Courseiva

AWS Certified Developer Associate DVA-C02 (DVA-C02) — Questions 826–900

1135 questions total · 16pages · All types, answers revealed

Page 11

Page 12 of 16

Page 13
826
Multi-Selectmedium

A company stores sensitive data in an S3 bucket. The security team requires that all data be encrypted at rest and in transit. Which THREE measures should be implemented?

Select 3 answers
A.Use HTTPS for all requests to S3
B.Enable server-side encryption (SSE) on the S3 bucket
C.Add a bucket policy that denies requests without encryption in transit
D.Use client-side encryption
E.Enable MFA Delete on the bucket
AnswersA, B, C

When accessing S3, using HTTPS (TLS/SSL) encrypts the data as it travels between the client and the S3 service endpoints. This prevents eavesdropping and man-in-the-middle attacks, ensuring the confidentiality and integrity of sensitive data during transmission over public networks. AWS S3 supports HTTPS by default, and it is a fundamental security best practice for protecting data in transit.

Why this answer

HTTPS encrypts data in transit between the client and S3 using TLS, ensuring confidentiality and integrity during transmission. This satisfies the requirement for encryption in transit, as HTTP requests would send data in plaintext.

Exam trap

The trap here is that candidates may confuse client-side encryption as a bucket-level security measure, but it is an application-side implementation that does not enforce encryption at the S3 bucket level, and MFA Delete is a red herring unrelated to encryption requirements.

827
MCQeasy

A developer is deploying a Node.js application to AWS Elastic Beanstalk. The application needs to read environment-specific configuration variables. Which configuration file should the developer use to define these variables within the Elastic Beanstalk environment?

A.package.json
B..ebextensions/*.config
C.Dockerfile
D.buildspec.yml
AnswerB

.ebextensions/*.config files are the correct and recommended approach for customizing and configuring AWS Elastic Beanstalk environments. These YAML or JSON formatted files, placed within the .ebextensions directory at the root of the application source bundle, enable developers to define environment properties, modify EC2 instance settings, install packages, and execute custom commands. Specifically, application environment variables are configured under the 'option_settings' section using the 'aws:elasticbeanstalk:application:environment' namespace.

Why this answer

Ebextensions/*.config files in YAML or JSON format are used to define environment-specific configuration, including environment variables, in Elastic Beanstalk. Option A is wrong because package.json is for Node.js dependencies and cannot set environment variables. Option C is wrong because Dockerfile is for Docker containers, not Elastic Beanstalk configuration.

Option D is wrong because buildspec.yml is used by AWS CodeBuild, not Elastic Beanstalk.

828
MCQmedium

A company uses AWS Elastic Beanstalk to deploy a web application. The developer has updated the application code and wants to deploy the new version with a rolling deployment strategy to minimize downtime. Which configuration should the developer use?

A.Set the deployment policy to 'Rolling'
B.Set the deployment policy to 'Immutable'
C.Set the deployment policy to 'All at once'
D.Set the deployment policy to 'Blue/green'
AnswerA

Setting the deployment policy to 'Rolling' is the correct approach for a rolling deployment strategy in AWS Elastic Beanstalk. This method updates instances in batches, ensuring that a portion of the application's capacity remains available to serve traffic throughout the deployment process. Elastic Beanstalk performs health checks on each batch before proceeding, minimizing downtime and allowing for a gradual, controlled update of the application version across the environment.

Why this answer

The 'Rolling' deployment policy in AWS Elastic Beanstalk updates instances in batches, moving the new application version into a subset of instances while keeping the rest serving traffic, which minimizes downtime by ensuring capacity is never fully reduced. This is the correct choice for a rolling update that balances speed and availability without requiring a full parallel environment.

Exam trap

The trap here is that candidates often confuse 'Rolling' with 'Blue/green' because both aim to reduce downtime, but Blue/green requires a separate environment and is not a rolling deployment within the same environment, while 'Immutable' is mistakenly chosen for its safety despite not being a rolling strategy.

How to eliminate wrong answers

Option B is wrong because 'Immutable' deployment launches a completely new Auto Scaling group with the new version, then swaps it with the old group, which minimizes risk but incurs higher cost and longer deployment time, not specifically minimizing downtime through a rolling approach. Option C is wrong because 'All at once' deploys the new version to all instances simultaneously, causing full downtime during the deployment as all instances are replaced at the same time. Option D is wrong because 'Blue/green' deploys a separate environment (green) alongside the existing one (blue), then swaps the CNAME, which avoids downtime but requires additional infrastructure and is not a rolling deployment strategy.

829
MCQhard

A CodeDeploy deployment to Lambda should shift 10 percent of traffic for 10 minutes before full rollout and automatically roll back on alarms. Which configuration should be used?

A.Canary deployment preference with CloudWatch alarms
B.All-at-once deployment without alarms
C.Manual alias update after deployment
D.S3 static website deployment
AnswerA

A Canary deployment preference with CloudWatch alarms is the correct approach for shifting 10 percent of traffic to a new Lambda version. This strategy allows CodeDeploy to gradually shift a specified percentage of traffic (e.g., 10%) to the new function version, while the remaining traffic continues to serve the old version. Integrating CloudWatch alarms provides automated monitoring during this shift, triggering an automatic rollback to the stable version if predefined error thresholds or latency metrics are breached, ensuring a safe and controlled rollout.

Why this answer

A is correct because CodeDeploy's canary deployment preference shifts 10% of traffic to the new Lambda version for 10 minutes, then automatically shifts the remaining 90% after the specified interval. CloudWatch alarms are configured to trigger an automatic rollback if the alarm state is breached during the canary period, meeting the requirement for a gradual shift with automated rollback on failure.

Exam trap

The trap here is that candidates may confuse 'canary' with 'linear' deployments, or assume that any gradual shift (like 'linear10PercentEvery10Minutes') is equivalent, but the requirement specifies a single 10% shift for 10 minutes before full rollout, which matches the canary preference, not a linear incremental shift.

How to eliminate wrong answers

Option B is wrong because 'All-at-once' deploys all traffic instantly without a gradual 10% shift or a 10-minute waiting period, and it lacks any alarm-based rollback mechanism. Option C is wrong because manually updating an alias after deployment bypasses CodeDeploy's automated traffic shifting and rollback capabilities, requiring manual intervention for both the shift and any rollback. Option D is wrong because an S3 static website deployment is unrelated to Lambda traffic shifting; it is used for hosting static content, not for managing Lambda alias traffic or CodeDeploy deployments.

830
MCQmedium

A developer is troubleshooting a slow-running Amazon RDS for MySQL query. The query performance has degraded over time. Which approach should the developer take first to identify the cause?

A.Enable Performance Insights and review the database load
B.Upgrade the DB instance to a larger instance class
C.Create a read replica to offload read traffic
D.Enable the MySQL query cache
AnswerA

Enabling Amazon RDS Performance Insights is the most effective initial step for diagnosing slow database performance. It provides a visual dashboard of database load, breaking down wait events, active sessions, and top SQL queries over time. This granular visibility allows developers to pinpoint specific bottlenecks, such as I/O waits, CPU contention, or inefficient query execution plans, before implementing any corrective actions.

Why this answer

Amazon RDS Performance Insights is the first-line diagnostic tool for identifying why a query has degraded — it visualizes database load (DBLoad) sliced by SQL statement, wait event, user, and host, showing exactly which query and which wait state is consuming resources. Enabling it is non-invasive and provides the evidence needed before making any infrastructure change. The other options are remediation steps that should only follow diagnosis.

Exam trap

DVA-C02 often tests the 'diagnose before remediate' principle — candidates are tempted to pick scaling or caching actions, but the question asks for the FIRST step, which is always observability (Performance Insights, slow query log, EXPLAIN).

How to eliminate wrong answers

Option B is wrong because upgrading the instance class is a costly remediation that may not address the root cause — if the bottleneck is a missing index or lock contention, a larger instance only masks the problem temporarily. Option C is wrong because a read replica offloads read traffic but does not diagnose a slow query; if the query is a write or the replica lags, it does not help, and it does not identify the cause. Option D is wrong because the MySQL query cache was deprecated in MySQL 5.7 and removed in 8.0, and even when available it is invalidated by any write to the table, making it ineffective for write-heavy workloads and irrelevant as a diagnostic step.

831
MCQeasy

An S3 bucket has versioning enabled with MFA Delete. A developer tries to permanently delete a specific version of an object using the AWS CLI without providing MFA. What is the result?

A.A delete marker is created for the object version.
B.The object version is permanently deleted.
C.The request is denied with an AccessDenied error.
D.The object version is marked with a delete marker.
AnswerC

Since MFA Delete is configured for the S3 bucket, any operation that results in the permanent deletion of an object version, such as deleting a specific version ID, necessitates the inclusion of a valid MFA token in the request. If the DELETE request targeting a specific version ID lacks this required MFA authentication, Amazon S3 will strictly enforce the MFA Delete policy. Consequently, the request will be rejected, and an AccessDenied error will be returned to the caller.

Why this answer

When MFA Delete is enabled on an S3 bucket, any request to permanently delete an object version must include multi-factor authentication. Without MFA, the AWS CLI request is denied with an AccessDenied error, as S3 enforces this security requirement at the API level. The developer cannot bypass this by omitting the MFA token.

Exam trap

The trap here is that candidates often confuse MFA Delete with standard versioning behavior, assuming a delete marker is created as a fallback, but MFA Delete strictly denies any permanent deletion request without the required authentication.

How to eliminate wrong answers

Option A is wrong because a delete marker is created only when deleting the latest version of an object without specifying a version ID, not when attempting to permanently delete a specific version with MFA Delete enabled. Option B is wrong because permanent deletion of a specific version requires MFA authentication when MFA Delete is enabled; without it, the operation fails. Option D is wrong because marking an object version with a delete marker is not a valid S3 operation; delete markers are only applied to the current version of an object, not to specific versions.

832
MCQmedium

A developer has an AWS Lambda function that needs to read objects from an S3 bucket in another account. The Lambda function's execution role includes an IAM policy that allows s3:GetObject on the bucket. The bucket owner has added a bucket policy that grants s3:GetObject to the Lambda execution role. However, the Lambda function receives Access Denied errors. The S3 bucket uses SSE-KMS for encryption. What is the most likely cause?

A.The S3 bucket does not have versioning enabled.
B.The Lambda function's execution role does not have an explicit allow for s3:GetObject.
C.The Lambda function is not in the same AWS region as the S3 bucket.
D.The Lambda function does not have kms:Decrypt permission on the KMS key used by the bucket.
AnswerD

When an S3 bucket utilizes Server-Side Encryption with AWS KMS (SSE-KMS) for object encryption, any entity attempting to read those encrypted objects requires two distinct sets of permissions. First, it needs `s3:GetObject` permission on the S3 bucket and object. Second, and critically, the Lambda function's execution role must also have `kms:Decrypt` permission on the specific AWS KMS key used to encrypt the objects. This `kms:Decrypt` permission is granted via the KMS key policy, not the S3 bucket policy, and without it, the Lambda cannot decrypt the object data even if it successfully retrieves the encrypted bytes from S3.

Why this answer

When an S3 bucket uses SSE-KMS, the Lambda function must have explicit kms:Decrypt permission on the KMS key to decrypt the object after s3:GetObject retrieves the encrypted data. Even though the bucket policy and execution role allow s3:GetObject, the missing KMS permission causes an Access Denied error because S3 returns the encrypted object and the Lambda runtime cannot decrypt it without the key.

Exam trap

The trap here is that candidates focus on the S3 bucket policy and IAM role for s3:GetObject, overlooking that SSE-KMS introduces a separate KMS authorization layer that must be explicitly configured.

How to eliminate wrong answers

Option A is wrong because S3 versioning is unrelated to access permissions or KMS decryption; it controls object version retention, not read access. Option B is wrong because the scenario explicitly states the execution role includes an IAM policy that allows s3:GetObject, so an explicit allow exists. Option C is wrong because cross-region access between Lambda and S3 is fully supported; region mismatch does not cause Access Denied errors unless the bucket policy explicitly restricts by source IP or VPC, which is not mentioned.

833
MCQmedium

Refer to the exhibit. A developer runs the AWS CLI command to decrypt a file using a KMS key. The command fails with an AccessDeniedException. What is the most likely cause?

A.The IAM user 'DevUser' does not have the kms:Decrypt permission on the KMS key.
B.The ciphertext blob is not base64-encoded.
C.The KMS key is disabled.
D.The KMS key ID is incorrect.
AnswerA

The error message "User: arn:aws:iam::123456789012:user/DevUser is not authorized to perform: kms:Decrypt" explicitly indicates that the IAM principal attempting the operation lacks the necessary kms:Decrypt permission. This typically means either the IAM policy attached to 'DevUser' does not grant kms:Decrypt on the specific KMS key, or the KMS key policy itself does not permit 'DevUser' to perform this action. For a KMS operation to succeed, both the IAM identity's policy and the KMS key's resource policy must explicitly allow the requested action.

Why this answer

An AccessDeniedException indicates that the IAM identity (user or role) making the request lacks the required kms:Decrypt permission on the specified KMS key. KMS key policies and IAM policies must both allow the action for the call to succeed.

Exam trap

Candidates often confuse AccessDeniedException with other KMS errors. For example, a disabled key throws DisabledException, and an invalid or improperly encoded ciphertext throws InvalidCiphertextException. AccessDeniedException specifically points to an authorization/permission issue.

How to eliminate wrong answers

Option B is wrong because the AWS CLI decrypt command automatically handles base64 decoding of the ciphertext blob if the --ciphertext-blob parameter is provided as a file or base64-encoded string; an incorrect encoding would produce a ValidationError, not AccessDeniedException. Option C is wrong because a disabled KMS key would return a DisabledException, not AccessDeniedException. Option D is wrong because an incorrect key ID would result in a NotFoundException or InvalidKeyIdException, not AccessDeniedException.

834
Multi-Selectmedium

A developer is troubleshooting a slow-running query on an Amazon RDS for MySQL database. The query is used by a reporting application and takes over 30 seconds to complete. The database is a db.r5.large instance with 200 GB of gp2 storage. Which TWO actions should the developer take to improve query performance?

Select 2 answers
A.Terminate idle connections to free up resources.
B.Review the slow query log to identify the query and its execution plan.
C.Increase the allocated storage to 500 GB to improve I/O performance.
D.Add appropriate indexes to the tables involved in the query.
E.Enable Multi-AZ deployment for better read performance.
AnswersB, D

Reviewing the slow query log is the first diagnostic step because it captures queries that exceed a specified duration, along with their execution time and connection metadata. Once identified, use EXPLAIN to analyze the execution plan, exposing table scans, missing indexes, or poor join ordering. This evidence-based approach tells you exactly which query to optimize and whether to add indexes or rewrite the query.

Why this answer

Option B is correct because the MySQL slow query log captures queries exceeding the long_query_time threshold (default 10 seconds), and reviewing it along with EXPLAIN output reveals the query's execution plan, helping pinpoint full table scans, missing indexes, or inefficient joins. Option D is correct because adding appropriate indexes on the columns used in WHERE, JOIN, and ORDER BY clauses lets MySQL satisfy the query with index lookups instead of full table scans, which is the most direct fix for a slow reporting query. Option A is not appropriate because idle connections consume minimal resources and terminating them does not address query execution inefficiency.

Option C is not appropriate because increasing gp2 storage size only raises the baseline IOPS (3 IOPS/GB) and burst balance; it does not fix a poorly optimized query and is a costly workaround. Option E is not appropriate because Multi-AZ is a high-availability feature that maintains a standby replica for failover, not a read-scaling mechanism, so it does not improve query performance.

Exam trap

DVA-C02 often tests the misconception that scaling storage or enabling Multi-AZ improves query performance, when the real fix is query-level tuning (indexes, execution plan review).

835
MCQeasy

A developer notices that an S3 bucket policy allows public read access to all objects. The bucket contains sensitive data that should only be accessible by authorized IAM users. What is the BEST way to remediate this?

A.Enable default encryption on the bucket.
B.Modify the bucket policy to remove the public statement and use IAM policies for access.
C.Enable S3 Block Public Access at the account level.
D.Enable S3 Object Ownership and use ACLs.
AnswerB

The most direct and secure solution is to modify the S3 bucket policy to remove any statements that grant public access, typically identified by "Principal: "*". Concurrently, implement specific IAM policies attached to users, groups, or roles to grant precise, least-privilege access to authorized principals. This approach directly addresses the misconfiguration, ensures granular control, and aligns with AWS security best practices for managing access to S3 resources.

Why this answer

The bucket policy currently grants public read access, which overrides any IAM-based restrictions. By removing the public statement from the bucket policy and relying solely on IAM policies, access is controlled at the user level, ensuring only authorized IAM users can read objects. This aligns with the principle of least privilege and follows AWS best practices for securing S3 data.

