DVA-C02 Deployment Practice Question
A developer is deploying a static website to Amazon S3. The website uses client-side JavaScript to make API calls to an AWS Lambda function via Amazon API Gateway. The developer wants to enable cross-origin resource sharing (CORS) on the API Gateway to allow the S3 website to make requests. After enabling CORS on the API Gateway and redeploying the API, the browser still reports CORS errors. The developer checks the API Gateway configuration and sees that the OPTIONS method is not defined. The developer has already enabled CORS via the API Gateway console, which should have created the OPTIONS method. However, it did not appear. What should the developer do to resolve the issue?
⚠ Common exam trap
DVA-C02 often tests the misconception that enabling CORS in the console is always sufficient, when in fact the OPTIONS method must exist and return the correct headers for the preflight to succeed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Manually add an OPTIONS method to the API Gateway resource and configure the CORS headers in the integration response.
When API Gateway's CORS console feature fails to create the OPTIONS method (often due to permissions, resource policy conflicts, or the resource already having a mock integration), the developer must manually create an OPTIONS method on the resource, set the integration type to MOCK, and configure the integration response with the Access-Control-Allow-Origin, Access-Control-Allow-Headers, and Access-Control-Allow-Methods headers. The browser's preflight request (OPTIONS) must receive those headers before the actual GET/POST is sent, so a missing OPTIONS method guarantees CORS failure regardless of what the backend returns.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Update the JavaScript in the website to use a different HTTP method.
Why it's wrong here
Changing the HTTP method (e.g., from POST to GET) does not address the fundamental cross-origin security restriction enforced by web browsers. CORS errors occur when the browser's same-origin policy blocks a request to a different origin unless the server explicitly grants permission via specific HTTP response headers, regardless of the method used for the actual request.
- ✗
Update the S3 bucket policy to allow cross-origin requests from any origin.
Why it's wrong here
An S3 bucket policy defines access permissions for objects within an S3 bucket, controlling who can read, write, or delete them. It has no bearing on the Cross-Origin Resource Sharing (CORS) configuration of an API Gateway endpoint, which is a distinct service responsible for managing HTTP requests and responses to backend resources like Lambda functions.
- ✗
Modify the Lambda function to return CORS headers in its response.
Why it's wrong here
While a Lambda function can include CORS headers in its response for the actual request, the browser's preflight OPTIONS request, which precedes 'non-simple' cross-origin requests, must be handled directly by API Gateway. If API Gateway does not respond to the OPTIONS method with the necessary Access-Control-Allow-Origin header, the browser will block the request before it ever reaches the Lambda function.
- ✓
Manually add an OPTIONS method to the API Gateway resource and configure the CORS headers in the integration response.
Why this is correct
To resolve CORS issues, API Gateway must be explicitly configured to handle the browser's preflight OPTIONS request. This involves manually adding an OPTIONS method to the API Gateway resource and setting up a mock integration response that includes the required Access-Control-Allow-Origin, Access-Control-Allow-Methods, and Access-Control-Allow-Headers in its headers, allowing the browser to proceed with the actual request.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.