Courseiva

AWS Certified Developer Associate DVA-C02 (DVA-C02) — Questions 76–150

1135 questions total · 16pages · All types, answers revealed

Page 1

Page 2 of 16

Page 3
76
Multi-Selecteasy

A developer is building a REST API using API Gateway and Lambda. The API must be secured using a Lambda authorizer. Which THREE steps are necessary to implement the Lambda authorizer? (Choose THREE.)

Select 3 answers
A.Configure the API Gateway method to use the Lambda authorizer.
B.Return a JSON Web Token (JWT) from the authorizer function.
C.Create a Lambda function that validates the token and returns an IAM policy.
D.Grant API Gateway permission to invoke the Lambda authorizer function.
E.Generate an API key and distribute it to clients.
AnswersA, C, D

After creating and configuring a Lambda authorizer, the crucial next step is to associate it with the specific API Gateway methods that require authorization. This configuration tells API Gateway to invoke the designated Lambda authorizer function before forwarding the request to the backend integration, ensuring that the incoming request's identity or token is validated. Without this explicit link, the authorizer would exist but never be utilized by the API endpoint.

Why this answer

The API Gateway method must be explicitly configured to use the Lambda authorizer as the authorization mechanism. This is done by setting the method's Authorization type to the Lambda authorizer's logical name in the API Gateway console or via the REST API's `authorizationType` property set to `CUSTOM` and referencing the authorizer's ID. Without this configuration, API Gateway will not invoke the authorizer function for incoming requests.

Exam trap

The trap here is that candidates confuse the token validation logic inside the authorizer with the output format, mistakenly thinking the authorizer returns a JWT or API key, when in fact it must return an IAM policy document for API Gateway to enforce authorization.

77
MCQhard

A developer is designing a serverless application that processes user-uploaded images. The images are uploaded to an S3 bucket, which triggers a Lambda function to create a thumbnail and store metadata in DynamoDB. The thumbnail creation is CPU-intensive and can take up to 10 seconds. The developer wants to minimize costs and ensure that the thumbnail is created as soon as possible. Which approach should the developer choose?

A.Use AWS Step Functions to orchestrate the Lambda function and DynamoDB update.
B.Use an ECS Fargate task to process the images, triggered by S3 events.
C.Use S3 event notifications to directly invoke the Lambda function.
D.Use an SQS queue between S3 and Lambda to buffer requests.
AnswerC

S3 event notifications provide a native, highly efficient mechanism to directly invoke an AWS Lambda function whenever specific object events occur, such as object creation. This approach offers the simplest integration pattern, minimizing configuration and operational overhead. It ensures minimal latency between the S3 event and the Lambda execution, making it highly responsive, and is extremely cost-effective as you only pay for the Lambda compute duration and S3 storage.

Why this answer

S3 event notifications directly invoke the Lambda function asynchronously, which is the simplest, fastest, and most cost-effective approach for this use case. The Lambda function's 15-minute timeout easily accommodates the 10-second thumbnail creation, and direct invocation eliminates the cost and latency of additional intermediate services like SQS or Step Functions, ensuring the thumbnail is processed as soon as the image is uploaded.

Exam trap

Candidates often overcomplicate serverless architectures by adding SQS queues or Step Functions by default. While SQS is excellent for smoothing out traffic spikes (buffering) and Step Functions is great for complex workflows, they introduce additional latency and cost. For immediate, simple processing of individual uploads, direct S3-to-Lambda asynchronous invocation is the most optimal and cost-effective choice.

How to eliminate wrong answers

Option A is wrong because AWS Step Functions would introduce unnecessary orchestration overhead and cost, as the workflow is a simple single-step process (create thumbnail and store metadata) that does not require state management or retry logic. Option B is wrong because ECS Fargate tasks incur higher costs and startup latency compared to Lambda, and are overkill for a short-lived, CPU-intensive task that fits within Lambda's timeout limits. Option D is wrong because adding an SQS queue between S3 and Lambda introduces buffering latency and additional cost, which contradicts the requirement to create the thumbnail 'as soon as possible' and does not improve performance for a single-event trigger.

78
Multi-Selecthard

A developer is using AWS CodePipeline to deploy a web application. The pipeline has a source stage from GitHub and a deploy stage to Elastic Beanstalk. The deploy stage fails with the error 'The S3 bucket does not allow access to the artifact'. Which THREE actions could resolve this issue?

Select 3 answers
A.Specify a different artifact bucket in the pipeline configuration.
B.Add a bucket policy that grants the pipeline's service role access to the artifact bucket.
C.Ensure the pipeline's IAM role has s3:GetObject and s3:PutObject permissions on the artifact bucket.
D.If the artifact bucket is encrypted with AWS KMS, ensure the pipeline role has kms:Decrypt permission.
E.Enable versioning on the artifact bucket.
AnswersB, C, D

An S3 bucket policy is a resource-based policy attached directly to the S3 bucket, allowing you to grant permissions to AWS accounts, IAM users, or IAM roles, even across different AWS accounts. Adding a bucket policy that explicitly grants `s3:GetObject` and `s3:PutObject` (and potentially `s3:ListBucket`) permissions to the CodePipeline's service role ensures the pipeline has the necessary access to store and retrieve artifacts, complementing or overriding identity-based policies.

Why this answer

The deploy stage fails because the CodePipeline service role cannot access the artifact S3 bucket. To resolve this, you can: (1) Attach a bucket policy that grants the pipeline's service role access to the bucket (Option B). (2) Ensure the pipeline's IAM role has the necessary S3 permissions: s3:GetObject and s3:PutObject on the artifact bucket (Option C). (3) If the artifact bucket uses AWS KMS encryption, the pipeline role also needs kms:Decrypt permission to read the encrypted artifacts (Option D). Option A is not a direct fix — specifying a different bucket may avoid the issue but does not address the access problem with the current bucket.

Option E is irrelevant because bucket versioning does not affect access permissions.

79
Multi-Selecthard

A developer is using Amazon S3 to store sensitive data. The compliance team requires that all objects be encrypted at rest using server-side encryption with a customer-managed key (SSE-KMS). Which THREE steps must the developer take to enforce this requirement? (Choose THREE.)

Select 3 answers
A.Create an AWS KMS customer-managed key.
B.Configure the bucket ACL to require encryption.
C.Add a bucket policy that denies PutObject if the x-amz-server-side-encryption header is not set to 'aws:kms'.
D.Enable S3 default encryption with SSE-S3.
E.Set the bucket's default encryption to SSE-KMS using the customer-managed key.
AnswersA, C, E

To implement Server-Side Encryption with AWS KMS (SSE-KMS) for sensitive data, creating an AWS KMS customer-managed key (CMK) is a fundamental prerequisite. This key provides the developer with full control over the encryption process, including key policies, rotation, and audit trails, which is crucial for meeting stringent compliance requirements. Without a CMK, the enhanced security and control offered by SSE-KMS cannot be leveraged for data protection.

Why this answer

SSE-KMS requires a customer-managed AWS KMS key to encrypt objects at rest. By creating a customer-managed key, the developer gains control over key rotation, access policies, and audit trails, which satisfies the compliance team's requirement for server-side encryption with a customer-managed key.

Exam trap

The trap here is that candidates often confuse S3 default encryption (which can be set to SSE-KMS) with bucket policies that enforce encryption headers, but the question requires both the key creation (A) and the enforcement mechanisms (C and E) to fully satisfy the compliance requirement.

80
MCQmedium

A developer is deploying a serverless application using AWS CloudFormation. The stack creation fails with the error 'CREATE_FAILED: The following resource(s) failed to create: [MyLambdaFunction]'. The developer checks the CloudFormation events and sees 'Resource creation cancelled'. What is the most likely cause?

A.The Lambda function code is too large and exceeds the deployment limit.
B.The Lambda function creation timed out due to a network issue.
C.Another resource in the stack failed, triggering a rollback and cancelling the Lambda creation.
D.The Lambda function's execution role is missing permissions.
AnswerC

When deploying resources using AWS CloudFormation, the deployment process is atomic. If any single resource within a CloudFormation stack fails to create, update, or delete, CloudFormation initiates an automatic rollback of the entire stack to its last stable state. In this scenario, if the Lambda function was pending creation or in the process of being created when another resource in the same stack encountered a failure, its creation would be explicitly cancelled as part of this rollback mechanism, resulting in the 'Resource creation cancelled' status.

Why this answer

When CloudFormation creates a stack, resources are provisioned in dependency order. If any resource fails, CloudFormation initiates a rollback and cancels in-progress creations of other resources — producing the 'Resource creation cancelled' message for MyLambdaFunction. The Lambda itself did not fail; it was cancelled because a sibling resource failed first.

Exam trap

DVA-C02 often tests whether candidates chase the visible error ('Resource creation cancelled') instead of identifying the root-cause resource that failed first and triggered the rollback.

How to eliminate wrong answers

Option A is wrong because an oversized Lambda deployment package would produce a specific error like 'Code storage limit exceeded' or 'RequestEntityTooLarge', not 'Resource creation cancelled'. Option B is wrong because a network timeout would surface as a timeout error on the Lambda resource itself, not a cancellation triggered by another resource. Option D is wrong because a missing IAM permission on the execution role would cause the Lambda to fail at invocation time or produce an explicit 'AccessDenied' during creation, not a cancellation message.

81
MCQeasy

A developer is deploying a static website to Amazon S3 and wants to use Amazon CloudFront for content delivery. The developer wants to ensure that only CloudFront can access the S3 bucket. Which S3 bucket policy should the developer use?

A.Use a bucket policy that allows access only if the Referer header matches the CloudFront distribution domain.
B.Make the bucket public and use CloudFront's default caching.
C.Grant CloudFront access by allowing the CloudFront IP address range.
D.Grant CloudFront access via an origin access identity (OAI) and restrict the bucket policy to the OAI.
AnswerD

Granting CloudFront access through an Origin Access Identity (OAI) is the recommended and most secure method. An OAI is a special CloudFront user that you associate with your distribution, and then you modify the S3 bucket policy to explicitly grant read permissions only to this specific OAI. This ensures that content can only be accessed through your CloudFront distribution, preventing direct public access to the S3 bucket and securing your origin.

Why this answer

An Origin Access Identity (OAI) is a special CloudFront user that you can associate with your distribution. By configuring the S3 bucket policy to grant access only to that OAI, you ensure that direct S3 requests are denied, and only requests routed through CloudFront can retrieve objects. This provides a secure, private origin without exposing the bucket publicly.

Exam trap

The trap here is that candidates often choose IP-based restrictions (Option C) or Referer header checks (Option A) because they seem simpler, but AWS explicitly recommends OAI for secure S3 origin access in CloudFront, and the exam tests this best practice.

How to eliminate wrong answers

Option A is wrong because the Referer header can be easily spoofed by clients, so it does not provide a reliable security mechanism to restrict access exclusively to CloudFront. Option B is wrong because making the bucket public defeats the purpose of restricting access to CloudFront only, and anyone with the S3 URL can bypass CloudFront entirely. Option C is wrong because CloudFront IP address ranges are shared with other AWS services and can change without notice, making this approach both insecure and difficult to maintain; it also does not prevent direct access from other sources within the same IP range.

82
Drag & Dropmedium

Drag and drop the steps to implement a disaster recovery plan using cross-region replication for S3 in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First create buckets, enable versioning, configure replication rule, and set permissions.

83
MCQeasy

A developer needs to grant an IAM user access to list objects in an S3 bucket named 'app-data'. Which IAM policy statement should be used?

A.{"Effect":"Allow","Action":"s3:*","Resource":"*"}
B.{"Effect":"Allow","Action":"s3:ListAllMyBuckets","Resource":"*"}
C.{"Effect":"Allow","Action":"s3:ListBucket","Resource":"arn:aws:s3:::app-data"}
D.{"Effect":"Allow","Action":"s3:GetObject","Resource":"arn:aws:s3:::app-data/*"}
AnswerC

This policy correctly grants the `s3:ListBucket` action, which is specifically used to retrieve a list of objects and common prefixes within a designated S3 bucket. The resource ARN `arn:aws:s3:::app-data` precisely targets the `app-data` bucket, ensuring the user can list its contents without gaining broader, unnecessary permissions. This aligns perfectly with the principle of least privilege for the stated requirement.

Why this answer

The s3:ListBucket action is required to list the objects in an S3 bucket, and the resource ARN must specify the bucket itself (arn:aws:s3:::app-data) without a trailing /*. This grants permission to list the contents of the 'app-data' bucket, which is the exact requirement.

Exam trap

The trap here is that candidates often confuse s3:ListBucket (bucket-level action) with s3:GetObject (object-level action) or incorrectly apply the resource ARN with a trailing '/*' for bucket-level permissions.

How to eliminate wrong answers

Option A is wrong because it grants full administrative access to all S3 actions on all resources, which violates the principle of least privilege and is overly permissive for the specific task of listing objects. Option B is wrong because s3:ListAllMyBuckets lists all buckets in the account, not the objects within a specific bucket, and the resource '*' does not restrict to 'app-data'. Option D is wrong because s3:GetObject is used to retrieve an object's data, not to list objects; additionally, the resource ARN includes a trailing '/*' which refers to objects within the bucket, not the bucket itself.

84
MCQmedium

A team uses AWS CodeBuild to run automated tests. The buildspec.yaml file contains a 'pre_build' phase that sets environment variables. During a build, the build fails with 'Error: Cannot find module 'express' when running a Node.js application. The application's package.json is in the source root. What is the most likely cause?

A.The Node.js runtime version is incompatible with the express module.
B.The environment variable NODE_ENV is set to production, which skips devDependencies.
C.The buildspec does not include a command to run 'npm install' in the install or pre_build phase.
D.The package.json file is not in the source root directory.
AnswerC

For Node.js projects, the `express` module, like other project dependencies, must be explicitly installed into the build environment. This is typically achieved by running `npm install` (or `yarn install`) within the `install` or `pre_build` phase of the CodeBuild `buildspec.yml`. Without this command, the `node_modules` directory will not be populated, leading to a "cannot find module 'express'" error when the application attempts to import it.

Why this answer

AWS CodeBuild runs each phase in the buildspec in order: install, pre_build, build, post_build. If the buildspec does not include an 'npm install' (or 'npm ci') command in the install or pre_build phase, the Node.js dependencies listed in package.json — including express — are never downloaded into node_modules. The build then fails when it tries to require('express').

The fix is to add 'npm install' to the install phase.

Exam trap

DVA-C02 often tests the misconception that CodeBuild automatically installs dependencies — candidates assume the runtime handles it, but you must explicitly run npm install in the buildspec.

How to eliminate wrong answers

Option A is wrong because a Node.js runtime incompatibility would typically produce a different error (e.g., syntax or engine mismatch), and express is broadly compatible; the error 'Cannot find module' specifically means the module is not present. Option B is wrong because NODE_ENV=production skips devDependencies, but express is a regular dependency, so it would still be installed if npm install ran. Option D is wrong because the question states package.json is in the source root, so the path is correct.

85
MCQhard

A developer is storing an API secret for a third-party service in AWS Secrets Manager. The secret needs to be accessed by an AWS Lambda function that runs in a VPC. The Lambda function must have the minimum required permissions. Which IAM policy statement should the developer attach to the Lambda execution role?