Exam trap

The trap here is that candidates often confuse encryption with access control, thinking that enabling encryption (Option A) will prevent unauthorized access, when in fact encryption only protects data at rest and does not affect public read permissions.

How to eliminate wrong answers

Option A is wrong because enabling default encryption only encrypts data at rest; it does not restrict access, so public read access would still be allowed. Option C is wrong because S3 Block Public Access at the account level would prevent all public access, but it is a broad, account-wide setting that may inadvertently block legitimate public access for other buckets; the question asks for the best remediation for this specific bucket, not a blanket account-level change. Option D is wrong because S3 Object Ownership and ACLs are legacy access control mechanisms that are less secure and more complex to manage than IAM policies, and they do not directly address the public read access granted by the bucket policy.

836
MCQhard

A developer notices that an IAM user has permissions to terminate EC2 instances, but the user should only be allowed to stop instances. The developer needs to update the policy to prevent termination while allowing stop. Which IAM policy statement should be added?

A.{"Effect":"Deny","Action":"ec2:TerminateInstances","Resource":"*"}
B.{"Effect":"Allow","Action":"ec2:TerminateInstances","Resource":"*"}
C.{"Effect":"Allow","Action":["ec2:StopInstances","ec2:TerminateInstances"],"Resource":"*"}
D.{"Effect":"Allow","Action":"ec2:RebootInstances","Resource":"*"}
AnswerA

An explicit Deny statement takes precedence over any Allow, so even if the user's other policies grant ec2:TerminateInstances, this line will effectively block the action. The wildcard resource scopes the denial to all EC2 instances in the account, meaning no running instance can be terminated by that user. This directly implements the developer's requirement to prevent termination.

Why this answer

An explicit Deny statement always overrides any Allow in IAM policy evaluation, so adding {"Effect":"Deny","Action":"ec2:TerminateInstances","Resource":"*"} guarantees the user cannot terminate instances even if an existing policy grants it. This is the only option that removes the unwanted permission while leaving ec2:StopInstances untouched.

Exam trap

DVA-C02 often tests the misconception that adding an Allow for a different action (like StopInstances) implicitly removes the TerminateInstances permission, when in fact IAM is additive and only an explicit Deny can revoke an existing Allow.

How to eliminate wrong answers

Option B is wrong because an Allow for ec2:TerminateInstances would grant the very permission the developer is trying to remove, not restrict it. Option C is wrong because it explicitly allows both StopInstances and TerminateInstances, which is the opposite of the requirement. Option D is wrong because ec2:RebootInstances is a different API action that neither stops nor terminates instances and does nothing to block termination.

837
MCQeasy

A developer wants to store session state for a web application running on multiple EC2 instances. Which AWS service provides a fully managed, in-memory data store that is ideal for this use case?

A.Amazon ElastiCache for Redis
B.Amazon S3
C.Amazon DynamoDB
D.Amazon RDS for MySQL
AnswerA

Amazon ElastiCache for Redis is an excellent choice for storing web application session state due to its in-memory, high-performance nature. It provides extremely low-latency read and write operations, essential for a responsive user experience. As a fully managed service, it simplifies deployment and scaling, offering robust support for various data structures that efficiently manage session attributes and expiration.

Why this answer

Amazon ElastiCache for Redis is the correct choice because it provides a fully managed, in-memory data store that is ideal for storing session state across multiple EC2 instances. Redis supports atomic operations, TTL-based key expiration, and high-speed reads/writes, making it perfect for session management where low-latency access and automatic data eviction are critical. Unlike disk-based stores, ElastiCache for Redis keeps session data in memory, ensuring sub-millisecond response times and seamless scaling as the web application grows.

Exam trap

The trap here is that candidates often choose DynamoDB because it is fully managed and supports TTL, but they overlook the fact that the question specifically asks for an 'in-memory data store,' which DynamoDB is not—it uses SSD storage and has higher latency than an in-memory cache like Redis.

How to eliminate wrong answers

Option B is wrong because Amazon S3 is an object storage service designed for durable, long-term storage of static assets (e.g., images, backups), not for low-latency, in-memory session state; its read/write latency and lack of native TTL or atomic operations make it unsuitable for session management. Option C is wrong because Amazon DynamoDB is a fully managed NoSQL database that can store session data, but it is not an in-memory data store—it uses SSD-backed storage and has higher latency than an in-memory cache, and while it supports TTL, it is not optimized for the sub-millisecond access patterns required for session state in a high-traffic web app. Option D is wrong because Amazon RDS for MySQL is a relational database that stores data on disk, introducing significant latency for session reads/writes and requiring schema management; it is not designed for ephemeral, high-throughput session state and would create unnecessary overhead and performance bottlenecks.

838
MCQhard

A company uses AWS CloudFormation to deploy a stack that includes an RDS MySQL instance. During an update, the stack fails with a 'DELETE_FAILED' status on a security group resource. The security group has a dependency on the RDS instance. What is the MOST likely cause?

A.The RDS instance is not fully deleted because of a deletion protection flag.
B.The security group has a rule that references itself.
C.The security group must be deleted manually before updating the stack.
D.The security group is attached to an EC2 instance outside the stack.
AnswerA

If the RDS instance has the DeletionProtection attribute set to true, CloudFormation's attempt to delete or replace that instance during the stack update silently fails, leaving the instance running and still attached to the security group's ENI, which in turn prevents the security group from being deleted since AWS will not remove a security group that is still in use by an active resource.

Why this answer

The most likely cause is that the RDS instance has deletion protection enabled, preventing it from being deleted even when CloudFormation attempts to delete it. The security group depends on the RDS instance, so if the RDS instance cannot be deleted, the security group also fails to delete, resulting in a DELETE_FAILED status. Option A correctly identifies this.

Option B is incorrect because a self-referencing rule would not cause a delete failure. Option C is incorrect because manual deletion is not required; the issue is with the RDS instance. Option D is incorrect because the security group being attached to an external EC2 instance would cause a different error, not a dependency-related failure.

839
Multi-Selecthard

A developer is deploying a containerized application on Amazon ECS with Fargate. The application requires access to an Amazon RDS database. The developer needs to securely pass database credentials to the container. Which THREE methods can the developer use?

Select 3 answers
A.Store the credentials in AWS Systems Manager Parameter Store and reference the parameter in the task definition.
B.Store the credentials in AWS Secrets Manager and reference the secret in the task definition.
C.Use IAM roles for tasks and retrieve credentials from AWS Secrets Manager at runtime.
D.Hardcode the credentials in the container image.
E.Define environment variables in the task definition with the credentials.
AnswersA, B, C

Storing credentials as a SecureString parameter in Systems Manager Parameter Store and referencing it via the task definition's secrets block injects the value at container start, satisfying the requirement to pass database credentials securely without hardcoding them in the image or environment variables.

Why this answer

Options A, B, and C are correct because they all provide secure, native mechanisms for delivering RDS credentials to an ECS Fargate task. Option A is right because ECS task definitions support the secrets parameter with valueFrom pointing to a Systems Manager Parameter Store parameter (for example, arn:aws:ssm:region:account:parameter/name), and the value is injected at container start without being baked into the image. Option B is right because ECS also supports referencing AWS Secrets Manager secrets in the task definition's secrets block, allowing the credential to be fetched and injected securely at runtime.

Option C is right because an IAM task role can grant the container permission to call secretsmanager:GetSecretValue (or ssm:GetParameter) at runtime, letting the application retrieve credentials dynamically without embedding them. Option D is wrong because hardcoding credentials in the container image exposes them to anyone who can pull or inspect the image and violates credential-rotation best practices. Option E is wrong because defining credentials as plaintext environment variables in the task definition stores them in the task definition itself, making them visible to anyone with ECS read access and not securely encrypted or rotated.

Exam trap

The trap here is that candidates often confuse 'referencing a secret in the task definition' (which is secure and done at launch time) with 'defining environment variables directly in the task definition' (which is insecure), and they may also overlook that IAM roles for tasks can be used to retrieve secrets at runtime, not just at launch.

840
MCQeasy

A developer needs to deploy a containerized application on AWS. The application requires persistent storage that can be shared across multiple containers running on different EC2 instances. Which AWS service should the developer use?

A.Amazon S3
B.Amazon Elastic Block Store (EBS)
C.Amazon RDS
D.Amazon Elastic File System (EFS)
AnswerD

Amazon Elastic File System (EFS) is a fully managed, scalable, and highly available network file system designed for use with AWS cloud services and on-premises resources. EFS provides a POSIX-compliant file system interface, allowing multiple EC2 instances, containers, or serverless functions to concurrently access and share the same data. This makes it an ideal solution for containerized applications that require persistent, shared storage across a fleet of instances.

Why this answer

Amazon EFS provides a fully managed, scalable, and elastic NFS file system that can be mounted concurrently on multiple EC2 instances across different Availability Zones. This makes it the ideal choice for shared persistent storage when containers running on separate EC2 instances need to access the same data simultaneously.

Exam trap

The trap here is that candidates often confuse EBS with EFS, assuming EBS can be shared across instances, but EBS volumes are single-instance attachments by default, while EFS is purpose-built for concurrent multi-instance access.

How to eliminate wrong answers

Option A is wrong because Amazon S3 is an object storage service accessed via HTTP/HTTPS APIs, not a file system that can be mounted as a POSIX-compliant shared volume across EC2 instances. Option B is wrong because Amazon EBS volumes are block-level storage devices that can only be attached to a single EC2 instance at a time (unless using multi-attach EBS, which has strict limitations and is not designed for general-purpose shared file storage across many containers). Option C is wrong because Amazon RDS is a managed relational database service, not a file storage solution, and cannot be used as a shared file system for containerized applications.

841
Multi-Selecthard

A company is running a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application uses Amazon ElastiCache for session state. Recently, users are experiencing intermittent session timeouts and slow page loads. The developer suspects the issue is related to the ElastiCache cluster. Which THREE actions should the developer take to troubleshoot and resolve the issue? (Choose THREE.)

Select 3 answers
A.Monitor the ElastiCache cluster's CPU utilization and cache hit ratio in CloudWatch.
B.Enable Encryption in transit for the ElastiCache cluster.
C.Scale the ElastiCache cluster by adding more nodes or using a larger node type.
D.Review the application's cache key design and ensure that data is evenly distributed across shards.
E.Enable Multi-AZ replication for the ElastiCache cluster.
AnswersA, C, D

Monitoring ElastiCache CPU utilization in CloudWatch helps identify if the cluster is under-provisioned or experiencing heavy processing load, indicating a need for scaling. Concurrently, tracking the cache hit ratio is vital; a low hit ratio suggests that the application is frequently missing cached data, leading to increased latency as requests fall back to the origin database. These metrics collectively provide actionable insights into cache efficiency and potential performance bottlenecks.

Why this answer

Option A is correct because CloudWatch metrics such as CPUUtilization and CacheHits/CacheMisses (cache hit ratio) directly reveal whether the ElastiCache cluster is saturated or failing to serve cached session data, which would cause the intermittent timeouts and slow loads. Option C is correct because if monitoring shows sustained high CPU or memory pressure, vertically scaling to a larger node type or horizontally adding nodes/shards increases capacity and restores consistent session-state performance. Option D is correct because uneven key distribution or poor cache key design can create hot shards/keys, leading to throttling and latency spikes even when overall cluster capacity looks adequate, so reviewing key design and shard balance addresses the root cause.

Option B does not belong because enabling encryption in transit is a security hardening measure and does not resolve performance or session-timeout issues. Option E does not belong because Multi-AZ replication improves availability/failover, not the intermittent latency and timeout symptoms described.

Exam trap

The trap here is that candidates often confuse high-availability features like Multi-AZ replication or encryption with performance fixes, when in fact they address durability and security, not throughput or latency.

842
MCQhard

A developer is troubleshooting access to an S3 bucket from an EC2 instance. The instance has an IAM role with a policy that allows s3:GetObject on the bucket. However, the application receives an AccessDenied error. The bucket policy is as follows: { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::123456789012:role/AppRole" }, "Action": "s3:GetObject", "Resource": "arn:aws:s3:::my-bucket/*" } ] } The EC2 instance is using the correct IAM role. What is the most likely cause of the error?

A.The bucket uses default encryption with SSE-S3, and the application does not support it.
B.The IAM role attached to the EC2 instance has a different ARN than the one specified in the bucket policy.
C.The IAM role policy allows s3:GetObject, but the bucket policy also must allow it, which it does.
D.The bucket policy requires MFA, but the application does not provide it.
AnswerB

For an EC2 instance to access an S3 bucket, both the IAM role attached to the instance and the S3 bucket policy must explicitly grant the necessary permissions. If the S3 bucket policy includes a Principal element or a Condition that references a specific IAM role ARN, a mismatch between that ARN and the actual ARN of the role assumed by the EC2 instance will result in an AccessDenied error. This strict ARN matching ensures that only authorized identities can perform actions, even if the IAM role policy itself grants permissions.

Why this answer

The correct answer is B: the IAM role attached to the EC2 instance has a different ARN than the one specified in the bucket policy. In S3, when a bucket policy explicitly names a Principal, the request must come from exactly that principal; if the instance's role ARN differs (for example, a different role name, path, or account), the bucket policy does not grant access and the request is denied even though the identity-based policy allows s3:GetObject. Option A is wrong because SSE-S3 encryption is transparent to clients and does not cause AccessDenied.

Option C is wrong because it merely restates that both policies allow the action, which would not produce a denial. Option D is wrong because the shown bucket policy contains no MFA condition.

843
MCQmedium

A company uses AWS Elastic Beanstalk to deploy a web application. The environment is currently running a previous version. The developer uploads a new application version and deploys it to the environment. After the deployment, the environment health status turns 'Severe' and the new version is not accessible. The developer needs to quickly revert to the previous working version. What should the developer do?

A.Create a new environment with the previous version and swap CNAMEs.
B.Use the Elastic Beanstalk console to deploy the previous application version.
C.Roll back the environment configuration to a previous saved configuration.
D.Terminate the environment and launch a new one with the previous version.
AnswerB

Elastic Beanstalk maintains a history of all deployed application versions. When a new deployment introduces issues, the console or CLI allows direct selection and deployment of any previously uploaded and deployed application version. This process triggers an in-place update of the existing environment's instances, replacing the problematic code with the last known good version, thereby providing a quick and efficient rollback mechanism without requiring environment recreation.

Why this answer

Elastic Beanstalk allows you to deploy a previous application version directly from the console or CLI without creating a new environment. This action replaces the current application version in the existing environment, restoring the previously working code and resolving the health status. It is the fastest and most straightforward way to revert while preserving the environment's configuration and resources.

Exam trap

The trap here is that candidates confuse 'deploying a previous application version' (which directly fixes the code) with 'rolling back environment configuration' (which only affects settings), leading them to incorrectly choose Option C.

How to eliminate wrong answers

Option A is wrong because creating a new environment and swapping CNAMEs is an unnecessary, time-consuming process that introduces a new environment with its own resources and potential configuration drift, whereas a simple version rollback achieves the same result instantly. Option C is wrong because rolling back the environment configuration reverts settings like instance type or scaling rules, not the application version; the application code remains the broken version. Option D is wrong because terminating the environment and launching a new one with the previous version destroys all existing resources (e.g., RDS database if attached, logs, monitoring data) and requires reconfiguration, which is far more disruptive than a direct version deployment.

844
MCQhard

A company is using AWS Lambda to process messages from an Amazon SQS queue. The Lambda function is configured with a reserved concurrency of 10. The SQS queue receives a burst of 1000 messages. The Lambda function processes each message in about 5 seconds. What is the most likely behavior of the system?

A.Lambda rejects the messages and sends them to the dead-letter queue.
B.Lambda automatically scales up to 1000 concurrent executions to process all messages quickly.
C.Lambda increases the reserved concurrency to accommodate the burst.
D.Lambda processes up to 10 messages concurrently, and the rest remain in the queue until processing capacity is available.
AnswerD

When a Lambda function has a reserved concurrency of 10, it means that at any given moment, a maximum of 10 instances of that function can be executing simultaneously. If there's a sudden influx of messages from the SQS queue, Lambda will invoke up to 10 functions to process them. Any additional messages beyond what these 10 concurrent invocations can handle will remain in the SQS queue, awaiting an available function instance to process them.

Why this answer

Lambda's reserved concurrency of 10 caps the maximum number of concurrent executions. When the SQS queue receives 1000 messages, Lambda polls the queue and invokes the function with up to 10 messages at a time (based on batch size, default 1). The remaining messages stay in the queue and are retried after the visibility timeout expires, as Lambda processes messages in batches limited by the reserved concurrency.

Exam trap

The trap here is that candidates assume Lambda automatically scales to handle any burst, but reserved concurrency explicitly limits scaling, and the exam tests understanding that this limit is enforced regardless of queue depth.

