Cert Notes/ Commute Study Notes
Roadmap
KOEN
CLF-C02 · FoundationalCloud Practitioner - Foundational
DVA-C02 · AssociateDeveloper - Associate
SAA-C03 · AssociateSolutions Architect - Associate
SOA-C02 · AssociateCloudOps Engineer - Associate
SAP-C02 · ProfessionalSolutions Architect - Professional
DOP-C02 · ProfessionalDevOps Engineer - Professional
  • Week 1
    • 1.DevOps as an Operating Model: The Five Axes of CALMS and the Truth DORA Proved Through Measurement
    • 2.Well-Architected Framework: Rereading It Through the Six Lenses of DevOps
    • 3.The AWS DevOps Tool Map: The Code* Series and the Real Picture Beyond It
    • 4.Multi-Account Strategy: The Real Picture of Organizations, Control Tower, and IAM Identity Center
    • 5.Week 1 Wrap-Up: Cementing the DevOps Thinking Frame with Scenarios
  • Week 2
    • 1.CodeCommit Deep Dive: What Changes When Git Hosting is Integrated with IAM
    • 2.GitHub Actions ↔ AWS OIDC: Eliminating Static Keys Permanently Through Federation
    • 3.CodeArtifact and Supply Chain Security: When Dependencies Become Attack Surface
    • 4.DevSecOps Shift Left: Automated Security Gates Built with Code Signing, CodeGuru, and Inspector
    • 5.Week 2 Synthesis: DevSecOps Thinking Framework From Source Control to Code Signing
  • Week 3
    • 1.The Real Meaning of buildspec.yml: The Moment a Pipeline Specification Becomes Code
    • 2.The Physics of Build Speed: Trade-offs Among Cache, Parallelism, and Compute
    • 3.Design Principles of Secret Management: The Criteria That Separate Secrets Manager from Parameter Store
    • 4.VPC CodeBuild, Custom Images, ARM/Graviton: Expanding the Boundary of the Build Environment
    • 5.Week 3 Review: Integrated CodeBuild Scenarios and Practical Judgment
  • Week 4
    • 1.In-place vs Blue/Green, AppSpec: The Physics of Deployment Strategies
    • 2.EC2/On-Prem Deployment + Auto Scaling Integration: The Intersection of Instance Lifecycle and Deployment
    • 3.Lambda Deployment: Linear/Canary/AllAtOnce and the Math of Aliases
    • 4.ECS Blue/Green + CodeDeploy Traffic Shift: The Logic of Two Target Groups
    • 5.Week 4 Review: Integrated Scenarios in CodeDeploy Deployment Strategies
  • Week 5
    • 1.CodePipeline Architecture: Understanding Why Stage, Action, and Artifact Were Designed This Way
    • 2.Multi-Account Pipeline: Why Cross-Account IAM Is Required
    • 3.Action Providers: How Lambda, Step Functions, and Manual Approval Extend the Pipeline
    • 4.Dynamic Pipeline: V2 Variable System, Trigger Filters, and Execution Mode Design
    • 5.Week 5 Review: CodePipeline Integration Scenarios
  • Week 6
    • 1.ECR: Solving the Problems that Container Image Registries Must Solve
    • 2.ECS Automatic Deployment: From Task Definition Update to Auto Scaling
    • 3.EKS CI/CD: Why GitOps Was Born, and How ArgoCD and Flux Changed Kubernetes
    • 4.App Runner and ECS Copilot: The Spectrum of Container Operations Abstraction
    • 5.Week 6 Review + 12 Scenario Practice Problems
  • Week 7
    • 1.Serverless CI/CD: Lambda, SAM, and Canary Deployments
    • 2.Lambda Permissions, Layers, and Container Images
    • 3.API Gateway and Serverless Integrations
    • 4.X-Ray and CloudWatch for Serverless Observability
    • 5.Week 7 Review: Serverless CI/CD Summary
  • Week 8
    • 1.CloudFormation Advanced: Nested·Cross-Stack and the Deep Story of Modularization
    • 2.StackSets: The Deep Story of Deploying IaC to Thousands of Accounts
    • 3.Custom Resource·Hooks·Change Set: CloudFormation's Extension and Validation Mechanisms
    • 4.CDK·CDK Pipelines·Terraform: Deep Comparison of Modern IaC Tools and Self-Evolving Pipelines
    • 5.Week 8 Integrated Scenario: IaC Tools Meeting Within One Incident
  • Week 9
