DVA-C02 Development with AWS Services Practice Question
A developer is designing a mobile application that needs to upload files to Amazon S3. The developer wants to use temporary credentials to avoid storing long-term AWS credentials on the device. Which TWO services should the developer use together?
⚠ Common exam trap
Test-takers frequently confuse IAM (which manages long-term credentials) with STS (which issues temporary credentials), or they mistakenly think S3 Transfer Acceleration or KMS can handle authentication, when in fact only STS and Cognito together solve the temporary credential requirement for mobile apps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Security Token Service (STS)
AWS Security Token Service (STS) is used to generate temporary, limited-privilege credentials for accessing AWS resources, such as S3 buckets. Amazon Cognito provides identity pools that can automatically obtain and refresh STS tokens for authenticated users, eliminating the need to store long-term AWS credentials on the mobile device. Together, they enable secure, temporary credential management for file uploads.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AWS Security Token Service (STS)
Why this is correct
AWS Security Token Service (STS) is fundamental for granting temporary, limited-privilege credentials to users or services that don't have long-term IAM credentials. For mobile applications, STS is often used indirectly via services like Amazon Cognito, which federates identities and then calls STS to issue session tokens. Developers can also directly use STS API operations, such as AssumeRoleWithWebIdentity, to exchange tokens from external identity providers for temporary AWS access keys, enabling secure, time-bound access to AWS resources.
- ✓
Amazon Cognito
Why this is correct
Amazon Cognito Identity Pools are specifically designed to provide temporary, limited-privilege AWS credentials to mobile and web application users, even if they are unauthenticated ("guest" users). It integrates seamlessly with public identity providers like Google, Facebook, and Apple, or custom OIDC providers. After a user authenticates with an identity provider, Cognito exchanges the identity token with STS to obtain temporary AWS credentials, allowing the mobile application to directly access other AWS services securely.
- ✗
Amazon S3 Transfer Acceleration
Why it's wrong here
Amazon S3 Transfer Acceleration is a feature designed to speed up data transfers to and from S3 buckets over long distances. It achieves this by routing data through CloudFront's globally distributed edge locations, optimizing network paths. This service focuses solely on improving data transfer performance and has no functionality related to user authentication, authorization, or the provision of temporary AWS credentials for mobile applications.
- ✗
AWS Identity and Access Management (IAM)
Why it's wrong here
AWS IAM is the service for securely managing access to AWS services and resources, primarily through long-term credentials like IAM user access keys or roles. While IAM defines the permissions, directly embedding or distributing IAM user credentials within a mobile application is a severe security vulnerability. Mobile applications require temporary, short-lived credentials with specific, limited permissions, which IAM users do not inherently provide for end-users.
- ✗
AWS Key Management Service (KMS)
Why it's wrong here
AWS Key Management Service (KMS) is a managed service that makes it easy to create and control encryption keys used to encrypt your data. KMS is primarily focused on cryptographic operations, such as generating, storing, and managing symmetric and asymmetric encryption keys. It does not provide any mechanism for authenticating application users or issuing temporary security credentials for accessing AWS services; its role is purely data protection through encryption.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every DVA-C02 question from scratch — 1,135 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DVA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DVA-C02 exam.