Courseiva

AWS Certified Developer Associate DVA-C02 (DVA-C02) — Questions 751–825

1135 questions total · 16pages · All types, answers revealed

Page 10

Page 11 of 16

Page 12
751
MCQmedium

A company runs a web application on EC2 instances in an Auto Scaling group. The application needs to store session state. The architecture must be highly available and scalable. Which solution should the developer choose?

A.Use sticky sessions on the Application Load Balancer
B.Store session data in an S3 bucket
C.Use Amazon ElastiCache for Redis to store session state
D.Store session data in the instance's ephemeral storage
AnswerC

Amazon ElastiCache for Redis provides a highly performant, scalable, and fully managed in-memory data store perfectly suited for externalizing session state. Its extremely low-latency read and write capabilities ensure a responsive user experience, while its built-in replication and automatic failover mechanisms guarantee high availability and durability of session data. By storing sessions externally, any EC2 instance in an Auto Scaling group can access any user's session, enabling seamless horizontal scaling and robust fault tolerance without session loss.

Why this answer

Amazon ElastiCache for Redis is a fully managed, highly available, and scalable in-memory data store that is purpose-built for session state management. It supports replication, automatic failover, and horizontal scaling, making it the ideal choice for a highly available and scalable session store across an Auto Scaling group of EC2 instances.

Exam trap

DVA-C02 often tests the difference between sticky sessions (which are not a session store) and a centralized session store like ElastiCache, causing candidates to pick sticky sessions as a scalability solution.

How to eliminate wrong answers

Option A is wrong because sticky sessions on an ALB only pin a user to a single instance; if that instance fails or is replaced by Auto Scaling, the session is lost, and it does not provide a shared, scalable session store. Option B is wrong because S3 is object storage with high latency and is not designed for the low-latency, high-throughput read/write access pattern required for session state. Option D is wrong because ephemeral instance storage is tied to a single EC2 instance and is lost on stop/terminate, making it unsuitable for highly available, scalable session management.

752
MCQmedium

A developer is building a serverless application using AWS Step Functions to orchestrate multiple AWS Lambda functions. One of the Lambda functions occasionally fails due to a transient error. The developer wants the Step Functions execution to automatically retry the failed task up to three times with exponential backoff. Which configuration should the developer set in the Step Functions state machine definition?

A.Add a Retry clause in the Lambda function's configuration with a maximum retry count of 3.
B.Use the Amazon States Language (ASL) Retry field in the Task state definition.
C.Wrap the Lambda function invocation in a custom while loop within the function code.
D.Use the Amazon States Language Catch field in the Task state to redirect to a retry logic.
AnswerB

The Amazon States Language (ASL) Retry field is the definitive and recommended mechanism within AWS Step Functions for handling transient failures in Task states. This declarative approach allows developers to specify which error types to retry, the maximum number of attempts, the initial delay, and an exponential backoff rate. Implementing retries directly in the state machine definition ensures robust error handling without modifying the underlying Lambda function code.

Why this answer

The Amazon States Language (ASL) provides a native Retry field within a Task state definition that allows you to specify retry policies, including a maximum retry count and exponential backoff. This is the intended mechanism for handling transient failures in Step Functions without requiring custom code or external retry logic.

Exam trap

The trap here is that candidates confuse the Retry field (for retries) with the Catch field (for error handling) or mistakenly think retry logic belongs in the Lambda function code rather than in the state machine definition.

How to eliminate wrong answers

Option A is wrong because the Retry clause in a Lambda function's configuration (e.g., in the function's reserved concurrency or event source mapping) does not control Step Functions retries; Step Functions retries are defined in the state machine definition, not in the Lambda function itself. Option C is wrong because wrapping the Lambda invocation in a custom while loop within the function code would not integrate with Step Functions' retry mechanism and would violate the serverless orchestration pattern, as Step Functions manages retries at the state machine level. Option D is wrong because the Catch field is used to handle errors by redirecting to a different state (e.g., a fallback or error-handling state), not to implement retry logic; retries are handled exclusively by the Retry field.

753
Multi-Selecthard

A developer is building a serverless application that uses Amazon Cognito user pools for authentication and an Amazon API Gateway REST API with a Lambda authorizer. The developer needs to ensure that the Lambda authorizer can validate tokens and return an IAM policy that allows access to specific API methods. The developer also wants to cache the authorizer result to reduce latency and cost. Which TWO actions must the developer take to meet these requirements? (Choose two.)

Select 2 answers
A.Use an AWS Lambda function that returns a boolean value indicating whether the token is valid.
B.Configure the Lambda authorizer with a token source header, such as Authorization, and set the authorizer type to TOKEN.
C.Configure the API Gateway method to use AWS_IAM authorization instead of the Lambda authorizer.
D.Attach an IAM execution role to the Lambda authorizer that grants apigateway:Invoke permissions.
E.Enable authorization caching on the API Gateway authorizer and specify a time-to-live (TTL) in seconds.
AnswersB, E

A TOKEN authorizer expects a single identity source header, typically Authorization. Configuring the token source correctly allows API Gateway to extract the token and pass it to the Lambda authorizer. Without specifying a valid token source, the authorizer cannot retrieve the token, and requests will fail authorization.

Why this answer

To use a Lambda authorizer with a token source, the authorizer must be configured with the correct token source header and type TOKEN. Enabling authorization caching with a TTL reduces repeated Lambda invocations and latency. These two configurations together satisfy the validation and caching requirements.

The authorizer must return a valid IAM policy, not a boolean, and does not require apigateway:Invoke permissions.

Exam trap

The trap here is confusing the authorizer's response requirements, assuming a boolean or an execution role with API Gateway permissions is needed, when a full IAM policy and caching configuration are what matter.

754
MCQhard

A developer is using AWS CodeBuild to build a Docker image and push it to Amazon ECR. The build fails with the error 'no basic authentication credentials'. The build project has an IAM role with the AmazonEC2ContainerRegistryPowerUser policy. What is the most likely cause?

A.The build project is not configured to use a VPC that can reach ECR.
B.The build environment does not have Docker installed.
C.The IAM role does not have sufficient permissions to push to ECR.
D.The buildspec does not include the pre_build step to authenticate with ECR.
AnswerD

The 'no basic authentication credentials' error occurs specifically when the Docker client attempts to push to ECR without first authenticating; the buildspec must include a pre_build phase command that runs 'aws ecr get-login-password | docker login' to obtain a temporary token, and omitting this step is the classic root cause of this exact error message.

Why this answer

AWS CodeBuild does not automatically authenticate to Amazon ECR. The buildspec must include a pre_build phase that runs 'aws ecr get-login-password' piped to 'docker login' (or uses the ECR credential helper) to obtain temporary credentials. The IAM role's AmazonEC2ContainerRegistryPowerUser policy grants the necessary permissions, but the Docker client still needs explicit authentication before pushing.

Exam trap

DVA-C02 often tests the misconception that granting an IAM policy like AmazonEC2ContainerRegistryPowerUser is sufficient for Docker to push to ECR, when in fact the buildspec must explicitly authenticate the Docker client.

How to eliminate wrong answers

Option A is wrong because CodeBuild runs in an AWS-managed environment with internet access by default, and ECR is reachable via public endpoints; VPC configuration is not required for ECR access unless private endpoints are mandated. Option B is wrong because the error is specifically about authentication credentials, not a missing Docker binary — CodeBuild's standard images include Docker, and a missing Docker install would produce a 'command not found' error. Option C is wrong because AmazonEC2ContainerRegistryPowerUser provides full push/pull permissions to ECR; the error 'no basic authentication credentials' indicates the Docker client was never authenticated, not that the IAM role lacks permissions.

755
MCQhard

Refer to the exhibit. An S3 bucket policy is set as shown. A developer tries to download an object from my-bucket using the AWS CLI from an IP address in the 203.0.113.0/24 range. What will happen?

A.The policy is invalid because of conflicting statements.
B.The download succeeds because the Allow statement matches the request.
C.The download succeeds because the Deny statement does not apply to GetObject.
D.The download fails with an AccessDenied error.
AnswerD

The AWS IAM policy evaluation logic follows a strict order of precedence. An explicit "Deny" statement, such as one using "s3:*" on the target resource, always overrides any "Allow" statements, even if an "Allow" statement specifically grants "s3:GetObject" permission. Since the request is explicitly denied by a matching "Deny" statement, the download attempt will result in an "AccessDenied" error, preventing the user from retrieving the object.

Why this answer

In an S3 bucket policy, explicit Deny statements override any Allow statements. Even though the Allow statement grants s3:GetObject to all principals, the Deny statement explicitly denies s3:GetObject when the request originates from the 203.0.113.0/24 IP range. Since the developer's IP falls within that range, the Deny takes precedence, resulting in an AccessDenied error.

Exam trap

The trap here is that candidates often assume that an Allow statement will always grant access, forgetting that an explicit Deny for the same action from a matching condition (like a source IP) takes precedence and causes the request to fail.

How to eliminate wrong answers

Option A is wrong because the policy is valid; S3 bucket policies can contain both Allow and Deny statements, and they are evaluated with Deny taking precedence over Allow. Option B is wrong because the Allow statement does match the request, but the explicit Deny statement for the same action from the specified IP range overrides it, causing the download to fail. Option C is wrong because the Deny statement explicitly applies to s3:GetObject, as it uses a wildcard '*' for actions, which includes GetObject.

756
MCQeasy

A developer is deploying a serverless application using the AWS Serverless Application Model (SAM). The developer wants to set environment variables for the Lambda function that are specific to the deployment stage (e.g., dev, prod). How should the developer accomplish this?

A.Use SAM parameters to pass stage-specific values into the template.
B.Define the environment variables in the Lambda function configuration and use 'Ref' with the stage name.
C.Hardcode the environment variables in the SAM template for each stage.
D.Use AWS CloudFormation 'Conditions' to set environment variables based on the stage.
AnswerA

SAM parameters, which are built upon AWS CloudFormation parameters, provide a robust and standard mechanism to inject environment-specific values into a single, reusable template. Developers define these parameters in the `Parameters` section of their `template.yaml` and then supply different values at deployment time, for instance, using `sam deploy --parameter-overrides Environment=Prod`. This allows a single template to be deployed consistently across development, staging, and production environments with distinct configurations, promoting reusability and reducing configuration drift.

Why this answer

AWS SAM natively supports template parameters, which allow you to pass stage-specific values (e.g., environment variables) at deployment time. By defining a parameter in the SAM template and referencing it in the Lambda function's `Environment.Variables` section, you can inject different values for dev, prod, etc., without modifying the template itself. This approach leverages CloudFormation's parameter substitution to keep the template reusable and environment-agnostic.

Exam trap

Candidates often think they must use complex CloudFormation Conditions or Mappings to manage environment-specific values, but the simplest and most standard approach in AWS SAM is to use Parameters to pass these values during deployment (e.g., via sam deploy --parameter-overrides).

How to eliminate wrong answers

Option B is wrong because `Ref` with a stage name is not a valid intrinsic function for dynamically setting environment variables based on deployment stage; `Ref` is used to reference logical IDs of resources or parameters, not to conditionally select values. Option C is wrong because hardcoding environment variables for each stage violates the principle of infrastructure as code, requiring manual template edits per deployment and increasing the risk of misconfiguration. Option D is wrong because CloudFormation `Conditions` can only control whether a resource or property is included in the stack, not dynamically assign different values to a property; environment variables must be set to a specific value, not conditionally omitted or included.

757
Multi-Selectmedium

A developer is using AWS CodeDeploy to deploy a revision to an Amazon EC2 instance. The deployment fails with the error 'The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available for deployment, or some instances in your deployment group are experiencing problems.' Which TWO actions should the developer take to troubleshoot the issue? (Choose TWO.)

Select 2 answers
A.Check the CodeDeploy agent logs on the EC2 instance for errors.
B.Change the deployment configuration to AllAtOnce.
C.Verify that the EC2 instance has an IAM role that allows CodeDeploy to access it.
D.Verify that the CodeDeploy agent is installed and running on the instance.
E.Increase the health check grace period on the Auto Scaling group.
AnswersA, D

Checking the CodeDeploy agent logs, typically located at `/var/log/aws/codedeploy-agent/codedeploy-agent.log` on Linux or `C:\ProgramData\Amazon\CodeDeploy\log\codedeploy-agent.log` on Windows, is the most direct way to diagnose deployment failures. These logs provide granular details about the agent's actions, script execution outputs, and any errors encountered during the deployment lifecycle events. This critical first step helps pinpoint issues like missing files, incorrect permissions, or script execution failures.

Why this answer

The CodeDeploy agent logs on the EC2 instance contain detailed error messages about why the deployment script failed, such as script exit codes, missing dependencies, or permission issues. Checking these logs is the first step in diagnosing individual instance failures, as the agent writes events to `/var/log/aws/codedeploy-agent/codedeploy-agent.log`.

Exam trap

The trap here is that candidates often confuse the deployment configuration (AllAtOnce) with a troubleshooting step, when in fact it only changes the rollout speed and does not help diagnose why individual instances are failing.

758
MCQhard

A company runs a containerized application on Amazon ECS using Fargate launch type. The application needs to read and write files to a shared file system across multiple tasks. The development team wants a solution that provides high throughput and is POSIX-compliant. Which storage solution should the team use?

A.Amazon S3 with mountpoint-s3
B.Amazon EFS
C.Amazon EBS with multi-attach enabled
D.Amazon FSx for Windows File Server
AnswerB

Amazon EFS provides a fully managed, scalable, and highly available network file system (NFS) that offers full POSIX compliance. This enables multiple Amazon ECS tasks, even those running on different EC2 instances or Fargate across various Availability Zones, to concurrently read and write to the same shared file system. EFS is an ideal solution for containerized applications requiring persistent, consistent, and shared file storage that behaves like a traditional file system.

Why this answer

Amazon EFS is the correct choice because it provides a fully managed, POSIX-compliant shared file system that can be mounted concurrently by multiple Amazon ECS tasks using the Fargate launch type. EFS uses the NFSv4.1 protocol, supports high throughput (up to 10 GB/s with Bursting or Provisioned Throughput modes), and automatically scales storage capacity as files are added or removed, making it ideal for shared read/write workloads across containers.

Exam trap

The trap here is that candidates often confuse Amazon EBS Multi-Attach with a shared file system, but EBS Multi-Attach is limited to EC2 instances in the same AZ and does not support Fargate, while EFS is the only POSIX-compliant, fully managed file system that works natively with Fargate tasks across multiple Availability Zones.

How to eliminate wrong answers

Option A is wrong because Amazon S3 with mountpoint-s3 is an object storage service that uses a custom FUSE-based mount, which is not POSIX-compliant (e.g., it does not support file locking, hard links, or atomic renames) and is designed for high-latency, throughput-oriented workloads rather than low-latency shared file system access. Option C is wrong because Amazon EBS with multi-attach enabled supports only up to 16 Nitro-based EC2 instances, not Fargate tasks, and requires the volume to be attached to instances in the same Availability Zone, making it unsuitable for a serverless container environment. Option D is wrong because Amazon FSx for Windows File Server uses the SMB protocol and is not POSIX-compliant; it is designed for Windows-based workloads and does not natively support Linux containers without additional translation layers.

759
MCQmedium

A developer is using AWS CloudFormation to deploy a stack that includes an S3 bucket and a Lambda function. The stack fails with the error 'The following resource(s) failed to create: [MyBucket]'. What is the most likely cause?

A.The S3 bucket name is already taken.
B.The stack's VPC configuration is incorrect.
C.The S3 bucket policy is malformed.
D.The Lambda function code is invalid.
AnswerA

S3 bucket names must be globally unique across all AWS accounts and regions; if the specified BucketName property is already claimed by another account, CloudFormation's CreateBucket call fails immediately with a naming conflict, which is the most common cause of this specific error.

Why this answer

The correct answer is A: the S3 bucket name is already taken. S3 bucket names must be globally unique across all AWS accounts and regions, so if the requested name already exists, CloudFormation fails to create the MyBucket resource with exactly this kind of 'failed to create' error. The other options do not fit: a VPC configuration issue would typically affect resources like Lambda or EC2 networking, not S3 bucket creation; a malformed bucket policy would usually fail during policy attachment or update rather than initial bucket creation; and invalid Lambda code would cause the Lambda resource to fail, not MyBucket.

