Courseiva

DVA-C02 Development with AWS Services Practice Question

A developer is designing a mobile application that needs to upload files to Amazon S3. The developer wants to use temporary credentials to avoid storing long-term AWS credentials on the device. Which TWO services should the developer use together?

⚠ Common exam trap

Test-takers frequently confuse IAM (which manages long-term credentials) with STS (which issues temporary credentials), or they mistakenly think S3 Transfer Acceleration or KMS can handle authentication, when in fact only STS and Cognito together solve the temporary credential requirement for mobile apps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Security Token Service (STS)

AWS Security Token Service (STS) is used to generate temporary, limited-privilege credentials for accessing AWS resources, such as S3 buckets. Amazon Cognito provides identity pools that can automatically obtain and refresh STS tokens for authenticated users, eliminating the need to store long-term AWS credentials on the mobile device. Together, they enable secure, temporary credential management for file uploads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AWS Security Token Service (STS)

    Why this is correct

    AWS Security Token Service (STS) is fundamental for granting temporary, limited-privilege credentials to users or services that don't have long-term IAM credentials. For mobile applications, STS is often used indirectly via services like Amazon Cognito, which federates identities and then calls STS to issue session tokens. Developers can also directly use STS API operations, such as AssumeRoleWithWebIdentity, to exchange tokens from external identity providers for temporary AWS access keys, enabling secure, time-bound access to AWS resources.

  • ✓

    Amazon Cognito

    Why this is correct

    Amazon Cognito Identity Pools are specifically designed to provide temporary, limited-privilege AWS credentials to mobile and web application users, even if they are unauthenticated ("guest" users). It integrates seamlessly with public identity providers like Google, Facebook, and Apple, or custom OIDC providers. After a user authenticates with an identity provider, Cognito exchanges the identity token with STS to obtain temporary AWS credentials, allowing the mobile application to directly access other AWS services securely.

  • ✗

    Amazon S3 Transfer Acceleration

    Why it's wrong here

    Amazon S3 Transfer Acceleration is a feature designed to speed up data transfers to and from S3 buckets over long distances. It achieves this by routing data through CloudFront's globally distributed edge locations, optimizing network paths. This service focuses solely on improving data transfer performance and has no functionality related to user authentication, authorization, or the provision of temporary AWS credentials for mobile applications.

  • ✗

    AWS Identity and Access Management (IAM)

    Why it's wrong here

    AWS IAM is the service for securely managing access to AWS services and resources, primarily through long-term credentials like IAM user access keys or roles. While IAM defines the permissions, directly embedding or distributing IAM user credentials within a mobile application is a severe security vulnerability. Mobile applications require temporary, short-lived credentials with specific, limited permissions, which IAM users do not inherently provide for end-users.

  • ✗

    AWS Key Management Service (KMS)

    Why it's wrong here

    AWS Key Management Service (KMS) is a managed service that makes it easy to create and control encryption keys used to encrypt your data. KMS is primarily focused on cryptographic operations, such as generating, storing, and managing symmetric and asymmetric encryption keys. It does not provide any mechanism for authenticating application users or issuing temporary security credentials for accessing AWS services; its role is purely data protection through encryption.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.