Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
(What is a patch baseline attached to if it is not defined in Patch Manager?)
If a patch baseline is not explicitly defined in Patch Manager, it is attached to the default patch group. This default group applies a preconfigured baseline with AWS-recommended patches, ensuring basic compliance for instances without custom baselines. The WGU Cloud Deployment and Operations Study Guide (Section 5.2, Patch Manager) states, 'If no custom patch baseline is defined, instances are associated with the default patch group, which uses AWS-provided baseline settings for automatic patch approval.' Options A, C, and D are not valid attachments for patch baselines.
(What is used to change stacks across multiple accounts and Regions in a single operation?)
Comprehensive and Detailed Explanation From Exact Extract:
StackSets are used to change stacks across multiple AWS accounts and regions in a single operation, enabling centralized management of infrastructure deployments. StackSets allow administrators to create, update, or delete stacks consistently across specified accounts and regions. The WGU Cloud Deployment and Operations Study Guide (Section 5.4, StackSets) states, 'StackSets provide the capability to manage and update stacks across multiple accounts and regions with a single operation, streamlining multi-region deployments.' StackInstance, nested stacks, and stack policies do not support this multi-account, multi-region functionality.
(A company is using Route 53 for Domain Name System (DNS) hosting. The company requires a zone that should only be accessible from instances in a Virtual Private Cloud (VPC). Which type of hosted zone should be used?)
A Private Hosted Zone in Amazon Route 53 should be used to restrict DNS resolution to instances within a Virtual Private Cloud (VPC), ensuring that the zone is only accessible internally. This isolates DNS services from public internet access. The WGU Cloud Deployment and Operations Study Guide (Section 3.1, Route 53 Hosted Zones) states, 'A Private Hosted Zone in Route 53 limits DNS resolution to resources within a specified VPC, preventing external access and enhancing security for internal services.' Public Hosted Zones, DNS Zones, and Lightsail DNS Zones do not provide this VPC-specific restriction.
(A company uses SQS and EC2 to convert videos uploaded by users. In the evenings, videos take several hours to convert when they normally take minutes. The user base is expected to grow a hundredfold in the next 12 months. Which solution should be used to reduce the conversion delays?)
To reduce conversion delays caused by increased demand, the company should configure a CloudWatch alarm to scale the EC2 fleet based on the SQS queue length. This auto-scaling approach dynamically adjusts the number of EC2 instances to handle the workload, especially during peak evening hours and anticipated growth. The WGU Cloud Deployment and Operations Study Guide (Section 3.3, Auto Scaling and SQS) explains, 'Auto Scaling can be triggered by a CloudWatch alarm monitoring SQS queue depth, ensuring the EC2 fleet scales out to process video conversion tasks efficiently as the queue length increases.' Spot instances, dead-letter queues, and instance type upgrades do not directly address dynamic scaling needs.
(An administrator needs to implement Amazon Route 53 multivalue routing policy. The operator must ensure that Route 53 will respond to incoming requests with the maximum allowed number of records. How many records should be created?)
The multivalue routing policy in Amazon Route 53 allows up to 8 healthy records to be returned in response to DNS queries, enabling load balancing across multiple resources. To ensure the maximum allowed number of records is utilized, the administrator should create 8 records. The WGU Cloud Deployment and Operations Study Guide (Section 3.1, Route 53 Routing Policies) specifies, 'Multivalue answer routing supports up to 8 healthy resource record sets per response, requiring the creation of 8 records to maximize the policy's capability.' Options A, C, and D exceed or fall short of this limit.
67 questions covering all exam domains, starting from $20
Exam domains verified against: Official WGU Cloud-Deployment-and-Operations exam guide, last checked August 2026.
Deploy and manage cloud services while ensuring system stability. Understand scalability requirements, backup strategies, and recovery workflows to maintain reliable cloud environments. Handle provisioning, monitoring, and connectivity tasks essential for supporting production cloud operations.
Use automation tools to streamline cloud resource creation and management throughout their lifecycle. Apply automation methods to provisioning processes and routine maintenance tasks to keep cloud operations efficient and reduce manual overhead.
Establish and manage network connectivity within AWS environments. Configure, troubleshoot, and resolve connectivity issues to ensure reliable communication between cloud systems and services.
Identify the effective balance between cost and performance in AWS service selection. Choose appropriate resources and configurations that support efficient operations without unnecessary expenses.
Apply AWS security services to protect workloads and infrastructure. Demonstrate understanding of compliance requirements and implement security controls that meet organizational and industry standards.
Apply AWS capabilities for scalability and elasticity to handle varying workloads. Implement robust backup strategies to maintain service continuity and protect critical data for recovery purposes.
Sample question from this domain above: Q4
Use AWS monitoring and logging services to detect operational issues. Analyze system outputs, identify problems, and implement corrective actions to maintain smooth cloud operations.
Common questions about the exam itself