760
MCQhard

A developer is deploying an application on EC2 instances behind an Application Load Balancer (ALB). The application must authenticate users using an identity provider (IdP) that supports OpenID Connect (OIDC). What is the MOST secure way to offload authentication to the ALB?

A.Configure the ALB with an OIDC identity provider and use the authenticate-oidc action.
B.Use AWS Lambda@Edge to authenticate users at the CloudFront edge.
C.Use IAM federation to trust the IdP and assign IAM roles to users.
D.Use Amazon Cognito User Pools and configure the ALB to use Cognito as the authentication provider.
AnswerA

The Application Load Balancer (ALB) natively supports OpenID Connect (OIDC) authentication through its `authenticate-oidc` action. This allows the ALB to delegate user authentication to an external OIDC identity provider (IdP). When a user attempts to access the application, the ALB redirects them to the IdP for login. Upon successful authentication, the IdP returns an ID token to the ALB, which validates it and then forwards the request to the backend EC2 instances, optionally injecting user claims as HTTP headers. This offloads authentication from the application code.

Why this answer

The ALB supports OIDC authentication natively through the `authenticate-oidc` action, which securely offloads user authentication to the IdP. This is the most secure and efficient approach because it keeps authentication at the edge of the load balancer. Option B is incorrect because Lambda@Edge is used with CloudFront, not directly with ALB.

Option C is incorrect because IAM federation is for granting AWS API access, not for web application authentication. Option D is incorrect because while Cognito User Pools can be used with ALB, the question specifies the organization already has an OIDC-compliant IdP; the ALB's native integration is more direct and secure than adding Cognito as an intermediary.

761
Multi-Selectmedium

A company is using Amazon API Gateway to expose a REST API. The API is integrated with an AWS Lambda function. The developer wants to implement caching to improve performance. Which THREE steps are necessary to enable caching for a specific stage? (Choose THREE.)

Select 3 answers
A.Attach an IAM policy to the API Gateway role for cache access.
B.Modify the Lambda function to store responses in ElastiCache.
C.Enable API caching in the stage settings.
D.Set a cache time-to-live (TTL) value.
E.Specify a cache cluster size (e.g., 0.5 GB).
AnswersC, D, E

Enabling API caching in the stage settings is the fundamental first step to activate API Gateway's managed caching feature for a specific deployment stage. This action provisions a dedicated cache cluster for that stage, allowing API Gateway to store and retrieve responses for subsequent identical requests without invoking the backend integration. Without explicitly enabling caching at the stage level, no other caching configurations will have any effect.

Why this answer

API Gateway provides built-in caching at the stage level, which can be enabled directly in the stage settings without modifying the Lambda function or adding external services. This caching reduces the number of calls made to the backend Lambda function by serving cached responses for identical requests, improving performance and reducing latency.

Exam trap

The trap here is that candidates may think caching requires modifying the Lambda function (Option B) or adding IAM policies (Option A), when in fact API Gateway's stage-level caching is a simple toggle with configurable cluster size and TTL, and no backend changes are needed.

762
MCQhard

A company is running a containerized application on Amazon ECS with Fargate launch type. The application needs to access an Amazon S3 bucket. The company wants to follow the principle of least privilege. How should the developer provide the necessary permissions?

A.Use Amazon EFS to store access keys.
B.Assign an IAM instance profile to the Fargate tasks.
C.Create an IAM task role with S3 permissions and associate it with the ECS task definition.
D.Store AWS credentials in the container image.
AnswerC

Creating an IAM task role with S3 permissions and associating it with the ECS task definition is the recommended and most secure approach. This method grants temporary, specific permissions directly to the containers within an ECS task, allowing them to interact with AWS services like S3 without embedding static credentials. It adheres to the principle of least privilege, ensuring the application only has the necessary permissions and that credentials are automatically managed and rotated by AWS.

Why this answer

Amazon ECS with Fargate launch type uses IAM task roles to grant permissions to containers at the task level. The task role is an IAM role that the ECS task assumes, allowing the application to securely access S3 without hardcoding credentials. This follows the principle of least privilege by scoping permissions to the specific task and using temporary credentials via the AWS STS service.

Exam trap

The trap here is that candidates confuse instance profiles (used with EC2 launch type) with task roles (used with Fargate), leading them to select Option B, but Fargate tasks cannot assume an instance profile because there is no underlying EC2 instance.

How to eliminate wrong answers

Option A is wrong because Amazon EFS is a file storage service, not a credential store; it cannot be used to store or provide access keys for IAM permissions. Option B is wrong because Fargate tasks do not use instance profiles; instance profiles are used with EC2 launch type to grant permissions to the underlying EC2 instance, not to the containers. Option D is wrong because storing AWS credentials in the container image violates security best practices, as credentials would be exposed in the image layers and cannot be rotated or scoped to least privilege.

763
Multi-Selectmedium

A company wants to encrypt data at rest in an Amazon RDS for MySQL DB instance. Which of the following are true about RDS encryption? (Select THREE.)

Select 3 answers
A.Encryption at rest can be enabled on an existing unencrypted DB instance.
B.Encryption at rest can be enabled when you create the DB instance.
C.Snapshots of an encrypted instance are encrypted.
D.When encryption is enabled, automated backups are encrypted.
E.Read replicas of an encrypted instance can be unencrypted.
AnswersB, C, D

Encryption at rest is an instance-level configuration selected at the moment you create the DB instance. When you launch a new RDS database, you choose the 'Enable encryption' option and specify an AWS KMS key; from that point onward, all data on the underlying storage is AES-256 encrypted, and this setting cannot be changed after creation.

Why this answer

Option B is correct because RDS encryption at rest is configured at creation time: when you launch the DB instance you select an AWS KMS customer master key (CMK), and RDS uses it to encrypt the underlying storage, logs, and snapshots. Option C is correct because any DB snapshot taken from an encrypted instance is automatically encrypted with the same KMS key, so copies and restores of that snapshot remain encrypted. Option D is correct because automated backups of an encrypted DB instance are encrypted with the same KMS key as the instance, as are manual snapshots and read replicas.

Option A is not correct because you cannot enable encryption on an existing unencrypted instance in place; you must create an encrypted snapshot copy or restore into a new encrypted instance. Option E is not correct because a read replica of an encrypted instance must also be encrypted with the same KMS key; you cannot create an unencrypted read replica from an encrypted source.

Exam trap

The trap is believing you can toggle encryption on an existing RDS instance — the exam tests that encryption is set at creation and that snapshots/backups/replicas inherit it, while in-place enablement is impossible.

764
Multi-Selectmedium

A developer is using AWS Lambda to process files uploaded to an S3 bucket. The Lambda function is triggered by S3 events. The developer notices that the function sometimes processes the same file multiple times. Which TWO steps should the developer take to make the processing idempotent? (Choose TWO.)

Select 2 answers
A.Check if the file has already been processed by storing a marker in DynamoDB.
B.Use conditional writes in DynamoDB to ensure that updates are idempotent.
C.Reduce the S3 event batch size in the Lambda trigger.
D.Increase the Lambda function's timeout.
E.Enable S3 versioning on the bucket.
AnswersA, B

This strategy involves using a unique identifier for each file, such as its S3 object key or ETag, as a primary key in a DynamoDB table. Before processing a file, the Lambda function attempts to write this identifier to DynamoDB. If the write succeeds (e.g., using a conditional write `attribute_not_exists`), the file is processed; otherwise, if the item already exists, it indicates prior processing, and the function can safely exit, ensuring idempotent execution.

Why this answer

Storing a marker in DynamoDB (e.g., a record with the S3 object key as the partition key) allows the Lambda function to check if a file has already been processed before performing the work. This ensures that even if the same S3 event is delivered multiple times (due to retries or duplicate notifications), the function will skip reprocessing, making the operation idempotent.

Exam trap

The trap here is that candidates often confuse reducing batch size or increasing timeout with solving duplicate processing, when in fact idempotency requires a stateful check (like DynamoDB) to track what has already been processed.

765
Drag & Dropmedium

Drag and drop the steps to encrypt an EBS volume using AWS KMS in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First create a KMS key, then snapshot the unencrypted volume, copy with encryption, and create the encrypted volume.

766
MCQhard

A developer notices that an Amazon RDS for MySQL DB instance's CPU utilization is consistently above 90% during peak hours. The application uses read-heavy workloads. Which action would MOST effectively reduce CPU load without major architectural changes?

A.Implement an in-memory cache layer with Amazon ElastiCache.
B.Migrate the database to Amazon Aurora with auto-scaling.
C.Increase the DB instance size to a larger instance type.
D.Create a Multi-AZ deployment and use the standby for read queries.
AnswerA

Implementing an in-memory cache layer with Amazon ElastiCache (e.g., Redis or Memcached) is an effective strategy for reducing CPU load on a read-heavy database. By caching frequently accessed data, ElastiCache intercepts read requests before they reach the database, serving them much faster from memory. This significantly decreases the number of queries the RDS instance needs to process, directly lowering its CPU utilization and improving overall application responsiveness. It requires application-level changes to interact with the cache, but these are typically manageable.

Why this answer

For a read-heavy workload causing sustained high CPU on RDS MySQL, offloading repeated read queries to an in-memory cache like ElastiCache (Redis or Memcached) removes the majority of read traffic from the database engine, directly reducing CPU utilization without re-architecting the application. This is the least invasive and most effective fix for read-dominated load.

Exam trap

The trap here is confusing RDS Multi-AZ standby with a read replica — many candidates believe the standby can serve read traffic, but it is a passive failover node, making option D a classic distractor.

How to eliminate wrong answers

Option B is wrong because migrating to Aurora with auto-scaling is a major architectural change (data migration, endpoint changes, cost implications) and auto-scaling in Aurora primarily targets read replicas, not the writer's CPU — it does not satisfy the 'without major architectural changes' constraint. Option C is wrong because vertically scaling the instance only buys temporary headroom; it does not address the root cause of repeated identical reads and is more expensive than caching. Option D is wrong because a Multi-AZ standby in RDS is a passive failover target and cannot serve read queries — that is a common misconception; only read replicas serve reads.

767
MCQmedium

A developer is deploying a web application using AWS Elastic Beanstalk. The application uses an Amazon RDS MySQL database. The developer wants to ensure that database credentials are not stored in the application code or environment variables. The solution must automatically rotate credentials every 90 days. The developer has created a secret in AWS Secrets Manager containing the database credentials. The Elastic Beanstalk environment is configured with an IAM instance profile that has permission to read the secret. However, when the application is deployed, it fails to connect to the database. The developer checks the application logs and sees a 'Host not found' error. The RDS instance is in a private subnet, and the Elastic Beanstalk environment is in the same VPC. What is the MOST likely cause of the connection failure?

A.The secret is not correctly referenced in the Elastic Beanstalk environment properties.
B.The application code is not retrieving the secret from Secrets Manager at startup.
C.The IAM instance profile does not have the necessary permissions to access the secret.
D.The secret is stored in a different region than the Elastic Beanstalk environment.
AnswerB

For an application running on Elastic Beanstalk to utilize a secret stored in AWS Secrets Manager, its code must contain specific logic to programmatically fetch that secret. This involves using an AWS SDK to instantiate a Secrets Manager client and then calling the GetSecretValue API operation, passing the secret's ARN or name. If this retrieval step is missing or improperly implemented, the application will attempt to connect to the database with undefined or placeholder credentials, inevitably leading to authentication failures.

Why this answer

The correct option is B: the application code is not retrieving the secret from Secrets Manager at startup. Since the credentials are no longer in code or environment variables, the app must call the Secrets Manager API (e.g., GetSecretValue) at runtime to obtain the DB host, username, and password; if it never does so, it has no host to resolve, producing the 'Host not found' error. Option A is wrong because environment properties are explicitly not used for credentials here, and the failure is a missing hostname, not a misreferenced property.

Option C is wrong because the instance profile already has read permission to the secret, so an access-denied error would occur instead. Option D is wrong because a cross-region secret would cause an access/not-found error for the secret, not a 'Host not found' database connection error.

768
MCQeasy

A developer is deploying a new version of a Lambda function and wants to roll back immediately if errors are detected. Which deployment strategy should the developer use?

A.Use AWS CodeDeploy with a canary deployment configuration
B.Use an EC2 rolling update strategy
C.Use AWS CodeDeploy with a linear deployment configuration
D.Use an immutable update strategy
AnswerA

Using AWS CodeDeploy with a canary deployment configuration is the optimal strategy for safely deploying new Lambda function versions. This approach shifts a small, configurable percentage of traffic (e.g., 10%) to the new version for a specified 'bake time,' allowing real-world monitoring via CloudWatch alarms. If errors or performance issues are detected during this period, CodeDeploy automatically rolls back to the previous stable version, minimizing impact and ensuring application stability.

Why this answer

The correct option is A: AWS CodeDeploy with a canary deployment configuration. CodeDeploy supports Lambda deployments with traffic-shifting configurations, and a canary deployment shifts a small percentage of traffic first (e.g., 10% for 5 minutes) so that CloudWatch alarms can trigger an automatic rollback if errors are detected, satisfying the requirement to roll back immediately. Option B is wrong because EC2 rolling updates apply to EC2 instances, not Lambda functions.

Option C is less suitable because a linear configuration shifts traffic in equal increments over time, which delays error detection compared to a canary's initial small traffic slice. Option D is wrong because immutable updates are an EC2/Elastic Beanstalk strategy, not a Lambda deployment strategy.

769
Multi-Selecthard

A developer is using AWS X-Ray to trace a Lambda function that calls DynamoDB and SQS. Some traces show errors. Which TWO actions should the developer take to diagnose the issue?

Select 2 answers
A.Examine the trace details for exception messages.
B.Verify that the Lambda function's IAM role has permissions for X-Ray.
C.Check the X-Ray service map for error edges.
D.Disable X-Ray sampling to capture all requests.
E.Enable CloudFront to cache responses.
AnswersA, C

Examining X-Ray trace details is the most direct and effective method to diagnose errors within a Lambda function. Each trace provides granular information for segments and subsegments, including full stack traces, precise exception messages, error codes, and specific HTTP status codes for downstream calls. This allows a developer to pinpoint the exact failure point, whether it's within the Lambda's code logic or an issue with an external service call, such as a DynamoDB throttling exception or a permission denied error.

Why this answer

To diagnose errors in existing X-Ray traces, the developer should examine trace details (Option A) to see exception messages and stack traces for each segment, and check the service map (Option C) for error edges that indicate which service interactions failed. Option B is about enabling X-Ray permissions, which is a prerequisite for tracing but does not help diagnose errors in traces that are already captured. Option D (disabling sampling) is unnecessary because X-Ray captures errors by default regardless of sampling.

Option E (CloudFront caching) is unrelated to trace diagnostics.

Exam trap

A common trap is selecting Option B, thinking that ensuring X-Ray permissions is a diagnostic step. However, missing permissions would prevent traces from being sent at all; since traces are present, the focus should be on analyzing the existing trace data (details and service map) to find error causes.

770
MCQhard

A developer is using AWS CodeDeploy to deploy an application to an EC2 Auto Scaling group. The deployment must ensure that a minimum number of instances are always running and healthy. The developer wants to deploy to 10 instances. Which deployment configuration should the developer use?

A.CodeDeployDefault.OneAtATime
B.CodeDeployDefault.AllAtOnce
C.CodeDeployDefault.HalfAtATime
D.CodeDeployDefault.MinHealthyHostsPercentage: 90
AnswerA

This configuration ensures that only one instance is taken offline for deployment at any given time, maintaining the maximum possible number of healthy instances throughout the process. Specifically, it guarantees that N-1 instances remain healthy and serving traffic while one instance is updated and validated. This sequential approach is ideal for achieving zero-downtime deployments, minimizing service impact, and ensuring high availability for critical applications.

Why this answer

CodeDeployDefault.OneAtATime, is correct because it ensures that only one instance is updated at a time, which guarantees that a minimum number of instances (9 out of 10) remain healthy and running throughout the deployment. This configuration is ideal for maintaining high availability and meeting strict uptime requirements.