How to eliminate wrong answers

Option A is wrong because Lambda does not reject messages due to concurrency limits; messages remain in the queue and are retried, and a dead-letter queue is only used after the maximum retry count is exceeded. Option B is wrong because Lambda cannot scale beyond the reserved concurrency of 10, which is a hard limit set by the user, not an automatic scaling target. Option C is wrong because reserved concurrency is a static configuration that cannot be dynamically increased by Lambda in response to a burst; it must be changed manually or via an auto-scaling mechanism like Application Auto Scaling.

845
Multi-Selecteasy

A developer needs to securely store database credentials and retrieve them programmatically from a Lambda function. Which AWS services can be used for this purpose? (Choose TWO.)

Select 2 answers
A.AWS Systems Manager Parameter Store (SecureString)
B.AWS Secrets Manager
C.AWS CloudFormation
D.AWS Identity and Access Management (IAM)
E.Amazon S3
AnswersA, B

AWS Systems Manager Parameter Store SecureString parameters store database credentials as encrypted values using AWS KMS, and they can be retrieved through the AWS API, CLI, or SDK by services like EC2, ECS, and Lambda. However, while Parameter Store can integrate with KMS and supports versioning, it does not natively automate credential rotation, so it is best when you need encrypted secrets without the additional lifecycle features of Secrets Manager.

Why this answer

AWS Systems Manager Parameter Store (SecureString) [CORRECT] is right because it stores sensitive values like database credentials as encrypted parameters using KMS, and a Lambda function can retrieve them programmatically via the GetParameter API with the WithDecryption flag set to true. AWS Secrets Manager [CORRECT] is also right because it is purpose-built for storing and rotating secrets such as database credentials, and Lambda can retrieve them programmatically using the GetSecretValue API. AWS CloudFormation does not belong because it is an infrastructure-as-code service for provisioning resources, not a secrets store for runtime retrieval.

AWS Identity and Access Management (IAM) does not belong because it manages permissions and identities, not the storage of credential values themselves. Amazon S3 does not belong because it is object storage and, while it can hold files, it is not designed as a secure credential store with native secret-retrieval APIs for this use case.

Exam trap

DVA-C02 often tests the confusion between services that store secrets (Secrets Manager, Parameter Store SecureString) and services that merely authorize or provision (IAM, CloudFormation) — candidates must pick the storage services.

846
MCQmedium

A developer is using AWS Elastic Beanstalk to deploy a web application. The application experiences high latency during peak hours. The developer wants to scale the application automatically based on CPU utilization. Which configuration should the developer use?

A.Configure an Auto Scaling step scaling policy based on MemoryReservation metric.
B.Use AWS CloudFront to cache responses and reduce load on the application.
C.Configure an Auto Scaling simple scaling policy based on Average CPU Utilization > 70% for scale-out and < 30% for scale-in.
D.Configure an Auto Scaling target tracking policy based on NetworkIn metric.
AnswerC

Configuring an Auto Scaling simple scaling policy based on Average CPU Utilization with thresholds of > 70% for scale-out and < 30% for scale-in is the correct and most common approach for horizontally scaling web applications in Elastic Beanstalk. High CPU utilization directly indicates that the existing instances are struggling to process requests, necessitating more compute capacity. Conversely, low CPU utilization suggests instances are underutilized, allowing for cost-efficient scale-in.

Why this answer

AWS Elastic Beanstalk integrates with Auto Scaling to automatically adjust the number of EC2 instances based on a simple scaling policy that uses the Average CPU Utilization metric. By setting a scale-out threshold at >70% and a scale-in threshold at <30%, the application can dynamically handle peak-hour traffic while reducing costs during low usage. This directly addresses the developer's requirement to scale based on CPU utilization.

Exam trap

The trap here is that candidates may confuse the metric used for scaling (CPU utilization) with other metrics like MemoryReservation or NetworkIn, or assume that caching solutions like CloudFront can replace the need for compute scaling, when the question explicitly requires scaling based on CPU utilization.

How to eliminate wrong answers

Option A is wrong because the MemoryReservation metric is specific to Amazon ECS and Fargate tasks, not to EC2 instances managed by Elastic Beanstalk, and step scaling policies are not the recommended approach for CPU-based scaling in this context. Option B is wrong because while CloudFront can reduce latency by caching responses at edge locations, it does not automatically scale the application's compute capacity based on CPU utilization; it only offloads requests for cached content. Option D is wrong because a target tracking policy based on NetworkIn metric would scale based on network traffic rather than CPU utilization, which does not meet the developer's explicit requirement to scale based on CPU utilization.

847
MCQmedium

A company uses AWS KMS to encrypt data at rest in S3. The security team requires that all objects uploaded to a specific S3 bucket must be encrypted with a specific KMS key (key ID: xyz). The developer needs to enforce this by denying any PutObject request that does not use the correct key. Which bucket policy condition should be used?

A.s3:x-amz-server-side-encryption-aws-kms-key-id
B.kms:EncryptionContext
C.s3:EncryptionAlgorithm
D.kms:GrantOperations
AnswerA

This condition key, `s3:x-amz-server-side-encryption-aws-kms-key-id`, is precisely designed for S3 bucket policies to enforce the use of a *specific* AWS KMS customer master key (CMK) when objects are uploaded with server-side encryption using KMS (SSE-KMS). By including this condition, an S3 bucket policy can mandate that all incoming objects encrypted with SSE-KMS must utilize a predefined KMS key ARN, preventing uploads encrypted with unauthorized or default KMS keys. This ensures strict compliance with data residency or security requirements by linking data to a specific cryptographic key.

Why this answer

The `s3:x-amz-server-side-encryption-aws-kms-key-id` condition key allows you to enforce that a specific KMS key ID (e.g., `xyz`) is used for server-side encryption with AWS KMS (SSE-KMS). By including this condition in a bucket policy with a `Deny` effect, any `PutObject` request that does not specify the required key ID will be denied, meeting the security team's requirement.

Exam trap

The trap here is confusing S3-specific condition keys (like `s3:x-amz-server-side-encryption-aws-kms-key-id`) with KMS condition keys (like `kms:EncryptionContext`), leading candidates to pick a KMS condition key that does not apply to S3 bucket policies.

How to eliminate wrong answers

Option B is wrong because `kms:EncryptionContext` is a condition key used to control access based on the encryption context in KMS API calls (e.g., `Encrypt`, `Decrypt`), not to enforce the KMS key ID used for S3 object encryption. Option C is wrong because `s3:EncryptionAlgorithm` is not a valid S3 condition key; S3 uses `s3:x-amz-server-side-encryption` to specify the encryption type (e.g., AES256 or aws:kms), not the algorithm. Option D is wrong because `kms:GrantOperations` is a condition key used to restrict the operations allowed in a KMS grant, not to enforce the KMS key ID in S3 PutObject requests.

848
MCQmedium

A developer is writing an AWS Lambda function that needs to access an Amazon S3 bucket. The Lambda function's execution role has been granted s3:GetObject permission on the bucket. However, when the function runs, it receives an Access Denied error. The S3 bucket policy allows access only from a specific VPC endpoint. What is the most likely cause of the error?

A.The Lambda execution role lacks the s3:ListBucket permission, which is required to access objects in the bucket.
B.The Lambda function's execution role needs an explicit deny override for the bucket policy condition.
C.The S3 bucket policy must be updated to include the Lambda function's IAM role ARN as a principal.
D.The Lambda function is not configured to use the VPC endpoint; it must be associated with the VPC and route traffic through the endpoint.
AnswerD

If the S3 bucket policy restricts access to a specific VPC endpoint, the Lambda function must send requests through that endpoint. This requires the Lambda function to be configured with VPC access, and the VPC must have an S3 gateway endpoint. Without this, the request originates from the public internet and is denied by the bucket policy.

Why this answer

The S3 bucket policy likely has a condition that restricts access to requests originating from a specific VPC endpoint. For the Lambda function to access the bucket, it must be configured to run within the VPC and use the VPC endpoint for S3. Without this, the request comes from the public internet and is denied.

Exam trap

The trap here is assuming that IAM permissions alone are sufficient; bucket policies with VPC endpoint conditions require the request to originate from that endpoint.

849
Multi-Selecteasy

Which TWO of the following are valid use cases for Amazon S3 event notifications?

Select 2 answers
A.Automatically replicate objects to another bucket
B.Automatically delete objects after 30 days
C.Encrypt objects automatically with KMS
D.Send a notification to an SQS queue when a new object is created
E.Trigger a Lambda function to process an image after upload
AnswersD, E

This is a valid and common use case for Amazon S3 event notifications. S3 can be configured to publish messages to an Amazon SQS queue whenever specific object-level events occur, such as s3:ObjectCreated:Put or s3:ObjectCreated:Post. This enables decoupled architectures where other services can asynchronously consume these messages to react to new object uploads, facilitating further processing or logging.

Why this answer

Amazon S3 event notifications can be configured to publish events to an SQS queue when a new object is created (s3:ObjectCreated:*). This allows decoupled, asynchronous processing of object creation events without polling, making it ideal for workflows like log aggregation or data ingestion pipelines.

Exam trap

The trap here is that candidates confuse S3 event notifications with S3 lifecycle policies or replication features, mistakenly thinking notifications can directly perform actions like deletion or replication, when in fact they only trigger notifications to specified destinations.

850
MCQeasy

A developer is using AWS CloudFront to serve static content. Users in some geographic regions report slow load times. Which CloudFront feature can the developer use to reduce latency for these users?

A.Change the CloudFront price class to include all edge locations.
B.Create multiple origins in different regions.
C.Enable S3 Transfer Acceleration on the origin S3 bucket.
D.Use Lambda@Edge to optimize content delivery.
AnswerA

CloudFront's price classes determine which edge locations are utilized for content delivery. Selecting "Price Class All" ensures that CloudFront leverages its entire global network of edge locations, including those in regions with higher infrastructure costs. This maximizes the geographic proximity of cached content to end-users worldwide, thereby minimizing latency for static content delivery regardless of the user's physical location.

Why this answer

CloudFront's price class determines which edge locations are used to serve content. By default, CloudFront may use only a subset of edge locations (Price Class 100 or 200) to reduce costs, which can cause higher latency for users in regions not covered. Changing the price class to 'All Edge Locations' (Price Class All) ensures that CloudFront uses every global edge location, providing lower latency for all users.

Option B is incorrect because creating multiple origins in different regions addresses origin distance, not edge location coverage. Option C is incorrect because S3 Transfer Acceleration is for speeding up uploads to S3, not for improving CloudFront content delivery. Option D is incorrect because Lambda@Edge can modify content at edge locations but does not expand the set of edge locations used.

851
MCQeasy

A developer is deploying a new version of a Lambda function using an alias for blue/green deployment. Traffic is gradually shifted to the new version. During the shift, a high error rate is observed. What should the developer do to minimize impact?

A.Use the Lambda function's provisioned concurrency to pre-warm the new version.
B.Manually revert the alias to point back to the old version.
C.Configure the alias with a canary deployment and an error rate alarm for automatic rollback.
D.Delete the new version and redeploy after fixing the issue.
AnswerC

Configuring a Lambda alias with a canary deployment allows for gradual shifting of traffic to the new function version, starting with a small percentage. Integrating this with an Amazon CloudWatch error rate alarm enables automatic rollback: if the new version's error rate exceeds a predefined threshold during the canary phase, the alias automatically reverts all traffic to the stable old version. This strategy minimizes the impact of potential issues by detecting them early and automating recovery.

Why this answer

It automates the rollback process using AWS CodeDeploy's canary deployment with an Amazon CloudWatch alarm on the error rate. When the alarm triggers, CodeDeploy automatically shifts traffic back to the previous version, minimizing impact without manual intervention. This is the recommended approach for safe blue/green deployments with Lambda aliases.

Exam trap

The trap here is that candidates may think manual reversion (Option B) is the simplest fix, but the exam emphasizes automated rollback strategies (like canary deployments with alarms) as the best practice for minimizing impact during blue/green deployments.

How to eliminate wrong answers

Option A is wrong because provisioned concurrency pre-warms execution environments to reduce cold starts, but it does not address a high error rate during traffic shifting; errors are typically caused by code defects, not cold starts. Option B is wrong because manually reverting the alias is a valid fallback but is slower and error-prone compared to an automated rollback; the question asks to minimize impact, and manual reversion introduces delay and potential for human error. Option D is wrong because deleting the new version and redeploying after fixing the issue is a reactive approach that does not minimize impact during the shift; it requires manual intervention and does not provide automatic recovery.

852
MCQmedium

A developer is managing an application running on Amazon EC2 instances behind an Application Load Balancer. Users report that the application becomes unresponsive after several hours, and restarting the instance temporarily fixes the issue. The developer suspects a memory leak but cannot add custom instrumentation. Which AWS service can collect memory utilization metrics and help identify the memory leak with minimal configuration?

A.Use Amazon CloudWatch Logs agent to capture application logs.
B.Use the EC2 instance metadata service to query memory usage.
C.Install the CloudWatch agent on the EC2 instances to collect memory metrics and emit them to CloudWatch.
D.Use AWS X-Ray to trace memory allocation.
AnswerC

The unified CloudWatch agent is the correct and recommended solution for collecting detailed operating system-level metrics, including memory utilization, from EC2 instances. This agent can be configured to gather various custom metrics, such as used memory percentage, free memory, and swap usage, directly from the instance's operating system. These collected metrics are then reliably published to CloudWatch, enabling comprehensive monitoring, alarming, and dashboarding capabilities.

Why this answer

The CloudWatch agent can collect custom metrics, including memory utilization, from EC2 instances and publish them to Amazon CloudWatch. This allows the developer to monitor memory usage over time and identify a memory leak without modifying the application code. The default EC2 metrics do not include memory utilization, so the CloudWatch agent is the minimal-configuration solution for this requirement.

Exam trap

The trap here is that candidates assume EC2 automatically provides memory metrics in CloudWatch, but in reality, only CPU, network, and disk metrics are available by default; memory requires the CloudWatch agent.

How to eliminate wrong answers

Option A is wrong because the CloudWatch Logs agent captures application logs, not memory utilization metrics; logs could indirectly indicate issues but do not provide direct memory metrics needed to identify a leak. Option B is wrong because the EC2 instance metadata service provides information about the instance itself (e.g., instance ID, AMI ID) but does not expose memory utilization data; it is not a monitoring service for OS-level metrics. Option D is wrong because AWS X-Ray traces requests and identifies performance bottlenecks in distributed applications, not memory allocation or utilization; it is designed for tracing, not OS-level resource monitoring.

853
MCQmedium

A developer is troubleshooting a DynamoDB table that is experiencing high write throttling (ProvisionedThroughputExceededException) on certain days. The table has provisioned write capacity of 1000 WCU. The table has a partition key of 'user_id' which is a UUID. The table is accessed by multiple services. CloudWatch metrics show that the WriteThrottleEvents are spiking during specific hours, and the ConsumedWriteCapacityUnits often reaches 1000. What is the most likely cause of the throttling?

A.The partition key is not distributed evenly, causing a hot partition.
B.The provisioned write capacity is insufficient to handle the traffic spikes.
C.The table does not have DynamoDB Accelerator (DAX) enabled.
D.The table is configured with eventual consistency, which throttles writes.
AnswerB

This is the correct answer. DynamoDB tables operate on a provisioned throughput model, where Write Capacity Units (WCUs) must be sufficient to handle the incoming write traffic. When the rate of write requests, especially during traffic spikes, exceeds the allocated provisioned write capacity, DynamoDB will begin to throttle requests. This throttling mechanism protects the underlying infrastructure and ensures consistent performance for other requests within the provisioned limits, but it results in rejected write operations for the application.

Why this answer

The ConsumedWriteCapacityUnits consistently reaches the provisioned 1000 WCU during specific hours, and WriteThrottleEvents spike at those same times. This indicates that the provisioned capacity is insufficient to handle peak traffic, causing requests to be throttled. The partition key (UUID) is well-distributed, so a hot partition is unlikely.

Exam trap

The trap here is that candidates often assume throttling must be caused by a hot partition (Option A) when the partition key is not a UUID, but in this case the UUID ensures even distribution, so the real issue is simply insufficient capacity during traffic spikes.

How to eliminate wrong answers

Option A is wrong because the partition key is a UUID, which is inherently random and evenly distributes writes across partitions, making a hot partition improbable. Option C is wrong because DAX is an in-memory cache for reads, not writes, and does not affect write throttling or provisioned write capacity. Option D is wrong because eventual consistency applies only to reads, not writes; writes are always strongly consistent and throttling is based on write capacity, not consistency settings.

854
MCQeasy

A developer wants to encrypt data in transit between an application and an S3 bucket. Which option achieves this?

