Courseiva

AWS Certified Developer Associate DVA-C02 (DVA-C02) — Questions 976–1050

1135 questions total · 16pages · All types, answers revealed

Page 13

Page 14 of 16

Page 15
976
Multi-Selecteasy

A developer is using Amazon DynamoDB for a gaming leaderboard. The table has a sort key of 'score' (Number). The developer wants to retrieve the top 10 players. Which TWO operations can achieve this? (Choose TWO.)

Select 2 answers
A.TransactGetItems
B.Scan and sort results client-side, then take first 10
C.BatchGetItem
D.GetItem
E.Query with ScanIndexForward set to false and Limit set to 10
AnswersB, E

A Scan operation reads every single item in the entire DynamoDB table or a secondary index, which can then be sorted client-side by the score attribute in descending order, with the first 10 items taken. While this method technically yields the correct top 10 results, it is highly inefficient and expensive for large tables. It consumes significant read capacity units (RCUs) and network bandwidth by transferring all data, making it impractical for a production leaderboard.

Why this answer

Scanning all items and sorting them client-side by score descending gives the global top 10, regardless of partition keys. Option E is correct if the table is designed with a single partition key (e.g., a constant value like 'Leaderboard'), because a Query with ScanIndexForward=false and Limit=10 then retrieves the top 10 items from that partition efficiently. Options A, C, and D are incorrect because they cannot return the top 10 items sorted globally.

Exam trap

The pitfall is that candidates assume Query with ScanIndexForward=false and Limit=10 works globally across all partitions, but it only applies within a single partition key. However, if the table uses a constant partition key (common for leaderboards), it becomes a valid solution. Always consider the table design when evaluating Query vs.

Scan.

977
MCQhard

A company runs a critical web application on Amazon EC2 instances behind an Application Load Balancer. The application needs to authenticate users via an external OpenID Connect (OIDC) identity provider. The company wants to offload authentication to the load balancer and use IAM roles to access AWS resources. Which solution should the developer implement?

A.Configure the ALB target group to authenticate using the OIDC identity provider.
B.Use AWS Lambda@Edge to authenticate users at the edge.
C.Configure the ALB to use the OIDC identity provider for user authentication. Use the identity token to assume an IAM role via web identity federation.
D.Use Amazon Cognito user pools as the OIDC provider and integrate with ALB.
AnswerC

Application Load Balancers natively support authentication with OpenID Connect (OIDC) identity providers by configuring an `authenticate-oidc` action on a listener rule. After successful authentication, the ALB forwards the ID token to the backend application. The application can then use this OIDC identity token to securely assume an AWS IAM role via web identity federation, granting temporary, fine-grained permissions to access AWS resources without embedding long-lived credentials.

Why this answer

The Application Load Balancer (ALB) can directly authenticate users against an external OpenID Connect (OIDC) identity provider using its native OIDC authentication action. After successful authentication, the ALB passes the ID token to the backend application, which can then use the AWS Security Token Service (STS) AssumeRoleWithWebIdentity API to exchange the token for temporary AWS credentials, allowing the application to access AWS resources via an IAM role without managing long-term keys.

Exam trap

The trap here is that candidates confuse target group configuration with listener rule authentication actions, or assume that Cognito is required for any OIDC integration with ALB, when in fact ALB natively supports external OIDC providers directly.

How to eliminate wrong answers

Option A is wrong because ALB target groups do not handle authentication; authentication is configured at the listener rule level, not on the target group. Option B is wrong because Lambda@Edge is designed for content delivery and request/response manipulation at CloudFront edge locations, not for offloading OIDC authentication directly to an ALB or for assuming IAM roles via web identity federation. Option D is wrong because while Amazon Cognito can act as an OIDC provider and integrate with ALB, the question specifies an external OIDC provider, and using Cognito would introduce an unnecessary intermediary; the ALB supports direct integration with any OIDC-compliant identity provider without requiring Cognito.

978
MCQhard

A company wants to encrypt data at rest in Amazon S3 using server-side encryption with KMS (SSE-KMS). They want to ensure that only certain IAM roles can decrypt objects. What must be configured?

A.IAM role policy to allow kms:Decrypt
B.S3 bucket policy to allow decrypt
C.KMS key policy to allow the IAM roles to decrypt
D.KMS key policy to allow s3.amazonaws.com to decrypt
AnswerC

For an IAM role to successfully decrypt data encrypted with an AWS KMS Customer Managed Key (CMK), the KMS key policy associated with that specific CMK must explicitly allow the IAM role to perform the `kms:Decrypt` action. This is a critical requirement because the key policy is the definitive access control mechanism for the KMS key, dictating which principals are authorized to use it. Without this explicit permission in the key policy, decryption attempts by the IAM role will fail, even if the role's IAM policy permits `kms:Decrypt`.

Why this answer

SSE-KMS uses a customer master key (CMK) to encrypt and decrypt S3 objects. The KMS key policy is the primary access control mechanism for a CMK; it must explicitly grant the IAM roles the kms:Decrypt permission. Without this policy statement, even if the IAM roles have a policy allowing kms:Decrypt, they will be denied access because KMS key policies can override IAM permissions when the key policy does not grant access to the account's IAM principals.

Exam trap

The trap here is that candidates assume an IAM role policy granting kms:Decrypt is sufficient, forgetting that KMS key policies act as an independent access control layer that can explicitly deny or allow access, and without the key policy granting the role, the IAM policy is ineffective.

How to eliminate wrong answers

Option A is wrong because an IAM role policy allowing kms:Decrypt is necessary but not sufficient; the KMS key policy must also grant the role permission to use the key, and if the key policy does not include the role, the IAM policy alone will not allow decryption. Option B is wrong because S3 bucket policies control access to S3 actions (like s3:GetObject) but cannot grant KMS decryption permissions; KMS actions are governed solely by KMS key policies and IAM policies. Option D is wrong because allowing the service principal s3.amazonaws.com to decrypt would grant decryption to any S3 request that uses the key, bypassing the IAM role restriction and violating the requirement that only certain IAM roles can decrypt.

979
MCQhard

A developer is troubleshooting an AWS Lambda function that processes large CSV files (up to 1 GB) uploaded to an Amazon S3 bucket. The function uses Python and the pandas library to perform data transformations. Recently, the function started timing out on large files. CloudWatch Logs show that the function's execution time is close to the 15-minute Lambda timeout, and memory utilization peaks at around 80% of the configured 3,008 MB. The function has not been modified in months. Which action will most likely resolve the timeout issue without requiring code changes?

A.Increase the memory allocation of the Lambda function to the maximum available (10,240 MB)
B.Increase the function timeout to the maximum allowed (900 seconds is already the max)
C.Use S3 Select to filter columns and rows before invoking the Lambda function
D.Increase the batch size of the S3 event notification to invoke the function with multiple files
AnswerA

Increasing the Lambda function's memory allocation directly scales the available CPU power, network bandwidth, and ephemeral storage. For CPU-intensive tasks like `pandas` processing of large CSV files, more CPU can significantly accelerate computations, reducing the overall execution time. This approach is highly effective in preventing timeouts by providing the necessary resources to complete the workload within the allowed duration, without requiring any changes to the existing function code.

Why this answer

Increasing the memory allocation to the maximum (10,240 MB) proportionally increases the CPU and network throughput allocated to the Lambda function, which directly reduces execution time for CPU-bound pandas operations. Since memory utilization is only at 80% of the current 3,008 MB, the bottleneck is likely CPU, not memory, and Lambda's CPU scales linearly with memory configuration. This action resolves the timeout without any code changes.

Exam trap

The trap here is that candidates assume the function needs more memory because memory utilization is at 80%, but the real bottleneck is CPU, which is tied to memory allocation in Lambda's pricing and performance model.

How to eliminate wrong answers

Option B is wrong because the Lambda function timeout is already at 900 seconds (15 minutes), which is the maximum allowed; increasing it further is impossible. Option C is wrong because S3 Select filters data before the Lambda function is invoked, which would require modifying the S3 event notification or adding a separate trigger, thus requiring code changes to the Lambda function or infrastructure. Option D is wrong because increasing the batch size of the S3 event notification would invoke the function with multiple files at once, which would increase the processing load and worsen the timeout issue, not resolve it.

980
Multi-Selectmedium

A developer is troubleshooting a slow-performing Amazon RDS for MySQL database. Which TWO actions should the developer take to improve query performance?

Select 2 answers
A.Delete unused indexes to reduce write overhead.
B.Enable Multi-AZ deployment for better read performance.
C.Increase the instance size to provide more CPU and memory.
D.Enable the slow query log to identify poorly performing queries.
E.Delete the binary log files to free up storage.
AnswersC, D

Scaling up to a larger instance class directly addresses the symptoms by giving the database engine more vCPUs and more memory. With additional memory, the InnoDB buffer pool can cache more data and index pages, reducing disk I/O, while extra CPU accelerates query execution, sorting, and joins. This is an appropriate immediate mitigation when CloudWatch metrics show high CPU utilization or high swap usage, though it doesn't fix inefficient queries.

Why this answer

Option C is correct because a slow-performing RDS for MySQL instance is often constrained by CPU, memory, or IOPS, and vertically scaling to a larger instance class provides more vCPU, RAM, and baseline EBS throughput, which directly improves query execution and buffer pool caching. Option D is correct because enabling the MySQL slow query log (via the slow_query_log and long_query_time parameters in a custom parameter group) captures queries exceeding the threshold, letting the developer identify and then optimize the specific poorly performing SQL statements. Option A is not appropriate because deleting indexes generally hurts read performance and only marginally reduces write overhead, and unused indexes are not the typical cause of slow queries.

Option B is wrong because Multi-AZ is a high-availability/failover feature that maintains a synchronous standby, not a read-scaling mechanism, so it does not improve read performance. Option E is wrong because purging binary logs only frees storage and does not address query performance, and it can break point-in-time recovery and replication.

Exam trap

The trap here is conflating Multi-AZ with read scaling — candidates pick Multi-AZ thinking the standby serves reads, when only Read Replicas do that.

981
MCQeasy

A developer is creating a deployment pipeline using AWS CodePipeline. The pipeline includes a source stage from Amazon S3, a build stage using AWS CodeBuild, and a deploy stage using AWS CloudFormation. The developer wants to ensure that the pipeline can automatically create the CloudFormation stack if it does not exist. Which action mode should the developer use in the CloudFormation deploy action?

A.UPDATE_ONLY
B.CREATE_UPDATE
C.REPLACE_ON_FAILURE
D.CREATE_ONLY
AnswerB

The CREATE_UPDATE action in AWS CodePipeline's CloudFormation deploy stage is designed for idempotent infrastructure deployments. It intelligently determines whether a CloudFormation stack with the specified name already exists in the target account and region. If no stack is found, it initiates a new stack creation; otherwise, it performs an update operation on the existing stack. This dual functionality is crucial for continuous deployment pipelines, ensuring that the infrastructure is always brought to the desired state, whether it's the first deployment or a subsequent modification.

Why this answer

The CREATE_UPDATE action mode in AWS CodePipeline's CloudFormation deploy action creates the stack if it does not exist and updates it if it does. This is the default and most flexible mode, ensuring the pipeline can handle both initial deployment and subsequent updates without manual intervention.

Exam trap

DVA-C02 often tests the confusion between CREATE_UPDATE and UPDATE_ONLY, so candidates must remember that CREATE_UPDATE is the only mode that handles both creation and updates seamlessly.

How to eliminate wrong answers

Option A is wrong because UPDATE_ONLY will fail if the stack does not exist, as it only updates an existing stack. Option C is wrong because REPLACE_ON_FAILURE is used to replace a stack if the update fails, but it still requires an existing stack and does not create one from scratch. Option D is wrong because CREATE_ONLY will fail if the stack already exists, preventing updates and breaking the pipeline on subsequent runs.

982
Multi-Selecthard

A company is designing a secure CI/CD pipeline using AWS CodePipeline and AWS CodeBuild. The pipeline must securely store and access sensitive parameters (e.g., API keys) used during the build. Which TWO services can be used to securely store and retrieve these parameters?

Select 2 answers
A.AWS Systems Manager Parameter Store (SecureString)
B.AWS Secrets Manager
C.Amazon S3 with server-side encryption
D.AWS Key Management Service (KMS) alone
E.AWS CloudFormation parameter store
AnswersA, B

Systems Manager Parameter Store lets you store values as SecureString parameters encrypted under a KMS key, and CodeBuild buildspec files natively support pulling these into environment variables at build time via the parameter-store mapping, making it a valid secure retrieval mechanism.

Why this answer

AWS Systems Manager Parameter Store (SecureString) and AWS Secrets Manager are both designed to securely store secrets and can be accessed by CodeBuild via IAM roles.

983
MCQmedium

A developer is building a RESTful API using Amazon API Gateway and AWS Lambda. The API needs to support custom domain names with SSL/TLS certificates. The developer has created the custom domain name in API Gateway and uploaded the certificate to AWS Certificate Manager (ACM) in the same region. However, when accessing the custom domain, users get an SSL error. What is the most likely cause?

A.The certificate was not issued by a trusted certificate authority.
B.The custom domain name's DNS record does not point to API Gateway's regional domain name.
C.The API Gateway API is not deployed to a stage that is mapped to the custom domain name.
D.The certificate is in the wrong region relative to the API Gateway regional endpoint.
AnswerB

For a custom domain to function with API Gateway, its DNS record (typically a CNAME or an ALIAS record in Route 53) must correctly resolve to the API Gateway's regional endpoint domain name. If the DNS record is misconfigured or missing, client requests will not reach the API Gateway endpoint associated with the custom domain. Consequently, the server presenting the certificate (which would be the API Gateway) cannot be found at the requested custom domain, leading to an SSL handshake failure as the client cannot establish a secure connection with the intended server.

Why this answer

The most likely cause is that the custom domain name's DNS record does not point to API Gateway's regional domain name. When using a custom domain name with API Gateway, you must create a DNS record (typically a CNAME or A record using Route 53 alias) that maps your custom domain to the API Gateway-generated regional domain name (e.g., d-xxxxx.execute-api.region.amazonaws.com). Without this correct DNS mapping, the SSL/TLS handshake fails because the certificate presented by API Gateway does not match the domain name the client is connecting to, resulting in an SSL error.

Exam trap

The trap here is that candidates often confuse SSL errors with API configuration issues like missing stage mappings or incorrect certificate authorities, but SSL errors occur at the transport layer due to DNS misconfiguration or certificate domain mismatch, not at the application layer.

How to eliminate wrong answers

Option A is wrong because AWS Certificate Manager (ACM) only issues certificates that are trusted by major browsers and operating systems; if ACM issued the certificate, it is automatically from a trusted CA, so this is not the cause. Option C is wrong because while the API must be deployed to a stage and the stage must be mapped to the custom domain name for the API to respond, an SSL error occurs at the TLS handshake level before any API routing happens; a missing stage mapping would cause a 404 or 403 error, not an SSL error. Option D is wrong because the developer created the custom domain name in API Gateway and uploaded the certificate to ACM in the same region, so the region mismatch is not the issue; the certificate must be in the same region as the API Gateway regional endpoint, which it is.

984
MCQeasy

A developer needs to store application configuration that can be accessed by multiple microservices running on Amazon ECS. The configuration must be encrypted at rest and automatically rotate secrets. Which AWS service should be used?

A.AWS Systems Manager Parameter Store
B.AWS CloudFormation
C.Amazon S3
D.AWS Secrets Manager
AnswerD

AWS Secrets Manager is specifically engineered for managing sensitive credentials such as database passwords, API keys, and other secrets that require robust security and lifecycle management. Its core features include automatic rotation, fine-grained access control, and auditing, which are critical for secrets but often overkill for general application configuration. While technically capable of storing configuration, its higher cost and specialized feature set make it an inefficient choice for non-secret application parameters.

Why this answer

AWS Secrets Manager is the correct choice because it is specifically designed to protect secrets (such as database credentials, API keys, and OAuth tokens) and features built-in, automatic rotation of secrets using AWS Lambda. While AWS Systems Manager Parameter Store can store encrypted configuration data (using SecureString), it does not offer native automatic rotation capabilities; implementing rotation in Parameter Store requires custom integration and code.

Exam trap

Candidates often confuse AWS Systems Manager Parameter Store and AWS Secrets Manager. While both can store encrypted data, only AWS Secrets Manager provides native, automatic rotation of secrets. If the exam question mentions 'automatically rotate secrets' as a requirement, AWS Secrets Manager is almost always the correct choice.

How to eliminate wrong answers

Option B (AWS CloudFormation) is wrong because it is an infrastructure-as-code service for provisioning resources, not a runtime configuration store; it cannot dynamically serve configuration to running microservices or rotate secrets automatically. Option C (Amazon S3) is wrong because while it can store encrypted objects, it lacks native secret rotation capabilities and is not designed for low-latency, parameter-style access from ECS tasks without additional client logic. Option D (AWS Secrets Manager) is wrong because although it supports automatic secret rotation and encryption, it is specifically designed for managing secrets like database credentials, not general application configuration; the question asks for storing 'application configuration' that must be rotated, and Parameter Store is the more appropriate service for configuration data with optional rotation via integration.

985
Multi-Selecthard

A developer is designing a CI/CD pipeline using AWS CodePipeline. The pipeline deploys a Lambda function. Which THREE practices should be followed to ensure security?