Exam trap

The trap here is that candidates often mistake 'CodeDeployDefault.MinHealthyHostsPercentage: 90' for a predefined deployment configuration. In reality, the only predefined configurations are CodeDeployDefault.OneAtATime, CodeDeployDefault.HalfAtATime, and CodeDeployDefault.AllAtOnce. 'MinHealthyHostsPercentage' is a parameter used to define custom configurations, not a standalone predefined name.

How to eliminate wrong answers

Option B (CodeDeployDefault.AllAtOnce) is wrong because it deploys to all 10 instances simultaneously, which can cause a complete outage if the deployment fails or the application has issues. Option C (CodeDeployDefault.HalfAtATime) is wrong because it deploys to 5 instances at a time, which does not guarantee that a minimum number of instances (e.g., 9) are always running; it only ensures half are updated at once, potentially leaving only 5 healthy instances. Option D (CodeDeployDefault.MinHealthyHostsPercentage: 90) is wrong because it is not a valid predefined deployment configuration in AWS CodeDeploy; it is a custom configuration option that can be set via the API or CLI, but it is not a built-in named configuration like the others.

771
MCQeasy

A developer is encrypting an S3 bucket using server-side encryption with AWS KMS (SSE-KMS). What is a benefit of using SSE-KMS over SSE-S3?

A.Reduced latency for encrypted object retrieval
B.Lower cost than SSE-S3
C.Ability to control access to the encryption key separately
D.Automatic encryption of objects at rest
AnswerC

SSE-KMS provides enhanced security by allowing the encryption key, known as a Customer Master Key (CMK), to be managed independently within AWS KMS. Access to these CMKs is governed by dedicated key policies and IAM policies, enabling granular control over who can use the key for cryptographic operations, separate from S3 bucket permissions. This distinct management allows for a robust separation of duties, ensuring that access to data and access to its encryption key are controlled and auditable independently.

Why this answer

SSE-KMS allows you to use AWS KMS customer master keys (CMKs) to encrypt objects, giving you control over key access through KMS key policies and IAM. This separation of key management from data management is a key benefit over SSE-S3, where AWS manages the keys entirely. Thus, the ability to control access to the encryption key separately is the correct benefit.

Exam trap

DVA-C02 often tests the differences between S3 encryption options. Candidates may think SSE-KMS is always faster or cheaper, but it actually adds latency and cost due to KMS operations. The key benefit is control and auditability.

How to eliminate wrong answers

Option A is wrong because SSE-KMS can introduce additional latency due to KMS API calls, not reduce it. Option B is wrong because SSE-KMS may incur KMS request costs, making it potentially more expensive than SSE-S3. Option D is wrong because automatic encryption at rest is provided by both SSE-S3 and SSE-KMS; it is not a unique benefit of SSE-KMS.

772
Multi-Selectmedium

A company uses AWS CodePipeline to deploy a web application to an EC2 instance. The deployment often fails because the application is still running when new files are copied. Which THREE actions can be combined to achieve zero-downtime deployments?

Select 3 answers
A.Use AWS CodeDeploy with an in-place deployment configuration.
B.Configure the EC2 instances behind an Auto Scaling group and use a rolling update.
C.Define an AppSpec file that includes 'BeforeInstall' and 'AfterInstall' hooks to stop and start the application.
D.Use AWS CodeBuild to build and deploy the application.
E.Use Amazon Inspector to check the application before deployment.
AnswersA, B, C

AWS CodeDeploy is purpose-built for orchestrating application deployments to various compute services, including EC2 instances. An in-place deployment configuration updates the application directly on existing instances, leveraging lifecycle hooks to manage the application's state during the update. This ensures the new version is installed correctly and the application's availability is maintained, making it a direct solution for deploying a web application.

Why this answer

AWS CodeDeploy with an in-place deployment configuration can be combined with lifecycle hooks (such as BeforeInstall and AfterInstall) to stop the application before new files are copied and start it afterward, enabling zero-downtime deployments when properly orchestrated with a load balancer to drain traffic. Option B is correct because configuring EC2 instances behind an Auto Scaling group with a rolling update allows new instances to be launched with the updated application while old instances are terminated, ensuring continuous service availability. Option C is correct because defining an AppSpec file with BeforeInstall and AfterInstall hooks provides the mechanism to gracefully stop and start the application, preventing file conflicts and downtime.

Exam trap

The trap here is that candidates often confuse CodeBuild (a build service) with a deployment tool, or assume Amazon Inspector (a security scanner) can manage deployment workflows, when in fact only CodeDeploy and Auto Scaling groups provide the necessary lifecycle hooks and traffic management for zero-downtime updates.

773
MCQeasy

A company stores sensitive customer data in Amazon S3. The security policy requires that all data be encrypted at rest using server-side encryption with a customer-managed AWS KMS key. Which S3 server-side encryption option should the developer use?

A.SSE-S3
B.SSE-KMS
C.SSE-C
D.Client-side encryption
AnswerB

SSE-KMS utilizes AWS Key Management Service (KMS) to manage encryption keys, allowing customers to use either AWS-managed KMS keys or customer-managed keys (CMKs). This method provides a robust audit trail through AWS CloudTrail for key usage and enables granular access control policies on the keys themselves. It directly supports the requirement for customer-managed encryption keys by integrating with KMS, offering control over key lifecycle and permissions.

Why this answer

SSE-KMS is the correct option because it provides server-side encryption with a customer-managed AWS KMS key, allowing the company to control key rotation, access policies, and audit usage via AWS CloudTrail. This meets the security policy requirement for encryption at rest using a customer-managed key, which SSE-S3 (using AWS-managed keys) and SSE-C (using customer-provided keys) do not fulfill.

Exam trap

The trap here is that candidates often confuse SSE-KMS with SSE-S3, assuming both use AWS-managed keys, but SSE-KMS uniquely supports customer-managed keys and additional control features like key rotation and audit logging.

How to eliminate wrong answers

Option A (SSE-S3) is wrong because it uses AWS-managed keys, not customer-managed keys, so it does not meet the policy requirement for customer control over the encryption key. Option C (SSE-C) is wrong because it requires the customer to provide their own encryption keys in each request, and AWS does not manage or store the key, which contradicts the requirement for a customer-managed AWS KMS key. Option D (Client-side encryption) is wrong because it encrypts data before sending it to S3, not at rest on the server side, and does not use S3 server-side encryption at all.

774
MCQeasy

A developer is building a web application that must encrypt data in transit. Which AWS service should be used to manage SSL/TLS certificates?

A.AWS KMS
B.AWS Secrets Manager
C.AWS CloudHSM
D.AWS Certificate Manager (ACM)
AnswerD

AWS Certificate Manager (ACM) is the correct service for encrypting a web application because it fully automates the provisioning, management, and deployment of public and private SSL/TLS certificates. ACM handles the complex processes of certificate issuance, renewal, and binding to integrated AWS services like Elastic Load Balancers, CloudFront distributions, and API Gateways. This ensures secure, encrypted communication for web applications without manual intervention, simplifying certificate lifecycle management significantly.

Why this answer

AWS Certificate Manager (ACM) is the correct service because it is specifically designed to provision, manage, and deploy public and private SSL/TLS certificates for use with AWS services (e.g., Elastic Load Balancers, CloudFront, API Gateway). It handles the full lifecycle of certificates, including renewal, which directly addresses the requirement to encrypt data in transit using HTTPS.

Exam trap

The trap here is that candidates often confuse AWS KMS (used for encryption keys for data at rest) with SSL/TLS certificate management for data in transit, leading them to select KMS instead of ACM.

How to eliminate wrong answers

Option A is wrong because AWS KMS is a key management service for symmetric and asymmetric encryption keys used for data at rest, not for managing SSL/TLS certificates for data in transit. Option B is wrong because AWS Secrets Manager is designed to rotate and manage secrets such as database credentials and API keys, not SSL/TLS certificates. Option C is wrong because AWS CloudHSM provides dedicated hardware security modules for generating and storing encryption keys, but it does not manage SSL/TLS certificates or integrate directly with AWS services for automatic certificate deployment and renewal.

775
Drag & Dropmedium

Drag and drop the steps to authenticate a user using Amazon Cognito User Pools in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First create the user pool and app client, then authenticate to receive tokens, and use tokens for authorization.

776
MCQhard

A developer is building a REST API using Amazon API Gateway and AWS Lambda. The API receives a large number of requests with duplicate payloads from the same client within a short time window. To reduce Lambda invocations and improve performance, the developer wants to return the previously computed response for identical requests based on a unique client ID in the header. How can the developer achieve this using API Gateway features?

A.Enable API Gateway caching on the stage and configure the client ID header as a cache key parameter. Set a cache TTL of 5 minutes.
B.Configure a usage plan with a quota and throttle settings to limit requests per client ID.
C.Use request validation to reject requests that have the same client ID within 5 minutes.
D.Reduce the Lambda function's batch size to 1 and implement caching logic inside the function using an external cache like ElastiCache.
AnswerA

API Gateway caching uses cache key parameters to index responses. By including the client ID header in the cache key, different clients get separate cached responses. The TTL controls how long the response is cached.

Why this answer

API Gateway caching allows you to store responses for a configurable TTL and use the client ID header as a cache key parameter. This means that when a request with the same client ID arrives within the TTL window, API Gateway returns the cached response directly without invoking the Lambda function, reducing invocations and improving performance.

Exam trap

The trap here is that candidates may confuse API Gateway caching (which returns cached responses for identical cache keys) with usage plans or throttling (which only limit request rates) or with Lambda-level caching (which still incurs invocation costs).

How to eliminate wrong answers

Option B is wrong because usage plans with quota and throttle settings limit the rate or total number of requests, but they do not return previously computed responses for duplicate payloads; they simply reject or delay requests. Option C is wrong because request validation in API Gateway only checks the structure and presence of required headers or body fields, not the content or duplication of payloads; it cannot reject requests based on a client ID being repeated. Option D is wrong because reducing the Lambda batch size to 1 is irrelevant (Lambda functions process one event at a time by default) and implementing caching inside the function with ElastiCache would still invoke Lambda for every request, missing the goal of reducing invocations; API Gateway caching avoids Lambda invocation entirely for cached responses.

777
MCQeasy

A developer needs to securely store database credentials used by an application running on EC2. Which AWS service should be used?

A.AWS Secrets Manager
B.AWS Systems Manager Parameter Store
C.Amazon S3
D.AWS Certificate Manager (ACM)
AnswerA

AWS Secrets Manager is the optimal choice for securely storing and managing database credentials because it is purpose-built for secrets lifecycle management. It offers robust features such as automatic rotation of credentials, integration with various AWS databases like Amazon RDS, and fine-grained access control through AWS Identity and Access Management (IAM). This service ensures that credentials are automatically updated without requiring manual intervention, significantly enhancing security posture and reducing the risk of compromise.

Why this answer

AWS Secrets Manager is the correct choice because it is purpose-built for securely storing, rotating, and managing database credentials and other secrets throughout their lifecycle. It offers automatic rotation of credentials for Amazon RDS, Redshift, and DocumentDB with built-in integration, and it encrypts secrets at rest using AWS KMS. For an EC2 application, Secrets Manager can be accessed via the AWS SDK or CLI using IAM roles attached to the EC2 instance, ensuring credentials are never hardcoded or stored in plaintext.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store with Secrets Manager because both can store secrets, but Parameter Store does not support automatic rotation for database credentials, which is a key requirement for securely managing database credentials in production.

How to eliminate wrong answers

Option B is wrong because AWS Systems Manager Parameter Store is a hierarchical store for configuration data and secrets, but it lacks native automatic rotation for database credentials and does not provide the same level of integration with RDS or other database services as Secrets Manager. Option C is wrong because Amazon S3 is an object storage service designed for storing files and static data, not for securely managing sensitive credentials with built-in rotation and access control via IAM policies. Option D is wrong because AWS Certificate Manager (ACM) is specifically for managing SSL/TLS certificates, not for storing database credentials or other secrets.

778
MCQhard

A developer is deploying a microservices application using Amazon ECS with Fargate. The application consists of multiple services that need to communicate with each other over HTTP. The developer wants to ensure that service-to-service communication is encrypted in transit and that the services can discover each other by logical service names instead of IP addresses. Which combination of AWS services should the developer use?

A.Elastic Load Balancing with AWS Systems Manager
B.Amazon Route 53 with AWS Direct Connect
C.AWS Lambda with Amazon API Gateway
D.AWS App Mesh with AWS Cloud Map
AnswerD

AWS App Mesh is a service mesh that provides application-level networking to make it easy to run microservices, offering capabilities like mutual TLS (mTLS) for secure communication, traffic routing, and observability. AWS Cloud Map is a cloud resource discovery service that allows developers to register and discover application resources, such as microservices, using custom names. Together, App Mesh leverages Cloud Map for dynamic service discovery, enabling secure, observable, and resilient inter-service communication within a microservices architecture, directly addressing the requirements for mTLS and service discovery.

Why this answer

AWS App Mesh provides a service mesh that handles service-to-service communication with encryption in transit using TLS, while AWS Cloud Map enables service discovery by logical names, allowing ECS services to resolve each other via DNS or API calls. Together, they meet the requirements for encrypted HTTP communication and logical name resolution without exposing IP addresses.

Exam trap

The trap here is that candidates often confuse service discovery with load balancing or serverless APIs, overlooking that App Mesh provides both encrypted service mesh and Cloud Map for logical name resolution, which is the exact combination needed for secure, discoverable inter-service communication.

How to eliminate wrong answers

Option A is wrong because Elastic Load Balancing handles traffic distribution but does not provide service discovery by logical names or built-in encryption for service-to-service communication, and AWS Systems Manager is for operational management, not service mesh. Option B is wrong because Amazon Route 53 can provide DNS-based service discovery, but AWS Direct Connect is a dedicated network connection to on-premises, not relevant for service-to-service encryption or discovery within ECS. Option C is wrong because AWS Lambda and Amazon API Gateway are for serverless API backends, not for managing inter-service communication and discovery in a microservices architecture on ECS.

779
Multi-Selectmedium

Which TWO statements are true about AWS CodeDeploy deployment groups? (Choose two.)

Select 2 answers
A.A deployment group can only target a single EC2 instance.
B.A deployment group can use an Auto Scaling group as its target.
C.A deployment group can be shared across multiple CodeDeploy applications.
D.A deployment group is a collection of deployment targets for an application.
E.A deployment group cannot be associated with a load balancer.
AnswersB, D

A deployment group can indeed use an Auto Scaling group as its target, which is a fundamental capability of AWS CodeDeploy. This integration ensures that any EC2 instances launched by the Auto Scaling group, whether due to scaling events or instance replacements, automatically receive the latest application revision. This mechanism is crucial for maintaining application consistency and availability in dynamic, scalable environments.

Why this answer

Option B is correct because a CodeDeploy deployment group can target an Auto Scaling group, allowing deployments to scale across the instances managed by that group. Option D is correct because a deployment group is fundamentally defined as a set of deployment targets (such as EC2 instances, on-premises instances, Lambda functions, or ECS services) associated with a single CodeDeploy application. Option A is incorrect because a deployment group can contain many instances, not just one.

Option C is incorrect because a deployment group belongs to exactly one CodeDeploy application and cannot be shared across multiple applications. Option E is incorrect because a deployment group can be associated with a load balancer to manage traffic during deployments.

Exam trap

The trap here is that candidates often confuse deployment groups with being application-specific and think they can be shared across applications, or they incorrectly assume that deployment groups are limited to single instances or cannot integrate with load balancers.

780
MCQhard

A developer is designing a serverless application that uses Amazon API Gateway and AWS Lambda. The application needs to handle a sudden spike in traffic. The Lambda function performs CPU-intensive operations. What should the developer do to ensure the application scales without errors?

