DVA-C02 Development with AWS Services Practice Question
A developer is deploying a microservices architecture on Amazon ECS with Fargate. The services need to communicate with each other using service discovery. The developer wants to use AWS Cloud Map for service discovery. Which configuration is required for the services to register and discover each other?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Cloud Map namespace and service; then configure ECS tasks to register with the service.
AWS Cloud Map requires a namespace (either HTTP or DNS) and a service resource. ECS tasks configured with service discovery can register themselves with the Cloud Map service, and other tasks can discover them via DNS queries or the Cloud Map API. Option A is incorrect because an Application Load Balancer is used for load balancing traffic, not for service discovery. Option B is incorrect because VPC endpoints provide private connectivity to AWS services, not service registration and discovery. Option C is incorrect because Security Groups control network traffic but do not facilitate service discovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create an Application Load Balancer and register each service as a target group.
Why it's wrong here
An Application Load Balancer (ALB) is designed to distribute incoming application traffic across multiple targets, such as EC2 instances or containers, based on various routing rules. While ALBs are crucial for external client access and load distribution, they do not inherently provide a mechanism for internal microservices to dynamically discover each other's network locations. Registering services as target groups only tells the ALB where to send traffic it receives, not how other services can find them.
- ✗
Create a VPC endpoint for each service.
Why it's wrong here
VPC endpoints enable private connectivity from your VPC to supported AWS services or VPC endpoint services powered by AWS PrivateLink, without requiring an internet gateway, NAT device, VPN connection, or AWS Direct Connect. These endpoints secure traffic by keeping it within the AWS network, but they are not a service discovery mechanism. They facilitate secure access to a known service endpoint, rather than helping services locate other dynamically provisioned services.
- ✗
Configure Security Groups to allow traffic between services.
Why it's wrong here
Security Groups act as virtual firewalls for your instances to control inbound and outbound traffic at the instance level. They are fundamental for network security, defining which IP addresses and ports are allowed to communicate, but they do not offer any functionality for service discovery. Configuring Security Groups only permits communication once a service's network location is already known; it doesn't help one service find another's dynamic IP address or port.
- ✓
Create a Cloud Map namespace and service; then configure ECS tasks to register with the service.
Why this is correct
AWS Cloud Map is a cloud service discovery solution that allows you to register any application resource, such as microservices, and then define custom names for them. It provides a centralized registry that services can query using either DNS queries or an API to discover the network locations (IP addresses and ports) of other services. By configuring ECS tasks to register with a Cloud Map service, new instances automatically become discoverable, which is essential for the dynamic and ephemeral nature of microservices.
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.