Select 3 answers
A.Use IAM roles for pipeline actions instead of access keys.
B.Scan code dependencies for known vulnerabilities.
C.Use CloudFront to distribute pipeline artifacts.
D.Store database credentials in AWS Secrets Manager and retrieve them during deployment.
E.Encrypt artifacts in transit using TLS.
AnswersA, B, D

IAM roles provide temporary, short-lived credentials that are automatically rotated by AWS, significantly reducing the risk associated with long-lived access keys. When an AWS service like CodeBuild or CodeDeploy assumes an IAM role, it receives a temporary security token, eliminating the need to embed static credentials directly into pipeline configurations or source code. This aligns with the principle of least privilege and enhances security posture by preventing credential leakage and simplifying credential management.

Why this answer

IAM roles provide temporary credentials for AWS services, eliminating the need to manage long-term access keys. CodePipeline can assume an IAM role to perform actions like deploying a Lambda function, which reduces the risk of credential leakage. This follows the principle of least privilege and is a security best practice for automated pipelines.

Exam trap

The trap here is that candidates may confuse CloudFront's artifact distribution capability with S3's role in CodePipeline, or assume TLS encryption is an optional security practice rather than a default AWS behavior.

986
MCQhard

A DynamoDB table uses partition key customerId. One enterprise customer generates most traffic and is throttled while the table has unused capacity elsewhere. What design change best addresses the hot partition?

A.Enable point-in-time recovery
B.Reduce item size by removing attributes
C.Use strongly consistent reads only
D.Add write sharding or redesign the partition key to distribute that customer's workload
AnswerD

A hot partition occurs when a single partition key value receives disproportionately high read or write traffic, leading to throttling. To mitigate this, one can implement write sharding by appending a random or calculated suffix to the `customerid` (e.g., `customerid-001`, `customerid-002`), effectively distributing that single customer's operations across multiple logical partitions. Alternatively, redesigning the partition key entirely to include a more granular attribute alongside `customerid` can achieve similar workload distribution.

Why this answer

The hot partition is caused by a single customerId receiving a disproportionate amount of traffic, exceeding the 3000 RCU or 1000 WCU per partition limit. By adding write sharding (e.g., appending a random suffix to the partition key) or redesigning the partition key to include a more granular attribute, you distribute that customer's writes across multiple partitions, eliminating the bottleneck and utilizing the table's unused capacity.

Exam trap

The trap here is that candidates mistakenly believe reducing item size or changing read consistency can resolve a hot partition, when only redistributing the partition key's workload addresses the underlying throughput imbalance.

How to eliminate wrong answers

Option A is wrong because point-in-time recovery (PITR) enables continuous backups and restores to any point within the last 35 days; it does not affect request distribution or throttling. Option B is wrong because reducing item size can lower consumed capacity per operation but does not change how requests are distributed across partitions; the hot partition remains throttled if the same customerId still receives high traffic. Option C is wrong because strongly consistent reads consume twice the RCU of eventually consistent reads and do not alter partition key distribution; they would actually increase throttling risk on the hot partition.

987
MCQeasy

A developer wants to trigger an AWS Lambda function every time a new object is created in an Amazon S3 bucket. Which S3 event notification configuration should be used?

A.s3:ObjectCreated:*
B.s3:ObjectRestore:*
C.s3:ReducedRedundancyLostObject:*
D.s3:ObjectRemoved:*
AnswerA

This event notification type, `s3:ObjectCreated:*`, is a wildcard that encompasses all actions resulting in a new object being stored in an S3 bucket. It includes specific events like `s3:ObjectCreated:Put`, `s3:ObjectCreated:Post`, `s3:ObjectCreated:Copy`, and `s3:ObjectCreated:CompleteMultipartUpload`. This makes it the most comprehensive and appropriate choice for triggering a Lambda function whenever any new file is successfully added to S3, regardless of the specific upload method used.

Why this answer

The `s3:ObjectCreated:*` event type captures all object creation events in an S3 bucket, including PUT, POST, COPY, and multipart upload completions. This is the appropriate event notification to trigger an AWS Lambda function when a new object is created.

Exam trap

The trap here is that candidates might confuse `s3:ObjectCreated:*` with `s3:ObjectRemoved:*` or `s3:ObjectRestore:*`, thinking any object state change triggers the function, but only creation events are relevant for the 'new object' requirement.

How to eliminate wrong answers

Option B is wrong because `s3:ObjectRestore:*` is used for S3 Glacier or S3 Deep Archive restore lifecycle events, not for new object creation. Option C is wrong because `s3:ReducedRedundancyLostObject:*` is a deprecated event that only fires when an object stored with Reduced Redundancy Storage (RRS) is lost, which is unrelated to new object creation. Option D is wrong because `s3:ObjectRemoved:*` is triggered when objects are deleted (e.g., via DELETE or lifecycle expiration), not when they are created.

988
MCQmedium

A developer is using AWS Elastic Beanstalk to deploy a web application. The application requires custom configuration, such as setting environment variables for the EC2 instances. Which file should the developer include in the application source bundle under the appropriate directory to achieve this?

A.Include a buildspec.yml file in the root directory.
B.Include a .ebextensions/options.config file.
C.Include an appspec.yml file.
D.Include a cron.yaml file.
AnswerB

Placing a YAML or JSON file with a .config extension inside the .ebextensions directory at the root of the source bundle lets Elastic Beanstalk apply option_settings such as aws:elasticbeanstalk:application:environment during deployment, which is exactly how environment variables and other instance-level customizations like packages, commands, and container settings get injected.

Why this answer

AWS Elastic Beanstalk uses `.ebextensions` directory with `.config` files (e.g., `options.config`) to define custom configuration, including environment variables for EC2 instances. These YAML or JSON files are processed during environment creation and updates, allowing you to set `option_settings` that override or augment the default platform configuration.

Exam trap

The trap here is that candidates confuse Elastic Beanstalk configuration files with other AWS service configuration files (CodeBuild's `buildspec.yml` or CodeDeploy's `appspec.yml`) or assume `cron.yaml` can handle general environment settings, leading them to pick a wrong option based on familiarity with other services.

How to eliminate wrong answers

Option A is wrong because `buildspec.yml` is used by AWS CodeBuild to define build commands and output artifacts, not by Elastic Beanstalk for environment configuration. Option C is wrong because `appspec.yml` is used by AWS CodeDeploy to manage deployment lifecycle hooks and file permissions, not by Elastic Beanstalk for custom EC2 settings. Option D is wrong because `cron.yaml` is used by Elastic Beanstalk for periodic tasks (worker environment cron jobs), not for setting environment variables or general configuration.

989
Multi-Selectmedium

A developer is designing a messaging system where orders are placed into an SQS queue and processed by a Lambda function. The developer wants to ensure that failed messages are not lost and can be analyzed later. Which TWO steps should the developer take? (Choose 2.)

Select 2 answers
A.Configure a dead-letter queue (DLQ) for the SQS queue.
B.Enable Lambda function retries on failure.
C.Set the redrive policy to move messages to the DLQ after a specified number of receive attempts.
D.Increase the visibility timeout of the SQS queue.
E.Set up a CloudWatch alarm to monitor the queue depth.
AnswersA, C

A dead-letter queue (DLQ) is a standard SQS queue that receives messages from a source queue after they have failed to be processed successfully a specified number of times. Configuring a DLQ prevents messages from being lost due to repeated processing failures, allowing for later inspection, debugging, or manual reprocessing. This mechanism is crucial for ensuring message durability and reliability in a distributed messaging system, isolating problematic messages.

Why this answer

Configuring a dead-letter queue (DLQ) for the SQS queue ensures that messages that cannot be processed successfully after a specified number of attempts are moved to a separate queue. This prevents message loss and allows the developer to analyze the failed messages later, fulfilling the requirement to not lose failed messages and to enable analysis.

Exam trap

The trap here is that candidates often confuse Lambda retries (which only re-invoke the function) with the SQS DLQ mechanism, failing to realize that without a DLQ, messages that exhaust all retries are silently deleted from the queue and permanently lost.

990
MCQhard

A company is deploying a new microservice on AWS Lambda that processes high-resolution images and stores results in Amazon S3. The Lambda function currently uses 1024 MB of memory and has a timeout of 2 minutes. During peak load, many invocations are timing out. The function is CPU-bound during image processing. Which change is MOST likely to reduce timeouts without increasing costs unnecessarily?

A.Increase the function memory to 3008 MB.
B.Enable provisioned concurrency to reduce cold starts.
C.Increase the function memory to 2048 MB.
D.Increase the function timeout to 5 minutes.
AnswerC

AWS Lambda allocates CPU power proportionally to the configured memory setting, making it a direct lever for performance optimization. Increasing the function's memory to 2048 MB provides a full virtual CPU (vCPU) to the execution environment, significantly boosting computational resources. For CPU-bound microservices, this direct increase in processing power will reduce the overall execution time, making it a highly effective and often cost-efficient optimization.

Why this answer

Increasing memory from 1024 MB to 2048 MB proportionally increases CPU allocation in AWS Lambda (up to 1.7 GHz per vCPU at 1769 MB). Since the function is CPU-bound, this directly reduces processing time, mitigating timeouts without the cost spike of 3008 MB. The cost increase is linear with memory, so doubling memory doubles cost per invocation, but the reduced duration often offsets this, keeping total cost similar or lower.

Exam trap

The trap here is that candidates assume increasing timeout (Option D) is the simplest fix for timeouts, ignoring that CPU-bound functions need more CPU, not just more time, and that provisioned concurrency (Option B) is mistakenly thought to improve execution speed rather than just reducing cold start latency.

How to eliminate wrong answers

Option A is wrong because increasing memory to 3008 MB provides more CPU than needed for a CPU-bound task, leading to unnecessary cost without proportional performance gain (Lambda CPU scales linearly up to ~1769 MB, then plateaus). Option B is wrong because provisioned concurrency addresses cold starts, not timeout issues caused by insufficient CPU during peak load; it does not reduce execution time for CPU-bound processing. Option D is wrong because increasing the timeout to 5 minutes does not fix the root cause (CPU-bound processing is too slow); it only delays the timeout, allowing the function to run longer but still at the same slow speed, potentially increasing costs due to longer execution duration.

991
MCQeasy

A developer deploys a new version of an AWS Lambda function using the AWS CLI. The deployment fails with a 'ResourceConflictException' error. What is the most likely cause?

A.The function's handler name is incorrect in the deployment package.
B.The Lambda function's IAM role is missing necessary permissions.
C.The Lambda function's memory limit is set too low for the deployment package.
D.Another deployment is currently in progress for the same Lambda function.
AnswerD

AWS Lambda enforces serialization of deployment operations for a given function to maintain consistency and prevent race conditions. If a developer attempts to deploy a new version or update configuration while another update, such as a code upload or configuration change, is already in progress for the same function, the Lambda service will return a `ResourceConflictException`. This error specifically signals that the resource is temporarily unavailable for modification due to another ongoing operation.

Why this answer

`ResourceConflictException` in Lambda indicates a conflict with the function's current state — most commonly that another deployment or configuration update is already in progress on the same function. Lambda serializes updates per function, so concurrent deployments collide. The fix is to wait for the in-flight operation to complete and retry.

Exam trap

DVA-C02 often tests whether candidates misattribute `ResourceConflictException` to IAM or handler issues, when it specifically signals a concurrent state-changing operation on the same resource.

How to eliminate wrong answers

Option A is wrong because an incorrect handler name causes a different error (e.g., `InvalidParameterValueException` or a runtime 'handler not found' error), not `ResourceConflictException`. Option B is wrong because missing IAM permissions produce `AccessDeniedException` or `KMSAccessDeniedException`, not a conflict error. Option C is wrong because insufficient memory for the deployment package is not a Lambda error condition — package size limits are enforced separately (50 MB zipped direct upload, 250 MB unzipped), and memory is a runtime setting unrelated to deployment conflicts.

992
MCQeasy

A company runs an application on Amazon EC2 instances that need to read data from an Amazon DynamoDB table. The developer must grant access to DynamoDB without storing any long-term credentials on the instance. Which approach should the developer use?

A.Store the AWS access key and secret key in a configuration file.
B.Use an IAM role and attach it to the EC2 instance profile.
C.Use an IAM user and store credentials in AWS Secrets Manager.
D.Use the DynamoDB table's resource-based policy to allow the EC2 instance.
AnswerB

Attaching an IAM role to an EC2 instance profile is the recommended and most secure method for granting AWS service access to applications running on EC2 instances. This mechanism provides temporary, automatically rotated credentials to the instance via the EC2 instance metadata service, eliminating the need to store any long-term static credentials on the instance itself. This approach adheres to the principle of least privilege, significantly reducing the attack surface and improving overall security posture by ensuring credentials are short-lived and not directly exposed.

Why this answer

Attaching an IAM role to an EC2 instance profile allows the instance to obtain temporary security credentials from the AWS Security Token Service (STS) via the instance metadata service. This eliminates the need to store long-term credentials on the instance, adhering to the principle of least privilege and improving security posture.

Exam trap

The trap here is that candidates may think resource-based policies (Option D) can grant access to EC2 instances, but DynamoDB resource-based policies only support principals like AWS accounts, IAM users, or IAM roles—not EC2 instances directly—and the correct mechanism for EC2 is always an IAM role attached to the instance profile.

How to eliminate wrong answers

Option A is wrong because storing AWS access keys and secret keys in a configuration file on the EC2 instance introduces long-term static credentials, which violates the requirement to avoid storing long-term credentials and increases the risk of credential leakage. Option C is wrong because using an IAM user and storing credentials in AWS Secrets Manager still requires the EC2 instance to retrieve and use long-term credentials (the IAM user's access keys) at some point, and the instance would need to authenticate to Secrets Manager, typically with another set of credentials, creating a circular dependency; the recommended approach for EC2 is always an IAM role. Option D is wrong because DynamoDB does not support resource-based policies that grant access to EC2 instances directly; resource-based policies in DynamoDB are used for cross-account access or service-to-service authorization, not for granting permissions to compute resources like EC2 instances.

993
Multi-Selecteasy

A developer is using Amazon DynamoDB as a data store for a serverless application. The application requires strongly consistent reads and must be able to recover from failures. Which THREE measures should the developer implement? (Choose THREE.)

Select 2 answers
A.Use the ConsistentRead parameter set to true in GetItem and Query operations.
B.Use DynamoDB read replicas to offload read traffic.
C.Configure DynamoDB global tables for multi-region replication.
D.Enable DynamoDB Streams to capture changes.
E.Implement DAX (DynamoDB Accelerator) for caching.
AnswersA, C

Setting ConsistentRead to true forces DynamoDB to return the most up-to-date data by reading from the leader node, satisfying the strong consistency requirement for GetItem and Query. Without it, reads may return stale replicas, which the application cannot tolerate.

Why this answer

Option A is correct because setting ConsistentRead to true on GetItem, Query, and Scan forces a strongly consistent read that returns the most up-to-date data instead of a possibly stale eventually consistent result. Option C is correct because DynamoDB global tables provide multi-region, active-active replication, allowing the application to continue serving reads and writes from another Region if one Region fails, which directly supports failure recovery. Option D is incorrect because DynamoDB Streams is a change-data-capture feature that records item-level changes for event-driven processing, replication, or auditing; it does not itself provide failure recovery or strongly consistent reads.

Option B is incorrect because DynamoDB does not offer native read replicas as a standalone feature; read scaling is achieved through partitions, global tables, or DAX. Option E is incorrect because DAX is an in-memory write-through cache that serves eventually consistent reads by default and does not provide strongly consistent reads or cross-Region failure recovery.

Exam trap

The trap is confusing DAX (performance enhancement) with a recovery mechanism, or assuming DynamoDB has read replicas like RDS. Avoid selecting options that only improve performance or are not available for DynamoDB.

994
MCQmedium

A developer is troubleshooting access to an S3 bucket from an EC2 instance. The bucket policy allows s3:GetObject for the instance's IAM role, but the application is still getting access denied errors. What is the MOST likely cause?

A.The EC2 instance's security group does not allow outbound traffic to S3.
B.The S3 bucket is encrypted with SSE-KMS and the instance does not have kms:Decrypt permissions.
C.The S3 bucket has a block public access setting enabled.
D.The EC2 instance does not have an instance profile associated with the IAM role.
AnswerB

While missing `kms:Decrypt` permissions would indeed prevent an EC2 instance from accessing SSE-KMS encrypted S3 objects, this presumes the instance already has an IAM identity and general S3 access permissions. The scenario describes troubleshooting general access, implying a more fundamental issue. Without an instance profile, the EC2 instance cannot assume any IAM role, meaning it would lack *all* permissions, including any necessary KMS permissions, making the instance profile the more foundational problem.

Why this answer

When an S3 bucket is encrypted using SSE-KMS, any entity attempting to retrieve an object (s3:GetObject) must also have permission to decrypt the object using the KMS key (kms:Decrypt). If the IAM role has the correct S3 permissions but lacks the kms:Decrypt permission on the KMS key, AWS S3 will return an 'Access Denied' error.

Why other options are incorrect:

A: Security group restrictions on outbound traffic would cause the connection to time out, not return an 'Access Denied' error.

C: Block Public Access settings prevent anonymous/public access, but access via an authorized IAM role is not public access.

D: If the EC2 instance did not have an instance profile associated, the AWS SDK would fail locally with a credentials lookup error (e.g., 'Unable to locate credentials') rather than receiving an 'Access Denied' response from the S3 service.

Exam trap

AWS frequently tests the interaction between S3 permissions and KMS permissions. Remember that if an S3 bucket is encrypted with a customer managed KMS key (SSE-KMS), the caller needs both S3 permissions (s3:GetObject) and KMS permissions (kms:Decrypt) to successfully download the file. Lacking KMS permissions results in an 'Access Denied' error.