A.A policy that grants secretsmanager:GetSecretValue for the specific secret ARN and includes a condition for aws:SourceVpce to restrict access to the VPC endpoint
B.A policy that grants secretsmanager:GetSecretValue for all secrets in the account
C.A policy that grants secretsmanager:GetSecretValue for the secret and includes a condition for aws:SourceIp
D.A policy that grants secretsmanager:GetSecretValue for the secret and includes a condition for ec2:Vpc
AnswerA

This policy correctly implements the principle of least privilege by granting access only to the specific secret identified by its Amazon Resource Name (ARN). Furthermore, the `aws:SourceVpce` condition key ensures that requests to retrieve the secret value must originate from the specified VPC endpoint, providing a critical layer of network-level security. This prevents unauthorized access attempts from outside the designated private network path, enhancing the overall security posture for confidential data.

Why this answer

It grants the minimum required permission (secretsmanager:GetSecretValue) scoped to the specific secret ARN, and uses the aws:SourceVpce condition key to restrict access to the VPC endpoint used by the Lambda function. This ensures that only requests originating from the specified VPC endpoint can retrieve the secret, aligning with the principle of least privilege and the requirement that the Lambda function runs in a VPC.

Exam trap

The trap here is that candidates often confuse aws:SourceIp with VPC-based access control, not realizing that Lambda functions in a VPC use private IPs and require VPC endpoint conditions (aws:SourceVpce or aws:SourceVpc) instead of IP-based conditions.

How to eliminate wrong answers

Option B is wrong because it grants secretsmanager:GetSecretValue for all secrets in the account, which violates the principle of least privilege by allowing access to secrets beyond the intended one. Option C is wrong because aws:SourceIp is not effective for Lambda functions in a VPC, as they use private IP addresses from the VPC subnet, and the condition would not match the source IP seen by Secrets Manager (which is the VPC endpoint's private IP). Option D is wrong because ec2:Vpc is not a valid condition key for Secrets Manager; the correct condition key for VPC endpoint restrictions is aws:SourceVpce, not ec2:Vpc.

86
MCQhard

A company deploys a microservices application using AWS CloudFormation. Each microservice is deployed as a separate stack. The developer wants to pass the output values (e.g., API endpoint URLs) from one stack to another. Which CloudFormation feature should be used?

A.Custom resources with Lambda
B.Stack outputs
C.Nested stacks
D.Cross-stack references using Export and ImportValue
AnswerD

This is the native and most efficient CloudFormation mechanism for sharing values between *independent* stacks. A stack can explicitly `Export` an output value, making it discoverable and consumable by other CloudFormation stacks within the same AWS account and region. These other stacks can then use the `Fn::ImportValue` intrinsic function to reference the exported value by its unique name, establishing a direct and managed dependency without requiring custom code or complex workarounds. This approach ensures proper dependency tracking and simplifies value propagation.

Why this answer

Cross-stack references using Export and ImportValue allow you to share values between CloudFormation stacks. You export a value from one stack and import it into another, enabling loose coupling. This is the standard way to pass outputs between separate stacks.

Exam trap

DVA-C02 often tests the difference between nested stacks and cross-stack references. Candidates may confuse nested stacks (which are part of a single stack) with cross-stack references (which link separate stacks).

How to eliminate wrong answers

Option A is wrong because custom resources with Lambda are used to execute custom logic during stack operations, not for passing values between stacks. Option B is wrong because stack outputs alone do not enable cross-stack referencing; they must be exported. Option C is wrong because nested stacks are used to compose stacks within a single parent stack, not for sharing values between independent stacks.

87
MCQhard

A developer is building a serverless application that uses AWS Step Functions to orchestrate multiple AWS Lambda functions. The workflow involves three steps: validate input, process data, and store results. The developer notices that the workflow occasionally fails due to transient errors in the process data step. The developer wants to implement error handling so that the workflow retries the process data step up to three times with an exponential backoff. Additionally, if all retries fail, the workflow should send a notification to an Amazon SNS topic and transition to a failure state. The developer has defined the state machine in Amazon States Language (ASL). How should the developer configure the state machine?

A.Write custom retry logic inside the Lambda function code and catch exceptions there.
B.Modify the IAM execution role to allow the state machine to call SNS and then use a ResultPath to handle errors.
C.In the process data state definition, add a Retry field with MaxAttempts: 3 and BackoffRate: 2, and add a Catch field that transitions to a failure state and sends an SNS notification.
D.Add a Retry field at the workflow level and a Catch field at the workflow level.
AnswerC

This option correctly leverages AWS Step Functions' native error handling and retry mechanisms. Adding a `Retry` field to the specific state definition allows for automatic retries with exponential backoff (`BackoffRate: 2`) and a maximum number of attempts (`MaxAttempts: 3`), enhancing the workflow's resilience against transient failures. Subsequently, a `Catch` field provides a robust fallback mechanism, directing the workflow to a designated failure state and enabling an SNS notification for operational awareness after all retries are exhausted.

Why this answer

In Amazon States Language (ASL), retry and error handling are configured per-state, not at the workflow level. The process data state should include a Retry block with MaxAttempts: 3 and BackoffRate: 2 (which produces exponential backoff: 1s, 2s, 4s by default), and a Catch block that matches the error and transitions to a failure state. The failure state can be a Task state invoking SNS Publish, or the Catch can route to a state that publishes to SNS before ending in a Fail state.

Exam trap

DVA-C02 often tests the misconception that Retry and Catch can be defined at the workflow (top) level in ASL — they cannot; they must be attached to individual Task, Parallel, or Map states.

How to eliminate wrong answers

Option A is wrong because implementing retry logic inside the Lambda function bypasses Step Functions' native error handling, loses visibility into retry attempts in the execution history, and doesn't leverage the state machine's declarative Retry/Catch semantics. Option B is wrong because IAM permissions alone do not implement retry or error routing — ResultPath is used to inject error info into the state output, not to handle errors or trigger retries. Option D is wrong because ASL does not support Retry or Catch at the workflow (top-level) scope; these fields are only valid within individual state definitions.

88
Multi-Selectmedium

A developer is creating an IAM policy to allow access to an Amazon DynamoDB table. The policy must allow the user to read and write items, but not to delete the table or modify its schema. Which TWO DynamoDB actions should be included in the policy?

Select 2 answers
A.UpdateTable
B.Scan
C.GetItem
D.DeleteTable
E.PutItem
AnswersC, E

The GetItem action is a fundamental data plane operation in DynamoDB, specifically designed to retrieve a single item from a table. It requires the full primary key (partition key and sort key, if applicable) to uniquely identify and fetch the desired data record, making it the precise action for reading individual items.

Why this answer

GetItem and PutItem are the actions for reading and writing individual items. DeleteTable and UpdateTable are administrative actions that should not be allowed.

89
MCQhard

A company has a production environment using AWS Elastic Beanstalk with a multi-container Docker platform. The application consists of a PHP web server and a Redis cache, each running in separate containers. The deployment uses a rolling update policy with a batch size of 1. Recently, during deployments, some users experience intermittent 502 Bad Gateway errors for about 30 seconds. The errors occur when the old containers are terminated and new containers are not yet ready to serve traffic. The development team wants to eliminate this downtime without increasing the deployment time significantly. The team has access to modify the Elastic Beanstalk environment configuration and the Dockerrun.aws.json file. Which action should the team take to resolve the issue?

A.Increase the batch size to 2 to reduce the number of deployment cycles.
B.Configure a health check grace period in the Elastic Beanstalk environment to delay load balancer registration until the containers are healthy.
C.Change the deployment policy to 'All at once' to complete the deployment faster.
D.Reduce the health check interval on the load balancer to detect healthy instances faster.
AnswerB

Configuring a health check grace period is crucial for allowing newly launched instances or containers sufficient time to fully initialize and pass their application-level health checks. This delay prevents the load balancer from prematurely marking an instance as unhealthy simply because it hasn't completed its startup routine. By doing so, it ensures that traffic is only routed to instances that are genuinely ready to serve requests, thereby maintaining application availability during deployments.

Why this answer

Configuring a health check grace period allows new containers time to become healthy before the load balancer routes traffic to them, preventing the 502 errors during the transition. Option A is incorrect because increasing the batch size would cause more containers to be replaced simultaneously, potentially increasing downtime. Option C is incorrect because 'All at once' deployment would terminate all old containers before starting new ones, causing full downtime.

Option D is incorrect because reducing the health check interval would make the load balancer check more frequently, which could cause premature routing to unhealthy instances and exacerbate the issue.

90
MCQmedium

A developer is debugging an AWS Lambda function that processes messages from an Amazon SQS queue. The function is failing with an error when processing certain messages. The developer wants to isolate the failed messages for later analysis without losing them. What should the developer do?

A.Publish the failed messages to an SNS topic for later processing.
B.Log the error and delete the message from the queue.
C.Increase the visibility timeout of the SQS queue.
D.Configure a dead-letter queue (DLQ) for the SQS queue.
AnswerD

Configuring a dead-letter queue (DLQ) for the SQS queue is the standard and most robust solution for handling message processing failures. When a Lambda function fails to process a message a specified number of times (defined by the maxReceiveCount on the redrive policy), SQS automatically moves that message to the DLQ. This isolates problematic messages for later inspection and debugging, prevents them from continuously blocking the main queue, and ensures no data is lost, allowing developers to analyze and re-process them.

Why this answer

Configuring a dead-letter queue (DLQ) for the SQS queue is the correct approach because it automatically captures messages that cannot be processed successfully after a specified number of retries (the redrive policy). This isolates the failed messages for later analysis without losing them, while allowing the function to continue processing other messages from the source queue.

Exam trap

The trap here is that candidates may think logging and deleting the message (Option B) is sufficient for debugging, but this permanently loses the message payload, whereas a DLQ preserves the message for later analysis without manual intervention.

How to eliminate wrong answers

Option A is wrong because publishing failed messages to an SNS topic would require custom code and does not provide automatic retry management or isolation; SNS is a pub/sub service, not a message retention mechanism for failed SQS messages. Option B is wrong because logging the error and deleting the message discards the message permanently, preventing later analysis of the failed message content. Option C is wrong because increasing the visibility timeout only delays when the message becomes visible again for reprocessing; it does not isolate the message or prevent it from being retried indefinitely, and it does not preserve the message for later analysis.

91
Multi-Selectmedium

A developer is building a serverless application using AWS Lambda to process images uploaded to an S3 bucket. The Lambda function needs to resize each image and store the result in another S3 bucket. Which TWO actions should the developer take to ensure the function can access the S3 buckets securely?

Select 2 answers
A.Create an IAM execution role for the Lambda function with permissions to read from the source bucket and write to the destination bucket.
B.Configure a bucket policy on the destination S3 bucket that grants the Lambda execution role s3:PutObject permission.
C.Store the AWS access key and secret key in the Lambda environment variables.
D.Assign an IAM user to the Lambda function and embed the user's access key in the function code.
E.Attach an IAM instance profile to the Lambda function.
AnswersA, B

Creating an IAM execution role is the standard and most secure method for a Lambda function to interact with other AWS services. This role defines the permissions the function assumes when invoked, allowing it to read objects from the source S3 bucket and write processed objects to the destination S3 bucket without embedding any static credentials. This adheres to the principle of least privilege, granting only necessary access.

Why this answer

Lambda functions require an IAM execution role that grants permissions to access other AWS services. By creating a role with policies that allow s3:GetObject on the source bucket and s3:PutObject on the destination bucket, the function can securely read and write images without embedding long-term credentials.

Exam trap

The trap here is that candidates often think they need to embed static credentials (access keys) in the function code or environment variables, but the AWS Well-Architected Framework mandates using IAM roles for temporary, least-privilege credentials in serverless applications.

92
MCQhard

A developer is deploying a Node.js application on AWS Lambda. The function uses the 'axios' library to call an external API. After deployment, the function times out after 3 seconds. The external API response time is normally under 500 ms. What should the developer do to resolve this issue?

A.Increase the Lambda function timeout to 10 seconds.
B.Increase the Lambda function reserved concurrency.
C.Remove the Lambda function from the VPC.
D.Increase the Lambda function memory to 1024 MB.
AnswerC

Removing the Lambda function from a Virtual Private Cloud (VPC) is unrelated to addressing function timeouts. Placing a Lambda function within a VPC allows it to access private resources like Amazon RDS databases or EC2 instances within that VPC. While incorrect VPC configuration (e.g., missing a NAT Gateway for internet access) can cause functions to hang and eventually time out due to network issues, the VPC configuration itself does not directly control or modify the function's execution timeout setting, which is an independent parameter.

Why this answer

When a Lambda function is configured to run inside a VPC, it loses its default internet access. If the function needs to call an external API, the connection will hang and eventually time out. Increasing the timeout (Option A) will not resolve this, as the network path is blocked.

To resolve this, the developer should either configure a NAT Gateway in the VPC or, if VPC resources are not required, remove the Lambda function from the VPC (Option C) to restore default internet access.

Exam trap

AWS often tests your understanding of Lambda VPC networking. Candidates frequently assume that increasing the timeout (Option A) or memory (Option D) will solve timeout issues, but if the root cause is a lack of internet access due to VPC configuration, the function will continue to time out regardless of the timeout limit or memory allocated.

How to eliminate wrong answers

Option B is wrong because increasing reserved concurrency only guarantees a set number of concurrent executions, which does not affect the execution duration or timeout behavior of a single invocation. Option C is wrong because removing the function from a VPC would only help if the timeout were caused by network latency or missing VPC endpoints; the problem is a timeout on an external API call, which is not inherently related to VPC configuration. Option D is wrong because increasing memory to 1024 MB allocates more CPU and network throughput, which can speed up execution but does not change the maximum allowed execution time; the function still times out at 3 seconds regardless of memory size.

93
MCQeasy

A developer needs to grant least-privilege access to a Lambda function to write logs to CloudWatch Logs. Which IAM policy effect should be used?

A.Always allow
B.Allow
C.Deny
D.Revoke
AnswerB

Allow is the correct IAM policy effect for least-privilege access because it explicitly grants only the specific actions listed, such as logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents, scoped to the exact CloudWatch Logs resource ARNs the Lambda function needs, without granting any broader access.

Why this answer

IAM policies use the Effect element with valid values of Allow or Deny; to grant least-privilege access, the policy statement must specify Effect: Allow with the specific action logs:CreateLogGroup, logs:CreateLogStream, and logs:PutLogEvents scoped to the function's log group. Allow is the only effect that grants permissions in an identity-based policy. Deny would explicitly block the action, which is the opposite of the requirement.

Exam trap

DVA-C02 often tests IAM policy syntax basics, and the trap is that candidates overthink the question and look for a special effect, when the only valid granting effect is Allow.

How to eliminate wrong answers

Option A is wrong because 'Always allow' is not a valid IAM policy effect value; IAM only accepts Allow or Deny. Option C is wrong because Deny explicitly blocks the action and would prevent the Lambda function from writing logs, contradicting the least-privilege grant requirement. Option D is wrong because 'Revoke' is not a valid IAM policy effect and does not exist in IAM policy syntax.

94
MCQmedium

A company is using AWS CodeCommit for source control. Developers need to access the repository from their local machines. Which authentication method is recommended for secure access?

A.Use IAM user name and password for Git credentials.
B.Use IAM access key and secret key for authentication.
C.Use Amazon Cognito user pools for authentication.
D.Generate and use SSH keys paired with an IAM user.
AnswerD

Generating an SSH key pair and associating the public key with an IAM user is a secure and widely recommended method for authenticating Git operations with AWS CodeCommit. The private key resides on the developer's local machine, and CodeCommit uses the registered public key to verify the developer's identity during Git push/pull operations, ensuring secure access without exposing long-lived credentials. This method leverages standard Git SSH protocols.

Why this answer

SSH keys provide secure access without storing credentials on the machine and can be paired with an IAM user for CodeCommit. Option A is wrong because IAM user password is for console access, not Git. Option B is wrong because while access keys can be used for Git credentials, they are long-term credentials and less secure than SSH keys.

