Courseiva

AWS Certified Developer Associate DVA-C02 (DVA-C02) — Questions 1051–1125

1135 questions total · 16pages · All types, answers revealed

Page 14

Page 15 of 16

Page 16
1051
MCQmedium

A company uses AWS OpsWorks to manage a stack of EC2 instances. The operations team needs to deploy a new configuration file to all instances in a layer. Which approach should the team use to automate this deployment?

A.Use AWS Systems Manager Run Command to execute a script that deploys the file
B.Add a Chef recipe to the layer's custom cookbooks that copies the configuration file to the instances
C.Create a new AWS CloudFormation stack to update the instances
D.Use AWS CodeDeploy to deploy the configuration file
AnswerB

OpsWorks Stacks is built on Chef, and adding a custom Chef recipe to the layer's cookbook (then associating it with a lifecycle event such as Configure or Deploy, or triggering it on demand) is the native, idempotent mechanism for pushing configuration file changes to every instance in that layer consistently and repeatably.

Why this answer

The correct answer is B: adding a Chef recipe to the layer's custom cookbooks that copies the configuration file to the instances. AWS OpsWorks Stacks is built on Chef, so configuration management tasks like distributing files to all instances in a layer are performed through recipes executed during lifecycle events (Setup, Configure, Deploy), making this the native and automated approach. Option A is not the OpsWorks-native mechanism and would bypass the stack's Chef-based lifecycle, requiring manual invocation or separate targeting.

Option C is incorrect because CloudFormation provisions infrastructure and does not manage in-instance configuration files for an existing OpsWorks stack. Option D is also wrong because CodeDeploy is a separate deployment service not integrated with OpsWorks Stacks' Chef recipe model.

1052
MCQhard

A company has an S3 bucket with versioning enabled. A developer accidentally deleted an object. What must be done to recover it?

A.Copy the object from another bucket
B.Restore the object from Glacier Deep Archive
C.Delete the delete marker
D.Enable versioning on the bucket
AnswerC

When versioning is enabled, deleting an object does not erase its data but instead inserts a delete marker as the new current version; removing that specific delete marker version makes the previous object version become current again, effectively undeleting the object without any data loss.

Why this answer

When versioning is enabled on an S3 bucket, a delete operation does not actually remove the object; instead, it inserts a delete marker that becomes the current version, hiding the previous versions. To recover the object, you must delete that delete marker, which promotes the prior object version back to being the current version and makes it accessible again. Option C is therefore correct.

Option A is wrong because no copy exists elsewhere, option B is wrong because Glacier Deep Archive is a storage class for archival data and is not involved in this recovery, and option D is wrong because versioning is already enabled and enabling it again would not restore the object.

1053
Multi-Selecteasy

Which TWO approaches can be used to optimize costs for an Amazon DynamoDB table with predictable read/write patterns? (Select TWO.)

Select 2 answers
A.Increase the read capacity units to avoid throttling.
B.Use provisioned capacity with auto scaling.
C.Use DynamoDB global tables for multi-region replication.
D.Use DynamoDB Accelerator (DAX) to cache read results.
E.Use on-demand capacity mode.
AnswersB, D

Provisioned capacity with auto scaling is the most cost-effective approach for predictable workloads. DynamoDB uses CloudWatch alarms on utilization metrics (e.g., 70% of consumed capacity) to automatically increase or decrease your provisioned read and write capacity units, so you only pay for what your traffic actually requires. However, note that scaling happens gradually, so you must set sensible minimums and maximums to avoid both throttling and underused capacity.

Why this answer

Option B is correct because provisioned capacity with auto scaling lets you set a target utilization and have Application Auto Scaling adjust read/write capacity units to match predictable traffic, so you pay only for the capacity you actually need rather than over-provisioning. Option D is correct because DAX is an in-memory cache for DynamoDB that serves eventually consistent reads from memory, reducing the number of read capacity units consumed on the table and lowering cost for read-heavy, predictable workloads. Option A is not correct because increasing read capacity units raises cost rather than optimizing it, and it addresses throttling, not cost efficiency.

Option C is not correct because global tables add multi-region replication and incur extra write and storage costs, which is a resilience feature, not a cost optimization. Option E is not correct because on-demand capacity mode is designed for unpredictable or spiky workloads and typically costs more per request than well-tuned provisioned capacity for predictable patterns.

Exam trap

DVA-C02 often tests the misconception that on-demand mode is always cheaper or that global tables reduce costs, when in fact they increase cost for resilience.

1054
MCQmedium

A developer has deployed an AWS Lambda function that is triggered by an Amazon S3 event. The function processes image files and stores metadata in an Amazon DynamoDB table. CloudWatch metrics show that the function's error count has increased. The developer checks CloudWatch Logs and sees errors related to insufficient memory. The function is configured with 128 MB of memory. What should the developer do to resolve the errors?

A.Increase the function's memory to 256 MB or higher.
B.Increase the function's timeout to 30 seconds.
C.Reduce the size of the images being uploaded to S3.
D.Move the DynamoDB write operation to an asynchronous invocation.
AnswerA

An "out-of-memory" error directly indicates that the allocated memory for the Lambda function is insufficient to perform its operations, such as image processing which can be memory-intensive. Increasing the memory allocation directly addresses this by providing more RAM for the function to utilize during execution. Furthermore, AWS Lambda's execution environment scales CPU power proportionally with memory allocation, meaning higher memory also grants more vCPUs, accelerating image processing and reducing overall execution time.

Why this answer

The error is caused by insufficient memory, which directly impacts the CPU and execution resources allocated to the Lambda function. Increasing the memory allocation to 256 MB or higher provides more CPU throughput and memory, resolving the out-of-memory errors without requiring code changes.

Exam trap

The trap here is that candidates confuse memory errors with timeout errors and incorrectly choose to increase the timeout, but the logs explicitly state insufficient memory, not duration limits.

How to eliminate wrong answers

Option B is wrong because increasing the timeout does not address memory exhaustion; timeout errors occur when execution duration exceeds the limit, not when memory is insufficient. Option C is wrong because reducing image sizes is a workaround that may not be feasible or controlled by the developer, and it does not fix the underlying resource allocation issue. Option D is wrong because moving the DynamoDB write to an asynchronous invocation does not reduce memory consumption during image processing; the function still needs enough memory to process the image in memory before any write occurs.

1055
MCQmedium

An application running on EC2 needs to access an S3 bucket. The security team wants to avoid using long-term access keys. What is the most secure approach?

A.Generate an access key and secret key for an IAM user and store them on the instance.
B.Create a new IAM user and store the credentials in S3 with bucket policies.
C.Use AWS Systems Manager Parameter Store to store the credentials and retrieve them at runtime.
D.Launch the EC2 instance with an IAM role that grants S3 access.
AnswerD

Launching an EC2 instance with an attached IAM role is the most secure and recommended method for granting AWS resource access. This approach leverages the instance metadata service to provide temporary, frequently rotated credentials to applications running on the instance. These credentials are never stored directly on the instance, eliminating the risk associated with static access keys and simplifying credential management and rotation.

Why this answer

Assigning an IAM role to an EC2 instance allows the instance to obtain temporary security credentials from the AWS Security Token Service (STS) automatically via the instance metadata service. This eliminates the need to store, rotate, or manage long-term access keys, adhering to the security team's requirement for a credential-less approach. The IAM role's permissions policy grants the EC2 instance access to the S3 bucket, and the credentials are automatically rotated by AWS before they expire.

Exam trap

The trap here is that candidates often confuse 'secure storage' (like Parameter Store or Secrets Manager) with 'no long-term credentials at all,' failing to recognize that an IAM role provides temporary credentials that are inherently more secure and require no key management on the instance.

How to eliminate wrong answers

Option A is wrong because storing an access key and secret key on the EC2 instance introduces long-term static credentials that can be compromised if the instance is breached, violating the security team's requirement to avoid long-term access keys. Option B is wrong because storing IAM user credentials in S3 with bucket policies still relies on long-term access keys and adds unnecessary complexity; bucket policies cannot securely protect the credentials themselves from unauthorized access. Option C is wrong because while Systems Manager Parameter Store can securely store secrets, the EC2 instance still needs a mechanism (such as an IAM role) to retrieve them at runtime, and using Parameter Store with long-term credentials stored as parameters does not eliminate the underlying risk of managing static keys.

1056
MCQeasy

A developer invoked a Lambda function and saw the above output. What is the root cause of the error?

A.The Lambda function lacks permission to access the event payload.
B.The function code expects a property that is missing from the event payload.
C.The Lambda function's handler name is incorrect.
D.The Lambda function timed out.
AnswerB

The observed error, likely a TypeError indicating an attempt to access a property (e.g., 'length') on an 'undefined' value, strongly suggests that a nested property or object expected by the function's code was not present in the incoming event payload. When a JavaScript or Python function tries to dereference a property on an 'undefined' or non-existent object, the runtime throws an exception because the path to the desired property does not exist, causing the execution to halt.

Why this answer

The correct answer is B: the function code expects a property that is missing from the event payload. In Lambda, when the handler accesses a key on the parsed event object (e.g., event['detail'] or event.detail) that does not exist, the runtime raises a KeyError or TypeError, which surfaces as an invocation error in the response. This is a data-shape mismatch between what the code reads and what the caller sent, not an infrastructure or configuration failure.

Option A is wrong because payload access is not gated by IAM permissions; the event is always delivered to the handler. Option C is wrong because an incorrect handler name produces a Runtime.HandlerNotFound or 'handler does not exist' error before any code runs. Option D is wrong because a timeout returns Task timed out after X seconds rather than a missing-property error.

1057
MCQhard

A developer needs to deploy a serverless application using AWS CloudFormation. The application includes an AWS Lambda function, an Amazon API Gateway REST API, and an Amazon DynamoDB table. The developer wants to create a stack that can be updated without downtime. Which CloudFormation feature should be used?

A.Drift detection
B.StackSets
C.Nested stacks
D.Change Sets
AnswerD

AWS CloudFormation Change Sets provide a powerful mechanism to preview the proposed changes to your stack before they are actually applied. By generating a Change Set, developers can review exactly which resources will be added, modified, or deleted, and understand the potential impact on existing resources. This foresight is crucial for planning updates that minimize or eliminate downtime, allowing for adjustments to the template or deployment strategy to ensure continuous service availability.

Why this answer

Change Sets allow you to preview how changes to your CloudFormation stack will affect your running resources before you apply them. By reviewing the change set, you can ensure that the update does not cause downtime, for example by replacing resources without interruptions. This makes Change Sets the appropriate feature for updating a stack without downtime.

1058
MCQmedium

A development team is using AWS CodeCommit as a source repository and CodeBuild for build automation. They want to trigger a build automatically whenever a pull request is created or updated in the repository. Which configuration should they use?

A.Configure an S3 event notification on the repository
B.Configure a webhook in CodeCommit to trigger CodeBuild
C.Use Amazon EventBridge to capture CodeCommit events and trigger CodeBuild
D.Create a CodePipeline that polls CodeCommit for changes
AnswerC

Amazon EventBridge is the correct and recommended service for integrating CodeCommit with other AWS services based on repository events. CodeCommit automatically publishes various events, including repository pushes, pull request creations, and state changes, to EventBridge. A specific EventBridge rule can then be configured to filter for desired CodeCommit event patterns and directly invoke AWS CodeBuild as a target, initiating a build process in response to code changes or pull request activity. This provides a robust, serverless, and event-driven integration.

Why this answer

The correct option is C: use Amazon EventBridge to capture CodeCommit events and trigger CodeBuild. CodeCommit emits pull request state-change events (e.g., pullRequestCreated and pullRequestSourceBranchUpdated) to the default EventBridge bus, and an EventBridge rule can match those events and invoke CodeBuild as a target, which is the supported way to start builds on pull request creation or updates. Option A is wrong because S3 event notifications apply to S3 buckets, not CodeCommit repositories.

Option B is wrong because CodeCommit webhooks are not a native trigger mechanism for CodeBuild in this pull request scenario. Option D is wrong because CodePipeline polling detects branch commits, not pull request creation/update events, and polling is not event-driven.

1059
MCQeasy

A developer is deploying a new version of an AWS Lambda function that is invoked by an Amazon API Gateway REST API. The developer wants to shift 10% of incoming traffic to the new version while keeping 90% on the current version, and then gradually increase traffic to the new version. The developer also needs the ability to roll back instantly if errors occur. Which approach should the developer use?

A.Use AWS CodeDeploy to perform a blue/green deployment of the Lambda function, specifying a 10% traffic shift in the deployment configuration.
B.Publish a new Lambda function version and create an alias that points to both versions with a weighted routing configuration, then update the API Gateway integration to use the alias ARN.
C.Configure the API Gateway method to use a Lambda proxy integration and enable throttling to limit the new version's invocations.
D.Create a new API Gateway stage for the new Lambda version and use canary deployment settings on the stage to route 10% of traffic.
AnswerB

Lambda aliases support weighted routing between two versions, allowing traffic to be split by percentage. API Gateway can invoke the alias ARN, so the traffic distribution is managed at the alias level. This enables gradual shifts and instant rollback by adjusting weights or repointing the alias to the previous version.

Why this answer

Lambda aliases with weighted routing allow a developer to direct a percentage of invocations to a new version while keeping the rest on the current version. By pointing API Gateway to the alias ARN, the traffic split is enforced at the alias level. Adjusting the weights or repointing the alias provides immediate rollback, satisfying all requirements with minimal operational overhead.

Exam trap

The trap here is assuming that API Gateway stage canary settings or CodeDeploy are required for traffic shifting, when Lambda alias weighted routing directly provides the needed split and rollback.

1060
MCQhard

A developer is building a serverless application using AWS Lambda and Amazon API Gateway REST API. The API Gateway is configured to use a Lambda proxy integration. The developer wants to return a custom error message with a specific HTTP status code (e.g., 404) when a resource is not found. How should the developer implement this?

A.Return a JSON object with 'status_code' and 'message' keys.
B.Throw an exception with a message that includes the HTTP status code.
C.Return a JSON object with 'errorMessage' and 'errorType' keys.
D.Return a JSON object with keys 'statusCode', 'headers', and 'body' where 'statusCode' is 404 and 'body' contains the error message.
AnswerD

For API Gateway Lambda proxy integration, the Lambda function must return a JSON object with the exact structure `{ 'statusCode': <number>, 'headers': <object>, 'body': <string> }`. This specific format allows the Lambda function to fully control the HTTP response returned to the client, including the status code (e.g., 404 Not Found), custom headers, and the response body containing the error message. Adhering to this contract ensures API Gateway correctly maps the Lambda's output to the desired HTTP response.

Why this answer

With Lambda proxy integration in API Gateway, the Lambda function must return a response in the exact format that API Gateway expects: a JSON object with 'statusCode' (integer), 'headers' (object), and 'body' (string). This allows the developer to set a custom HTTP status code like 404 and include a custom error message in the body. API Gateway will then map this response directly to the HTTP response sent to the client.

Exam trap

The trap here is that candidates often confuse the Lambda proxy integration response format with the standard Lambda error response format (errorMessage/errorType) or assume that simply throwing an exception will propagate the status code, but AWS requires a specific structured success response to control the HTTP status code.

How to eliminate wrong answers

Option A is wrong because returning a JSON object with 'status_code' and 'message' keys does not match the required response format for Lambda proxy integration; API Gateway will not interpret these keys and will likely return a 502 Malformed Lambda Response. Option B is wrong because throwing an exception in Lambda causes the function to fail, and API Gateway will return a 502 Internal Server Error, not the custom status code or message. Option C is wrong because 'errorMessage' and 'errorType' are part of the standard error response format for Lambda invocations (used in non-proxy integrations or direct invocations), but with proxy integration, the Lambda must return a properly formatted success response, not an error object.

1061
MCQhard

A developer is optimizing an API Gateway REST API that uses Lambda integration. The response times are high, and CloudWatch logs show that the Lambda function has cold starts frequently. The function is written in Java and uses a large library. What is the MOST effective optimization?

