Courseiva

AWS Certified Developer Associate DVA-C02 (DVA-C02) — Questions 1126–1135

1135 questions total · 16pages · All types, answers revealed

Page 15

Page 16 of 16

1126
MCQeasy

A developer is using AWS SAM to define a serverless application. The application includes an AWS Lambda function that needs to access an Amazon DynamoDB table. The developer wants to grant the Lambda function the minimum required permissions to read and write items in the table. Which resource should the developer use to define the IAM permissions?

A.AWS::DynamoDB::Table
B.AWS::IAM::Role
C.AWS::Serverless::Function Policies property
D.AWS::Lambda::Permission
AnswerC

The Policies property within an AWS::Serverless::Function resource in a SAM template is the designated and most efficient way to attach IAM permissions to the Lambda function's execution role. This property allows developers to specify predefined SAM policy templates (e.g., DynamoDBReadPolicy) or define custom inline IAM policy statements, granting the function the necessary permissions to interact with other AWS services like DynamoDB. It directly modifies the function's execution role to allow specific actions.

Why this answer

The AWS::Serverless::Function resource's Policies property allows you to attach IAM policies directly to the Lambda function's execution role in a declarative manner. By specifying a policy statement with dynamodb:GetItem, dynamodb:PutItem, etc., and the ARN of the DynamoDB table, you grant the minimum required permissions for read and write access without manually creating an IAM role. SAM automatically creates and associates the IAM role with the function, simplifying permission management.

Exam trap

The trap here is that candidates confuse AWS::Lambda::Permission (which controls who can invoke the Lambda) with the IAM permissions needed for the Lambda to access other services, leading them to select Option D instead of the correct Policies property.

How to eliminate wrong answers

Option A is wrong because AWS::DynamoDB::Table defines the DynamoDB table resource itself, not IAM permissions; it cannot grant access to Lambda functions. Option B is wrong because AWS::IAM::Role is a generic CloudFormation resource that requires you to manually define the role, trust policy, and attach policies, which is more verbose and error-prone than using SAM's Policies property. Option D is wrong because AWS::Lambda::Permission is used to grant other AWS services or accounts permission to invoke the Lambda function, not to grant the Lambda function permissions to access other resources like DynamoDB.

1127
MCQmedium

A developer is using AWS CodeDeploy to deploy an application to an EC2 Auto Scaling group. The deployment must follow a rolling update, deploying to exactly 50% of the instances at a time. Which built-in deployment configuration should the developer use?

A.CodeDeployDefault.OneAtATime
B.CodeDeployDefault.HalfAtATime
C.CodeDeployDefault.AllAtOnce
D.CodeDeployDefault.LambdaAllAtOnce
AnswerB

CodeDeployDefault.HalfAtATime deploys to half the instances in the deployment group simultaneously, then the remainder, satisfying the exact 50% rolling update constraint. It is a built-in configuration, so no custom deployment configuration needs creating, and it works with EC2 Auto Scaling groups during in-place deployments.

Why this answer

CodeDeployDefault.HalfAtATime, is correct because it instructs CodeDeploy to deploy to exactly 50% of the instances in the Auto Scaling group at a time during a rolling update. This built-in configuration ensures that half the instances are updated before the other half, matching the requirement for a 50% rolling deployment.

Exam trap

The trap here is that candidates may confuse CodeDeployDefault.HalfAtATime with CodeDeployDefault.OneAtATime or CodeDeployDefault.AllAtOnce, or incorrectly apply Lambda-specific configurations like CodeDeployDefault.LambdaAllAtOnce to EC2 deployments.

How to eliminate wrong answers

Option A is wrong because CodeDeployDefault.OneAtATime deploys to only one instance at a time, not 50% of the instances. Option C is wrong because CodeDeployDefault.AllAtOnce deploys to all instances simultaneously, which is not a rolling update and does not limit to 50%. Option D is wrong because CodeDeployDefault.LambdaAllAtOnce is a deployment configuration for AWS Lambda functions, not for EC2 Auto Scaling groups, and it deploys to all traffic at once.