Option C is wrong because Cognito is for end-user authentication, not developer access to CodeCommit.

95
MCQeasy

A company is using AWS CodePipeline to automate its CI/CD pipeline. The pipeline has a source stage that uses Amazon S3. The developer updates a file in the S3 bucket, but the pipeline does not start automatically. What is the MOST likely cause?

A.The IAM role for CodePipeline does not have s3:GetObject permission.
B.The pipeline is configured to use polling instead of event-based triggers.
C.Amazon S3 versioning is not enabled on the bucket.
D.AWS CloudTrail is not enabled.
AnswerC

Amazon S3 versioning is a mandatory prerequisite for CodePipeline source actions that monitor an S3 bucket for changes. CodePipeline relies on S3 event notifications, specifically s3:ObjectCreated:* events, to detect new or updated artifacts. Without versioning enabled on the S3 bucket, these critical event notifications may not be reliably generated or processed by CodePipeline, preventing the pipeline from automatically triggering upon artifact uploads.

Why this answer

CodePipeline requires S3 versioning to be enabled on the source bucket to automatically detect changes and start the pipeline. Without versioning, CodePipeline cannot uniquely identify new object versions, so it relies on manual or scheduled polling instead of event-based triggers. Enabling versioning ensures that each PUT operation generates a new version ID, which CodePipeline uses to invoke the pipeline automatically.

Exam trap

The trap here is that candidates often assume the IAM role permissions (Option A) are the root cause, but the actual requirement is S3 versioning, which is a bucket-level configuration that enables event-driven pipeline starts.

How to eliminate wrong answers

Option A is wrong because the IAM role for CodePipeline needs s3:GetObject permission to read the source artifact, but the lack of this permission would cause the pipeline to fail during execution, not prevent it from starting. Option B is wrong because polling is a fallback mechanism; the pipeline is configured to use event-based triggers by default when versioning is enabled, and the issue is that versioning is disabled, not that polling is explicitly configured. Option D is wrong because AWS CloudTrail is not required for CodePipeline to detect S3 events; CloudTrail logs API calls for auditing but does not trigger pipeline executions.

96
MCQmedium

A developer is designing a system where an S3 bucket receives uploads, and each upload triggers a Lambda function to process the file. The processed output is stored in another S3 bucket. The developer notices that sometimes the same file is processed multiple times. How can this be prevented?

A.Make the Lambda function idempotent by checking if the object has already been processed using a DynamoDB table.
B.Use an SQS FIFO queue as the event destination and enable content-based deduplication.
C.Enable S3 bucket replication to another bucket and trigger Lambda from the replica.
D.Enable S3 bucket versioning and use 's3:ObjectCreated:Put' events.
AnswerA

To ensure reliable processing despite S3's "at-least-once" event delivery model, a Lambda function must be idempotent. This is achieved by using a persistent store, such as a DynamoDB table, to record unique identifiers of processed S3 objects. Before processing an S3 event, the Lambda function checks if the object's unique identifier (e.g., bucket name + object key + version ID) already exists in the DynamoDB table. If it does, the function skips processing, preventing duplicate work and maintaining data consistency.

Why this answer

Making the Lambda function idempotent using a DynamoDB table ensures that even if the same S3 event is delivered multiple times (due to at-least-once delivery semantics) or if the same file is uploaded again, the function checks a unique identifier (such as the object key or hash) in DynamoDB before processing. If it has already been processed, the function can safely skip it. This is the standard architectural pattern for ensuring idempotency in serverless pipelines.

Exam trap

While Amazon S3 Event Notifications do support SQS FIFO queues as destinations, relying solely on SQS FIFO deduplication is insufficient. SQS FIFO deduplication has a strict 5-minute window and does not protect against Lambda retries, function timeouts, or duplicate uploads occurring outside that window. True end-to-end idempotency must be implemented at the application level (e.g., using DynamoDB).

How to eliminate wrong answers

Option B is wrong because S3 cannot send events directly to an SQS FIFO queue; S3 event notifications only support standard SQS queues, not FIFO queues. Option C is wrong because S3 replication is asynchronous and does not prevent duplicate processing; it would actually introduce additional copies and potential duplicate triggers. Option D is wrong because enabling versioning and using 's3:ObjectCreated:Put' events does not prevent duplicate invocations; versioning creates new versions but S3 still sends at-least-once notifications for each Put, so the same object version can trigger Lambda multiple times.

97
MCQmedium

A company uses CodePipeline to deploy a web application to Elastic Beanstalk. The deployment fails at the Build stage with an error 'BUILD FAILED'. Which step should the developer take first to troubleshoot?

A.Review the buildspec.yml file for syntax errors
B.Verify the CodeDeploy application revision
C.Examine the Elastic Beanstalk environment logs
D.Check AWS CloudTrail for API calls
AnswerA

When a CodePipeline build stage fails, the `buildspec.yml` file is the primary configuration for the AWS CodeBuild project responsible for compiling code, running tests, and packaging artifacts. Syntax errors within this YAML file, such as incorrect indentation, invalid commands, or missing required phases, will directly prevent CodeBuild from executing its defined steps successfully. Reviewing the CodeBuild project logs, which detail the execution of each command specified in `buildspec.yml`, is crucial for identifying the exact line or phase where the build process encountered an unrecoverable error.

Why this answer

The error 'BUILD FAILED' originates from the Build stage, which is executed by CodeBuild. The first step in troubleshooting a CodeBuild failure is to review the buildspec.yml file for syntax errors or misconfigurations, as this file defines the build commands, environment variables, and phases. Incorrect YAML formatting, missing required fields (e.g., 'phases'), or invalid commands will cause the build to fail immediately, making it the most direct and logical starting point.

Exam trap

The trap here is that candidates may jump to checking Elastic Beanstalk logs or CloudTrail, assuming the failure is related to deployment or API issues, when the error clearly indicates a build-stage failure that is most often caused by a misconfigured buildspec.yml file.

How to eliminate wrong answers

Option B is wrong because CodeDeploy is used in the Deploy stage, not the Build stage; verifying the application revision would only be relevant if the failure occurred during deployment, not during the build process. Option C is wrong because Elastic Beanstalk environment logs pertain to runtime issues with the deployed application, not to build-time failures in CodeBuild; the build fails before any deployment to Elastic Beanstalk occurs. Option D is wrong because AWS CloudTrail records API calls for auditing and security, but it does not provide granular details about build execution errors, such as syntax errors in buildspec.yml or command failures within CodeBuild.

98
Multi-Selectmedium

A developer is using AWS CodePipeline to automate the deployment of a microservices application. The pipeline consists of a source stage (GitHub), a build stage (AWS CodeBuild), and a deploy stage (Amazon ECS). The developer wants to ensure that only approved changes are deployed to production. Which THREE actions should the developer take? (Choose THREE.)

Select 3 answers
A.Configure the pipeline to automatically deploy every commit to production.
B.Deploy all feature branches directly to production.
C.Add a manual approval step before the deploy stage.
D.Use separate pipelines for different environments (e.g., dev, staging, prod).
E.Implement integration tests in the build stage to catch errors early.
AnswersC, D, E

In CodePipeline, a manual approval step is an action that pauses the pipeline execution at a specified stage and sends an SNS notification to designated reviewers. The reviewer must sign in, review the deployment details, and choose Approve or Reject before the Deploy stage can run, providing a human control point for production changes. This is the recommended way to satisfy a 'gates' requirement without removing automation.

Why this answer

Option C is correct because inserting a manual approval action (an Approval action in CodePipeline, typically using Amazon SNS to notify approvers) between the build stage and the ECS deploy stage gates production deployment so that only changes a human explicitly approves proceed to production. Option D is correct because using separate pipelines for dev, staging, and prod isolates environments, so a change must pass through the earlier pipelines before a production pipeline is triggered, preventing unvetted commits from reaching production. Option E is correct because adding integration tests in the CodeBuild build stage (via buildspec.yml commands) validates the microservices against their dependencies and fails the pipeline on errors, so broken or unapproved-quality changes never reach the deploy stage.

Option A is incorrect because automatically deploying every commit to production removes any approval gate and directly contradicts the requirement that only approved changes be deployed. Option B is incorrect because deploying all feature branches directly to production bypasses review, testing, and approval, which is exactly the risk the developer wants to eliminate.

Exam trap

DVA-C02 often tests the misconception that automation alone ensures safety, so candidates select auto-deploy options instead of recognizing that approval gates and environment separation are required for controlled production releases.

99
MCQmedium

A developer is building an order-processing workflow using AWS Step Functions. The state machine has a Task state that invokes a Lambda function to charge a credit card. The Lambda function occasionally returns a transient error due to a downstream payment gateway timeout. The developer must ensure the workflow automatically retries the charge up to 3 times with increasing intervals between attempts, without modifying the state machine definition for every error type. Which solution meets these requirements with the LEAST operational overhead?

A.Wrap the Lambda invocation in an SQS queue with a visibility timeout and a dead-letter queue, and have the state machine poll the queue.
B.Configure a Retry field on the Task state with ErrorEquals set to States.TaskFailed, IntervalSeconds set to 2, MaxAttempts set to 3, and BackoffRate set to 2.0.
C.Modify the Lambda function to implement its own retry loop with exponential backoff using the AWS SDK retry configuration.
D.Enable AWS X-Ray tracing on the Lambda function and use CloudWatch alarms to trigger a new state machine execution on failure.
AnswerB

The Retry field on a Task state natively supports ErrorEquals, IntervalSeconds, MaxAttempts, and BackoffRate. Setting ErrorEquals to States.TaskFailed catches Lambda function errors, and BackoffRate 2.0 doubles the wait each retry, satisfying the increasing-interval requirement without code changes or additional services.

Why this answer

Step Functions Task states support built-in retry policies through the Retry field, which accepts ErrorEquals, IntervalSeconds, MaxAttempts, and BackoffRate. Using States.TaskFailed as the error matcher catches errors returned by the Lambda function, and BackoffRate greater than 1.0 produces the required increasing intervals. This declarative approach requires no changes to the Lambda code or additional services, minimizing operational overhead.

Exam trap

The trap here is assuming that retries must be implemented in code or with additional services, when Step Functions provides a declarative Retry field with exponential backoff.

100
Multi-Selectmedium

A developer is building a RESTful API using AWS Lambda and Amazon API Gateway. The API will be accessed by external customers. The developer needs to implement authentication and authorization. Which THREE steps should the developer take to secure the API? (Choose three.)

Select 3 answers
A.Use Amazon Cognito user pools for user authentication and to generate JWT tokens.
B.Configure the API to use AWS IAM roles for authentication by passing the role ARN in the request.
C.Create a Lambda authorizer that validates a JWT token from a third-party identity provider.
D.Enable Amazon Cognito as an authorizer in the API Gateway method request settings.
E.Attach a resource policy to the API Gateway that allows only specific IAM users.
AnswersA, C, D

Amazon Cognito User Pools are a fully managed service designed for user directory management, sign-up, and sign-in. They authenticate users and issue JSON Web Tokens (JWTs) (ID, access, and refresh tokens) upon successful authentication. These JWTs can then be used by clients to authorize requests to an API Gateway, making Cognito a robust and scalable solution for user authentication in RESTful APIs.

Why this answer

Amazon Cognito user pools provide a fully managed service for user authentication, allowing users to sign in and receive JSON Web Tokens (JWT). These tokens can then be used to authorize API requests, integrating directly with API Gateway as a built-in authorizer to secure the RESTful API.

Exam trap

The trap here is that candidates may confuse IAM roles with user authentication, thinking that passing a role ARN in the request is valid, when in fact IAM authorization requires signed requests and is not suitable for external customer authentication without AWS credentials.

101
Multi-Selecteasy

A developer is building a serverless application using AWS Lambda and Amazon API Gateway. The application processes user uploads stored in an S3 bucket. The developer needs to ensure that the Lambda function can read objects from the S3 bucket. Which TWO steps should the developer take to meet this requirement? (Choose two.)

Select 2 answers
A.Set the S3 bucket's object-level permissions to allow the Lambda function.
B.Use AWS Key Management Service (KMS) to grant the Lambda function access to the S3 bucket.
C.Add a bucket policy on the S3 bucket that grants access to the Lambda function's execution role.
D.Attach an IAM policy to the Lambda execution role with permissions for s3:GetObject.
E.Create an IAM user with S3 read permissions and configure the Lambda function to assume that user.
AnswersC, D

Because the Lambda function and the S3 bucket reside in different accounts (or because the bucket owner controls the resource), a bucket policy on the S3 bucket is the resource-based policy that can explicitly grant the Lambda execution role's ARN permission to s3:GetObject. S3 evaluates both the identity-based policy on the principal (the Lambda role) and the resource-based policy, and a statement in the bucket policy that allows the role's ARN satisfies the resource authorization. This is the recommended way to enable cross-account or cross-service access because it does not require creating or rotating IAM users.

Why this answer

Option D is correct because a Lambda function accesses AWS services through its execution role, so attaching an IAM policy that allows s3:GetObject (and typically s3:ListBucket) to that role grants the function the required read access to objects in the bucket. Option C is correct because a bucket policy is a resource-based policy that can explicitly grant the Lambda function's execution role principal access to the S3 bucket and its objects, which is a valid way to authorize the read operations. Option A is incorrect because S3 object-level permissions are ACLs that grant access to AWS accounts or predefined groups, not to a Lambda function directly, and ACLs are not the recommended mechanism for Lambda-to-S3 authorization.

Option B is incorrect because KMS is used for encryption key management and does not itself grant S3 data access; KMS permissions would only matter if the objects are encrypted with a customer managed key. Option E is incorrect because Lambda functions should use an execution role, not assume an IAM user with long-term credentials, which is an insecure and unsupported pattern for this scenario.

Exam trap

DVA-C02 often tests the misconception that you can grant S3 access by setting object ACLs or by using KMS, when in fact Lambda requires an IAM execution role with the appropriate S3 permissions.

102
Multi-Selecthard

Which THREE are best practices for managing IAM users and roles? (Choose three.)

Select 3 answers
A.Rotate IAM user access keys periodically.
B.Grant least privilege permissions.
C.Use IAM roles for EC2 instances instead of storing access keys.
D.Use the root account for daily administrative tasks.
E.Assign full administrator access to all users.
AnswersA, B, C

IAM user access keys are long-term credentials that remain valid until explicitly deactivated or deleted. Periodic rotation—for example, via an automated script or the AWS Console—shrinks the exploit window should a key leak into source code or logs. AWS provides 'last used' information to help identify and prune stale keys, and rotating keys is a fundamental part of any credential management policy.

Why this answer

Option A is correct because periodically rotating IAM user access keys limits the window of exposure if a key is compromised, and AWS best practices recommend key rotation (for example, via the IAM console or aws iam create-access-key/update-access-key/delete-access-key). Option B is correct because granting least privilege means attaching only the minimal IAM policies and permissions required for a principal's task, reducing the blast radius of accidental or malicious actions. Option C is correct because EC2 instances should assume an IAM role through instance profiles and the Instance Metadata Service (IMDS) to obtain temporary credentials via AWS STS, eliminating long-lived access keys stored on the instance.

Option D is not correct because the root account should be used only for a few account-level tasks, protected with MFA, and never for daily administration. Option E is not correct because assigning full administrator access to all users violates least privilege and dramatically increases security risk.

Exam trap

DVA-C02 often tests the misconception that root account usage or broad admin access is acceptable for convenience, when AWS best practice strictly prohibits both.

103
MCQhard

A developer is deploying a microservices architecture on Amazon ECS with Fargate. The services need to communicate with each other using service discovery. The developer wants to use AWS Cloud Map for service discovery. Which configuration is required for the services to register and discover each other?