A.Enable server-side encryption with S3 managed keys (SSE-S3).
B.Configure an IAM policy to require encryption.
C.Use HTTPS when making requests to S3.
D.Use AWS KMS to encrypt the data before upload.
AnswerC

Making requests to the S3 API endpoint over HTTPS wraps every request and response in TLS, encrypting the data as it moves across the network between the application and S3's servers, which is precisely what in-transit encryption means and is enabled by default on all S3 endpoints.

Why this answer

HTTPS encrypts data in transit between the application and S3, ensuring confidentiality during transmission. Option A is incorrect because SSE-S3 encrypts data at rest, not in transit. Option B is incorrect because IAM policies control access permissions, not encryption.

Option D is incorrect because encrypting data with AWS KMS before upload addresses at-rest encryption, but without HTTPS, data is still transmitted in plaintext.

855
MCQmedium

A development team is using AWS CodeDeploy to deploy a web application to an Auto Scaling group. The deployment fails with a 'HealthCheck' error. The application runs on Amazon EC2 instances behind an Application Load Balancer (ALB). What is the MOST likely cause of this error?

A.The ALB target group health check is misconfigured or the application is not responding to health check requests.
B.The EC2 instances do not have the correct IAM instance profile attached.
C.The deployment configuration is set to 'AllAtOnce' which does not support health checks.
D.The deployment group is not configured with the ALB target group.
AnswerA

CodeDeploy integrates directly with an Application Load Balancer (ALB) to manage traffic during deployments and validate instance health. During a deployment, CodeDeploy monitors the health of instances in the target group using the ALB's configured health checks. If these health checks fail, either due to an incorrect configuration (e.g., wrong port, path, or expected response) or because the deployed application itself is not starting correctly or responding to the health check requests, CodeDeploy will detect this and halt the deployment, often initiating a rollback. This critical mechanism ensures that only healthy instances receive production traffic, preventing service disruptions.

Why this answer

The 'HealthCheck' error in AWS CodeDeploy indicates that the deployment failed because the target group health checks are not passing. This typically occurs when the ALB health check path or configuration does not match the application's expected response, or the application is not running correctly on the instances, causing the ALB to mark them as unhealthy. CodeDeploy monitors the ALB target group health status during deployment and will fail if instances do not become healthy within the configured timeout.

Exam trap

The trap here is that candidates often confuse a 'HealthCheck' error with a permissions or configuration issue, but the error specifically points to the ALB health check failing, not to IAM roles or deployment group setup.

How to eliminate wrong answers

Option B is wrong because an incorrect IAM instance profile would cause the CodeDeploy agent to fail to communicate with the service or to download the revision, resulting in a different error (e.g., 'InstanceAgent' or 'AccessDenied'), not a 'HealthCheck' error. Option C is wrong because the 'AllAtOnce' deployment configuration does support health checks; it simply deploys to all instances simultaneously, but CodeDeploy still validates health status against the ALB target group. Option D is wrong because if the deployment group were not configured with the ALB target group, CodeDeploy would not perform health checks at all, and the error would be about missing target group configuration, not a health check failure.

856
MCQmedium

A developer is building a serverless application using AWS Lambda and Amazon API Gateway. The API requires that the same Lambda function handle different HTTP methods (GET, POST, DELETE) for the same resource. The developer wants to minimize code and configuration. Which integration type should the developer use?

A.Lambda proxy integration
B.Lambda custom integration
C.HTTP integration
D.Mock integration
AnswerA

Lambda proxy integration simplifies API Gateway configuration by passing the entire client request, including headers, query string parameters, path parameters, and body, directly to the Lambda function as a single event object. This allows the Lambda function to parse the request and handle different HTTP methods and paths dynamically, significantly reducing the need for explicit mapping templates within API Gateway and streamlining serverless application development.

Why this answer

Lambda proxy integration (option A) is correct because it automatically passes the entire HTTP request (method, headers, query parameters, path parameters) to the Lambda function as a single event object, allowing the same function to inspect the `httpMethod` field and branch logic for GET, POST, DELETE without any additional API Gateway mapping or transformation configuration. This minimizes both code (the function handles routing internally) and configuration (no need to define separate integration requests/responses per method).

Exam trap

The trap here is that candidates often confuse 'custom integration' (option B) with 'proxy integration' (option A), mistakenly thinking custom integration offers more flexibility when in fact it requires more configuration and does not automatically pass the full request context.

How to eliminate wrong answers

Option B (Lambda custom integration) is wrong because it requires you to explicitly define request/response mapping templates for each HTTP method, increasing configuration complexity and defeating the goal of minimizing code and configuration. Option C (HTTP integration) is wrong because it proxies requests to an HTTP endpoint, not to a Lambda function, so it cannot directly invoke the same Lambda for multiple methods without an intermediate HTTP service. Option D (Mock integration) is wrong because it returns a static response defined in API Gateway without invoking any backend, so it cannot handle dynamic business logic for different HTTP methods.

857
MCQeasy

A developer wants to securely store database credentials for a Lambda function. Which AWS service should be used?

A.AWS Secrets Manager
B.AWS Systems Manager Parameter Store
C.Amazon S3 with server-side encryption
D.Amazon DynamoDB
AnswerA

AWS Secrets Manager is the optimal choice as it is purpose-built for managing, retrieving, and rotating database credentials, API keys, and other secrets throughout their lifecycle. It offers native integration with services like Amazon RDS and Amazon Redshift for automatic credential rotation, enhancing security by regularly changing credentials without application downtime. Furthermore, it provides fine-grained access control through AWS IAM and comprehensive auditing via AWS CloudTrail, ensuring secure and compliant secret management.

Why this answer

AWS Secrets Manager is purpose-built for storing, rotating, and retrieving sensitive credentials such as database passwords. It integrates natively with Lambda via the AWS SDK, supports automatic rotation using Lambda rotation functions, and encrypts secrets with KMS. For database credentials specifically, Secrets Manager's built-in RDS/Redshift/DocumentDB rotation templates make it the recommended service.

Exam trap

DVA-C02 often tests the distinction between Secrets Manager and Parameter Store — candidates pick Parameter Store because it can store SecureStrings, but the question's emphasis on 'database credentials' signals Secrets Manager's native rotation capability.

How to eliminate wrong answers

Option B is wrong because Systems Manager Parameter Store can store SecureString values but lacks native automatic rotation for database credentials and is better suited to configuration data. Option C is wrong because S3 with SSE is object storage, not a secrets management service — it lacks rotation, fine-grained secret retrieval APIs, and audit integration designed for credentials. Option D is wrong because DynamoDB is a NoSQL database, not a secrets store; using it would require custom encryption, rotation, and access-control logic.

858
MCQmedium

A developer is deploying an application on Amazon EC2 instances that need to securely retrieve secrets from AWS Secrets Manager. What is the MOST secure way to provide the necessary permissions without hardcoding credentials?

A.Store the secret in an environment variable.
B.Attach an IAM role to the EC2 instance with permission to access Secrets Manager.
C.Embed the secret in the application code.
D.Use a configuration file stored in S3 with bucket policy.
AnswerB

An IAM role attached to the EC2 instance delivers temporary, automatically rotated credentials through the instance metadata service, so no long-term secrets are stored on the instance. This satisfies the no-hardcoded-credentials constraint while granting least-privilege access to Secrets Manager.

Why this answer

Attaching an IAM role to the EC2 instance is the most secure method because it leverages temporary security credentials obtained via the EC2 instance metadata service (IMDS). This eliminates the need to hardcode, embed, or store any long-term credentials on the instance, adhering to the AWS Well-Architected Framework's security pillar. The IAM role's policy grants the instance precise permissions to call Secrets Manager APIs like GetSecretValue, ensuring least privilege.

Exam trap

The trap here is that candidates may think environment variables or S3 configuration files are secure enough, but the exam emphasizes that any form of static credential storage (including environment variables) is insecure compared to IAM roles, which provide automatic, temporary, and rotated credentials.

How to eliminate wrong answers

Option A is wrong because storing the secret in an environment variable still exposes the secret in plaintext within the instance's process space and can be read by any user or process with access to the environment, violating security best practices. Option C is wrong because embedding the secret in application code hardcodes the credential, making it visible in source control, logs, or binary analysis, and prevents rotation without redeployment. Option D is wrong because using a configuration file stored in S3 with a bucket policy does not inherently provide secure access; the EC2 instance would still need credentials to retrieve the file, and the bucket policy alone cannot grant permissions to the instance without an IAM role or user, while also exposing the secret in transit and at rest if not encrypted.

859
MCQeasy

A developer needs to store application logs from multiple EC2 instances in a centralized location for analysis. The logs should be retained for 90 days. Which AWS service should be used to collect and store the logs?

A.Amazon Kinesis Data Firehose
B.Amazon CloudWatch Logs
C.AWS CloudTrail
D.Amazon S3 with S3 Server Access Logs
AnswerB

Amazon CloudWatch Logs is specifically designed for centralizing logs from various sources, including EC2 instances, AWS Lambda functions, and other AWS services. It provides a dedicated agent for easy installation on EC2 instances to collect application logs, offers configurable retention policies, and allows for real-time monitoring, searching, and analysis of log data. This makes it the most straightforward and cost-effective solution for collecting, storing, and managing application logs with integrated viewing capabilities.

Why this answer

Amazon CloudWatch Logs is the correct service for collecting, monitoring, and storing application logs from EC2 instances in a centralized location. It integrates directly with the CloudWatch Logs agent (or unified CloudWatch agent) installed on EC2 instances to stream log data, and it supports configurable retention policies, including a 90-day retention period. This makes it the ideal choice for centralized log storage and analysis without requiring additional infrastructure.

Exam trap

The trap here is that candidates often confuse AWS CloudTrail (which logs API calls) with CloudWatch Logs (which collects application logs), leading them to select CloudTrail for application-level logging needs.

How to eliminate wrong answers

Option A is wrong because Amazon Kinesis Data Firehose is a real-time data streaming service designed to load data into destinations like S3, Redshift, or Elasticsearch, not a native log storage and retention service; it lacks built-in log retention policies and is not optimized for storing logs directly for 90 days. Option C is wrong because AWS CloudTrail records API activity and governance events across AWS services, not application-level logs from EC2 instances; it is focused on auditing, not application log collection. Option D is wrong because Amazon S3 with S3 Server Access Logs captures detailed records about requests made to an S3 bucket, not application logs from EC2 instances; it is a bucket-level logging feature, not a centralized log collection service for EC2.

860
MCQmedium

A company is deploying a new microservice on AWS Lambda behind an API Gateway. The development team wants to ensure that new versions of the Lambda function can be rolled out gradually and automatically rolled back if error rates exceed a threshold. Which deployment strategy should the team use?

A.Use AWS CodeDeploy with a canary deployment strategy that shifts 10% of traffic to the new version for 5 minutes, then shifts the remaining 90%. Configure a CloudWatch alarm to automatically roll back if error rates exceed 2%.
B.Use AWS Lambda function aliases with weighted alias traffic shifting. Update the weights manually and monitor error rates using CloudWatch. Roll back by reverting the alias weights.
C.Use AWS CodeDeploy with a linear deployment strategy that shifts 10% of traffic every 5 minutes. Configure a CloudWatch alarm to monitor error rates and manually roll back if needed.
D.Use AWS CodeDeploy with a blue/green deployment and an Application Load Balancer (ALB) to shift traffic to the new version. Configure CloudWatch alarms to trigger a rollback if errors exceed 5%.
AnswerA

This option correctly leverages AWS CodeDeploy's canary deployment strategy, which gradually shifts a small percentage of traffic (10%) to the new Lambda version initially. This allows for real-world testing with minimal impact before shifting the remaining traffic. Crucially, integrating a CloudWatch alarm for error rates enables automatic rollback, ensuring immediate mitigation if the new version introduces issues, making it a robust and safe deployment approach.

Why this answer

AWS CodeDeploy supports canary deployments for Lambda, where you specify a percentage of traffic to shift to the new version for a specified interval, then shift the rest. You can attach CloudWatch alarms to the deployment group so that if error rates exceed a threshold during the canary window, CodeDeploy automatically rolls back to the previous version. This matches the requirement for gradual rollout and automatic rollback.

Exam trap

DVA-C02 often tests whether candidates know that automatic rollback requires CloudWatch alarms attached to a CodeDeploy deployment group, and that Lambda traffic shifting uses aliases, not ALBs — the trap is picking a manual rollback or an ALB-based answer.

How to eliminate wrong answers

Option B is wrong because weighted alias traffic shifting requires manual weight updates and manual rollback — it does not provide automatic rollback based on CloudWatch alarms. Option C is wrong because a linear deployment strategy shifts traffic in equal increments, and the option specifies manual rollback, which does not meet the automatic rollback requirement. Option D is wrong because CodeDeploy blue/green for Lambda does not use an ALB — Lambda traffic shifting is done via aliases and weights, and the option specifies a 5% error threshold with rollback, but the architecture (ALB) is incorrect for Lambda.

861
MCQmedium

A developer is building a serverless application that processes images uploaded to an S3 bucket. The processing includes generating thumbnails and storing metadata in DynamoDB. The developer wants to ensure that the processing function is triggered only when new objects are created, not when existing objects are updated. Which S3 event notification configuration should be used?

A.Use s3:ObjectCreated:*
B.Use s3:ObjectCreated:Post
C.Use s3:ObjectCreated:Put
D.Use s3:ObjectCreated:Copy
AnswerA

Correct. s3:ObjectCreated:* captures all creation events, allowing the developer to filter updates in the processing function. While it does not exclusively trigger on new objects, it is the most comprehensive event type and is the intended answer given the limitations of S3 event notifications.

Why this answer

The `s3:ObjectCreated:*` event type is a wildcard that covers all object creation APIs, including `s3:ObjectCreated:Put`, `s3:ObjectCreated:Post`, `s3:ObjectCreated:Copy`, and `s3:ObjectCreated:CompleteMultipartUpload`. Using `s3:ObjectCreated:*` ensures that the Lambda function is triggered regardless of how the image was uploaded or created in the bucket. If the developer only configured `s3:ObjectCreated:Put`, then images uploaded via multipart uploads (which trigger `CompleteMultipartUpload`) or POST requests would not trigger the function.

Exam trap

The exam tests your knowledge of S3 event types. Candidates often mistakenly choose `s3:ObjectCreated:Put` thinking it covers all uploads. However, large files are often uploaded using multipart upload, which triggers `s3:ObjectCreated:CompleteMultipartUpload`, not `Put`.

To capture all creation methods, `s3:ObjectCreated:*` must be used.

How to eliminate wrong answers

Option A is wrong because s3:ObjectCreated:* is a wildcard that matches all object creation events, including PUT, POST, COPY, and multipart upload completions, which would trigger the function for both new and updated objects. Option B is wrong because s3:ObjectCreated:Post is specific to objects uploaded via HTTP POST (typically used for browser-based uploads via HTML forms) and does not cover PUT operations, which are the most common method for uploading new objects programmatically. Option D is wrong because s3:ObjectCreated:Copy triggers only when an object is copied within S3 (via PUT Object - Copy), which is not the primary method for uploading new images; it would miss direct uploads and also trigger on copies of existing objects.

862
MCQhard

An organization wants to enforce that all IAM users must use multi-factor authentication (MFA) to access the AWS Management Console. The security team needs to deny any console access if MFA is not enabled. Which IAM policy statement should be used?

A.Deny action '*' unless 'aws:MultiFactorAuthPresent' is true.
B.Deny action '*' if 'aws:MultiFactorAuthPresent' is false.
C.Deny action '*' if 'aws:MultiFactorAuthPresent' is false using BoolIfExists.
D.Allow action '*' if 'aws:MultiFactorAuthPresent' is true.
AnswerB

Because the aws:MultiFactorAuthPresent key is always populated with a true or false value during Management Console sign-in, a Deny statement using Bool with the condition set to false correctly and directly blocks every console action for any session that did not authenticate with MFA, which is exactly the explicit-deny enforcement the security team requires.

Why this answer

It uses a Deny statement with the condition 'aws:MultiFactorAuthPresent' set to 'false', which explicitly blocks any action when MFA is not present. This is the standard approach to enforce MFA for console access, as it overrides any Allow policies by default. The Deny effect ensures that even if other policies grant access, the lack of MFA results in denial.

Exam trap

The trap here is that candidates confuse 'Deny' with 'Allow' logic or misuse 'BoolIfExists' thinking it handles missing keys, but for console access the key is always present, so 'Bool' is required to correctly enforce the denial.

How to eliminate wrong answers

Option A is wrong because it uses 'unless' syntax, which is not valid in IAM policy language; IAM uses condition operators like 'Bool', 'StringEquals', etc., not 'unless'. Option C is wrong because 'BoolIfExists' is used when the condition key might not exist (e.g., for API calls that don't support MFA), but for console access the key is always present, so 'Bool' is appropriate and 'BoolIfExists' could inadvertently allow access if the key is missing. Option D is wrong because an Allow statement alone cannot enforce denial; it would only grant access when MFA is present but would not block access when MFA is absent if other policies allow it, and it fails to explicitly deny non-MFA access.