    • 1.Systems Manager: Run Command·Session Manager·Patch Manager's Deep Story
    • 2.State Manager·Inventory·Compliance: The Abstraction of Desired State
    • 3.AppConfig: Feature Flags and Progressive Deployment
    • 4.Secrets Manager and Parameter Store: Lifecycle and Rotation
    • 5.Week 9 Integrated Scenario: Configuration Management Across Fleet Scale
  • Week 10
    • 1.CloudWatch Metrics: Time Series, Dimensions, and Alarm Evaluation Model Deep Dive
    • 2.CloudWatch Logs: Groups, Streams, Subscriptions, and Insights Deep Dive
    • 3.Container Insights·Lambda Insights·EMF: Workload-Specific Observability Deep Dive
    • 4.Synthetics·RUM·Evidently: Three Lenses Measuring User Experience
    • 5.Week 10 Synthesis: Tying Observability into Incidents
  • Week 11
    • 1.X-Ray: Causal Graphs of Distributed Tracing and the Deep Story of the Trace Model
    • 2.X-Ray Sampling: Reservoir Algorithm and the Economics of Tracing at Operational Scale
    • 3.ADOT: The Deep Story of OpenTelemetry Ending the Tracing Tool Wars
    • 4.OpenSearch · AMP · AMG: The Two Worlds of Inverted Indices and Time-Series Databases
    • 5.Week 11 Synthesis: Real-World Decision-Making in Tracing and Telemetry Observability
  • Week 12
    • 1.EventBridge: Event Bus Routing Model and the Nervous System of Asynchronous Automation
    • 2.Systems Manager Automation: Codifying Runbooks and the Operator's Disappearance
    • 3.Auto-Healing and Control Theory: When Systems Repair Themselves
    • 4.ChatOps and Incident Manager: The Coordination Layer
    • 5.Week 12 Synthesis: The Five-Stage Pipeline and Decision Trees
  • Week 13
    • 1.Multi-AZ High Availability: Distributed Principles Underlying Replication Consistency, Quorum, and Failover
    • 2.Multi-Region Resilience: Distributed Principles of DNS Routing, Global Replication, and Encryption Boundaries
    • 3.Four DR Strategies: Tradeoffs of RTO, RPO, Cost and Their Economics
    • 4.Validating Resilience: Chaos Engineering with Resilience Hub and FIS
    • 5.Week 13 Comprehensive Review: Tying Together High Availability, Multi-Region, DR, and Resilience Validation
  • Week 14
    • 1.GuardDuty and Automatic Isolation: Signal Processing, Statistics, and Auto-Response Principles
    • 2.Security Hub: SIEM Principles of Normalization, Aggregation, and Auto-Remediation
    • 3.AWS Config: Closed-Loop Control Principles for State Recording, Drift Detection, and Automated Remediation
    • 4.Audit Manager, Macie, Inspector: Evidence Automation, Data Classification, Vulnerability Scanning Principles
    • 5.Week 14 Comprehensive Review: The Big Picture of Security Automation Stack and Practical Scenarios
  • Week 15
    • 1.Multi-Account Enterprise CI/CD: Governance and Platform Engineering Principles for 50+ Accounts
    • 2.Hybrid CI/CD: Bridging On-Premises and AWS into One Deployment Model
    • 3.Large-Scale ECS/EKS Operations: Scheduling, GitOps, Cost Principles for 100+ Microservices
    • 4.Serverless Large-Scale Incident Auto-Response: Recovery Without People, Safety Rails
    • 5.Week 15 Synthesis: Reading Signals and Trade-Off Judgment
  • Week 16
    • 1.Domain 1+2 Integrated Review: SDLC Automation and IaC as One Thread
    • 2.Domain 3+4 Integrated: Resilience and Observability as Failure Prevention
    • 3.Incident Response and Security Compliance Woven Through Everything
    • 4.Full Exam Scenarios (Domains 1-6 Integrated)
    • 5.D-Day Exam Prep: Mental State, Time Management, Last-Minute Do's and Don'ts
SCS-C03 · SpecialtySecurity - Specialty
MLA-C01 · AssociateMachine Learning Engineer - Associate
AIF-C01 · FoundationalAI Practitioner - Foundational
DEA-C01 · AssociateData Engineer - Associate
MLS-C01 · SpecialtyMachine Learning - Specialty
← DOP-C02/Week 1/Day 5
DOP-C02· ProWeek 1 · Day 5~45 min read