A.Create an Application Load Balancer and register each service as a target group.
B.Create a VPC endpoint for each service.
C.Configure Security Groups to allow traffic between services.
D.Create a Cloud Map namespace and service; then configure ECS tasks to register with the service.
AnswerD

AWS Cloud Map is a cloud service discovery solution that allows you to register any application resource, such as microservices, and then define custom names for them. It provides a centralized registry that services can query using either DNS queries or an API to discover the network locations (IP addresses and ports) of other services. By configuring ECS tasks to register with a Cloud Map service, new instances automatically become discoverable, which is essential for the dynamic and ephemeral nature of microservices.

Why this answer

AWS Cloud Map requires a namespace (either HTTP or DNS) and a service resource. ECS tasks configured with service discovery can register themselves with the Cloud Map service, and other tasks can discover them via DNS queries or the Cloud Map API. Option A is incorrect because an Application Load Balancer is used for load balancing traffic, not for service discovery.

Option B is incorrect because VPC endpoints provide private connectivity to AWS services, not service registration and discovery. Option C is incorrect because Security Groups control network traffic but do not facilitate service discovery.

104
MCQeasy

A developer is writing an AWS Lambda function that processes files uploaded to an S3 bucket. The function should only be triggered when a new object is created in a specific subfolder (e.g., /uploads/). Which S3 event notification configuration should the developer use?

A.Configure the event notification with a prefix filter set to 'uploads/' and event type 's3:ObjectCreated:*'.
B.Configure a single event notification for all objects and filter on the prefix inside the Lambda function.
C.Configure the event notification using object tags to filter events.
D.Use AWS CloudTrail to detect S3 PutObject events and trigger Lambda.
AnswerA

This approach leverages Amazon S3's native event notification capabilities to precisely target specific object creation events. By setting a prefix filter to 'uploads/', the S3 bucket will only send notifications to the Lambda function when an object is created within that specific virtual folder. Combining this with the `s3:ObjectCreated:*` event type ensures that the Lambda function is invoked solely for new object uploads in the designated path, optimizing resource utilization and minimizing unnecessary Lambda invocations and associated costs.

Why this answer

S3 event notifications support prefix filtering, which allows you to specify a key prefix (e.g., 'uploads/') so that only object creation events in that subfolder trigger the Lambda function. By setting the event type to 's3:ObjectCreated:*', the function responds to all object creation operations (PUT, POST, Copy, etc.) within the filtered path, meeting the requirement precisely without unnecessary invocations.

Exam trap

The trap here is that candidates might think filtering inside the Lambda function is acceptable (Option B), but AWS best practice and the exam emphasize configuring filtering at the event source to minimize invocations and follow the principle of least privilege for triggers.

How to eliminate wrong answers

Option B is wrong because filtering on the prefix inside the Lambda function would still cause the function to be invoked for every object created in the bucket, leading to unnecessary executions and increased costs; S3 event notifications support prefix filtering natively, so this should be configured at the event source level. Option C is wrong because S3 event notifications do not support filtering by object tags; tag-based filtering is not a feature of S3 event notifications, and tags are not evaluated during event generation. Option D is wrong because AWS CloudTrail is not designed for real-time event-driven triggers; it logs API calls with a delay and is intended for auditing, not for invoking Lambda functions in response to S3 object creation events.

105
MCQmedium

A developer is deploying a serverless application using AWS SAM. The application includes an AWS Lambda function that is triggered by an S3 bucket event when an object is created. The developer wants to ensure that the Lambda function has the correct permissions to be invoked by S3. Which resource should the developer define in the SAM template?

A.AWS::Lambda::Permission
B.AWS::S3::BucketPolicy
C.AWS::Lambda::EventSourceMapping
D.AWS::IAM::Role
AnswerA

AWS::Lambda::Permission creates the resource-based policy granting S3 the lambda:InvokeFunction action, which is what allows the bucket's event notification to invoke the function. Execution roles govern outbound calls, not inbound invocation, so this resource satisfies the stated requirement.

Why this answer

AWS::Lambda::Permission is the correct resource because it explicitly grants the S3 service principal permission to invoke the Lambda function when an object is created. In AWS SAM, this resource is automatically generated when you define an S3 event source on a Lambda function, but if you need to declare it manually or override permissions, you use AWS::Lambda::Permission with a SourceArn pointing to the S3 bucket and a SourceAccount to prevent confused deputy attacks.

Exam trap

The trap here is that candidates confuse the Lambda execution role (IAM::Role) with the invocation permission (Lambda::Permission), or mistakenly think S3 uses a bucket policy or event source mapping to trigger Lambda, when in fact S3 uses a push-based notification that requires a resource-based policy on the Lambda function.

How to eliminate wrong answers

Option B is wrong because AWS::S3::BucketPolicy controls access to the S3 bucket itself (e.g., who can read/write objects), not who can invoke a Lambda function; S3 uses a Lambda resource-based policy, not a bucket policy, to trigger invocations. Option C is wrong because AWS::Lambda::EventSourceMapping is used for poll-based event sources like DynamoDB Streams, Kinesis, or SQS, not for S3 event notifications, which are push-based and do not require an event source mapping. Option D is wrong because AWS::IAM::Role defines the execution role for the Lambda function (what the function can do), not the permissions for S3 to invoke the function; invocation permissions are handled via a resource-based policy on the Lambda function itself.

106
MCQhard

A company uses AWS Organizations with multiple accounts. A developer needs to grant an IAM user in Account A (111111111111) read-only access to an S3 bucket in Account B (222222222222). The bucket is encrypted with SSE-S3. Which combination of policies is required for cross-account access?

A.Bucket policy in Account B granting s3:GetObject to the IAM user ARN, and an IAM policy in Account A allowing s3:GetObject.
B.Bucket policy in Account B granting s3:GetObject to Account A's root user ARN, and an IAM policy in Account A allowing s3:GetObject.
C.Bucket policy in Account B granting s3:GetObject to the IAM user ARN, and no IAM policy in Account A is needed.
D.IAM policy in Account A allowing s3:GetObject, and an S3 Access Point in Account B configured for cross-account access.
AnswerA

This combination correctly implements cross-account S3 access using the standard two-policy model. The bucket policy in Account B explicitly grants the `s3:GetObject` permission to the specific IAM user's ARN in Account A, acting as the resource-based policy. Concurrently, the IAM policy attached to the user in Account A allows that user to perform the `s3:GetObject` action, serving as the identity-based policy. Both policies must explicitly permit the action for access to be granted successfully.

Why this answer

Cross-account S3 access requires both a bucket policy in the resource account (Account B) that explicitly grants the IAM user ARN from Account A the s3:GetObject permission, and an IAM policy in the user's account (Account A) that allows the same action. The bucket policy acts as a resource-based policy that authorizes the cross-account principal, while the IAM policy is necessary to authorize the user to make the request. SSE-S3 encryption does not require additional configuration because S3 handles decryption automatically for authorized users.

Exam trap

The trap here is that candidates often think only a bucket policy is needed for cross-account access, forgetting that the IAM user must also have an explicit allow in their own account's IAM policy to actually invoke the S3 API call.

How to eliminate wrong answers

Option B is wrong because granting access to Account A's root user ARN would allow any principal in Account A to assume root-level permissions, which is overly broad and not a best practice; the correct approach is to grant access to the specific IAM user ARN. Option C is wrong because without an IAM policy in Account A allowing s3:GetObject, the IAM user lacks the necessary permissions to initiate the request, even if the bucket policy grants access; both policies are required for cross-account access. Option D is wrong because an S3 Access Point in Account B can simplify cross-account access but still requires a bucket policy that grants access to the Access Point, and the IAM user in Account A still needs an IAM policy allowing s3:GetObject; the Access Point alone does not eliminate the need for both policies.

107
MCQmedium

A developer attaches the IAM policy shown to a user. The user attempts to upload an object to example-bucket using the AWS CLI with the command: `aws s3 cp file.txt s3://example-bucket/`. The upload fails. What is the MOST likely reason?

A.The user does not have permission to perform s3:PutObject on the bucket.
B.The bucket policy overrides the IAM policy and denies the request.
C.The resource ARN does not include the bucket itself.
D.The user did not specify server-side encryption in the request.
AnswerD

The IAM policy includes a `Condition` requiring `s3:x-amz-server-side-encryption` to be `AES256`. This means any `s3:PutObject` request must explicitly include the `x-amz-server-side-encryption` header with the exact value `AES256`. If the user's request omits this specific header or provides a different encryption method, the condition will not be met, and the action will be implicitly denied, causing the upload to fail.

Why this answer

The IAM policy shown (not provided in the question but implied by the context) likely includes a condition that requires server-side encryption (e.g., `s3:x-amz-server-side-encryption: AES256`). The `aws s3 cp` command by default does not set the `--sse` flag, so the request lacks the required encryption header, causing S3 to deny the upload with an AccessDenied error.

Exam trap

The trap here is that candidates often assume an upload failure is due to missing `s3:PutObject` permission, overlooking that S3 condition keys (like encryption requirements) can silently deny requests even when the base action is allowed.

How to eliminate wrong answers

Option A is wrong because the IAM policy likely grants `s3:PutObject` on the bucket (the policy is not shown but the question implies it exists), so the failure is not due to missing PutObject permission. Option B is wrong because bucket policies and IAM policies are evaluated together; unless an explicit Deny exists, the effective permission is the union of allows, and the question does not indicate a bucket policy. Option C is wrong because the resource ARN `arn:aws:s3:::example-bucket/*` correctly covers objects within the bucket, and the `s3:PutObject` action operates on objects, not the bucket itself.

108
MCQmedium

A web application running on EC2 instances behind an Application Load Balancer (ALB) is experiencing intermittent 503 errors. The ALB target group health checks are succeeding. Which step should the developer take FIRST to diagnose the issue?

A.Increase the number of EC2 instances in the target group.
B.Examine the ALB access logs for 503 responses.
C.Check the Route 53 record for the ALB.
D.Verify that the EC2 instances are in a running state.
AnswerB

Examining ALB access logs is the most effective diagnostic step because these logs capture detailed information about every request processed by the load balancer, including the HTTP status code returned to the client and the target status code from the EC2 instance. Filtering for 503 responses ("HTTP 503" or "target_status_code:503") allows identification of specific request patterns, source IPs, or target groups that are experiencing issues. This data helps pinpoint whether the 503s are due to application errors, target connection issues, or other load balancer-related problems.

Why this answer

The correct first step is to examine the ALB access logs for 503 responses. Since health checks are succeeding, the EC2 instances are considered healthy by the target group, but the ALB itself may be returning 503 errors due to issues like request rate limits, connection limits, or backend response timeouts. Access logs provide detailed HTTP response codes and timestamps, allowing you to identify the pattern and cause of the 503 errors without making assumptions about instance count or state.

Exam trap

The trap here is that candidates assume 503 errors always mean unhealthy instances, so they jump to checking instance state or scaling, ignoring that health checks are passing and that ALB-level issues (like connection limits or timeouts) are the actual cause.

How to eliminate wrong answers

Option A is wrong because increasing the number of EC2 instances does not address the root cause of 503 errors when health checks are passing; it may mask the issue but does not diagnose it. Option C is wrong because Route 53 records only affect DNS resolution, not the ALB's ability to forward requests to healthy targets; a misconfigured Route 53 record would cause different errors (e.g., 503 or connection failures) but checking it first is premature when the ALB itself is reachable. Option D is wrong because the health checks are succeeding, which already confirms the EC2 instances are in a running state and responding to health check pings; verifying instance state again is redundant and does not explain the intermittent 503 errors.

109
MCQeasy

A developer is deploying a serverless application using AWS SAM. The deployment fails with the error 'Resource creation cancelled'. What is the most likely cause?

A.The SAM template is malformed.
B.A resource in the stack failed to create.
C.The Lambda function code has a timeout.
D.The IAM role does not have sufficient permissions.
AnswerB

'Resource creation cancelled' is CloudFormation's standard rollback behavior: when one resource in the stack fails to create (for example, an S3 bucket name collision or an invalid property value), CloudFormation cancels the creation of any remaining resources that haven't started yet and begins rolling back what did get created.

Why this answer

The 'Resource creation cancelled' error in AWS SAM indicates that the CloudFormation stack creation was cancelled because one or more resources failed to create, triggering a rollback. Option A is incorrect because a malformed SAM template would produce a validation error, not 'Resource creation cancelled'. Option C is incorrect because a Lambda function timeout is a runtime issue, not a deployment error.

Option D is incorrect because insufficient IAM permissions would result in an access denied error, not this specific cancellation message.

110
MCQhard

A company has an S3 bucket configured with server-side encryption using AWS KMS (SSE-KMS). An application running on EC2 with an appropriate IAM role is unable to write objects to the bucket. The error message indicates an access denied error. Which additional permission is most likely required?

A.kms:GenerateDataKey
B.kms:Decrypt
C.kms:Encrypt
D.kms:ReEncrypt
AnswerA

When an object is written to a bucket using SSE-KMS, S3 internally calls KMS on the caller's behalf to generate a unique data encryption key for that object, so the IAM principal performing the PutObject must be granted kms:GenerateDataKey on the KMS key; without it, S3 cannot obtain the key material needed to encrypt the object and the write fails with access denied.

Why this answer

When writing an object to an S3 bucket encrypted with SSE-KMS, S3 must call KMS GenerateDataKey to obtain a data key for envelope encryption, so the writer needs kms:GenerateDataKey on the KMS key. Without it, the PutObject call fails with AccessDenied even if s3:PutObject is granted.

Exam trap

DVA-C02 often tests the envelope encryption workflow, baiting candidates into choosing kms:Encrypt when the actual KMS action S3 invokes for SSE-KMS writes is kms:GenerateDataKey.

How to eliminate wrong answers

Option B is wrong because kms:Decrypt is required for reading objects, not writing them; the error occurs on write, so Decrypt is not the missing permission. Option C is wrong because kms:Encrypt alone is not what S3 uses for SSE-KMS; S3 uses GenerateDataKey to create a data key and then encrypts the object with it, so Encrypt is not the correct action. Option D is wrong because kms:ReEncrypt is used when changing encryption keys or re-encrypting existing ciphertext, not for initial object uploads.

111
MCQeasy

A developer is using the AWS CLI to deploy a new version of a Lambda function. The developer runs the following command: aws lambda update-function-code --function-name my-function --zip-file fileb://my-code.zip After the command completes, the developer checks the function and sees that the code has been updated but the version number is still $LATEST. The developer wants to create a new version so that the previous version is preserved. What should the developer do next?

A.Run the update-function-code command again with the --publish flag.
B.Run the delete-function command and then create-function with the updated code.
C.Run the publish-version command to create a new version from the updated $LATEST.
D.Run the update-function-configuration command to set the version number.
AnswerC

The publish-version command is the precise and correct mechanism to create an immutable, numbered version of a Lambda function based on the current state of its $LATEST qualifier. Since the developer has already successfully updated the function's code (which implicitly updates $LATEST), this command will capture that specific, updated code as a new, distinct version. This new version can then be referenced by aliases, enabling controlled deployments and reliable rollbacks.

Why this answer

The `update-function-code` command without the `--publish` flag only updates the `$LATEST` version of the Lambda function. To create an immutable, numbered version that preserves the previous code, the developer must explicitly run the `publish-version` command, which takes the current `$LATEST` code and publishes it as a new version (e.g., version 2). This ensures the previous version (version 1) remains unchanged and can be referenced via its version ARN.

Exam trap

The trap here is that candidates assume the `update-function-code` command automatically creates a new version, but it only updates `$LATEST` unless the `--publish` flag is explicitly used, leading them to incorrectly choose Option A or D.

