you register.
Why this paper leans on three domains
☺ Like you're 10: Three of the six chapters are worth more than half your grade combined — so this paper gives you extra practice on exactly those three.
AWS's own exam guide states the six DOP-C02 domain weights plainly, and they are not close to even. SDLC Automation alone is 22% — nearly a quarter of the entire exam from one domain. Add Configuration Management & IaC (17%) and Security & Compliance (17%) and three of the six domains already account for 56 of the exam's 100 weighted points, while the remaining three domains — Resilient Cloud Solutions, Monitoring & Logging, and Incident & Event Response — split the other 44% roughly evenly. A candidate who studies all six domains for equal amounts of time is spending disproportionate effort on the lighter half of the blueprint relative to what it's actually worth on exam day.
| Domain | Official blueprint weight | A balanced paper's share (Sets 1–3, 5) | Set 4's actual questions |
|---|---|---|---|
| 🦫 SDLC Automation | 22% | ~7 of 30 | 9 (30%) |
| 🤖 Configuration Management & IaC | 17% | ~5 of 30 | 7 (23%) |
| 🦉 Resilient Cloud Solutions | 15% | ~5 of 30 | 3 (10%) |
| 🐘 Monitoring & Logging | 15% | ~4 of 30 | 2 (7%) |
| 🐦 Incident & Event Response | 14% | ~4 of 30 | 2 (7%) |
| 🦊 Security & Compliance | 17% | ~5 of 30 | 7 (23%) |
| Total | 100% | 30 | 30 |
This is not "the other three domains don't matter" — they're still 44% of the real exam and this paper still tests them. It's "if you can only get two of the six blueprint pages to genuine fluency this week, make them SDLC Automation and one of Configuration Management & IaC or Security & Compliance" — because those three alone outweigh the other three combined by twelve full points on the real exam.
Reading a DOP-C02 scenario question fast
☺ Like you're 10: Find the AWS services hiding in the story, then find the one word that tells you what "best" actually means here.
Real DOP-C02 questions are almost never "what does service X do." They're a paragraph of scenario, a constraint, and four plausible-sounding options where two are usually wrong for a subtle reason rather than an obvious one. Three habits make these faster and more reliable to answer:
- Name the services in the stem before you read the options. A question mentioning "cross-account," "no plaintext credential," or "before it reaches a human" is telling you which service family the answer lives in — IAM/KMS, Secrets Manager, EventBridge/Automation — before you've seen a single option.
- Circle the qualifier word. "MOST operationally efficient," "LEAST development effort," "with the fewest ongoing costs" — these words eliminate options that technically work but fail the actual constraint. A correct-sounding option that ignores the qualifier is the classic trap.
- Ask what problem each wrong option actually solves. A tempting wrong answer on this exam is rarely nonsense — it's usually a real AWS feature that solves a slightly different problem than the one in the stem. Naming that different problem is how you eliminate it with confidence instead of a guess.
Before you touch this paper, pick any three questions from the SDLC Automation blueprint page's own examples and, for each of the four options, write one sentence naming the AWS problem it actually solves — not whether it's right or wrong, just what it's for. The option that solves a real problem the question never asked about is the wrong answer nine times out of ten, and this is the exact mechanic answer triage & elimination covers in full.
The paper — 30 questions
☺ Like you're 10: Pick an answer. It turns green or red right away and tells you why yours was wrong too.
Click an option to lock it in — the correct answer is marked, your mistake (if any) is marked, and the explanation appears underneath immediately. Each explanation covers both the right answer and the most tempting wrong one, because the near-miss is exactly what's worth understanding on a scenario-heavy paper. The counter and bar above the questions track your progress and score; the chips filter by domain for revision afterward; Shuffle / reset reshuffles both the questions and the options and starts a fresh attempt. Your best score is remembered on this device only — nothing is sent anywhere.
Scoring yourself, honestly
☺ Like you're 10: Write down your score per domain, not just the one big number at the top.