Day 5 - Week 1 Wrap-Up: Cementing the DevOps Thinking Frame with Scenarios

Week 1 was the week of abstractions. The five axes of CALMS, the four DORA metrics, the six pillars of Well-Architected, the AWS DevOps tool map, and multi-account governance. Taken separately, each is a massive book of its own, but within DOP-C02 scenarios, two or three of them always show up bundled together. Accelerating from "one deployment per quarter → one per day" is not solved by just installing Automation tooling — blast radius, account separation, signature verification, rollback automation, and observability all get pulled up along with it.

Today we cement that bundled problem-solving with 12 scenarios. Each question was built by weaving together two or three concepts from Days 1-4, and the explanations are written assuming you'll face exactly the same form of question in the exam room. In the end, what Week 1 wants to teach is one sentence: "DevOps is a system for flowing code quickly and safely, and AWS's tools, account structures, and metrics are the parts for translating that system into code."

One-Page Compact — Week 1 Essentials

CALMS 5-Axis Diagnostic Table (the weakest axis is your next priority)

AxisDiagnostic questionSymptoms when weakTop-priority AWS tools
CultureWho gets blamed during incidents?Incident cover-ups, repeated identical incidentsBlameless COE, Incident Manager, Chatbot
AutomationHow many manual steps remain?Frequency stagnation, MTTR explosion, human errorCodePipeline + CodeBuild + CodeDeploy + SSM Automation
LeanHow many days until PR merge?WIP accumulation, runaway lead timeTrunk-based dev, AppConfig feature flags
MeasurementHow do you know a change's effect?"Gut feel" decisions, KPI gamingCloudWatch Metrics + EMF + DORA dashboard
SharingDo one team's insights flow onward?Same mistakes recur in other teamsService Catalog, Proton, Wiki

DORA 4 Metrics → Prescription Mapping

MetricSignal of weaknessFirst-line prescription (AWS)
Deployment Frequency ↓Once per quarter, once per monthCodePipeline automation + small batches + AppConfig flags
Lead Time ↑Commit→prod 2 weeks+Remove Manual Approval + CodeBuild cache + monorepo split
Change Failure Rate ↑30%+ incident rateCanary + CloudWatch alarm auto-rollback + pre-deploy hooks
MTTR ↑Days after an incidentEventBridge → SSM Runbook + Incident Manager

W-AF 6 Pillars → Scenario Keywords

PillarScenario keywordsDevOps perspective
Operational Excellence"automation," "observability," "runbooks"CALMS's A + M
Security"least privilege," "shift-left," "auditing"DevSecOps
Reliability"RTO/RPO," "Multi-AZ/Region," "self-healing"Auto-rollback + chaos
Performance"latency," "throughput"Profiler, instance types
Cost"waste," "budget," "Spot"Right-sizing, autoscale
Sustainability"carbon," "renewable energy"Region selection, ARM/Graviton

Standard Multi-Account Structure

  • OUs: Security / Infrastructure / Workloads(Prod/Non-Prod) / Sandbox
  • The 3 standard accounts: Management (billing+SCP), Log Archive (immutable), Audit (SecurityHub/GuardDuty aggregation)
  • SCP: deny-only guardrail (not a permission grant). Applies even to root. Excluding global services via NotAction is mandatory.
  • Cross-account: STS AssumeRole + ExternalId / resource policies / RAM
  • CI/CD: Shared Services (Hub) → environment account (Spoke) deployment via AssumeRole

The 4-Step Flow for Solving Week 1 Scenarios

In the exam room, consciously walk through these four steps.

