AWS DevOps Engineer - Professional

After passing the AWS Certified Security – Specialty, I decided to take on the AWS Certified DevOps Engineer – Professional.
On the road to this one, I studied the AWS Certified DevOps Engineer – Professional path on Pluralsight and kept notes on the concepts that finally made things click for me.
Since I’d already covered the fundamentals in earlier certifications, these notes skip the basics and focus on the advanced, exam-critical material.
If they help you too, great – here they are, organised by the exam’s main domains.
Contents
SDLC Automation
CloudFormation
Two helper tools come up repeatedly on the exam:
- cfn-init - reads initialisation metadata from the CloudFormation stack and configures the instance accordingly. It signals CloudFormation when it finishes (or fails), which is why it fits naturally into a stack’s lifecycle.
- cfn-hup - a daemon that watches for changes in resource metadata and runs user-defined actions when a change is detected. Useful for applying updates to running instances without recreating them.
For waiting on instance readiness, remember the pairing: CreationPolicy for EC2 instances, WaitOperation for other resource types.
For command-line credentials, the CLI resolves them in a specific order – I remembered it as CEAW: Command line options → Environment variables → Assume role → Assume role with Web Identity. Knowing this ordering helps with troubleshooting identity questions.
CodeBuild
- To store build artifacts in the region where they were built, use the
artifactssection ofbuildspec.ymlwith a name likebuild-$(AWS_REGION)(environment variables can be referenced inline in the buildspec). - For ECS blue/green deployments, the lifecycle hooks in appspec.yml run in this order:
BeforeInstall→AfterInstall→AllowTestTraffic→BeforeAllowTraffic→AfterAllowTraffic.
CodeDeploy
- Deployment statuses progress through:
Created→Queued→InProgress→Baking→Succeeded/Failed/Stopped→Ready. - For Lambda deployments, the two validation hook names are exactly what they sound like:
BeforeAllowTraffic: LambdaFunctionToValidateBeforeTrafficShiftandAfterAllowTraffic: LambdaFunctionToValidateAfterTrafficShift. The exam loves the naming convention – before traffic shifts vs. after.
Access control with resource tags
A classic exam scenario: restrict access by matching a tag on the principal with a tag on the resource - compare ec2:ResourceTag/CostCenter against ${aws:PrincipalTag/CostCenter}.
CodeCommit
Trigger an event on repository state change: for a referenceCreated event, specify referenceType as a tag - useful for firing a pipeline when a production release is tagged after merging to master.
Elastic Beanstalk and CI
- The Jenkins plugin for Elastic Beanstalk can automate deployments straight from your Jenkins build.
- For Docker on Elastic Beanstalk, deployments are described with
Dockerrun.aws.json.
Artifacts in S3
- CodeArtifact requires bucket versioning to be enabled for artifact storage.
- CodePipeline can store the outputs of deployment actions as artifacts in S3.
Kinesis family cheat sheet
Getting the four Kinesis services mixed up is easy, so here’s the one-liner for each:
| Service | What it does |
|---|---|
| Video Streams | Capture, process, and store media streams for playback, analytics, and ML |
| Data Streams | Collect streaming data at scale for real-time analytics |
| Data Analytics | Analyse data from an input source (often Kinesis Data Streams) |
| Data Firehose | Deliver streaming data to S3, Redshift, Elasticsearch, or Splunk |
Resilient Cloud Solutions
AWS SSO
Usernames work in either UPN or Domain\UserName format, but with a catch: UPN cannot be used with two-step verification or context-aware verification. That limitation shows up in scenario questions.
Auto Scaling lifecycle hooks
Lifecycle hooks pause an instance in Pending:Wait, giving you time to run setup or install software before it goes into service (and Terminating:Wait on the way out).
CodeBuild
The namespaceType option inserts the build ID into the ZIP file or folder name – handy for keeping artifacts from separate builds distinguishable.
Monitoring and Logging
API Gateway + Lambda
- Caching reduces invocations but is not a substitute for provisioned concurrency – provisioned concurrency pre-warms Lambda by reserving simultaneous function instances. A very common trap answer.
- HTTP APIs are cheaper and faster than REST APIs – but with fewer features.
- API Gateway gets permission to invoke a Lambda function from the function’s resource-based policy, which is automatically updated when you add the API as a trigger in the Lambda console.
CloudWatch
- Console sign-in alerts: route the “Management Console sign-in” service event through a CloudWatch Event (EventBridge) rule to SNS.
- Monitoring a .NET app on EC2: CloudWatch → Metrics → AWS Namespaces →
CWAgent, with the SSM Agent installed and theAmazonEC2RoleforSSMrole attached. Configuration lives incommon-config.toml, and the agent is started withamazon-CloudWatch-agent-ctl.ps1. - CloudWatch Logs can be sent to Lambda or streamed to OpenSearch.
SQS
A queue that keeps growing means jobs aren’t completing. Note the trap answer: increasing the visibility timeout won’t fix it – go look at application logs and metrics to find out why messages aren’t being processed.
EMR and OpsCenter
- EMR will remove underutilised instances as part of managed scaling.
- AWS Systems Manager OpsCenter gives you a centralised place to view, investigate, and resolve operational issues.
Security and Compliance
Know which tool covers which job - this maps directly to Security Specialty knowledge, which gave me a head start here:
- Detective – investigations; analyses VPC flow logs, CloudTrail logs, and DNS logs.
- Inspector – discovers workloads (EC2 instances, containers, Lambda functions) and scans them for vulnerabilities and patching gaps.
- GuardDuty – an IDS powered by machine learning that continuously monitors accounts and workloads and delivers detailed security findings.
Other exam-relevant details:
- AWS Config does not terminate non-compliant instances by itself – remediation requires explicit rules/actions.
- Certificate Manager: generated certificates renew automatically; imported ones don’t. Remember which one you chose.
- AWS Organizations: the well-architected approach is multiple accounts arranged under multiple OUs, and CloudFormation StackSets can be granted trusted access to deploy across them.
- Trusted Advisor checks depend on your support plan: Basic/Developer gets 7 core checks, Business/Enterprise gets the full set. The seven core checks are:
- 1 – S3 bucket permissions
- 2 – Security groups (specific ports)
- 3 – IAM use
- 4 – MFA on the root account
- 5 – EBS public snapshots
- 6 – RDS public snapshots
- 7 – Service limits
Those were the notes that mattered most to me. If you’re coming from the Security Specialty like I did, the security domain will feel familiar and the SDLC automation domain is where you’ll spend most of your study time.
Good luck with the exam!
Related Posts
2024-06-11
2024-03-22
2024-03-06