How to eliminate wrong answers

Option A is wrong because security groups operate at the network layer and do not affect outbound traffic to S3 by default; outbound traffic is allowed unless explicitly denied, and S3 access uses HTTPS over port 443 which is typically open. Option B is wrong because while SSE-KMS requires kms:Decrypt permissions, the question states the bucket policy allows s3:GetObject for the role, and the error could be due to missing KMS permissions, but the most likely cause given the scenario is the missing instance profile, not KMS. Option C is wrong because block public access settings only restrict public (unauthenticated) access, not access from an IAM role that has been explicitly granted permissions via a bucket policy.

995
Multi-Selecthard

Which THREE AWS services are commonly used together to build a serverless event-driven architecture that processes real-time streaming data? (Choose three.)

Select 3 answers
A.Amazon Kinesis Data Streams
B.AWS Lambda
C.Amazon DynamoDB
D.Amazon SQS
E.Amazon Redshift
AnswersA, B, C

Amazon Kinesis Data Streams is a highly scalable and durable real-time data streaming service. It can continuously capture gigabytes of data per second from hundreds of thousands of sources, such as website clickstreams, IoT device data, and financial transactions. This service acts as the entry point for real-time data pipelines, providing a persistent, ordered, and replayable stream of records for downstream processing.

Why this answer

Amazon Kinesis Data Streams (A) is correct because it ingests and buffers real-time streaming data at scale, serving as the event source for downstream serverless processing. AWS Lambda (B) is correct because it provides serverless compute that can be triggered by Kinesis stream records via event source mappings, enabling event-driven processing without managing servers. Amazon DynamoDB (C) is correct because it is a fully managed, serverless NoSQL database commonly used as the sink to store processed streaming results, and DynamoDB Streams can further propagate events.

Amazon SQS (D) is not selected because it is a message queue for decoupling components, not a real-time streaming data service, and it is not one of the three services typically combined for streaming ingestion and processing in this scenario. Amazon Redshift (E) is not selected because it is a data warehouse designed for analytical queries on batch-loaded data, not for real-time serverless stream processing.

Exam trap

The trap here is that candidates often confuse Amazon SQS with Kinesis Data Streams, but SQS is a pull-based queue for decoupled messaging, not a streaming data platform with ordered, replayable records.

996
MCQhard

A developer is using AWS CodeDeploy with a blue/green deployment on an Amazon ECS service running on Fargate. The developer wants to ensure that the new (green) task set is fully healthy and serving traffic before the old (blue) task set is terminated. The deployment should automatically roll back to the blue task set if the green task set fails health checks. Which configuration should the developer set in the CodeDeploy deployment group?

A.Deployment type: blue/green, with rollback configuration enabled to trigger automatic rollback and reroute traffic to the original task set
B.Deployment type: blue/green, Deployment configuration: CodeDeployDefault.ECSAllAtOnce
C.Deployment type: blue/green, Deployment configuration: CodeDeployDefault.ECSLinear10PercentEvery1Minutes
D.Deployment type: blue/green, with an Application Load Balancer
AnswerA

This configuration leverages AWS CodeDeploy's integrated rollback capabilities for blue/green deployments. By enabling rollback, CodeDeploy actively monitors predefined CloudWatch alarms or health checks during the traffic shifting phase. If any alarm is triggered, indicating a deployment failure or performance degradation, CodeDeploy automatically initiates a rollback, rerouting all traffic back to the original, stable task set to maintain application availability and minimize impact.

Why this answer

The developer needs to configure the CodeDeploy deployment group with a blue/green deployment type and enable automatic rollback. This ensures that if the green task set fails health checks, CodeDeploy automatically terminates the green deployment and reroutes traffic back to the original blue task set, meeting the requirement for a fully healthy green task set before termination.

Exam trap

The trap here is that candidates often confuse deployment configurations (like AllAtOnce or Linear) with rollback settings, assuming that a traffic shifting strategy alone ensures health checks and automatic rollback, but rollback must be explicitly configured in the deployment group.

How to eliminate wrong answers

Option B is wrong because CodeDeployDefault.ECSAllAtOnce is a deployment configuration that shifts all traffic to the green task set immediately, which does not ensure the green task set is fully healthy before the blue task set is terminated; it also lacks automatic rollback on health check failure. Option C is wrong because CodeDeployDefault.ECSLinear10PercentEvery1Minutes is a linear traffic shifting configuration that gradually moves traffic in 10% increments every minute, but it does not automatically roll back to the blue task set if the green task set fails health checks; it only controls the traffic shift rate. Option D is wrong because while an Application Load Balancer is required for blue/green deployments on ECS, it alone does not provide the automatic rollback behavior needed; the rollback configuration must be explicitly enabled in the deployment group.

997
MCQmedium

A developer is troubleshooting a CloudFormation stack that fails to create. The stack includes an Auto Scaling group with a launch template. The error message says 'Value (null) for parameter groupId is invalid.' What is the MOST likely cause?

A.The launch template references a SecurityGroupId parameter that is not provided or is misspelled.
B.The Auto Scaling group does not specify a VPC subnet.
C.The Auto Scaling group's user data script contains a syntax error.
D.The launch template specifies an invalid key pair name.
AnswerA

When a CloudFormation launch template attempts to create an EC2 instance, it requires valid security group IDs. If the template references a `SecurityGroupId` parameter that is either not declared in the CloudFormation template's `Parameters` section, or if the `Ref` function used to access it contains a typo, CloudFormation will fail to resolve a concrete value. This results in a null or empty value being passed to the EC2 API for `groupId`, leading to a validation error during stack creation.

Why this answer

The error 'Value (null) for parameter groupId is invalid' indicates that a SecurityGroupId parameter referenced in the launch template is either not provided or misspelled. CloudFormation resolves parameters at stack creation; if the parameter is missing or has a typo, it evaluates to null, causing the launch template to fail validation because a security group ID is required for the network interface.

Exam trap

The trap here is that candidates confuse a missing subnet or user data error with a parameter null value, but the specific 'groupId' error points directly to a security group parameter issue, not infrastructure or script problems.

How to eliminate wrong answers

Option B is wrong because a missing VPC subnet would cause a different error, such as 'VPCIdNotSpecified' or 'SubnetIDNotSpecified', not a null groupId parameter. Option C is wrong because a syntax error in user data would result in a script execution failure, not a parameter validation error during stack creation. Option D is wrong because an invalid key pair name would produce an error like 'InvalidKeyPair.NotFound', not a null parameter value for groupId.

998
MCQeasy

A developer needs to store application configuration data, such as database connection strings and API keys, for a microservices application running on Amazon ECS. The configuration must be encrypted at rest and easily auditable. Which AWS service should the developer use?

A.AWS Secrets Manager.
B.Amazon S3 with server-side encryption.
C.AWS Systems Manager Parameter Store.
D.Amazon DynamoDB with encryption at rest.
AnswerC

AWS Systems Manager Parameter Store is purpose-built for securely storing and managing application configuration data, including both plain-text and encrypted parameters. It offers hierarchical organization, automatic versioning of parameter changes, and seamless integration with AWS Key Management Service (KMS) for encryption. Its ability to retrieve parameters by name and integration with AWS CloudTrail for auditing all access and modifications makes it the ideal, cost-effective, and operationally simple choice for this use case.

Why this answer

AWS Systems Manager Parameter Store is the correct choice because it is designed to store application configuration data like database connection strings and API keys, integrates natively with Amazon ECS for secure parameter retrieval, and supports encryption at rest using AWS KMS. It also provides built-in auditing through AWS CloudTrail, which logs all API calls to the Parameter Store, meeting the auditability requirement.

Exam trap

The trap here is that candidates often confuse AWS Secrets Manager with Systems Manager Parameter Store, but Secrets Manager is specifically for secrets requiring automatic rotation, while Parameter Store is the appropriate choice for general configuration data that needs encryption and auditing without rotation.

How to eliminate wrong answers

Option A is wrong because AWS Secrets Manager is optimized for managing secrets with automatic rotation, which is overkill for general configuration data and incurs additional cost per secret; the question does not require rotation. Option B is wrong because Amazon S3 with server-side encryption can store configuration data but lacks native integration with ECS for secure, low-latency parameter retrieval and does not provide the same level of auditability via CloudTrail for individual parameter access without additional configuration. Option D is wrong because Amazon DynamoDB with encryption at rest is a NoSQL database designed for high-scale application data, not for storing simple configuration parameters, and it requires custom code to manage access control and auditing, adding unnecessary complexity.

999
MCQmedium

A developer is creating an IAM policy to allow a Lambda function to write logs to CloudWatch. Which policy should be attached to the Lambda execution role?

A.AWSLambdaBasicExecutionRole
B.AdministratorAccess
C.AmazonDynamoDBFullAccess
D.AmazonS3FullAccess
AnswerA

The AWSLambdaBasicExecutionRole is an AWS managed policy specifically designed to grant a Lambda function the essential permissions required for its operation. This includes the ability to create log groups and log streams in Amazon CloudWatch Logs, and to put log events into those streams. These permissions are fundamental for monitoring function execution, debugging, and ensuring operational visibility, making it the correct and least-privileged choice for basic Lambda functionality.

Why this answer

The AWSLambdaBasicExecutionRole managed policy grants permissions for Lambda to write logs to CloudWatch Logs, specifically allowing the logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents actions. This is the minimal set of permissions required for a Lambda function to send execution logs to CloudWatch, making it the correct choice for this use case.

Exam trap

The trap here is that candidates may mistakenly choose a broad policy like AdministratorAccess or a service-specific policy like AmazonDynamoDBFullAccess, thinking they need to grant 'full' permissions or that the Lambda function might need access to other services, when the question specifically asks only for CloudWatch logging permissions.

How to eliminate wrong answers

Option B (AdministratorAccess) is wrong because it grants full administrative permissions to all AWS services, which violates the principle of least privilege and is overly permissive for a Lambda function that only needs to write logs. Option C (AmazonDynamoDBFullAccess) is wrong because it provides full access to DynamoDB operations but does not include any CloudWatch Logs permissions, so the Lambda function would fail to write logs. Option D (AmazonS3FullAccess) is wrong because it grants full access to S3 buckets and objects but lacks the necessary CloudWatch Logs actions, making it irrelevant for logging purposes.

1000
MCQeasy

A company wants to give a third-party auditor read-only access to their AWS account for compliance purposes. What is the most appropriate way to grant this access?

A.Attach the AdministratorAccess managed policy to an IAM user.
B.Create an IAM role with the SecurityAudit managed policy and allow the auditor to assume it.
C.Create an IAM user with a custom policy that allows all actions.
D.Share the root account credentials with the auditor.
AnswerB

Creating an IAM role with the SecurityAudit managed policy and allowing the auditor to assume it is the correct approach because SecurityAudit grants only read-only access to security-related services and many other AWS services, aligning with the auditor's need to review configurations and logs without making changes. The role uses temporary credentials through AWS STS, so no long-term keys are issued or shared, and access can be scoped with a trust policy that specifies the auditor's AWS account or external identity provider. This follows least privilege and provides a secure, auditable mechanism for third-party access.

Why this answer

An IAM role with the AWS-managed SecurityAudit policy grants read-only access to configuration and audit metadata across services without allowing data access or mutations. The auditor assumes the role using STS, receiving temporary credentials, which is the AWS-recommended pattern for cross-account or third-party access. This satisfies least privilege and avoids long-lived credentials.

Exam trap

DVA-C02 often tests the reflex to grant access via IAM users or managed admin policies when the correct answer is a scoped IAM role with temporary credentials — candidates overlook roles and least-privilege managed policies like SecurityAudit.

How to eliminate wrong answers

Option A is wrong because AdministratorAccess grants full control over the account, violating least privilege and giving the auditor far more than read-only compliance access. Option C is wrong because a custom policy allowing all actions is effectively admin access and is both over-permissive and unnecessary when SecurityAudit already exists. Option D is wrong because sharing root credentials is a severe security anti-pattern — root has unrestricted access, cannot be scoped, and its compromise is catastrophic; AWS explicitly advises against root usage for anything but a few account-level tasks.

1001
MCQhard

A team is using AWS CodePipeline to deploy a critical application to Amazon ECS. The pipeline has a deployment stage that uses Amazon ECS (Blue/Green) action with CodeDeploy. Recently, the deployment failed because the new task set did not become healthy within the specified timeout. The team wants to ensure that future deployments automatically roll back if the health check fails. What should the team do?

A.Create a CloudWatch alarm that triggers when the healthy task count of the ECS service falls below a threshold. Configure the CodeDeploy deployment group to automatically roll back when this alarm is in ALARM state.
B.Modify the CodeDeploy deployment group to enable automatic rollback when a deployment fails. The deployment will automatically revert to the last successful deployment.
C.Increase the deployment timeout in the CodeDeploy deployment configuration to allow more time for the new task set to become healthy.
D.Configure the ECS service to automatically roll back to the previous task definition if the deployment fails. Use the ECS service's deployment circuit breaker.
AnswerB

While CodeDeploy deployment groups do offer an option to automatically roll back on deployment failures (e.g., hooks failing, timeout, or insufficient instances), this addresses a different problem than what the team is facing. The question implies the deployment itself might succeed initially, but the application's health degrades after the deployment completes or during the traffic shifting phase. Rolling back only on deployment failure wouldn't catch post-deployment health issues detected by the healthy task count.

Why this answer

AWS CodeDeploy allows you to configure automatic rollbacks in the event of a deployment failure. If a new task set fails to become healthy within the specified timeout during an Amazon ECS blue/green deployment, CodeDeploy marks the deployment as failed. By enabling the 'Roll back when a deployment fails' option in the CodeDeploy deployment group, CodeDeploy will automatically roll back the deployment to the last known successful revision without requiring manual intervention or custom CloudWatch alarms.

Exam trap

Candidates often think they need to set up complex CloudWatch alarms (Option A) or use ECS deployment circuit breakers (Option D) to roll back ECS blue/green deployments. However, because the deployment is managed by CodeDeploy, the native and simplest way to handle this is to enable automatic rollback on deployment failure directly within the CodeDeploy deployment group configuration.

How to eliminate wrong answers

Option B is wrong because enabling automatic rollback on deployment failure only triggers after the deployment has already failed (e.g., timeout exceeded), not when health checks fail during the deployment's lifecycle. Option C is wrong because increasing the timeout merely delays the failure detection; it does not implement a rollback mechanism. Option D is wrong because the ECS service's deployment circuit breaker rolls back the ECS service itself, but it does not integrate with CodeDeploy's Blue/Green deployment lifecycle or trigger a rollback of the CodePipeline pipeline stage.

1002
MCQhard

A developer is deploying a serverless application using AWS Lambda and API Gateway. The application needs to authenticate users via a third-party OIDC provider. The developer wants to minimize latency and avoid managing sessions. What is the BEST approach to achieve this?

A.Use Amazon Cognito User Pools with the OIDC identity provider and integrate with API Gateway.
B.Use Lambda@Edge to validate tokens at CloudFront edge locations.
C.Use Amazon Cognito Identity Pools with the OIDC provider.
D.Implement a custom Lambda authorizer in API Gateway to validate tokens.
AnswerA

Amazon Cognito User Pools provide a managed user directory service that handles user registration, authentication, and account recovery. When integrated with API Gateway, User Pools can directly validate JSON Web Tokens (JWTs) issued after successful user authentication, simplifying the authorization process. This native integration offloads token validation and user management, making it an efficient and scalable solution for serverless applications without requiring custom code.

Why this answer

Amazon Cognito User Pools natively support OIDC identity providers as federated IdPs, and API Gateway can use a Cognito User Pool authorizer to validate the resulting JWT tokens at the edge with minimal latency and no session management. This offloads authentication to a managed service, satisfying the requirements for third-party OIDC auth, low latency, and statelessness.

Exam trap

The trap is confusing Cognito User Pools (authentication, OIDC federation, JWT issuance) with Cognito Identity Pools (AWS credential vending) — candidates who pick Identity Pools misunderstand that API Gateway authorization needs authentication tokens, not temporary AWS credentials.

How to eliminate wrong answers

Option B is wrong because Lambda@Edge runs at CloudFront edge locations but is not an authentication service — it would require custom token validation code and adds complexity without the managed OIDC integration Cognito provides. Option C is wrong because Cognito Identity Pools provide AWS credentials for authenticated users (federation for AWS access), not user authentication/session tokens for API Gateway authorization. Option D is wrong because a custom Lambda authorizer requires writing and maintaining token validation logic, increasing latency and operational overhead compared to the native Cognito User Pool authorizer.

1003
MCQmedium

The exhibit shows the output of invoking a Lambda function from the AWS CLI. The function returned a status code of 200 but included a FunctionError field set to 'Unhandled'. What does this indicate?

A.The function executed but threw an unhandled exception.
B.The function returned an error in the LogResult field.
C.The function timed out during execution.
D.The function was invoked but there was a network error.
AnswerA

A 200 status code confirms the invocation reached the function and returned a response, while FunctionError set to 'Unhandled' signals the runtime caught an exception the code did not handle. The function executed but terminated abnormally, so the handler threw an unhandled error.

Why this answer

When a Lambda function returns a status code of 200 but includes a FunctionError field set to 'Unhandled', it means the function was invoked successfully but encountered an unhandled exception during execution. The 'Unhandled' error indicates that the function threw an error that was not caught by the function's code, causing the Lambda runtime to report it. The status code 200 refers to the HTTP response from the Lambda service, not the function's execution status.

Exam trap

DVA-C02 often tests the confusion between HTTP status codes and function execution errors, leading candidates to think a 200 status means success even when FunctionError is present.

How to eliminate wrong answers

Option B is wrong because the LogResult field contains base64-encoded logs, not error information; the FunctionError field specifically indicates an unhandled exception. Option C is wrong because a timeout would result in a FunctionError of 'Unhandled' with a specific timeout message, but the question states the function returned a status code 200, which would not happen on timeout. Option D is wrong because a network error would typically result in a different error, such as a connection error, not a FunctionError field in the response.