A.Rewrite the function in Node.js to reduce cold start time.
B.Increase the Lambda function's memory allocation to 3008 MB.
C.Enable provisioned concurrency on the Lambda function.
D.Use the AWS SDK for Java 2.x to reduce initialization time.
AnswerC

Enabling provisioned concurrency on a Lambda function explicitly pre-initializes a specified number of execution environments, keeping them warm and ready to process invocations immediately. This mechanism directly bypasses the cold start process, as the runtime and function code are already loaded and initialized before an invocation arrives. For API Gateway integrations, this ensures consistent, low-latency responses by eliminating the variable startup time associated with cold starts, which is critical for user-facing applications.

Why this answer

The most effective optimization is C: enabling provisioned concurrency on the Lambda function, because it pre-initializes execution environments so that invocations are served by already-warm instances, eliminating the cold starts that CloudWatch logs show are frequent. This directly addresses the Java runtime's heavy initialization cost caused by the large library, without changing application code. Option A is a major rewrite that may reduce cold start duration but does not guarantee elimination and changes the technology stack.

Option B increases memory and can proportionally speed initialization, but cold starts would still occur. Option D may modestly improve Java initialization, but it does not prevent cold starts the way provisioned concurrency does.

1062
MCQmedium

Given the IAM policy above, what is the effective permission for an IAM user?

A.No access to the bucket.
B.Full access to the bucket including delete.
C.Read-only access to the bucket.
D.Full access to the bucket except delete.
AnswerC

The policy grants only s3:GetObject and s3:ListBucket actions, with no PutObject, DeleteObject or bucket-level write permissions attached. The IAM user can therefore retrieve and enumerate objects but cannot modify or remove them, giving read-only access.

Why this answer

The IAM policy grants only s3:GetObject and s3:ListBucket permissions, which allow reading objects and listing the bucket, and explicitly denies s3:DeleteObject. Since no write permissions (e.g., s3:PutObject) are granted, the effective permission is read-only access (list and get) with delete explicitly denied. Therefore, the user has read-only access to the bucket, not full access.

Exam trap

Candidates often misinterpret 'full access except delete' as including write permissions, but the policy only grants read and list actions. The explicit deny on delete does not add write permissions.

How to eliminate wrong answers

Option A is wrong because the policy grants read access (s3:GetObject and s3:ListBucket), so the user does have access to the bucket. Option B is wrong because the policy includes an explicit deny for s3:DeleteObject, which prevents full access including delete. Option C is wrong because the policy does not grant write permissions (e.g., s3:PutObject), but the user has read access plus the ability to list, which is not strictly read-only (though close); more importantly, the explicit deny on delete does not make it read-only—it still allows read and list actions, but the key point is that the correct answer is D, not C.

1063
MCQmedium

A company runs an application on Amazon EC2 that needs to securely store database credentials. The security team requires that credentials be automatically rotated every 30 days to reduce the risk of compromise. The application must be able to retrieve the credentials at startup without storing them in code or configuration files. Which AWS service should the developer use?

A.AWS Secrets Manager
B.AWS Systems Manager Parameter Store (SecureString)
C.AWS Key Management Service (KMS)
D.AWS Identity and Access Management (IAM) roles
AnswerA

AWS Secrets Manager is purpose-built for securely storing, managing, and automatically rotating sensitive application secrets, such as database credentials. It integrates directly with services like Amazon RDS to facilitate seamless, scheduled password rotation without requiring manual intervention, significantly enhancing security posture and reducing operational overhead. This capability directly addresses the requirement for automatic rotation.

Why this answer

AWS Secrets Manager is the correct choice because it is specifically designed to securely store, retrieve, and automatically rotate database credentials on a schedule (e.g., every 30 days) without requiring custom code. The application can retrieve credentials at startup via the Secrets Manager API using IAM permissions, eliminating the need to store secrets in code or configuration files. Secrets Manager natively supports automatic rotation for Amazon RDS, Redshift, and DocumentDB, and can be extended to other services via custom Lambda functions.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (SecureString) with Secrets Manager, overlooking that Parameter Store lacks native automatic rotation, which is a key requirement in the question.

How to eliminate wrong answers

Option B is wrong because AWS Systems Manager Parameter Store (SecureString) can store encrypted secrets but does not natively support automatic rotation of credentials; rotation would require custom automation via AWS Lambda or other services. Option C is wrong because AWS Key Management Service (KMS) is a key management and encryption service that does not store or rotate secrets; it only provides encryption keys for protecting data. Option D is wrong because AWS Identity and Access Management (IAM) roles provide temporary credentials for AWS service access, not for storing or rotating database credentials; they cannot be used to retrieve static secrets like database passwords.

1064
MCQhard

A company has multiple AWS accounts managed under AWS Organizations. The security team requires that all Amazon S3 buckets with bucket names containing 'logs' must be encrypted with a specific KMS key (key ID: alias/logs-key) at rest. A developer must enforce this using an SCP (Service Control Policy). Which SCP effect and condition key should be used to deny any PutObject request that does not use the required KMS key?

A.Deny effect with a Condition: StringNotEquals on s3:x-amz-server-side-encryption-aws-kms-key-id
B.Deny effect with a Condition: StringEquals on s3:x-amz-server-side-encryption
C.Allow effect with a Condition: StringEquals on kms:RequestTag/key-id
D.Deny effect with a Condition: IpAddress on aws:SourceIp
AnswerA

This SCP will deny any PutObject request that specifies a KMS key that is not the required key. The StringNotEquals condition ensures that if the request does not use the specific key ID, the request is denied. This is the standard way to enforce encryption with a specific KMS key using SCPs.

Why this answer

SCPs use a Deny effect to block non-compliant requests. The condition key `s3:x-amz-server-side-encryption-aws-kms-key-id` with `StringNotEquals` ensures that any PutObject request that does not specify the exact KMS key alias/logs-key is denied. This enforces encryption with the required key for all S3 buckets containing 'logs' in their name.

Exam trap

The trap here is that candidates confuse `s3:x-amz-server-side-encryption` (which only checks encryption type) with `s3:x-amz-server-side-encryption-aws-kms-key-id` (which checks the specific KMS key), leading them to choose Option B instead of A.

How to eliminate wrong answers

Option B is wrong because `s3:x-amz-server-side-encryption` only checks whether server-side encryption is enabled (e.g., AES256 or aws:kms), but does not verify the specific KMS key ID, so it cannot enforce the required key. Option C is wrong because Allow effects in SCPs are permissive and cannot deny non-compliant requests; also `kms:RequestTag/key-id` is not a valid condition key for S3 PutObject operations. Option D is wrong because `aws:SourceIp` restricts requests based on IP address, which is unrelated to encryption key enforcement.

1065
MCQhard

A company runs a stateful web application on EC2 instances behind an Application Load Balancer. The application uses WebSockets for real-time communication. The company wants to use AWS CodeDeploy to deploy updates with minimal downtime. Which deployment configuration should the developer use?

A.Canary deployment.
B.In-place deployment.
C.Blue/green deployment.
D.Immutable deployment.
AnswerC

Blue/green deployment involves creating an entirely new, identical environment (the "green" environment) running the new version of the application alongside the existing "blue" environment. Traffic remains directed to the stable "blue" environment while the "green" environment is thoroughly tested. Once verified, traffic is seamlessly shifted from "blue" to "green" at the load balancer level. This approach ensures zero downtime and preserves existing user sessions on the "blue" environment until the switch is complete, making it ideal for stateful applications.

Why this answer

Blue/green deployment is correct because it allows the company to deploy a new version of the application on a separate set of EC2 instances (green environment) while the current version continues to serve traffic on the original set (blue environment). Once the green environment is fully tested and healthy, the Application Load Balancer can instantly switch traffic to it, minimizing downtime. This approach is ideal for stateful WebSocket applications because it avoids terminating active connections during the deployment, as the blue environment remains operational until the switch is complete.

Exam trap

The trap here is that candidates often confuse 'immutable deployment' with a valid CodeDeploy option, but AWS CodeDeploy only supports blue/green and in-place deployments, while immutable deployments are a concept from Elastic Beanstalk or EC2 Auto Scaling with launch template versioning.

How to eliminate wrong answers

Option A is wrong because a canary deployment gradually shifts a small percentage of traffic to the new version, which can cause issues with stateful WebSocket connections that require session persistence and may not handle partial traffic shifts gracefully. Option B is wrong because an in-place deployment updates the existing EC2 instances one at a time, which terminates active WebSocket connections and disrupts real-time communication, leading to downtime. Option D is wrong because immutable deployment is not a standard AWS CodeDeploy deployment configuration; AWS CodeDeploy supports blue/green and in-place deployments, but immutable deployments are typically associated with AWS Elastic Beanstalk or EC2 Auto Scaling with launch templates, not CodeDeploy.

1066
MCQhard

A developer is deploying a microservices architecture on Amazon ECS. The services need to communicate with each other securely. The developer wants to use service discovery and ensure that traffic between services is encrypted. Which combination of services should the developer use?

A.Use AWS Cloud Map for service discovery and AWS App Mesh with mutual TLS
B.Use Amazon API Gateway and AWS Lambda
C.Use Amazon Route 53 private hosted zones and enable DNSSEC
D.Use an Application Load Balancer for each service and enable TLS termination
AnswerA

AWS Cloud Map provides robust service discovery, allowing microservices to dynamically locate each other using either DNS queries or an API. When combined with AWS App Mesh, a service mesh solution, it enables advanced traffic management and security features. App Mesh facilitates mutual TLS (mTLS) between services by injecting Envoy proxies, ensuring that both the client and server services authenticate each other with certificates, thus securing inter-service communication at the transport layer without requiring application code changes. This combination is the most suitable for secure, dynamic microservice interactions.

Why this answer

AWS Cloud Map provides service discovery by registering ECS service instances with DNS-based or API-based resolution, enabling dynamic routing between microservices. AWS App Mesh with mutual TLS (mTLS) encrypts traffic between services and enforces identity-based authentication, ensuring end-to-end encryption and secure communication. This combination directly addresses the requirements for service discovery and encrypted traffic.

Exam trap

The trap here is that candidates often confuse TLS termination at a load balancer (which only encrypts traffic from client to ALB) with mutual TLS between services, or assume DNS-based discovery alone (like Route 53) provides encryption, when it does not.

How to eliminate wrong answers

Option B is wrong because Amazon API Gateway and AWS Lambda are typically used for building serverless APIs, not for service-to-service communication within a microservices architecture on ECS; they lack native service discovery and mTLS encryption between ECS tasks. Option C is wrong because Route 53 private hosted zones provide DNS-based service discovery but DNSSEC only validates DNS responses, it does not encrypt traffic between services. Option D is wrong because an Application Load Balancer (ALB) terminates TLS at the load balancer, not between services, and does not provide service discovery or mTLS for inter-service communication.

1067
MCQmedium

A company uses AWS CodePipeline to deploy a Node.js application to AWS Elastic Beanstalk. The build stage runs successfully, but the deploy stage fails with an error: 'The deployment failed because no instances were found for the environment.' What is the most likely cause?

A.The CodeDeploy application is not configured correctly.
B.The IAM role for CodePipeline lacks permissions to describe EC2 instances.
C.The build artifact is not named correctly for Elastic Beanstalk.
D.The Elastic Beanstalk environment has no running instances due to a failed health check.
AnswerD

If an Elastic Beanstalk environment's instances consistently fail health checks (e.g., application not responding on the configured port, high resource utilization), the underlying Auto Scaling group will terminate them. If new instances launched by Auto Scaling also fail to become healthy, the environment can enter a degraded state with zero healthy, running instances. In this scenario, when CodePipeline attempts to deploy a new application version, it correctly reports "no instances found" because there are no available, healthy targets to receive the deployment.

Why this answer

The error 'no instances were found for the environment' directly indicates that the Elastic Beanstalk environment has no running EC2 instances. This typically occurs when the environment's health checks have failed, causing all instances to be terminated or remain in a degraded state. Without any healthy instances, CodePipeline cannot deploy the application, as Elastic Beanstalk requires at least one running instance to perform a deployment.

Exam trap

The trap here is that candidates often confuse the error with a permissions or artifact issue, but the specific wording 'no instances were found' points directly to the Elastic Beanstalk environment's instance count, not to IAM roles or build outputs.

How to eliminate wrong answers

Option A is wrong because CodeDeploy is not used with Elastic Beanstalk; Elastic Beanstalk uses its own deployment mechanism (e.g., rolling updates, immutable deployments) and does not rely on a CodeDeploy application. Option B is wrong because CodePipeline does not need permissions to describe EC2 instances for an Elastic Beanstalk deployment; the pipeline interacts with Elastic Beanstalk via the CreateApplicationVersion and UpdateEnvironment APIs, not directly with EC2. Option C is wrong because the build artifact name does not affect instance availability; Elastic Beanstalk accepts any valid artifact (e.g., .zip or .war) and the error message specifically mentions missing instances, not artifact naming issues.

1068
MCQmedium

A developer is building a serverless application using AWS Lambda. The Lambda function needs to read messages from an Amazon SQS queue and write items to an Amazon DynamoDB table. The developer wants to follow the principle of least privilege and avoid hardcoding credentials. Which approach should the developer use to grant the Lambda function the necessary permissions?

A.Create an IAM role with the required permissions and configure it as the Lambda function's execution role. Lambda will assume this role automatically.
B.Create an IAM user with programmatic access and store the access key ID and secret access key as environment variables in the Lambda function configuration.
C.Attach an IAM policy directly to the Lambda function's resource policy that grants access to SQS and DynamoDB.
D.Store the AWS credentials in AWS Secrets Manager and have the Lambda function retrieve them at runtime using the Secrets Manager API.
AnswerA

Lambda functions assume an execution role to obtain temporary credentials for accessing AWS services. By attaching an IAM role with the necessary SQS and DynamoDB permissions, the function can securely interact with these services without hardcoded credentials. This follows least privilege and is the AWS-recommended approach for Lambda permissions.

Why this answer

The Lambda execution role is assumed by the function at runtime, providing temporary credentials with the permissions defined in the role's policies. This approach eliminates the need to manage long-term credentials and adheres to least privilege. Other methods either involve long-term credentials or misunderstand the purpose of resource policies.

Exam trap

The trap here is confusing Lambda resource policies with execution roles; resource policies control who can invoke the function, not what the function can access.

1069
MCQeasy

A company uses AWS Elastic Beanstalk to deploy a web application. The application stores user-uploaded images in an S3 bucket. The developer needs to ensure that the application can read and write to the S3 bucket. What should the developer do?

A.Use Amazon CloudFront to proxy requests to the S3 bucket.
B.Hardcode the AWS access keys in the application code.
C.Apply an S3 bucket policy that allows access from the Elastic Beanstalk environment's security group.
D.Configure the Elastic Beanstalk environment to use an IAM instance profile that grants S3 access.
AnswerD

Configuring the Elastic Beanstalk environment to use an IAM instance profile that grants S3 access is the recommended and most secure method. An IAM instance profile attaches an IAM role to the underlying EC2 instances, allowing the application to obtain temporary, automatically rotated credentials from the instance metadata service. This enables the application to make authenticated AWS API calls to S3 without storing any long-term credentials directly within the application code or configuration.

Why this answer

Elastic Beanstalk environments run on EC2 instances, and the recommended way to grant AWS permissions to those instances is by attaching an IAM instance profile. This profile includes an IAM role with a policy that allows the required S3 read and write actions, enabling the application to securely access the S3 bucket without embedding credentials in the code.

Exam trap

The trap here is that candidates may confuse network-level controls (security groups) with identity-based controls (IAM roles) and incorrectly assume that an S3 bucket policy can reference a security group, when in fact S3 bucket policies support only principal, source IP, VPC, or source VPC endpoint conditions, not security group IDs.