  1. Classify the W-AF Pillar: "Which pillar is this scenario asking about?" (Reliability? Cost? Security?)
  2. Diagnose with CALMS/DORA: Which axis is weak and which metric is broken?
  3. Shortlist AWS tool candidates: 3-4 candidates from the per-domain tool map
  4. Pick the single answer via trade-offs: priorities, blast radius, cost, operational burden

🎯 Scenario: A report comes in that "there are so many Slack alerts they're being ignored." What is the problem? Not the tooling — it's a broken Measurement definition. Making every metric an alert without SLOs/SLIs produced alert fatigue. The answer is not adding tools but defining SLOs + reducing noise with Composite Alarms + Error Budget-based classification. A case where CALMS's M axis was quantitatively satisfied but qualitatively collapsed.


📝 Comprehensive Scenarios (12 items)

📝 Practice Questions

Click a choice to reveal the answer and explanation.

Question 1

A large fintech is pushing to accelerate from "one deployment per quarter → one per week." Current state: dev/staging/prod separated only by VPC in a single AWS account, humans deploying directly from the console with no CodePipeline, and an average of 8 hours to recover when incidents occur. Which CALMS diagnosis + prioritized prescription is most appropriate?

Question 2

A company deploys identical workloads to us-east-1 and eu-west-1. Its users are global and GDPR compliance is mandatory. Operating in a single account, it is highly concerned about blast radius during incidents. After adopting Organizations, which OU structure is most appropriate?

Question 3

A company is adopting the SaaS monitoring tool Datadog. Datadog needs access to metrics in our AWS account. From a security + automation standpoint, what is the most appropriate setup?

Question 4

A company reported this problem: "deployment frequency is Elite-level at 5 per day, but Change Failure Rate is 40%." Which of the following actions is most effective?

Question 5

A global company deploying across 5 regions wants to manage all accounts' CloudTrail logs with centralization + tamper prevention. What is the most appropriate architecture?

Question 6

A company is building CI/CD in a multi-account environment. CodePipeline lives in the Shared Services account, and the deployment target is the Prod account. It must deploy to an ECS service in the Prod account and uses artifacts encrypted with a KMS key. What is the most accurate permission setup?

Question 7

A company wants to enforce "no EC2/RDS/S3 operations in any region other than ap-northeast-2 and us-east-1" across all accounts. What must you absolutely watch out for when writing the SCP?

Question 8

A company runs an EKS cluster in the Prod account and deploys GitOps-style via ArgoCD. In a single-cluster scenario, where is the most appropriate place to put ArgoCD?

Question 9

A company received the requirement "visualize DORA metrics on a dashboard." What is the most appropriate data pipeline in an AWS environment?

Question 10

A company wants to enforce an automatic "read-only mode during specific hours (weekends, 0-6 a.m.)" on the Production account. What is the most appropriate mechanism?

Question 11

Which organizational model most accurately implements Werner Vogels's "You Build It, You Run It" principle in an AWS environment?

Question 12

A company received the demand: "one team ran up \$30,000 in a month in a sandbox account. Make sure it never happens again." What is the most effective combination of actions?

Week 1 Close — The Bridge to Next Week

The five things we've covered so far — the DevOps operating model, CALMS/DORA, W-AF, the tool map, and multi-account — form the background for all of DOP-C02 Domains 1-6. Starting next week we dive into Domain 1 (SDLC) in earnest, and every CodePipeline / CodeBuild / CodeDeploy scenario you'll meet there is solved on top of these two questions:

  1. "How quickly and safely will we flow this change through?" (DORA)
  2. "When an incident happens, within how narrow a scope will it stop?" (blast radius + multi-account)

Keep these two questions in mind, and next week's topics — trunk-based development, OIDC federation, CodeArtifact, code signing — will start to look not like "tools to memorize separately" but like "different parts of the same thinking frame."

PreviousMulti-Account Strategy: The Real Picture of Organizations, Control Tower, and IAM Identity CenterWeek 1 · Day 4Next CodeCommit Deep Dive: What Changes When Git Hosting is Integrated with IAMWeek 2 · Day 1

On this page

  • One-Page Compact — Week 1 Essentials
  • CALMS 5-Axis Diagnostic Table (the weakest axis is your next priority)
  • DORA 4 Metrics → Prescription Mapping
  • W-AF 6 Pillars → Scenario Keywords
  • Standard Multi-Account Structure
  • The 4-Step Flow for Solving Week 1 Scenarios
  • Comprehensive Scenarios (12 items)
  • Week 1 Close — The Bridge to Next Week