A.Set the API Gateway throttling limits to a high value.
B.Use an Amazon SQS queue to buffer requests before processing.
C.Configure the Lambda function with reserved concurrency and provisioned concurrency.
D.Increase the Lambda function timeout to the maximum value.
AnswerC

Configuring a Lambda function with reserved concurrency guarantees a specific number of concurrent executions are always available for that function, preventing other functions from consuming its capacity and ensuring it can scale. Provisioned concurrency goes further by pre-initializing a specified number of execution environments, ensuring that invocations within this limit experience significantly reduced latency by eliminating cold starts. Together, these settings provide dedicated capacity and optimize startup performance.

Why this answer

Reserved concurrency guarantees that the Lambda function has a dedicated pool of concurrency available to handle traffic spikes without being throttled by other functions in the account, while provisioned concurrency pre-warms execution environments to eliminate cold starts for CPU-intensive operations. This combination ensures that the application scales smoothly under sudden load without encountering Lambda throttling errors (HTTP 429) or latency spikes from cold starts.

Exam trap

The trap here is that candidates often confuse API Gateway throttling (which controls request rate at the API level) with Lambda concurrency management, leading them to pick Option A, when the real bottleneck is Lambda's concurrency limits and cold starts for CPU-intensive functions.

How to eliminate wrong answers

Option A is wrong because setting API Gateway throttling limits to a high value only controls the request rate at the API layer, not the Lambda concurrency; if Lambda concurrency limits are exceeded, requests will still be throttled with 429 errors regardless of API Gateway settings. Option B is wrong because using an SQS queue to buffer requests introduces asynchronous processing, which is unsuitable for a synchronous API Gateway integration that expects immediate responses; the queue would decouple the request-response cycle and cause timeouts or lost responses. Option D is wrong because increasing the Lambda function timeout to the maximum value (900 seconds) does not address concurrency limits or cold starts; it only allows the function to run longer, which does not prevent throttling errors when traffic spikes exceed the available concurrency.

781
MCQeasy

A developer is building a microservice that needs to invoke another AWS Lambda function and wait for the result to continue processing. Which Lambda invocation type must the developer use to achieve synchronous invocation?

A.RequestResponse
B.Event
C.DryRun
D.None of the above
AnswerA

When a microservice needs to invoke another AWS Lambda function synchronously, the RequestResponse invocation type is used. This causes the invoking client to pause its execution and wait for the target Lambda function to fully execute and return its response payload. The client receives the function's output, including any errors, directly, enabling real-time processing and decision-making based on the invoked function's result.

Why this answer

The RequestResponse invocation type is the correct choice for synchronous invocation of a Lambda function, where the caller waits for the function to execute and receive a response. This is the default invocation type when using the Invoke API with InvocationType set to 'RequestResponse', and it is required for microservices that need to block until the downstream Lambda returns a result.

Exam trap

The trap here is that candidates may confuse the Event invocation type (asynchronous) with synchronous behavior, or mistakenly think DryRun is a valid Lambda invocation type, leading them to select 'None of the above' when they don't recognize RequestResponse as the correct term.

How to eliminate wrong answers

Option B is wrong because the Event invocation type is asynchronous; it queues the invocation and returns immediately with an HTTP status code of 202, without waiting for the function to execute or return a result. Option C is wrong because DryRun is not a valid Lambda invocation type; it is a parameter used with other AWS services (e.g., EC2) to test permissions without executing the action. Option D is wrong because 'None of the above' is incorrect since RequestResponse is a valid and correct invocation type for synchronous invocation.

782
MCQeasy

A developer is deploying a serverless application using the AWS Serverless Application Model (SAM). The application consists of an API Gateway endpoint and an AWS Lambda function. The developer wants to define a stage name for the API Gateway deployment. Which section of the SAM template should the developer use?

A.Globals
B.Conditions
C.Outputs
D.Parameters
AnswerA

The `Globals` section in an AWS SAM template is specifically designed to define common properties that apply to all resources of a particular type within the template. For API Gateway resources, setting `Api.StageName` within the `Globals` section ensures that every API defined in the template will automatically use the specified stage name. This approach centralizes the configuration, making it efficient for a developer to apply a consistent stage name across all APIs in a serverless application.

Why this answer

The `Globals` section in an AWS SAM template allows you to define shared configuration settings that apply to all resources in the template. For API Gateway, you can set properties like `StageName` under `Globals.Api`, which will be inherited by all API Gateway resources defined in the template, ensuring consistent stage naming without repeating the configuration.

Exam trap

The trap here is that candidates often think stage names must be defined directly on the API Gateway resource (e.g., under `Properties` of `AWS::Serverless::Api`), but the `Globals` section is the correct and more efficient way to set shared API Gateway properties like `StageName` across the entire template.

How to eliminate wrong answers

Option B is wrong because the `Conditions` section is used to define conditions that control whether certain resources are created or properties are set, not to define API Gateway stage names. Option C is wrong because the `Outputs` section is used to declare values that are returned after the stack is created (e.g., API endpoint URLs), not to configure deployment properties like stage names. Option D is wrong because the `Parameters` section is used to accept custom input values at deployment time (e.g., environment names), but it does not directly define a stage name for API Gateway; you would still need to reference a parameter in the resource or Globals section to set the stage name.

783
MCQmedium

A developer is using Amazon API Gateway to expose a Lambda function as a REST API. The Lambda function queries an Amazon RDS database. Under heavy load, the database connection pool is exhausted, causing errors. What is the BEST way to manage database connections in this serverless architecture?

A.Migrate the database to Amazon DynamoDB.
B.Increase the concurrency limit of the Lambda function.
C.Use Amazon RDS Proxy to pool and share database connections.
D.Use Amazon ElastiCache to cache database connections.
AnswerC

Amazon RDS Proxy is specifically designed to manage and pool database connections for Amazon RDS. It acts as an intermediary, maintaining a pool of established connections to the RDS database and reusing them across multiple Lambda function invocations. This significantly reduces the overhead of opening and closing connections, preventing connection exhaustion and improving application scalability and responsiveness.

Why this answer

Amazon RDS Proxy sits between Lambda and RDS, managing a pool of database connections that can be reused across multiple concurrent Lambda invocations. This prevents connection exhaustion under heavy load without requiring code changes, as the proxy handles connection multiplexing and keeps idle connections warm.

Exam trap

The trap here is that candidates confuse connection pooling with caching (ElastiCache) or assume scaling Lambda concurrency will solve the issue, when in fact it exacerbates the connection exhaustion problem.

How to eliminate wrong answers

Option A is wrong because migrating to DynamoDB changes the database paradigm entirely, which is not a connection management solution and may not be feasible for existing relational workloads. Option B is wrong because increasing Lambda concurrency would actually worsen the problem by allowing more concurrent invocations to compete for the same limited pool of database connections. Option D is wrong because ElastiCache caches data, not database connections; it cannot pool or share TCP connections to RDS.

784
MCQeasy

A developer is troubleshooting an AWS CloudFormation stack creation failure. The stack creation failed with the error: 'Resource creation cancelled'. What does this error typically indicate?

A.The IAM user does not have permission to create the resource.
B.Another resource in the stack failed, causing a rollback.
C.The template has a syntax error.
D.The resource type is not supported by CloudFormation.
AnswerB

When a CloudFormation stack creates multiple resources, these operations often occur in parallel or a defined sequence. If one resource fails to create or update successfully, CloudFormation's default behavior is to initiate a rollback of the entire stack to its previous stable state. During this rollback, any resources that were in the process of being created or updated, but had not yet failed themselves, will have their operations terminated, resulting in a "Resource creation cancelled" status. This indicates an orchestrated termination rather than an individual resource failure.

Why this answer

'Resource creation cancelled' is CloudFormation's generic message when a resource's creation is aborted because another resource in the same stack failed and CloudFormation initiated a rollback. By default, stack creation uses rollback-on-failure, so once any resource fails, all in-progress creations are cancelled and successfully created resources are deleted. The error is a symptom of a sibling resource failure, not a problem with the cancelled resource itself.

Exam trap

DVA-C02 often tests whether candidates recognize that 'Resource creation cancelled' is a downstream symptom of rollback, not a root-cause error — candidates incorrectly blame IAM or syntax instead of finding the first resource that actually failed.

How to eliminate wrong answers

Option A is wrong because missing IAM permissions produce an 'Access Denied' or 'not authorized to perform' error on the specific resource, not 'Resource creation cancelled'. Option C is wrong because template syntax errors are caught during validation and return 'Template format error' or 'YAML not well-formed' before any resource provisioning begins. Option D is wrong because an unsupported resource type yields 'Resource type X is not supported' or 'Invalid resource type' during template validation, not a cancellation message.

785
MCQhard

A developer is troubleshooting an Amazon API Gateway REST API that returns 504 Gateway Timeout errors for certain requests. The backend is a Lambda function that performs a resource-intensive operation that occasionally takes up to 30 seconds. API Gateway has a default integration timeout of 29 seconds. The developer cannot reduce the execution time. What should the developer do to resolve the timeout issue?

A.Increase the API Gateway integration timeout to 30 seconds.
B.Refactor the Lambda function to use asynchronous invocation, return a 202 immediately, and have the client poll for results.
C.Enable API Gateway caching to avoid repeated calls.
D.Use multiple Lambda functions to parallelize processing.
AnswerB

Refactoring the Lambda function to use asynchronous invocation, returning a 202 immediately, and having the client poll for results is the correct approach for long-running operations. This pattern decouples the synchronous API Gateway request from the extended backend processing, allowing API Gateway to respond promptly with a 202 Accepted status. The Lambda function can then trigger an asynchronous workflow (e.g., via SQS, SNS, or directly invoking another Lambda asynchronously) and store results for the client to retrieve later through a separate polling mechanism, effectively bypassing the 29-second timeout.

Why this answer

It decouples the client from the long-running Lambda execution. By invoking the Lambda asynchronously, the API Gateway can return a 202 Accepted response immediately, well within the 29-second integration timeout. The client then polls a separate endpoint (e.g., using a presigned S3 URL or a DynamoDB status record) to retrieve the final result, completely sidestepping the timeout limitation.

Exam trap

The trap here is that candidates assume the integration timeout is configurable to any value, but AWS enforces a hard 29-second limit for REST APIs, making Option A technically impossible.

How to eliminate wrong answers

Option A is wrong because Amazon API Gateway has a hard maximum integration timeout of 29 seconds for REST APIs (and 30 seconds for HTTP APIs). You cannot increase it beyond that limit, so setting it to 30 seconds is not possible. Option C is wrong because caching only serves previously computed responses for identical requests; it does not reduce the execution time of a new, uncached request that still takes up to 30 seconds.

Option D is wrong because parallelizing the Lambda function does not reduce the total execution time of a single resource-intensive operation; the request still waits for all parallel tasks to complete, which can still exceed the 29-second timeout.

786
MCQmedium

A company wants to enforce that all uploads to an Amazon S3 bucket must be encrypted using server-side encryption. The developer needs to write an IAM policy condition that denies any s3:PutObject request that does not include the server-side encryption header. Which IAM condition key should be used?

A.s3:x-amz-server-side-encryption
B.s3:x-amz-server-side-encryption-aws-kms-key-id
C.s3:x-amz-acl
D.s3:x-amz-storage-class
AnswerA

This condition key is used in an S3 bucket policy to evaluate the "x-amz-server-side-encryption" request header. By setting its value to "AES256" or "aws:kms" using a StringEquals operator, you can effectively mandate that all incoming PUT requests must include this header, thereby enforcing server-side encryption for all uploaded objects. This ensures data at rest is protected according to the specified encryption standard.

Why this answer

The `s3:x-amz-server-side-encryption` condition key matches the `x-amz-server-side-encryption` request header, which is used to specify server-side encryption (SSE-S3 or SSE-KMS) for S3 PutObject requests. By denying requests that do not include this header, the policy enforces that all uploads must be encrypted at rest using server-side encryption.

Exam trap

The trap here is that candidates confuse the condition key for requiring encryption (`s3:x-amz-server-side-encryption`) with the key for specifying a particular KMS key (`s3:x-amz-server-side-encryption-aws-kms-key-id`), leading them to pick option B when the question only asks about enforcing the presence of any server-side encryption header.

How to eliminate wrong answers

Option B is wrong because `s3:x-amz-server-side-encryption-aws-kms-key-id` is used to enforce a specific KMS key ID for SSE-KMS, not to require the presence of any server-side encryption header. Option C is wrong because `s3:x-amz-acl` controls access control list settings, not encryption. Option D is wrong because `s3:x-amz-storage-class` controls the storage class (e.g., STANDARD, GLACIER), not encryption.

787
MCQhard

An application stores session data in DynamoDB and must expire sessions automatically after a timestamp. Which feature should be used?

A.DynamoDB global tables
B.DynamoDB transactions
C.DynamoDB export to S3
D.DynamoDB Time to Live
AnswerD

DynamoDB Time to Live (TTL) is the correct solution as it enables automatic, cost-effective deletion of items from a table after a specified timestamp. By designating a numeric attribute (e.g., `expirationTime`) as the TTL attribute, DynamoDB asynchronously removes items once their timestamp value is in the past. This directly fulfills the requirement for expiring session data, reducing storage costs and simplifying application logic by offloading cleanup tasks.

Why this answer

DynamoDB Time to Live (TTL) allows you to define a timestamp attribute per item, and DynamoDB automatically deletes items once that timestamp is reached. This is the ideal feature for expiring session data without requiring custom scan-and-delete logic, reducing cost and operational overhead.

Exam trap

The trap here is that candidates may confuse DynamoDB TTL with DynamoDB Streams or Lambda triggers for cleanup, but TTL is the native, serverless mechanism that requires no custom code for expiration.

How to eliminate wrong answers

Option A is wrong because DynamoDB global tables replicate data across regions for low-latency access and disaster recovery, not for automatic expiration of items. Option B is wrong because DynamoDB transactions provide ACID guarantees for multi-item operations, not scheduled deletion based on time. Option C is wrong because DynamoDB export to S3 is used for point-in-time backups or data lake integration, not for expiring items within the table.

788
MCQeasy

A developer is building a web application that must encrypt data in transit between the client and the server. Which AWS service should be used to offload SSL/TLS termination?

A.Application Load Balancer (ALB)
B.Amazon CloudFront
C.Network Load Balancer (NLB)
D.Amazon Route 53
AnswerA

An Application Load Balancer (ALB) operates at Layer 7 (application layer) and is specifically designed to handle HTTP/HTTPS traffic, making it ideal for web applications. It can offload the CPU-intensive SSL/TLS encryption and decryption process from backend instances, significantly improving their performance and simplifying certificate management. By configuring HTTPS listeners and associating an SSL/TLS certificate, typically from AWS Certificate Manager (ACM), the ALB terminates the secure connection from clients and forwards unencrypted or re-encrypted traffic to targets.

Why this answer

An Application Load Balancer (ALB) is ideal for web applications (HTTP/HTTPS) to offload SSL/TLS termination. It decrypts HTTPS traffic from clients at Layer 7 and forwards it to backend targets, reducing CPU load on application servers and centralizing certificate management via AWS Certificate Manager (ACM). While Network Load Balancer (NLB) also supports TLS termination at Layer 4, ALB is specifically designed for HTTP/HTTPS application-level routing and features.

Exam trap

Candidates often confuse the use cases of ALB and NLB for SSL/TLS termination. While both can terminate SSL/TLS, ALB operates at Layer 7 (HTTP/HTTPS) and is the standard choice for web applications requiring content-based routing, whereas NLB operates at Layer 4 (TCP/UDP/TLS) for ultra-high performance or static IP requirements.

How to eliminate wrong answers

Option B (Amazon CloudFront) is wrong because CloudFront is a content delivery network (CDN) that caches content at edge locations; while it can terminate SSL/TLS, its primary purpose is not to offload termination for a single web application but to accelerate delivery globally, and it does not function as a load balancer for backend targets. Option C (Network Load Balancer) is wrong because NLB operates at Layer 4 (TCP/UDP) and does not terminate SSL/TLS; it can pass through TLS traffic to targets but cannot decrypt it, so it cannot offload termination. Option D (Amazon Route 53) is wrong because Route 53 is a DNS service that resolves domain names to IP addresses; it has no capability to terminate SSL/TLS or handle HTTPS traffic.

789
MCQhard

A developer is using AWS CodeBuild to build a Java application. The build fails with 'OutOfMemoryError: Java heap space'. How can the developer fix this without changing the source code?