1128
Multi-Selecthard

A company has a web application running on Amazon ECS with Fargate launch type. The application needs to store and retrieve user session data. The sessions are small and require very low latency access. The development team wants a fully managed solution. Which storage options meet these requirements? (Choose TWO.)

Select 2 answers
A.Amazon DynamoDB
B.Amazon S3
C.Amazon EFS
D.Amazon ElastiCache for Redis
E.Amazon RDS for PostgreSQL
AnswersA, D

Amazon DynamoDB is a fully managed, serverless NoSQL database service that provides consistent single-digit millisecond latency at any scale. Its key-value data model is highly efficient for storing and retrieving session data, which typically involves simple lookups by session ID. DynamoDB's automatic scaling, high availability, and built-in Time-To-Live (TTL) functionality make it an excellent choice for dynamic web application workloads requiring persistent, low-latency session state without operational overhead.

Why this answer

Amazon DynamoDB is correct because it is a fully managed NoSQL key-value database that provides single-digit millisecond latency for read and write operations, making it ideal for storing small session data with low latency requirements. It scales automatically and requires no server management, aligning with the fully managed requirement and the Fargate launch type's serverless nature.

Exam trap

The trap here is that candidates often choose Amazon S3 for its simplicity and low cost, overlooking its higher latency and lack of support for low-latency session storage, or they mistakenly think EFS can be mounted directly to Fargate tasks without understanding the integration limitations.

1129
MCQeasy

A developer uses the CloudFormation template in the exhibit to create an S3 bucket. The stack creation fails with the error 'Bucket already exists'. What is the MOST likely reason?

A.The CloudFormation template has invalid JSON syntax.
B.The bucket name is already taken by another AWS account.
C.The IAM user does not have permission to create S3 buckets.
D.The bucket name is not available in the specified region.
AnswerB

Amazon S3 bucket names are globally unique across all AWS accounts, not just within a single account or region. When a CloudFormation stack attempts to create an S3 bucket with a name that is already registered by any other AWS account worldwide, the creation will fail with a 'Bucket already exists' error. This global namespace constraint means even if the name appears available within your account's context, it might be owned by another AWS customer.

Why this answer

S3 bucket names are globally unique across all AWS accounts and regions, so if the name specified in the CloudFormation template is already in use by another account, the stack creation fails with 'Bucket already exists'. This is the most likely cause given the error message. The error is not related to syntax, IAM permissions, or region availability.

Exam trap

DVA-C02 often tests the global uniqueness of S3 bucket names versus regional resource constraints; candidates who assume the error is region-related or permission-related pick the wrong answer instead of recognizing the global namespace conflict.

How to eliminate wrong answers

Option A is wrong because invalid JSON syntax would produce a template validation error (e.g., 'Template format error'), not 'Bucket already exists'. Option C is wrong because insufficient IAM permissions would produce an 'Access Denied' error, not a bucket-name conflict. Option D is wrong because S3 bucket names are global, not region-scoped; the same name cannot be reused in any region, so the error is not about regional availability.

1130
MCQeasy

A developer needs to grant an IAM user access to an S3 bucket for read-only operations. Which IAM policy action should be used?

A.s3:PutObject
B.s3:DeleteObject
C.s3:ListBucket
D.s3:GetObject
AnswerD

s3:GetObject is the specific action that permits downloading an object's content from S3, and it carries no ability to write, overwrite, or delete anything, making it the precise, minimal permission that satisfies a read-only access requirement for retrieving object data.

Why this answer

S3:GetObject allows reading objects from S3, which is required for read-only operations. Option A (s3:PutObject) allows writing, option B (s3:DeleteObject) allows deletion, and option C (s3:ListBucket) allows listing bucket contents but not reading object content, so none of these provide read-only access.