1004
MCQeasy

A company has a DynamoDB table that stores personally identifiable information (PII). A developer needs to allow a Lambda function to read and write to this table. What is the MOST secure way to grant the Lambda function access?

A.Create an IAM role with a policy that allows DynamoDB read/write access and attach it to the Lambda function.
B.Use a resource-based policy on the DynamoDB table to allow the Lambda function's IAM role.
C.Create an IAM user with programmatic access and embed the credentials in the Lambda environment variables.
D.Have the Lambda function assume a role using AWS STS each time it runs.
AnswerA

An IAM role attached to the Lambda function supplies temporary credentials via the execution environment, so no long-term keys are stored. Scoping the policy to the specific DynamoDB table actions follows least privilege, satisfying the PII security requirement.

Why this answer

Attaching an IAM role with a least-privilege policy to the Lambda function is the AWS-recommended, most secure approach. Lambda assumes the execution role automatically at invocation, and no long-lived credentials are stored anywhere. This eliminates credential leakage risk and follows the principle of least privilege.

Exam trap

DVA-C02 often tests whether candidates know that Lambda automatically assumes an execution role — the trap is picking STS AssumeRole inside the function or embedding credentials, which are either redundant or insecure.

How to eliminate wrong answers

Option B is wrong because DynamoDB does not support resource-based policies that grant access to IAM roles for data-plane operations; DynamoDB resource policies are limited and not a substitute for identity-based policies on the Lambda execution role. Option C is wrong because embedding IAM user credentials in environment variables is a serious security anti-pattern — credentials can be exposed via logs, console, or code, and they are long-lived. Option D is wrong because Lambda already assumes an execution role automatically; manually calling STS AssumeRole inside the function adds unnecessary complexity and latency, and still requires an execution role with sts:AssumeRole permissions.

1005
MCQmedium

Refer to the exhibit. A developer attempted to update a CloudFormation stack that includes an EC2 instance. The update failed and the stack is rolling back. The event shows that the EC2 instance update failed with reason 'Resource update cancelled: stack update cancelled'. What is the most likely cause of this failure?

A.A stack policy is preventing updates to the EC2 instance resource.
B.The IAM user does not have permission to update EC2 instances.
C.The template has a missing required parameter for the EC2 instance.
D.The EC2 instance is in a stopped state and cannot be updated.
AnswerA

CloudFormation stack policies are JSON documents that define which resources within a stack can be updated or deleted. If a stack policy is in place and explicitly denies an update action (e.g., "Update": "Deny") on a specific EC2 instance resource, any attempt to modify that resource will be rejected by CloudFormation. This rejection manifests as a "cancelled" status for the update operation, as the service is explicitly prevented from proceeding with the requested change due to the policy's enforcement.

Why this answer

A CloudFormation stack policy is an explicit guardrail that denies Update:Modify (or Update:Replace) actions on specified resources. When the update attempts to modify the EC2 instance, the policy blocks the change, CloudFormation cancels the resource update, and the stack begins rolling back — producing exactly the 'Resource update cancelled: stack update cancelled' event. This is the only option that directly produces a cancellation rather than an authorization, template, or runtime-state error.

Exam trap

DVA-C02 often tests whether candidates can distinguish between IAM authorization failures (Access Denied) and CloudFormation stack-policy denials (Resource update cancelled) — the wording 'cancelled' is the key signal for a stack policy, not permissions.

How to eliminate wrong answers

Option B is wrong because missing IAM permissions produce an 'Access Denied' or 'not authorized to perform: cloudformation:UpdateStack' error, not a resource-level cancellation event. Option C is wrong because a missing required parameter fails template validation before any resource update begins, yielding a 'Parameters: [X] must have values' error rather than a mid-update cancellation. Option D is wrong because a stopped EC2 instance does not prevent CloudFormation from updating its properties; the instance state is irrelevant to the update API call.

1006
Multi-Selecthard

A developer is using AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment is set to use a 'OneAtATime' deployment configuration. The developer wants to ensure that the deployment does not cause downtime. Which TWO configurations are necessary?

Select 2 answers
A.Set the 'IgnoreApplicationStopFailures' flag to true.
B.Configure a load balancer for the Auto Scaling group.
C.Use an 'AllAtOnce' deployment configuration.
D.Configure health checks on the load balancer.
E.Install the CodeDeploy agent on each instance.
AnswersB, D

Configuring a load balancer for the Auto Scaling group is crucial for achieving zero-downtime deployments. A load balancer, such as an Application Load Balancer (ALB), can gracefully drain connections from instances being updated, ensuring active user sessions are not abruptly terminated. It then reroutes traffic to healthy, available instances, and only directs new traffic to instances once the updated application is fully deployed and passes health checks, thereby maintaining continuous service availability during the deployment process.

Why this answer

Registering the Auto Scaling group with a load balancer allows CodeDeploy to deregister each instance before deployment and re-register it after the new application version is installed and passes health checks. This ensures traffic is shifted away from the instance being updated, preventing downtime during a 'OneAtATime' deployment.

Exam trap

The trap here is that candidates often think setting 'IgnoreApplicationStopFailures' or using 'AllAtOnce' can achieve zero downtime, but without a load balancer and health checks, traffic cannot be shifted away from instances during deployment.

1007
MCQhard

A developer is deploying a microservices architecture on Amazon ECS with Fargate. Each service needs to store sensitive configuration data such as database passwords. The developer wants to avoid hardcoding secrets in the application code. Which approach should the developer use?

A.Store the secrets in an Amazon S3 bucket and use a pre-signed URL to download them at startup.
B.Define the secrets as environment variables in the ECS task definition.
C.Encrypt the secrets using AWS KMS and store the encrypted blob in a configuration file within the Docker image.
D.Store the secrets in AWS Systems Manager Parameter Store or AWS Secrets Manager and reference them in the ECS task definition using the 'secrets' parameter.
AnswerD

This is the most secure and recommended approach for managing secrets in ECS. AWS Systems Manager Parameter Store (especially `SecureString` parameters) and AWS Secrets Manager are purpose-built services for securely storing and managing sensitive data. By referencing these services in the ECS task definition's `secrets` parameter, ECS automatically retrieves and injects the secrets into the container's environment at runtime, leveraging the task's IAM role for secure, granular access. This ensures secrets are never hardcoded, are not visible in task definitions or logs, and can be rotated independently of application deployments.

Why this answer

AWS Systems Manager Parameter Store and AWS Secrets Manager are purpose-built services for securely storing and managing sensitive configuration data. By referencing secrets via the `secrets` parameter in the ECS task definition, the secrets are injected into the container at runtime without being exposed in the application code, task definition plaintext, or Docker image. This approach integrates natively with ECS Fargate and supports automatic rotation of secrets.

Exam trap

The trap here is that candidates often choose Option B (environment variables in the task definition) because it seems simple and works in development, but they overlook that the task definition is stored in plaintext and accessible via the ECS API, making it insecure for production secrets.

How to eliminate wrong answers

Option A is wrong because storing secrets in an S3 bucket with a pre-signed URL introduces a long-lived URL that can be intercepted or leaked, and it does not provide native secret rotation or fine-grained access control compared to AWS Secrets Manager. Option B is wrong because defining secrets as environment variables in the ECS task definition stores them in plaintext within the task definition, which can be viewed by anyone with access to the ECS API or console, violating security best practices. Option C is wrong because encrypting secrets with KMS and storing the encrypted blob in a Docker image embeds the encrypted data in the image, making it difficult to rotate secrets without rebuilding the image, and the decryption key must be managed separately, increasing complexity and risk.

1008
MCQeasy

A developer is writing code to upload an object to an Amazon S3 bucket. The object is 200 MB in size. Which AWS SDK method should the developer use to perform this upload?

A.Enable S3 Transfer Acceleration and use the PutObject API.
B.Use the PutObject API operation.
C.Use the multipart upload API.
D.Use a pre-signed URL and upload using HTTP PUT.
AnswerC

The S3 multipart upload API is the recommended and most robust method for uploading large objects to Amazon S3, particularly those exceeding 100 MB, and is mandatory for objects larger than 5 GB. This API breaks the object into smaller, manageable parts, which can be uploaded independently, in parallel, and even out of order. This approach significantly enhances upload speed, provides resilience against network failures (only failed parts need re-uploading), and allows for pausing and resuming uploads.

Why this answer

Objects larger than 100 MB should be uploaded using the multipart upload API to improve throughput and provide resilience against network failures. The multipart upload API allows the 200 MB object to be split into parts, uploaded in parallel, and then assembled, which is more efficient and reliable than a single PutObject operation for objects over 5 GB or for large objects in general.

Exam trap

The trap here is that candidates assume the PutObject API is sufficient for any object under 5 GB, but the AWS SDK best practice and the exam emphasize using multipart upload for objects over 100 MB to ensure reliability and performance.

How to eliminate wrong answers

Option A is wrong because S3 Transfer Acceleration is a feature that speeds up uploads over long distances using edge locations, but it does not replace the need for multipart upload for large objects; the PutObject API still has a 5 GB limit and is not recommended for objects over 100 MB. Option B is wrong because the PutObject API operation is designed for objects up to 5 GB, but for a 200 MB object, using a single PutObject call is less reliable and efficient than multipart upload due to potential network interruptions and lack of parallel uploads. Option D is wrong because a pre-signed URL grants temporary access for an HTTP PUT upload, but it still uses the PutObject API under the hood, which is not optimal for a 200 MB object; multipart upload is the recommended approach for objects over 100 MB.

1009
MCQmedium

A company has an S3 bucket that stores sensitive customer data. The security team requires that all data be encrypted at rest using server-side encryption with AWS KMS. Additionally, they want to enforce that objects are not uploaded without encryption. Which bucket policy should be used?

A.Deny s3:PutObject if the request includes x-amz-server-side-encryption
B.Deny s3:PutObject unless the request includes x-amz-server-side-encryption with value aws:kms
C.Allow s3:PutObject only if the request uses a specific KMS key
D.Deny s3:PutObject unless the request includes x-amz-server-side-encryption with value AES256
AnswerB

This bucket policy statement correctly enforces Server-Side Encryption with AWS KMS (SSE-KMS) for all objects uploaded to the S3 bucket. By using a `Deny` effect with a `StringNotEquals` condition on the `s3:x-amz-server-side-encryption` header, it ensures that any `PutObject` request that does not explicitly specify `aws:kms` for server-side encryption will be rejected. This guarantees that all sensitive customer data at rest is protected by customer-managed or AWS-managed KMS keys.

Why this answer

It uses a Deny effect with a condition that checks for the presence and value of the `x-amz-server-side-encryption` header. This policy explicitly denies any `s3:PutObject` request that does NOT include `x-amz-server-side-encryption` with the value `aws:kms`, thereby enforcing server-side encryption with AWS KMS (SSE-KMS) on all uploads.

Exam trap

The trap here is that candidates often confuse the encryption header values (`aws:kms` vs `AES256`) or mistakenly think that an Allow statement alone can enforce encryption, when in fact a Deny statement with a condition is required to block non-compliant requests.

How to eliminate wrong answers

Option A is wrong because it denies `s3:PutObject` if the request includes the `x-amz-server-side-encryption` header, which would block all encrypted uploads, not enforce them. Option C is wrong because it only allows `s3:PutObject` if a specific KMS key is used, but it does not enforce that encryption is present at all; a request without encryption could still be allowed if no explicit Deny is present. Option D is wrong because it enforces SSE-S3 (AES256) rather than SSE-KMS (aws:kms), which does not meet the requirement for server-side encryption with AWS KMS.

1010
Multi-Selectmedium

A developer is using AWS Elastic Beanstalk to deploy a web application. The application is experiencing high latency. Which TWO steps should the developer take to troubleshoot and optimize the application?

Select 2 answers
A.Configure an Amazon RDS read replica.
B.Enable AWS X-Ray integration and analyze service maps.
C.Enable enhanced health reporting and review the environment health metrics.
D.Increase the instance type to a larger size.
E.Deploy the application to a different AWS region.
AnswersB, C

Enabling AWS X-Ray on Elastic Beanstalk instruments your application and produces service maps and traces that reveal end-to-end request paths, downstream call latencies, and dependency errors. Analyzing these maps pinpoints slow segments such as API calls, database queries, or third-party services that contribute to user-facing latency. This is precisely the diagnostic step needed to focus on the actual bottleneck in the code or call chain.

Why this answer

AWS X-Ray integration provides tracing to identify bottlenecks in the application. Option C is correct because enhanced health reporting gives detailed environment health metrics for troubleshooting. Option A is wrong because an RDS read replica is for database read scaling, not directly for latency troubleshooting.

Option D is wrong because increasing the instance type is a scaling solution, not a troubleshooting step. Option E is wrong because deploying to a different region does not address latency for existing users.

1011
MCQhard

A company uses AWS CloudFormation to deploy resources. The templates are stored in an S3 bucket. A developer wants to ensure that only authorized users can create stacks from these templates. What should be implemented?

A.Use IAM policies to control who can call CreateStack and add S3 bucket policies to restrict template access.
B.Use a stack policy to restrict updates.
C.Enable CloudTrail to log template access.
D.Set the S3 bucket to private and rely on bucket policies.
AnswerA

IAM policies are crucial for controlling which users or roles can invoke the `CreateStack` API action within CloudFormation, directly preventing unauthorized stack deployments. Concurrently, S3 bucket policies restrict access to the CloudFormation template file itself, ensuring only authorized entities can read or download it. This dual-layer approach provides robust preventative security by controlling both the action and the asset, embodying a defense-in-depth strategy.

Why this answer

It combines two layers of access control: IAM policies restrict the ability to call the CreateStack API action, and S3 bucket policies restrict access to the template objects stored in S3. This ensures that even if a user has IAM permissions to create stacks, they cannot retrieve or use the template unless the S3 bucket policy also grants them access. Without both controls, an unauthorized user could bypass IAM by directly accessing the template URL or using a different AWS account.

Exam trap

The trap here is that candidates often assume S3 bucket policies alone are sufficient for access control, forgetting that IAM policies are required to authorize the CreateStack API call itself.

How to eliminate wrong answers

Option B is wrong because stack policies control updates to stack resources after creation, not who can create stacks from templates. Option C is wrong because CloudTrail logs API calls for auditing but does not enforce any access control or authorization. Option D is wrong because setting the S3 bucket to private and relying solely on bucket policies does not prevent an authorized S3 user from creating a stack with the template; it also fails to control the CreateStack API call itself, which is governed by IAM.

1012
MCQmedium

A developer is troubleshooting an AWS Lambda function that processes records from an Amazon Kinesis Data Stream. The function is configured with a batch size of 100 and a parallelization factor of 1. The iterator age metric is increasing, and CloudWatch Logs show the function execution time is around 4 minutes (timeout is 5 minutes). The stream has 10 shards. What is the most cost-effective way to increase processing throughput?

A.Increase the batch size to 500
B.Increase the number of shards
C.Increase the timeout to 10 minutes
D.Increase the parallelization factor per shard
AnswerD

Increasing the parallelization factor per shard for a Kinesis stream event source mapping allows a single Lambda function to process multiple concurrent batches from the *same* shard. By default, Lambda processes one batch per shard concurrently. Raising this factor (up to 10) directly boosts the effective processing throughput from each shard without incurring additional Kinesis shard costs, making it a highly efficient way to reduce iterator age and catch up on backlog.

Why this answer

Increasing the parallelization factor per shard (option D) allows each shard to be processed by multiple Lambda instances concurrently, which directly increases throughput without requiring additional shards or changes to the stream. Since the function is not hitting the 5-minute timeout but is taking ~4 minutes per batch, the bottleneck is processing concurrency per shard, not batch size or execution duration. This is the most cost-effective solution because it uses existing shards and avoids the cost of additional shards or unnecessary timeout increases.

Exam trap

The trap here is that candidates often assume increasing batch size (option A) is the natural fix for slow processing, but they overlook that the function is already near its timeout limit, making a larger batch size impractical without also increasing the timeout.

How to eliminate wrong answers

Option A is wrong because increasing the batch size to 500 would likely cause the function to exceed the 5-minute timeout (since it already takes ~4 minutes for 100 records), leading to throttling and failed processing. Option B is wrong because increasing the number of shards incurs additional costs and is not the most cost-effective approach; the current 10 shards are underutilized due to the parallelization factor of 1. Option C is wrong because the function is not timing out (it completes in ~4 minutes with a 5-minute timeout), so increasing the timeout does not address the throughput bottleneck and only delays potential failures.

1013
Multi-Selectmedium

A developer is troubleshooting an AWS Lambda function that is timing out. The function has a timeout of 5 seconds and is configured with 128 MB of memory. Which TWO of the following are effective ways to resolve the timeout?

Select 2 answers
A.Increase the memory allocation to 512 MB.
B.Decrease the memory allocation to 64 MB.
C.Deploy the function inside a VPC.
D.Optimize the function code to reduce execution time.
E.Increase the function timeout to 10 seconds.
AnswersA, D

Increasing the memory allocation for an AWS Lambda function directly scales the available CPU power proportionally. This provides more computational resources, allowing the function to process data faster and complete tasks in less time. Additionally, higher memory allocations often come with increased network bandwidth, which can significantly reduce I/O bound delays for functions interacting with other AWS services or external APIs, thereby mitigating potential timeouts.

Why this answer

Increasing memory allocation in AWS Lambda proportionally increases CPU and network throughput, which can reduce execution time and prevent timeouts. With 128 MB, the function may be CPU-bound; raising it to 512 MB provides more compute resources, often resolving timeout issues without code changes.