How to eliminate wrong answers

Option A is wrong because the `--publish` flag is used with `update-function-code` to publish a new version in a single step, but running the command again without it will not retroactively publish the already-updated `$LATEST`; it would simply re-upload the same code. Option B is wrong because deleting and recreating the function is unnecessary and destructive—it removes all existing versions, aliases, and event source mappings, which is not required to simply create a new version from the updated code. Option D is wrong because `update-function-configuration` modifies settings like memory, timeout, or environment variables, not the version number; version numbers are immutable and can only be created via `publish-version` or the `--publish` flag during code update.

112
Multi-Selecthard

A Lambda function reading from Kinesis is falling behind. Which two metrics/settings should be reviewed first?

Select 2 answers
A.IteratorAge for the event source mapping
B.S3 bucket public access settings
C.Route 53 hosted zone count
D.Batch size, parallelization factor, and shard count
AnswersA, D

IteratorAge is a critical Amazon Kinesis Streams metric, reported by the Event Source Mapping, that measures the age of the last record successfully processed by the Lambda function. A consistently high or increasing IteratorAge directly indicates that the Lambda function is falling behind in processing records from the Kinesis stream. This metric provides a real-time, direct measurement of the processing lag, making it the primary indicator for diagnosing such issues.

Why this answer

The IteratorAge metric measures how far behind the Lambda function is in processing records from the Kinesis stream. A high IteratorAge indicates the function is falling behind, making it the primary metric to review. The batch size, parallelization factor, and shard count directly control the concurrency and throughput of the event source mapping, so adjusting these settings can help catch up.

Exam trap

The trap here is that candidates may overlook the direct performance-tuning metrics (IteratorAge, batch size, parallelization factor) and instead focus on unrelated AWS services like S3 or Route 53, which are red herrings in this troubleshooting context.

113
MCQeasy

Which AWS service provides a managed, rotating secret store for database credentials?

A.AWS Secrets Manager
B.AWS KMS
C.AWS IAM Roles
D.AWS Systems Manager Parameter Store
AnswerA

AWS Secrets Manager is a dedicated, managed service designed for securely storing, managing, and automatically rotating database credentials, API keys, and other secrets throughout their lifecycle. It provides built-in, configurable rotation for supported AWS services like RDS, Redshift, and DocumentDB, as well as custom rotation logic via AWS Lambda functions. This automatic rotation capability significantly enhances security by regularly changing credentials, minimizing the impact of compromised secrets.

Why this answer

AWS Secrets Manager is the correct service because it is specifically designed to manage the entire lifecycle of secrets, including automatic rotation of database credentials on a configurable schedule (e.g., every 30 days). It natively integrates with Amazon RDS, Aurora, Redshift, and DocumentDB to rotate credentials without application downtime, using a built-in Lambda rotation function. This makes it the only fully managed, rotating secret store among the options.

Exam trap

The trap here is that candidates confuse AWS Systems Manager Parameter Store (which can store secrets) with Secrets Manager, but Parameter Store lacks native automatic rotation, making Secrets Manager the only correct answer for a managed rotating secret store.

How to eliminate wrong answers

Option B (AWS KMS) is wrong because it is a key management service for creating and controlling encryption keys, not a secret store; it does not store or rotate database credentials. Option C (AWS IAM Roles) is wrong because IAM roles provide temporary credentials for AWS service access via the AWS STS, but they are not a secret store and cannot store or rotate static database passwords. Option D (AWS Systems Manager Parameter Store) is wrong because while it can store secrets as SecureString parameters, it does not provide native automatic rotation of database credentials; rotation must be implemented manually or via custom automation.

114
MCQeasy

A developer is building a RESTful API that allows clients to query a database and retrieve results. The backend logic is implemented in AWS Lambda, which queries an Amazon DynamoDB table. The developer wants to expose the API over HTTPS and manage authentication and throttling. Which AWS service should the developer use to create and manage the API endpoints?

A.Application Load Balancer
B.Amazon API Gateway
C.AWS CloudFront
D.Amazon S3
AnswerB

Amazon API Gateway is a fully managed service specifically designed for creating, publishing, maintaining, monitoring, and securing REST, HTTP, and WebSocket APIs at any scale. It acts as a secure 'front door' for applications to access data, business logic, or functionality from backend services like AWS Lambda or DynamoDB. Key features include request/response transformation, authentication (e.g., API keys, IAM, Cognito), throttling, caching, and custom domain support, making it ideal for exposing a database query API.

Why this answer

Amazon API Gateway is the correct choice because it is a fully managed service that enables developers to create, publish, maintain, monitor, and secure RESTful APIs at any scale. It directly supports HTTPS endpoints, integrates natively with AWS Lambda for backend logic, and provides built-in features for authentication (e.g., IAM, Cognito, Lambda authorizers) and throttling (usage plans and rate limits). This makes it the ideal service for exposing a Lambda-backed DynamoDB query as a secure, managed API.

Exam trap

The trap here is that candidates may confuse an Application Load Balancer with API Gateway because both can invoke Lambda functions, but ALB lacks API management features like authentication, throttling, and API key validation, which are explicitly required in the question.

How to eliminate wrong answers

Option A is wrong because an Application Load Balancer operates at Layer 7 of the OSI model and distributes traffic to targets like Lambda functions, but it does not provide API management features such as authentication, throttling, or API key validation; it is designed for load balancing, not for creating and managing RESTful API endpoints. Option C is wrong because AWS CloudFront is a content delivery network (CDN) that caches and accelerates content delivery, but it does not natively create API endpoints or manage authentication and throttling for a RESTful API; it can be placed in front of API Gateway but is not a substitute for it. Option D is wrong because Amazon S3 is an object storage service that can host static websites and serve content over HTTPS, but it cannot execute backend logic like querying a DynamoDB table, nor does it provide authentication or throttling for API requests; it is not designed for dynamic API endpoints.

115
MCQeasy

An organization uses AWS CodeCommit for source control and AWS CodeBuild for building a Java application. The build process needs to run integration tests that require a MySQL database. The team wants to ensure the database is provisioned only during the build and cleaned up afterward to minimize costs. What is the most efficient solution?

A.Provision a small RDS MySQL instance and keep it running for the build process.
B.Use AWS CloudFormation to create an RDS instance at the start of the build and delete it at the end.
C.Use a Docker container running MySQL within the CodeBuild environment.
D.Use Amazon DynamoDB as a substitute for MySQL for the integration tests.
AnswerC

Using a Docker container running MySQL directly within the CodeBuild environment is an efficient and cost-effective solution. CodeBuild supports running services as Docker containers alongside the build environment, allowing MySQL to be spun up quickly and ephemerally for each build. This approach ensures a clean database instance for every integration test run, providing isolation and repeatability without incurring persistent costs for an always-on database.

Why this answer

Running MySQL inside a Docker container within the CodeBuild environment is the most efficient solution because the database is ephemeral, starts and stops with the build, and incurs no persistent infrastructure cost. CodeBuild supports Docker via the privileged mode setting, and the container can be started in the buildspec's pre_build phase and torn down automatically when the build finishes. This satisfies the requirement to provision only during the build and clean up afterward.

Exam trap

DVA-C02 often tests the misconception that CloudFormation-provisioned RDS is the 'proper' way to get a temporary database — candidates overlook that Docker-in-CodeBuild is faster, cheaper, and truly ephemeral.

How to eliminate wrong answers

Option A is wrong because keeping an RDS MySQL instance running continuously incurs ongoing cost and violates the requirement to provision only during the build. Option B is wrong because creating and deleting an RDS instance via CloudFormation at the start and end of each build is slow (RDS provisioning takes several minutes), error-prone, and still incurs cost during the build window. Option D is wrong because DynamoDB is a NoSQL database and is not compatible with MySQL integration tests that rely on SQL syntax, drivers, and schema.

116
MCQmedium

A company uses Amazon API Gateway to expose a REST API backed by AWS Lambda. The API is experiencing high latency. The developer suspects cold starts are contributing to the latency. Which action would be MOST effective in reducing cold start latency?

A.Increase the memory allocation of the Lambda function.
B.Place the Lambda function in a VPC to improve network latency.
C.Enable Lambda@Edge to cache responses.
D.Increase the function timeout to 15 minutes.
AnswerA

Increasing the memory allocation for a Lambda function directly correlates with an increase in allocated CPU power. AWS Lambda provisions CPU cycles proportionally to the memory configured for the function. More CPU resources allow the function's execution environment to initialize faster, load dependencies more quickly, and execute the handler code more efficiently during a cold start, thereby reducing the overall latency experienced by the user.

Why this answer

Increasing the memory allocation of a Lambda function directly correlates to allocating more CPU power, which reduces the initialization time during a cold start. AWS Lambda provisions CPU proportionally to the configured memory, so a higher memory setting speeds up the runtime environment setup and code loading, thereby lowering cold start latency.

Exam trap

The trap here is that candidates often confuse increasing timeout with improving performance, but timeout only affects how long a function can run, not how quickly it starts.

How to eliminate wrong answers

Option B is wrong because placing a Lambda function in a VPC adds an Elastic Network Interface (ENI) setup step during cold starts, which actually increases latency, not reduces it. Option C is wrong because Lambda@Edge is designed for content delivery and caching at CloudFront edge locations, not for reducing cold start latency of an API Gateway backend Lambda function. Option D is wrong because increasing the function timeout to 15 minutes does not affect the initialization phase of a cold start; it only allows the function to run longer, which does not address the latency issue.

117
Multi-Selecthard

A company uses AWS KMS to encrypt data in S3. The security team wants to ensure that only specific IAM roles can decrypt the data. Which THREE steps should be taken?

Select 3 answers
A.Add a condition in the key policy that allows decrypt only when the principal matches the desired IAM roles.
B.Grant all IAM users decrypt permission and rely on S3 bucket policies.
C.Create an IAM policy that grants kms:Decrypt only to the specific roles.
D.Create a customer-managed customer master key (CMK) in KMS.
E.Use separate CMKs for each IAM role to isolate access.
AnswersA, C, D

A KMS key policy is the primary access control mechanism for a CMK, defining who can use the key and under what conditions. By adding a "Condition" block to the key policy, you can specify that the "kms:Decrypt" action is only allowed when the "aws:PrincipalArn" matches the ARNs of the desired IAM roles. This ensures that even if an IAM user or role has "kms:Decrypt" permission via an IAM policy, the key policy will deny access unless the principal is one of the explicitly allowed roles. This provides a robust, centralized control over key usage.

Why this answer

Key policies in AWS KMS are resource-based policies that directly control access to the CMK. By adding a condition that restricts the `kms:Decrypt` action to only specific IAM roles (using the `aws:PrincipalArn` or `kms:CallerPrincipal` condition key), the security team can ensure that only those roles can decrypt data encrypted with that key. This approach is more secure than relying solely on IAM policies, as key policies are evaluated first and can explicitly deny access even if an IAM policy grants it.

Exam trap

The trap here is that candidates often think IAM policies alone are sufficient for KMS access control, but they forget that KMS key policies are the primary mechanism and must explicitly allow IAM policies to take effect; otherwise, even if an IAM policy grants `kms:Decrypt`, the key policy will deny the request.

118
MCQeasy

A developer is deploying a CloudFormation stack and sees the event above. What should the developer do to fix the error?

A.Update the Lambda function code to use a different programming language.
B.Increase the Lambda function timeout in the template.
C.Change the runtime to a supported version like nodejs18.x.
D.Add permissions to the Lambda function's execution role.
AnswerC

AWS Lambda regularly deprecates older runtime versions to ensure security, performance, and maintainability. When a CloudFormation stack specifies a runtime that is no longer supported (e.g., `nodejs12.x` or `python3.7`), the deployment will fail with an explicit error indicating the runtime is invalid. Updating the `Runtime` property in the CloudFormation template to a currently supported version, such as `nodejs18.x` or `python3.9`, directly resolves this specific deployment failure.

Why this answer

The error indicates that the runtime (Node.js 12.x) used in the Lambda function is deprecated and no longer supported by AWS. To fix this, the developer must update the CloudFormation template to specify a supported runtime version, such as nodejs18.x, and redeploy the stack. Option C correctly identifies this solution.

Option A is incorrect because the programming language itself is not the issue; the runtime version needs updating. Option B is incorrect because increasing the timeout does not address the unsupported runtime. Option D is incorrect because adding permissions does not resolve the runtime deprecation error.

119
MCQmedium

A company uses AWS Elastic Beanstalk to deploy a Python web application. After a successful deployment, the environment's health turns 'Severe' and the application returns HTTP 502 errors. What is the most likely cause?

A.The EC2 instances have insufficient storage for the deployment.
B.The application's requirements.txt file is missing a required dependency.
C.The load balancer's health check path is incorrectly configured.
D.The RDS database connection string is incorrect.
AnswerB

When a Python application deployed on Elastic Beanstalk has a missing dependency in its `requirements.txt` file, the application server (e.g., Gunicorn, uWSGI) will fail to start correctly or crash immediately upon startup. The proxy server (e.g., Nginx, Apache) on the EC2 instance will then be unable to establish a connection or forward requests to the unresponsive application server. This common scenario directly leads to a 502 Bad Gateway error, as the proxy cannot communicate with the upstream application process.

Why this answer

A missing dependency in requirements.txt causes the Python application to fail during startup, leading to the EC2 instances reporting an unhealthy status to the Elastic Load Balancer. Elastic Beanstalk relies on the application process to respond to health checks; if the app crashes due to an ImportError, the load balancer receives no valid HTTP response and returns 502 Bad Gateway errors. The environment health turns 'Severe' because the platform detects that the application process is not running or is failing repeatedly.

Exam trap

The trap here is that candidates often confuse HTTP 502 with 503 or 504, or assume that a missing dependency would cause a deployment failure rather than a runtime error that still allows the environment to be created but with a broken application.

How to eliminate wrong answers

Option A is wrong because insufficient storage on EC2 instances would typically cause deployment failures or disk-full errors, not HTTP 502 errors; the load balancer would still receive a response from the web server, albeit potentially slow or incomplete. Option C is wrong because an incorrectly configured health check path would cause the load balancer to mark instances as unhealthy and return 503 Service Unavailable, not 502 Bad Gateway; 502 indicates the upstream server (the application) is not responding correctly. Option D is wrong because an incorrect RDS connection string would cause the application to fail at runtime when querying the database, but the web server would still start and respond to health checks with a 200 status unless the application crashes entirely on startup due to the misconfiguration.

120
MCQeasy

An application running on Amazon ECS with Fargate is unable to pull an image from Amazon ECR. The task definition uses the 'default' task execution role. What is the most likely cause?

A.The task role does not have permissions to access ECR.
B.The ECS cluster does not have permissions to access ECR.
C.The ECS service role does not have permissions to access ECR.
D.The task execution role does not have permissions to pull from ECR.
AnswerD

The Amazon ECS task execution role grants permissions to the ECS agent or the Fargate infrastructure to perform essential actions on your behalf, *before* your application code even starts. This includes crucial operations such as pulling container images from Amazon ECR, pushing container logs to Amazon CloudWatch Logs, and retrieving sensitive data from AWS Secrets Manager or Parameter Store for image pull authentication. For successful image retrieval, this role specifically requires permissions like `ecr:GetDownloadUrlForLayer`, `ecr:BatchGetImage`, and `ecr:BatchCheckLayerAvailability` to authenticate and download image layers, without which the task launch will fail.