1131
MCQeasy

The exhibit shows the output of the describe-instances command. An Elastic Beanstalk environment is configured to use this EC2 instance as a web server. The application is not accessible. What is the most likely cause?

A.The instance has been terminated.
B.The security group does not allow HTTP traffic.
C.The instance does not have the correct Name tag.
D.The instance does not exist.
AnswerA

The describe-instances output shows the instance's state as 'terminated', meaning the underlying EC2 host has been permanently shut down and its resources released; a terminated instance can never serve traffic again, which directly explains why the Elastic Beanstalk application is completely inaccessible.

Why this answer

The instance state in the exhibit is 'terminated', meaning the instance is no longer running. This makes the application inaccessible. Option B is incorrect because the security group configuration is not indicated as an issue.

Option C is incorrect because the Name tag is irrelevant to accessibility. Option D is incorrect because the instance exists but is terminated.

1132
Multi-Selecteasy

A developer is using AWS Elastic Beanstalk to deploy a web application. The environment uses an Application Load Balancer (ALB). The developer wants to perform a blue/green deployment to minimize downtime. Which TWO steps should the developer take? (Choose two.)

Select 2 answers
A.Terminate the old environment after the new environment is deployed.
B.Add more EC2 instances to the existing environment.
C.Deploy the new version to a separate Elastic Beanstalk environment.
D.Update the existing environment with the new version.
E.Swap the CNAME records of the two environments.
AnswersC, E

Deploying the new application version to a separate, distinct Elastic Beanstalk environment is the crucial initial step for implementing a blue/green deployment strategy. This action creates the 'green' environment, allowing the new version to be fully tested and validated in isolation without impacting the currently live 'blue' environment. This separation is fundamental to achieving zero-downtime deployments and ensuring stability.

Why this answer

Blue/green deployment requires a separate, isolated environment running the new version. Elastic Beanstalk supports this by allowing you to create a second environment (green) alongside the existing one (blue), ensuring zero overlap and no risk to the live application during deployment.

Exam trap

The trap here is that candidates often confuse blue/green deployment with in-place updates (Option D) or scaling (Option B), failing to recognize that a separate environment and a CNAME swap are the defining steps for a true blue/green deployment on Elastic Beanstalk.

1133
Multi-Selecthard

A company is using AWS CloudFormation to deploy infrastructure. The developer needs to update a stack but wants to avoid downtime for a critical database. Which THREE strategies should the developer consider?

Select 3 answers
A.Set the DeletionPolicy attribute to Retain on the database resource.
B.Use the Parameters section to set a conditional update flag.
C.Use the UpdateReplace policy to create a new resource before deleting the old one.
D.Apply a stack policy that prevents updates to the database resource.
E.Use change sets to review the impact of changes before executing them.
AnswersC, D, E

The UpdateReplacePolicy attribute, when applied to a resource like a database, allows CloudFormation to create a new resource instance before deleting the old one if a property change necessitates replacement. By setting this policy to `Retain` or `Snapshot` (for snapshot-capable resources), CloudFormation ensures the new resource is successfully provisioned and potentially populated or integrated before the original resource is terminated. This strategy significantly minimizes downtime and reduces the risk of data loss during critical database updates, maintaining service continuity.

Why this answer

The `UpdateReplace` policy (specifically using a `CreationPolicy` and `UpdatePolicy` with `AutoScalingReplacingUpdate`) instructs CloudFormation to create a replacement resource before deleting the original, ensuring zero downtime during a stack update that requires resource replacement. This is critical for a database where continuous availability is required.

Exam trap

The trap here is that candidates confuse `DeletionPolicy: Retain` (which only protects against accidental stack deletion) with a mechanism that prevents downtime during updates, when in fact it does nothing to manage the update lifecycle.

1134
MCQeasy

A developer is using the AWS CLI to upload a file to an S3 bucket with server-side encryption. The bucket is configured with default encryption (SSE-S3). The developer wants to ensure the object is encrypted with SSE-KMS instead. What should the developer do?