Exam trap

The trap here is that candidates often think increasing the timeout alone is a valid fix, but the DVA-C02 exam emphasizes resolving the root cause (e.g., insufficient resources or inefficient code) rather than just extending the timeout window.

1014
MCQhard

A company is migrating a monolithic application to microservices on AWS. They want to use a blue/green deployment strategy for a new version of a service running on Amazon ECS with Fargate. The service is behind an Application Load Balancer. Which combination of actions should be taken to implement blue/green deployment with minimal downtime? (Choose the correct answer.)

A.Create a second ALB pointing to the new service, then update DNS to switch traffic.
B.Use AWS CodeDeploy to orchestrate a blue/green deployment by creating a new task set and shifting traffic.
C.Update the existing ECS service with the new task definition and allow rolling update.
D.Manually create a new target group with the new service and update the ALB listener rule.
AnswerB

This is the recommended approach for zero-downtime deployments on Amazon ECS. AWS CodeDeploy orchestrates a blue/green deployment by provisioning a completely new "green" task set alongside the existing "blue" one. It then incrementally shifts traffic from the blue environment to the green environment using the Application Load Balancer, allowing for thorough testing before full cutover. This method provides immediate rollback capabilities if issues arise, ensuring minimal impact and high availability during updates.

Why this answer

AWS CodeDeploy supports blue/green deployments on Amazon ECS with Fargate. It creates a new task set and gradually shifts traffic from the existing (blue) task set to the new (green) task set, minimizing downtime. Option A is incorrect because managing a second ALB and updating DNS is more complex and not the typical approach for ECS blue/green; AWS CodeDeploy automates this.

Option C is incorrect because a rolling update updates the existing service in place, which may cause downtime or require careful orchestration; it is not a blue/green deployment. Option D is incorrect because manually creating a new target group and modifying the ALB listener rule is error-prone and does not provide automated traffic shifting or rollback capabilities.

1015
MCQhard

A developer is using AWS X-Ray to trace requests through a microservices application. The application consists of several AWS Lambda functions that call each other and Amazon DynamoDB. The developer notices that some traces are incomplete and missing segments for downstream calls. What is the MOST likely cause?

A.The downstream DynamoDB table does not have X-Ray tracing enabled.
B.The Lambda functions do not have the X-Ray SDK imported.
C.The X-Ray daemon is not running on the Lambda execution environment.
D.The X-Ray sampling rate is set too low.
AnswerB

This is correct. If the Lambda functions do not import the X-Ray SDK, they cannot create segments or subsegments for downstream calls, leading to incomplete traces.

Why this answer

The Lambda functions need to import the X-Ray SDK to create subsegments for downstream calls and propagate the trace header. Without the SDK, traces will be missing segments for DynamoDB calls. DynamoDB does not have a per-table X-Ray tracing setting; tracing is achieved by instrumenting the client in the calling code.

Exam trap

The trap is that candidates often think DynamoDB tables have an X-Ray tracing toggle, but in reality, X-Ray tracing for DynamoDB is done by instrumenting the client with the X-Ray SDK. The most common cause of missing segments is failing to import and use the X-Ray SDK in Lambda functions.

How to eliminate wrong answers

Option B is wrong because the Lambda functions do not need the X-Ray SDK imported to send trace data; the X-Ray daemon automatically captures segments for Lambda invocations and downstream calls if the service supports it. Option C is wrong because the X-Ray daemon is already running in the Lambda execution environment by default when X-Ray tracing is enabled on the Lambda function. Option D is wrong because a low sampling rate would reduce the number of traces captured, not cause incomplete traces with missing segments for downstream calls.

1016
MCQmedium

A developer is using Amazon API Gateway with a Lambda authorizer to control access to an API. The authorizer function needs to decode a JWT token from the request header and return an IAM policy. Which type of Lambda authorizer should be used?

A.TOKEN authorizer with the token passed in the Authorization header.
B.REQUEST authorizer with the token in a custom header.
C.Use Amazon Cognito User Pools as the authorizer.
D.Use a resource policy to allow or deny access based on the JWT token.
AnswerA

A TOKEN authorizer is specifically designed to receive a single authorization token, typically a JWT, from a designated header like `Authorization`. It passes this token directly to a Lambda function which then decodes and validates it, returning an IAM policy that grants or denies access to API resources. This streamlined approach is ideal for scenarios focused solely on token-based authentication, simplifying the Lambda's input processing by providing just the raw token string.

Why this answer

A TOKEN authorizer is designed to receive a JWT or OAuth token in the Authorization header and pass it directly to the Lambda function for validation. The Lambda function then decodes the token and returns an IAM policy document to allow or deny the API request. This is the correct choice because the question explicitly states the token is in the request header and needs to be decoded, which matches the TOKEN authorizer's behavior of forwarding the raw token value.

Exam trap

The trap here is that candidates confuse the TOKEN authorizer (which passes only the token) with the REQUEST authorizer (which passes the full request), assuming that decoding a JWT requires access to other request parameters, when in fact the token alone is sufficient for validation.

How to eliminate wrong answers

Option B is wrong because a REQUEST authorizer passes the entire request context (headers, query parameters, path parameters) to the Lambda function, which is unnecessary overhead when only the JWT token from a header is needed; it also requires more complex parsing logic. Option C is wrong because Amazon Cognito User Pools are a managed identity service that handles JWT verification natively, not a Lambda authorizer; using them would bypass the requirement for a custom Lambda function to decode the token. Option D is wrong because resource policies control access based on IP addresses, VPCs, or AWS accounts, not on the contents of a JWT token; they cannot decode or validate token claims.

1017
MCQhard

A company uses AWS Secrets Manager to store database credentials. The credentials must be automatically rotated every 30 days. The developer needs to configure rotation without exposing the secret to any IAM user directly. Which configuration steps should the developer take?

A.Enable automatic rotation and choose a rotation interval of 30 days. Secrets Manager will automatically rotate the secret using a built-in Lambda function.
B.Create a Lambda function with rotation logic, attach an IAM role with permissions to read and update the secret, and configure Secrets Manager to invoke the function every 30 days.
C.Use AWS Certificate Manager (ACM) to rotate the secret automatically every 30 days.
D.Store the secret in AWS Systems Manager Parameter Store and set a schedule to rotate it using a CloudWatch Events rule.
AnswerB

This is the correct approach for implementing secret rotation with AWS Secrets Manager. To enable automatic rotation, a dedicated AWS Lambda function must be created, containing the specific logic to generate a new secret, update it in the target service (e.g., a database), and then update Secrets Manager. This Lambda function requires an IAM role with precise permissions, including `secretsmanager:GetSecretValue` to retrieve the current secret and `secretsmanager:PutSecretValue` to store the new one, along with permissions to interact with the target resource. Secrets Manager is then configured to invoke this Lambda function on the specified schedule, such as every 30 days.

Why this answer

AWS Secrets Manager does not provide a built-in Lambda function for rotating database credentials; you must create your own Lambda function that contains the rotation logic (e.g., querying the database, creating a new credential, and updating the secret). The Lambda function must be attached to an IAM role with permissions to read and update the secret, and Secrets Manager invokes this function based on the rotation schedule (every 30 days). This ensures the secret is never exposed directly to any IAM user, as only the Lambda function interacts with the secret programmatically.

Exam trap

The trap here is that candidates assume Secrets Manager provides a built-in Lambda function for all secret types, but in reality, you must create your own Lambda function for database credentials, while only AWS-managed secrets (like RDS) have pre-built rotation templates.

How to eliminate wrong answers

Option A is wrong because Secrets Manager does not include a built-in Lambda function for rotating secrets; you must provide your own custom Lambda function with the rotation logic. Option C is wrong because AWS Certificate Manager (ACM) is used for managing SSL/TLS certificates, not for rotating database credentials stored in Secrets Manager. Option D is wrong because AWS Systems Manager Parameter Store does not support automatic rotation of secrets; it is a simple key-value store without built-in rotation capabilities, and using a CloudWatch Events rule would require custom scripting and does not integrate with Secrets Manager's native rotation features.

1018
MCQhard

A developer is running an AWS Lambda function that is triggered by Amazon S3 events. The function writes processed data to an Amazon DynamoDB table. Over time, the function's execution time has increased significantly. CloudWatch Logs show many DynamoDBProvisionedThroughputExceededException errors. The table is configured with 5 read capacity units (RCUs) and 5 write capacity units (WCUs). The function performs both reads and writes. Which optimization will MOST effectively reduce throttling errors while maintaining performance?

A.Increase the RCUs and WCUs of the table to 50 each
B.Switch the DynamoDB table to on-demand capacity mode
C.Implement a DynamoDB Accelerator (DAX) cluster for caching reads
D.Increase Lambda function memory to 1024 MB
AnswerB

Switching to on-demand capacity mode allows DynamoDB to automatically scale read and write throughput based on the actual traffic patterns generated by the Lambda function. This eliminates ProvisionedThroughputExceededException errors by dynamically adjusting capacity, ensuring the table can handle unpredictable or spiky workloads without manual intervention or capacity planning. It directly resolves throttling issues stemming from insufficient provisioned capacity.

Why this answer

The DynamoDBProvisionedThroughputExceededException errors indicate that the Lambda function is exceeding the provisioned write capacity of 5 WCUs. Switching to on-demand capacity mode eliminates the need to manage throughput, automatically scaling to handle the workload without throttling. This directly resolves the root cause—capacity exhaustion—without requiring manual adjustments or architectural changes.

Exam trap

The trap here is that candidates often confuse read throttling with write throttling and reach for DAX (a read cache) or assume that increasing Lambda resources will solve database-level throughput issues, when the real fix is to match the database capacity mode to the workload pattern.

How to eliminate wrong answers

Option A is wrong because simply increasing RCUs and WCUs to 50 is a manual, reactive fix that does not address the root cause of unpredictable traffic patterns; it may still lead to throttling if the workload spikes beyond the new limit, and it incurs unnecessary cost if the average usage is lower. Option C is wrong because DAX caches reads only, but the errors are DynamoDBProvisionedThroughputExceededException, which primarily affects writes (the function writes processed data); caching reads does not reduce write throttling. Option D is wrong because increasing Lambda memory only increases CPU and network throughput, not DynamoDB capacity; it does not resolve the throttling errors caused by exceeding the table's write capacity.

1019
MCQeasy

A developer is building a serverless application using AWS Lambda. The function needs to access a DynamoDB table and write logs to Amazon CloudWatch. What is the minimum set of IAM permissions the Lambda execution role must have?

A.dynamodb:PutItem, logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents
B.logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents
C.dynamodb:*, logs:PutLogEvents
D.dynamodb:GetItem, dynamodb:PutItem, logs:PutLogEvents
AnswerA

This option provides the precise set of permissions required for a serverless application, such as an AWS Lambda function, to operate effectively. `dynamodb:PutItem` enables the function to write data to a DynamoDB table, fulfilling its primary data interaction requirement. Concurrently, `logs:CreateLogGroup`, `logs:CreateLogStream`, and `logs:PutLogEvents` grant the necessary capabilities for the Lambda function to establish its dedicated log group and stream, then continuously publish its execution logs to CloudWatch, ensuring comprehensive operational visibility. This adheres to the principle of least privilege by granting only essential actions.

Why this answer

The Lambda execution role must include `dynamodb:PutItem` to write to the DynamoDB table, and the three `logs:` permissions (`CreateLogGroup`, `CreateLogStream`, `PutLogEvents`) are required for Lambda to create log groups/streams and send log events to CloudWatch Logs. This is the minimum set that satisfies both requirements without granting unnecessary privileges.

Exam trap

The trap here is that candidates often forget that Lambda requires both `logs:CreateLogGroup` and `logs:CreateLogStream` (not just `logs:PutLogEvents`) to set up CloudWatch logging, or they assume `dynamodb:GetItem` is needed for writing, leading them to choose Option D.

How to eliminate wrong answers

Option B is wrong because it omits `dynamodb:PutItem`, which is essential for writing to the DynamoDB table; without it, the function will fail with an access denied error. Option C is wrong because `dynamodb:*` grants all DynamoDB actions (including delete, scan, etc.), which violates the principle of least privilege and is not the minimum set. Option D is wrong because it includes `dynamodb:GetItem` (unnecessary for writing) and omits `logs:CreateLogGroup` and `logs:CreateLogStream`, which are required for Lambda to initialize CloudWatch log streams; without them, the function cannot write logs.

1020
Multi-Selectmedium

A developer is designing a serverless application that uses Amazon API Gateway and AWS Lambda. The API receives a high volume of requests, and the developer needs to cache responses to reduce latency and cost. Which TWO actions should the developer take? (Choose TWO.)

Select 2 answers
A.Use DynamoDB Accelerator (DAX) to cache Lambda responses.
B.Use ElastiCache for Redis to store frequently accessed responses.
C.Use Amazon CloudFront in front of API Gateway to cache responses.
D.Enable API Gateway caching and set a TTL for the cache.
E.Configure the Lambda function to return cache-control headers in the response.
AnswersC, D

CloudFront caches at the edge location level, but API Gateway’s native caching operates at the API stage level, which is the specific requirement for reducing latency and cost within the API Gateway service itself. This option is tempting because CloudFront is commonly used to accelerate content delivery and cache static assets for web applications, and it would be the correct choice if the goal were to offload requests from the origin for a globally distributed user base rather than caching API responses at the API Gateway stage.

Why this answer

Option C is correct because Amazon CloudFront can be deployed in front of API Gateway as a CDN, caching responses at edge locations to reduce latency and offload requests from the API, which lowers Lambda invocations and cost. Option D is correct because API Gateway has a built-in caching feature that can be enabled per stage or method, and setting a TTL controls how long responses are cached, directly reducing backend calls and latency. Option A is incorrect because DAX is a caching layer for DynamoDB, not for API Gateway or Lambda responses.

Option B is incorrect because ElastiCache for Redis would require custom application logic to read/write the cache and is not a native API Gateway caching mechanism. Option E is incorrect because returning cache-control headers from Lambda does not by itself enable caching in API Gateway; caching must be explicitly configured on the API Gateway stage or method.

Exam trap

Candidates often miss that CloudFront (Option C) can be placed in front of API Gateway to act as a highly cost-effective cache. They might incorrectly choose Option E, thinking that returning `Cache-Control` headers from Lambda automatically enables caching, but without a caching proxy like CloudFront, those headers only affect client-side (browser) caching and do not protect the backend from high-volume concurrent requests from different users.

1021
MCQeasy

A developer is using Amazon S3 to host a static website. The website returns 403 Forbidden errors. The bucket policy allows public read access. What is the most likely cause?

A.The bucket's 'Block public access' settings are enabled.
B.The bucket has an ACL that denies read access.
C.The bucket policy does not include the 's3:GetObject' action.
D.The bucket policy is not correctly attached to the bucket.
AnswerA

This is the correct reason. Amazon S3 Block Public Access settings provide a critical security layer that overrides all other access control mechanisms, including bucket policies and ACLs, to prevent public access to S3 buckets and objects. If these settings are enabled at either the account or bucket level, they will effectively block any public read access, even if a bucket policy explicitly grants 's3:GetObject' permissions to the public, thereby preventing the static website from loading.

Why this answer

The most likely cause is that the bucket's 'Block public access' settings are enabled. Even if the bucket policy explicitly grants public read access, S3's Block Public Access settings act as an overarching security override that denies all public requests, resulting in a 403 Forbidden error. These settings are enabled by default for new buckets and can be applied at the account or bucket level, making them a common pitfall.

Exam trap

The trap here is that candidates often focus on the bucket policy syntax or ACLs, overlooking the fact that S3's Block Public Access settings can silently override all public permissions, even when the policy is perfectly written.

How to eliminate wrong answers

Option B is wrong because if an ACL denies read access, it would conflict with the bucket policy, but the question states the bucket policy allows public read access, and S3 evaluates both ACLs and policies; however, Block Public Access settings are a more common and immediate cause. Option C is wrong because the bucket policy is stated to allow public read access, which implicitly includes the 's3:GetObject' action; if it were missing, the error would be Access Denied, but the policy is correctly configured per the question. Option D is wrong because if the bucket policy were not correctly attached, the bucket would not have any policy to evaluate, leading to default private access (403), but the question explicitly says the policy allows public read access, implying it is attached; the issue is the Block Public Access override.

1022
Multi-Selectmedium

Which THREE steps should a developer include in a CI/CD pipeline to deploy a serverless application using AWS SAM? (Choose three.)

Select 3 answers
A.Run 'sam build' to prepare the application
B.Manually configure API Gateway stages
C.Run 'sam deploy' to create or update the CloudFormation stack
D.Run 'aws lambda update-alias' to shift traffic
E.Run 'sam package' to upload artifacts to S3
AnswersA, C, E

Correct. `sam build` is the first step in a SAM-based CI/CD pipeline. It compiles your source code, installs dependencies listed in `requirements.txt`, `package.json`, or similar manifests, and stages the runnable code under `.aws-sam/build`. It also rewrites the AWS SAM template to replace local artifact paths with the built-artifact locations, so downstream commands have a reproducible deployable bundle to consume.

Why this answer

Option A is correct because 'sam build' compiles dependencies and prepares the application artifacts in the .aws-sam/build directory, which is the required first step before packaging or deploying a SAM application. Option C is correct because 'sam deploy' creates or updates the CloudFormation stack that provisions the serverless resources (Lambda functions, API Gateway, IAM roles, etc.) defined in the SAM template. Option E is correct because 'sam package' uploads the built artifacts to an S3 bucket and rewrites the template with the S3 locations, which is necessary for CloudFormation to access the code during deployment (in newer SAM CLI versions this is handled automatically by 'sam deploy --guided', but 'sam package' remains the explicit packaging step).