863
MCQmedium

A company is using Amazon API Gateway to expose a REST API. The API is integrated with an AWS Lambda function. Lately, the API is returning 502 Bad Gateway errors. What is the MOST likely cause?

A.The API Gateway request throttling limit has been exceeded.
B.The API Gateway API key is invalid.
C.The Lambda function is returning an unhandled exception.
D.The Lambda function's execution role does not allow API Gateway to invoke it.
AnswerC

API Gateway expects its integrated Lambda function to return a specific JSON response format, including status code, headers, and body, for successful processing and mapping. When a Lambda function encounters an unhandled exception, times out, or returns malformed output that does not conform to this expected structure, API Gateway cannot properly map this response to an HTTP response for the client. Consequently, API Gateway returns an HTTP 502 Bad Gateway error, indicating that it received an invalid response from the upstream Lambda service.

Why this answer

A 502 Bad Gateway error from API Gateway typically indicates that the backend integration (in this case, the Lambda function) returned an error response. When a Lambda function throws an unhandled exception, API Gateway receives a 200 OK with a function error payload, but it cannot parse the response into a valid HTTP response, resulting in a 502. This is distinct from throttling or permission issues, which produce different HTTP status codes.

Exam trap

The trap here is that candidates often confuse 502 errors with throttling (429) or permission issues (403/500), but the 502 specifically points to a malformed or error response from the backend integration.

How to eliminate wrong answers

Option A is wrong because exceeding API Gateway request throttling limits results in a 429 Too Many Requests error, not a 502 Bad Gateway. Option B is wrong because an invalid API key causes a 403 Forbidden error, not a 502. Option D is wrong because if the Lambda function's execution role does not allow API Gateway to invoke it, API Gateway would return a 500 Internal Server Error or a 403, not a 502.

864
MCQmedium

A developer is working on an application that uses Amazon SQS as a message queue. The application polls the queue using long polling with a wait time of 20 seconds. Recently, the team noticed that messages are being processed multiple times. The application is idempotent, but duplicate processing is causing unnecessary costs. What should the developer do to reduce duplicate message processing?

A.Use a DynamoDB table to track processed message IDs and ignore duplicates.
B.Switch to a FIFO queue to enable exactly-once processing.
C.Increase the visibility timeout to a value greater than the maximum processing time.
AnswerA

Using a DynamoDB table to store unique message identifiers (e.g., SQS MessageId or a business transaction ID) allows the consumer to check if a message has already been processed before executing its logic. By performing a conditional write (e.g., PutItem with ConditionExpression attribute_not_exists(id)) to the DynamoDB table, the application ensures that the processing logic for a specific message ID is executed only once, effectively achieving idempotency and eliminating duplicate processing even with SQS's at-least-once delivery.

Why this answer

SQS standard queues provide at-least-once delivery, so duplicates are expected. Since the application is already idempotent, the developer should track processed message IDs in a DynamoDB table (with conditional writes or TTL) and skip messages already processed. This reduces redundant processing and cost without changing the queue type.

Exam trap

DVA-C02 often tests the misconception that FIFO queues guarantee exactly-once processing universally — candidates pick FIFO without realizing the 5-minute deduplication window and the architectural changes required, when idempotency with DynamoDB is the more practical answer.

How to eliminate wrong answers

Option B is wrong because FIFO queues provide exactly-once processing only within a 5-minute deduplication window and require a .fifo queue name, message group IDs, and deduplication IDs — switching queue types is a larger architectural change and does not guarantee exactly-once for all scenarios (e.g., retries after visibility timeout). Option C is wrong because increasing the visibility timeout only reduces duplicates caused by messages becoming visible again before processing completes; it does not address duplicates from at-least-once delivery or retries, and the question implies duplicates are already occurring.

865
MCQhard

A developer is creating an AWS Lambda function that processes events from an Amazon S3 bucket. The function writes logs to Amazon CloudWatch Logs. The developer wants to ensure that the Lambda function has the minimum required permissions. Which IAM policy should be attached to the Lambda execution role?

A.A policy that includes 'logs:CreateLogStream', 'logs:PutLogEvents', and 's3:*' on the bucket.
B.A policy that includes 'logs:*' and 's3:*' on the bucket.
C.A policy that includes 'logs:PutLogEvents' and 's3:ListBucket' on the bucket.
D.A policy that includes 'logs:CreateLogGroup', 'logs:CreateLogStream', 'logs:PutLogEvents', and 's3:GetObject' on the specific bucket.
AnswerD

This policy correctly adheres to the principle of least privilege by granting only the necessary permissions for a Lambda function to process an S3 object and log its execution. 'logs:CreateLogGroup' allows the function to create its dedicated log group, 'logs:CreateLogStream' enables the creation of log streams within that group, and 'logs:PutLogEvents' permits writing runtime logs to CloudWatch. 's3:GetObject' is the precise permission required to retrieve the S3 object's content, ensuring the function can perform its core task securely.

Why this answer

It grants the minimum required permissions for the Lambda function to read objects from the specific S3 bucket (s3:GetObject) and to write logs to CloudWatch Logs (logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents). The s3:GetObject action is necessary to process events from S3, and the three logs actions are the minimum needed for the Lambda runtime to create a log group, create a log stream, and write log events. This policy follows the principle of least privilege by scoping permissions to the specific bucket and avoiding wildcards.

Exam trap

The trap here is that candidates often forget that 'logs:CreateLogGroup' is required for the first invocation of a Lambda function, and they mistakenly choose a policy with only 'logs:PutLogEvents' or overly broad S3 permissions like 's3:*'.

How to eliminate wrong answers

Option A is wrong because it includes 's3:*' on the bucket, which grants all S3 actions (e.g., delete, put) far beyond the required 's3:GetObject', violating least privilege. Option B is wrong because it includes 'logs:*' (all CloudWatch Logs actions) and 's3:*' on the bucket, both overly permissive and not minimal. Option C is wrong because it omits 'logs:CreateLogGroup' and 'logs:CreateLogStream', which are required for the Lambda runtime to initialize logging, and includes 's3:ListBucket' instead of the necessary 's3:GetObject' for reading objects.

866
MCQmedium

A developer is using AWS Lambda to process records from an Amazon Kinesis Data Stream. The Lambda function is invoked with a batch of records. The function processes each record and then returns a response. The developer notices that some records are being processed multiple times. The function's execution time is within the Lambda timeout. The Kinesis stream has 10 shards. The developer wants to ensure that each record is processed exactly once. What should the developer do?

A.Reduce the number of shards to minimize the chance of duplicates.
B.Modify the Lambda function to use the sequence number of each record to deduplicate processing.
C.Configure the Lambda function's error handling to retry only failed records.
D.Increase the batch size to process more records per invocation.
AnswerB

Modifying the Lambda function to use the sequence number of each record is the correct approach for deduplication. Each record in a Kinesis stream has a unique sequence number within its shard, which, when combined with the shard ID, forms a globally unique identifier. By storing the last successfully processed sequence number (and shard ID) in a durable external data store, such as Amazon DynamoDB, the Lambda function can check if a record has already been processed before executing its business logic, effectively achieving idempotency.

Why this answer

The correct option is B: modify the Lambda function to use the sequence number of each record to deduplicate processing. AWS Lambda's Kinesis event source mapping provides at-least-once delivery, so a batch or individual records can be retried after a failure or timeout, causing duplicates; Kinesis sequence numbers uniquely identify each record within a shard, so the function can track processed sequence numbers (for example in DynamoDB) and skip records already handled. Option A is wrong because reducing shards does not change Lambda's at-least-once semantics and would only lower throughput.

Option C is wrong because retry configuration cannot prevent duplicates from Lambda's own retries or checkpointing behavior. Option D is wrong because a larger batch size does not provide exactly-once processing and can actually increase the number of records reprocessed after a failure.

867
MCQmedium

A developer notices that an AWS Lambda function, configured to access an Amazon RDS database in the same VPC, is timing out. The function has a 30-second timeout. CloudWatch Logs show that the function starts execution but never reaches the database. The VPC configuration includes private subnets without a NAT gateway. The RDS database is in the same VPC. What is the most likely cause of the timeout?

A.The Lambda function does not have internet access because it is in a VPC without a public IP.
B.The security group of the RDS database does not allow inbound traffic from the Lambda function's security group.
C.The Amazon RDS database is not publicly accessible and the Lambda function cannot resolve the database endpoint.
D.The VPC does not have a VPC endpoint for Amazon RDS, and the Lambda function cannot access the database through the NAT gateway.
AnswerB

For a Lambda function to successfully connect to an Amazon RDS database, the RDS instance's security group must explicitly permit inbound traffic on the database port (e.g., 3306 for MySQL, 5432 for PostgreSQL). A common best practice is to configure the RDS security group to allow inbound connections from the *security group associated with the Lambda function's ENIs*. If this rule is missing or incorrectly configured, the connection will be blocked, making this a highly probable cause of connectivity issues.

Why this answer

The Lambda function is timing out when trying to connect to the RDS database, which is in the same VPC. The most likely cause is that the RDS database's security group does not have an inbound rule allowing traffic from the Lambda function's security group on the database port (e.g., 3306 for MySQL, 5432 for PostgreSQL). Without this rule, the TCP connection attempt is silently dropped or rejected, causing the Lambda function to wait until its 30-second timeout expires.

Exam trap

The trap here is that candidates often assume the Lambda function needs internet access or a NAT gateway to communicate with an RDS database in the same VPC, overlooking the fact that security group rules are the primary control for inbound traffic within a VPC.

How to eliminate wrong answers

Option A is wrong because the Lambda function does not need internet access to reach an RDS database in the same VPC; private subnet communication within a VPC does not require a public IP or NAT gateway. Option C is wrong because the RDS database being publicly accessible is irrelevant when both resources are in the same VPC; DNS resolution of the database endpoint works via the VPC's internal DNS, and the Lambda function can resolve it without public access. Option D is wrong because a VPC endpoint for Amazon RDS is used for accessing RDS API operations (e.g., CreateDBInstance), not for database client connections (e.g., MySQL/PostgreSQL protocol), and the scenario explicitly states there is no NAT gateway, but the Lambda function does not need one to communicate within the VPC.

868
MCQhard

A web application runs on Amazon EC2 instances behind an Application Load Balancer (ALB). During rolling updates of the Auto Scaling group, users intermittently receive HTTP 502 (Bad Gateway) errors. The developer checks the ALB access logs and notices that requests are being routed to instances that are in the 'Draining' state. The ALB has connection draining enabled with a timeout of 30 seconds. The Auto Scaling group terminates instances after they are taken out of service. What is the most likely cause of the 502 errors?

A.The connection draining timeout is too short, causing the ALB to terminate connections before in-flight requests finish.
B.The health check interval is set too long, causing the ALB to consider unhealthy instances as healthy.
C.Cross-zone load balancing is disabled, so the ALB is routing requests to instances that are already draining.
D.The Auto Scaling group's minimum size is too small, causing the ALB to have no healthy targets.
AnswerA

When an EC2 instance is deregistered from an Application Load Balancer (ALB) target group, connection draining (also known as deregistration delay) begins. During this period, the ALB stops sending new requests to the instance but attempts to allow existing in-flight requests to complete. If the configured deregistration delay timeout is shorter than the time required for active requests to finish processing, the ALB will forcibly close those connections, leading to 502 Bad Gateway errors for the client, as the backend server did not return a proper response.

Why this answer

The 502 errors occur because the ALB's connection draining timeout of 30 seconds is too short to allow all in-flight requests to complete before the Auto Scaling group terminates the instances. When an instance enters the 'Draining' state, the ALB stops sending new requests but waits up to the draining timeout for existing connections to finish. If the timeout expires before requests complete, the ALB forcibly closes connections, resulting in HTTP 502 (Bad Gateway) errors for clients whose requests were still in progress.

Exam trap

The trap here is that candidates often confuse connection draining timeout with health check interval, assuming that a long health check interval causes the ALB to route to unhealthy instances, when in fact the 502 errors are caused by the ALB forcibly terminating connections before in-flight requests complete due to an insufficient draining timeout.

How to eliminate wrong answers

Option B is wrong because a long health check interval would cause the ALB to consider unhealthy instances as healthy for longer, but the issue here is that requests are being routed to instances already in the 'Draining' state, not that unhealthy instances are mistakenly considered healthy. Option C is wrong because cross-zone load balancing affects how traffic is distributed across Availability Zones, not the routing of requests to draining instances; the ALB routes to draining instances only when connection draining is active, regardless of cross-zone settings. Option D is wrong because a small minimum size would cause a lack of healthy targets, leading to 503 errors, not 502 errors; the 502 errors here are specifically tied to connection termination during draining, not insufficient capacity.

869
Multi-Selecteasy

A developer is using Amazon RDS for MySQL and notices that the database performance has degraded. The developer suspects that slow queries are the cause. Which THREE actions should the developer take to identify and address the slow queries?

Select 3 answers
A.Enable the slow query log in RDS and review the logs.
B.Increase the DB instance size to improve performance.
C.Enable Performance Insights to analyze database performance.
D.Use the RDS console to review metrics for high CPU or IOPS usage.
E.Create a read replica to offload read traffic.
AnswersA, C, D

The slow query log records every SQL statement that takes longer than the `long_query_time` threshold to execute, capturing the exact query text, execution time, lock time, and rows examined. Enabling it via the RDS parameter group (`slow_query_log=1`) is the most direct way to pinpoint which specific statements are causing the observed slowdown, allowing targeted optimization such as adding indexes or rewriting the query. This makes it the definitive first step for diagnosing slow queries at the statement level rather than relying on inferred metrics.

Why this answer

Option A is correct because enabling the MySQL slow query log on RDS captures queries exceeding long_query_time, and these logs can be downloaded or published to CloudWatch Logs for review to pinpoint offending SQL. Option C is correct because Performance Insights provides a database load view (DB load by wait event and SQL) so the developer can identify the top SQL statements and waits causing degradation. Option D is correct because RDS console CloudWatch metrics such as CPUUtilization and ReadIOPS/WriteIOPS help correlate resource saturation with suspected slow queries and confirm the bottleneck.

Option B is not appropriate as a first step because resizing the instance masks symptoms without identifying the slow queries and may not resolve inefficient SQL. Option E is also not appropriate because a read replica offloads read traffic but does not diagnose or fix the slow queries themselves.

Exam trap

DVA-C02 often tests the difference between diagnostic actions (slow query log, Performance Insights, CloudWatch metrics) and remediation/scaling actions (resize instance, read replica), so candidates who pick scaling options as 'fixes' miss the intent of identifying slow queries.

870
MCQhard

A developer notices that the Lambda function 'my-function' is not generating any logs in CloudWatch, although the function is invoked successfully. The developer runs the command above. What is the MOST likely cause?

A.The log group retention policy is set to 0 days.
B.The Lambda function is configured to log to a custom log group.
C.The Lambda function has reserved concurrency set to 0.
D.The Lambda function's execution role is missing the 'logs:CreateLogStream' and 'logs:PutLogEvents' permissions.
AnswerD

The Lambda function's execution role requires specific permissions to interact with CloudWatch Logs. The 'logs:CreateLogStream' permission allows the function to create a unique log stream for its execution environment within the designated log group, while 'logs:PutLogEvents' is essential for sending the actual log data to that stream. Without both of these critical permissions, the function cannot successfully publish any output or runtime messages to CloudWatch Logs, leading to the observation of no logs.

Why this answer

The log group exists but has 0 stored bytes, meaning no log streams have been created. This typically indicates that the Lambda function's execution role does not have permissions to create log streams and put log events. The function runs but fails silently to write logs.

871
MCQeasy

A developer is deploying a new version of a Lambda function using the AWS CLI. Which command should the developer use to update the function code?

A.aws lambda update-function-code
B.aws lambda update-function-configuration
C.aws lambda invoke
D.aws lambda create-function
AnswerA

aws lambda update-function-code is the correct command because it uploads a new deployment package (ZIP file or container image) to the Lambda service, replacing the code currently associated with the function. This command updates the function's code while preserving its configuration, and it operates on the $LATEST version unless you specify a different qualifying qualifier, making it the proper way to deploy a new code version.

Why this answer

The AWS CLI command `aws lambda update-function-code` is specifically designed to update the code of an existing Lambda function. It allows you to specify the function name and the location of the new code (e.g., S3 bucket and key, or a local zip file). This is the correct command for deploying a new version of the function code.

Exam trap

DVA-C02 often tests the distinction between updating function code versus configuration, so candidates might confuse the two commands.

How to eliminate wrong answers

Option B is wrong because `aws lambda update-function-configuration` updates settings like memory, timeout, environment variables, and IAM role, but not the function code. Option C is wrong because `aws lambda invoke` is used to invoke a Lambda function, not update it. Option D is wrong because `aws lambda create-function` creates a new Lambda function, not update an existing one.

