Courseiva
Deployment →mediumMultiple Choice

DVA-C02 Deployment Practice Question

A developer is deploying a static website to Amazon S3. The website uses client-side JavaScript to make API calls to an AWS Lambda function via Amazon API Gateway. The developer wants to enable cross-origin resource sharing (CORS) on the API Gateway to allow the S3 website to make requests. After enabling CORS on the API Gateway and redeploying the API, the browser still reports CORS errors. The developer checks the API Gateway configuration and sees that the OPTIONS method is not defined. The developer has already enabled CORS via the API Gateway console, which should have created the OPTIONS method. However, it did not appear. What should the developer do to resolve the issue?

⚠ Common exam trap

DVA-C02 often tests the misconception that enabling CORS in the console is always sufficient, when in fact the OPTIONS method must exist and return the correct headers for the preflight to succeed.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Manually add an OPTIONS method to the API Gateway resource and configure the CORS headers in the integration response.

When API Gateway's CORS console feature fails to create the OPTIONS method (often due to permissions, resource policy conflicts, or the resource already having a mock integration), the developer must manually create an OPTIONS method on the resource, set the integration type to MOCK, and configure the integration response with the Access-Control-Allow-Origin, Access-Control-Allow-Headers, and Access-Control-Allow-Methods headers. The browser's preflight request (OPTIONS) must receive those headers before the actual GET/POST is sent, so a missing OPTIONS method guarantees CORS failure regardless of what the backend returns.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Update the JavaScript in the website to use a different HTTP method.

    Why it's wrong here

    Changing the HTTP method (e.g., from POST to GET) does not address the fundamental cross-origin security restriction enforced by web browsers. CORS errors occur when the browser's same-origin policy blocks a request to a different origin unless the server explicitly grants permission via specific HTTP response headers, regardless of the method used for the actual request.

  • ✗

    Update the S3 bucket policy to allow cross-origin requests from any origin.

    Why it's wrong here

    An S3 bucket policy defines access permissions for objects within an S3 bucket, controlling who can read, write, or delete them. It has no bearing on the Cross-Origin Resource Sharing (CORS) configuration of an API Gateway endpoint, which is a distinct service responsible for managing HTTP requests and responses to backend resources like Lambda functions.

  • ✗

    Modify the Lambda function to return CORS headers in its response.

    Why it's wrong here

    While a Lambda function can include CORS headers in its response for the actual request, the browser's preflight OPTIONS request, which precedes 'non-simple' cross-origin requests, must be handled directly by API Gateway. If API Gateway does not respond to the OPTIONS method with the necessary Access-Control-Allow-Origin header, the browser will block the request before it ever reaches the Lambda function.

  • ✓

    Manually add an OPTIONS method to the API Gateway resource and configure the CORS headers in the integration response.

    Why this is correct

    To resolve CORS issues, API Gateway must be explicitly configured to handle the browser's preflight OPTIONS request. This involves manually adding an OPTIONS method to the API Gateway resource and setting up a mock integration response that includes the required Access-Control-Allow-Origin, Access-Control-Allow-Methods, and Access-Control-Allow-Headers in its headers, allowing the browser to proceed with the actual request.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,135 original DVA-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.