Option B is incorrect because API Gateway stages are defined declaratively in the SAM template and created automatically by CloudFormation during deployment, not configured manually. Option D is incorrect because traffic shifting via Lambda aliases is an optional deployment preference configured in the SAM template (e.g., DeploymentPreference with Canary/Linear), not a manual 'aws lambda update-alias' command in the pipeline.

Exam trap

DVA-C02 often tests the misconception that manual console or CLI operations (like configuring API Gateway stages or updating aliases) belong in a CI/CD pipeline, when the exam expects the declarative SAM build/package/deploy sequence.

1023
MCQmedium

Refer to the exhibit. A developer runs the AWS CLI command for an EC2 instance. The instance is in the 'running' state, but the application hosted on it is not reachable. What should the developer check first?

A.Check the security group rules for inbound traffic.
B.Check the ELB health check settings.
C.Check the instance status checks in the EC2 console.
D.Verify the instance ID is correct.
AnswerA

Security groups act as a virtual stateful firewall for EC2 instances, controlling both inbound and outbound traffic. If the security group associated with the EC2 instance does not have an inbound rule explicitly allowing traffic on the required port (e.g., HTTP on port 80, SSH on port 22) from the source IP address range of the client, the connection will be blocked. This typically results in a "Connection refused" or timeout error, even if the instance is running and healthy, making it the most common cause of network connectivity issues.

Why this answer

When an EC2 instance is in the 'running' state but the application is unreachable, the most common initial cause is that the Security Group associated with the instance does not allow inbound traffic on the application's port (e.g., port 80 or 443). Security groups act as stateful firewalls at the instance level, and by default, they block all inbound traffic unless explicitly allowed.

Exam trap

Candidates often confuse the instance state ('running') with network accessibility. An instance can be fully operational and healthy, but still completely unreachable from the internet if the security group rules or network ACLs are misconfigured.

How to eliminate wrong answers

Option B is wrong because ELB health check settings are only relevant if the instance is behind an Elastic Load Balancer, and the question does not mention an ELB; even if it were, the health check would fail due to the same security group issue, making it a secondary check. Option C is wrong because instance status checks verify the OS and hypervisor health (e.g., system reachability), and since the instance is 'running' and the application is unreachable, the issue is likely at the network layer, not the instance's operational status. Option D is wrong because verifying the instance ID is a basic validation step that would have been done before running the CLI command; if the ID were incorrect, the CLI command would have failed with an error, not left the instance running but unreachable.

1024
MCQmedium

A developer attached the IAM policy above to an IAM user. What is the effect when the user tries to download an object from the 'confidential' folder in 'example-bucket'?

A.The policy is invalid because Deny cannot be used with s3:*
B.The user can download only if the object is encrypted
C.The user is denied access because of the explicit Deny statement
D.The user can download the object because of the Allow statement
AnswerC

The user is denied access precisely because of the explicit Deny statement within the IAM policy. According to IAM policy evaluation logic, an explicit Deny always takes precedence over any Allow statements. If a Deny statement matches the requested action (s3:GetObject) and resource (an object within the confidential folder), access is immediately blocked, regardless of other Allow permissions.

Why this answer

In AWS IAM, an explicit Deny statement always overrides any Allow statement, regardless of order or specificity. The policy includes a Deny for s3:* on the confidential folder, so the user is denied access to download objects there even if a separate Allow exists.

Exam trap

DVA-C02 often tests the IAM evaluation logic where candidates forget that explicit Deny always wins, leading them to pick the Allow-based answer.

How to eliminate wrong answers

Option A is wrong because Deny can absolutely be used with wildcard actions like s3:*; IAM policies support wildcards in both Action and Resource elements. Option B is wrong because encryption status of the object is irrelevant to the policy evaluation; the explicit Deny blocks access regardless of encryption. Option D is wrong because the Allow statement cannot override an explicit Deny; IAM evaluates explicit Deny first and it wins.

1025
MCQeasy

A developer wants to store application logs in Amazon S3 with automatic transition to Glacier after 30 days and deletion after 365 days. Which S3 feature should be used?

A.S3 Lifecycle configuration
B.S3 Object Lock
C.S3 Replication
D.S3 Event Notifications
AnswerA

S3 Lifecycle configuration is the correct choice because it allows developers to define rules for automatically transitioning objects between different S3 storage classes (e.g., S3 Standard to S3 Standard-IA, Glacier, or Glacier Deep Archive) based on their age or access patterns. This is ideal for application logs, which typically become less frequently accessed over time but still require retention, enabling significant cost savings by moving them to progressively colder storage tiers. Furthermore, lifecycle policies can also be configured to automatically expire and permanently delete objects after a specified period, ensuring compliance and managing storage footprint efficiently.

Why this answer

S3 Lifecycle configuration is the correct feature because it allows you to define rules that automatically transition objects to colder storage classes like Glacier after a specified number of days (30) and permanently delete them after a longer period (365). This directly matches the requirement for time-based storage tiering and deletion without manual intervention.

Exam trap

The trap here is that candidates confuse S3 Lifecycle policies with S3 Event Notifications, thinking event-driven triggers can handle time-based transitions, but Lifecycle policies are the only native S3 feature that automates storage class transitions and deletions based on object age.

How to eliminate wrong answers

Option B is wrong because S3 Object Lock is designed to prevent objects from being deleted or overwritten for a fixed retention period, not to automate storage class transitions or scheduled deletions. Option C is wrong because S3 Replication asynchronously copies objects to another bucket for redundancy or compliance, but it does not manage lifecycle transitions or deletion schedules. Option D is wrong because S3 Event Notifications trigger actions (e.g., Lambda, SQS) on object events like PUT or DELETE, but they cannot enforce time-based transitions to Glacier or automatic deletion after a set number of days.

1026
MCQhard

An organization uses AWS CodeBuild to run tests for a Node.js application. The build environment is Linux. The buildspec.yml includes a pre_build phase that runs 'npm install'. Occasionally, the build fails with an error 'npm ERR! code EINTEGRITY'. The developer wants to resolve this issue without compromising security. Which action should be taken?

A.Create a separate CodeBuild project to run npm install.
B.Add 'npm cache verify' to the pre_build phase before 'npm install'.
C.Add 'npm config set registry http://registry.npmjs.org/' to use HTTP.
D.Use 'npm install --prefer-offline' to avoid fetching from registry.
AnswerB

Adding 'npm cache verify' to the `pre_build` phase before 'npm install' is the correct solution because it directly addresses the cause of an 'EINTEGRITY' error. This command systematically checks the integrity of all cached packages, identifying and repairing any corrupted or incomplete entries. By ensuring the npm cache is clean and valid, subsequent 'npm install' commands will operate with correct package data, resolving the integrity mismatch without compromising security or requiring a full cache clear.

Why this answer

The EINTEGRITY error occurs when npm's local cache contains corrupted or mismatched package data, causing integrity checks to fail. Running 'npm cache verify' in the pre_build phase validates the cache, removes corrupted entries, and garbage collects unnecessary data, ensuring subsequent 'npm install' operations use a clean cache. This resolves the issue without disabling security features like integrity checking or switching to insecure HTTP.

Exam trap

DVA-C02 often tests the misconception that EINTEGRITY errors are network-related and can be fixed by changing registry protocols or offline flags, when the actual cause is local cache corruption.

How to eliminate wrong answers

Option A is wrong because creating a separate CodeBuild project does not address the root cause—cache corruption—and adds unnecessary complexity. Option C is wrong because switching to HTTP disables TLS encryption, compromising security and violating best practices; the error is not caused by HTTPS. Option D is wrong because '--prefer-offline' still uses the corrupted cache and may fail integrity checks; it does not repair the cache and could mask the issue while potentially using stale packages.

1027
MCQmedium

A team uses AWS Elastic Beanstalk to deploy a web application. The application experiences intermittent high latency. The team notices that the environment's Auto Scaling group is not scaling out quickly enough. Which configuration change should the team make to improve scaling responsiveness?

A.Modify the Elastic Load Balancer health check path to a lighter endpoint
B.Enable detailed CloudWatch metrics for the Auto Scaling group
C.Increase the instance type to a larger size
D.Decrease the Auto Scaling group's cooldown period
AnswerD

Decreasing the Auto Scaling group's cooldown period directly impacts how quickly the group can initiate subsequent scaling activities after a previous one has completed. The cooldown period is a configurable setting designed to prevent rapid, oscillating scaling actions by pausing further scaling for a specified duration. A shorter cooldown allows the Auto Scaling group to respond to persistent or rapidly changing load conditions more promptly, enabling faster scale-out or scale-in operations.

Why this answer

Decreasing the Auto Scaling group's cooldown period reduces the time that the group waits after a scaling activity before it can launch another instance, thereby improving scaling responsiveness. Option A is incorrect because a lighter health check path does not affect scaling speed—it only affects how quickly unhealthy instances are detected. Option B is incorrect; while detailed CloudWatch metrics provide more granular data, they do not directly reduce the cooldown period.

Option C is incorrect because increasing instance size improves per-instance capacity but does not change how quickly the group scales out.

1028
MCQmedium

A developer is creating a Lambda function that requires access to a DynamoDB table. The function will be invoked by an Amazon API Gateway REST API. What is the BEST way to secure this architecture?

A.Create an IAM role for the Lambda function with a policy granting access to the DynamoDB table.
B.Attach a resource-based policy to the DynamoDB table allowing Lambda access.
C.Use API Gateway to pass a shared secret to Lambda for DynamoDB access.
D.Store the DynamoDB access keys in the Lambda environment variables.
AnswerA

Creating an IAM role for the Lambda function is the standard and most secure method for granting AWS service permissions. This role provides temporary, automatically rotated credentials to the Lambda execution environment, allowing it to assume the specified permissions. By attaching an identity-based policy that grants specific `dynamodb:` actions on the target table, the Lambda function adheres to the principle of least privilege, accessing only what it needs.

Why this answer

The Lambda function needs an execution role—an IAM role that Lambda assumes at runtime—with a policy that grants the specific DynamoDB actions (e.g., GetItem, PutItem) on the target table. This follows the principle of least privilege and is the standard AWS pattern for granting Lambda access to AWS resources. API Gateway invokes the Lambda function via a resource-based policy on the function itself, but that does not affect DynamoDB access; the Lambda execution role handles all downstream permissions.

Exam trap

The trap here is that candidates confuse resource-based policies (used for granting invocation permissions to other AWS accounts or services) with execution roles (used for granting the Lambda function permissions to access other AWS resources), leading them to incorrectly choose Option B or think Option C is a valid authentication method.

How to eliminate wrong answers

Option B is wrong because resource-based policies on DynamoDB tables are not supported; DynamoDB uses IAM policies attached to users, roles, or the table's own resource policy (only for cross-account access via VPC endpoints or AWS Organizations), not for granting access to a Lambda function in the same account. Option C is wrong because passing a shared secret via API Gateway to Lambda for DynamoDB access is insecure and unnecessary; secrets should never be passed through API Gateway payloads, and AWS recommends using IAM roles for service-to-service authentication. Option D is wrong because storing DynamoDB access keys (long-term credentials) in Lambda environment variables violates security best practices—they can be exposed in logs, console, or version history—and AWS strongly recommends using IAM roles with temporary credentials instead.

1029
MCQmedium

A company uses AWS OpsWorks for configuration management. They have a stack with multiple layers. They want to deploy a new application version to the application layer using rolling updates. What is the correct way to achieve this?

A.Update the custom cookbook and run the 'setup' command on the layer.
B.Clone the stack and then delete the old stack.
C.Update the app with the new version and run the 'deploy' command on the stack.
D.Modify the Auto Scaling group to launch new instances with the updated app.
AnswerC

The correct procedure involves updating the application definition within the AWS OpsWorks stack to point to the new version's source, such as a new Git commit or S3 object. Subsequently, executing the 'deploy' command on the stack or a specific layer triggers the 'deploy' lifecycle event across all instances. This command instructs OpsWorks to pull the updated application code and run the associated deployment recipes, ensuring the new version is installed and services are restarted as configured.

Why this answer

In AWS OpsWorks, deploying a new application version to a layer is done by updating the app configuration with the new version and then running the 'deploy' command on the stack. This command triggers the built-in Chef deploy recipes on the layer's instances, performing a rolling update that installs the new application version while minimizing downtime. The 'deploy' lifecycle event is specifically designed for application deployment, unlike 'setup' which configures the instance's initial state.

Exam trap

The trap here is confusing the 'setup' lifecycle event (used for initial configuration) with the 'deploy' lifecycle event (used for application deployment), leading candidates to incorrectly choose Option A instead of C.

How to eliminate wrong answers

Option A is wrong because the 'setup' command runs the setup lifecycle event, which configures the instance's packages, dependencies, and custom cookbooks, but it does not deploy application code; deploying a new app version requires the 'deploy' command. Option B is wrong because cloning the stack and deleting the old stack is an unnecessarily disruptive and manual process that does not achieve a rolling update; OpsWorks supports in-place rolling updates via the 'deploy' command without stack recreation. Option D is wrong because modifying the Auto Scaling group to launch new instances with an updated app bypasses OpsWorks's deployment lifecycle and does not perform a controlled rolling update; it would replace instances without the orchestrated 'deploy' recipes that handle application-specific tasks like database migrations or cache clearing.

1030
MCQeasy

A developer is creating an AWS Lambda function that needs to access files from an Amazon EFS file system. The Lambda function must be configured to access the VPC. Which of the following is required to allow the Lambda function to mount the EFS file system?

A.The Lambda function must have the AWSLambdaVPCAccessExecutionRole managed policy attached.
B.The Lambda function must be in the same Availability Zone as the EFS mount target.
C.The Lambda function must have the AmazonElasticFileSystemClientReadWriteAccess managed policy attached.
D.The Lambda function must have the efs:MountFileSystem permission in its execution role.
AnswerA

The AWSLambdaVPCAccessExecutionRole managed policy is essential because it grants the necessary IAM permissions for Lambda to create, describe, and delete Elastic Network Interfaces (ENIs) within the specified VPC subnets. When a Lambda function is configured to access resources in a VPC, AWS Lambda provisions these ENIs to establish network connectivity, allowing the function to communicate with private resources like EFS file systems. Without these permissions, Lambda cannot integrate into the VPC and therefore cannot reach EFS.

Why this answer

The AWSLambdaVPCAccessExecutionRole managed policy provides the necessary permissions for Lambda to manage elastic network interfaces (ENIs) in a VPC, which is required for Lambda to connect to an EFS file system via mount targets. Without this policy, the Lambda function cannot create or manage the ENI needed to route traffic to the EFS mount target within the VPC.

Exam trap

The trap here is that candidates confuse the VPC networking permissions required for Lambda to mount EFS (AWSLambdaVPCAccessExecutionRole) with EFS-specific API permissions (AmazonElasticFileSystemClientReadWriteAccess) or a nonexistent efs:MountFileSystem action, leading them to select the wrong policy or permission.

How to eliminate wrong answers

Option B is wrong because Lambda can access EFS mount targets in any Availability Zone within the same VPC; it does not need to be in the same AZ as the mount target, as Lambda uses ENIs in the VPC subnets to reach the mount target across AZs. Option C is wrong because the AmazonElasticFileSystemClientReadWriteAccess policy grants permissions to EFS API operations (e.g., CreateFileSystem, DescribeMountTargets) but does not include the specific efs:MountFileSystem permission or the VPC networking permissions required for Lambda to mount the file system. Option D is wrong because the efs:MountFileSystem permission is not a valid IAM action; EFS mounting is controlled by network connectivity (VPC configuration) and the execution role must include permissions for EC2 ENI management (ec2:CreateNetworkInterface, etc.), not a direct EFS mount action.

1031
MCQmedium

A developer is configuring an S3 bucket to host a static website. The bucket policy allows public read access. However, users receive a 403 Forbidden error when accessing the website. What is the most likely cause?

A.The bucket is located in a different AWS region than the website endpoint.
B.The bucket name does not match the domain name.
C.The bucket has 'Block all public access' settings enabled.
D.The bucket is not configured with CloudFront as a content delivery network.
AnswerC

The S3 Block Public Access settings are a powerful security control that overrides any bucket policies or access control lists (ACLs) that might otherwise grant public read access. When 'Block all public access' is enabled, it explicitly prevents anonymous users from accessing objects within the bucket, including static website content. For a static website to be publicly accessible, these settings must be disabled, specifically the 'Block public and cross-account access to buckets and objects' option, allowing the bucket policy to grant public read permissions.

Why this answer

The 'Block all public access' settings in the S3 bucket's Permissions tab override any bucket policy that grants public read access. Even if the bucket policy explicitly allows s3:GetObject for Principal "*", enabling any of the four block public access settings (especially 'Block public access to buckets and objects granted through new public bucket policies' or 'Block public and cross-account access to buckets and objects through any public bucket policies') will cause S3 to reject all anonymous requests, resulting in a 403 Forbidden error when accessing the static website endpoint.

Exam trap

The trap here is that candidates assume a bucket policy granting public read access is sufficient for static website hosting, overlooking that S3's Block Public Access settings act as a separate, overriding permission layer that can silently deny all public access even when the bucket policy is correctly configured.

How to eliminate wrong answers

Option A is wrong because S3 static website hosting endpoints are region-specific (e.g., http://bucket-name.s3-website-us-east-1.amazonaws.com), but the bucket's region does not affect access permissions; a 403 Forbidden error is an authorization issue, not a routing issue. Option B is wrong because while a bucket name must match the domain name for custom domain mapping (e.g., via Route 53), the 403 Forbidden error occurs regardless of domain name mismatch; a mismatch would cause a DNS resolution failure or a different error (e.g., 404 NoSuchBucket), not a 403. Option D is wrong because CloudFront is not required for S3 static website hosting; S3 can serve content directly via its website endpoint, and the absence of CloudFront does not cause a 403 Forbidden error—it would only affect performance, caching, or HTTPS support if not configured.