872
Multi-Selecthard

A developer is designing a serverless application that uses Amazon DynamoDB as the data store. The application must handle sudden spikes in read traffic without throttling. Which THREE actions should the developer take?

Select 3 answers
A.Configure DynamoDB auto scaling for the table
B.Implement exponential backoff and retry in the application code
C.Use a global secondary index with a different partition key
D.Use strongly consistent reads for all queries
E.Enable DynamoDB Accelerator (DAX) for caching
AnswersA, B, E

DynamoDB auto scaling dynamically adjusts the provisioned read and write capacity units (RCUs/WCUs) for a table or global secondary index based on actual traffic patterns. By automatically increasing capacity during peak loads and decreasing it during lulls, auto scaling ensures that the table has sufficient throughput to handle incoming requests, effectively preventing throttling errors caused by exceeding provisioned limits.

Why this answer

DynamoDB auto scaling (option A) dynamically adjusts the provisioned read and write capacity based on actual traffic patterns, using CloudWatch alarms and the Application Auto Scaling service. This ensures the table can handle sudden spikes in read traffic without manual intervention, preventing throttling exceptions.

Exam trap

The trap here is that candidates often confuse throttling prevention mechanisms (auto scaling, caching) with throttling mitigation techniques (exponential backoff) or unrelated features (GSIs, consistency models), leading them to select options that do not actually prevent throttling.

873
MCQeasy

A development team uses AWS Elastic Beanstalk to deploy a containerized application. They notice that after a successful deployment, the environment's health turns from Green to Red. The application logs show no errors. What is the most likely cause?

A.The ELB health check endpoint returns a 503 status code after the new version is deployed.
B.The deployment failed due to a missing environment variable.
C.The application's Docker image is not compatible with the platform version.
D.The Auto Scaling group's minimum instance count is too low.
AnswerA

Elastic Beanstalk's enhanced health reporting is derived primarily from the associated load balancer's target health checks; if the new application version returns HTTP 503 (or fails to respond) on the configured health check path after deployment, the ELB marks targets unhealthy and Beanstalk immediately reflects that as Red, even though application-level logs show nothing because the failure is at the HTTP response layer, not an exception.

Why this answer

After a successful deployment, the environment turns Red if the ELB health check endpoint returns a non-200 status (e.g., 503) on the new version. Elastic Beanstalk uses ELB health checks to determine environment health; if the health check fails, the environment health changes to Red even if application logs show no errors. Option B is incorrect because a missing environment variable typically causes deployment failure or immediate instance health issues, not a post-deployment health change.

Option C is incorrect because Docker image incompatibility with the platform version would cause deployment failure or instance launch failure, not a health change after successful deployment. Option D is incorrect because a low Auto Scaling minimum instance count does not directly affect health status after a successful deployment; it would affect scaling behavior.

874
MCQhard

A company wants to encrypt data at rest in an Amazon RDS for PostgreSQL database. The database is already running, and the company wants to enable encryption without significant downtime. Which approach should be taken?

A.Take a snapshot of the database and enable encryption on the snapshot.
B.Take a snapshot, copy the snapshot with encryption, and restore a new encrypted instance from the encrypted snapshot.
C.Modify the RDS instance and enable encryption in the configuration.
D.Create a read replica with encryption and promote it.
AnswerB

This is the correct and standard procedure for adding encryption to an existing unencrypted Amazon RDS instance. First, a snapshot captures the current data of the unencrypted instance. Then, this unencrypted snapshot is copied, and crucially, during the copy process, encryption with an AWS Key Management Service (KMS) key is enabled. Finally, a new encrypted RDS instance is launched from this newly encrypted snapshot, effectively migrating the data to an encrypted environment.

Why this answer

RDS encryption at rest can only be enabled at instance creation time, so an existing unencrypted instance must be migrated. The supported path is to snapshot the instance, copy the snapshot with encryption enabled, then restore a new encrypted DB instance from that encrypted snapshot — this yields an encrypted database with only the downtime of the cutover.

Exam trap

DVA-C02 often tests that RDS encryption cannot be enabled in place — candidates pick 'Modify the instance' or 'encrypt the snapshot' because those seem simpler, but the only valid path is snapshot → encrypted copy → restore.

How to eliminate wrong answers

Option A is wrong because you cannot enable encryption directly on an existing snapshot; snapshots inherit the encryption state of their source, and there is no 'encrypt this snapshot' toggle. Option C is wrong because RDS does not allow enabling encryption via a Modify operation on a running instance — the encryption setting is immutable after creation. Option D is wrong because read replicas inherit the encryption state of the primary; you cannot create an encrypted read replica from an unencrypted primary, so this approach is not possible.

875
MCQhard

A developer wants exactly-once processing semantics for commands submitted to a queue where duplicate command IDs must be rejected within five minutes. Which SQS feature is most directly relevant?

A.Standard queue delay seconds
B.Dead-letter queue redrive policy
C.FIFO queue deduplication ID
D.Visibility timeout extension
AnswerC

The "MessageDeduplicationId" in an Amazon SQS FIFO queue is the primary mechanism for achieving exactly-once processing semantics by preventing duplicate messages from being added to the queue. When a producer sends a message with a specific deduplication ID, SQS ensures that any subsequent message sent with the same ID within a 5-minute deduplication interval is treated as a duplicate and not delivered to the queue. This directly guarantees that a command is enqueued and thus processed only once, even if the producer attempts to send it multiple times.

Why this answer

FIFO queues support exactly-once processing by using a deduplication ID. When a message with a given deduplication ID is sent, SQS automatically rejects any duplicate within a 5-minute deduplication interval. This directly meets the requirement to reject duplicate command IDs within five minutes.

Exam trap

The trap here is that candidates confuse visibility timeout (which controls reprocessing) with deduplication (which prevents duplicate submissions), leading them to select option D instead of the correct FIFO deduplication ID feature.

How to eliminate wrong answers

Option A is wrong because standard queue delay seconds only postpone message delivery, they do not provide deduplication or exactly-once semantics. Option B is wrong because a dead-letter queue redrive policy moves messages after repeated processing failures, it does not prevent duplicate submissions. Option D is wrong because visibility timeout extension only prevents other consumers from processing a message while it is being handled, it does not reject duplicates.

876
MCQmedium

A company uses AWS KMS to encrypt data at rest. A developer wants to allow a Lambda function to decrypt data using a KMS key. What is the minimum permissions required?

A.kms:Decrypt on all keys.
B.kms:Encrypt and kms:Decrypt on the key.
C.kms:Decrypt on the key in the Lambda execution role.
D.Full access to KMS.
AnswerC

Attaching a policy statement granting only kms:Decrypt, scoped to the specific key's ARN, on the Lambda execution role is exactly the least-privilege permission needed — it grants decrypt capability for that one key and nothing more.

Why this answer

The minimum permission required is kms:Decrypt on the specific key, attached to the Lambda execution role. The Lambda function only needs to decrypt data, not encrypt it, so kms:Decrypt is sufficient. Granting it on the specific key follows the principle of least privilege.

Exam trap

DVA-C02 often tests least privilege, and candidates may choose kms:Encrypt and kms:Decrypt thinking both are needed, but the question specifies only decryption.

How to eliminate wrong answers

Option A is wrong because granting kms:Decrypt on all keys is overly broad and violates least privilege. Option B is wrong because kms:Encrypt is not needed if the function only decrypts. Option D is wrong because full access to KMS is excessive and insecure.

877
MCQmedium

A developer is building a REST API using Amazon API Gateway that will serve static content from an Amazon S3 bucket. The API should cache responses for frequently accessed objects to reduce latency. Which API Gateway feature should the developer enable?

A.API Gateway caching with TTL set per method.
B.Amazon CloudFront as a custom domain.
C.Lambda@Edge for caching.
D.S3 Transfer Acceleration.
AnswerA

API Gateway offers built-in caching capabilities that can be enabled per stage or per method. This feature stores responses from your backend integrations, reducing the number of requests sent to your backend and significantly improving API response times for repeat requests. You can configure a Time To Live (TTL) for cached responses, allowing precise control over how long data remains in the cache before being refreshed, which is crucial for managing data freshness and reducing backend load.

Why this answer

API Gateway caching allows you to cache responses from your backend (e.g., an S3 bucket) for a specified Time-to-Live (TTL) per method, reducing the number of calls to the backend and lowering latency for frequently accessed objects. This feature is natively integrated with API Gateway and requires no additional services or complex configurations, making it the most direct solution for caching static content served through a REST API.

Exam trap

The trap here is that candidates often confuse API Gateway caching with CloudFront, assuming that a CDN is required for caching, when in fact API Gateway has its own built-in caching feature that is simpler to enable for REST APIs serving static content.

How to eliminate wrong answers

Option B is wrong because Amazon CloudFront as a custom domain is a content delivery network (CDN) that can cache content at edge locations, but it is not an API Gateway feature; it is a separate service that would be placed in front of API Gateway, not enabled within API Gateway itself. Option C is wrong because Lambda@Edge is used for customizing CloudFront behavior (e.g., modifying requests/responses) and is not a caching mechanism; it runs code at edge locations but does not provide built-in response caching like API Gateway caching. Option D is wrong because S3 Transfer Acceleration is designed to speed up uploads to S3 over long distances using AWS edge locations, but it does not cache responses or reduce latency for GET requests served through API Gateway.

878
MCQeasy

A developer runs a script that uses the AWS CLI to copy a large number of files from an on-premises server to an S3 bucket. The copy operation fails partway through with a 'RequestTimeout' error. What is the MOST efficient way to resume the copy and ensure all files are transferred?

A.Delete the S3 bucket and restart the copy operation.
B.Use the aws s3 sync command to synchronize the source directory with the S3 bucket.
C.Use the cp command with the --recursive flag to copy the remaining files.
D.Increase the --cli-read-timeout value in the AWS CLI configuration and retry the original command.
AnswerB

The aws s3 sync command is the most appropriate and efficient solution for resuming an interrupted file transfer to S3. It intelligently compares the source directory with the S3 bucket, identifying only files that are new, have changed content (based on size and modification time), or are missing from the destination. This ensures that only the necessary data is transferred, minimizing bandwidth usage and significantly reducing the time required to complete the operation.

Why this answer

The `aws s3 sync` command is the most efficient way to resume the copy because it automatically compares the source directory with the destination S3 bucket and transfers only the files that are missing or have been modified. This avoids re-uploading already transferred files, directly addressing the partial failure without manual intervention or unnecessary overhead.

Exam trap

The trap here is that candidates often confuse `cp --recursive` with `sync`, assuming both can resume a copy, but only `sync` performs a differential comparison to avoid re-uploading already transferred files.

How to eliminate wrong answers

Option A is wrong because deleting the S3 bucket and restarting the entire copy operation is extremely inefficient and unnecessary; it would re-upload all files, including those already successfully transferred. Option C is wrong because the `cp --recursive` command does not perform any comparison or state tracking; it would blindly copy all files from the source again, potentially re-uploading already transferred files and wasting time and bandwidth. Option D is wrong because increasing the `--cli-read-timeout` only extends the time the CLI waits for a response from the S3 service; it does not address the root cause of the partial failure (e.g., network interruptions or throttling) and would not resume the copy from where it left off, nor does it skip already transferred files.

879
MCQeasy

A developer is troubleshooting an S3 bucket policy that is denying all access. The policy has an explicit Deny for s3:PutObject. What is the most likely reason for the denial even though an Allow exists?

A.The bucket policy has an explicit Deny for all actions.
B.The user is not authorized because the bucket is in a different account.
C.IAM evaluates explicit Deny before Allow.
D.The AWS account root user has denied access.
AnswerC

This statement accurately describes a fundamental principle of AWS Identity and Access Management (IAM) policy evaluation. When multiple policies apply to a request, IAM first checks for any explicit Deny statements. If an explicit Deny exists for the requested action or resource, the request is immediately denied, regardless of any explicit Allow statements that might also be present. An explicit Deny always overrides an explicit Allow, making it the most powerful permission modifier in the evaluation logic.

Why this answer

IAM policy evaluation logic explicitly states that an explicit Deny always overrides any Allow. In S3 bucket policies, if any statement includes an explicit Deny for s3:PutObject that matches the principal and resource, the request is denied regardless of other Allow statements. This is the core reason the denial occurs even when an Allow exists.

Exam trap

DVA-C02 often tests the 'explicit Deny always wins' rule, but candidates sometimes think an Allow in a different policy can override a Deny, or that the most specific policy wins — the exam expects you to know Deny is absolute.

How to eliminate wrong answers

Option A is wrong because the question states the policy has an explicit Deny for s3:PutObject, not for all actions; a blanket Deny for all actions would be a different (and broader) misconfiguration. Option B is wrong because cross-account access can be a factor, but the question already establishes an explicit Deny for s3:PutObject as the cause; cross-account alone does not cause denial if the bucket policy allows it. Option D is wrong because the root user does not 'deny access' via a separate mechanism; root has full permissions unless an SCP or explicit Deny applies, and the question's Deny is in the bucket policy.

880
MCQmedium

A company uses AWS CodeDeploy to deploy a web application to an Auto Scaling group. The deployment fails, and the rollback is triggered. However, the rollback also fails. What is a likely cause?

A.The rollback deployment uses an AppSpec file that references a lifecycle hook that does not exist in the current environment.
B.The target group for the load balancer is not properly configured.
C.The Amazon S3 bucket containing the deployment artifacts is missing.
D.The Auto Scaling group does not have sufficient capacity to run the rollback.
AnswerA

A CodeDeploy rollback re-deploys a previously successful application revision, utilizing that revision's specific AppSpec file. If this AppSpec file contains a 'hooks' section referencing a script, an IAM role, or a lifecycle event that has since been removed or become invalid in the target environment, the rollback deployment will fail when attempting to execute that non-existent or misconfigured hook. This scenario highlights how environmental drift can cause a previously successful revision's deployment instructions to become unexecutable.

Why this answer

The correct option is A: the rollback deployment uses an AppSpec file that references a lifecycle hook that does not exist in the current environment. During a CodeDeploy rollback, CodeDeploy redeploys the last known good revision, and if that revision's AppSpec file defines a lifecycle event hook (for example, a Lambda validation hook or a script in the wrong location) that is not present or valid in the current environment, the rollback deployment will fail just as the original did. Options B, C, and D are less likely because a misconfigured load balancer target group, a missing S3 artifact bucket, or insufficient Auto Scaling capacity would typically cause the initial deployment to fail rather than specifically explaining why the rollback itself fails due to the prior revision's configuration.

Exam trap

A common trap is assuming rollback always succeeds if the original deployment did. Rollback can fail if the previous version's AppSpec file references resources (e.g., lifecycle hooks) that have been removed or changed.

881
MCQeasy

An application running on Amazon EC2 generates logs that need to be streamed to Amazon CloudWatch Logs. The developer installs and configures the CloudWatch agent. However, logs are not appearing in the log group. What is the most likely cause?

A.The EC2 instance does not have an IAM role with CloudWatch Logs write permissions.
B.The CloudWatch agent cannot be installed on Amazon Linux 2.
C.The CloudWatch agent must be configured from the AWS Management Console.
D.The log group must be created manually before the agent can send logs.
AnswerA

The CloudWatch agent, when running on an EC2 instance, requires an associated IAM role with specific permissions to interact with CloudWatch Logs. Without an IAM policy granting actions such as logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents, the agent will be unauthorized to publish log events to the designated log group and stream. This is a fundamental security requirement, ensuring that AWS services only perform actions for which they have explicit authorization.

Why this answer

The CloudWatch agent requires IAM permissions to call CloudWatch Logs APIs (CreateLogGroup, CreateLogStream, PutLogEvents). On EC2, these permissions are provided via an instance profile attached to the instance. If the instance lacks an IAM role with CloudWatch Logs write permissions, the agent cannot publish logs, and they will not appear in the log group.

Exam trap

DVA-C02 often tests whether candidates know the CloudWatch agent needs an IAM role with logs permissions — candidates incorrectly blame installation, console configuration, or pre-created log groups instead of the missing instance profile.

How to eliminate wrong answers

Option B is wrong because the CloudWatch agent is fully supported on Amazon Linux 2 — it is the recommended platform. Option C is wrong because the agent is configured via a JSON config file on the instance (or via SSM), not from the AWS Management Console. Option D is wrong because the agent can create the log group automatically if the config specifies it and the IAM role has CreateLogGroup permission; manual creation is not required.

882
MCQmedium

A developer is using AWS Elastic Beanstalk to deploy a web application. The application requires a relational database. The developer wants to ensure that the database is not accidentally deleted when the Elastic Beanstalk environment is terminated. Which approach should the developer take?