A.Add -Xmx1024m to the buildspec commands
B.Change the build image to a smaller one
C.Set the memory parameter in the build project
D.Increase the compute type of the build project
AnswerD

Increasing the compute type of the CodeBuild project is the correct solution for a Java application encountering a heap space error. CodeBuild compute types, such as BUILD_GENERAL1_MEDIUM or BUILD_GENERAL1_LARGE, provide progressively more CPU and, crucially, more memory to the build environment. By selecting a higher compute type, the underlying container running the build will have access to a larger pool of RAM, directly addressing the "out of heap space" issue by allowing the Java Virtual Machine to allocate more memory for the build process.

Why this answer

AWS CodeBuild allows you to increase the compute type (e.g., from BUILD_GENERAL1_SMALL to BUILD_GENERAL1_MEDIUM or LARGE), which provides more memory and CPU resources. This directly addresses the 'OutOfMemoryError: Java heap space' by giving the JVM more physical memory to work with, without requiring any source code changes.

Exam trap

The trap here is that candidates confuse the JVM's -Xmx flag (a code-level fix) with the infrastructure-level memory allocation controlled by the CodeBuild compute type, and incorrectly assume a 'memory parameter' exists as a separate setting in CodeBuild.

How to eliminate wrong answers

Option A is wrong because adding -Xmx1024m to the buildspec commands modifies the build process (a command-line change), which violates the constraint of not changing the source code; also, it only adjusts the JVM heap limit, not the underlying compute resources. Option B is wrong because changing the build image to a smaller one would reduce available memory, worsening the out-of-memory error. Option C is wrong because CodeBuild does not have a configurable 'memory parameter' in the build project settings; memory is tied directly to the compute type selection.

790
Multi-Selecthard

A developer is deploying an application that uses Amazon SQS queues. The messages contain sensitive data that must be encrypted at rest. Which TWO actions should the developer take? (Choose TWO.)

Select 2 answers
A.Encrypt the messages client-side before sending to SQS.
B.Store the messages in an S3 bucket with default encryption instead of using SQS.
C.Configure the SQS queue to use a customer managed KMS key.
D.Enable server-side encryption (SSE) for the SQS queue using AWS KMS.
E.Use AWS CloudHSM to generate and store the encryption keys.
AnswersC, D

Configuring an SQS queue to use a Customer Managed Key (CMK) from AWS Key Management Service (KMS) is a correct approach to enable server-side encryption (SSE) for messages at rest. This option provides enhanced control over the encryption key, allowing developers to define specific key policies, manage key rotation schedules, and audit all key usage through AWS CloudTrail. SQS will then use this CMK to encrypt messages upon receipt and decrypt them automatically when consumers retrieve them, meeting the requirement for encryption at rest.

Why this answer

Configuring an SQS queue to use a customer managed KMS key gives you control over the key lifecycle, including rotation and access policies, while still leveraging AWS KMS for server-side encryption. Option D is also correct because enabling server-side encryption (SSE) for SQS using AWS KMS encrypts messages at rest automatically, without requiring client-side changes. Together, these two actions ensure that sensitive data in SQS messages is encrypted at rest using KMS, meeting the requirement.

Exam trap

The trap here is that candidates often think client-side encryption (Option A) is required for encryption at rest, but SQS SSE with KMS provides server-side encryption at rest without needing to modify the application code, making client-side encryption redundant for this specific requirement.

791
MCQhard

A company uses AWS OpsWorks for configuration management. They want to deploy a new application version to a stack. Which lifecycle event should they use to run deployment scripts?

A.Configure
B.Undeploy
C.Setup
D.Deploy
AnswerD

The "Deploy" event is the correct and designated lifecycle event in AWS OpsWorks for installing or updating an application on an instance. When this event is triggered, OpsWorks executes recipes designed to fetch application code from a specified repository, install necessary dependencies, configure web servers, and start application services. This ensures the application is correctly placed, configured, and made available to users.

Why this answer

The Deploy lifecycle event in AWS OpsWorks is specifically designed to run deployment scripts when you deploy a new application version to a stack. This event occurs after the application code has been installed, allowing you to execute custom scripts for tasks like database migrations, cache clearing, or service restarts. It is the correct choice because it aligns with the deployment phase of the application lifecycle.

Exam trap

The trap here is that candidates confuse the Deploy event with the Setup or Configure events, mistakenly thinking that code deployment happens during initial instance setup or configuration updates, rather than understanding that Deploy is the dedicated event for application version releases.

How to eliminate wrong answers

Option A is wrong because the Configure lifecycle event runs whenever an instance enters or leaves the online state, not for deploying application code; it is used for updating configuration files or adjusting settings based on the stack's current state. Option B is wrong because Undeploy is not a standard lifecycle event in AWS OpsWorks; the correct event for removing an application is the Shutdown lifecycle event, which runs when an instance is stopped or terminated. Option C is wrong because the Setup lifecycle event runs only once when an instance is first booted, to install packages and configure the instance, not for deploying new application versions.

792
Multi-Selectmedium

A company uses AWS CodePipeline to deploy a web application. The pipeline has a Source stage (CodeCommit), a Build stage (CodeBuild), and a Deploy stage (CodeDeploy). The developer wants to add a manual approval step before the Deploy stage. Which TWO configurations are required?

Select 2 answers
A.An Amazon SES identity to send emails.
B.An AWS Lambda function to send approval emails.
C.An Amazon CloudWatch alarm to trigger the approval.
D.An IAM role that allows CodePipeline to publish to the SNS topic.
E.An Amazon SNS topic to notify the approver.
AnswersD, E

An IAM role is essential for CodePipeline to interact with other AWS services, including Amazon SNS. The CodePipeline service role must be granted explicit `sns:Publish` permissions to the target SNS topic. Without this specific permission, CodePipeline would lack the necessary authorization to send notification messages to the SNS topic, preventing approvers from being alerted about pending actions.

Why this answer

CodePipeline requires an IAM role with permissions to publish to an SNS topic in order to send notifications for manual approval actions. This role is assumed by CodePipeline to invoke the SNS Publish API, which delivers the approval request message to the configured topic. Without this role, the pipeline cannot notify the approver, and the approval step will fail.

Option E is correct because an SNS topic is the mechanism used to send the approval notification to the approver. The SNS topic is configured in the approval stage of the pipeline, and it publishes a message that is sent to the subscribed approvers (e.g., via email). Both the SNS topic and the IAM role allowing CodePipeline to publish to it are required for the manual approval action to function.

Exam trap

The trap here is that candidates often think an email-sending service like SES or a custom Lambda function is required, but the exam expects you to know that CodePipeline natively integrates with SNS for approval notifications and only needs the correct IAM permissions.

793
MCQhard

A company has a Lambda function that writes to an S3 bucket. The IAM role used by the function has an inline policy allowing s3:PutObject on the bucket. However, writes fail with an access denied error. What is the MOST likely cause?

A.The S3 bucket is in a different region.
B.The S3 bucket uses SSE-KMS encryption and the function lacks kms:Decrypt permissions.
C.The Lambda function does not have the correct execution role.
D.The S3 bucket has a bucket policy that denies the request.
AnswerD

This is the correct explanation because AWS IAM policy evaluation logic dictates that an explicit Deny in any applicable policy always overrides an Allow. Even if the Lambda function's execution role has an Allow statement for s3:PutObject, an explicit Deny statement within the S3 bucket policy will take precedence, resulting in an "Access Denied" error for the request. This mechanism allows resource owners to enforce strict access controls.

Why this answer

Even if the Lambda function's IAM role grants s3:PutObject, an explicit deny in the S3 bucket policy takes precedence over any allow. The access denied error indicates that the request is being evaluated and denied by the bucket policy, which overrides the IAM permission due to AWS's policy evaluation logic (explicit deny > allow).

Exam trap

The trap here is that candidates often assume IAM permissions alone are sufficient and overlook that S3 bucket policies can explicitly deny access, which overrides any IAM allow due to AWS's explicit deny precedence.

How to eliminate wrong answers

Option A is wrong because S3 operations work across regions; a bucket in a different region does not cause an access denied error—it would instead result in a redirect or a different error. Option B is wrong because if SSE-KMS were used, the function would need kms:GenerateDataKey or kms:Encrypt, not kms:Decrypt, and the error would typically be a 403 Forbidden with a KMS-specific message, not a generic access denied. Option C is wrong because the question states the IAM role has an inline policy allowing s3:PutObject, so the execution role is correctly assigned; the error is not due to a missing role but due to a conflicting bucket policy.

794
MCQhard

A developer is tasked with rotating database credentials stored in AWS Secrets Manager for an RDS MySQL instance. The rotation must occur automatically every 30 days. What is the BEST approach?

A.Store the credentials in AWS Systems Manager Parameter Store and use a scheduled Lambda to rotate them.
B.Use RDS automatic password rotation and have the application fetch the new password from RDS.
C.Use an IAM role for the RDS instance and rotate the role's credentials.
D.Configure automatic rotation in Secrets Manager using a rotation Lambda function.
AnswerD

AWS Secrets Manager is specifically designed for managing, retrieving, and rotating secrets, including database credentials. It offers a robust, integrated solution for automatic rotation by leveraging a rotation Lambda function. This function, either pre-built by AWS or custom, connects to the database, updates the user's password, and then updates the secret in Secrets Manager, ensuring applications always retrieve the current, rotated credentials securely.

Why this answer

Secrets Manager natively supports automatic rotation via a Lambda rotation function, and for RDS MySQL it provides a built-in rotation template that handles the two-step process of creating a new password and updating both the database and the secret. Configuring rotation with a 30-day schedule is a single setting in the console or CLI. This is the purpose-built, lowest-effort solution.

Exam trap

DVA-C02 often tests the misconception that Parameter Store or RDS itself handles credential rotation, when the correct answer is Secrets Manager's built-in rotation Lambda.

How to eliminate wrong answers

Option A is wrong because Parameter Store does not natively support rotation — you would have to build and maintain a custom Lambda, which is more work and less secure than the managed Secrets Manager rotation. Option B is wrong because RDS does not have an 'automatic password rotation' feature that the application can fetch from; RDS manages the master password only at creation or manual modification. Option C is wrong because IAM roles are for AWS API authentication, not for database user credentials — rotating an IAM role does not rotate the MySQL user's password.

795
Multi-Selectmedium

A developer is designing a system that ingests high-volume data from IoT devices. The data must be processed in near real-time and then stored in Amazon S3 for analytics. Which TWO AWS services should the developer use together to meet these requirements? (Choose TWO.)

Select 2 answers
A.Amazon SQS
B.Amazon SNS
C.Amazon Kinesis Data Streams
D.Amazon EC2
E.AWS Lambda
AnswersC, E

Amazon Kinesis Data Streams is a fully managed, scalable service specifically designed for ingesting and processing large streams of data records in real time. It provides durable storage for up to 7 days, allowing multiple consumers to process the same data concurrently and independently. This makes it ideal for applications requiring real-time analytics, log aggregation, and continuous data ingestion from various sources at high throughput.

Why this answer

Amazon Kinesis Data Streams is designed for real-time ingestion of large data streams, such as IoT telemetry, and can capture and store data in shards for up to 365 days. AWS Lambda can be configured as a consumer of the Kinesis stream to process records in near real-time and then write the results to Amazon S3 for analytics. Together, they provide a serverless, scalable pipeline for high-volume IoT data.

Exam trap

The trap here is that candidates often confuse Amazon SQS or SNS as suitable for real-time streaming, but they lack the ordered, replayable, and parallel-consumer capabilities that Kinesis Data Streams provides for high-volume IoT ingestion.

796
Multi-Selecthard

A developer is designing a serverless application that processes streaming data from IoT devices. The application must be able to handle data from millions of devices and store the data in a durable, scalable data store. Which AWS services should the developer use? (Choose THREE.)

Select 3 answers
A.Amazon Kinesis Data Streams
B.Amazon RDS
C.Amazon DynamoDB
D.AWS Lambda
E.Amazon SQS
AnswersA, C, D

Amazon Kinesis Data Streams is purpose-built for ingesting and processing large streams of data records in real time. It can continuously capture gigabytes of data per second from hundreds of thousands of sources, making it ideal for high-velocity IoT data ingestion. Its ability to order records within a shard and provide replayability is crucial for reliable real-time analytics and further processing by downstream services.

Why this answer

Amazon Kinesis Data Streams is designed for real-time streaming of large volumes of data, such as from millions of IoT devices. It can ingest and store data durably for up to 365 days, making it ideal for the ingestion layer of this serverless application.

Exam trap

The trap here is that candidates often confuse Amazon SQS as a streaming ingestion service, but SQS is a message queue for decoupling, not a streaming data store with replay capabilities like Kinesis Data Streams.

797
MCQeasy

A developer is building a serverless application using AWS Lambda. The function needs to access a private S3 bucket in the same AWS account. What is the BEST way to grant the Lambda function access to the bucket?

A.Create an IAM execution role with an S3 access policy and attach it to the Lambda function.
B.Store AWS credentials in environment variables and use them in the function code.
C.Attach an inline IAM policy directly to the Lambda function.
D.Add a bucket policy to the S3 bucket allowing the Lambda function's ARN.
AnswerA

Creating an IAM execution role with an S3 access policy and attaching it to the Lambda function is the standard and most secure method. This role provides the Lambda function with temporary, scoped credentials to interact with other AWS services like S3, adhering to the principle of least privilege. It ensures that the function only has the necessary permissions without exposing sensitive, long-lived credentials.

Why this answer

The correct answer. The best practice for granting an AWS Lambda function access to an S3 bucket in the same account is to create an IAM execution role with a policy that allows the necessary S3 actions, and then attach that role to the Lambda function. This provides temporary credentials via STS, follows the principle of least privilege, and avoids hardcoding credentials.

Option B is incorrect because storing AWS credentials in environment variables is insecure and can lead to accidental exposure. AWS recommends using IAM roles for temporary credentials.

Option C is incorrect because Lambda functions do not support attaching IAM policies directly. Policies must be attached to an IAM role, and that role is assigned to the function.

Option D is incorrect because while a bucket policy could grant access based on the function's ARN, it is not the best approach for same-account access. Using an execution role is more scalable, easier to manage, and follows the principle of least privilege.

798
Multi-Selecthard

A company is using AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment group has a deployment configuration of CodeDeployDefault.AllAtOnce. During a deployment, some instances fail the deployment. Which THREE actions should the developer take to improve the deployment health?

Select 3 answers
A.Increase the minimum number of healthy instances in the Auto Scaling group.
B.Change the deployment configuration to CodeDeployDefault.OneAtATime.
C.Configure a lifecycle hook to run validation tests before the instance is marked as healthy.
D.Use a larger instance type to handle the deployment load.
E.Add an Elastic Load Balancer health check to the deployment group.
AnswersB, C, E

CodeDeployDefault.OneAtATime is a deployment configuration that deploys the application revision to a single instance at a time, pausing between instances to verify that the deployment succeeded. This minimizes the number of instances taken out of service concurrently, so if the new revision fails health checks, only a small fraction of traffic is affected. It also provides an automatic rollback or stop opportunity before the entire fleet is updated.

Why this answer

The correct options are B, C, and E.

Option A is incorrect: Increasing the minimum number of healthy instances in the Auto Scaling group does not affect CodeDeploy's deployment health checks; it only controls ASG scaling behavior.

Option B is correct: Changing the deployment configuration to CodeDeployDefault.OneAtATime reduces risk by deploying to one instance at a time, allowing you to detect and halt failures before affecting more instances.

Option C is correct: Configuring a lifecycle hook to run validation tests ensures that an instance is only marked healthy after passing critical checks, preventing unhealthy instances from receiving traffic.

Option D is incorrect: Using a larger instance type does not address the underlying cause of deployment failures (e.g., script errors, misconfigurations) and is not a direct mechanism to improve deployment health.

Option E is correct: Adding an Elastic Load Balancer health check to the deployment group allows CodeDeploy to verify that instances are healthy before completing the deployment, enabling automatic rollback if checks fail.