Why this answer

When using Amazon ECS with Fargate, the task execution role (not the task role) is responsible for pulling container images from Amazon ECR. The 'default' task execution role is created automatically but lacks the necessary permissions (e.g., ecr:GetDownloadUrlForLayer, ecr:BatchGetImage, and ecr:BatchCheckLayerAvailability) unless explicitly attached via an IAM policy. Since the question states the task definition uses the 'default' task execution role, the most likely cause is that this role does not have the required ECR permissions.

Exam trap

The trap here is that candidates often confuse the task execution role with the task role, assuming the task role handles all permissions including image pulling, when in fact the task execution role is a separate IAM role specifically required for ECR image pulls and CloudWatch Logs.

How to eliminate wrong answers

Option A is wrong because the task role is used by the application code running inside the container to interact with AWS services (e.g., DynamoDB, S3), not for pulling images from ECR; image pulling is handled by the ECS agent using the task execution role. Option B is wrong because an ECS cluster itself does not have an IAM role or permissions; permissions are assigned to the task execution role or the ECS service role, not to the cluster resource. Option C is wrong because the ECS service role (formerly ecsServiceRole) is used for actions like registering/deregistering targets with a load balancer, not for pulling container images from ECR; image pulling is exclusively the responsibility of the task execution role.

121
MCQeasy

A company is using AWS CodePipeline to automate deployments. The pipeline has a source stage that retrieves code from Amazon S3, a build stage using AWS CodeBuild, and a deploy stage using AWS CodeDeploy. The build stage is failing intermittently with errors related to missing dependencies. What should a developer do to ensure the build environment has all required dependencies?

A.Configure environment variables in CodePipeline to set dependency paths.
B.Manually install dependencies on the CodeBuild build server each time.
C.Use AWS CodeCommit as the source repository instead of S3.
D.Create a custom buildspec.yml file in the source code that installs the dependencies in the install phase.
AnswerD

Creating a custom `buildspec.yml` file in the source code is the standard and most effective method for automating dependency installation within AWS CodeBuild. By defining commands in the `install` phase of the `buildspec.yml` (e.g., `npm install`, `pip install`), CodeBuild automatically executes these steps every time the project is built. This ensures that all necessary dependencies are consistently fetched and installed, making the build process reproducible, reliable, and fully integrated with the source code version control.

Why this answer

The buildspec.yml file defines the build phases for AWS CodeBuild, including the install phase where you can specify commands to install dependencies (e.g., using package managers like pip, npm, or apt-get). By placing this file in the source code, the build environment automatically executes these commands on every build, ensuring all required dependencies are present and consistent across runs, which resolves intermittent failures caused by missing dependencies.

Exam trap

The trap here is that candidates may think environment variables (Option A) can solve dependency issues, but they confuse configuration with actual installation, or they assume changing the source repository (Option C) will somehow fix build failures, when the real solution lies in defining the build process within the source code itself.

How to eliminate wrong answers

Option A is wrong because environment variables in CodePipeline can set paths or configuration values but cannot install or fetch missing dependencies; they only influence runtime behavior of existing tools. Option B is wrong because manually installing dependencies on the CodeBuild build server is impractical and defeats automation—CodeBuild uses ephemeral, disposable build environments that are recreated for each build, so manual changes are lost. Option C is wrong because switching to CodeCommit as the source repository does not address missing dependencies; the source type (S3 vs.

CodeCommit) has no impact on dependency installation in the build stage.

122
MCQhard

A developer is running a Lambda function that uses the 'requests' library. The error shown in the exhibit occurs when invoking the function. Which step should the developer take to fix this?

A.Change the Lambda runtime to Python 3.9 which includes requests
B.Package the 'requests' library with the Lambda deployment package
C.Use the 'urllib' library instead of 'requests'
D.Install the 'requests' library using pip in the Lambda console
AnswerB

To successfully use the `requests` library in an AWS Lambda function, it must be included as part of the deployment package. This typically involves installing `requests` and its dependencies into a local directory, then zipping that directory along with the function's handler code. Alternatively, for shared dependencies across multiple functions, a Lambda Layer can be created and attached, which is a best practice for managing common libraries efficiently.

Why this answer

The 'requests' library is not included in the AWS Lambda Python runtime by default. To use it, the developer must package the library as a dependency layer or include it in the deployment package. Option B correctly identifies this approach, ensuring the library is available at runtime.

Exam trap

The trap here is that candidates assume AWS Lambda runtimes include popular third-party libraries like 'requests', but in reality only the standard library is provided, so dependencies must be bundled manually.

How to eliminate wrong answers

Option A is wrong because no AWS Lambda Python runtime (including Python 3.9) includes the 'requests' library by default; it must be bundled manually. Option C is wrong because switching to 'urllib' is a workaround, not a fix for the missing dependency, and may require significant code changes. Option D is wrong because the Lambda console does not support installing libraries via pip; dependencies must be packaged locally or via a Lambda layer.

123
MCQhard

Refer to the exhibit. An IAM policy is attached to an IAM user. The user tries to upload an object to s3://my-bucket/confidential/report.pdf. What is the outcome?

A.The upload succeeds because the Allow statement grants s3:PutObject on the bucket.
B.The upload fails because there is no Allow statement for the confidential prefix.
C.The upload fails because the Deny statement explicitly denies access to the confidential prefix.
D.The upload fails because the policy is malformed.
AnswerC

The upload fails precisely because the IAM policy contains an explicit Deny statement for the s3:PutObject action on resources within the confidential prefix. In AWS IAM policy evaluation, an explicit Deny always overrides any Allow statements that might otherwise grant access, regardless of their scope or specificity. This strict precedence ensures that sensitive operations or resources can be absolutely protected.

Why this answer

The IAM policy includes an explicit Deny statement for s3:PutObject on the `confidential` prefix, which overrides any Allow statements. AWS IAM evaluates policies with explicit Denies taking precedence over Allows, so the upload to `s3://my-bucket/confidential/report.pdf` is blocked regardless of the Allow statement on the bucket.

Exam trap

The trap here is that candidates often assume an Allow statement on the bucket is sufficient for all objects, forgetting that an explicit Deny on a specific prefix takes precedence and blocks the action.

How to eliminate wrong answers

Option A is wrong because while the Allow statement grants s3:PutObject on the bucket, the explicit Deny statement for the `confidential` prefix overrides it, causing the upload to fail. Option B is wrong because the failure is not due to a missing Allow statement; the Allow statement exists on the bucket, but the Deny statement explicitly blocks the action on the `confidential` prefix. Option D is wrong because the policy is not malformed; it is syntactically valid and follows IAM policy structure.

124
MCQmedium

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application stores session state in an S3 bucket. Users report that after logging in, they are sometimes redirected to the login page again on subsequent requests. What is the MOST likely cause?

A.S3 is not a suitable store for session state due to its higher latency compared to in-memory stores like ElastiCache or DynamoDB.
B.The EC2 instances do not have internet access to reach S3.
C.The ALB does not have sticky sessions enabled.
D.The application is not scaling properly, causing session loss.
AnswerA

Amazon S3, while highly durable and scalable, is an object storage service optimized for throughput of large objects and cost-effectiveness, not for low-latency, high-frequency access to small, frequently changing data like session state. Its typical latency, even with strong consistency, is significantly higher than in-memory caches like ElastiCache (Redis/Memcached) or specialized NoSQL databases like DynamoDB. This higher latency can cause the application to time out when attempting to retrieve session data, leading to the perception of a lost session and subsequent redirection to the login page.

Why this answer

Amazon S3 now provides strong read-after-write consistency, so eventual consistency is not the cause. However, S3's higher latency compared to in-memory stores like ElastiCache or DynamoDB makes it unsuitable for session management, which requires fast, frequent reads and writes. The higher latency can cause delays in session retrieval, leading to timeouts and the login page being displayed again.

Exam trap

Candidates may incorrectly attribute the problem to S3's eventual consistency, which was fixed. The real issue is S3's higher latency relative to in-memory services, making it a poor choice for session state.

How to eliminate wrong answers

Option B is wrong because EC2 instances in a VPC can access S3 via a VPC endpoint or NAT gateway without requiring internet access; the lack of internet access alone would not cause intermittent session loss. Option C is wrong because sticky sessions (session affinity) are used to route requests to the same EC2 instance, but the session state is stored in S3, not on the instance, so sticky sessions are irrelevant to session persistence. Option D is wrong because scaling issues would cause all sessions to be lost or new instances to be unable to serve existing sessions, not intermittent redirects to the login page; the described behavior points to a data consistency problem, not capacity.

125
MCQmedium

A company stores sensitive data in Amazon S3. The security team requires that all objects are encrypted at rest using server-side encryption with AWS KMS managed keys (SSE-KMS). The developer needs to enforce that any PutObject request that does not specify the 'x-amz-server-side-encryption' header with value 'aws:kms' is denied. Which S3 bucket policy condition should be used?

A.s3:x-amz-server-side-encryption equals 'aws:kms'
B.s3:x-amz-server-side-encryption-aws-kms-key-id equals the KMS key ARN
C.s3:x-amz-acl equals 'bucket-owner-full-control'
D.s3:signatureversion equals 'AWS4-HMAC-SHA256'
AnswerA

This condition directly checks for the presence and specific value of the `x-amz-server-side-encryption` request header. When set to `aws:kms`, it mandates that Amazon S3 encrypts the object using Server-Side Encryption with AWS KMS (SSE-KMS) during the upload operation. This is the fundamental policy condition to enforce SSE-KMS for all new objects uploaded to the bucket, ensuring data is encrypted at rest using a customer-managed key or AWS-managed key within KMS.

Why this answer

The condition key `s3:x-amz-server-side-encryption` in an S3 bucket policy can be used to require that the `x-amz-server-side-encryption` header is set to `aws:kms` on every PutObject request. This enforces server-side encryption with AWS KMS (SSE-KMS) at the bucket policy level, denying any request that omits or uses a different encryption header value.

Exam trap

The trap here is that candidates often confuse the condition key for the encryption header (`s3:x-amz-server-side-encryption`) with the condition key for the KMS key ID (`s3:x-amz-server-side-encryption-aws-kms-key-id`), mistakenly choosing Option B to enforce SSE-KMS instead of the correct header-based condition.

How to eliminate wrong answers

Option B is wrong because `s3:x-amz-server-side-encryption-aws-kms-key-id` checks for a specific KMS key ARN, not the encryption header value; it would allow requests with any SSE-KMS key but does not enforce the header itself. Option C is wrong because `s3:x-amz-acl` controls access control lists (ACLs), not encryption requirements; it is unrelated to server-side encryption enforcement. Option D is wrong because `s3:signatureversion` checks the signature version used in the request (e.g., AWS Signature Version 4), which is about request authentication, not encryption headers.

126
MCQhard

A company is using AWS CodeDeploy to deploy a web application to an Auto Scaling group. The deployment fails with the error: 'The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available, or some instances in your deployment group are experiencing problems.' The application is deployed to a t2.micro instance with 1 GB of RAM. The deployment uses an in-place update with a deployment configuration that has a minimum of 1 healthy host. What is the most likely cause of the failure?

A.The application uses too much memory, causing the instance to become unhealthy during deployment.
B.The instance does not have enough disk space to download the application revision.
C.The CodeDeploy agent timed out because the deployment took longer than 30 minutes.
D.The IAM role for the CodeDeploy agent does not have sufficient permissions to deploy the application.
AnswerA

A t2.micro instance has only 1 GB of RAM, which is a very limited resource for many modern web applications. If the application, especially during startup or initial load after deployment, consumes memory beyond this capacity, the operating system may become unresponsive or critical services could crash. This resource exhaustion would cause the instance's health checks, monitored by CodeDeploy and potentially an associated Load Balancer or Auto Scaling Group, to fail, leading to a deployment rollback or failure.

Why this answer

The most likely cause is option A: the application uses too much memory, causing the instance to become unhealthy during deployment. The t2.micro instance has only 1 GB of RAM. If the web application consumes significant memory, deploying a new version can trigger out-of-memory (OOM) errors, leading the instance to fail health checks.

The deployment configuration requires a minimum of 1 healthy host, so when the instance becomes unhealthy, the deployment fails with the error about too few healthy instances. Option B (insufficient disk space) is unlikely because t2.micro instances typically have at least 8 GB of EBS storage, which is usually sufficient for downloading application revisions. Option C (CodeDeploy agent timeout) would produce a different error, such as 'deployment timed out,' not a message about healthy instances.

Option D (insufficient IAM permissions) would result in authorization failures, such as 'AccessDenied' errors, not a health-related failure. Therefore, memory exhaustion due to the small instance size is the best explanation.

127
MCQmedium

A company runs a microservices architecture on Amazon ECS with Fargate. The application experiences intermittent high latency. The operations team wants to trace requests across services and identify bottlenecks. Which AWS service should be used?

A.VPC Flow Logs
B.Amazon CloudWatch Logs
C.AWS X-Ray
D.Amazon CloudWatch Metrics
AnswerC

AWS X-Ray is purpose-built for end-to-end tracing and analysis of requests as they flow through distributed applications, including those running on Amazon ECS microservices. It collects data about requests, responses, and calls to downstream services, providing a visual service map, detailed trace data, and latency breakdowns for each segment. This enables developers to precisely identify performance bottlenecks, errors, and the full execution path of individual requests across complex architectures.

Why this answer

AWS X-Ray is the correct service because it provides end-to-end tracing of requests as they travel through microservices, capturing latency at each hop. It generates a service map that visualizes the flow and pinpoints bottlenecks, which is exactly what the operations team needs for a distributed application on ECS Fargate.

Exam trap

The trap here is that candidates confuse CloudWatch Logs (which shows logs) or Metrics (which shows aggregates) with the distributed tracing capability that X-Ray uniquely provides for microservices architectures.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture IP traffic metadata (source/destination, ports, protocols) but do not trace application-level requests or measure service latency. Option B is wrong because Amazon CloudWatch Logs aggregates log data but lacks the distributed tracing capability to follow a single request across multiple services and identify per-service latency. Option D is wrong because Amazon CloudWatch Metrics provides aggregated performance data (e.g., CPU, memory) but cannot trace individual request paths or pinpoint which specific service call caused the latency.

128
MCQmedium

A developer is troubleshooting an AWS Lambda function that is triggered by an Amazon SQS queue. The function processes messages but occasionally fails. The failed messages are not being sent to the dead-letter queue (DLQ). What is the most likely reason?

A.The Lambda function's execution role does not have permission to send messages to the DLQ.
B.The SQS queue's redrive policy is not configured.
C.The Lambda function's reserved concurrency is set to 0.
D.The Lambda function does not have a dead-letter queue configured.
AnswerB

When an AWS Lambda function processes messages from an SQS queue, and an invocation fails (e.g., due to an error in the function code or a timeout), SQS will return the message to the queue after its visibility timeout expires. If the message processing continues to fail and the SQS queue does not have a redrive policy configured, the message will eventually be discarded by SQS after its maximum receive count is exceeded, rather than being moved to a Dead-Letter Queue (DLQ). Therefore, a missing redrive policy directly prevents failed messages from being captured in a DLQ associated with the source queue.

Why this answer

For Lambda functions triggered by SQS, the dead-letter queue is configured on the SQS queue via its redrive policy, not on the Lambda function. If the redrive policy is missing or misconfigured, failed messages will not be moved to a DLQ even if the Lambda function has its own DLQ configured. The most likely reason is that the SQS queue's redrive policy is not configured.

Exam trap

The trap is assuming the Lambda function's DLQ configuration applies to SQS triggers — candidates often miss that SQS-triggered invocations use the queue's redrive policy, not Lambda's DLQ.