How to eliminate wrong answers

Option A is wrong because Amazon CloudFront is a content delivery network (CDN) that can cache and serve content from S3, but it does not grant the application itself the ability to read/write to the bucket; it only proxies requests from clients. Option B is wrong because hardcoding AWS access keys in application code violates security best practices, as keys can be exposed in version control or logs, and Elastic Beanstalk provides a more secure mechanism via instance profiles. Option C is wrong because S3 bucket policies can restrict access by source IP or VPC, but they cannot reference EC2 security groups directly; security groups are a network-level construct, not an identity-based one, and S3 does not evaluate security group IDs in bucket policies.

1070
MCQeasy

A developer wants to ensure that an S3 bucket only allows HTTPS requests. What S3 bucket policy condition should be used?

A.aws:CurrentTime
B.aws:MultiFactorAuthPresent
C.aws:SourceIp
D.aws:SecureTransport
AnswerD

The aws:SecureTransport condition key specifically evaluates whether the incoming request to an S3 bucket was made using HTTPS (TLS/SSL). When set to "true" in a bucket policy, it mandates that all interactions with the bucket must occur over an encrypted connection, effectively preventing unencrypted HTTP requests. This directly addresses the requirement to ensure that the S3 bucket only allows secure, encrypted data transfer.

Why this answer

The aws:SecureTransport condition checks whether the request was sent using SSL/TLS, effectively enabling HTTPS-only access. Option A is incorrect because aws:CurrentTime is used to allow or deny access based on the time of the request. Option B is incorrect because aws:MultiFactorAuthPresent checks if the requester authenticated with multi-factor authentication.

Option C is incorrect because aws:SourceIp is used to restrict requests based on the source IP address.

1071
Matchingmedium

Match each AWS deployment strategy to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Switch between two environments

Gradual traffic shifting

Update instances incrementally

Immediate full deployment

Equal percentage increments

Why these pairings

Common deployment strategies include Rolling, Blue/Green, and Canary. Rolling deploys incrementally, Blue/Green switches between environments, and Canary tests with a small subset. Distractors often confuse these definitions.

1072
MCQmedium

Refer to the exhibit. A developer deploys this CloudFormation template. The Lambda function needs to write objects to an S3 bucket named 'my-app-bucket'. What must the developer add to the template?

A.Add an S3 bucket policy allowing the Lambda function's ARN to write objects.
B.Add a policy statement to LambdaExecutionRole allowing 's3:*' on 'arn:aws:s3:::my-app-bucket'.
C.Add a KMS key policy to allow the Lambda function to use a customer managed key.
D.Add a new policy statement to LambdaExecutionRole allowing 's3:PutObject' on 'arn:aws:s3:::my-app-bucket/*'.
AnswerD

This is the correct solution as it precisely grants the necessary permissions while adhering to the principle of least privilege. Attaching a policy statement to the 'LambdaExecutionRole' is the standard method for providing a Lambda function with permissions to interact with other AWS services. The 's3:PutObject' action is the specific permission required to write objects, and 'arn:aws:s3:::my-app-bucket/*' correctly scopes this permission to all objects within the specified S3 bucket.

Why this answer

The Lambda function requires an IAM policy attached to its execution role to grant permissions for specific S3 actions. The `s3:PutObject` action on the `arn:aws:s3:::my-app-bucket/*` resource ARN precisely allows writing objects to the bucket, following the principle of least privilege. Without this policy statement, the Lambda function will receive an access denied error when trying to write to S3.

Exam trap

The trap here is that candidates often confuse bucket-level ARNs with object-level ARNs, selecting overly permissive options like `s3:*` on the bucket ARN instead of scoping the exact action and resource, or incorrectly assuming an S3 bucket policy is needed for same-account Lambda access.

How to eliminate wrong answers

Option A is wrong because an S3 bucket policy is used to grant cross-account access or public access, not to grant permissions to a Lambda function within the same account; the Lambda function's execution role is the correct mechanism. Option B is wrong because it uses a wildcard `s3:*` action and the bucket-level ARN `arn:aws:s3:::my-app-bucket` instead of the object-level ARN `arn:aws:s3:::my-app-bucket/*`, which is overly permissive and does not correctly scope the `s3:PutObject` permission to objects within the bucket. Option C is wrong because there is no indication that the S3 bucket uses a customer managed KMS key; the question only states the Lambda function needs to write objects, and KMS key policy is only relevant if server-side encryption with KMS is enabled, which is not mentioned.

1073
MCQmedium

A company is developing a microservices architecture using Amazon ECS with Fargate launch type. Each microservice needs to store sensitive configuration data such as database passwords. The company wants to avoid storing secrets in the application code or environment variables. What is the MOST secure and recommended approach?

A.Pass secrets as environment variables in the task definition.
B.Store secrets in an encrypted S3 bucket and have the application download them at startup.
C.Use AWS Systems Manager Parameter Store or AWS Secrets Manager to store and retrieve secrets.
D.Use an AWS Lambda function to generate secrets and store them in DynamoDB.
AnswerC

AWS Systems Manager Parameter Store (specifically Secure String parameters) and AWS Secrets Manager are purpose-built services designed for the secure storage, retrieval, and rotation of sensitive information. They integrate natively with AWS Key Management Service (KMS) for encryption at rest and AWS Identity and Access Management (IAM) for fine-grained access control, providing a robust and compliant solution for managing secrets in a microservices architecture.

Why this answer

AWS Systems Manager Parameter Store (SecureString) and AWS Secrets Manager are purpose-built services for storing and retrieving secrets securely, with encryption at rest via KMS, fine-grained IAM access control, and native integration with ECS/Fargate task definitions. Secrets Manager additionally supports automatic rotation. This is the AWS-recommended approach for injecting secrets into containerized workloads without hardcoding them.

Exam trap

DVA-C02 often tests the misconception that environment variables in task definitions are secure — candidates pick option A because it is convenient, missing that task definition environment variables are visible in plaintext via the ECS API and console.

How to eliminate wrong answers

Option A is wrong because environment variables in task definitions are visible in the ECS console, API responses, and container metadata — they are not a secure storage mechanism for sensitive data. Option B is wrong because downloading secrets from S3 at startup requires the application to manage decryption, caching, and rotation itself, and S3 is not designed as a secrets store — it lacks rotation and fine-grained secret-level access controls. Option D is wrong because using Lambda to generate secrets and store them in DynamoDB creates a custom, unmanaged secrets pipeline with no rotation, no encryption-by-default guarantees, and unnecessary operational complexity.

1074
MCQmedium

A developer is using CloudFront to serve content from an S3 bucket. The bucket contains sensitive data and should only be accessible through CloudFront. How can the developer enforce this?

A.Set the bucket policy to allow access only from CloudFront IP addresses.
B.Set the bucket policy to allow access only from AWS services.
C.Set the bucket policy to allow public read access and use CloudFront signed URLs.
D.Create an origin access identity (OAI) and grant it read access in the bucket policy.
AnswerD

Creating an Origin Access Identity (OAI) and granting it read access in the S3 bucket policy is the recommended and most secure method. The OAI acts as a virtual user for your CloudFront distribution, allowing only that specific distribution to retrieve content from the S3 bucket. This prevents direct public access to the S3 bucket while enabling CloudFront to serve the content securely to end-users.

Why this answer

An Origin Access Identity (OAI) is a special CloudFront user that you can associate with your distribution. By configuring the S3 bucket policy to grant read access only to that OAI, you ensure that content can only be retrieved via CloudFront, not directly from the S3 endpoint. This enforces the requirement that the bucket is accessible exclusively through CloudFront.

Exam trap

The trap here is that candidates often assume restricting by CloudFront IP addresses (Option A) is a valid approach, but AWS explicitly warns that CloudFront IP ranges are not static and should not be used for access control in bucket policies.

How to eliminate wrong answers

Option A is wrong because CloudFront IP addresses are not static and can change over time; using them in a bucket policy would require constant updates and is not a supported or reliable method for restricting access. Option B is wrong because there is no generic 'AWS services' principal in S3 bucket policies; you must specify a specific service principal or user, and this approach would not restrict access to CloudFront only. Option C is wrong because allowing public read access defeats the purpose of restricting access to CloudFront; signed URLs can control who accesses content via CloudFront, but the bucket itself would remain publicly accessible, violating the requirement.

1075
Multi-Selectmedium

A developer is implementing S3 multipart upload for large files. Which two actions are required to complete the upload?

Select 2 answers
A.Enable S3 static website hosting
B.Upload all parts and keep their ETags/part numbers
C.Disable bucket encryption
D.Call CompleteMultipartUpload with the uploaded part list
AnswersB, D

After initiating a multipart upload, the core process involves uploading each individual part of the large file using the `UploadPart` API operation. For every successful part upload, Amazon S3 returns a unique ETag (entity tag) and the corresponding part number. It is critical to store these ETags and part numbers, as they are mandatory parameters for the subsequent `CompleteMultipartUpload` request, which reassembles the parts into the final object.

Why this answer

During an S3 multipart upload, each part must be uploaded individually, and the response includes an ETag (a hash of the part) and a part number. These must be recorded and provided in the final request to assemble the object. Option D is correct because the CompleteMultipartUpload API call is required to signal S3 to combine all uploaded parts into the final object, using the list of ETags and part numbers.

Exam trap

The trap here is that candidates may think uploading all parts is sufficient without calling CompleteMultipartUpload, or they may confuse the multipart upload process with other S3 features like static hosting or encryption settings.

1076
MCQmedium

A developer deployed a new version of a Lambda function that processes S3 events. After deployment, some S3 events are not being processed. The CloudWatch Logs show no errors. What is the most likely cause?

A.The Lambda function has a syntax error.
B.The S3 bucket's event notification still points to the old Lambda function.
C.The Lambda function alias is not pointing to the new version.
D.The S3 events are being throttled by Lambda.
AnswerB

When a new Lambda function version is deployed, S3 event notifications configured to invoke a specific Lambda function (by ARN) will continue to invoke the previously configured version or $LATEST if no specific version was specified. To direct S3 events to a new specific version, the S3 event notification configuration on the bucket must be explicitly updated with the new Lambda function version ARN. This is a common operational oversight when deploying new function versions.

Why this answer

After deploying a new version of a Lambda function, the S3 bucket's event notification configuration still references the Amazon Resource Name (ARN) of the old Lambda function version or the function without a qualifier. S3 event notifications are configured to invoke a specific Lambda function ARN, and if the ARN does not point to the new version (e.g., by using an alias or the $LATEST qualifier), events will continue to be sent to the old version, which may not be processing them. Since CloudWatch Logs show no errors, the old version is likely not being invoked or is not logging, confirming the mismatch.

Exam trap

The trap here is that candidates assume deploying a new Lambda version automatically updates all event sources, but S3 event notifications are static ARN references that must be manually updated or use aliases to reflect the new version.

How to eliminate wrong answers

Option A is wrong because a syntax error would cause the Lambda function to fail during invocation, which would generate error logs in CloudWatch Logs, but the question states there are no errors. Option C is wrong because Lambda function aliases are optional; if the S3 event notification is configured to invoke the function directly without an alias (e.g., using the function ARN without a qualifier), the alias not pointing to the new version is irrelevant. Option D is wrong because Lambda throttling would produce a 'ThrottleReason' metric in CloudWatch and error logs (e.g., 429 TooManyRequestsException), but the question states no errors are present.

1077
MCQhard

A Lambda function needs to write logs to CloudWatch Logs. The developer attaches an IAM role with a policy that allows logs:CreateLogGroup and logs:PutLogEvents. However, logs are not appearing. What is the most likely cause?

A.The Lambda function is not configured to use a VPC.
B.The IAM role does not have a trust policy that allows Lambda to assume it.
C.The IAM policy does not include logs:CreateLogStream.
D.The CloudWatch Logs log group does not exist.
AnswerC

For a Lambda function to successfully write logs to CloudWatch Logs, its execution role requires specific permissions. While `logs:PutLogEvents` is necessary to transmit the actual log data, the function also crucially needs `logs:CreateLogStream` to establish a new log stream within the designated log group if one does not already exist for that particular invocation or execution environment. Without this `CreateLogStream` permission, the function cannot initialize the required logging infrastructure, leading to a failure in log delivery, even if it possesses the permission to put events.

Why this answer

Lambda requires the `logs:CreateLogStream` permission to create a log stream within a log group before it can write log events. Without this permission, the function can create the log group but cannot create the individual log stream needed to store log entries, causing logs to silently fail to appear.

Exam trap

The trap here is that candidates assume `logs:CreateLogGroup` and `logs:PutLogEvents` are sufficient, overlooking the mandatory `logs:CreateLogStream` permission required for the log stream creation step between group creation and event writing.

How to eliminate wrong answers

Option A is wrong because Lambda functions can write logs to CloudWatch Logs without being in a VPC; VPC configuration affects network access but not log delivery. Option B is wrong because the Lambda function already has an IAM role attached, meaning the trust policy (which allows Lambda to assume the role) was already validated when the role was assigned to the function. Option D is wrong because CloudWatch Logs automatically creates the log group if it does not exist when the Lambda function first invokes, provided the IAM policy includes `logs:CreateLogGroup`.

1078
Multi-Selectmedium

A developer is troubleshooting a slow-running application that uses ElastiCache for Redis as a caching layer. The application frequently reads and writes data to the cache. Which TWO actions should the developer take to improve cache performance?

Select 2 answers
A.Use optimized data structures like hashes instead of strings for complex data.
B.Configure the cache to use LRU eviction policy.
C.Disable persistence by setting appendonly to no.
D.Increase the number of shards to distribute data.
E.Enable ElastiCache auto scaling to adjust the number of nodes.
AnswersA, E

Employing optimized data structures such as Redis hashes, instead of storing complex data as serialized strings, significantly enhances performance. Hashes allow for direct field access, reducing the need for costly serialization/deserialization operations and parsing overhead on the application side. This leads to more efficient memory usage and faster CPU processing for read and write operations, as data can be accessed and manipulated with O(1) average time complexity, directly improving application responsiveness.

Why this answer

Using optimized data structures like hashes instead of strings reduces memory and CPU overhead for complex data, improving cache performance. Option E is correct because enabling ElastiCache auto scaling allows the cluster to adjust the number of nodes based on demand, preventing performance degradation during traffic spikes. Option B is incorrect: LRU eviction policy helps manage memory when full but is not a performance optimization for read/write operations.

Option C is incorrect: disabling persistence (appendonly no) improves write performance but is not the primary issue for a slow application and may affect data durability. Option D is incorrect: increasing shards distributes data but does not directly improve performance if the bottleneck is CPU or memory; auto scaling is a more targeted solution.

Exam trap

A common trap is to think that disabling persistence (appendonly) is the best way to improve write performance in Redis, but in a caching scenario, persistence may not be the main bottleneck.

1079
MCQmedium

A company uses AWS CodeDeploy to deploy a web application to an Auto Scaling group of Amazon EC2 instances. The deployment fails with the error 'The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available for deployment, or some instances in your deployment group are experiencing problems.' The developer needs to identify the root cause. Which AWS service should the developer use to view detailed error logs from the failed deployment?

A.Amazon CloudWatch Logs (if configured) or the CodeDeploy agent log files on the EC2 instances
B.AWS X-Ray
C.AWS CloudTrail
D.AWS CodeDeploy console
AnswerA

The CodeDeploy agent, which runs on the target EC2 instances, generates detailed logs for every step of the deployment process, including lifecycle hook script execution and file transfers. These logs are stored locally on the instance (e.g., /var/log/aws/codedeploy-agent/codedeploy-agent.log on Linux) and provide the most granular information for troubleshooting. If configured, the agent can stream these logs to Amazon CloudWatch Logs, offering a centralized and easily accessible location for analysis without requiring direct SSH access to each instance.

Why this answer

When a CodeDeploy deployment fails due to instance-level errors, the most direct way to investigate is to examine the CodeDeploy agent logs located on each EC2 instance at `/opt/codedeploy-agent/deployment-root/deployment-logs/codedeploy-agent.log`. If Amazon CloudWatch Logs has been configured to stream these logs, you can also view them centrally in the CloudWatch console. These logs contain detailed error messages from the `codedeploy-agent` process, including script failures, permission issues, or missing dependencies that caused the deployment to fail.

