For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 7Question 08
    Hard1 markMultiple Choice
    Domain 2.1: Deployment StrategyEKSCI/CDSecrets Manager

    AWS SAP-C02 · Question 08 · Domain 2.1: Deployment Strategy

    A company is designing a CI/CD pipeline for a microservices application deployed on Amazon EKS. The pipeline must support automated canary deployments, rollback capabilities, and integration with AWS Key Management Service (KMS) for secret management. Which combination of AWS services and tools should the architect use? (Select TWO)

    Answer options:

    A.

    Use AWS CodeDeploy to manage canary deployments directly to EKS pods.

    B.

    Use AWS CodePipeline with AWS CodeBuild for CI, and integrate with an open-source tool like ArgoCD or Flux for GitOps-based EKS deployments.

    C.

    Store secrets in AWS Systems Manager Parameter Store and mount them using EFS.

    D.

    Store secrets in AWS Secrets Manager encrypted with KMS, and use the Secrets Store CSI Driver to mount them in EKS pods.

    E.

    Use AWS Elastic Beanstalk to manage the EKS cluster deployments.

    F.

    Use AWS CloudFormation to perform canary deployments of Kubernetes manifests.

    How to approach this question

    Identify the best practices for EKS deployments and secret management.

    Full Answer

    For EKS, GitOps tools (ArgoCD/Flux) are preferred for complex deployments. The Secrets Store CSI Driver securely integrates AWS Secrets Manager with Kubernetes pods.

    Common mistakes

    Selecting CodeDeploy, assuming it supports EKS natively.
    Question 07All questionsQuestion 09

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 7

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A global enterprise is designing a multi-region network architecture connecting 50 AWS accounts a...HardQ02A company is migrating its hybrid network to AWS. They have two 10 Gbps AWS Direct Connect connec...HardQ03An enterprise has 100 AWS accounts in AWS Organizations. The security team mandates that all Amaz...MediumQ04A financial company requires that all EBS volumes, S3 buckets, and RDS databases be encrypted usi...EasyQ05An enterprise is designing a disaster recovery strategy for a critical application running on Ama...Hard
    View all 75 questions →