How to eliminate wrong answers

Option A is wrong because the Lambda execution role's permissions are not the issue — the redrive policy on the SQS queue governs DLQ behavior, and the queue's own permissions matter, not the Lambda role's. Option C is wrong because reserved concurrency set to 0 would prevent the function from processing any messages at all, not cause occasional failures without DLQ delivery. Option D is wrong because Lambda's own DLQ configuration applies to asynchronous invocations, not to SQS-triggered (poll-based) invocations; for SQS, the DLQ is configured on the queue.

129
MCQmedium

A company uses AWS CodeDeploy to deploy a web application to an Auto Scaling group. The deployment fails with a 'ScriptMissing' error. What is the most likely cause?

A.The deployment group is not configured for an Auto Scaling group.
B.The buildspec.yml file is missing from the application root.
C.The application revision is not stored in an S3 bucket.
D.The lifecycle event hook script referenced in appspec.yml is not present.
AnswerD

The ScriptMissing error occurs specifically when the appspec.yml file references a script under hooks (such as BeforeInstall or ApplicationStart) by filename, but that script file does not actually exist in the deployed revision bundle at the expected path, so the agent cannot locate it to execute.

Why this answer

The 'ScriptMissing' error occurs when the appspec.yml file references a lifecycle event hook script that is not present in the application revision. CodeDeploy expects the script to exist at the specified path. Option A is incorrect: the deployment group can be configured for an Auto Scaling group, and that is not the cause of ScriptMissing.

Option B is incorrect: buildspec.yml is used by AWS CodeBuild, not CodeDeploy. Option C is incorrect: while the application revision must be stored in S3 (or GitHub), the error is not about the bucket location but about a missing script within the revision.

130
Multi-Selectmedium

Which TWO actions should a developer take to improve the security of an AWS Lambda function that processes sensitive data?

Select 2 answers
A.Use a dead-letter queue (DLQ) for failed invocations
B.Encrypt environment variables using AWS KMS
C.Grant the Lambda function full access to all S3 buckets
D.Run the Lambda function inside a VPC
E.Store secrets in the Lambda function code
AnswersB, D

Encrypting environment variables with AWS Key Management Service (KMS) ensures that sensitive data, such as API keys or database credentials, is protected when stored at rest within the Lambda service configuration. This prevents unauthorized access to these secrets if the Lambda configuration is compromised, as the data remains encrypted until the function is invoked and decrypted by the Lambda runtime using the specified KMS key.

Why this answer

Encrypting environment variables with AWS KMS ensures that sensitive data, such as database credentials or API keys, is protected at rest and in transit during function deployment. This is a critical security best practice because environment variables are visible in plaintext in the Lambda console and API responses unless encrypted. KMS provides envelope encryption, where a customer master key (CMK) encrypts the data key that encrypts the environment variables, giving you full control over access and key rotation.

Exam trap

The trap here is that candidates may think a DLQ (Option A) improves security by handling failures, but it is a reliability mechanism, not a security control, and they may overlook that running a Lambda in a VPC (Option D) is a security measure to isolate network traffic, even though it is not directly about encrypting data.

131
MCQmedium

A developer monitors an AWS Lambda function that processes messages from an Amazon SQS queue. CloudWatch logs show that the function's execution time has increased significantly over the past week. The function's code has not been changed recently. The function makes calls to an Amazon DynamoDB table. CloudWatch metrics show a high rate of DynamoDBProvisionedThroughputExceededException errors. The DynamoDB table has 5 read and 5 write capacity units (RCU/WCU). What is the most effective action to reduce the function's execution time?

A.Increase the Lambda function's memory allocation.
B.Increase the Lambda function's reserved concurrency.
C.Increase the DynamoDB table's read and write capacity units.
D.Increase the Lambda function's timeout.
AnswerC

Increasing the table's provisioned RCU and WCU directly removes the throttling that causes DynamoDBProvisionedThroughputExceededException, so the Lambda function's DynamoDB calls stop retrying with exponential backoff. Those retry delays, not the function's code, explain the inflated execution time, and raising capacity addresses the 5 RCU/5 WCU constraint named in the stem.

Why this answer

The high rate of DynamoDBProvisionedThroughputExceededException errors indicates that the Lambda function is being throttled by DynamoDB due to insufficient read and write capacity units. This throttling causes the function to retry operations, significantly increasing execution time. Increasing the RCU/WCU from 5 to a higher value directly addresses the bottleneck, allowing operations to complete without retries and reducing overall execution time.

Exam trap

The trap here is that candidates often confuse performance issues caused by Lambda resource limits (memory, concurrency, timeout) with downstream service throttling, leading them to adjust Lambda settings instead of addressing the root cause in DynamoDB capacity.

How to eliminate wrong answers

Option A is wrong because increasing memory allocation improves CPU performance and execution speed for compute-bound tasks, but the issue here is a DynamoDB throughput limitation, not a lack of compute resources. Option B is wrong because reserved concurrency controls how many concurrent Lambda invocations are allowed, which does not affect the per-invocation execution time or resolve DynamoDB throttling errors. Option D is wrong because increasing the timeout only allows the function to run longer before being terminated, but it does not reduce the actual time taken to process each message; the function will still be delayed by DynamoDB retries.

132
MCQhard

A company wants to audit all API calls made to AWS. Which service should be used to collect and store these logs?

A.VPC Flow Logs
B.AWS Config
C.AWS CloudTrail
D.Amazon CloudWatch Logs
AnswerC

AWS CloudTrail is the primary service for auditing and monitoring all API calls made to your AWS account, whether through the AWS Management Console, AWS SDKs, command-line tools, or other AWS services. It records management events, such as creating or deleting resources, and can also capture data events for services like S3 and Lambda. CloudTrail logs provide crucial details including the identity of the caller, the time of the call, the source IP address, and the specific API operation performed, making it indispensable for security analysis, compliance, and operational troubleshooting.

Why this answer

AWS CloudTrail records all API calls and can store logs in S3. Option A (VPC Flow Logs) captures network traffic, not API calls. Option B (AWS Config) records resource configuration changes, not API calls.

Option D (Amazon CloudWatch Logs) can store logs but is not the primary service for API auditing.

133
MCQmedium

A developer has set up an AWS CodePipeline pipeline that automatically deploys a web application through a series of stages: Source, Build, Staging, and Production. The developer wants to require a manual approval before the pipeline proceeds to the Production stage. How should the developer implement this?

A.Add a manual approval action in the Staging stage
B.Add a manual approval action between the Staging and Production stages
C.Configure the Production stage to use a CloudFormation change set with execution role
D.Use an SNS topic to notify developers of the deployment
AnswerB

Correct. A manual approval action placed as a separate stage or as an action in the transition between stages pauses the pipeline until approval is granted.

Why this answer

AWS CodePipeline supports manual approval actions that can be added as a stage or between stages to pause the pipeline and require explicit approval before proceeding. By placing the manual approval action between the Staging and Production stages, the pipeline will halt after the Staging stage completes and wait for an approver to manually approve the transition to the Production stage, ensuring no automatic deployment to production occurs without human oversight.

Exam trap

The trap here is that candidates may think a manual approval action must be placed inside a stage (like Staging) rather than as a separate stage between stages, but CodePipeline allows stages to be ordered sequentially, and the approval action must be in its own stage or at the end of a stage to block the transition to the next stage.

How to eliminate wrong answers

Option A is wrong because adding a manual approval action in the Staging stage would pause the pipeline during the Staging stage itself, not between Staging and Production, so the deployment would proceed to Production automatically after the Staging stage completes, defeating the requirement. Option C is wrong because configuring the Production stage to use a CloudFormation change set with execution role does not introduce a manual approval step; it only controls how CloudFormation executes changes, not a human approval gate. Option D is wrong because using an SNS topic to notify developers of the deployment does not block the pipeline; it only sends notifications, so the pipeline would continue to Production without any manual approval.

134
MCQeasy

A developer reports that an AWS Lambda function is timing out after 3 seconds. The function reads from an Amazon SQS queue. What is the most likely cause?

A.The Lambda function memory is set too low, causing slow execution.
B.The Lambda function timeout is set to 3 seconds, which is too low.
C.The Lambda execution role lacks permissions to poll SQS.
D.The SQS queue is empty, causing the function to wait indefinitely.
AnswerB

AWS Lambda functions have a configurable timeout setting, with a default value of 3 seconds. If the function's execution logic, including any external API calls or complex processing, exceeds this configured duration, Lambda will forcibly terminate the invocation and report a timeout error. This is a common and direct cause for consistent timeouts occurring at a specific, short duration.

Why this answer

The Lambda function is timing out after exactly 3 seconds because its configured timeout is set to 3 seconds, which is too low for the workload. Lambda has a maximum execution timeout of 15 minutes (900 seconds), but the default timeout is 3 seconds. Since the function reads from an SQS queue, it likely needs more time to process messages, and increasing the timeout value will resolve the issue.

Exam trap

The trap here is that candidates often confuse timeout with memory or permissions issues, but the exact 3-second timeout is a direct indicator of the default Lambda timeout being too low, not a resource or authorization problem.

How to eliminate wrong answers

Option A is wrong because low memory can cause slower execution, but it would not cause a hard timeout at exactly 3 seconds; memory affects performance, not the timeout limit. Option C is wrong because if the execution role lacked permissions to poll SQS, the function would fail with an access denied error (e.g., 403 or 500), not a timeout. Option D is wrong because an empty SQS queue does not cause a Lambda function to wait indefinitely; Lambda polls the queue and returns immediately if no messages are available, and the function would complete quickly without timing out.

135
MCQeasy

A developer is using Amazon DynamoDB as the database for a web application. The application experiences occasional spikes in traffic, and some write requests fail with a ProvisionedThroughputExceededException. What is the MOST cost-effective way to handle these spikes without manual intervention?

A.Switch to on-demand mode for the table.
B.Enable DynamoDB auto scaling for the table.
C.Increase the provisioned write capacity to the peak expected value.
D.Use DynamoDB Accelerator (DAX) to cache writes.
AnswerB

DynamoDB auto scaling continuously monitors consumed capacity through CloudWatch alarms and automatically raises or lowers the table's provisioned read and write capacity units within configured min/max bounds and a target utilization percentage, absorbing traffic spikes without manual intervention while keeping baseline costs lower than a flat over-provisioned or fully on-demand configuration.

Why this answer

DynamoDB auto scaling automatically adjusts the provisioned read and write capacity based on actual traffic patterns, handling spikes without manual intervention and only paying for the capacity needed at peak times. Option A (on-demand mode) avoids capacity management but can be more expensive for predictable workloads or sustained traffic. Option C (increasing to peak) leads to over-provisioning and higher cost during low traffic.

Option D (DAX) is a caching layer for reads, not writes, and does not address write throughput limitations.

136
MCQmedium

Refer to the exhibit. A developer invoked a Lambda function and received the response shown. What does the response indicate?

A.The function was not invoked due to a permissions error.
B.The function executed successfully but did not return any logs.
C.The invocation timed out.
D.The function was invoked but returned an error.
AnswerD

The presence of the `FunctionError` header in the Lambda invocation response explicitly indicates that the function code was successfully invoked by the Lambda service, but encountered an unhandled error during its execution. This error could be an exception thrown by the function code that was not caught, or a runtime error that prevented successful completion. The Lambda service captures this and signals it via the `FunctionError` header, even if the HTTP status code is 200.

Why this answer

The response includes a 'FunctionError' field with value 'Unhandled' and an 'error' object, indicating that the Lambda function was invoked successfully (StatusCode 200) but the function itself encountered an error during execution. Option A is incorrect because a permissions error would result in a 4xx or 5xx StatusCode, not 200. Option B is incorrect because the function did not execute successfully—it returned an error.

Option C is incorrect because a timeout would typically produce a 'null' FunctionError or a specific timeout error, not an explicit error object. Option D is correct: the function was invoked, but it returned an error.

137
MCQhard

A team uses AWS CodePipeline to deploy a microservices application to Amazon ECS. The pipeline has a Source stage (GitHub), a Build stage (CodeBuild), and a Deploy stage (ECS). During a deployment, the pipeline fails at the Deploy stage with the error: 'Action execution failed: Deployment failed. The service my-service has reached the maximum number of tasks.' The service is configured with a desired count of 2 and a maximum percent of 200%. What is the most likely cause of this failure?

A.The task definition references a memory value that exceeds the available container instance memory.
B.There are already 4 tasks running for the service, which is the maximum allowed by the deployment configuration.
C.The service's minimum healthy percent is set too high, preventing new tasks from starting.
D.The pipeline is trying to deploy to an ECS cluster that has reached its Amazon EC2 instance limit.
AnswerB

The `maximum healthy percent` deployment configuration parameter defines the upper limit on the number of tasks that can be running for a service during a deployment, expressed as a percentage of the desired task count. If the desired count is 2 and the maximum is 200%, then up to 4 tasks (2 * 200%) can run concurrently at any point. If 4 tasks are already active, the service cannot launch additional tasks for the new deployment, leading to the 'maximum tasks allowed' error.

Why this answer

With a desired count of 2 and a maximum percent of 200%, ECS allows up to 4 tasks during a deployment (2 × 200% = 4). If there are already 4 tasks running (e.g., from a previous deployment that did not complete or a manual scaling action), the new deployment cannot start additional tasks because it would exceed the maximum allowed. Option A is incorrect because insufficient memory would cause a different error, such as a task failing to start.

Option C is incorrect because a high minimum healthy percent would prevent task replacement but would not directly cause a 'maximum number of tasks' error. Option D is incorrect because the error is about task count, not EC2 instance limits.

138
MCQeasy

A company wants to deploy a serverless application using AWS Lambda and API Gateway. The deployment process must support automatic rollbacks if the new version fails CloudWatch alarms. Which AWS service should be used to orchestrate this deployment?

A.AWS Elastic Beanstalk
B.AWS CodeDeploy
C.AWS CloudFormation with a change set
D.AWS CodePipeline
AnswerB

AWS CodeDeploy is the correct choice because it natively supports advanced deployment strategies for AWS Lambda functions, including canary and linear deployments. It facilitates gradual traffic shifting to new Lambda function versions, allowing for real-time monitoring of performance and errors. Crucially, CodeDeploy integrates with Amazon CloudWatch alarms to automatically roll back to the deployment to the previous stable version if predefined error thresholds are exceeded during the deployment, ensuring application stability and minimizing user impact.

Why this answer

AWS CodeDeploy is the correct choice because it natively supports deployment strategies like canary, linear, and all-at-once, and can be configured with CloudWatch alarms to automatically trigger rollbacks when a new version fails. This makes it ideal for serverless applications using Lambda and API Gateway, where you need safe, automated deployments with health-check-driven rollback capabilities.

Exam trap

The trap here is that candidates often confuse CodePipeline (which orchestrates the overall pipeline) with CodeDeploy (which handles the actual deployment and rollback logic), leading them to select CodePipeline even though it lacks native automatic rollback based on CloudWatch alarms.

How to eliminate wrong answers

Option A is wrong because AWS Elastic Beanstalk is a PaaS service for web applications and does not natively support serverless deployments with Lambda and API Gateway, nor does it provide automatic rollback based on CloudWatch alarms. Option C is wrong because AWS CloudFormation with a change set is used for infrastructure provisioning and updating, not for orchestrating deployment strategies or automatic rollbacks based on alarm thresholds. Option D is wrong because AWS CodePipeline is a CI/CD orchestration service that can trigger deployments but does not itself manage deployment strategies or automatic rollbacks; it delegates that to services like CodeDeploy.

139
Multi-Selecthard

Which TWO security best practices should be applied when using AWS Lambda? (Choose TWO.)