1032
MCQeasy

A company stores sensitive user data in an S3 bucket. The security team requires that all data be encrypted at rest using a customer-managed KMS key. The bucket already has default encryption configured with SSE-S3. What is the MINIMUM change needed to meet the requirement?

A.Change the default encryption of the bucket to SSE-KMS with the desired KMS key.
B.Add an object-level encryption setting to each object after upload.
C.Enable S3 Bucket Keys on the bucket.
D.Attach a bucket policy that denies uploads without the required KMS key.
AnswerA

Changing the S3 bucket's default encryption to SSE-KMS with a specified AWS KMS key ensures that all new objects uploaded to the bucket are automatically encrypted at rest using that customer-managed key. This eliminates the need for individual uploaders to specify encryption headers, significantly reducing the risk of unencrypted data and simplifying compliance requirements for sensitive user data. It's the most robust and operationally efficient method to enforce encryption for all objects.

Why this answer

The current bucket has default encryption set to SSE-S3, which uses AWS-managed keys, not customer-managed KMS keys. Changing the default encryption to SSE-KMS with the desired customer-managed KMS key ensures that all new objects uploaded to the bucket are automatically encrypted at rest using that key, meeting the security team's requirement without additional per-object configuration.

Exam trap

The trap here is that candidates often confuse enforcing encryption via bucket policies (which only denies non-compliant uploads) with actually setting the encryption method via default encryption, which automatically applies the required encryption to all objects.

How to eliminate wrong answers

Option B is wrong because adding object-level encryption settings after upload does not enforce encryption at rest for all objects; it requires manual intervention and does not change the default encryption behavior for future uploads. Option C is wrong because enabling S3 Bucket Keys reduces the number of KMS API calls for SSE-KMS but does not change the encryption type from SSE-S3 to SSE-KMS; it is an optimization feature, not a method to enforce customer-managed KMS encryption. Option D is wrong because a bucket policy that denies uploads without the required KMS key can enforce encryption requirements but does not change the default encryption configuration; it would still allow objects encrypted with SSE-S3 if the policy is not correctly crafted, and it does not automatically encrypt objects—it only denies unencrypted uploads, which is not the same as ensuring all data is encrypted at rest with the specified KMS key.

1033
MCQhard

A company is using Amazon API Gateway to expose a set of RESTful APIs. Each API call is processed by an AWS Lambda function. The company wants to enforce throttling limits to prevent abuse. Specifically, the company wants to allow 100 requests per second per API key. What is the SIMPLEST way to achieve this?

A.Use AWS WAF to block requests after 100 per second.
B.Set a reserved concurrency on the Lambda function to 100.
C.Configure a CloudWatch alarm to disable the API key after exceeding the limit.
D.Create a usage plan in API Gateway with a rate limit of 100 requests per second per API key.
AnswerD

API Gateway usage plans are specifically designed to control access to API stages and methods by defining throttling and quota limits for individual API keys. By associating an API key with a usage plan, you can enforce precise rate limits, such as 100 requests per second, and burst limits on a per-consumer basis. This provides real-time, fine-grained control over API consumption, ensuring fair usage and protecting backend resources.

Why this answer

API Gateway usage plans are specifically designed to enforce throttling limits per API key. By creating a usage plan with a rate limit of 100 requests per second and associating it with the desired API keys, you can directly control request rates at the API Gateway layer without additional services or custom logic. This is the simplest and most native approach for per-API-key throttling.

Exam trap

The trap here is that candidates may confuse reserved concurrency (which limits Lambda execution concurrency) with API-level rate limiting, or assume that a reactive solution like CloudWatch alarms can enforce proactive throttling, when in fact API Gateway usage plans provide the simplest and most direct mechanism for per-API-key rate control.

How to eliminate wrong answers

Option A is wrong because AWS WAF is a web application firewall that filters traffic based on rules (e.g., IP sets, SQL injection), but it does not natively support per-API-key rate limiting; implementing such a limit would require custom logic and is not the simplest solution. Option B is wrong because reserved concurrency on a Lambda function limits the number of concurrent executions, not the request rate per second per API key; it also applies globally to the function, not per API key, and does not prevent abuse at the API Gateway level. Option C is wrong because a CloudWatch alarm can only trigger actions (e.g., disable an API key) after the limit is exceeded, but it cannot enforce a hard throttle in real time; the alarm would react after the fact, allowing bursts beyond 100 requests per second before any action is taken.

1034
MCQhard

A developer is using AWS CodeDeploy with a blue/green deployment strategy to update an application running on Amazon ECS with the Fargate launch type. After the new (green) task set is created and traffic is shifted to it, users immediately report errors when trying to write data. The developer discovers that the green task set is connecting to a different database than the blue task set. The database endpoints are configured in the ECS task definition. What is the simplest way to prevent this issue in future deployments?

A.Modify the blue/green deployment configuration to use the same database endpoint for both task sets by updating the environment variables in the task definition before deployment.
B.Create two separate Amazon RDS databases and use an Amazon Route 53 weighted routing policy to distribute traffic.
C.Use an Application Load Balancer (ALB) with stickiness to route each user to the correct task set.
D.Use AWS CloudFormation to create a new database stack for each deployment and update the task definition dynamically.
AnswerA

During an AWS CodeDeploy blue/green deployment, both the existing (blue) and new (green) application versions must access the same persistent data store to maintain data consistency. By updating environment variables within the ECS task definition, such as `DATABASE_ENDPOINT`, before deployment, both task sets can be configured to point to the single, shared database instance. This approach avoids data migration complexities and ensures a seamless transition without modifying the container image itself, making it the most straightforward and efficient solution for database connectivity.

Why this answer

The issue stems from the green task set using a different database endpoint than the blue task set, which is configured via environment variables in the ECS task definition. By updating the task definition to use the same database endpoint before deployment, both task sets will connect to the same database, ensuring consistency during the traffic shift. This is the simplest fix as it requires no additional infrastructure or complex routing changes.

Exam trap

The trap here is that candidates may think the issue is about traffic routing or session persistence (options B or C), rather than recognizing that the root cause is a configuration mismatch in the task definition environment variables, which is a common oversight in blue/green deployments.

How to eliminate wrong answers

Option B is wrong because creating two separate RDS databases and using Route 53 weighted routing would introduce data inconsistency and complexity, as users would write to different databases, defeating the purpose of a single application state. Option C is wrong because using an ALB with stickiness would route users to either the blue or green task set based on session affinity, but it does not address the root cause of different database endpoints; the task sets would still connect to different databases, causing data fragmentation. Option D is wrong because using CloudFormation to create a new database stack for each deployment is overly complex and unnecessary; it would require managing multiple databases and updating the task definition dynamically, which is not the simplest solution and could lead to data loss or inconsistency.

1035
MCQmedium

A company wants to build a RESTful API that handles file uploads. The API needs to support multipart/form-data content type. The developer is using Amazon API Gateway and AWS Lambda. Which approach should the developer use to handle file uploads efficiently?

A.Configure API Gateway to pass the entire request body to Lambda, and process the file within the Lambda function.
B.Create a Lambda function that accepts the file and uploads it to S3 using the AWS SDK.
C.Use API Gateway to generate a presigned S3 URL, and have the client upload directly to S3. The Lambda function can then process the file asynchronously.
D.Use an EC2 instance to host a custom web server that accepts file uploads and writes to S3.
AnswerC

This is the recommended serverless pattern for large file uploads. API Gateway can authenticate the request and then generate a temporary, time-limited presigned URL for S3. The client then uses this URL to upload the file directly to S3, bypassing API Gateway and Lambda payload limits entirely. S3 can then asynchronously trigger a Lambda function (e.g., via S3 event notifications) to process the uploaded file, ensuring scalability and efficiency.

Why this answer

It offloads the file upload to Amazon S3 directly via a presigned URL, which avoids the 10 MB payload limit and 29-second timeout of API Gateway and Lambda for large files. The client uploads the file to S3, and a separate Lambda function processes the file asynchronously, making the solution efficient and scalable for multipart/form-data uploads.

Exam trap

The trap here is that candidates assume Lambda can handle file uploads directly via API Gateway, overlooking the 10 MB payload limit and 29-second timeout, and fail to recognize the presigned URL pattern as the efficient serverless solution for large multipart/form-data uploads.

How to eliminate wrong answers

Option A is wrong because API Gateway has a 10 MB payload limit and a 29-second integration timeout, making it unsuitable for large file uploads; passing the entire request body to Lambda also forces the function to handle raw multipart parsing, which is inefficient and error-prone. Option B is wrong because it still requires the client to send the file through API Gateway and Lambda, hitting the same size and timeout constraints; the Lambda function would need to receive the entire file payload before uploading to S3, defeating the purpose of direct upload. Option D is wrong because it introduces unnecessary infrastructure management (EC2) and does not leverage serverless benefits; it also does not address the requirement to use API Gateway and Lambda, and a custom web server on EC2 adds operational overhead without improving efficiency.

1036
MCQmedium

A developer is building a microservices application composed of multiple AWS Lambda functions and an Amazon API Gateway. The developer needs to trace requests as they travel through different services to identify performance bottlenecks. Which AWS service should the developer integrate?

A.AWS CloudTrail
B.Amazon CloudWatch Logs
C.AWS X-Ray
D.Amazon Inspector
AnswerC

AWS X-Ray is purpose-built for distributed tracing, providing an end-to-end view of requests as they travel through your microservices application. It collects data about requests, generates a service map visualizing application components and their interconnections, and allows developers to identify performance bottlenecks, errors, and latency issues within individual services or across the entire request path. X-Ray's ability to trace requests across multiple services makes it invaluable for debugging and optimizing complex distributed systems.

Why this answer

AWS X-Ray is the correct service because it provides end-to-end tracing of requests as they travel through distributed applications, including AWS Lambda functions and API Gateway. It generates a service map that shows the flow of requests, latency breakdowns, and identifies performance bottlenecks across microservices. X-Ray integrates directly with Lambda and API Gateway via the X-Ray SDK and tracing headers, enabling trace propagation without code changes.

Exam trap

The trap here is that candidates confuse CloudWatch Logs (which shows logs) with distributed tracing (which correlates requests across services), leading them to pick CloudWatch Logs instead of X-Ray for end-to-end performance analysis.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API calls for auditing and governance, not for tracing individual request paths or performance bottlenecks across microservices. Option B is wrong because Amazon CloudWatch Logs aggregates log data but does not provide distributed tracing or service maps to correlate requests across multiple Lambda functions and API Gateway. Option D is wrong because Amazon Inspector is a vulnerability management service that scans for software vulnerabilities and network exposure, not for tracing application requests or performance analysis.

1037
MCQmedium

A company uses Amazon API Gateway to expose a REST API. The API uses a Lambda authorizer to validate JWT tokens. Recently, the API has been returning 401 Unauthorized errors for valid tokens. The developer notices that the tokens are signed with a new key but the authorizer still uses the old key. What is the MOST efficient way to update the authorizer with the new key?

A.Modify the Lambda authorizer to fetch the public key from a well-known URL at runtime.
B.Update the API Gateway stage deployment to redeploy the API.
C.Delete and recreate the API Gateway authorizer with the new key.
D.Update the Lambda authorizer's environment variable with the new key and publish a new version.
AnswerA

Modifying the Lambda authorizer to fetch the public key from a well-known URL at runtime is the most robust solution. This approach leverages standard identity provider practices where public keys (often in JWKS format) are exposed at a predictable endpoint (e.g., `/.well-known/jwks.json`). The Lambda function can programmatically retrieve and cache these keys, ensuring it always uses the latest valid key for JWT signature verification without requiring any redeployment of the Lambda function or API Gateway when the key rotates. This significantly reduces operational overhead and enhances security by enabling seamless key rotation.

Why this answer

Fetching the public key from a well-known URL (e.g., the JWKS endpoint) at runtime allows the Lambda authorizer to automatically use the latest signing key without manual intervention. This approach decouples key rotation from the authorizer code, ensuring that valid tokens signed with the new key are accepted immediately. It is the most efficient method as it avoids redeployments, environment variable updates, or recreating the authorizer.

Exam trap

The trap here is that candidates assume updating environment variables or redeploying the API is sufficient, but they overlook that the authorizer must dynamically resolve the signing key to handle automatic key rotation without manual steps.

How to eliminate wrong answers

Option B is wrong because redeploying the API Gateway stage does not update the signing key used by the Lambda authorizer; it only deploys the current API configuration. Option C is wrong because deleting and recreating the authorizer is unnecessary and inefficient; the authorizer can be updated programmatically or by modifying its logic. Option D is wrong because updating an environment variable and publishing a new Lambda version still requires manual key rotation and does not address the root cause of dynamic key changes; the authorizer would still need to be updated each time the key changes.

1038
MCQhard

A developer ran the above CLI command to describe an EC2 instance. The instance is running but the developer cannot connect to it via SSH. Which additional step should the developer take to troubleshoot the connectivity issue?

A.Check the AMI ID to ensure it is a valid Linux AMI
B.Check the instance's network interfaces for a public IP
C.Check the instance status checks in the EC2 console
D.Check the security group rules associated with the instance
AnswerD

Security groups function as stateful virtual firewalls that control inbound and outbound traffic for an EC2 instance. For SSH connectivity, an inbound rule must explicitly permit TCP traffic on port 22 from the source IP address range (e.g., `0.0.0.0/0` for anywhere, or a specific IP) to the instance. If no such rule exists, or if the source IP is not allowed, the connection attempt will be silently dropped at the security group level, preventing SSH from establishing.

Why this answer

Security group rules control inbound traffic to the instance. If the security group does not allow SSH (port 22) from the developer's IP, the connection will fail even if the instance is running and has a public IP. The describe-instances command output includes security group names and IDs, allowing the developer to verify the rules.

Option A is wrong because a valid AMI does not guarantee network connectivity. Option B is wrong because the instance may have a public IP but still be unreachable if the security group blocks SSH. Option C is wrong because instance status checks indicate the OS and instance health, not network-level access.

1039
Multi-Selecteasy

A developer is deploying a serverless application using AWS SAM. The application includes multiple Lambda functions and an API Gateway. Which THREE AWS CLI commands are part of the typical SAM deployment workflow? (Choose THREE.)

Select 3 answers
A.sam deploy
B.sam init
C.sam package
D.sam build
E.aws s3 cp
AnswersA, C, D

The sam deploy command is the final and most comprehensive step in the AWS SAM CLI workflow for deploying a serverless application. It takes the built and packaged artifacts, along with the transformed SAM template, and uses AWS CloudFormation to create or update the necessary AWS resources, such as Lambda functions, API Gateway endpoints, and DynamoDB tables, in the specified AWS account and region. This command orchestrates the entire resource provisioning and update process.

Why this answer

`sam deploy` is the AWS SAM CLI command that deploys the packaged application to AWS, creating or updating the CloudFormation stack with the Lambda functions and API Gateway resources. It reads the `template.yaml` and the packaged artifacts (from `sam package`) to provision the infrastructure. This command is the final step in the standard SAM deployment workflow.

Exam trap

The trap here is that candidates confuse `sam init` (a project scaffolding command) with a deployment step, or mistakenly think `aws s3 cp` is part of the SAM workflow when in fact SAM provides its own `sam package` command to handle S3 uploads and template transformation.

1040
Multi-Selectmedium

Which TWO actions are recommended to secure an S3 bucket? (Choose 2)

Select 2 answers
A.Block public access at the bucket level
B.Disable versioning to reduce complexity
C.Use HTTP instead of HTTPS for faster access
D.Enable default encryption
E.Grant public read access via ACLs
AnswersA, D

Blocking public access at the bucket level is a key security control that prevents all public access, even if a bucket policy or ACL explicitly grants it. This setting overrides any permissive configuration and acts as a safety net against accidental data leaks, making it a mandatory part of AWS S3 security best practices. By enforcing this at the bucket level, you eliminate the risk of objects being inadvertently exposed to the internet.

Why this answer

Option A is correct because enabling S3 Block Public Access at the bucket level overrides any bucket policy or ACL that would otherwise grant public access, preventing accidental exposure of objects. Option D is correct because enabling default encryption (SSE-S3, SSE-KMS, or SSE-C) ensures all objects are encrypted at rest automatically, protecting data even if storage media is compromised. Option B is wrong because disabling versioning reduces recoverability from accidental deletes or overwrites and is not a security best practice.

Option C is wrong because HTTP transmits data in plaintext; HTTPS (TLS) should always be used to protect data in transit. Option E is wrong because granting public read access via ACLs exposes objects to anyone on the internet, directly undermining bucket security.

Exam trap

DVA-C02 often tests whether candidates confuse 'security best practice' with 'operational convenience' — options like disabling versioning or using HTTP sound simpler but are anti-patterns, and the exam expects you to reject them immediately.

1041
Multi-Selectmedium

A company is using AWS Elastic Beanstalk to deploy a web application. The application uses an Amazon RDS MySQL database. The development team wants to ensure that database credentials are not exposed in the application code. Which THREE actions should the team take to securely manage and retrieve database credentials? (Choose three.)

Select 3 answers
A.Store the credentials in an S3 bucket with a bucket policy that restricts access to the application.
B.Configure Elastic Beanstalk to pass the secret ARN to the application as an environment property.
C.Modify the application code to retrieve the credentials from Secrets Manager at startup.
D.Hardcode the credentials in the application code and use environment variables to override them.
E.Store the database credentials in AWS Secrets Manager.
AnswersB, C, E

Passing the secret ARN as an environment property in Elastic Beanstalk is a secure pattern because the actual credential value is never embedded in code or environment configuration. The application retrieves the secret from AWS Secrets Manager at runtime using the ARN, while the Elastic Beanstalk instance profile supplies the necessary IAM permissions. This keeps the secret itself hidden and ensures the application always uses the current value, even if the secret is rotated.