Exam trap

The trap here is that candidates assume the CodeDeploy console provides detailed error logs, but it only shows aggregated failure counts and high-level messages, while the actual root cause is buried in the agent logs on the EC2 instances or in CloudWatch Logs if configured.

How to eliminate wrong answers

Option B is wrong because AWS X-Ray is a distributed tracing service for analyzing and debugging request flows in microservices applications, not a log viewer for deployment errors. Option C is wrong because AWS CloudTrail records API calls made to AWS services (e.g., who triggered the deployment), but it does not capture the internal agent-level error logs from individual EC2 instances. Option D is wrong because the AWS CodeDeploy console only shows high-level deployment status and failure summaries (e.g., 'failed instances'), not the detailed per-instance error logs needed to diagnose root causes.

1080
MCQeasy

A developer is building an application that needs to send email notifications to users. Which AWS service is designed for sending transactional emails?

A.AWS Lambda
B.Amazon Simple Email Service (SES)
C.Amazon Simple Notification Service (SNS)
D.Amazon Simple Queue Service (SQS)
AnswerB

Amazon Simple Email Service (SES) is a highly scalable, cost-effective, and flexible cloud-based email sending service designed for developers to send marketing, notification, and transactional emails from any application. It handles the underlying email infrastructure, including SMTP, deliverability, and reputation management, allowing applications to programmatically send emails via API, SDKs, or SMTP interface. This makes SES the ideal choice for applications requiring direct email sending capabilities.

Why this answer

Amazon Simple Email Service (SES) is specifically designed for sending transactional emails, such as order confirmations, password resets, and marketing communications. It provides a reliable, scalable SMTP interface or API to send high-deliverability emails, with features like dedicated IP addresses and feedback loops. This makes it the correct choice for an application that needs to send email notifications directly to users.

Exam trap

The trap here is that candidates often confuse Amazon SNS with SES because both can send notifications, but SNS is limited to push notifications (SMS, mobile push, HTTP) and cannot send rich transactional emails, while SES is the dedicated email service.

How to eliminate wrong answers

Option A is wrong because AWS Lambda is a serverless compute service for running code in response to events, not a service for sending emails; it could be used to trigger email sending via SES, but it is not the email delivery service itself. Option C is wrong because Amazon Simple Notification Service (SNS) is a pub/sub messaging service designed for sending push notifications to endpoints like SMS, mobile apps, or HTTP/HTTPS, not for sending transactional emails with rich content or attachments. Option D is wrong because Amazon Simple Queue Service (SQS) is a fully managed message queuing service for decoupling application components, and it has no capability to send emails; it can only hold messages for processing by other services.

1081
Multi-Selectmedium

A developer is troubleshooting a slow Amazon DynamoDB table. The table has a read capacity of 1000 RCU and a write capacity of 500 WCU. The application frequently reads the same item. Which TWO actions can improve read performance?

Select 2 answers
A.Increase the read capacity units (RCU) to 2000.
B.Add a Global Secondary Index (GSI) on the frequently read attribute.
C.Decrease the write capacity units (WCU) to 250.
D.Implement DynamoDB Accelerator (DAX) for caching.
E.Use eventually consistent reads instead of strongly consistent reads.
AnswersD, E

DynamoDB Accelerator (DAX) is an in-memory cache specifically designed for DynamoDB, providing microsecond response times for read-heavy workloads. By caching frequently accessed items, DAX significantly reduces the latency of read operations and offloads read traffic from the underlying DynamoDB table. This direct caching mechanism is highly effective at improving application responsiveness for 'slow' reads.

Why this answer

DynamoDB Accelerator (DAX) is an in-memory cache that can reduce read latency for frequently accessed items from milliseconds to microseconds, offloading read traffic from the table and improving performance without requiring a capacity increase. Option E is correct because eventually consistent reads consume half the RCU of strongly consistent reads (0.5 RCU vs 1 RCU per 4 KB item) and return data faster, which is suitable when the application can tolerate slightly stale data for the same item.

Exam trap

The trap here is that candidates often choose to increase RCU (Option A) as a knee-jerk reaction to slow reads, overlooking that caching (DAX) and consistency model changes are more cost-effective and targeted solutions for repeated reads of the same item.

1082
Multi-Selecteasy

Which of the following are valid ways to secure access to an Amazon S3 bucket? (Choose TWO.)

Select 2 answers
A.Bucket policies
B.CloudFront distribution
C.IAM policies
D.Network ACLs
E.Security groups
AnswersA, C

Bucket policies are resource-based access policies directly attached to an S3 bucket, defining who (principals like IAM users, roles, or other AWS accounts) can perform which actions (e.g., GetObject, PutObject) on the objects within that specific bucket. They are fundamental for granting cross-account access, defining public access configurations, or restricting access based on IP addresses. These policies act as a primary access control layer, evaluated directly by the S3 service upon every request to the bucket.

Why this answer

Bucket policies are a form of resource-based policy that you attach directly to an S3 bucket. They allow you to grant or deny access to the bucket and its objects for principals (users, roles, or AWS accounts) using the AWS JSON policy language. This is a primary and native way to control access to S3 resources, making option A correct.

Exam trap

The trap here is that candidates confuse network-level security controls (like NACLs and Security Groups) with resource-level access controls, mistakenly thinking they can be applied to S3 buckets, which are global services not bound to a VPC subnet.

1083
Multi-Selectmedium

A developer is using AWS CodeBuild to build a Docker image and push it to Amazon ECR. The build fails with a 'no basic auth credentials' error when trying to push the image. Which TWO actions should the developer take to resolve this issue? (Choose two.)

Select 2 answers
A.Add a pre-build command to run 'aws ecr get-login-password --region <region> | docker login --username AWS --password-stdin <account-id>.dkr.ecr.<region>.amazonaws.com'.
B.Install the AWS CLI in the buildspec.yml file.
C.Install Docker in the buildspec.yml file.
D.Add an IAM policy to the CodeBuild service role that allows ecr:GetAuthorizationToken and ecr:Push.
E.Configure SSH key-based authentication for ECR.
AnswersA, D

For CodeBuild to successfully push a Docker image to Amazon ECR, the Docker daemon running within the build environment must first authenticate with the ECR registry. This pre-build command retrieves a temporary authorization token from ECR using the AWS CLI's 'get-login-password' command and pipes it directly to 'docker login', securely authenticating the Docker client for subsequent push operations. This is a mandatory step to establish a trusted connection.

Why this answer

The 'aws ecr get-login-password' command retrieves a temporary authentication token from AWS, which is then piped to 'docker login' to authenticate the Docker client with the Amazon ECR registry. This is the standard method for authenticating Docker to ECR, and it must be executed in the pre-build phase to ensure credentials are available before the 'docker push' command runs.

Exam trap

The trap here is that candidates often assume the issue is missing Docker or AWS CLI installations, overlooking that both are pre-installed in CodeBuild, and instead fail to recognize the need for explicit authentication and IAM permissions for ECR.

1084
MCQeasy

Refer to the exhibit. A developer creates this CloudFormation template and tries to deploy it. The deployment fails with 'CREATE_FAILED' for the S3 bucket resource. What is the most likely cause?

A.The template does not enable versioning on the bucket.
B.The bucket name must be in all lowercase letters.
C.The bucket name is already taken by another AWS account.
D.The template does not specify a bucket policy.
AnswerC

AWS S3 bucket names must be globally unique across all AWS accounts, not just within a single account or region. If the specified bucket name, "myuniquebucket123", has already been claimed by any other AWS customer worldwide, the CloudFormation stack creation will fail with a "BucketAlreadyOwnedByYou" or "BucketAlreadyExists" error. This global uniqueness constraint is a common reason for S3 bucket creation failures, making this a highly plausible cause.

Why this answer

S3 bucket names must be globally unique across all AWS accounts. If the bucket name specified in the template is already in use by another account, CloudFormation will fail with CREATE_FAILED for the S3 bucket resource. This is a fundamental requirement of the S3 service, not a template syntax or configuration issue.

Exam trap

The trap here is that candidates often assume the failure is due to a missing configuration (like versioning or policy) rather than recognizing the global uniqueness constraint as the root cause.

How to eliminate wrong answers

Option A is wrong because versioning is an optional feature; its absence does not cause a bucket creation failure. Option B is wrong because while S3 bucket names must be lowercase, the template likely already uses lowercase (the error would be a validation error, not a CREATE_FAILED due to name conflict). Option D is wrong because a bucket policy is not required for bucket creation; it can be added later or omitted entirely.

1085
MCQmedium

A company uses AWS OpsWorks for configuration management. They want to migrate to AWS Systems Manager for patching and automation. They have a fleet of EC2 instances running Amazon Linux 2. Which Systems Manager capability should they use to automate patching?

A.Patch Manager
B.State Manager
C.Run Command
D.Maintenance Windows
AnswerA

AWS Systems Manager Patch Manager is the dedicated service specifically designed to automate the process of scanning instances for missing patches and applying security updates or other patches. It allows administrators to define patch baselines, schedule patching operations, and monitor compliance across entire fleets of managed instances, including those configured via AWS OpsWorks, ensuring systems remain secure and up-to-date without manual intervention.

Why this answer

AWS Systems Manager Patch Manager is the capability specifically designed to automate the process of patching managed nodes, including EC2 instances running Amazon Linux 2. It uses patch baselines to define approved patches and can apply them on a schedule via maintenance windows or on demand. This directly replaces the patching functionality previously provided by OpsWorks.

Exam trap

DVA-C02 often tests the confusion between Systems Manager capabilities — candidates pick Run Command or Maintenance Windows for patching when the correct answer is the purpose-built Patch Manager.

How to eliminate wrong answers

Option B is wrong because State Manager is used to maintain a consistent configuration state on instances (e.g., ensuring an agent is installed or a file exists) via associations, not to scan for and install OS patches. Option C is wrong because Run Command lets you execute commands or scripts remotely at scale, but it does not natively manage patch baselines, compliance reporting, or patch approval — you would have to script patching yourself. Option D is wrong because Maintenance Windows is only a scheduling mechanism that defines when operations run; it must be paired with a task like Patch Manager or Run Command and does not itself perform patching.

1086
MCQmedium

A company runs a Node.js application on AWS Elastic Beanstalk. The application is experiencing high latency. The developer suspects the database queries are slow. Which step should the developer take first to diagnose the issue?

A.Migrate the database to Amazon DynamoDB for better performance.
B.Enable enhanced health reporting and monitor CloudWatch metrics for database connection time.
C.Add database indexing to improve query performance.
D.Increase the instance size to improve performance.
AnswerB

Elastic Beanstalk's enhanced health reporting provides detailed system and application metrics, including crucial database connection statistics, directly to Amazon CloudWatch. Monitoring "database connection time" specifically allows for direct diagnosis of latency issues between the application instances and the database. This approach provides actionable data to pinpoint whether the database itself, network latency, or application-level connection pooling is the bottleneck, enabling targeted resolution.

Why this answer

The first step should be to enable enhanced health reporting and monitor CloudWatch metrics for database connection time. This provides visibility into the application's performance and helps identify if the database is indeed the bottleneck.

Exam trap

DVA-C02 often tests the principle of diagnosing before acting, with distractors that suggest immediate fixes like migration or scaling without evidence.

How to eliminate wrong answers

Option A is wrong because migrating to DynamoDB is a drastic step that should not be taken before diagnosing the issue; it may not solve the problem and could introduce new complexities. Option C is wrong because adding indexes is a potential fix but should be based on diagnosis; without confirming slow queries, it could be premature. Option D is wrong because increasing instance size is a scaling action that may not address the root cause and could be costly if the issue is elsewhere.

1087
MCQhard

A company runs a microservices architecture on Amazon ECS with Fargate. Each service uses an Application Load Balancer and stores data in Amazon DynamoDB. The operations team notices that during traffic spikes, some requests fail with HTTP 503 errors. CloudWatch metrics show that the ALB's TargetResponseTime is increasing, and the DynamoDB table's ConsumedWriteCapacityUnits are reaching the provisioned limit. The team wants to handle traffic spikes gracefully without manual intervention. What should they do?

A.Increase the DynamoDB table's provisioned write capacity and the ALB's target group deregistration delay.
B.Use an SQS queue to buffer write requests and process them asynchronously.
C.Add a DynamoDB Accelerator (DAX) cluster to cache frequently accessed data.
D.Enable DynamoDB Auto Scaling for write capacity and configure ECS Service Auto Scaling based on ALB request count.
AnswerD

Enabling DynamoDB Auto Scaling for write capacity allows the table to automatically adjust its provisioned throughput based on actual utilization and defined target metrics, preventing throttling during peak loads and scaling down during lulls to optimize costs. Concurrently, configuring ECS Service Auto Scaling based on the ALB request count ensures that the microservices processing the requests will dynamically add or remove tasks to match incoming traffic, providing sufficient compute resources to handle the increased demand and effectively utilize the scaled DynamoDB capacity. This combination offers a fully automated, elastic, and cost-efficient solution.

Why this answer

DynamoDB Auto Scaling automatically adjusts the provisioned write capacity based on traffic, preventing throttling and 503 errors from write capacity exhaustion. ECS Service Auto Scaling adds more tasks when the ALB request count increases, distributing the load. Together, they handle traffic spikes without manual intervention.

Option A is wrong because manually increasing provisioned capacity does not scale automatically, and deregistration delay does not address capacity issues. Option B is wrong because while SQS can buffer write requests, it adds complexity and latency; the question asks for graceful handling, and auto scaling addresses the root cause more directly. Option C is wrong because DAX is a cache for read operations, not write capacity.

1088
MCQmedium

A developer is using AWS CodePipeline to deploy a web application. The pipeline has a source stage that pulls from CodeCommit and a deploy stage that uses AWS Elastic Beanstalk. The developer wants to run unit tests automatically before deploying to Elastic Beanstalk. Which action should the developer add to the pipeline?

A.Add a test stage that uses an AWS CodeBuild project configured to run unit tests
B.Add a manual approval step before the deploy stage
C.Configure Elastic Beanstalk health checks to run tests
D.Replace Elastic Beanstalk with AWS CodeDeploy
AnswerA

AWS CodeBuild is specifically designed to run custom build and test commands as part of a CI/CD pipeline. By integrating a CodeBuild project into a dedicated test stage within AWS CodePipeline, developers can execute unit tests, integration tests, or even security scans against their application code in a managed compute environment. This ensures that code quality and functionality are validated automatically before proceeding to deployment, catching issues early in the development lifecycle.

Why this answer

AWS CodeBuild can be integrated as a test stage in CodePipeline to run unit tests automatically. By adding a CodeBuild project configured with a buildspec.yml file that executes unit tests, the pipeline will run tests after the source stage and before the deploy stage, ensuring only code that passes tests is deployed to Elastic Beanstalk.

Exam trap

The trap here is that candidates may confuse health checks (which monitor runtime health) with unit tests (which validate code logic), or think a manual approval step can substitute for automated testing, but AWS specifically tests the understanding that CodeBuild is the service designed for running custom build and test commands in a pipeline.

How to eliminate wrong answers

Option B is wrong because a manual approval step pauses the pipeline for human review, but does not execute unit tests automatically; it only gates deployment. Option C is wrong because Elastic Beanstalk health checks monitor the environment's operational status (e.g., HTTP response codes), not run unit tests on the application code. Option D is wrong because replacing Elastic Beanstalk with CodeDeploy does not add automated testing; CodeDeploy is a deployment service, not a test runner.

1089
MCQeasy

A developer is using AWS CodePipeline to deploy a web application. The pipeline has stages: Source, Build, Staging Deploy, Staging Test, and Prod Deploy. The developer wants to ensure that if the Staging Test stage fails, the pipeline automatically stops and does not proceed to Prod Deploy. Which action should the developer take?