799
MCQhard

An application uses Amazon Cognito user pools for authentication. A developer wants to restrict access to an API Gateway endpoint to only authenticated users from a specific user pool. What is the best approach?

A.Attach an IAM policy to the API Gateway resource that allows only the Cognito user pool ARN.
B.Use a Cognito User Pool authorizer in API Gateway.
C.Use an API Gateway resource policy that allows access only from the Cognito user pool.
D.Use a Lambda authorizer that validates the JWT token against the user pool.
AnswerB

The Cognito User Pool authorizer in API Gateway is the purpose-built, native solution for validating JWTs issued by Amazon Cognito User Pools. It automatically inspects the `Authorization` header for a valid JWT, verifies its signature against the user pool's public keys, checks its expiration, and confirms the issuer. Upon successful validation, API Gateway allows the request to proceed to the backend integration, often passing decoded token claims for application use.

Why this answer

A Cognito User Pool authorizer in API Gateway is the native, fully managed way to restrict access to an API endpoint to authenticated users from a specific user pool. It automatically validates the JWT token issued by the user pool and caches the result, requiring no custom code. This approach integrates directly with API Gateway's authorization flow, ensuring only tokens from the specified user pool are accepted.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing a Lambda authorizer (option D) because they think they need custom validation logic, forgetting that API Gateway has a built-in Cognito User Pool authorizer that handles JWT validation natively without any custom code.

How to eliminate wrong answers

Option A is wrong because IAM policies cannot reference a Cognito user pool ARN as a principal or resource for API Gateway; IAM policies control access based on IAM users/roles, not user pool identities. Option C is wrong because API Gateway resource policies control access by source IP, VPC, or AWS account, not by Cognito user pool tokens or user pool ARN. Option D is wrong because while a Lambda authorizer could validate a JWT against a user pool, it is unnecessary overhead and not the 'best approach' when a built-in Cognito User Pool authorizer exists that is simpler, faster, and requires no custom code.

800
MCQmedium

A company runs a production application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application receives high traffic and needs to process incoming HTTP requests, store the request payload in an S3 bucket for auditing, and return a response. The development team uses AWS Lambda to process the payload. The team wants to ensure that the solution is scalable, fault-tolerant, and decoupled. The current approach is to have the EC2 instances send requests directly to the Lambda function via the AWS SDK. However, the team notices that during traffic spikes, some requests are lost and the Lambda function throttles. What should the team do to improve the architecture?

A.Increase the Lambda function's reserved concurrency to the maximum allowed.
B.Place API Gateway in front of Lambda and have EC2 send requests to API Gateway.
C.Use Amazon Kinesis Data Streams instead of Lambda to process the payload.
D.Have the EC2 instances send messages to an Amazon SQS queue, and configure the SQS queue as an event source for the Lambda function.
AnswerD

This solution effectively decouples the EC2 instances (producers) from the Lambda function (consumer) using Amazon SQS as an intermediary buffer. EC2 instances can asynchronously send messages to the SQS queue without waiting for Lambda's immediate response, ensuring messages are not lost even if Lambda is temporarily unavailable or experiencing high load. Lambda can then poll the SQS queue at its own pace, processing messages in batches and automatically scaling its concurrency based on the queue's backlog, which significantly reduces the likelihood of throttling and improves overall system resilience and fault tolerance.

Why this answer

Using Amazon SQS decouples the EC2 instances from the Lambda function, providing a buffer that absorbs traffic spikes and prevents request loss. The SQS queue acts as an event source for Lambda, allowing the function to process messages at its own pace, reducing throttling. Option A is incorrect because increasing reserved concurrency may reduce throttling but does not buffer requests; if the function is still overwhelmed, requests can be dropped.

Option B is incorrect because API Gateway still invokes Lambda synchronously, and throttling can still occur. Option C is incorrect because Kinesis Data Streams is designed for real-time streaming and analytics, not for simple request queuing, and introduces unnecessary complexity.

801
MCQmedium

A developer receives an AccessDenied error when trying to put an object into an S3 bucket using the AWS SDK. The IAM user has an attached policy that grants s3:PutObject on the bucket. What is the MOST likely cause of the error?

A.The request is being throttled by S3.
B.The object key is too long.
C.The AWS SDK version is outdated.
D.The bucket policy explicitly denies the action.
AnswerD

When evaluating permissions, AWS IAM follows a strict order of precedence where an explicit Deny statement always overrides any Allow statement. If a bucket policy contains an explicit Deny for a specific action or principal, that denial takes precedence over any Allow statement present in the requesting IAM user's or role's identity-based policy. This ensures that even if an identity policy grants permission, a resource-based policy can still block access, resulting in an AccessDenied error (HTTP 403).

Why this answer

The most likely cause is that the bucket policy explicitly denies the s3:PutObject action. IAM policies grant permissions, but S3 bucket policies can override them with an explicit deny, which takes precedence over any allow. Since the IAM user already has an attached policy allowing s3:PutObject, the only way to get an AccessDenied error is if a bucket policy explicitly denies the action.

Exam trap

The trap here is that candidates assume an IAM allow is sufficient, forgetting that S3 bucket policies can explicitly deny actions, and that explicit deny always wins over allow.

How to eliminate wrong answers

Option A is wrong because S3 throttling returns a 503 SlowDown error, not an AccessDenied error. Option B is wrong because an overly long object key would cause a 400 Bad Request error, not an AccessDenied error. Option C is wrong because an outdated SDK version might cause compatibility issues or missing features, but it would not result in an AccessDenied error; the error is a permissions issue, not a client version issue.

802
MCQmedium

A developer needs to encrypt secrets such as database passwords used by an application running on EC2. Which AWS service should be used to securely store and rotate these secrets?

A.AWS CloudHSM
B.AWS Secrets Manager
C.AWS KMS
D.AWS Systems Manager Parameter Store
AnswerB

AWS Secrets Manager is purpose-built for securely storing, managing, and retrieving various types of secrets, including database credentials, API keys, and other sensitive data. Its key feature is native integration with services like Amazon RDS, enabling automatic rotation of database passwords on a schedule or on demand. This capability is crucial for enhancing security posture and meeting compliance requirements by regularly changing sensitive credentials.

Why this answer

AWS Secrets Manager is the correct choice because it is specifically designed to securely store, manage, and automatically rotate secrets such as database passwords, API keys, and other credentials. It integrates natively with AWS services like RDS, Redshift, and DocumentDB to enable automatic rotation of secrets without custom code, and it enforces encryption at rest using AWS KMS. This makes it the ideal service for the use case described, where secrets must be both stored securely and rotated automatically.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store with Secrets Manager because both can store secrets, but Parameter Store lacks native automatic rotation, which is the key requirement in this question.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM provides dedicated hardware security modules for cryptographic key storage and operations, but it does not offer a managed service for storing or rotating secrets like database passwords; it is a lower-level key management solution. Option C is wrong because AWS KMS is a key management service that creates and controls encryption keys used to encrypt data, but it does not store secrets or provide automatic rotation of secrets; it only supports automatic rotation of the KMS key itself, not the secret value. Option D is wrong because AWS Systems Manager Parameter Store can store secrets as SecureString parameters with KMS encryption, but it lacks built-in automatic rotation capabilities; any rotation would require custom implementation using AWS Lambda or other automation.

803
MCQmedium

A developer is deploying a containerized application on Amazon ECS with the Fargate launch type. The application needs to read data from an Amazon S3 bucket. The developer wants to follow the principle of least privilege. How should the developer grant the necessary permissions to the ECS tasks?

A.Store AWS access keys as environment variables in the task definition.
B.Create an IAM task role and reference it in the task definition using the 'taskRoleArn' parameter.
C.Create an IAM user and embed its credentials in the container image.
D.Use an S3 bucket policy that grants access based on the security group of the ECS tasks.
AnswerB

Creating an IAM task role and referencing it via the 'taskRoleArn' parameter in the task definition is the recommended and most secure method for granting AWS permissions to containers. ECS automatically injects temporary, frequently rotated credentials into the container's metadata service. This allows applications using the AWS SDK to seamlessly assume the role and access AWS resources without hardcoding any credentials, adhering to the principle of least privilege and secure credential management.

Why this answer

Amazon ECS with the Fargate launch type supports IAM task roles, which allow you to assign an IAM role to the ECS task itself. By referencing the IAM task role in the task definition using the 'taskRoleArn' parameter, the containerized application can securely obtain temporary credentials from the ECS container agent via the AWS STS service, adhering to the principle of least privilege without embedding long-lived credentials.

Exam trap

The trap here is that candidates may confuse IAM roles with IAM users or think that network-level controls like security groups can be used for S3 access, but AWS S3 does not evaluate security groups for authorization; only IAM policies and bucket policies are evaluated.

How to eliminate wrong answers

Option A is wrong because storing AWS access keys as environment variables in the task definition exposes long-term credentials in plaintext, violating the principle of least privilege and increasing the risk of credential leakage. Option C is wrong because embedding IAM user credentials in the container image is a security anti-pattern that hardcodes long-lived secrets, making rotation difficult and violating best practices for container security. Option D is wrong because S3 bucket policies cannot grant permissions based on security groups; security groups are network-level constructs for EC2 instances and are not evaluated by AWS S3 for access control decisions.

804
MCQmedium

A developer needs to allow an EC2 instance to read objects from a specific S3 bucket. Which is the MOST secure way to grant permissions?

A.Store AWS access keys in the EC2 instance's user data
B.Use an S3 bucket policy that allows access from the EC2 instance's public IP
C.Create an IAM role with S3 read permission and attach it to the EC2 instance as an instance profile
D.Attach a security group to the EC2 instance that allows S3 access
AnswerC

This is the secure and recommended method. An IAM role, configured with a trust policy allowing the EC2 service to assume it, grants temporary, frequently rotated credentials to the EC2 instance. By attaching this role via an instance profile, the EC2 instance can make API calls to S3 using these temporary credentials, inheriting the S3 read permissions defined in the role's policy without ever storing static access keys on the instance. This approach adheres to the principle of least privilege and enhances security significantly.

Why this answer

Creating an IAM role with S3 read permission and attaching it to the EC2 instance as an instance profile is the most secure way because it provides temporary, automatically rotated credentials to the instance without storing any long-term secrets. The instance profile delivers credentials via the EC2 instance metadata service (IMDS), and the role's policy can be scoped to only the specific S3 bucket and read actions needed. This eliminates the risk of leaked access keys.

Exam trap

DVA-C02 often tests the misconception that security groups or bucket policies based on IP can grant S3 access — candidates pick those because they sound like network-level controls, but IAM roles with instance profiles are the only secure, credential-free method.

How to eliminate wrong answers

Option A is wrong because storing AWS access keys in user data embeds long-lived credentials in the instance, which are visible in the console and metadata, and cannot be rotated automatically — a major security risk. Option B is wrong because allowing access based on the EC2 instance's public IP is unreliable (IPs change) and insecure (any resource with that IP could access the bucket), and it does not authenticate the instance identity. Option D is wrong because security groups control network traffic (ports/protocols), not IAM permissions — a security group cannot grant S3 read access, and S3 access is authorized by IAM, not network rules.

805
MCQmedium

A developer is implementing an e-commerce application where a purchase operation must deduct inventory and create an order atomically. The inventory and orders are stored in separate DynamoDB tables. Which DynamoDB feature should the developer use to execute these operations as a single, all-or-nothing transaction?

A.DynamoDB Streams
B.DynamoDB Transactions
C.DynamoDB Accelerator (DAX)
D.DynamoDB Global Tables
AnswerB

DynamoDB Transactions, specifically using `TransactWriteItems` or `TransactGetItems`, provide full ACID (Atomicity, Consistency, Isolation, Durability) guarantees for operations involving multiple items within a single table or across multiple tables. For an e-commerce purchase, this ensures that critical related operations, such as deducting inventory from one item and simultaneously creating a new order record, are treated as a single, indivisible unit. If any part of the transaction fails, all changes are rolled back, preventing data inconsistencies.

Why this answer

DynamoDB Transactions provide ACID (Atomicity, Consistency, Isolation, Durability) guarantees across one or more tables within a single AWS account and region. This allows the developer to combine the deduct-inventory and create-order operations into a single all-or-nothing transaction, ensuring that both succeed or both fail without partial updates.

Exam trap

The trap here is that candidates often confuse DynamoDB Streams with transactional capabilities, assuming that capturing changes in order guarantees atomicity, but Streams are asynchronous and cannot enforce all-or-nothing semantics across multiple tables.

How to eliminate wrong answers

Option A is wrong because DynamoDB Streams capture a time-ordered sequence of item-level changes in a table, but they do not provide atomicity or transactional coordination across multiple tables. Option C is wrong because DynamoDB Accelerator (DAX) is an in-memory caching layer that improves read performance but does not offer transactional write capabilities. Option D is wrong because DynamoDB Global Tables provide multi-region replication for disaster recovery and low-latency reads, but they do not enable atomic multi-table transactions within a single region.

806
MCQeasy

A developer is creating an IAM policy to allow an EC2 instance to access an S3 bucket. Which AWS service should the developer use to securely provide credentials to the EC2 instance?

A.Use Amazon Cognito identity pools to generate temporary credentials for the instance.
B.Create an IAM user with access keys and store them on the instance.
C.Create an IAM role and attach it to the EC2 instance profile.
D.Store the AWS access key in AWS Secrets Manager and retrieve it at runtime.
AnswerC

Creating an IAM role and attaching it to an EC2 instance profile is the secure and recommended best practice for granting AWS permissions to an EC2 instance. The instance profile acts as a container for the IAM role, allowing the instance to assume the role and obtain temporary, automatically rotated credentials. These credentials are securely provided through the EC2 instance metadata service, eliminating the need to store static access keys on the instance itself.

Why this answer

IAM roles are designed to be assumed by AWS services like EC2. Instance profiles deliver temporary credentials to the EC2 instance automatically, avoiding hard-coded keys. Option A is incorrect because Cognito identity pools are intended for user identity in mobile/web apps, not for EC2 instances.

Option B is incorrect because storing IAM user access keys on the instance is insecure and not recommended. Option D is incorrect because AWS Secrets Manager is for managing secrets such as database credentials, not for providing credentials to EC2 instances. Option C is the correct approach: create an IAM role with the necessary S3 permissions and attach it to the EC2 instance profile.

807
MCQeasy

A developer is deploying a new version of an application to AWS Elastic Beanstalk. The developer wants to minimize the risk of the new version causing issues in production. The application must remain available during the deployment. Which deployment policy should the developer choose?

A.Rolling
B.All at once
C.Rolling with additional batch
D.Immutable
AnswerD

Immutable deployment creates a new set of instances with the new version in a temporary Auto Scaling group. Once healthy, these instances are moved to the original group, and old instances are terminated. This ensures zero downtime and allows easy rollback if issues occur, minimizing risk.

Why this answer

Immutable deployment is ideal for minimizing risk because it launches a full set of new instances with the updated application version, leaving the original instances untouched until the new ones pass health checks. This provides zero downtime and a safe rollback path. Other policies either cause downtime or do not isolate the new version as thoroughly.

Exam trap

The trap here is confusing rolling with additional batch as providing zero downtime with full safety, but it still updates existing instances and lacks the isolation of immutable deployments.

808
MCQeasy

A developer deploys a new version of an AWS Lambda function using the AWS CLI. After the deployment, the function starts returning errors. The developer needs to quickly revert to the previous version without redeploying. What should the developer do?

A.Use AWS CodeDeploy to automatically roll back the deployment.
B.Update the alias to point to the previous version.
C.Use the AWS CLI to update the function code with the previous code.
D.Delete the current function and recreate it using the previous deployment package.
AnswerB

Updating the alias to point to the previous version is the most effective and fastest method for an instant rollback. AWS Lambda aliases are mutable pointers to specific, immutable function versions. By simply redirecting the alias from the problematic new version to a known stable version, all subsequent invocations through that alias immediately begin using the stable code, ensuring zero downtime and minimal operational overhead.

Why this answer

AWS Lambda versions are immutable, while aliases are mutable pointers to specific function versions. By updating the alias to point to the previous version, the developer can instantly revert traffic to the stable code without any redeployment, as the alias is used as the invocation target (e.g., via the function's ARN with the alias name). This approach leverages Lambda's built-in versioning and alias routing, which is the fastest and safest rollback mechanism.

