
AWS Certified DevOps Engineer - Professional
The AWS Certified DevOps Engineer - Professional certification validates advanced expertise in provisioning, operating, and managing distributed application systems on AWS. It is designed for DevOps engineers with two or more years of AWS experience who bridge software development and cloud operations. Earning it demonstrates you can deliver secure, compliant, highly available, and scalable systems — and it gives you increased credibility with peers, colleagues, and customers.
497 practice questions · Updated 2026-07-30
DOP-C02 Curriculum
Every domain, objective, and concept the DOP-C02 exam measures.
- SDLC phases and models
- CI/CD pipeline fundamentals
- Pipeline deployment patterns for single-account environments
- Pipeline deployment patterns for multi-account environments
- Configuring code repositories
- Configuring image repositories
- Configuring artifact repositories
- Version control integration with application environments
- Setting up build processes with AWS CodeBuild
- Managing build and deployment secrets with AWS Secrets Manager
- Managing build and deployment secrets with AWS Systems Manager Parameter Store
- Determining deployment strategies
- Implementing deployment strategies with AWS CodeDeploy
- Types of automated tests
- Test placement in CI/CD pipeline
- Triggering tests on pull requests and merges
- Running load and stress tests
- Application testing at scale
- Measuring application health via exit codes
- Automating unit tests and code coverage
- Invoking AWS services for testing in pipelines
- Artifact use cases
- Secure artifact management
- Artifact generation methods
- Artifact lifecycle considerations
- AWS CodeArtifact configuration
- Amazon S3 artifact storage
- Amazon ECR configuration
- CodeBuild artifact generation
- Lambda artifact generation
- EC2 Image Builder automation
- Container image build automation
- Deployment methodologies for EC2
- Deployment methodologies for ECS
- Deployment methodologies for EKS
- Deployment methodologies for Lambda
- Application storage patterns
- Mutable vs immutable deployment patterns
- Tools for distributing code
- Configuring IAM for artifact repositories
- Configuring deployment agents
- Troubleshooting deployment issues
- Blue/green deployment method
- Canary deployment method
- IaC options and tools for AWS
- Change management for IaC
- Configuration management services and strategies
- Composing and deploying IaC templates
- CloudFormation StackSets for multi-account/region
- Selecting configuration management services
- Reusable IaC patterns and governance
- AWS account structures and best practices
- AWS Organizations for account management
- AWS Control Tower for account provisioning
- Automating account provisioning and configuration
- IAM for multi-account access
- Service Control Policies (SCPs)
- Governance and security controls at scale
- AWS Config for compliance and auditing
- AWS Security Hub for centralized security
- Amazon GuardDuty for threat detection
- Amazon Detective for security investigation
- AWS Service Catalog for standardized provisioning
- AWS Systems Manager inventory
- AWS Systems Manager patch management
- AWS Config for compliance
- AWS Lambda automation with SDKs
- AWS Step Functions orchestration
- AWS OpsWorks configuration management
- Systems Manager State Manager
- Systems Manager compliance reporting
- Automation with AWS software-defined infrastructure
- Multi-AZ and multi-Region deployment patterns
- SLA interpretation and business requirement translation
- Replication and failover for stateful services
- High availability techniques
- Single point of failure identification and remediation
- Cross-Region service configuration
- Load balancing for cross-AZ traffic
- Application configuration for multi-AZ and multi-Region
- Scaling metrics selection
- Scaling issue identification and remediation
- Loosely coupled architectures
- Distributed architecture patterns
- Serverless architecture fundamentals
- Auto scaling implementation
- Load balancing solutions
- Caching strategies
- Container platform deployment
- Multi-Region deployment for global scalability
- API Gateway configuration for serverless
- Lambda scaling and configuration
- Fargate serverless containers
- RTO and RPO definitions
- Disaster recovery strategies
- AWS Backup and recovery services
- Recovery procedures
- Testing failover for Multi-AZ workloads
- Testing failover for multi-Region workloads
- Cross-Region backup strategies
- Load balancer backend failure recovery
- CloudWatch metrics fundamentals
- Real-time log ingestion
- Encryption for logs and metrics
- IAM for log collection
- Secure log storage and management
- Metric filters
- CloudWatch metric streams
- Custom metrics collection
- Log storage lifecycle management
- CloudWatch log subscriptions
- Log search with filter and pattern syntax
- CloudWatch Logs Insights
- KMS encryption for log data
- CloudWatch anomaly detection alarms
- Common CloudWatch metrics and logs
- Amazon Inspector assessment templates
- AWS Config rules
- AWS CloudTrail log events
- Building CloudWatch dashboards
- Amazon QuickSight visualizations
- Associating CloudWatch alarms with metrics
- Configuring AWS X-Ray for services
- Analyzing real-time log streams with Kinesis
- Analyzing logs with Athena
- Analyzing logs with CloudWatch Logs Insights
- Event-driven asynchronous design patterns
- Auto scaling capabilities across AWS services
- Alert notification and action capabilities
- Health check capabilities in AWS services
- Configuring EC2 Auto Scaling groups
- Configuring RDS storage auto scaling
- Configuring DynamoDB auto scaling
- Configuring ECS capacity providers
- Configuring EKS autoscalers
- Creating CloudWatch custom metrics and metric filters
- Creating CloudWatch alarms and notifications
- Configuring S3 events for log processing
- Configuring EventBridge event patterns
- Installing and configuring agents on EC2
- Configuring AWS Config rules for remediation
- Configuring Route 53 health checks
- Configuring ALB target group health checks
- AWS event sources
- Event-driven architecture patterns
- Integrating AWS event sources
- Event processing workflows
- Fleet management services overview
- AWS Systems Manager capabilities
- AWS Auto Scaling for configuration changes
- Configuration management with AWS Config
- Applying configuration changes to systems
- Modifying infrastructure configurations in response to events
- Remediating non-desired system state
- AWS metrics and logging services
- AWS service health services
- Root cause analysis
- Analyzing failed deployments with CI/CD and IaC
- CloudWatch synthetic monitoring for deployments
- Analyzing incidents with auto scaling
- Analyzing incidents with Amazon ECS
- Analyzing incidents with Amazon EKS
- IAM entities for human and machine access
- Identity-based vs. resource-based policies
- Session policies
- Identity federation with IAM Identity Center
- IAM permissions boundaries
- Organizational SCPs
- Least privilege policy design
- Role-based access control (RBAC)
- Attribute-based access control (ABAC)
- Automating credential rotation for machine identities
- MFA enforcement for human and machine identities
- AWS Security Token Service (STS) for temporary credentials
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for DOP-C02, so none is invented.