A.No action is needed; CodePipeline automatically stops on stage failure
B.Add a manual approval step before Prod Deploy
C.Disable the transition from Staging Test to Prod Deploy
D.Configure the pipeline execution mode to 'Superseded'
AnswerA

AWS CodePipeline is inherently designed to halt execution when any action within a stage fails, causing the entire stage to be marked as failed. This default behavior prevents the pipeline from automatically transitioning to subsequent stages, ensuring that faulty code or configurations do not progress further into environments like staging or production. Therefore, no explicit configuration is needed to stop the pipeline on stage failure; it is a built-in safety mechanism.

Why this answer

AWS CodePipeline's default behavior is to stop execution when a stage fails, preventing the pipeline from proceeding to subsequent stages. When the Staging Test stage fails, the pipeline transitions to a 'Failed' status and does not automatically continue to Prod Deploy. No additional configuration is required for this behavior.

Exam trap

The trap here is that candidates may overthink the solution and assume additional configuration is needed, when in fact CodePipeline's default behavior already stops on stage failure, making options like manual approval or disabling transitions unnecessary.

How to eliminate wrong answers

Option B is wrong because adding a manual approval step before Prod Deploy would require human intervention to proceed, but it does not automatically stop the pipeline on Staging Test failure; the pipeline would still wait for approval even if the test failed, which is not the desired behavior. Option C is wrong because disabling the transition from Staging Test to Prod Deploy would prevent any execution to Prod Deploy, even if the Staging Test stage succeeds, which is overly restrictive and not conditional on failure. Option D is wrong because configuring the pipeline execution mode to 'Superseded' controls how multiple pipeline executions are handled (e.g., canceling a running execution when a new one starts), not how the pipeline responds to stage failures.

1090
MCQmedium

A company is using Amazon Cognito for user authentication. The developers need to add multi-factor authentication (MFA) for security. Which Cognito feature should be enabled?

A.Cognito Sync
B.Cognito User Pools with MFA configuration
C.Cognito Developer Authenticated Identities
D.Cognito Identity Pools
AnswerB

Cognito User Pools are the identity store and authentication service in Cognito, and they include a native MFA configuration option supporting SMS text message codes or TOTP authenticator apps, which can be set to off, optional, or required per user pool, directly satisfying the requirement to add MFA.

Why this answer

Amazon Cognito User Pools support multi-factor authentication (MFA) configurations, including SMS and TOTP. Option A is incorrect because Cognito Sync is used for synchronizing user data across devices, not for authentication or MFA. Option C is incorrect because Developer Authenticated Identities is a feature for custom authentication flows, not directly for enabling MFA.

Option D is incorrect because Cognito Identity Pools provide federated identities for accessing AWS resources, but MFA is configured at the User Pool level.

1091
MCQeasy

A development team wants to automatically deploy a web application to Amazon EC2 instances when new code is pushed to the master branch of an AWS CodeCommit repository. Which AWS service should the team use to orchestrate the build, test, and deployment phases?

A.AWS CloudFormation
B.AWS CodeBuild
C.AWS CodePipeline
D.AWS CodeDeploy
AnswerC

AWS CodePipeline is a fully managed continuous delivery service that automates release pipelines for rapid and reliable application and infrastructure updates. It orchestrates the entire CI/CD workflow, seamlessly integrating with various AWS services like CodeCommit for source, CodeBuild for build and test, and CodeDeploy for deployment. This comprehensive orchestration capability makes it the ideal choice for automatically deploying a web application through a defined, multi-stage pipeline.

Why this answer

AWS CodePipeline is the correct service because it is a fully managed continuous delivery service that orchestrates the entire build, test, and deployment phases as a pipeline. It can be configured to automatically trigger on code pushes to the master branch of an AWS CodeCommit repository, then invoke AWS CodeBuild for building and testing, and finally deploy to EC2 instances via AWS CodeDeploy, providing end-to-end automation.

Exam trap

The trap here is that candidates often confuse AWS CodeBuild with CodePipeline because both can be triggered by CodeCommit pushes, but CodeBuild alone cannot orchestrate multiple sequential phases like testing and deployment, which is the key requirement in the question.

How to eliminate wrong answers

Option A is wrong because AWS CloudFormation is an infrastructure-as-code service for provisioning and managing AWS resources, not for orchestrating build, test, and deployment phases triggered by code pushes. Option B is wrong because AWS CodeBuild is a fully managed build service that compiles source code, runs tests, and produces software packages, but it does not orchestrate the entire pipeline or trigger on repository events by itself. Option D is wrong because AWS CodeDeploy is a deployment service that automates application deployments to EC2 instances or other compute services, but it does not handle the build or test phases or orchestrate a multi-stage pipeline.

1092
Multi-Selecthard

A company is using AWS CodePipeline to automate its deployment pipeline. The pipeline has a source stage that pulls code from Amazon S3, a build stage using AWS CodeBuild, and a deploy stage using AWS CodeDeploy. The developer wants to add a manual approval step before deployment to production. Which of the following are correct steps to implement this? (Choose THREE.)

Select 3 answers
A.Add a second pipeline for the approval step.
B.Configure the approval action to use an SNS topic for notifications.
C.Use AWS CodeBuild to run a script that waits for manual approval.
D.Create an IAM role that allows the pipeline to publish to the SNS topic.
E.Add an approval action to the pipeline before the deploy stage.
AnswersB, D, E

When a manual approval action is configured in AWS CodePipeline, it can be integrated with Amazon SNS to send notifications to designated approvers. Upon reaching the approval stage, CodePipeline publishes a message to the specified SNS topic, which can then trigger email subscriptions or other endpoints to alert approvers. This ensures timely communication and allows approvers to access the approval console link directly from the notification, facilitating a prompt decision.

Why this answer

AWS CodePipeline approval actions can be configured to send notifications via Amazon SNS when the action requires manual approval. This allows approvers to be alerted that an approval is pending, enabling timely review and progression of the pipeline.

Exam trap

The trap here is that candidates may think a separate pipeline or a custom script is needed for manual approval, but AWS CodePipeline provides a built-in approval action that integrates directly with SNS and IAM, making those external workarounds incorrect.

1093
MCQmedium

A developer is deploying an application on Amazon ECS using the Fargate launch type. The application needs to communicate with a DynamoDB table. The developer creates a VPC with private subnets and configures the ECS service to use those subnets. However, the tasks cannot reach DynamoDB. What is the MOST likely cause?

A.The task IAM role does not have permissions to access DynamoDB.
B.The security group of the tasks does not allow outbound traffic to DynamoDB.
C.The VPC does not have a VPC endpoint for DynamoDB, and there is no NAT gateway.
D.The task definition does not have a network mode that supports DynamoDB.
AnswerC

When an ECS task runs in a private subnet, it lacks a direct route to the internet, which is necessary to reach public AWS service endpoints like DynamoDB. Without a NAT Gateway to provide outbound internet access or a VPC endpoint for DynamoDB (a Gateway Endpoint for DynamoDB specifically), the task has no network path to communicate with the DynamoDB service. This configuration prevents any successful API calls from the private subnet.

Why this answer

ECS tasks using the Fargate launch type in private subnets cannot reach public AWS services like DynamoDB unless the VPC has either a NAT gateway (to route traffic through an internet gateway) or a VPC endpoint for DynamoDB. Without one of these, the private subnets have no route to the DynamoDB API endpoints, causing connectivity failures. The IAM role and security group are configured correctly, but the network path is missing.

Exam trap

The trap here is that candidates often assume IAM permissions (Option A) are the sole cause of access failures, overlooking the network-layer requirement that private subnets need a route to public AWS services via a NAT gateway or VPC endpoint.

How to eliminate wrong answers

Option A is wrong because the task IAM role controls permissions to DynamoDB actions (e.g., GetItem, PutItem), but if the tasks cannot reach the DynamoDB endpoint at the network level, permissions are irrelevant—the request never arrives. Option B is wrong because security groups are stateful; outbound traffic is allowed by default unless explicitly denied, and DynamoDB does not require a specific outbound rule for HTTPS (port 443) since the default outbound rule allows all traffic. Option D is wrong because the network mode (e.g., awsvpc, bridge, host) does not affect the ability to reach DynamoDB; Fargate requires the awsvpc mode, which assigns an elastic network interface to each task, but this does not block outbound traffic to DynamoDB.

1094
Multi-Selectmedium

A developer is troubleshooting an issue where an IAM user cannot perform 's3:ListBucket' on a bucket. Which THREE factors could cause this denial?

Select 3 answers
A.The bucket is in a different region than the user's default region.
B.An explicit deny statement in the bucket policy.
C.The bucket is encrypted with AWS KMS.
D.The user has a permissions boundary that does not include s3:ListBucket.
E.The user's IAM policy does not include s3:ListBucket.
AnswersB, D, E

AWS IAM policy evaluation logic dictates that an explicit Deny statement always overrides any Allow statements, regardless of where the Allow is defined (e.g., in the user's identity-based policy). If the S3 bucket policy contains an explicit Deny for the s3:ListBucket action for the specific user or a group they belong to, this Deny will take precedence and prevent the user from listing the bucket's contents, even if their IAM policy allows it.

Why this answer

Option B is correct because an explicit Deny in a bucket policy always overrides any Allow in an identity-based policy, so a Deny on s3:ListBucket would block the user regardless of other permissions. Option D is correct because a permissions boundary sets the maximum permissions an IAM user can have; if s3:ListBucket is not within the boundary, the effective permissions cannot include it even if an identity policy allows it. Option E is correct because s3:ListBucket must be explicitly granted in an identity-based policy (or another applicable policy) for the user to list the bucket, and its absence results in an implicit deny.

Option A is not correct because S3 bucket access is not restricted by the user's default region; region only affects endpoint routing, not authorization. Option C is not correct because KMS encryption affects access to object data via kms:Decrypt, not the s3:ListBucket permission itself.

Exam trap

Candidates often forget that a permissions boundary acts as a maximum permission limit. If an action (like s3:ListBucket) is not explicitly allowed in the permissions boundary, the user cannot perform that action, even if their identity-based IAM policy explicitly allows it.

1095
MCQeasy

A developer has written an AWS Lambda function that processes messages from an Amazon SQS queue. The function is configured with a reserved concurrency of 5. The SQS queue has 10,000 messages waiting to be processed. What will happen when the Lambda function is invoked?

A.Lambda will automatically increase reserved concurrency to handle the load.
B.Lambda will reject the invocation because reserved concurrency is too low.
C.Lambda will scale up to 20 concurrent executions to process all messages quickly.
D.Lambda will process messages with a maximum of 5 concurrent executions, each processing a batch of messages.
AnswerD

This statement accurately describes the behavior of a Lambda function configured with reserved concurrency. The function will scale up to, but not exceed, the specified limit of 5 concurrent executions. Each of these concurrent executions will then process a batch of messages from the event source, ensuring that the processing adheres strictly to the defined concurrency constraint.

Why this answer

AWS Lambda integrates with Amazon SQS to poll the queue and invoke the function with batches of messages. The reserved concurrency of 5 caps the maximum number of concurrent executions, so Lambda will process messages with up to 5 concurrent invocations, each receiving a batch of up to 10 messages (default batch size). The remaining messages remain in the queue until they are processed or the visibility timeout expires.

Exam trap

The trap here is that candidates assume Lambda will automatically scale to handle the queue depth, but reserved concurrency is a hard limit that prevents scaling beyond the configured value, leading to throttling rather than rejection or automatic scaling.

How to eliminate wrong answers

Option A is wrong because reserved concurrency is a hard limit that Lambda cannot automatically increase; it must be manually adjusted or removed. Option B is wrong because Lambda does not reject invocations due to low reserved concurrency; it simply throttles the function, and unprocessed messages remain in the SQS queue. Option C is wrong because Lambda cannot scale beyond the reserved concurrency of 5, regardless of the number of messages in the queue.

1096
Multi-Selecthard

A company is deploying a microservices architecture using AWS Lambda and Amazon API Gateway. The developer wants to implement a canary release deployment for the API. Which THREE steps should the developer take? (Choose THREE.)

Select 3 answers
A.Configure stage variables to point the canary stage to a different Lambda function alias.
B.Enable canary by setting the traffic percentage in the API Gateway stage.
C.Use API Gateway canary release settings to create a canary stage.
D.Use Amazon CloudFront to distribute traffic between two API Gateway stages.
E.Use Lambda canary releases to gradually shift traffic.
AnswersA, B, C

Configuring stage variables within the API Gateway canary stage is the precise mechanism to direct a portion of incoming requests to a specific Lambda function alias, representing the new version of the backend service. This allows the canary stage to dynamically resolve the target Lambda version, ensuring that only the designated traffic percentage interacts with the updated code. It's fundamental for separating the base deployment from the experimental one.

Why this answer

Stage variables in API Gateway can be configured to point the canary stage to a different Lambda function alias, enabling the canary to invoke a separate version of the function for testing. This allows the canary to route a percentage of traffic to a new Lambda version while the main stage continues using the stable alias, supporting gradual rollouts.

Exam trap

The trap here is that candidates may confuse Lambda alias weighted routing (Option E) with API Gateway canary releases, but the question explicitly asks for API-level canary deployment, which requires API Gateway's native canary settings, not just Lambda-level traffic shifting.

1097
MCQeasy

A developer is deploying a Docker container to Amazon ECS using the Fargate launch type. The developer wants to ensure the container has access to an Amazon RDS database. What is the best way to securely pass the database credentials to the container?

A.Pass the credentials as plain text environment variables in the task definition.
B.Store the credentials in an Amazon S3 bucket and download them at container startup.
C.Store the credentials in the container image as environment variables.
D.Use AWS Systems Manager Parameter Store or AWS Secrets Manager to store the credentials and reference them in the task definition.
AnswerD

Utilizing AWS Systems Manager Parameter Store or AWS Secrets Manager for credential storage is the recommended secure practice for Amazon ECS. Both services encrypt secrets at rest and in transit, provide robust IAM-based access control, and integrate seamlessly with ECS task definitions to inject secrets at runtime. This method ensures credentials are never exposed in plain text within the task definition or container image, leveraging the task's IAM role for secure, on-demand retrieval and supporting features like automatic rotation with Secrets Manager.

Why this answer

AWS Systems Manager Parameter Store and AWS Secrets Manager are designed to securely store and manage sensitive information like database credentials. In Amazon ECS with Fargate, you can reference these secrets directly in the task definition using the 'secrets' parameter, which injects them as environment variables at runtime without exposing them in plain text or requiring additional code to fetch them. This approach adheres to the principle of least privilege and integrates natively with IAM roles for secure access.

Exam trap

The trap here is that candidates may think environment variables are inherently secure or that storing credentials in S3 is a safe alternative, overlooking the native integration and security guarantees of AWS Secrets Manager and Parameter Store for ECS tasks.

How to eliminate wrong answers

Option A is wrong because passing credentials as plain text environment variables in the task definition exposes them in the ECS console, API responses, and logs, violating security best practices. Option B is wrong because downloading credentials from an S3 bucket at container startup requires storing AWS access keys in the container or granting broad S3 permissions, and the credentials could be exposed in transit or logs; it also adds unnecessary complexity and latency. Option C is wrong because embedding credentials in the container image as environment variables makes them accessible to anyone with access to the image registry and prevents rotation without rebuilding the image, violating immutable infrastructure principles.

1098
MCQmedium

A team uses AWS CodeCommit for source control and wants to automatically trigger a build and deployment when code is pushed to the master branch. Which AWS service should be used to create this automation?

A.AWS CodeBuild
B.AWS CodePipeline
C.AWS Lambda
D.AWS CodeDeploy
AnswerB

AWS CodePipeline is a fully managed continuous delivery service that automates release pipelines for fast and reliable application and infrastructure updates. It seamlessly integrates with AWS CodeCommit as a primary source stage, automatically detecting code changes (e.g., pushes to a specific branch) and initiating the entire pipeline workflow. CodePipeline orchestrates subsequent stages like build, test, and deploy using other AWS services, making it the ideal choice for end-to-end CI/CD.