Why this answer

Option E is correct because AWS Secrets Manager is the purpose-built service for storing and rotating sensitive data such as RDS MySQL credentials, keeping them out of source code and enabling fine-grained IAM access control. Option B is correct because passing the secret ARN (not the secret value) as an Elastic Beanstalk environment property lets the application know which secret to fetch without embedding credentials in code or configuration files. Option C is correct because the application must call the Secrets Manager API (e.g., GetSecretValue) at startup to retrieve the credentials dynamically, which completes the secure retrieval workflow.

Option A is not appropriate because S3 is object storage, not a secrets management service, and a bucket policy alone does not provide the encryption, rotation, and audit controls of Secrets Manager. Option D is wrong because hardcoding credentials in application code is exactly the insecure practice the team is trying to eliminate, and environment variable overrides do not remove the exposed secrets from the codebase.

Exam trap

DVA-C02 often tests whether candidates know that S3 is not a secrets store and that hardcoding credentials — even with environment variable overrides — still violates secure coding practices.

1042
MCQmedium

A company runs a Node.js application on AWS Elastic Beanstalk. The application experiences high latency during peak hours. The developer suspects that the environment's EC2 instances are under-provisioned. Which configuration change would MOST effectively address the latency issue with minimal cost increase?

A.Place the environment behind an Application Load Balancer.
B.Enable Auto Scaling and configure scaling triggers based on CPU utilization.
C.Change the instance type to a larger size in the environment configuration.
D.Decrease the minimum number of instances in the Auto Scaling group.
AnswerB

Enabling Auto Scaling and configuring scaling triggers based on CPU utilization is the most effective and elastic solution for handling variable loads in a Node.js application. When the average CPU utilization across the Auto Scaling group exceeds a predefined threshold, new EC2 instances are automatically launched to distribute the workload, improving responsiveness and preventing performance degradation. Conversely, instances are terminated during periods of low utilization, optimizing operational costs.

Why this answer

Enabling Auto Scaling with CPU utilization triggers dynamically adds EC2 instances during peak hours, distributing the load and reducing latency without over-provisioning during off-peak times. This matches the symptom of under-provisioned instances and minimizes cost by scaling only when needed, unlike static solutions that waste resources.

Exam trap

The trap here is that candidates often confuse adding a load balancer (Option A) with solving capacity issues, but a load balancer only distributes traffic and does not increase compute resources, so latency remains if instances are saturated.

How to eliminate wrong answers

Option A is wrong because placing the environment behind an Application Load Balancer (ALB) alone does not address under-provisioned instances; an ALB distributes traffic but does not add compute capacity, so latency persists if instances are overloaded. Option C is wrong because changing to a larger instance type increases cost for all hours, including low-traffic periods, and does not dynamically adapt to peak demand, making it less cost-effective than Auto Scaling. Option D is wrong because decreasing the minimum number of instances reduces the baseline capacity, worsening latency during both peak and normal loads, as fewer instances handle the same traffic.

1043
MCQhard

A developer is deploying a serverless application using AWS SAM. The application consists of multiple Lambda functions and an API Gateway REST API. The developer needs to ensure that the API Gateway endpoint is created before the Lambda functions are deployed, because the functions need the endpoint URL as an environment variable. How should the developer configure the SAM template?

A.Separate the deployment into two stacks: first deploy API Gateway, then deploy Lambda functions
B.Add a DependsOn clause to each Lambda function resource to wait for the API Gateway resource
C.Define the Lambda functions to use the ServerlessRestApi implicit API and reference the API's output in the function's environment variables
D.Use a custom resource in CloudFormation to create the API Gateway endpoint before Lambda functions
AnswerC

Defining Lambda functions to use the `ServerlessRestApi` implicit API within the AWS Serverless Application Model (SAM) template is the recommended and most efficient approach. SAM automatically provisions and configures the API Gateway and integrates it with the Lambda functions, establishing all necessary permissions and dependencies. Referencing the API's output, such as its endpoint URL, in the function's environment variables provides a clean and dynamic way for the Lambda function to interact with its associated API at runtime, ensuring correct configuration.

Why this answer

AWS SAM automatically creates an implicit API Gateway REST API (logical ID `ServerlessRestApi`) when you define an `AWS::Serverless::Api` or use the `Events` property on a function. You can reference its endpoint URL using the `Fn::Sub` intrinsic function with the `ServerlessRestApi` logical ID, such as `!Sub 'https://${ServerlessRestApi}.execute-api.${AWS::Region}.amazonaws.com/${Stage}'`. This ensures the API Gateway resource is created before the Lambda functions that reference it, as CloudFormation resolves dependencies through intrinsic function references.

Exam trap

The trap here is that candidates may think `DependsOn` is sufficient to pass the endpoint URL, but it only orders creation and does not inject the URL into environment variables, which requires an intrinsic function reference like `Fn::Sub` or `Fn::GetAtt`.

How to eliminate wrong answers

Option A is wrong because separating into two stacks introduces unnecessary complexity and cross-stack output references, which is not required when SAM can handle the dependency within a single stack. Option B is wrong because `DependsOn` only ensures resource creation order but does not provide the endpoint URL as an environment variable; the developer still needs to reference the API Gateway output, and `DependsOn` alone does not pass the URL. Option D is wrong because using a custom resource to create the API Gateway endpoint is over-engineered and redundant; SAM already provides a built-in implicit API resource that handles creation and dependency resolution automatically.

1044
MCQeasy

Refer to the exhibit. A developer attached this bucket policy to an S3 bucket. Users from the 192.0.2.0/24 network can access objects, but users from a different network (203.0.113.0/24) get access denied. What change should be made to allow both networks?

A.Add a new statement with a different Principal.
B.Change the Condition to aws:SourceIp: "203.0.113.0/24".
C.Remove the Condition block entirely.
D.Change the Condition to use a list of IP ranges: ["192.0.2.0/24", "203.0.113.0/24"].
AnswerD

AWS IAM policies support specifying multiple values for a single condition key by using a JSON array. When aws:SourceIp is assigned a list like ["192.0.2.0/24", "203.0.113.0/24"], the condition evaluates to true if the request originates from *any* of the IP ranges within that list. This correctly allows access from both the 192.0.2.0/24 and 203.0.113.0/24 networks, fulfilling the requirement in a single, concise policy statement.

Why this answer

The `aws:SourceIp` condition key accepts a list of IP ranges in an array format. By specifying both `192.0.2.0/24` and `203.0.113.0/24` in the condition, the bucket policy will grant access to requests originating from either network, resolving the access denied error for the second network.

Exam trap

The trap here is that candidates mistakenly think the `aws:SourceIp` condition key can only hold a single value, leading them to choose Option B, when in fact it accepts a list of IP ranges to allow multiple networks.

How to eliminate wrong answers

Option A is wrong because the `Principal` element in an S3 bucket policy specifies the AWS account or IAM entity allowed to access the bucket, not the network IP range; adding a different Principal would not fix the IP-based restriction. Option B is wrong because changing the condition to only `203.0.113.0/24` would deny access to the original `192.0.2.0/24` network, simply swapping which network is blocked. Option C is wrong because removing the `Condition` block entirely would allow all IP addresses to access the bucket, which is overly permissive and violates the principle of least privilege.

1045
MCQmedium

A company is using an Application Load Balancer (ALB) to route traffic to a set of EC2 instances. The security team wants to ensure that only traffic from the ALB can reach the instances. Which security group configuration should be used?

A.Configure the EC2 instance security group to allow traffic from the ALB's private IP address range.
B.Configure the network ACL for the EC2 instance subnet to allow traffic from the ALB security group.
C.Configure the EC2 instance security group to allow traffic from the ALB security group.
D.Configure the EC2 instance security group to allow HTTP traffic from 0.0.0.0/0.
AnswerC

Configuring the EC2 instance security group to allow traffic from the ALB security group is the correct and most robust solution. By referencing the ALB's security group ID as the source in the EC2 instance's inbound rules, you dynamically permit traffic only from the network interfaces associated with that specific ALB. This ensures secure communication, automatically adapts to ALB scaling or underlying IP address changes, and adheres to the principle of least privilege by restricting access solely to the load balancer.

Why this answer

Option C is correct because security groups can reference other security groups as a source, so the EC2 instances' security group can allow inbound traffic specifically from the ALB's security group, ensuring only ALB-forwarded traffic reaches the instances. This approach is the AWS-recommended pattern and works regardless of the ALB's changing IP addresses. Option A is wrong because ALB IP addresses are dynamic and not a stable, manageable source.

Option B is wrong because network ACLs cannot reference security groups as a source; they only support CIDR-based rules. Option D is wrong because allowing HTTP from 0.0.0.0/0 exposes the instances to the entire internet, not just the ALB.

1046
MCQmedium

A developer is using Amazon API Gateway to expose a REST API. The API needs to validate request parameters and payload before invoking the backend Lambda function. What is the MOST efficient way to perform this validation?

A.Use API Gateway request validation with a model schema.
B.Validate the request in the Lambda function and return errors if validation fails.
C.Use Amazon CloudFront to validate the request at the edge.
D.Use API Gateway request parameters to enforce required headers.
AnswerA

API Gateway's request validation leverages JSON Schema Draft 4 models to define the expected structure and data types for request bodies, headers, and query parameters. By configuring a validator for a method, API Gateway automatically inspects incoming requests against the defined schema. This pre-processing rejects malformed requests before they reach the backend, significantly reducing unnecessary Lambda invocations, saving costs, and improving API responsiveness.

Why this answer

API Gateway's built-in request validation allows you to define a JSON Schema model that automatically validates request parameters, headers, and payload before the request reaches the backend Lambda function. This offloads validation from the Lambda function, reducing compute time and cost, and provides immediate 400 error responses without invoking the backend. It is the most efficient approach because it minimizes latency and Lambda invocations for invalid requests.

Exam trap

The trap here is that candidates often assume validation must happen in the Lambda function (Option B) because they think backend logic is required, but API Gateway's built-in request validation is more efficient and is the recommended approach for schema-based validation before invocation.

How to eliminate wrong answers

Option B is wrong because validating in the Lambda function incurs unnecessary compute cost and latency, as the function must be invoked even for invalid requests, and it does not leverage API Gateway's native validation capabilities. Option C is wrong because Amazon CloudFront is a content delivery network (CDN) that caches and distributes content at the edge; it does not perform request validation against a schema or model, and its primary purpose is not to validate API requests. Option D is wrong because using API Gateway request parameters to enforce required headers only validates the presence of headers, not the payload body or complex parameter constraints, and it lacks the schema-based validation needed for payload structure.

1047
MCQeasy

A developer is building a serverless application using AWS Lambda. The application needs to process messages from an Amazon SQS queue and store results in an Amazon DynamoDB table. Which AWS service should the developer use to trigger the Lambda function when new messages arrive in the SQS queue?

A.Set up an Amazon EventBridge rule to capture SQS events and invoke Lambda.
B.Use Amazon SNS to subscribe to the SQS queue and trigger Lambda.
C.Use AWS Step Functions to poll the SQS queue and invoke Lambda.
D.Configure an SQS event source mapping on the Lambda function.
AnswerD

Configuring an SQS event source mapping on a Lambda function is the correct and most efficient approach. This mechanism enables Lambda to automatically poll the specified SQS queue, retrieve batches of messages, and then synchronously invoke the Lambda function with these messages as the event payload. Lambda manages the polling infrastructure, scaling, and ensures messages are processed, deleted upon successful execution, or returned to the queue if the function fails.

Why this answer

AWS Lambda supports native SQS event source mappings, which allow Lambda to poll an SQS queue and invoke the function automatically when new messages arrive. This integration handles the polling, batch retrieval, and deletion of messages from the queue, making it the simplest and most efficient way to process SQS messages with Lambda.

Exam trap

The trap here is that candidates may confuse the direction of SNS-SQS integration, thinking SNS can subscribe to SQS to trigger Lambda, when in fact SNS publishes to SQS and Lambda must be triggered via an event source mapping or SNS topic subscription directly.

How to eliminate wrong answers

Option A is wrong because Amazon EventBridge rules cannot directly capture SQS events; SQS does not emit events to EventBridge for queue messages. Option B is wrong because Amazon SNS cannot subscribe to an SQS queue; SNS publishes messages to SQS subscriptions, not the reverse, and SNS cannot trigger Lambda from SQS messages. Option C is wrong because AWS Step Functions can poll SQS using a service integration, but it is not designed to trigger Lambda directly from new messages; it would require a custom polling loop or callback pattern, adding unnecessary complexity compared to the native SQS event source mapping.

1048
Multi-Selecthard

A company is using AWS CodePipeline to automate its CI/CD pipeline. The pipeline has a source stage that pulls code from an Amazon S3 bucket. Which THREE steps should the developer take to ensure that only approved changes are deployed to production?

Select 3 answers
A.Use AWS CloudFormation change sets to review changes
B.Enable versioning on the S3 bucket
C.Configure cross-account access for the pipeline
D.Add a manual approval step before the production deployment
E.Encrypt the S3 bucket with AWS KMS
AnswersA, B, D

CloudFormation change sets provide a summary of proposed changes to your AWS resources before they are actually implemented. Integrating change sets into a CodePipeline stage allows developers to review the exact modifications (e.g., resource additions, deletions, or property updates) that a new CloudFormation template would make to the existing stack. This critical review step helps prevent unintended resource modifications or accidental deletions in production environments, ensuring controlled and predictable infrastructure updates.

Why this answer

AWS CloudFormation change sets allow you to preview how proposed changes to a stack will impact existing resources before you execute them. By reviewing the change set, you can verify that only approved modifications (e.g., infrastructure updates) are applied, providing a safety check before deployment to production. This step ensures that unapproved or unintended changes are caught early in the pipeline.

Exam trap

The trap here is that candidates often confuse security controls (like encryption or cross-account access) with governance controls (like approval workflows), leading them to select options that protect data but do not enforce change approval.

1049
Multi-Selectmedium

A developer is designing a microservices architecture using Amazon ECS with Fargate. The services need to communicate with each other securely. Which THREE methods can be used to enable service-to-service authentication?

Select 3 answers
A.Use AWS App Mesh with mutual TLS (mTLS) authentication.
B.Configure Amazon ECS Service Connect for service-to-service communication.
C.Use Amazon API Gateway as a proxy for inter-service communication.
D.Use security group rules to allow traffic only between services.
E.Use IAM roles for tasks and AWS SDK to sign requests.
AnswersA, B, E

AWS App Mesh is a service mesh that provides application-level networking for microservices, leveraging Envoy proxies to manage all network traffic. It enables mutual TLS (mTLS) for strong identity-based authentication and encryption between services. This ensures that only trusted services can communicate, enhancing both security and observability within the microservices architecture by verifying the identity of both the client and server.

Why this answer

AWS App Mesh with mutual TLS (mTLS) provides service-to-service authentication by requiring each side of a connection to present and validate X.509 certificates. This ensures both the caller and the receiver are authenticated, preventing unauthorized services from communicating within the mesh.

Exam trap

The trap here is that candidates confuse network-layer controls (security groups) with application-layer authentication (mTLS, IAM), assuming that restricting traffic by IP/port is sufficient for service identity verification.

1050
MCQhard

A developer is building a REST API using Amazon API Gateway and AWS Lambda. The API must support CORS to allow requests from a web application hosted on a different domain. The developer has enabled CORS on the API Gateway resource and configured the Lambda function to return the appropriate headers. However, the web application is still receiving CORS errors. What is the most likely cause?

A.The API Gateway stage is not redeployed after enabling CORS.
B.The API Gateway CORS configuration is incorrect; the allowed origin should be set to '*'.
C.The web application is not sending the preflight OPTIONS request.
D.The Lambda function is not returning the CORS headers in the response.
AnswerA

While redeploying an API Gateway stage is often necessary for configuration changes to take effect, a CORS error specifically indicates that the required `Access-Control-Allow-Origin` header is missing from the HTTP response. Even if the API Gateway's own CORS configuration is correctly set and deployed, if the integrated backend Lambda function does not explicitly include these headers in its response, the browser will still block the request. Therefore, redeployment alone would not resolve the fundamental issue of missing headers from the Lambda's output.

Why this answer

When you enable CORS in the API Gateway console, it creates or updates the OPTIONS method for the resource. However, these configuration changes do not take effect until the API is redeployed to a stage. If the developer does not redeploy the API, the preflight OPTIONS request will fail (typically returning a 403 or 404), which the browser interprets as a CORS error.

Since the developer already configured the Lambda function to return the headers, the missing step is redeploying the API stage.

Exam trap

Candidates often forget that enabling CORS in the API Gateway console modifies the API definition (by adding/updating the OPTIONS method and mock integration). Like any other method or resource change in API Gateway, these changes are not active on the live stage until the API is explicitly redeployed.

How to eliminate wrong answers

Option A is wrong because redeploying the API Gateway stage is necessary after any configuration change, but the question states the developer enabled CORS on the resource, implying the stage was redeployed; the core issue is the Lambda response missing headers. Option B is wrong because setting the allowed origin to '*' is a valid wildcard for CORS, but it does not fix the missing headers from the Lambda function; the problem is not the origin value but the absence of headers entirely. Option C is wrong because the browser automatically sends the preflight OPTIONS request for cross-origin requests with non-simple methods or custom headers; the developer enabled CORS on API Gateway, which handles the OPTIONS response, so the preflight is not the issue.

Page 13

Page 14 of 16

Page 15