The counter gives you a raw percentage, but AWS's real scoring doesn't work in simple percentages — the pass mark is a scaled score of 750 out of 1000, and AWS states explicitly that the scaling accounts for question difficulty across exam forms rather than mapping cleanly to "75% correct." Treat any percentage on this page, including this one, as a thermometer rather than a certified predictor. What matters more than the headline number is the shape underneath it — and on a deliberately skewed paper, that shape needs a slightly different read than on a balanced one.
| Where you land | What it usually means on a skewed paper | The next move |
|---|---|---|
| Under 60% | Gaps in the three heaviest domains specifically — since they're 23 of 30 questions here, a low score is disproportionately a signal about SDLC Automation, Config & IaC, or Security & Compliance. | Filter by domain, find which of the three is weakest, and re-read that blueprint page in full before re-sitting. |
| 60–75% | The heavy domains are mostly solid; the misses often cluster in the three lighter domains this paper barely samples (2–3 questions each), which isn't enough to diagnose them properly on its own. | Sit Set 1 or Set 2 next for balanced coverage of Resilient Cloud Solutions, Monitoring & Logging, and Incident & Event Response. |
| 75–85% | Comfortable with the highest-value 56% of the blueprint. What's left is usually rounding out the lighter three domains and tightening scenario-reading speed. | Work the service reference and the closed-book strategy, then move to a balanced paper. |
| Over 85% | Strong across the domains this paper actually tests. Not yet proof of full-blueprint readiness, since three domains here got noticeably lighter coverage. | Sit Set 1, then Set 5 under strict timing as your final check before booking. |
Score your three heavy domains as one group and your three light domains as another. A candidate scoring 90% on SDLC/Config/Security but only 40% on the other three is in a genuinely strong position for this exam's actual point distribution — closer to passing than the raw 30-question percentage alone would suggest, because those three domains are worth more than half the real thing. The reverse pattern — strong on the light domains, weak on the heavy three — is the more dangerous one to walk into an exam with, even at the same overall percentage.
What to do with the wrong answers
☺ Like you're 10: Keep a list of what you got wrong and why your answer was wrong — that list becomes your whole revision plan.
Whatever you scored, the paper has only done its job if it produces a list. For every miss, write — in your own words — why the option you picked was wrong, not why the correct one was right. That's a different sentence, and it's the one that stops you repeating the same mistake once the real exam changes the service names and constraints on you.
mkdir -p ~/dop-c02-revision cat > ~/dop-c02-revision/set4-wrong-answers.md <<'EOF' # DOP-C02 Mock Set 4 — wrong answers | Q | Domain | What I picked | Why MY answer was wrong | Page to re-read | |---|--------|----------------|--------------------------|------------------| | | | | | | EOF open ~/dop-c02-revision/set4-wrong-answers.md
After a few papers, sort the rows by domain. If most of your misses sit in SDLC Automation, Configuration Management & IaC, or Security & Compliance, that's expensive to leave unfixed given their combined weight — treat it as this week's priority, not a someday task. If they're spread evenly but share a shape — every question that hinged on a cross-account KMS key policy, say, or every question about which CodeDeploy hook runs when — you've found something cheaper to fix than a domain-wide gap: a specific mechanic worth drilling once and remembering.
The fastest way to make a mechanic like a KMS grant or a CodePipeline change-set gate permanently intuitive is to actually run it once instead of only ever reading about it. Pick one from your wrong-answers list and reproduce it for real:
# Example: reproduce the cross-account KMS question for real, on a throwaway pair of accounts aws kms create-key --description "pipeline-artifact-key" --query 'KeyMetadata.KeyId' --output text # Grant the cross-account deployment role decrypt access via the key policy, # then confirm the account without an explicit grant is denied: aws kms decrypt --ciphertext-blob fileb://artifact.enc --key-id <key-id> --profile other-account # ...and re-run it after adding the grant to see the same call succeed.
The calculation or the permission model stops being an exam trick the moment it's attached to a command you actually ran and a denial you actually saw flip to success.
Where each domain is taught
☺ Like you're 10: Every question here traces back to one of six pages. Go back to the page, not to a search engine.
Nothing on this paper is examined that isn't taught somewhere in this course. The six blueprint pages below are the answer key at exam depth — and given this paper's skew, the first three cards are where a short-on-time candidate should spend the next study session.
SDLC Automation
CodePipeline orchestration, CodeBuild, CodeDeploy deployment configs and AppSpec hooks, CodeArtifact, and ECR.
🤖 · 7 Qs · 17% of the real examConfiguration Management & IaC
CloudFormation change sets, drift, stack policies, StackSets, custom resources, the CDK, and Systems Manager fleet config.
🦊 · 7 Qs · 17% of the real examSecurity & Compliance
IAM permission boundaries, KMS grants and key policies, Secrets Manager rotation, AWS Config remediation, GuardDuty and Security Hub.