Why this answer

AWS CodePipeline is the correct service because it is a fully managed continuous delivery service that can be configured to automatically start a pipeline execution when a change is pushed to a specific branch in AWS CodeCommit. By setting the source stage to the CodeCommit repository and master branch, CodePipeline triggers subsequent build and deploy actions without manual intervention, enabling a complete CI/CD workflow.

Exam trap

The trap here is that candidates confuse individual services (CodeBuild for building, CodeDeploy for deploying) with the orchestration service (CodePipeline) needed to chain them together in response to a source code event.

How to eliminate wrong answers

Option A is wrong because AWS CodeBuild is a build service that compiles source code and runs tests, but it does not have native event-driven triggers to automatically start on a CodeCommit push; it requires an external trigger like CodePipeline or a webhook. Option C is wrong because AWS Lambda can be used to react to CodeCommit events via CloudWatch Events or SNS, but it is not a purpose-built CI/CD service and would require custom code to orchestrate build and deployment steps, making it less suitable than CodePipeline. Option D is wrong because AWS CodeDeploy is a deployment service that automates application deployments to compute services like EC2 or Lambda, but it cannot directly listen to CodeCommit push events or orchestrate a build step; it relies on a pipeline or other trigger to initiate deployments.

1099
MCQmedium

A developer is building a REST API using Amazon API Gateway and wants to transform the request data before sending it to the backend Lambda function. The transformation includes mapping query string parameters to a JSON body. Which API Gateway feature should be used?

A.Velocity Template Language (VTL) mapping templates
B.Lambda authorizer
C.Request validator
D.CORS configuration
AnswerA

Velocity Template Language (VTL) mapping templates are a core feature within API Gateway's integration request and response stages. They enable the transformation of incoming client request payloads and outgoing backend responses into formats compatible with the integration. This includes converting query string parameters, path parameters, or headers into a structured JSON body, or vice-versa, making them essential for adapting data formats between client and backend services.

Why this answer

API Gateway uses Velocity Template Language (VTL) mapping templates to transform incoming request data, such as mapping query string parameters into a JSON body before passing it to the backend Lambda function. This feature allows you to define a template that extracts values from the request's query string parameters (e.g., `$input.params('paramName')`) and constructs a new JSON payload, enabling seamless integration with Lambda without modifying the client request.

Exam trap

The trap here is that candidates often confuse request validation (Option C) with data transformation, assuming that validating the request structure also implies the ability to reshape the data, but validation only checks for presence and format, not mapping or transformation.

How to eliminate wrong answers

Option B is wrong because a Lambda authorizer is used for custom authentication and authorization of API requests, not for transforming request data or mapping parameters to a JSON body. Option C is wrong because a request validator only validates that the request adheres to the API's defined schema (e.g., required parameters, types), but it does not perform any data transformation or mapping. Option D is wrong because CORS configuration manages cross-origin resource sharing headers (e.g., Access-Control-Allow-Origin) to allow browser-based clients from different domains, and it has no role in transforming request payloads or mapping query string parameters.

1100
MCQhard

A company has a production application running on AWS Lambda that processes real-time streaming data from Amazon Kinesis Data Streams. The Lambda function is configured with a batch size of 100 and a maximum concurrency of 5. Recently, the application has been experiencing failures with a high number of invocation errors. The errors indicate that the function is timing out. The developer checks the CloudWatch metrics and notices that the IteratorAge metric for the Kinesis stream is increasing rapidly, and there are many Throttles events for the Lambda function. The average execution duration of the function is 30 seconds, and the function timeout is set to 1 minute. The Kinesis stream has 10 shards. The company expects the data volume to double in the next month. Which combination of actions should the developer take to resolve the issue and prepare for future growth?

A.Increase the number of shards in the Kinesis stream to 20 and increase Lambda concurrency to 10.
B.Increase Lambda concurrency to at least 20 and reduce the batch size to 10.
C.Disable the reserved concurrency limit on the Lambda function and decrease the batch size to 5.
D.Increase the Lambda function timeout to 5 minutes and increase the batch size to 500.
AnswerB

Increasing Lambda concurrency to at least 20 allows the function to process more batches in parallel, effectively utilizing the Kinesis stream's capacity and reducing event backlog. Simultaneously, reducing the batch size to 10 records per invocation decreases the processing time for each individual invocation, making the function more efficient and less prone to timeouts, thereby improving overall throughput and mitigating throttling.

Why this answer

The Lambda function is throttled because the maximum concurrency of 5 is too low for 10 shards. With a batch size of 100 and average duration of 30 seconds, each batch takes too long, leading to timeouts and increasing IteratorAge. Increasing concurrency to at least 20 (2 per shard) allows processing of all shards in parallel.

Reducing batch size to 10 reduces the processing time per batch, helping avoid timeouts. Option A is wrong because increasing shards without increasing concurrency would worsen throttling. Option C is wrong because disabling reserved concurrency could lead to uncontrolled scaling, but the main issue is concurrency and batch size; also decreasing batch size to 5 may be too small and inefficient.

Option D is wrong because increasing timeout and batch size would not resolve throttling and would increase latency.

1101
MCQmedium

A developer invokes an AWS Lambda function and receives a timeout error. The function is configured with a 3-second timeout. The developer needs to process data that sometimes takes up to 10 seconds. What should the developer do?

A.Change the invocation type to Event (async).
B.Increase the Lambda function timeout to 10 seconds.
C.Increase the memory allocation for the Lambda function.
D.Set reserved concurrency to 1.
AnswerB

The Lambda function timeout setting directly controls the maximum amount of time a function is allowed to execute before the AWS Lambda service forcibly terminates it. If a function is consistently timing out, it indicates that its current execution duration exceeds the configured limit. Increasing this timeout value to 10 seconds directly addresses the problem by providing the function with sufficient time to complete its operations successfully, preventing premature termination.

Why this answer

The error indicates the Lambda function is timing out because its configured timeout of 3 seconds is insufficient for processing that sometimes takes up to 10 seconds. Option B directly addresses this by increasing the timeout to 10 seconds, which is within the maximum Lambda timeout of 15 minutes (900 seconds). This ensures the function can complete its execution without being prematurely terminated.

Exam trap

The trap here is that candidates may confuse increasing memory (which can improve performance but does not extend the timeout) with solving a timeout error, or incorrectly assume that changing the invocation type to async will allow the function to run longer.

How to eliminate wrong answers

Option A is wrong because changing the invocation type to Event (async) does not increase the execution time available to the function; it only changes how the function is triggered, and the function would still time out after 3 seconds. Option C is wrong because increasing memory allocation can improve CPU performance and potentially reduce execution time, but it does not guarantee that the function will finish within 3 seconds if the data processing inherently requires up to 10 seconds; the timeout must be increased. Option D is wrong because setting reserved concurrency to 1 limits the number of concurrent executions but does not affect the function's timeout duration, so the function would still fail with a timeout error.

1102
Multi-Selecthard

A developer is building a real-time chat application using WebSocket APIs in API Gateway and Lambda. The application must handle thousands of concurrent connections. Which TWO actions should the developer take to ensure the application scales properly?

Select 2 answers
A.Use CloudFront to distribute the WebSocket endpoints.
B.Place the Lambda function in a VPC to improve security.
C.Enable API Gateway caching to reduce Lambda invocations.
D.Set the Lambda function's reserved concurrency to a high enough value.
E.Use a DynamoDB table to store connection IDs and handle connection state.
AnswersD, E

For a real-time chat application, sudden bursts of user activity can lead to a large volume of concurrent Lambda invocations. Setting a high enough reserved concurrency guarantees that a specified number of execution environments are always available exclusively for this specific Lambda function, preventing it from being throttled by the account's unreserved concurrency pool. This ensures the function can consistently process messages and maintain responsiveness even during peak load, which is critical for delivering a smooth and reliable real-time chat experience.

Why this answer

Setting reserved concurrency ensures the Lambda function has enough allocated capacity to handle the high volume of concurrent WebSocket connections without being throttled by the account-level concurrency limit. Without reserved concurrency, the function could experience throttling errors (HTTP 429) during traffic spikes, causing dropped connections and poor user experience.

Exam trap

A common pitfall is assuming CloudFront can help scale WebSocket APIs for concurrent connections. While CloudFront does support WebSocket connections, it does not address the backend Lambda scaling or state management required for thousands of connections. The correct scaling actions are setting reserved concurrency for the Lambda function and storing connection IDs in DynamoDB for state management.

Similarly, enabling API Gateway caching or placing Lambda in a VPC do not solve the concurrency scaling issue.

1103
MCQeasy

A developer wants to deploy a containerized application to Amazon ECS using Fargate. The application requires persistent storage that can be shared across multiple containers in the same task. Which storage option should the developer use?

A.Amazon EC2 instance store
B.Amazon EFS file system
C.Amazon S3 bucket
D.Amazon EBS volume
AnswerB

Amazon EFS (Elastic File System) provides scalable, elastic, shared file storage that can be accessed concurrently by multiple AWS Fargate tasks. It offers persistent storage, ensuring data remains available even if containers are stopped, replaced, or scaled. This makes EFS an excellent choice for containerized applications requiring shared state, persistent data, or a common file system across different application instances running on Fargate.

Why this answer

Amazon EFS provides a shared, persistent, and scalable file system that can be mounted by multiple containers within the same ECS task using Fargate. EFS supports the Network File System (NFS) protocol, allowing concurrent read/write access from all containers in the task, which meets the requirement for shared persistent storage. Unlike ephemeral or block storage options, EFS is designed for multi-attach scenarios and persists independently of the container lifecycle.

Exam trap

The trap here is that candidates often confuse Amazon EBS with a shared storage solution, but EBS volumes cannot be attached to multiple Fargate containers or tasks simultaneously, making EFS the only correct choice for shared persistent storage in this context.

How to eliminate wrong answers

Option A is wrong because Amazon EC2 instance store provides ephemeral block storage that is tied to the lifecycle of an EC2 instance, not a Fargate task, and cannot be shared across multiple containers. Option C is wrong because Amazon S3 is an object storage service accessed via HTTP/HTTPS APIs, not a file system mountable via NFS, and does not provide the POSIX-compliant shared file system required for concurrent container access. Option D is wrong because Amazon EBS volumes are block-level storage that can only be attached to a single EC2 instance at a time (unless using multi-attach EBS, which is not supported with Fargate), and cannot be shared across multiple containers in the same Fargate task.

1104
MCQeasy

A developer needs to allow an IAM user to stop and start EC2 instances but not terminate them. Which IAM policy effect and action combination should be used?

A.Allow ec2:StopInstances and ec2:StartInstances
B.Allow ec2:StopInstances, ec2:StartInstances, and ec2:TerminateInstances
C.Deny ec2:TerminateInstances
D.Allow ec2:StartInstances and ec2:TerminateInstances
AnswerA

Granting only ec2:StartInstances and ec2:StopInstances gives the IAM user exactly the actions needed to power instances on and off while omitting ec2:TerminateInstances entirely, so any attempt to terminate an instance is implicitly denied by IAM's default-deny behavior, satisfying the requirement precisely.

Why this answer

It explicitly allows ec2:StopInstances and ec2:StartInstances, which grants the needed permissions without allowing ec2:TerminateInstances. Option B is incorrect because it includes ec2:TerminateInstances, which would allow termination, contrary to the requirement. Option C is incomplete: although it denies ec2:TerminateInstances, it does not allow ec2:StopInstances or ec2:StartInstances, so the user would not have the required start/stop permissions.

Option D is incorrect because it allows ec2:TerminateInstances.

1105
MCQmedium

A developer is using AWS Elastic Beanstalk to deploy a web application. The application needs to store session state. Which configuration is MOST cost-effective and scalable?

A.Use S3 to store session state
B.Use an ElastiCache Memcached cluster
C.Use an RDS database to store session state
D.Store session state in the local file system of each EC2 instance
AnswerB

An ElastiCache Memcached cluster provides a highly scalable, in-memory key-value store perfectly suited for transient session state. Its distributed nature allows multiple EC2 instances in an Elastic Beanstalk environment to access shared session data with very low latency. This ensures user sessions persist even if requests are routed to different instances by a load balancer, enhancing application scalability and user experience.

Why this answer

ElastiCache Memcached is the most cost-effective and scalable solution for storing session state because it is an in-memory cache designed for low-latency access, which is ideal for session data that must be frequently read and written. It scales horizontally by adding nodes, and its distributed nature ensures that session data persists across EC2 instance replacements, unlike local storage. This avoids the higher cost and overhead of RDS or the latency and eventual consistency issues of S3 for session management.

Exam trap

The trap here is that candidates often choose local file system storage (D) because it seems simplest and free, overlooking that it fails in auto-scaling environments where instances are ephemeral and session data is not shared.

How to eliminate wrong answers

Option A is wrong because S3 is an object store with higher latency and eventual consistency, making it unsuitable for session state that requires fast, consistent reads and writes; it also incurs per-request costs that can become expensive under high traffic. Option C is wrong because RDS is a relational database with higher cost and operational overhead (e.g., provisioning, scaling, backups) compared to an in-memory cache, and it is overkill for simple key-value session data. Option D is wrong because storing session state in the local file system of each EC2 instance breaks when instances are replaced or scaled out, as session data is not shared across instances, leading to data loss and poor scalability.

1106
Multi-Selecthard

A company uses Amazon API Gateway to expose a REST API backed by AWS Lambda. The API has a resource /items with GET and POST methods. The GET method returns items from a DynamoDB table. The POST method adds an item to the table. Currently, all methods are open to the public. Security requirements mandate that only authenticated users can access the POST method, while the GET method remains public. Which THREE steps should the developer take to meet these requirements?

Select 3 answers
A.Configure the Lambda authorizer only on the POST method in the API Gateway.
B.Create a Lambda function as an authorizer that validates a JWT token from the Authorization header.
C.In the Lambda authorizer, return an IAM policy that allows execute-api:Invoke on the POST method.
D.Use an Amazon Cognito User Pools authorizer for the entire API.
E.Add a resource policy that denies public access to the POST method.
AnswersA, B, C

API Gateway allows authorizers to be configured at the method level, providing fine-grained access control. By attaching the Lambda authorizer specifically to the POST method, the company ensures that only requests targeting this particular method are subjected to the custom authorization logic, while other methods remain unaffected or use different authorization mechanisms. This meets the requirement to secure only the POST method.

Why this answer

You can configure a Lambda authorizer at the method level in API Gateway, which allows you to selectively secure only the POST method while leaving the GET method public. This meets the requirement of restricting access to authenticated users for POST only, without affecting the public GET endpoint.

Exam trap

The trap here is that candidates often assume a resource policy can be used to selectively restrict methods, but resource policies apply at the API or stage level, not at the individual method level, making them unsuitable for this granular requirement.

1107
Multi-Selecthard

A Lambda function processes messages from an SQS standard queue and writes results to DynamoDB. Duplicate writes occasionally occur after retries. Which two changes best make the processing idempotent?

Select 2 answers
A.Use a deterministic idempotency key stored with a conditional write in DynamoDB
B.Increase the Lambda timeout to 15 minutes
C.Treat the SQS message ID or business transaction ID as a processed-record key
D.Disable SQS visibility timeout
AnswersA, C

SQS Standard queues provide at-least-once delivery, meaning messages can be delivered multiple times. Implementing idempotency is crucial to prevent duplicate processing side effects. By generating a deterministic key (e.g., from the SQS message ID or a business transaction ID) and storing it in DynamoDB with a conditional write (e.g., using `attribute_not_exists`), the Lambda function ensures that the operation only proceeds if the key hasn't been recorded before, making the operation safe for retries and preventing unintended state changes.

Why this answer

Using a deterministic idempotency key (e.g., a business transaction ID) combined with a conditional write in DynamoDB ensures that if the same message is processed more than once, the second write attempt will fail because the item already exists. This prevents duplicate records even when Lambda retries after a failure or timeout, making the processing idempotent at the database level.

