Courseiva

DVA-C02 Development with AWS Services Practice Question

A developer is building a REST API using Amazon API Gateway and AWS Lambda. The API must support CORS to allow requests from a web application hosted on a different domain. The developer has enabled CORS on the API Gateway resource and configured the Lambda function to return the appropriate headers. However, the web application is still receiving CORS errors. What is the most likely cause?

⚠ Common exam trap

Candidates often forget that enabling CORS in the API Gateway console modifies the API definition (by adding/updating the OPTIONS method and mock integration). Like any other method or resource change in API Gateway, these changes are not active on the live stage until the API is explicitly redeployed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The API Gateway stage is not redeployed after enabling CORS.

When you enable CORS in the API Gateway console, it creates or updates the OPTIONS method for the resource. However, these configuration changes do not take effect until the API is redeployed to a stage. If the developer does not redeploy the API, the preflight OPTIONS request will fail (typically returning a 403 or 404), which the browser interprets as a CORS error. Since the developer already configured the Lambda function to return the headers, the missing step is redeploying the API stage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The API Gateway stage is not redeployed after enabling CORS.

    Why this is correct

    While redeploying an API Gateway stage is often necessary for configuration changes to take effect, a CORS error specifically indicates that the required `Access-Control-Allow-Origin` header is missing from the HTTP response. Even if the API Gateway's own CORS configuration is correctly set and deployed, if the integrated backend Lambda function does not explicitly include these headers in its response, the browser will still block the request. Therefore, redeployment alone would not resolve the fundamental issue of missing headers from the Lambda's output.

  • ✗

    The API Gateway CORS configuration is incorrect; the allowed origin should be set to '*'.

    Why it's wrong here

    Setting the `Access-Control-Allow-Origin` header to '*' allows requests from any origin, which can resolve CORS issues but is generally not the most secure practice for production environments. However, the root cause of a CORS error is typically the *absence* of the necessary CORS headers in the response, not merely an overly restrictive origin value. If the Lambda function is not returning these headers at all, simply configuring API Gateway with a wildcard origin will not inject them into the Lambda's response, especially in a proxy integration.

  • ✗

    The web application is not sending the preflight OPTIONS request.

    Why it's wrong here

    Web browsers automatically handle the sending of preflight `OPTIONS` requests for 'complex' cross-origin requests, such as those involving non-standard HTTP methods or custom headers. The web application's code does not explicitly initiate this request. Therefore, if a CORS error occurs, it signifies that the browser *did* attempt the necessary CORS handshake, but the server's response (or lack of appropriate CORS headers) failed to satisfy the browser's security policy, rather than the client failing to send the preflight request.

  • ✗

    The Lambda function is not returning the CORS headers in the response.

    Why it's wrong here

    When an AWS Lambda function is integrated with Amazon API Gateway, particularly in a proxy integration, the Lambda function is fully responsible for constructing the complete HTTP response, including all necessary CORS headers such as `Access-Control-Allow-Origin`, `Access-Control-Allow-Methods`, and `Access-Control-Allow-Headers`. If these critical headers are omitted from the Lambda's response, the browser will block the cross-origin request due to security policies, leading directly to a CORS error. For non-proxy integrations, the Lambda must still provide these headers for API Gateway to map them correctly into the final response.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.