🦉 · 3 Qs · 15% of the real examResilient Cloud Solutions
Multi-AZ vs. read replicas, Route 53 failover routing, and the four standard DR strategies by RTO/RPO.
🐘 · 2 Qs · 15% of the real examMonitoring & Logging
CloudWatch composite alarms, anomaly detection, and Logs Insights queries.
🐦 · 2 Qs · 14% of the real examIncident & Event Response
EventBridge-driven auto-remediation via Systems Manager Automation, tied to CloudWatch alarms and AWS Config findings.
Around them sits the rest of the DOP-C02 kit: the study plan for pacing across all five papers, the service reference and answer triage & elimination for technique, know it cold and the closed-book strategy for the final week, and the shared course tools — the flashcards, the exam simulator, and the glossary for anything a question assumed you already knew. For the underlying practices rather than more multiple choice, see secrets & credential management, testing in the pipeline, and compliance as code & policy enforcement — all three lean directly into this paper's heaviest domains. The AWS Developer Tools suite page covers CodePipeline, CodeBuild, and CodeDeploy hands-on.
Benny the Beaver: I built us a full practice paper. Six domains, five questions each, nice and tidy.
Recon the Robot: Tidy, but wrong. SDLC Automation is worth twenty-two of the exam's hundred points. Your "tidy" paper gives it the same five questions as Incident & Event Response, which is worth fourteen.
Benny: It felt fair, though. One-sixth each.
Foxy: Fair to the domains, maybe. Not fair to the candidate who only has one more weekend before the exam. Where should they spend it?
Recon: SDLC Automation, Config & IaC, Security & Compliance. Fifty-six points, from three pages instead of six. That's where Set 4 puts nine, seven, and seven questions instead of five apiece.
Timmy the Turtle: And I'm still not letting anyone skip the other three entirely — forty-four points doesn't fail you by itself, but it can tip a close score the wrong way.
Benny: Fine. Reweighted. Still feels a little uneven.
Recon: It should. The real exam is uneven. Practicing evenly when the target isn't even is the actual mistake.
Answer these without scrolling back. 1. Which three DOP-C02 domains combine for 56% of the real exam, and what are their individual official weights? 2. Why does Set 4 give SDLC Automation, Configuration Management & IaC, and Security & Compliance more questions than a proportional split would, and what does it deliberately sacrifice to do that? 3. What's the real exam's published question count, duration, and pass-mark structure — and why does AWS say the pass mark shouldn't be read as a simple percent-correct? 4. Given a CloudFormation update that would replace a production database, what mechanism configured in advance would have blocked it? 5. What's the difference between what GuardDuty does and what Security Hub does? 6. Why does a customer-managed KMS key — not the AWS-managed aws/s3 key — matter for a cross-account or cross-region CodePipeline artifact bucket?
Check your answers
- SDLC Automation (22%), Configuration Management & IaC (17%), and Security & Compliance (17%) — 22 + 17 + 17 = 56% of the exam's total weight, per AWS's own published DOP-C02 exam guide.
- Because those three domains are worth more exam points than the other three combined, so extra repetitions there have higher expected payoff for a time-constrained candidate. The trade-off is lighter coverage of Resilient Cloud Solutions, Monitoring & Logging, and Incident & Event Response — real domains, still 44% of the exam, that this paper only samples two or three times each and shouldn't be mistaken for full coverage.
- At the time of writing: 75 questions (some unscored), 180 minutes, multiple-choice/multiple-response, with a scaled score of 100–1000 and a 750 pass mark. AWS states the scaling accounts for relative difficulty across different exam forms, so 750/1000 does not translate to "75% of questions correct" — confirm current figures at AWS's official certification page before booking.
- A stack policy denying
Update:ReplaceandUpdate:Deleteon that resource's logical ID, configured before the risky update — CloudFormation blocks the action unless the update is submitted with an explicit policy override. - GuardDuty is the detection engine — it continuously analyzes VPC Flow Logs, DNS logs, and CloudTrail for signs of compromise. Security Hub is the aggregation layer — it collects findings from GuardDuty, Config, Inspector, and other sources into one dashboard and separately scores compliance against standards like CIS.
- For a principal in a different account (or a different region's replicated artifact) to decrypt objects, the KMS key policy must explicitly name that external principal — something you cannot do with the AWS-managed
aws/s3key, since its policy isn't editable. A customer-managed CMK's key policy can be written to grant exactly the cross-account or cross-region access the pipeline needs.