Exam trap

The trap here is that candidates often confuse idempotency with simply increasing timeouts or disabling visibility timeouts, not realizing that idempotency requires a deterministic key and a conditional check at the storage layer.

1108
MCQeasy

A developer wants to store session state for a web application that runs on multiple EC2 instances behind an Application Load Balancer. Which AWS service should the developer use to store the session state in a centralized, highly available location?

A.Amazon RDS
B.Amazon S3
C.Amazon ElastiCache
D.AWS Lambda
AnswerC

Amazon ElastiCache is a fully managed in-memory caching service, offering high-performance, low-latency data retrieval using Redis or Memcached engines. It is specifically designed for use cases like session state management, where rapid access to frequently changing, ephemeral key-value data is critical. Its in-memory nature significantly reduces I/O latency compared to disk-based solutions, ensuring a responsive user experience and easily scaling to handle high request volumes.

Why this answer

Amazon ElastiCache is the correct choice because it provides a managed, in-memory caching service that supports Redis or Memcached, which are ideal for storing session state in a centralized, highly available manner. Session data requires low-latency reads and writes, and ElastiCache offers sub-millisecond performance, replication across multiple Availability Zones, and automatic failover, making it suitable for stateless web applications behind an Application Load Balancer.

Exam trap

The trap here is that candidates mistakenly choose Amazon RDS for session storage due to its familiarity with databases, overlooking that session state is transient and requires low-latency access, which ElastiCache's in-memory architecture provides far more efficiently.

How to eliminate wrong answers

Option A is wrong because Amazon RDS is a relational database service designed for persistent, structured data with ACID compliance, not for transient session state; its higher latency and connection overhead make it suboptimal for frequent session reads/writes. Option B is wrong because Amazon S3 is an object storage service with eventual consistency for read-after-write in some cases, and its higher latency (typically tens of milliseconds) and lack of native session expiration mechanisms make it unsuitable for real-time session state management. Option D is wrong because AWS Lambda is a serverless compute service for running code in response to events, not a data store; it cannot natively persist session state across invocations without an external storage layer like ElastiCache or DynamoDB.

1109
MCQhard

A developer is deploying an application using AWS CloudFormation. The template includes an AWS::Lambda::Function resource. The developer wants to ensure that the Lambda function's code is automatically updated when the source code in S3 changes. Which approach should the developer use?

A.Specify the S3 object version in the template and update the version number in the template when code changes.
B.Use the AWS::Lambda::Version resource to create a new version.
C.Include the S3 bucket and key as template parameters and update the stack with a new key when code changes.
D.Use a custom resource backed by a Lambda function that polls S3 for changes.
AnswerA

When a Lambda function's code is sourced from S3, CloudFormation monitors the S3ObjectVersion property within the Code block of the AWS::Lambda::Function resource. By explicitly including the S3 object's version ID in the template and updating this ID upon each code change, CloudFormation detects a modification to the resource's properties. This change then triggers an update to the Lambda function, ensuring the new code is deployed efficiently and reliably.

Why this answer

AWS CloudFormation detects changes to the `AWS::Lambda::Function` resource's `Code` property only when the properties defined in the template (such as `S3Key` or `S3ObjectVersion`) change. If you upload a new deployment package to S3 using the same bucket and key, CloudFormation will not detect any change and will not update the Lambda function. To resolve this, you should enable S3 Versioning on the bucket, specify the `S3ObjectVersion` in the CloudFormation template, and update this version parameter in the template whenever the code is updated.

Exam trap

Candidates often assume that simply uploading a new deployment package to the same S3 bucket and key will automatically trigger a Lambda update during a CloudFormation stack update. However, CloudFormation does not inspect the contents or hash of the S3 object; it only checks if the template properties themselves have changed. Therefore, you must either change the S3 key or use S3 object versioning and update the version in the template.

How to eliminate wrong answers

Option B is wrong because AWS::Lambda::Version creates a new version of the Lambda function but does not automatically update the function code when the source changes; it only publishes a version of the existing code. Option C is wrong because changing the S3 key alone (without specifying the S3 object version) does not guarantee CloudFormation detects the code change, as CloudFormation compares the S3 object version, not the key, to determine if an update is needed. Option D is wrong because using a custom resource backed by a Lambda function that polls S3 for changes is unnecessarily complex and not the recommended approach; CloudFormation's native S3 object versioning mechanism is the correct and simpler solution.

1110
MCQeasy

A company is using AWS CloudFormation to deploy infrastructure. The developer wants to update a stack and needs to know what changes will be made before executing the update. Which AWS CLI command should the developer use?

A.aws cloudformation deploy
B.aws cloudformation create-change-set
C.aws cloudformation validate-template
D.aws cloudformation update-stack
AnswerB

Correct. The aws cloudformation create-change-set command creates a change set, which is a summary of proposed changes to a CloudFormation stack. This allows the developer to review what resources will be added, modified, or deleted before executing the update, without making any actual changes.

Why this answer

The `aws cloudformation create-change-set` command creates a change set, which is a summary of proposed changes to a CloudFormation stack. This allows the developer to review what resources will be added, modified, or deleted before executing the update, without making any actual changes. The change set can then be executed with `aws cloudformation execute-change-set` to apply the changes.

Exam trap

The trap here is that candidates often confuse `aws cloudformation update-stack` with a preview command, but it directly applies changes, whereas `create-change-set` is the correct command for reviewing changes before execution.

How to eliminate wrong answers

Option A is wrong because `aws cloudformation deploy` is used to deploy a stack or update an existing stack directly, but it does not provide a preview of changes before execution; it applies changes immediately. Option C is wrong because `aws cloudformation validate-template` only checks the syntax and structure of a CloudFormation template, not the impact of changes on an existing stack. Option D is wrong because `aws cloudformation update-stack` directly updates the stack without offering a preview of the changes, making it unsuitable for reviewing changes beforehand.

1111
MCQmedium

A developer is using AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment fails during the 'BeforeInstall' lifecycle event. Which file should the developer check to debug the failure?

A.index.js
B.appspec.yml
C.taskdef.json
D.buildspec.yml
AnswerB

The appspec.yml file is central to AWS CodeDeploy, serving as the deployment specification. It explicitly defines the source files to be deployed, their destination on the target instance, and, critically, the lifecycle event hooks. Within these hooks, the appspec.yml specifies which scripts CodeDeploy should execute at each stage, such as BeforeInstall, AfterInstall, ApplicationStart, and ValidateService. Failures during these script executions directly manifest as lifecycle hook failures, making appspec.yml the primary configuration for managing deployment scripts and their outcomes.

Why this answer

The 'BeforeInstall' lifecycle event in AWS CodeDeploy is a hook defined in the appspec.yml file. This file specifies the deployment lifecycle hooks, including scripts to run before installation. When a deployment fails during this event, the appspec.yml is the primary file to inspect for misconfigured scripts, incorrect permissions, or missing script paths.

Exam trap

The trap here is that candidates confuse the deployment configuration file (appspec.yml) with build configuration files (buildspec.yml) or application code files (index.js), leading them to check the wrong file for deployment lifecycle failures.

How to eliminate wrong answers

Option A is wrong because index.js is a JavaScript application file, not a deployment configuration file; CodeDeploy does not read index.js for lifecycle events. Option C is wrong because taskdef.json is used by Amazon ECS to define task definitions, not by CodeDeploy for EC2/on-premises deployments. Option D is wrong because buildspec.yml is used by AWS CodeBuild to define build commands, not by CodeDeploy for deployment lifecycle hooks.

1112
MCQmedium

A developer is troubleshooting a CloudFront distribution that serves static content from an S3 bucket. Users in some geographic locations report slow load times. The developer checks the CloudFront metrics and sees a high number of cache misses. What is the MOST likely cause?

A.The CloudFront distribution is configured with Price Class 100, which uses only the US and Europe edge locations.
B.The S3 bucket is configured with signed URLs for access.
C.The CloudFront distribution is not configured to compress objects.
D.The object TTL is set to a very low value (e.g., 0 seconds).
AnswerD

Setting an object's Time To Live (TTL) to a very low value, such as 0 seconds, explicitly instructs CloudFront to either not cache the object at all or to revalidate it with the origin for virtually every subsequent request. This configuration directly prevents CloudFront from effectively serving content from its edge caches, forcing each user request to reach the origin. Consequently, this results in a consistently high cache miss ratio, significantly degrading performance and increasing origin load.

Why this answer

A very low or zero TTL (e.g., 0 seconds) causes CloudFront to treat every request as a cache miss, forcing it to fetch the object from S3 on each request. This increases latency for users, especially in distant geographic locations, because the edge location must repeatedly retrieve the object from the origin. Setting a reasonable TTL allows edge locations to serve cached content and reduces origin fetches.

Exam trap

DVA-C02 often tests the confusion between cache misses and latency causes — candidates blame Price Class or compression for high miss rates, when the real driver is a TTL of 0 or a no-cache origin header.

How to eliminate wrong answers

Option A is wrong because Price Class 100 only limits which edge locations are used (US, Canada, Europe); while it can affect latency for users outside those regions, it does not cause a high number of cache misses — the metric would show high latency, not high miss rate. Option B is wrong because signed URLs control access authorization, not cacheability; CloudFront can cache responses to signed URL requests as long as the cache key and TTL allow it. Option C is wrong because compression reduces payload size and improves transfer speed but does not affect whether an object is cached or the cache hit ratio.

1113
MCQhard

An S3 bucket policy allows GetObject from another account, but objects encrypted with SSE-KMS still return AccessDenied. Which additional authorization is required?

A.The caller must be allowed to use the KMS key for decrypt operations
B.The caller must own the destination VPC
C.The bucket must enable static website hosting
D.The object key must end with .kms
AnswerA

When an S3 object is encrypted using Server-Side Encryption with AWS KMS (SSE-KMS), the requesting principal requires explicit kms:Decrypt permissions on the associated KMS key. Even if the S3 bucket policy grants s3:GetObject to another account, the cross-account caller cannot retrieve the object's plaintext data without the necessary KMS key usage permissions. This dual authorization ensures robust data protection by separating storage access from encryption key access.

Why this answer

When an S3 object is encrypted with SSE-KMS, the S3 bucket policy granting GetObject access is not sufficient because S3 must also decrypt the object before returning it. The AWS KMS key policy must grant the caller kms:Decrypt permission, and the caller's IAM policy must also allow kms:Decrypt on the specific KMS key. Without this additional KMS authorization, S3 returns AccessDenied even if the bucket policy allows GetObject.

Exam trap

The trap here is that candidates assume a bucket policy granting s3:GetObject is sufficient for all objects, forgetting that SSE-KMS adds a separate authorization layer via KMS key policies that must explicitly allow the decrypt operation.

How to eliminate wrong answers

Option B is wrong because VPC ownership is irrelevant to S3 object access; S3 bucket policies and KMS permissions control cross-account access, not network ownership. Option C is wrong because static website hosting is a feature for serving public content and has no bearing on KMS-encrypted object access or cross-account authorization. Option D is wrong because the object key suffix has no effect on KMS authorization; SSE-KMS encryption is determined by the object's encryption settings, not its filename.

1114
Multi-Selecteasy

Which TWO are features of AWS Identity and Access Management (IAM)? (Choose 2)

Select 2 answers
A.Encrypt S3 objects automatically
B.Monitor network traffic
C.Define fine-grained permissions with policies
D.Manage EC2 instance lifecycle
E.Create and manage IAM users and groups
AnswersC, E

IAM policies are the core mechanism for defining fine-grained permissions. You can craft JSON-based identity policies that specify exactly which actions are allowed or denied on which resources, under what conditions (e.g., source IP, MFA presence, time of day). This allows least-privilege access control at the resource and API-action level, central to IAM's purpose.

Why this answer

Option C is correct because IAM's core purpose is to define fine-grained permissions using JSON policy documents that specify which principals can perform which actions on which resources under which conditions. Option E is correct because IAM natively provides identity management, allowing you to create and manage IAM users, groups, and roles, and attach policies to them for access control. Option A is incorrect because automatic S3 object encryption is a feature of Amazon S3 (e.g., SSE-S3, SSE-KMS, or default bucket encryption), not IAM.

Option B is incorrect because network traffic monitoring is handled by services such as VPC Flow Logs, CloudWatch, or GuardDuty, not IAM. Option D is incorrect because EC2 instance lifecycle management is performed through EC2, Auto Scaling, or EC2 Instance Lifecycle policies, not IAM.

Exam trap

DVA-C02 often tests the misconception that IAM performs encryption or network monitoring, when IAM is strictly an identity and access control service — encryption and traffic monitoring belong to KMS/S3 and VPC Flow Logs/GuardDuty respectively.

1115
MCQeasy

A developer is building a serverless API using Amazon API Gateway and AWS Lambda. The API accepts JSON payloads in the request body. The developer wants to ensure that incoming requests have a valid structure before being passed to the Lambda function to reduce unnecessary invocations. Which API Gateway feature should the developer use?

A.Request validation using models and request validators
B.Usage plans with API keys
C.WAF (AWS WAF) integration
D.Custom authorizer (Lambda authorizer)
AnswerA

API Gateway's request validation feature directly addresses the need to validate the structure and data types of incoming request payloads. By defining a Model, which is essentially a JSON schema, and associating it with a Method's request body, API Gateway automatically checks the request against this schema. Invalid requests, such as those with missing required fields or incorrect data types, are rejected with a 400 Bad Request error *before* the request reaches the backend integration, significantly reducing unnecessary Lambda invocations and operational costs.

Why this answer

API Gateway's request validation feature allows you to define a JSON Schema model for the request body and attach a request validator to the method. This validates the payload structure before the request reaches the Lambda function, preventing invalid payloads from triggering unnecessary invocations and reducing costs.

Exam trap

The trap here is that candidates confuse request validation (payload structure checking) with authorization (who can call the API) or security filtering (WAF), leading them to pick a wrong option like custom authorizer or WAF integration.

How to eliminate wrong answers

Option B is wrong because usage plans with API keys control rate limiting and quota management for API consumers, not payload structure validation. Option C is wrong because AWS WAF integration protects against web exploits like SQL injection or cross-site scripting at the HTTP layer, not JSON schema validation. Option D is wrong because a custom authorizer (Lambda authorizer) authenticates and authorizes the caller (e.g., via OAuth or JWT), but does not validate the request body's structure or content.

1116
MCQeasy

The exhibit shows the output of a command. What does this output indicate about the bucket?

A.Versioning is enabled, and MFA delete is required
B.Versioning is suspended
C.Versioning is disabled
D.Versioning is enabled, and MFA delete is not required
AnswerD

This option is correct. The exhibit output confirms that S3 Versioning is `Enabled` for the bucket, which means multiple versions of an object are retained, safeguarding against accidental overwrites or deletions. Furthermore, the output explicitly states that `MFADelete` is `Disabled`, indicating that a multi-factor authentication token is not required to permanently delete an object version or change the bucket's versioning state.

Why this answer

The command output shows `MFA Delete: disabled` and `Versioning: Enabled`. This directly indicates that versioning is enabled on the bucket, but MFA delete is not required. Option D is correct because it matches both displayed fields exactly.

Exam trap

The trap here is that candidates often confuse the `Versioning: Enabled` field with the MFA delete status, incorrectly assuming that versioning being enabled automatically means MFA delete is also enabled, but the two settings are independent.

How to eliminate wrong answers

Option A is wrong because the output explicitly shows `MFA Delete: disabled`, not `enabled`. Option B is wrong because the output shows `Versioning: Enabled`, not `Suspended`. Option C is wrong because the output shows `Versioning: Enabled`, not `Disabled`.

1117
MCQmedium

An application running on Amazon EC2 instances behind an Application Load Balancer (ALB) is experiencing increased latency. The developer suspects the ALB is the bottleneck. How can the developer confirm this using CloudWatch metrics?

