DVA-C02 Cross-Origin Resource Sharing (CORS) Practice Question
A developer is configuring an Amazon S3 bucket for static website hosting. The website includes JavaScript that makes AJAX calls to an API Gateway endpoint. Which TWO actions should the developer take to allow cross-origin requests?
⚠ Common exam trap
The trap is to think that enabling CORS on API Gateway alone is sufficient or that the S3 bucket policy/CORS is involved. In cross-origin calls to an API Gateway endpoint from an S3-hosted site, the browser enforces CORS based on the API Gateway/Lambda response; for Lambda proxy integrations, both the API Gateway CORS setting and the Lambda response headers are required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable CORS on the API Gateway API.
The API Gateway API must have CORS enabled to accept cross-origin requests from the S3-hosted static website. For an API Gateway endpoint backed by a Lambda proxy integration, enabling CORS in API Gateway alone is not enough — the Lambda function must also include the appropriate CORS headers (such as Access-Control-Allow-Origin) in its response. Therefore, the developer should both enable CORS on the API and modify the Lambda function to return CORS headers.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Amazon CloudFront to serve the website and set CORS headers.
Why it's wrong here
CloudFront can set headers, but it is not the action required in this scenario for an API Gateway endpoint.
- ✗
Add a CORS configuration to the S3 bucket.
Why it's wrong here
S3 bucket CORS governs access to objects in the bucket when accessed cross-origin, not cross-origin calls from the site to API Gateway.
- ✓
Enable CORS on the API Gateway API.
Why this is correct
Correct: Enabling CORS on API Gateway configures the API to respond to preflight OPTIONS requests with the necessary CORS headers.
- ✗
Configure the S3 bucket policy to allow cross-origin access.
Why it's wrong here
An S3 bucket policy controls access to S3 content; it does not enable cross-origin requests from the website to API Gateway.
- ✓
Modify the Lambda function to include CORS headers in the response.
Why this is correct
Correct: For a Lambda proxy integration, the Lambda function must include Access-Control-Allow-Origin and other CORS headers in its response.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This DVA-C02 question is part of Courseiva's 1,135-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.