A.Create the database as part of the Elastic Beanstalk environment by adding an RDS database configuration in the .ebextensions.
B.Create the RDS instance outside of Elastic Beanstalk and configure the application to connect to it using environment variables.
C.Use an Amazon DynamoDB table instead of a relational database.
D.Configure a retention policy on the RDS instance within the Elastic Beanstalk environment.
AnswerB

Creating the RDS instance outside Elastic Beanstalk decouples its lifecycle from the environment, so terminating the environment leaves the database intact. Environment variables pass connection details to the application, satisfying the no-accidental-deletion requirement without relying on Elastic Beanstalk's coupled database option.

Why this answer

Creating the RDS instance outside of Elastic Beanstalk decouples the database lifecycle from the environment lifecycle. When the Elastic Beanstalk environment is terminated, the external RDS instance remains intact and is not deleted. The application can connect to it using environment variables configured in the Elastic Beanstalk environment, ensuring persistence of data.

Exam trap

The trap here is that candidates may assume that adding a retention policy (Option D) is possible within Elastic Beanstalk, but Elastic Beanstalk does not expose a retention policy for RDS instances created as part of the environment; the database is always deleted with the environment unless it is created externally.

How to eliminate wrong answers

Option A is wrong because adding an RDS database configuration in .ebextensions creates the database as part of the Elastic Beanstalk environment, which means it will be deleted when the environment is terminated. Option C is wrong because DynamoDB is a NoSQL database, not a relational database, and the question explicitly requires a relational database. Option D is wrong because Elastic Beanstalk does not support configuring a retention policy on an RDS instance created within the environment; the database is tied to the environment's lifecycle and will be deleted upon termination.

883
MCQmedium

A company wants to encrypt data in transit between an Application Load Balancer and its EC2 instances. The instances run a custom web server. Which configuration should the developer implement?

A.Configure the ALB listener with a TLS certificate and set the target group protocol to HTTPS. Install the server certificate on the EC2 instances.
B.Use AWS Certificate Manager to issue a certificate for the EC2 instances and configure the web server to use it.
C.Configure the ALB listener with a TLS certificate and set the target group protocol to HTTP.
D.Enable client certificate authentication on the ALB.
AnswerA

Configuring the ALB listener with a TLS certificate ensures traffic from the client to the ALB is encrypted. By setting the target group protocol to HTTPS, the ALB then re-encrypts this traffic before forwarding it to the backend EC2 instances. The EC2 instances must have their own server certificates installed and configured on their web servers to successfully complete the TLS handshake, thereby providing comprehensive end-to-end encryption for data in transit.

Why this answer

To encrypt data in transit between an Application Load Balancer (ALB) and EC2 instances, the ALB listener must be configured with a TLS certificate for client-to-ALB encryption, and the target group protocol must be set to HTTPS to enable encryption between the ALB and the instances. The EC2 instances must have a server certificate installed (e.g., from ACM or self-signed) to terminate the TLS connection, ensuring end-to-end encryption. This setup allows the ALB to re-encrypt traffic after decrypting it from the client, using HTTPS for the backend connection.

Exam trap

The trap here is that candidates often assume setting the ALB listener to HTTPS alone encrypts the entire path, forgetting that the target group protocol must also be HTTPS to encrypt the ALB-to-instance traffic, or they mistakenly think ACM certificates can be directly installed on EC2 instances.

How to eliminate wrong answers

Option B is wrong because AWS Certificate Manager (ACM) cannot issue certificates directly to EC2 instances; ACM certificates are designed for use with AWS services like ALB, CloudFront, or API Gateway, and cannot be exported for installation on custom web servers. Option C is wrong because setting the target group protocol to HTTP sends unencrypted traffic between the ALB and EC2 instances, failing to encrypt data in transit as required. Option D is wrong because client certificate authentication on the ALB is used for mutual TLS (mTLS) to verify client identity, not for encrypting data in transit between the ALB and backend instances.

884
Multi-Selectmedium

Which TWO actions can help protect an S3 bucket from data leaks? (Choose two.)

Select 2 answers
A.Enable versioning.
B.Enable default encryption.
C.Enable MFA Delete.
D.Block public access at the bucket level.
E.Configure cross-region replication.
AnswersB, D

Enabling default encryption for an S3 bucket ensures that all newly written objects are encrypted at rest, either with SSE-S3 (AES-256) or SSE-KMS, so the raw data is stored as ciphertext. This protects against data leaks where an attacker gains access to the underlying storage media or backups, because they cannot interpret the encrypted bytes without the decryption keys. Note that default encryption is not a replacement for access control; it is a confidentiality layer that complements IAM policies and Block Public Access, and it can be enforced at the bucket policy level to reject unencrypted writes.

Why this answer

Option B (Enable default encryption) is correct because it ensures that all objects written to the bucket are encrypted at rest using SSE-S3, SSE-KMS, or SSE-C, so even if objects are inadvertently exposed or accessed without authorization, the data remains unreadable without the appropriate keys. Option D (Block public access at the bucket level) is correct because S3 Block Public Access settings override bucket policies and ACLs to prevent any public exposure, which is the primary vector for S3 data leaks. Option A (Enable versioning) only preserves object versions and aids recovery from overwrites or deletions; it does not prevent unauthorized access or public exposure.

Option C (Enable MFA Delete) adds protection against accidental or malicious deletion of object versions but does not stop data from being read or leaked. Option E (Configure cross-region replication) copies objects to another region for durability and latency, but it does not restrict access and can even widen the exposure surface if the destination bucket is misconfigured.

Exam trap

DVA-C02 often tests the misconception that versioning or MFA Delete prevent data leaks, when they actually address data integrity and deletion protection, not access control.

885
MCQeasy

A developer is deploying a new version of an application to Amazon ECS using the Fargate launch type. The task fails to start and the error message indicates that the task cannot pull the container image from Amazon ECR. What is the MOST likely cause?

A.The task definition family name is incorrect.
B.The task execution role lacks permissions to pull from ECR.
C.The container port is not mapped to a host port.
D.The CPU or memory limits are too low for the container.
AnswerB

The task execution role is critical for allowing the Amazon ECS agent to perform necessary actions on your behalf, including pulling container images from private repositories like Amazon ECR. If this role lacks specific permissions such as `ecr:GetDownloadUrlForLayer`, `ecr:BatchGetImage`, and `ecr:BatchCheckLayerAvailability`, the ECS agent will be unauthorized to retrieve the image layers. Consequently, the container runtime will fail to download the image, resulting in a distinct image pull error.

Why this answer

The error message indicates a failure to pull the container image from Amazon ECR. The task execution role must have permissions such as ecr:GetDownloadUrlForLayer and ecr:BatchGetImage to pull images. Option A is wrong because the task definition family name does not affect image pulling.

Option C is wrong because Fargate does not use host port mapping; container port mapping is handled automatically. Option D is wrong because insufficient CPU or memory typically results in a different error (e.g., task stuck in provisioning), not an image pull failure.

886
MCQeasy

A developer is building a serverless application using AWS Lambda that needs to connect to an Amazon RDS MySQL database. The function will be deployed in a VPC. Which resource should the developer use to ensure secure and efficient database connections?

A.NAT Gateway
B.RDS Proxy
C.VPC Endpoint
D.AWS PrivateLink
AnswerB

RDS Proxy is specifically designed to manage and pool database connections for applications like AWS Lambda, which often create many short-lived connections. It sits between your Lambda function and the RDS database, maintaining a pool of established connections to the database. This significantly reduces the overhead of establishing new connections, improves scalability, and enhances security by integrating with AWS Secrets Manager for credential management and IAM for authentication.

Why this answer

RDS Proxy is the correct choice because it manages a pool of database connections, allowing Lambda functions to reuse them efficiently and avoid exhausting MySQL connection limits under high concurrency. It also enforces IAM authentication and securely stores credentials in AWS Secrets Manager, eliminating the need to hardcode database passwords in the function code.

Exam trap

The trap here is that candidates often confuse VPC Endpoints or PrivateLink with database connectivity, not realizing that RDS Proxy is the only service designed specifically to solve connection management and security for Lambda functions accessing RDS in a VPC.

How to eliminate wrong answers

Option A is wrong because a NAT Gateway provides outbound internet access for private subnets but does not manage or secure database connections; it would not help with connection pooling or credential management. Option C is wrong because a VPC Endpoint (Gateway or Interface) enables private connectivity to AWS services like S3 or DynamoDB, not to RDS databases; it does not handle connection pooling or authentication for MySQL. Option D is wrong because AWS PrivateLink is used to expose services privately across VPCs or accounts via Network Load Balancers and interface endpoints, but it does not provide the connection pooling, IAM integration, or failover capabilities that RDS Proxy offers for Lambda-to-RDS connections.

887
MCQeasy

A developer is using AWS Elastic Beanstalk to deploy a Python web application. The application requires a specific version of a Python package that is not pre-installed on the Elastic Beanstalk platform. How should the developer ensure the package is installed on all environment instances?

A.Use the AWS CLI to run a script on each instance after deployment.
B.Include a .ebextensions configuration file that runs a command to install the package.
C.Add the package to a requirements.txt file and deploy it with the application source bundle.
D.Create a custom Dockerfile and use the Docker platform in Elastic Beanstalk.
AnswerC

While requirements.txt is the standard and preferred method for declaring Python application dependencies that pip can install, it is primarily designed for Python packages available via PyPI or specified URLs. This method is insufficient for installing system-level packages, libraries that require specific compilation flags, or dependencies that need custom shell commands to set up. For such non-standard or operating system-level requirements, requirements.txt alone cannot fulfill the installation.

Why this answer

AWS Elastic Beanstalk natively supports Python package management. If you include a `requirements.txt` file in the root directory of your source bundle, Elastic Beanstalk automatically installs the specified packages (and their specific versions, e.g., `package==1.2.3`) using `pip` during the deployment process. While `.ebextensions` can run custom commands, using it to install Python packages is non-standard, complex (due to virtual environment paths on Amazon Linux 2/2023), and unnecessary.

Exam trap

Candidates often overcomplicate Elastic Beanstalk deployments by assuming custom configuration files (`.ebextensions`) or Docker containers are required for basic dependency management. For supported platforms like Python, Node.js, and Ruby, Elastic Beanstalk natively respects standard package managers (like `requirements.txt`, `package.json`, or `Gemfile`).

How to eliminate wrong answers

Option A is wrong because using the AWS CLI to run a script on each instance after deployment is not an automated, repeatable approach; it requires manual intervention and does not integrate with Elastic Beanstalk's deployment lifecycle. Option C is wrong because a `requirements.txt` file is only automatically processed by Elastic Beanstalk if the platform's Python environment uses it during the `pip install` step; however, the question specifies a package that is 'not pre-installed,' and simply adding it to `requirements.txt` will not work if the package requires system-level dependencies or custom installation steps that `pip` alone cannot handle. Option D is wrong because creating a custom Dockerfile and using the Docker platform is an overengineered solution for a simple package installation; it adds unnecessary complexity and is not the standard way to install a Python package on the Elastic Beanstalk Python platform.

888
Multi-Selectmedium

A company is deploying a critical application using AWS CloudFormation. The stack creation fails due to a resource creation failure. The developer needs to troubleshoot the issue. Which TWO actions should the developer take to identify the root cause? (Choose TWO.)

Select 2 answers
A.View the stack events in the CloudFormation console.
B.Check the stack outputs.
C.Delete the stack and recreate it with the same parameters.
D.Review the stack template for logical errors.
E.Check AWS CloudTrail logs for the stack creation attempt.
AnswersA, D

Viewing stack events in the CloudFormation console is the direct diagnostic path. During stack creation, every resource activity is logged as an event with a status (CREATE_IN_PROGRESS, CREATE_FAILED, etc.) and a 'status reason' field. That status reason for the first failed resource contains the precise underlying error returned by the AWS service (for example, an EC2 error or an IAM permission problem), making it the authoritative source for troubleshooting a failed stack.

Why this answer

Option A is correct because CloudFormation records every resource-level status transition (CREATE_IN_PROGRESS, CREATE_FAILED, etc.) as a stack event, and the event for the failed resource includes the exact StatusReason returned by the underlying service, which is the fastest way to pinpoint the root cause. Option D is correct because a resource creation failure is frequently caused by an invalid template definition — for example a bad property value, an incorrect intrinsic function reference, or a missing required parameter — so reviewing the template for logical errors validates the resource configuration against the service's requirements. Option B is not appropriate because stack outputs are only populated after resources are successfully created and are not generated for a failed stack, so they contain no troubleshooting data.

Option C is not appropriate because deleting and recreating with identical parameters reproduces the same failure without gathering any diagnostic information. Option E is not appropriate because CloudTrail logs API calls made to AWS services (such as CreateStack), not the internal per-resource failure reasons that CloudFormation surfaces in stack events.

Exam trap

DVA-C02 often tests whether candidates know that stack events contain the specific resource failure reason, while CloudTrail is for API auditing — the trap is picking CloudTrail or stack outputs as the primary troubleshooting source.

889
Multi-Selecteasy

Which TWO services can be used to encrypt data at rest in Amazon S3? (Choose two.)

Select 2 answers
A.SSE-KMS
B.AWS IAM
C.AWS Certificate Manager (ACM)
D.AWS CloudHSM
E.SSE-S3
AnswersA, E

SSE-KMS encrypts each object using a data key generated and protected by an AWS KMS customer managed or AWS managed key, giving administrators fine-grained IAM control over who can use the key, a full CloudTrail audit trail of key usage, and support for key rotation.

Why this answer

Options A and E are correct. Option A: SSE-KMS uses AWS Key Management Service (KMS) for managing encryption keys, providing additional control and audit capabilities. Option E: SSE-S3 uses S3-managed keys for encryption at rest.

Option B is incorrect because AWS IAM is an access management service, not an encryption service. Option C is incorrect because AWS Certificate Manager (ACM) handles SSL/TLS certificates, not data encryption. Option D is incorrect because AWS CloudHSM provides hardware security modules but is not directly integrated with S3 for encryption.

Exam trap

Candidates often confuse the two server-side encryption options (SSE-S3 and SSE-KMS) and may forget that both can encrypt data at rest in S3. Also, IAM and ACM are not encryption services.

890
Multi-Selecthard

A developer is building a CI/CD pipeline using AWS CodePipeline. The pipeline has a source stage from Amazon S3, a build stage using AWS CodeBuild, and a deploy stage using AWS CodeDeploy. The developer wants to ensure that a manual approval step is required before deploying to production. Which THREE components must be configured? (Choose THREE.)

Select 3 answers
A.Create an AWS Lambda function to process approval logic.
B.Set up an Amazon SNS topic to notify approvers of pending approval.
C.Add an approval action in the pipeline before the deploy stage.
D.Attach an IAM policy to the approver group that allows codepipeline:PutApprovalResult.
E.Configure Amazon CloudWatch Events to trigger the approval step.
AnswersB, C, D

Setting up an Amazon SNS topic is a fundamental step when configuring a manual approval action in AWS CodePipeline. This SNS topic serves as the primary mechanism for automatically notifying designated approvers, typically via email or other subscribed endpoints, that a pipeline execution has reached a manual approval gate and is awaiting their intervention. Without an associated SNS topic, approvers would lack timely, automated alerts regarding pending approvals, potentially causing significant delays in the deployment process.

Why this answer

Amazon SNS is used to send notifications to approvers when a manual approval action is pending in the pipeline. The approval action in CodePipeline can be configured with an SNS topic ARN, and when the pipeline reaches that stage, it publishes a notification to the topic, alerting approvers to review and approve or reject the deployment.

Exam trap

The trap here is that candidates might think a custom Lambda function or CloudWatch Events is needed to implement the approval logic, but CodePipeline provides a native approval action that handles both the pause and notification via SNS, requiring only the IAM permission to submit the result.

891
MCQhard

A company's DynamoDB table has a read capacity of 10,000 RCUs and receives consistent traffic. Recently, users have reported increased latency for read requests. The application uses strongly consistent reads. The developer checks CloudWatch metrics and sees that 'ConsumedReadCapacityUnits' is at 9,500 but 'ThrottledRequests' is high. What is the most likely cause?

A.The application is using eventually consistent reads but expecting strongly consistent results.
B.A hot partition is exceeding its partition-level read capacity.
C.The DynamoDB table has auto scaling enabled and is scaling down too aggressively.
D.The provisioned read capacity is too low for the traffic.
AnswerB

DynamoDB distributes provisioned capacity evenly across its underlying partitions. If a specific partition key receives a disproportionately high volume of read requests, it can exhaust its allocated share of the table's total read capacity, even if the overall table capacity is not fully utilized. This scenario, known as a 'hot partition,' causes throttling errors for requests targeting that specific partition, despite ample table-level RCUs.