A.Use the --kms-key-id parameter with a KMS key ARN
B.Use the --sse aws:kms parameter when uploading
C.No action needed; the bucket default encryption will apply
D.Change the bucket policy to require SSE-KMS
AnswerB

This is the correct action. To ensure a file is encrypted with Server-Side Encryption with AWS KMS (SSE-KMS) during an AWS CLI upload, the --sse aws:kms parameter must be explicitly specified. This parameter instructs S3 to use KMS for encryption. If a specific KMS key is desired, it can be combined with the --kms-key-id parameter; otherwise, S3 will use the default AWS managed key for S3 in the account.

Why this answer

The developer must explicitly specify the server-side encryption method at the time of upload using the `--sse aws:kms` parameter in the AWS CLI. This overrides the bucket's default SSE-S3 encryption, ensuring the object is encrypted with SSE-KMS. Without this parameter, the object inherits the bucket's default encryption (SSE-S3), regardless of any other settings.

Exam trap

The trap here is that candidates assume bucket default encryption always applies to all objects, but in reality, request-level encryption parameters take precedence over bucket defaults, and the developer must explicitly specify SSE-KMS to override SSE-S3.

How to eliminate wrong answers

Option A is wrong because the `--kms-key-id` parameter is used to specify a specific KMS key ARN when SSE-KMS is already selected, but it does not enable SSE-KMS by itself; the `--sse aws:kms` parameter must also be provided. Option C is wrong because the bucket's default encryption (SSE-S3) will apply automatically, which does not meet the developer's requirement for SSE-KMS; the default is not overridden without explicit request-level parameters. Option D is wrong because changing the bucket policy to require SSE-KMS only enforces that objects must be encrypted with SSE-KMS at the bucket level, but the developer still needs to specify `--sse aws:kms` in the upload command to comply with that policy and achieve the desired encryption.

1135
MCQeasy

An application running on EC2 instances needs to access an S3 bucket securely. Which of the following is the BEST practice for managing credentials?

A.Store the AWS access key and secret key in a configuration file on the EC2 instance.
B.Use an IAM user with programmatic access and attach a policy allowing S3 access.
C.Launch the EC2 instance with an IAM role that grants S3 access.
D.Use a shared secret key stored in AWS Secrets Manager and retrieve it at runtime.
AnswerC

Launching an EC2 instance with an IAM role is the AWS best practice for granting applications secure access to AWS services like S3. An IAM role provides temporary security credentials that are automatically rotated and delivered to the instance via the instance metadata service. This eliminates the need to embed or manage long-term access keys on the instance, significantly reducing the risk of credential compromise and simplifying credential management, aligning with the principle of least privilege.

Why this answer

Assigning an IAM role to an EC2 instance is the AWS-recommended best practice for securely granting permissions to AWS services. The instance automatically obtains temporary security credentials from the instance metadata service (IMDS), eliminating the need to hardcode or manage long-term access keys. This approach follows the principle of least privilege and avoids the security risks of storing credentials on disk.

Exam trap

The trap here is that candidates often confuse IAM users with IAM roles, mistakenly thinking that creating a dedicated IAM user with programmatic access is a secure practice, when in fact IAM roles are the correct and secure method for EC2-to-S3 access because they eliminate the need to manage long-term credentials.

How to eliminate wrong answers

Option A is wrong because storing AWS access keys and secret keys in a configuration file on the EC2 instance is a security risk; if the instance is compromised, the credentials are exposed and can be used indefinitely. Option B is wrong because using an IAM user with programmatic access requires distributing and managing long-term access keys, which violates the AWS security best practice of using IAM roles for EC2 workloads. Option D is wrong because while AWS Secrets Manager securely stores secrets, retrieving a shared secret key at runtime still introduces a long-term credential that must be managed and rotated, whereas an IAM role provides temporary, automatically rotated credentials without any secret management overhead.

Page 15

Page 16 of 16