Exam trap

Candidates often confuse versions and aliases. Remember that Lambda versions are immutable (cannot be changed once published), while aliases are mutable (can be updated to point to different versions). This mutability is what allows for instant rollbacks.

How to eliminate wrong answers

Option A is wrong because AWS CodeDeploy is a separate service for automated deployments, not a built-in Lambda rollback feature; using it would require additional setup and is not the quickest revert method from the CLI. Option C is wrong because updating the function code with the previous code via the AWS CLI would overwrite the current version, effectively redeploying the old code rather than instantly reverting, and it does not leverage versioning. Option D is wrong because deleting and recreating the function is unnecessarily destructive and time-consuming, and it would lose the version history and any associated triggers or configurations.

809
MCQmedium

Refer to the exhibit. A developer created an IAM role for a Lambda function. When the Lambda function invokes, it fails with an access denied error when trying to write logs to CloudWatch Logs. What is the most likely cause?

A.The trust policy does not allow the Lambda service to assume the role.
B.The CloudWatch Logs log group has a resource-based policy that denies the Lambda function.
C.The role lacks a permissions policy that allows CloudWatch Logs actions.
D.The Lambda function is not associated with this role.
AnswerC

The permissions policy attached to an IAM role dictates the specific AWS API actions that the role, once assumed, is authorized to perform. For a Lambda function to successfully send logs to CloudWatch, its execution role must have a permissions policy explicitly allowing actions such as 'logs:CreateLogGroup', 'logs:CreateLogStream', and 'logs:PutLogEvents'. Without these explicit permissions, the function's attempts to interact with CloudWatch Logs will result in an "Access Denied" error, even if the role itself was successfully assumed.

Why this answer

The Lambda function's IAM role must include a permissions policy that grants the `logs:CreateLogGroup`, `logs:CreateLogStream`, and `logs:PutLogEvents` actions. Without these permissions, the Lambda runtime cannot write logs to CloudWatch Logs, resulting in an access denied error. The error occurs at invocation time when the Lambda service attempts to create or write to the log stream on behalf of the function.

Exam trap

Candidates often confuse trust policies with permissions policies, assuming that if the role is assumed successfully, all subsequent API calls will work. However, the trust policy only governs role assumption, not the actions the role can perform.

How to eliminate wrong answers

Option A is wrong because the trust policy is what allows the Lambda service to assume the role; if it were missing or incorrect, the error would be 'Lambda cannot assume the role' rather than an access denied on CloudWatch Logs writes. Option B is wrong because CloudWatch Logs log groups do not have resource-based policies by default; such policies are optional and typically used for cross-account access, not for denying a function that already has the correct role. Option D is wrong because the question states the developer created the role for the Lambda function, implying the function is associated with it; if it were not associated, the error would be about missing execution role or permissions, not specifically CloudWatch Logs access denied.

810
MCQmedium

A company uses AWS CodeDeploy to deploy a web application to an Auto Scaling group. The deployment fails with the error 'The overall deployment failed because too many individual instances failed deployment'. The deployment configuration is CodeDeployDefault.AllAtOnce. What is the most likely cause?

A.The application is not running on the instances before the deployment.
B.The Auto Scaling group has more than 100 instances.
C.The new application revision contains an error that prevents it from running.
D.The deployment group is not associated with the correct Amazon EC2 instances.
AnswerC

If the new application revision contains critical errors, such as incorrect configuration files, missing dependencies, or faulty code that prevents the application from starting or functioning correctly, the CodeDeploy deployment will fail. During an `AllAtOnce` deployment strategy, if the application fails to validate or run on any of the target instances after installation, the entire deployment is marked as failed. This ensures that a broken application is not considered successfully deployed across the fleet.

Why this answer

The error 'too many individual instances failed deployment' with the AllAtOnce deployment configuration indicates that the deployment failed on all instances simultaneously. The most likely cause is that the new application revision contains an error that prevents it from running, such as a syntax error, missing dependency, or misconfiguration. Since AllAtOnce deploys to all instances at once, a faulty revision causes all to fail.

Exam trap

DVA-C02 often tests the misconception that deployment failures are due to infrastructure issues like instance count or association, rather than the application revision itself.

How to eliminate wrong answers

Option A is wrong because if the application is not running before deployment, CodeDeploy would still attempt to deploy and might succeed if the revision is valid; the error is about deployment failure, not pre-existing state. Option B is wrong because Auto Scaling group size limits (e.g., more than 100 instances) are not a typical cause of this error; CodeDeploy supports large deployments. Option D is wrong because if the deployment group is not associated with the correct instances, the deployment would fail to target any instances or target wrong ones, but the error specifically mentions individual instances failed, implying they were targeted.

811
Multi-Selectmedium

Which TWO AWS services can be used to build a serverless event-driven application that processes data from Amazon S3 and stores results in Amazon DynamoDB? (Choose 2.)

Select 2 answers
A.AWS Lambda
B.Amazon Kinesis Data Streams
C.Amazon EC2
D.AWS Step Functions
E.Amazon EMR
AnswersA, D

AWS Lambda is a core serverless compute service that executes code in response to events, such as objects being uploaded to an Amazon S3 bucket. It automatically scales and manages the underlying infrastructure, making it ideal for event-driven architectures where functions are invoked only when needed. This allows developers to build highly scalable and cost-effective solutions without provisioning or managing servers, directly addressing the requirements for a serverless event-driven architecture.

Why this answer

AWS Lambda is correct because it can be triggered directly by S3 events (e.g., ObjectCreated) to process data as soon as it arrives, and it can write the processed results to DynamoDB via the AWS SDK. This creates a fully serverless, event-driven pipeline without provisioning any servers.

Exam trap

The trap here is that candidates often confuse Amazon Kinesis Data Streams as a direct S3 event target, but Kinesis cannot be triggered directly by S3 events and requires an intermediary like Lambda, making it an incorrect choice for a simple serverless event-driven application.

812
MCQmedium

A developer is deploying a new version of a Lambda function using AWS CodeDeploy with a linear canary deployment. The function is part of a serverless application. After the deployment starts, the developer notices that the new version is receiving only 10% of traffic initially, but after 10 minutes, the traffic increases to 100%. What should the developer do to ensure a more gradual traffic shift?

A.Use Lambda function aliases with weighted traffic shifting.
B.Use multiple Lambda function versions and update the alias gradually.
C.Configure AWS CloudFormation to update the Lambda alias.
D.Modify the CodeDeploy deployment configuration to use a linear 10% every 5 minutes instead of canary.
AnswerD

AWS CodeDeploy, when integrated with Lambda, provides robust capabilities for automating gradual deployments. A linear deployment configuration, such as "Linear10PercentEvery5Minutes," precisely matches the requirement for shifting traffic in fixed increments over a defined time period. This strategy allows for careful monitoring during the rollout and automatic rollback if issues are detected, ensuring a controlled and safe deployment process.

Why this answer

The developer is using a canary deployment configuration that shifts 10% of traffic immediately and then waits 10 minutes before shifting to 100%. To achieve a more gradual traffic shift, the developer should modify the CodeDeploy deployment configuration to use a linear 10% every 5 minutes, which will increment traffic by 10% every 5 minutes, taking 50 minutes to reach 100%.

Exam trap

The trap here is that candidates may confuse the built-in CodeDeploy deployment configurations (canary vs. linear) with manual alias weight adjustments, thinking that modifying the alias directly is the correct approach instead of changing the deployment configuration.

How to eliminate wrong answers

Option A is wrong because Lambda function aliases with weighted traffic shifting are used for manual or custom traffic routing, not for controlling the pace of a CodeDeploy deployment. Option B is wrong because using multiple Lambda function versions and updating the alias gradually is a manual process that does not leverage CodeDeploy's built-in deployment configurations for automated traffic shifting. Option C is wrong because configuring AWS CloudFormation to update the Lambda alias does not change the CodeDeploy deployment configuration; CloudFormation can manage the alias but cannot alter the traffic shift pattern defined in the CodeDeploy deployment group.

813
MCQmedium

A developer monitors an AWS Lambda function that processes records from an Amazon SQS queue and writes results to an Amazon DynamoDB table. CloudWatch Logs show that execution time has increased over the past week, and the function frequently times out at the 5-minute timeout. The function's code has not been changed recently. CloudWatch metrics show a high rate of DynamoDBProvisionedThroughputExceededException errors. The DynamoDB table has 5 write capacity units (WCUs). What action will MOST effectively reduce the function's execution time?

A.Increase the Lambda function's timeout to 10 minutes.
B.Increase the write capacity units (WCUs) on the DynamoDB table.
C.Increase the Lambda function's memory allocation to 3008 MB.
D.Use an Amazon SQS FIFO queue instead of a standard queue for the Lambda trigger.
AnswerB

The `DynamoDBProvisionedThroughputExceededException` directly signifies that the DynamoDB table's allocated write capacity units (WCUs) are insufficient to handle the incoming write requests. Increasing the WCUs directly addresses this bottleneck by provisioning more throughput for the table. This action allows DynamoDB to process more writes per second, eliminating throttling, reducing Lambda retries, and consequently speeding up the Lambda function's overall execution time.

Why this answer

The high rate of DynamoDBProvisionedThroughputExceededException errors indicates that the Lambda function is being throttled by DynamoDB due to insufficient write capacity. When writes are throttled, the Lambda function must retry, which increases execution time and can lead to timeouts. Increasing the WCUs on the DynamoDB table directly addresses the root cause by allowing the function to write without throttling, thereby reducing execution time.

Exam trap

The trap here is that candidates often assume increasing Lambda timeout or memory will fix performance issues, but the real bottleneck is the DynamoDB write capacity, which directly causes the throttling errors and increased execution time.

How to eliminate wrong answers

Option A is wrong because increasing the timeout to 10 minutes does not resolve the underlying throttling issue; it only masks the symptom by allowing the function to run longer while still being throttled. Option C is wrong because increasing memory allocation (up to 3008 MB) primarily improves CPU performance and network throughput, but does not fix DynamoDB throttling caused by insufficient WCUs. Option D is wrong because switching to an SQS FIFO queue does not affect DynamoDB write capacity; FIFO queues enforce message ordering and deduplication but do not reduce the throttling rate from DynamoDB.

814
MCQmedium

A developer is building a web application that uses Amazon DynamoDB as the database. The application needs to store user session data and must support eventual consistency reads for most use cases, but strongly consistent reads for critical operations. The developer wants to minimize costs. Which read capacity unit (RCU) configuration should the developer use?

A.Use on-demand capacity mode to pay per request, avoiding provisioned capacity costs.
B.Use provisioned capacity with 1 RCU per item, since eventually consistent reads consume half the RCUs.
C.Use provisioned capacity with sufficient RCUs to handle strongly consistent reads, as they consume the same as eventually consistent.
D.Use provisioned capacity with enough RCUs for peak traffic, and use DynamoDB Accelerator (DAX) for caching.
AnswerA

On-demand capacity mode is optimal for web applications with unpredictable or spiky traffic patterns because it automatically scales capacity up or down based on actual request volume. This pay-per-request model eliminates the need for capacity planning and avoids the costs associated with over-provisioning RCUs and WCUs that sit idle during low traffic periods. Consequently, it often results in significant cost savings for variable workloads, as you only pay for the reads and writes your application actually performs.

Why this answer

On-demand capacity mode charges per request (read/write), eliminating the need to provision fixed RCUs. For a session store with mixed consistency requirements, on-demand is cost-effective when traffic is unpredictable or low, as you only pay for actual reads and writes. Eventually consistent reads consume half the RCUs of strongly consistent reads, but on-demand pricing automatically accounts for this difference without manual configuration.

Exam trap

The trap here is that candidates assume provisioned capacity is always cheaper, but for variable workloads like session stores, on-demand can minimize costs by eliminating unused capacity, especially when mixed consistency models are needed.

How to eliminate wrong answers

Option B is wrong because 1 RCU per item is not a fixed rule; RCU consumption depends on item size (1 RCU = one strongly consistent read of up to 4 KB per second) and eventually consistent reads consume 0.5 RCUs, not a fixed 1 RCU per item. Option C is wrong because strongly consistent reads and eventually consistent reads do not consume the same RCUs; eventually consistent reads use half the RCUs (0.5 RCU per 4 KB item) compared to strongly consistent reads (1 RCU per 4 KB item). Option D is wrong because provisioning for peak traffic with DAX adds cost and complexity; DAX is a caching layer that reduces read load but incurs additional charges, contradicting the goal to minimize costs.

815
MCQmedium

A developer launches an Amazon EC2 instance that needs to read and write data to an Amazon DynamoDB table. The developer must follow the principle of least privilege and ensure that no long-term credentials are stored on the instance. Which approach should the developer use?

A.Create an IAM user with programmatic access, store the access key and secret key in a configuration file on the EC2 instance.
B.Store the DynamoDB credentials in AWS Systems Manager Parameter Store as a SecureString, and retrieve them from the EC2 instance at runtime.
C.Create an IAM role with the necessary DynamoDB permissions, and attach the role to the EC2 instance profile. The SDK will automatically retrieve temporary credentials from the instance metadata.
D.Use a Lambda function to generate temporary credentials for the EC2 instance and pass them via user data at launch.
AnswerC

This is the recommended and most secure method. By attaching an IAM role to the EC2 instance profile, the instance is granted temporary, frequently rotated credentials via the Instance Metadata Service (IMDS). AWS SDKs and CLIs automatically query IMDS for these credentials, eliminating the need to store any long-term access keys directly on the instance. This significantly reduces the attack surface and simplifies credential management.

Why this answer

It uses an IAM role attached to the EC2 instance profile, which allows the AWS SDK to automatically retrieve temporary credentials from the instance metadata service (IMDS). This follows the principle of least privilege by granting only the necessary DynamoDB permissions and eliminates the need to store any long-term credentials on the instance, as the credentials are rotated automatically by AWS STS.

Exam trap

The trap here is that candidates may choose Option B (Parameter Store) thinking it securely stores credentials, but they overlook that the instance still needs an IAM role to access Parameter Store, and the retrieved credentials are static rather than automatically rotated temporary credentials, which fails the 'no long-term credentials' requirement.

How to eliminate wrong answers

Option A is wrong because storing an IAM user's access key and secret key in a configuration file on the EC2 instance violates the requirement of no long-term credentials on the instance and increases the risk of credential exposure. Option B is wrong because while Parameter Store can securely store credentials, the EC2 instance would still need an IAM role or long-term credentials to retrieve them, and the retrieved credentials (if stored as a SecureString) are static, not temporary, thus not fully meeting the 'no long-term credentials' requirement. Option D is wrong because using a Lambda function to generate temporary credentials and passing them via user data at launch would require the instance to store those credentials locally, and the credentials would not be automatically rotated or refreshed, leading to potential security issues and operational complexity.

816
MCQmedium

A service needs loosely coupled asynchronous communication where one producer sends events to many different AWS service targets using rules. Which service fits best?

A.Amazon EFS
B.AWS CloudHSM
C.Amazon EventBridge
D.AWS DataSync
AnswerC

Amazon EventBridge is a serverless event bus service that enables building event-driven architectures by routing events from various sources to targets. It inherently supports loosely coupled asynchronous communication by allowing event producers to publish events without direct knowledge of their consumers, and consumers to subscribe to events without knowing the producers. This abstraction ensures that services can evolve independently, enhancing resilience and scalability as events are processed asynchronously.

Why this answer

Amazon EventBridge is a serverless event bus service that enables loosely coupled asynchronous communication. It allows a single producer to publish events, and then uses rules to route those events to multiple AWS service targets (e.g., Lambda, SQS, Step Functions) simultaneously, fulfilling the requirement exactly.

Exam trap

The trap here is that candidates may confuse Amazon EventBridge with Amazon SNS (Simple Notification Service), but the question explicitly mentions 'rules' to filter events, which is a core EventBridge feature, whereas SNS uses topic subscriptions without rule-based filtering.