Why this answer

The correct answer is B: a hot partition is exceeding its partition-level read capacity. Even though the table's total consumed read capacity (9,500 of 10,000 RCUs) is below the provisioned limit, DynamoDB distributes capacity across partitions, and a single partition can only support a maximum of 3,000 RCUs (or 1,000 WCUs); if one partition key receives disproportionate traffic, that partition throttles requests while overall table capacity remains underutilized, which matches the high ThrottledRequests with consumed capacity below the table maximum. Option D is wrong because the table-level provisioned capacity is not exhausted (9,500 < 10,000), so low capacity is not the cause.

Option A is wrong because the scenario states the application uses strongly consistent reads, and switching consistency would not explain throttling. Option C is wrong because auto scaling scaling down would reduce provisioned capacity, but the metric shows consumed capacity still below the provisioned 10,000 RCUs, and aggressive scale-down is not the typical cause of partition-level throttling.

892
MCQhard

A company runs a containerized application on Amazon ECS Fargate. The application writes logs to stdout. The operations team wants to centralize log monitoring and set up alarms for error patterns. What should a developer do to meet these requirements with minimal operational overhead?

A.Use Amazon Kinesis Data Firehose to stream logs to Amazon S3 and then to CloudWatch Logs.
B.Modify the application code to use the AWS SDK for CloudWatch Logs to put log events.
C.Install the CloudWatch agent in the container and configure it to send logs.
D.Configure the ECS task definition to use the awslogs log driver and set the log group.
AnswerD

Configuring the ECS task definition to utilize the `awslogs` log driver is the recommended and most efficient method for sending container logs from Fargate tasks to Amazon CloudWatch Logs. This native integration automatically captures `stdout` and `stderr` streams from your containers and delivers them to a specified CloudWatch Logs log group. It simplifies log management, centralizes monitoring, and requires no application code changes or agent deployments within the container.

Why this answer

The awslogs log driver is the native, zero-configuration way to send container stdout/stderr to Amazon CloudWatch Logs from ECS Fargate. By specifying the awslogs log driver and a log group in the task definition, logs are automatically forwarded without any additional agents, code changes, or infrastructure, meeting the requirement for minimal operational overhead.

Exam trap

The trap here is that candidates often overthink the solution and choose Option C (installing the CloudWatch agent) because they are familiar with it from EC2, forgetting that Fargate does not support host-level agents and that the awslogs driver is the built-in, agentless alternative.

How to eliminate wrong answers

Option A is wrong because Amazon Kinesis Data Firehose streams logs to S3, but then sending them to CloudWatch Logs requires an additional Lambda or subscription filter, adding unnecessary complexity and cost; the goal is minimal overhead, not a multi-hop pipeline. Option B is wrong because modifying application code to use the AWS SDK for CloudWatch Logs tightly couples the application to AWS APIs, increases development effort, and violates the principle of keeping logging infrastructure separate from application logic. Option C is wrong because installing the CloudWatch agent inside a Fargate container is not supported—Fargate does not allow running sidecar agents that require host-level access; the awslogs driver handles this at the container runtime level without any agent.

893
MCQmedium

A company uses AWS CodePipeline with CodeBuild to test and deploy a web application. The pipeline has been failing at the deploy stage with an error: 'Access Denied'. CloudTrail shows the CodePipeline service role is making the call. What is the MOST likely cause?

A.The CodeBuild project does not have internet access.
B.The CodePipeline service role lacks permissions for the deploy action.
C.The deploy provider (e.g., ECS, S3) is not in the same AWS region.
D.The source code repository does not have the correct branch.
AnswerB

An 'Access Denied' error during the deploy stage is a classic indication that the AWS CodePipeline service role lacks the necessary IAM permissions to perform the deployment actions on the target AWS resource. For instance, if deploying to an S3 bucket, the role needs `s3:PutObject` and `s3:GetObject` permissions for the artifact. Without these explicit `Allow` statements in its policy, the service principal is unauthorized to interact with the target service, resulting in the reported access denial.

Why this answer

The error 'Access Denied' in the deploy stage, with CloudTrail showing the CodePipeline service role making the call, indicates that the IAM role assumed by CodePipeline does not have the necessary permissions to perform the deploy action against the target provider (e.g., ECS, S3, Elastic Beanstalk). CodePipeline uses its service role to invoke the deploy action, and if that role lacks the required `codedeploy:*`, `s3:PutObject`, or `ecs:UpdateService` permissions, the API call will be denied.

Exam trap

The trap here is that candidates confuse the CodeBuild service role with the CodePipeline service role, assuming the build role is responsible for deployment, when in fact CodePipeline uses its own role for the deploy action.

How to eliminate wrong answers

Option A is wrong because CodeBuild not having internet access would cause build failures (e.g., cannot download dependencies), not a deploy-stage 'Access Denied' error, and CloudTrail shows the CodePipeline service role, not CodeBuild, is making the call. Option C is wrong because deploy providers can be in different regions (cross-region actions are supported with appropriate IAM and resource policies), and the error is 'Access Denied', not a region mismatch. Option D is wrong because an incorrect source branch would cause the pipeline to fetch the wrong code or fail at the source stage, not produce an 'Access Denied' error at the deploy stage.

894
MCQmedium

A developer is using AWS CodeBuild to build a Java application. The buildspec.yml file currently runs unit tests. The developer wants to generate a code coverage report and publish it to the CodeBuild console for analysis. Which CodeBuild feature should be used?

A.Test reports
B.Build artifacts
C.Amazon CloudWatch Logs
D.Amazon S3 access logs
AnswerA

AWS CodeBuild's "Test reports" feature is specifically designed to ingest and display structured test results and code coverage metrics directly within the CodeBuild console. By configuring the `reports` section in the `buildspec.yml` to point to test output files (e.g., JUnit XML, JaCoCo XML), CodeBuild processes these files to generate visual reports, including pass/fail rates, test duration, and code coverage percentages, providing immediate feedback on application quality.

Why this answer

AWS CodeBuild's test reports feature allows developers to create reports from test result files, including code coverage reports, and publish them to the CodeBuild console for analysis. This feature supports various report formats such as JaCoCo, Cobertura, and SimpleCov, enabling the developer to visualize coverage metrics directly in the console without external tools.

Exam trap

The trap here is that candidates confuse build artifacts (which store compiled binaries) with test reports (which store structured test and coverage data), or assume CloudWatch Logs can visualize coverage metrics when it only provides raw log text.

How to eliminate wrong answers

Option B is wrong because build artifacts are used to store output files (e.g., JARs, WARs) in Amazon S3 or CodeBuild, not for generating or publishing test or coverage reports. Option C is wrong because Amazon CloudWatch Logs captures build logs and output from CodeBuild runs, but it does not parse or display structured code coverage reports. Option D is wrong because Amazon S3 access logs track requests made to an S3 bucket, not CodeBuild test results or coverage data.

895
MCQmedium

A developer runs the commands above. The key is disabled. An application that uses this key to encrypt S3 objects starts failing. What should the developer do to fix the issue?

A.Delete the key and recreate it
B.Create a new KMS key and update the application to use it
C.Enable the KMS key
D.Enable automatic key rotation
AnswerC

When an AWS KMS key is disabled, it transitions into a `Disabled` state, preventing any cryptographic operations such as encryption or decryption. Enabling the KMS key directly changes its state back to `Enabled`, immediately restoring its full functionality. This allows the application to resume using the key for all authorized cryptographic operations without requiring any changes to application code or data migration, making it the most direct and efficient solution.

Why this answer

Enable the KMS key. The key is disabled, so enabling it will restore functionality. Option A (delete the key and recreate it) would create a new key, but the application would need to be updated to use the new key, which is unnecessary since the original key exists and can simply be re-enabled.

Option B (create a new KMS key and update the application to use it) is also a valid but more complex fix; however, the simplest and most direct solution is to re-enable the key. Option D (enable automatic key rotation) does not affect the disabled state; it only sets a rotation policy for future key updates.

896
MCQmedium

A developer is creating a new IAM policy to allow an application to read objects from a specific S3 bucket and write logs to a CloudWatch log group. Which policy statement is correct?

A.{"Effect":"Allow","Action":["ec2:DescribeInstances"],"Resource":"*"}
B.{"Effect":"Allow","Action":["s3:ListBucket"],"Resource":"arn:aws:s3:::my-bucket/*"}
C.{"Effect":"Allow","Action":["s3:GetObject","logs:CreateLogStream","logs:PutLogEvents"],"Resource":["arn:aws:s3:::my-bucket/*","arn:aws:logs:us-east-1:123456789012:log-group:MyLogGroup:*"]}
D.{"Effect":"Allow","Action":["s3:PutObject"],"Resource":"arn:aws:s3:::my-bucket/*"}
AnswerC

This statement correctly pairs s3:GetObject, which retrieves object content, with logs:CreateLogStream and logs:PutLogEvents, the two actions required to create a log stream and write log events, and scopes each action to its precise resource ARN, satisfying both requirements with least privilege.

Why this answer

It grants the necessary permissions: s3:GetObject to read objects from the bucket, and logs:CreateLogStream and logs:PutLogEvents to write logs to the CloudWatch log group. The resources are correctly specified: the bucket ARN with a wildcard for objects, and the log group ARN with a wildcard for log streams. Option A is incorrect because it uses ec2:DescribeInstances, which is unrelated to S3 or CloudWatch.

Option B is incorrect because it only allows s3:ListBucket on the bucket (listing objects) but not reading them (s3:GetObject), and it does not include CloudWatch actions. Option D is incorrect because it only allows s3:PutObject (writing objects) rather than reading, and lacks CloudWatch permissions.

897
MCQmedium

A company's security policy requires that all data in transit between an Application Load Balancer (ALB) and its backend EC2 instances be encrypted. The ALB currently uses HTTPS listeners. What configuration ensures encryption between the ALB and targets?

A.Add a security group rule allowing port 443 from the ALB to the instances.
B.Configure the target group to use HTTPS protocol.
C.Use a Network Load Balancer with a TLS listener.
D.Set the listener protocol to HTTPS with a certificate.
AnswerB

Configuring the target group to use HTTPS protocol explicitly instructs the Application Load Balancer (ALB) to establish a TLS-encrypted connection when forwarding requests to its registered backend instances. This setting ensures that all data transmitted from the ALB to the instances is encrypted in transit, directly fulfilling the security policy requirement. It offloads the initial client-side TLS termination to the ALB while maintaining a secure communication channel to the backend.

Why this answer

To encrypt traffic between the ALB and backend EC2 instances, the target group protocol must be set to HTTPS, which uses TLS encryption. Option A is incorrect: security group rules control access but do not encrypt traffic. Option C is incorrect: while a Network Load Balancer with a TLS listener encrypts client-to-ALB traffic, it does not affect ALB-to-target encryption, and the question specifically asks about an Application Load Balancer.

Option D is incorrect: setting the listener protocol to HTTPS with a certificate encrypts client-to-ALB traffic, not the traffic between ALB and targets.

898
MCQhard

A company uses AWS KMS customer master keys (CMKs) to encrypt sensitive data in Amazon S3. A compliance requirement mandates that the backing keys for the CMKs be automatically rotated every year. The developer must implement this with minimal operational overhead. Which solution meets the requirement?

A.Enable automatic key rotation for the CMK in AWS KMS.
B.Create a new CMK every year and update the S3 bucket policy to use the new key.
C.Use an AWS managed key (aws/s3) which automatically rotates annually.
D.Use SSE-S3 encryption with automatically rotated keys instead of KMS.
AnswerA

Enabling automatic key rotation for a CMK in AWS KMS ensures that the underlying cryptographic material (backing key) used for encryption is replaced annually. This process is transparent to applications, as the CMK's Amazon Resource Name (ARN) and Key ID remain unchanged, allowing existing encrypted data to still be decrypted by the original backing key. This fully automates the compliance requirement for annual key rotation without operational disruption.

Why this answer

AWS KMS supports automatic key rotation for customer managed CMKs. When enabled, KMS automatically rotates the backing key annually (approximately every 365 days) with no additional operational overhead. This satisfies the compliance requirement for yearly rotation without manual intervention.

Exam trap

The trap here is that candidates may confuse AWS managed keys (which rotate automatically but not on a customer-defined schedule) with customer managed CMKs, or assume that manual key rotation is required when automatic rotation is available.

How to eliminate wrong answers

Option B is wrong because manually creating a new CMK each year and updating the S3 bucket policy introduces significant operational overhead and violates the 'minimal operational overhead' requirement. Option C is wrong because AWS managed keys (aws/s3) are automatically rotated, but the rotation schedule is managed by AWS and is not guaranteed to be exactly every year; additionally, the question specifies using customer master keys (CMKs), not AWS managed keys. Option D is wrong because SSE-S3 uses server-side encryption with Amazon S3-managed keys, not AWS KMS CMKs, and the rotation schedule is managed by S3, not the customer, so it does not meet the requirement of using KMS CMKs with annual rotation.

899
MCQhard

A developer is deploying a containerized application on Amazon ECS with Fargate. The application needs to read configuration data from AWS Systems Manager Parameter Store. The developer wants to ensure that the ECS task definition can access the parameter without hardcoding the value. What should the developer do?

A.Store the configuration in Amazon ECR as a label and reference it in the task definition.
B.Use the 'configs' section in the task definition to load from Parameter Store.
C.Add a 'parameters' section in the task definition to load from Parameter Store.
D.Use the 'secrets' field in the task definition to reference the parameter ARN.
AnswerD

The `secrets` field within the `containerDefinitions` section of an AWS ECS task definition is the correct and intended mechanism for injecting sensitive data or configuration, including values stored in AWS Systems Manager Parameter Store, into a container. By specifying the ARN of a Parameter Store parameter, ECS can securely retrieve the value and expose it as an environment variable or file within the container at runtime. This ensures sensitive data is not hardcoded in the task definition or container image.

Why this answer

The 'secrets' field in an ECS task definition allows you to reference AWS Systems Manager Parameter Store (or AWS Secrets Manager) parameters by their ARN. This enables the container to retrieve the configuration value at runtime without hardcoding it in the task definition or container image, maintaining security and flexibility.

Exam trap

The trap here is that candidates confuse the 'secrets' field (which supports both Parameter Store and Secrets Manager) with the non-existent 'parameters' section or the 'configs' section (which is for file-based configuration), leading them to select a plausible-sounding but incorrect option.

How to eliminate wrong answers

Option A is wrong because Amazon ECR stores container images, not configuration data; labels in ECR are metadata for images and cannot be used to inject runtime configuration into a running container. Option B is wrong because the 'configs' section in an ECS task definition is used for referencing configuration files from Amazon S3 or other sources, not for directly loading Parameter Store values. Option C is wrong because there is no 'parameters' section in the ECS task definition schema; the correct mechanism for injecting Parameter Store values is the 'secrets' field.

900
MCQmedium

A company is building a serverless application using AWS Lambda. The application processes messages from an Amazon SQS queue. The Lambda function is idempotent and handles duplicate messages correctly. The company needs to ensure that messages are processed in the order they were sent. Which solution should the company use?

A.Use Amazon SNS to fan out messages to Lambda.
B.Use Amazon Kinesis Data Streams as the event source for Lambda.
C.Configure the Lambda function to poll an SQS standard queue with a batch size of 10.
D.Configure the Lambda function to poll an SQS FIFO queue with a batch size of 1.
AnswerD

Amazon SQS FIFO (First-In, First-Out) queues are specifically engineered to guarantee strict message ordering and exactly-once processing. By configuring the Lambda function to poll a FIFO queue with a batch size of 1, each message is retrieved and processed individually and sequentially. This combination ensures that the processing order by the Lambda function precisely matches the order in which messages were originally sent to the queue, reliably meeting both ordering and exactly-once requirements.

Why this answer

Amazon SQS FIFO queues guarantee first-in, first-out delivery and exactly-once processing, which ensures messages are processed in the order they were sent. By configuring the Lambda function to poll the FIFO queue with a batch size of 1, each message is processed individually, preserving strict ordering without concurrency issues. The Lambda function's idempotency further ensures that any duplicate messages are handled safely, but the FIFO queue's inherent ordering is the key mechanism for maintaining sequence.

Exam trap

The trap here is that candidates often assume a standard SQS queue with a small batch size can maintain order, but standard queues only provide best-effort ordering and can still reorder messages due to retries or distributed processing.

How to eliminate wrong answers

Option A is wrong because Amazon SNS fans out messages to multiple subscribers asynchronously and does not guarantee any ordering; messages can arrive at Lambda in a different order than they were published. Option B is wrong because Amazon Kinesis Data Streams provides ordering within a shard but does not guarantee global ordering across shards, and it is designed for real-time streaming analytics, not for simple message queue processing with strict FIFO semantics. Option C is wrong because an SQS standard queue does not preserve message order; it uses best-effort ordering and can deliver messages out of sequence, even with a batch size of 10, making it unsuitable for ordered processing.

Page 11

Page 12 of 16

Page 13