A.Monitor the HealthyHostCount metric and ensure it is equal to the number of instances.
B.Monitor the SurgeQueueLength metric and look for sustained high values.
C.Monitor the TargetResponseTime metric and compare it to the client's perspective.
D.Monitor the RequestCount metric and check if it exceeds the ALB's limit.
AnswerC

The TargetResponseTime metric measures the time elapsed from when the Application Load Balancer (ALB) sends a request to a registered target until the target responds. While important for understanding backend performance, this metric only accounts for the time after the request leaves the ALB. It does not include any potential delays or queuing time the request might experience within the ALB before being forwarded, thus not fully representing the client's total perceived latency.

Why this answer

To determine if the ALB or the backend targets are causing the latency, the developer should monitor the 'TargetResponseTime' metric. This metric measures the time elapsed (in seconds) from when the request leaves the ALB until a response from the target is received. If 'TargetResponseTime' is low but the client-side latency is high, the bottleneck lies within the ALB itself or the network.

If 'TargetResponseTime' is high, the bottleneck is the backend EC2 instances. 'SurgeQueueLength' is a Classic Load Balancer metric and is not available on ALBs.

Exam trap

AWS frequently tests your ability to distinguish between Classic Load Balancer (CLB) metrics (like SurgeQueueLength and SpilloverCount) and Application Load Balancer (ALB) metrics (like TargetResponseTime). Remember that ALBs do not have a request queue metric.

How to eliminate wrong answers

Option A is wrong because HealthyHostCount only indicates the number of registered instances that pass health checks; it does not measure ALB load or queuing, so it cannot confirm the ALB as the bottleneck. Option C is wrong because TargetResponseTime measures the time taken by the backend targets to respond, not the ALB's internal processing or queuing delay; comparing it to client-perceived latency would highlight backend issues, not ALB overload. Option D is wrong because RequestCount alone does not have a fixed 'limit' that triggers latency; ALBs scale automatically based on request load, and exceeding a limit would cause errors, not necessarily increased latency.

1118
Multi-Selectmedium

Which THREE components are required to enable encryption in transit for an Application Load Balancer? (Choose THREE.)

Select 3 answers
A.A security group rule allowing inbound traffic on port 443
B.An SSL/TLS certificate from ACM or uploaded to IAM
C.A listener configured on port 443 with the certificate
D.Server Name Indication (SNI) support
E.An HTTP to HTTPS redirect rule
AnswersA, B, C

To enable encryption, the Application Load Balancer (ALB) must be able to receive incoming encrypted traffic from clients. A security group rule allowing inbound traffic on port 443 (HTTPS) is fundamental, as it acts as a virtual firewall, explicitly permitting the necessary TLS communication to reach the ALB. Without this rule, client connections attempting to establish an encrypted session would be blocked at the network layer, preventing any encryption from occurring.

Why this answer

A security group rule allowing inbound traffic on port 443 is required because the Application Load Balancer (ALB) must accept HTTPS traffic from clients. Without this rule, the ALB's network interface will drop encrypted connections, preventing any TLS handshake from completing. This ensures that traffic between clients and the ALB is encrypted in transit.

Exam trap

The trap here is that candidates often confuse optional features like SNI or redirect rules as mandatory requirements, when in fact only the security group rule, the certificate, and the listener on port 443 are strictly necessary for encryption in transit.

1119
MCQhard

A developer is optimizing an S3 bucket for static website hosting. The site has a main page (index.html) and an error page (error.html). Users report seeing a generic 403 error instead of the error page when accessing a missing object. What is the likely cause?

A.The bucket policy denies access to the error.html object.
B.The Error document field in the static website hosting configuration is not set to error.html.
C.The index.html is missing from the bucket.
D.The error.html object has incorrect permissions.
AnswerB

This is the correct answer because the 'Error document' field within the S3 static website hosting configuration explicitly tells S3 which HTML file to serve when a 4xx error occurs. Without this field being correctly set to `error.html`, S3 will not know to redirect error requests to your custom page, even if `error.html` exists and has appropriate permissions. This configuration acts as the crucial routing instruction for custom error handling, ensuring a branded user experience during errors.

Why this answer

When static website hosting is enabled on an S3 bucket, the Error Document field specifies the object served when a 403 or 404 error occurs. If this field is not set to error.html, S3 returns its generic 403 error response instead of the custom error page. The correct answer is B because the Error document configuration is missing or incorrect.

Exam trap

The trap here is that candidates often confuse a permission issue (like a bucket policy or object ACL) with a configuration issue, assuming a 403 error always means 'access denied' rather than a missing Error Document setting.

How to eliminate wrong answers

Option A is wrong because a bucket policy denying access to error.html would cause a 403 error for that specific object, but the scenario describes a generic 403 error when accessing a missing object, not a permission issue on the error page itself. Option C is wrong because if index.html were missing, users would get a 403 or 404 error on the root, but the question specifically states the error occurs when accessing a missing object, not the main page. Option D is wrong because incorrect permissions on error.html would prevent it from being served, but the generic 403 error when accessing a missing object is controlled by the Error Document configuration, not the object's permissions.

1120
MCQmedium

A developer is using Amazon CloudFront to serve static content from an S3 bucket. Users are reporting that they see outdated content. The CloudFront distribution has a default TTL of 24 hours. What is the MOST efficient way to serve updated content immediately?

A.Create a CloudFront invalidation for the updated objects.
B.Disable and re-enable the CloudFront distribution.
C.Update the object key in the S3 bucket.
D.Change the default TTL to 0.
AnswerA

Creating a CloudFront invalidation is the precise and recommended method to force edge locations to remove specific cached objects. When an object in the origin is updated, an invalidation request explicitly tells CloudFront to delete the old version from all edge caches, compelling subsequent user requests for that object to fetch the newest version directly from the origin. This ensures immediate content freshness across the entire distribution without affecting other cached items.

Why this answer

Creating a CloudFront invalidation for the updated objects is the most efficient way to immediately serve updated content because it forces CloudFront to fetch the latest version from the origin, bypassing the cached copies. This method is targeted and does not affect other cached objects, making it ideal for urgent updates.

Exam trap

DVA-C02 often tests the misconception that changing TTL settings or disabling the distribution is a quick fix for cache updates, but the most efficient and immediate method is invalidation.

How to eliminate wrong answers

Option B is wrong because disabling and re-enabling the distribution is disruptive, takes time to propagate, and is not an efficient way to update content; it also does not guarantee immediate cache clearing. Option C is wrong because updating the object key in S3 changes the URL, which would require updating all references to the content and is not efficient for immediate updates. Option D is wrong because changing the default TTL to 0 would prevent caching entirely, increasing load on the origin and latency for users, and it does not immediately invalidate existing cached objects.

1121
MCQeasy

A developer wants to store application configuration securely and retrieve it programmatically from EC2 instances. The configuration includes database passwords and API keys. Which AWS service should be used?

A.EC2 user data
B.Amazon S3 with server-side encryption
C.AWS CloudFormation template parameters
D.AWS Systems Manager Parameter Store with SecureString
AnswerD

AWS Systems Manager Parameter Store, specifically when utilizing the SecureString data type, provides a highly secure and scalable solution for storing sensitive application configuration and secrets. SecureString encrypts parameter values using AWS Key Management Service (KMS) customer master keys, ensuring data is protected at rest and in transit. It offers fine-grained IAM access control, versioning, and seamless integration with EC2 instances and other AWS services for secure runtime retrieval without hardcoding credentials.

Why this answer

AWS Systems Manager Parameter Store with SecureString is the correct choice because it is purpose-built for securely storing sensitive configuration data like database passwords and API keys. It integrates with AWS KMS for encryption at rest, supports versioning, and allows EC2 instances to retrieve values via the AWS CLI or SDK using IAM roles, eliminating the need to hardcode secrets.

Exam trap

The trap here is that candidates confuse EC2 user data (which is easy to use but insecure) with a proper secrets management service, overlooking that Parameter Store provides encryption, access control, and audit logging essential for production security.

How to eliminate wrong answers

Option A is wrong because EC2 user data is unencrypted plaintext accessible via the instance metadata service (IMDS) and is intended for startup scripts, not secure storage of secrets. Option B is wrong because while Amazon S3 with server-side encryption protects data at rest, it lacks native integration for programmatic retrieval from EC2 with IAM roles and does not support automatic rotation or versioning of secrets. Option C is wrong because AWS CloudFormation template parameters are used for passing values during stack creation and are not designed for runtime secret retrieval; they can expose secrets in plaintext in the console or logs if not handled carefully.

1122
Multi-Selectmedium

A developer is deploying a serverless application using the AWS Serverless Application Model (SAM). The application consists of an API Gateway, Lambda functions, and a DynamoDB table. The developer wants to define and deploy this infrastructure as code. Which files and tools are required? (Choose THREE.)

Select 3 answers
A.Terraform configuration files
B.aws cloudformation deploy command
C.AWS SAM template file (template.yaml)
D.aws cloudformation package command
E.AWS CLI with aws lambda update-function-code command
AnswersB, C, D

The `aws cloudformation deploy` command is the final step in deploying a serverless application defined by an AWS SAM template. It takes the packaged CloudFormation template (which references artifacts uploaded to S3) and creates or updates the entire serverless application stack, including Lambda functions, API Gateway endpoints, and DynamoDB tables, ensuring all resources are provisioned and configured according to the template's specifications.

Why this answer

The AWS SAM template file (template.yaml) is required to define the serverless application resources. The `aws cloudformation package` command uploads local artifacts (such as Lambda deployment packages) to an S3 bucket and returns a copy of the template with references to the S3 object locations. The `aws cloudformation deploy` command then provisions the stack using the processed template.

Together, these three are essential for deploying a SAM application using CloudFormation commands. While SAM CLI provides convenient wrappers like `sam package` and `sam deploy`, the underlying CloudFormation commands can also be used directly.

Exam trap

The trap here is that candidates might think only the SAM template file is enough, but they overlook that the `package` and `deploy` commands are essential to upload artifacts and orchestrate the CloudFormation stack deployment.

1123
MCQhard

A developer is using AWS Elastic Beanstalk to deploy a Node.js application. The developer wants to run a custom script to set environment variables before the application starts. Which configuration file and location should the developer use?

A.Add a configuration file in the .ebextensions directory that uses container_commands.
B.Add a Procfile to the application root.
C.Place a shell script in the .ebextensions/scripts directory.
D.Add a cron.yaml file to the .ebextensions directory.
AnswerA

Elastic Beanstalk configuration files placed in the `.ebextensions` directory provide a robust mechanism for customizing the environment. `container_commands` are specifically designed to execute custom commands on the EC2 instances after the application source code has been deployed and dependencies installed, but critically, before the application server starts processing requests. This execution phase makes them ideal for running custom scripts, performing database migrations, or setting up application-specific configurations that depend on the deployed code.

Why this answer

`.ebextensions` configuration files with `container_commands` allow you to run custom commands before the application starts. `container_commands` execute after the application and web server have been set up but before the application is deployed, making them ideal for setting environment variables or running setup scripts. The files must be in YAML or JSON format and placed in the `.ebextensions` directory at the root of your source bundle.

Exam trap

The trap here is that candidates confuse `container_commands` with `commands` (which run before the application setup) or assume a Procfile is used in Elastic Beanstalk, when in fact Elastic Beanstalk uses platform-specific hooks like `.platform/hooks/prebuild` or `.ebextensions` for custom scripts.

How to eliminate wrong answers

Option B is wrong because a Procfile is used by Heroku, not AWS Elastic Beanstalk; Elastic Beanstalk uses its own platform hooks and configuration files. Option C is wrong because placing a shell script in `.ebextensions/scripts` is not a recognized configuration method; Elastic Beanstalk does not automatically execute scripts from that path. Option D is wrong because `cron.yaml` is used for periodic tasks (cron jobs) in Elastic Beanstalk worker environments, not for running pre-deployment setup scripts.

1124
MCQmedium

A developer is building a serverless application that uses Amazon S3 event notifications to trigger an AWS Lambda function for thumbnail generation. The developer wants to ensure that duplicate S3 events do not cause the same image to be processed multiple times. Which approach should the developer implement to ensure idempotent processing?

A.Store the object key and event ID in a DynamoDB table and check for duplicates before processing
B.Set the Lambda function's concurrency to 1 to prevent concurrent executions
C.Use an Amazon SQS FIFO queue as the event destination
D.Enable S3 event notification filtering based on object size
AnswerA

Amazon S3 event notifications operate on an "at least once" delivery model, meaning duplicate events can occur. By storing a unique identifier, such as a combination of the S3 object key and the event's `eventTime` or a generated `eventId`, in a DynamoDB table, the Lambda function can implement idempotency. Before processing, the function attempts a conditional write to DynamoDB; if the item already exists, it signifies a duplicate event that has been processed or is currently being handled, preventing redundant work and ensuring each object is processed exactly once.

Why this answer

Storing the S3 object key and event ID in a DynamoDB table with a TTL attribute allows the Lambda function to perform a conditional write (or check for an existing item) before processing. This ensures that even if duplicate S3 events are delivered (e.g., due to S3's at-least-once delivery guarantee), the same image is only processed once, achieving idempotency.

Exam trap

The trap here is that candidates often assume S3 event notifications are exactly-once, but the exam tests that they are at-least-once, requiring explicit idempotency handling via an external store like DynamoDB.

How to eliminate wrong answers

Option B is wrong because setting concurrency to 1 only prevents concurrent executions but does not prevent duplicate events from being processed sequentially; the same image could still be processed multiple times if duplicate events arrive one after another. Option C is wrong because SQS FIFO queues provide exactly-once processing within the queue, but S3 event notifications cannot directly send to a FIFO queue (S3 only supports standard SQS queues as event destinations), and even if you manually route through a FIFO queue, the deduplication ID would need to be based on the event ID, which is not automatically handled. Option D is wrong because filtering based on object size only reduces the number of events triggered (e.g., for small or large objects) but does not address duplicate events for the same object; duplicates can still occur regardless of size.

1125
MCQhard

A developer performed a CodeDeploy deployment to an Auto Scaling group. The deployment status is Failed with code HEALTH_CONSTRAINTS. Based on the exhibit, what is the most likely cause?

A.The CodeDeploy agent on the instances is not running
B.The minimum number of healthy instances required for the deployment was not met
C.The application revision contains invalid scripts
D.The IAM role for CodeDeploy does not have sufficient permissions
AnswerB

A HEALTH_CONSTRAINTS error in CodeDeploy explicitly indicates that the deployment configuration's specified minimum number of healthy instances could not be maintained throughout the deployment lifecycle. This often occurs when instances fail to come online, become unhealthy during a phased deployment (e.g., CodeDeployDefault.OneAtATime or HalfAtATime), or if the Auto Scaling group scales down unexpectedly. The deployment stops because proceeding would violate the application's availability requirements defined by the deployment group's health constraints.

Why this answer

The HEALTH_CONSTRAINTS error in CodeDeploy means the deployment could not maintain the minimum number of healthy instances specified in the deployment configuration during the deployment. This typically occurs when instances fail health checks, the ASG cannot launch replacements fast enough, or the deployment configuration's minimum healthy hosts threshold is too high relative to available capacity. The most likely cause is that the minimum healthy instance requirement was not met.

Exam trap

DVA-C02 often tests the ability to distinguish CodeDeploy error codes — candidates who pick 'agent not running' or 'IAM permissions' miss that HEALTH_CONSTRAINTS specifically points to the minimum healthy hosts threshold not being met during deployment.

How to eliminate wrong answers

Option A is wrong because a stopped CodeDeploy agent typically produces an AGENT_ISSUE or similar error code, not HEALTH_CONSTRAINTS. Option C is wrong because invalid scripts in the application revision produce a SCRIPT_FAILED or REVISION_MISSING error, not HEALTH_CONSTRAINTS. Option D is wrong because insufficient IAM permissions produce an ACCESS_DENIED or similar error, not HEALTH_CONSTRAINTS.

HEALTH_CONSTRAINTS specifically indicates the deployment could not satisfy the health check requirements of the deployment configuration.

Page 14

Page 15 of 16

Page 16