How to eliminate wrong answers

Option A is wrong because Amazon EFS is a file storage service for EC2 instances, not an event-driven communication service; it cannot route events or support producer-to-multiple-target patterns. Option B is wrong because AWS CloudHSM provides hardware security modules for cryptographic key storage, not event routing or asynchronous messaging. Option D is wrong because AWS DataSync is a data transfer service for moving large datasets between on-premises and AWS storage, not for event-driven, loosely coupled communication with rules.

817
MCQhard

A developer is building a real-time chat application using WebSockets via API Gateway. The backend uses AWS Lambda functions to handle connect, disconnect, and message events. The application needs to broadcast messages to all connected clients. What is the most scalable and cost-effective way to maintain the list of connection IDs and broadcast messages?

A.Use an SQS FIFO queue to store connection IDs and have a Lambda function poll the queue to broadcast.
B.Store connection IDs in a DynamoDB table. Use a Lambda function to query all connection IDs and send messages using the API Gateway Management API.
C.Maintain an in-memory list of connection IDs in a global variable of a single Lambda function.
D.Use Amazon ElastiCache Redis to store connection IDs and use Redis Pub/Sub for broadcasting.
AnswerB

Storing connection IDs in a DynamoDB table is the robust and scalable solution for managing WebSocket connections with API Gateway. DynamoDB provides a highly available, low-latency, and persistent store for these IDs. When a message needs to be broadcast, a Lambda function can efficiently query the DynamoDB table to retrieve all active connection IDs. It then uses the API Gateway Management API's `PostToConnection` action to send the message to each client, ensuring reliable and scalable real-time communication.

Why this answer

DynamoDB is the canonical serverless store for WebSocket connection IDs in API Gateway WebSocket APIs. Each Lambda handler writes or deletes the connection ID on connect/disconnect, and to broadcast, a Lambda scans or queries the table and calls the API Gateway Management API's PostToConnection for each ID. This scales horizontally and is pay-per-use.

Exam trap

DVA-C02 often tests the misconception that Lambda global variables or in-memory state persist across invocations — candidates pick C, not realizing each concurrent execution gets its own isolated container.

How to eliminate wrong answers

Option A is wrong because SQS FIFO is a queue, not a connection registry — it cannot store the current set of active connections, and polling introduces latency and duplicate-delivery complexity unsuitable for real-time broadcast. Option C is wrong because Lambda execution environments are ephemeral and not shared across concurrent invocations; a global variable only persists within a single warm container and cannot represent all connected clients. Option D is wrong because ElastiCache Redis requires a VPC-attached cluster, adds fixed hourly cost, and is overkill for a simple connection registry — it is not the most cost-effective serverless choice, and Redis Pub/Sub does not integrate natively with API Gateway Management API.

818
MCQhard

A company uses an IAM role to allow an EC2 instance to access an S3 bucket. The bucket policy also grants access to the role. An application running on the instance is unable to read objects. The instance has the correct instance profile. What is the MOST likely cause?

A.The bucket policy has a condition that does not match the request context.
B.The EC2 instance's security group blocks outbound traffic to S3.
C.The S3 bucket is in a different AWS account.
D.The instance profile is not attached to the EC2 instance.
AnswerA

An S3 bucket policy's conditions evaluate specific attributes of an incoming request, such as source IP, VPC endpoint ID, or specific tags. If any condition in an allow statement is not met, or if a condition in a deny statement *is* met, the request will be implicitly or explicitly denied, respectively. Therefore, even if the IAM role attached to the EC2 instance has the necessary S3 permissions, a mismatch with a restrictive bucket policy condition will prevent access.

Why this answer

The most likely cause is that the bucket policy includes a condition (e.g., aws:SourceIp, aws:SourceVpce, or aws:SecureTransport) that does not match the request context from the EC2 instance. Even though the IAM role grants access, the bucket policy's explicit condition denies the request if the condition key evaluates to false, resulting in an implicit deny. This is a common misconfiguration where the role has permissions but the bucket policy's conditions are too restrictive.

Exam trap

The trap here is that candidates often overlook bucket policy conditions and assume that if the IAM role has S3 permissions and the instance profile is attached, access should work, ignoring that bucket policies can impose additional restrictions that override role permissions.

How to eliminate wrong answers

Option B is wrong because security groups operate at the network layer (stateful filtering) and do not block outbound traffic to S3 by default; S3 uses HTTPS (TCP/443) which is typically allowed, and security groups do not inspect application-layer conditions. Option C is wrong because cross-account access is fully supported with proper IAM roles and bucket policies; the bucket being in a different account would not inherently cause failure if permissions are correctly configured. Option D is wrong because the question explicitly states the instance has the correct instance profile, so the instance profile attachment is not the issue.

819
MCQeasy

A developer is debugging an AWS Lambda function that is invoked by an Amazon S3 bucket notification. The function fails with an 'AccessDenied' error when trying to read an object from the same bucket. What should the developer check first?

A.Check if S3 bucket versioning is enabled.
B.Verify that the S3 bucket uses server-side encryption with AWS KMS.
C.Ensure the S3 bucket is not blocked by S3 Block Public Access.
D.Review the Lambda function's execution role for s3:GetObject permission.
AnswerD

An 'AccessDenied' error when an AWS Lambda function attempts to interact with Amazon S3 is most commonly caused by insufficient permissions defined in its IAM execution role. To successfully retrieve an object from S3, the Lambda function's execution role must have an IAM policy that explicitly grants the `s3:GetObject` action on the specific target S3 bucket and object path. This is the foundational security control for S3 object retrieval.

Why this answer

The developer should first review the Lambda function's execution role for s3:GetObject permission. The 'AccessDenied' error indicates the function lacks permission to read the object. The execution role must have an IAM policy granting s3:GetObject on the bucket or object.

This is the most direct cause.

Exam trap

The trap is overthinking encryption or public access blocks, but the most common cause of AccessDenied in Lambda is missing IAM permissions in the execution role.

How to eliminate wrong answers

Option A is wrong because S3 bucket versioning does not affect permissions; it only manages object versions. Option B is wrong because while KMS encryption can cause AccessDenied if the role lacks kms:Decrypt, the question says the error is when trying to read the object, and the most common cause is missing s3:GetObject; KMS is a secondary check. Option C is wrong because S3 Block Public Access prevents public access, but Lambda uses an IAM role, not public access, so it is not relevant.

820
MCQeasy

Refer to the exhibit. A developer created this CloudFormation template for an S3 bucket. What is the expected behavior?

A.Noncurrent versions of objects are deleted 30 days after they become noncurrent.
B.The bucket will have versioning disabled because the rule conflicts.
C.Current versions are transitioned to another storage class after 30 days.
D.Objects are automatically deleted after 30 days.
AnswerA

This statement is correct because an S3 Lifecycle Rule with NoncurrentVersionExpiration configured for 30 days will automatically delete noncurrent object versions. Once a new version of an object is uploaded, the previous version becomes noncurrent, and this rule ensures it is permanently removed from the bucket after 30 days from that point. This helps manage storage costs by cleaning up obsolete data while maintaining version history for a defined period.

Why this answer

The CloudFormation template defines an S3 Lifecycle rule with `NoncurrentVersionExpiration` set to 30 `NoncurrentDays`. This rule specifically targets noncurrent versions of objects, meaning that after an object version becomes noncurrent (e.g., due to a PUT or DELETE of the current version), that noncurrent version will be permanently deleted 30 days later. The `Status: Enabled` ensures the rule is active, and versioning is enabled via the `VersioningConfiguration` property.

Exam trap

The trap here is that candidates confuse `NoncurrentVersionExpirationInDays` with `ExpirationInDays` or `Transition`, leading them to think the rule deletes current versions or transitions objects, when in fact it only applies to noncurrent versions in a versioned bucket.

How to eliminate wrong answers

Option B is wrong because the template includes `VersioningConfiguration: Status: Enabled`, which explicitly enables versioning, and the lifecycle rule does not conflict with versioning—it complements it by managing noncurrent versions. Option C is wrong because the template uses `NoncurrentVersionExpirationInDays`, not `Transition` or `CurrentVersionExpirationInDays`, so it does not transition current versions to another storage class; it only expires noncurrent versions. Option D is wrong because the rule does not delete current versions or all objects after 30 days; it only deletes noncurrent versions after they become noncurrent, and the expiration count starts from when the version becomes noncurrent, not from object creation.

821
MCQhard

Refer to the exhibit. A developer created this IAM policy to allow a CI/CD service to trigger CodePipeline and CodeBuild. However, the pipeline fails with an 'AccessDenied' error when trying to start the CodeBuild project. What is the likely cause?

A.The policy should use 'Effect': 'Deny' for the CodeBuild actions.
B.The policy does not include 'codebuild:StartBuild' for the specific CodeBuild project ARN.
C.The policy must include 'codebuild:BatchGetBuilds' for the specific project.
D.The policy is attached to the developer's IAM user instead of the CodePipeline service role.
AnswerD

AWS CodePipeline, like many other AWS services, operates by assuming an IAM service role to perform actions on its behalf. For CodePipeline to interact with CodeBuild, the necessary permissions (e.g., codebuild:StartBuild, codebuild:BatchGetBuilds) must be attached to CodePipeline's service role. Attaching the policy to a developer's IAM user only grants the user these permissions, not the CodePipeline service itself, leading to permission failures during pipeline execution.

Why this answer

The policy is correctly defined to allow 'codebuild:StartBuild' on all resources, so options B and C are incorrect. Option A is incorrect because using 'Deny' would block the action entirely. The actual cause is that the policy is attached to the developer's IAM user, but CodePipeline requires the permissions to be attached to its service role.

When CodePipeline tries to start the CodeBuild project on behalf of the pipeline, it uses the service role, not the developer's user. Therefore, the policy must be attached to the CodePipeline service role to grant the necessary permissions.

822
MCQeasy

A developer is troubleshooting an Amazon RDS for MySQL instance that is experiencing high CPU utilization. The application performs many read operations. The developer wants to reduce the load on the database. What is the MOST effective solution?

A.Upgrade the DB instance to a larger instance class.
B.Create a read replica and direct read queries to it.
C.Enable Multi-AZ for automatic failover.
D.Purchase reserved instances to reduce costs.
AnswerB

Creating an Amazon RDS read replica asynchronously replicates data from the primary DB instance, allowing read queries to be directed to the replica. This effectively offloads read traffic from the primary instance, significantly reducing its CPU utilization and improving overall database performance. Read replicas are specifically designed to scale read-heavy workloads independently, providing a highly efficient and cost-effective solution.

Why this answer

Creating a read replica allows read queries to be directed to the replica, offloading the read workload from the primary instance and reducing its CPU utilization. Option A is incorrect because upgrading to a larger instance class increases capacity but does not specifically address read-heavy workloads efficiently and is less cost-effective than scaling reads with replicas. Option C is incorrect because Multi-AZ provides high availability and automatic failover, not performance improvement or load reduction.

Option D is incorrect because purchasing reserved instances reduces costs but does not affect CPU utilization.

823
MCQhard

A company is using AWS CodePipeline with a multi-branch strategy. The pipeline includes a source stage from AWS CodeCommit, a build stage using AWS CodeBuild, and a deploy stage using AWS CodeDeploy. The team wants to automatically deploy changes only when a pull request is merged to the 'main' branch. Which configuration should be used?

A.Configure a CodeCommit trigger to start the pipeline on push events to the 'main' branch.
B.Create a manual approval step before deployment and require a pull request merge as a trigger.
C.Use a scheduled trigger to run the pipeline every hour and check for changes.
D.Configure the source stage to use the 'main' branch and enable periodic polling.
AnswerA

Configuring a CodeCommit trigger establishes an event-driven mechanism where CodePipeline automatically starts execution upon detecting a `git push` event to the specified 'main' branch. This includes pushes resulting from direct commits or successful pull request merges, ensuring immediate and efficient pipeline initiation without manual intervention or polling overhead.

Why this answer

Option A is correct because a CodeCommit repository trigger configured for push events on the 'main' branch will start the pipeline exactly when a merge commit is pushed to main, which is the desired behavior for deploying only merged pull requests. This is the standard, event-driven way to integrate CodeCommit with CodePipeline for branch-specific deployments. Option B is wrong because manual approval is a pipeline action that gates a deployment after it has already started, not a trigger mechanism, and it cannot itself detect a pull request merge.

Option C is wrong because hourly scheduled runs are not event-driven and would deploy at arbitrary times, potentially including unmerged or stale changes. Option D is wrong because periodic polling is a legacy change-detection method that does not specifically react to a merge to 'main' and adds latency.

824
MCQeasy

A developer is building a serverless application using AWS Lambda that processes files uploaded to an S3 bucket. The function needs to read the file content and store metadata in DynamoDB. Which AWS service should be used to trigger the Lambda function when a new object is created in S3?

A.Amazon CloudWatch Events
B.Amazon SQS
C.Amazon SNS
D.Amazon S3 Event Notifications
AnswerD

Amazon S3 Event Notifications provide a native, direct, and highly efficient mechanism for triggering AWS Lambda functions in response to specific object-level events, such as object creation, deletion, or restoration. When configured, S3 directly invokes the specified Lambda function asynchronously, passing event details like the bucket name, object key, and event time. This direct integration eliminates the need for intermediary services, making it the most straightforward and performant solution for reacting to S3 object changes.

Why this answer

Amazon S3 Event Notifications (Option D) are the native mechanism for S3 to publish events (e.g., s3:ObjectCreated:*) directly to AWS Lambda, SQS, or SNS when an object is created. This is the simplest and most direct way to trigger a Lambda function for file processing without needing additional services.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing SQS or SNS, thinking they need a decoupling layer, but the question asks for the service that directly triggers the Lambda when an object is created — which is S3 Event Notifications, not a message broker.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Events (now Amazon EventBridge) is used for scheduling or reacting to AWS service events via a rule, but it is not the direct trigger for S3 object creation; you would need S3 to send events to EventBridge, which adds unnecessary complexity. Option B is wrong because Amazon SQS is a message queue that can receive S3 notifications, but it cannot directly invoke a Lambda function; you would need an additional SQS trigger on the Lambda, making it an indirect and less efficient solution. Option C is wrong because Amazon SNS is a pub/sub messaging service that can receive S3 notifications and fan out to subscribers, but it cannot directly invoke Lambda; you would need to subscribe Lambda to the SNS topic, which is an extra hop and not the native integration.

825
MCQeasy

What is required for the Lambda function to access the code in the S3 bucket?

A.The S3 bucket policy must grant access to the Lambda service.
B.The Lambda function must be in a VPC with an S3 VPC endpoint.
C.The S3 bucket must be configured as a static website with CloudFront.
D.The Lambda execution role must have s3:GetObject permission on the S3 bucket.
AnswerD

For an AWS Lambda function to successfully retrieve its deployment package, which is stored as an object in an S3 bucket, the function's associated IAM execution role must possess the necessary permissions. Specifically, the s3:GetObject action is required to allow the Lambda service, acting on behalf of the function, to read the code object from the specified S3 bucket. Without this explicit permission, the Lambda service cannot access the code to initialize and execute the function.

Why this answer

To allow a Lambda function to access AWS resources like an S3 bucket during its execution, it must assume an IAM execution role with the appropriate permissions. To read an object from S3, the execution role must have the `s3:GetObject` permission for the target bucket and object path.

Exam trap

Candidates often confuse the permissions needed by the IAM identity creating/updating the Lambda function (which needs access to the deployment package in S3) with the permissions needed by the Lambda execution role itself (which needs access to resources the function interacts with at runtime).

How to eliminate wrong answers

Option A is wrong because the S3 bucket policy granting access to the Lambda service is not sufficient; the Lambda execution role must also have the necessary IAM permissions, and the bucket policy alone does not authorize the Lambda function's principal. Option B is wrong because placing the Lambda function in a VPC with an S3 VPC endpoint is only required when the Lambda function needs to access S3 without traversing the public internet, but it is not a requirement for the Lambda function to access its own code in S3; the default public S3 endpoint works without a VPC. Option C is wrong because configuring the S3 bucket as a static website with CloudFront is unrelated to Lambda's code retrieval; Lambda downloads the deployment package directly from S3 via the S3 API, not through a website or CloudFront.

Page 10

Page 11 of 16

Page 12