Select 2 answers
A.Attach an IAM execution role with least privilege permissions.
B.Enable CloudWatch Logs for the Lambda function.
C.Hardcode database credentials in the function code.
D.Store sensitive data in Lambda environment variables.
E.Use AWS Secrets Manager to retrieve secrets at runtime.
AnswersA, E

An IAM execution role defines the permissions that the Lambda function assumes when it executes. Applying the principle of least privilege means granting only the specific permissions required for the function to perform its intended tasks, such as reading from an S3 bucket or writing to a DynamoDB table, and nothing more. This significantly reduces the potential blast radius if the function is compromised, as an attacker would only gain access to the limited set of authorized actions.

Why this answer

Option A is correct because every Lambda function assumes an IAM execution role to call other AWS services, and granting only the specific actions and resources the function needs (least privilege) limits the blast radius if the function is compromised or misused. Option E is correct because AWS Secrets Manager stores credentials and other secrets encrypted and lets the function retrieve them at runtime via the AWS SDK, so secrets are not embedded in code or configuration and can be rotated automatically. Option B is not a security best practice in this context; CloudWatch Logs is primarily for observability and monitoring, and logging sensitive data can even increase exposure.

Option C is wrong because hardcoding database credentials in function code exposes secrets in source control, deployment packages, and logs. Option D is wrong because Lambda environment variables are not a secure secret store—they are visible in the function configuration and can be exposed through console access, APIs, or misconfigured permissions.

Exam trap

Candidates often confuse operational best practices (like enabling CloudWatch Logs) with security best practices, or they mistakenly believe that environment variables are a safe place to store secrets because they are not visible in the function code itself. However, environment variables are visible to anyone with access to view the Lambda configuration, making AWS Secrets Manager the secure choice.

140
Multi-Selecthard

Which TWO of the following are required to enable cross-origin resource sharing (CORS) for an API hosted on Amazon API Gateway? (Choose two.)

Select 2 answers
A.Modify the Lambda function to return CORS headers in the response
B.Configure Amazon CloudFront to add CORS headers
C.Add an OPTIONS method to the API Gateway resource and configure it to return the required CORS headers
D.Configure an S3 bucket CORS policy
E.Enable CORS on the API Gateway resource and deploy the API
AnswersC, E

Browsers perform an HTTP OPTIONS 'preflight' request before certain cross-origin requests (e.g., those using non-simple methods or custom headers). To enable CORS, API Gateway must explicitly respond to these OPTIONS requests with the appropriate `Access-Control-Allow-*` headers. Manually adding an OPTIONS method to the resource and configuring its integration response to return these specific headers is a fundamental and correct way to satisfy the CORS preflight requirement.

Why this answer

CORS requires a preflight OPTIONS request to determine if the actual request is safe to send. By adding an OPTIONS method to the API Gateway resource and configuring it to return the required CORS headers (such as Access-Control-Allow-Origin, Access-Control-Allow-Methods, and Access-Control-Allow-Headers), the API can respond to the browser's preflight request and enable cross-origin requests.

Exam trap

The trap here is that candidates often think modifying the Lambda function to return CORS headers is sufficient, but they forget that the browser's preflight OPTIONS request must be handled separately, and without an OPTIONS method on the API Gateway resource, the preflight will fail.

141
MCQeasy

A company uses AWS CloudFormation to manage infrastructure. The development team wants to deploy a new version of a Lambda function without downtime. The function is part of a stack. Which action should the team take?

A.Create a change set and execute it after the current stack is deleted.
B.Update the CloudFormation stack with the new function code and deploy the stack update.
C.Manually update the Lambda function code in the console and then update the stack.
D.Create a new CloudFormation stack for the new function and delete the old stack.
AnswerB

The most appropriate and robust method is to update the existing CloudFormation stack by modifying the Lambda function's code within the template and then deploying the stack update. CloudFormation intelligently handles the deployment, often creating new versions of the Lambda function and potentially updating aliases, which can be orchestrated to achieve zero-downtime deployments. This approach maintains infrastructure as code principles and leverages CloudFormation's native, controlled update capabilities.

Why this answer

Updating the CloudFormation stack with the new Lambda function code and deploying the stack update is the correct approach because CloudFormation performs a rolling update on the Lambda function, replacing the old version with the new one without deleting the stack. This ensures zero downtime as the update is applied in place, and the function remains available throughout the process.

Exam trap

The trap here is that candidates mistakenly think manual changes (Option C) or creating a new stack (Option D) are safer, but CloudFormation's stack update is designed for zero-downtime deployments, and manual edits cause drift that CloudFormation will revert.

How to eliminate wrong answers

Option A is wrong because creating a change set and executing it after the current stack is deleted would cause downtime; the stack must exist for the change set to apply, and deleting the stack removes all resources. Option C is wrong because manually updating the Lambda function code in the console and then updating the stack creates a drift between the stack template and the actual resource, which CloudFormation will overwrite with the original code during the stack update, negating the manual change. Option D is wrong because creating a new CloudFormation stack for the new function and deleting the old stack introduces downtime during the deletion and creation process, and does not provide a seamless transition.

142
Multi-Selectmedium

A company is using AWS CodePipeline to automate deployments. The pipeline has a source stage that retrieves code from an S3 bucket, a build stage using CodeBuild, and a deploy stage using CodeDeploy. The build stage sometimes fails due to intermittent network issues. Which TWO actions would make the pipeline more resilient to such failures?

Select 1 answer
A.Enable retry on the build stage to automatically attempt the build again on failure.
B.Store build artifacts in a different S3 bucket.
C.Add a manual approval stage before the build stage.
D.Configure the build stage to run multiple build actions in parallel.
E.Use a different source repository, such as CodeCommit.
AnswersA

CodePipeline supports automatic retry on failed actions. Enabling retry on the build stage automatically re-runs the build if it fails due to transient network issues, improving resilience.

Why this answer

Option A is correct because CodePipeline supports automatic stage retry, which re-runs the failed build stage (including its CodeBuild action) after an intermittent network failure, allowing transient issues to resolve without manual intervention. Option D is incorrect because CodePipeline does not allow a stage to succeed when only one of several parallel actions succeeds; all actions in a stage must succeed for the stage to succeed, so running multiple build actions in parallel does not provide redundancy against transient failures and only adds complexity. Option B is incorrect because changing the artifact S3 bucket does not address intermittent network failures during the build.

Option C is incorrect because a manual approval stage only pauses the pipeline for human review and does not automatically recover from network-related build failures. Option E is incorrect because switching the source repository to CodeCommit does not make the CodeBuild stage resilient to intermittent network issues.

Exam trap

A common mistake is to assume that running multiple actions in parallel provides redundancy. In CodePipeline, all actions in a stage must succeed for the stage to succeed, so parallel execution does not make the pipeline resilient to a single action's transient failure. Retry logic is the correct mechanism for handling intermittent failures.

143
MCQhard

A web application runs on Amazon EC2 instances behind an Application Load Balancer (ALB). During peak hours, users report receiving HTTP 503 (Service Unavailable) errors. The developer checks Amazon CloudWatch metrics and finds that the ALB's request count is high but below the limit, and the target group's healthy host count drops to zero intermittently. The Auto Scaling group for the instances is configured with a minimum of 2, maximum of 10, and a simple scaling policy to add 2 instances when CPU utilization exceeds 70% for 5 consecutive minutes. What is the most likely cause of the 503 errors?

A.The Auto Scaling group's cooldown period prevents new instances from being added quickly enough during rapid traffic spikes
B.The ALB's idle timeout is set too low, causing dropped connections
C.The Auto Scaling group's maximum capacity of 10 is insufficient
D.The health check grace period is preventing instances from being marked healthy
AnswerA

During a rapid traffic spike, an Auto Scaling group's cooldown period, typically 300 seconds by default, prevents additional scaling activities from initiating immediately after a previous one. This delay means that even if the scaling policy is triggered multiple times, new instances cannot launch quickly enough to meet the escalating demand. Consequently, existing instances become overloaded and unhealthy, leading to 503 Service Unavailable errors as the application cannot process requests.

Why this answer

The 503 errors occur because the simple scaling policy has a cooldown period (default 300 seconds) that prevents the Auto Scaling group from launching new instances during rapid traffic spikes. When CPU exceeds 70% for 5 minutes, the policy adds 2 instances, but the cooldown blocks further scaling actions until it expires, even if the newly launched instances are still initializing and the healthy host count drops to zero. This mismatch between traffic demand and scaling responsiveness causes the ALB to have no healthy targets, resulting in 503 errors.

Exam trap

The trap here is that candidates often assume 503 errors are always due to capacity limits (Option C) or misconfigured health checks (Option D), but the real issue is the cooldown period's impact on scaling responsiveness during rapid traffic spikes.

How to eliminate wrong answers

Option B is wrong because the ALB's idle timeout (default 60 seconds) controls how long the ALB keeps a connection open without data transfer; it does not cause 503 errors or affect target health status. Option C is wrong because the maximum capacity of 10 is not the issue—the healthy host count drops to zero intermittently, indicating a scaling responsiveness problem, not a capacity ceiling. Option D is wrong because the health check grace period (default 300 seconds) delays the start of health checks for newly launched instances, but it does not cause healthy hosts to drop to zero; it only postpones marking them healthy, which would not explain intermittent drops in an already-running group.

144
Multi-Selectmedium

A developer is deploying a new version of an AWS Lambda function using the AWS CLI. The function is currently active and handling traffic. The developer wants to gradually shift traffic to the new version and rollback if errors increase. Which TWO actions should the developer take? (Choose TWO.)

Select 2 answers
A.Configure the alias to route a percentage of traffic to the new version and the rest to the current version.
B.Create a new version of the Lambda function.
C.Invoke the Lambda function with the new version using the AWS SDK.
D.Update the alias to route 100% of traffic to the new version.
E.Use AWS CodeDeploy to create a deployment group for the Lambda function.
AnswersA, B

This is a core capability of Lambda aliases, allowing for controlled, gradual rollouts of new function versions. By configuring a "weighted alias," a developer can specify a percentage of invocations to be directed to the new version while the remaining traffic continues to hit the stable, current version. This enables canary deployments, where the new version can be monitored for errors or performance regressions with minimal impact before a full rollout.

Why this answer

Lambda aliases support weighted routing, allowing you to specify a percentage of traffic to send to a new version while the remainder goes to the current version. This enables canary deployments where you can monitor error rates and rollback by adjusting the weights without redeploying.

Exam trap

The trap here is that candidates often think they must use an external service like CodeDeploy (Option E) for gradual traffic shifting, but Lambda aliases natively support weighted routing without additional services.

145
Multi-Selecteasy

A developer wants to ensure that an S3 bucket is not publicly accessible. Which TWO measures should the developer implement?

Select 2 answers
A.Enable S3 server access logging.
B.Enable versioning on the bucket.
C.Enable default encryption on the bucket.
D.Review the bucket policy to ensure it does not allow public access.
E.Enable S3 Block Public Access settings on the bucket.
AnswersD, E

Reviewing the bucket policy is a direct and necessary step because a bucket policy with a Principal of '*' and actions such as s3:GetObject or s3:ListBucket grants public read access to everyone. Even if the bucket ACLs and other settings appear restrictive, such a policy statement can make all objects publicly accessible. By auditing and removing any statement that grants access to 'Principal: *' or does not restrict access to specific AWS accounts, the developer can confirm that the bucket no longer publicly exposes objects. This complements Block Public Access, which provides a defensive override, but the policy itself is the actual source of public access.

Why this answer

Option D is correct because the bucket policy is the resource-based policy that can explicitly grant public access (for example, a Principal of "*" with s3:GetObject), so reviewing it to confirm it does not allow public access is a direct way to prevent the bucket from being publicly accessible. Option E is correct because S3 Block Public Access settings, when enabled on the bucket, override any bucket policy or ACL that would otherwise make objects public, providing a strong account- or bucket-level safeguard against public exposure. Option A is incorrect because S3 server access logging only records requests made to the bucket for auditing purposes; it does not restrict or prevent public access.

Option B is incorrect because versioning preserves multiple versions of objects for recovery and rollback, but it has no effect on whether the bucket or its objects are publicly accessible. Option C is incorrect because default encryption protects data at rest but does not control who can access the objects, so it does not prevent public accessibility.

Exam trap

DVA-C02 often tests the misconception that encryption or versioning prevents public access, when only Block Public Access and policy review actually restrict it.

146
MCQmedium

A developer needs to securely store database credentials for a Lambda function that accesses an Amazon RDS instance. The credentials must be automatically rotated every 30 days. Which AWS service should be used?

A.AWS IAM Roles for Lambda
B.AWS Secrets Manager
C.AWS Key Management Service (KMS)
D.AWS Systems Manager Parameter Store
AnswerB

AWS Secrets Manager is purpose-built for securely storing, managing, and retrieving sensitive information such as database credentials, API keys, and other secrets. It offers critical security features like automatic rotation of secrets, which is essential for enhancing security posture and reducing the risk of compromise. Furthermore, Secrets Manager provides fine-grained access control and integrates seamlessly with various AWS services and databases for streamlined secret management.

Why this answer

AWS Secrets Manager is the correct choice because it is specifically designed to securely store, manage, and automatically rotate database credentials for services like Amazon RDS. It supports built-in rotation with a configurable schedule (e.g., every 30 days) using a Lambda rotation function, and it integrates directly with RDS to update credentials without manual intervention. This meets the requirement for automatic rotation and secure storage.

Exam trap

Candidates often choose Parameter Store because it is cheaper and can store secrets, but it lacks native rotation scheduling for RDS credentials.

How to eliminate wrong answers

Option A is wrong because AWS IAM Roles for Lambda provide temporary credentials for API calls but cannot store or rotate database credentials; they are used for granting permissions to AWS services, not for managing secrets like usernames and passwords. Option C is wrong because AWS Key Management Service (KMS) is a key management service for encrypting data at rest and in transit, but it does not store secrets or provide automatic rotation of database credentials; it is used as an encryption key source, not a secret store. Option D is wrong because AWS Systems Manager Parameter Store can store secrets securely, but it lacks built-in automatic rotation capabilities for database credentials; while it can be integrated with custom rotation logic, it does not natively support scheduled rotation like Secrets Manager does.

147
MCQhard

A developer is building a serverless application that processes images uploaded to an S3 bucket. The bucket triggers a Lambda function that creates a thumbnail and stores it in another S3 bucket. The developer notices that the Lambda function is invoked multiple times for the same object, causing duplicate thumbnails. What is the MOST likely cause?

A.S3 event notifications are eventually consistent and may deliver duplicates.
B.The Lambda function is configured with a DLQ that causes retries.
C.The Lambda function is idempotent and should handle duplicates.
D.The S3 bucket has multiple event notifications that trigger the same Lambda function.
AnswerA

S3 event notifications are designed for at-least-once delivery, meaning duplicates are possible under rare circumstances like network issues or internal retries within AWS. However, the 'eventually consistent' nature of S3 object storage itself does not directly cause duplicate notification deliveries in the way this option implies. While S3 consistency models affect read-after-write behavior, they are not the primary or most common reason for receiving multiple identical event notifications for a single S3 action.

Why this answer

Amazon S3 event notifications are designed to provide at-least-once delivery. This means that while most events are delivered exactly once, duplicate event notifications can occasionally occur. To handle this, the Lambda function should be designed to be idempotent, ensuring that processing the same event multiple times does not cause unintended side effects (like duplicate thumbnails).

Exam trap

Candidates often assume that S3 event notifications guarantee exactly-once delivery, or they confuse S3's data consistency model (which is now strongly consistent for read-after-write) with its event delivery model (which is at-least-once).

How to eliminate wrong answers

Option A is wrong because S3 event notifications are designed to be delivered at least once, but they are not eventually consistent for new object creations; duplicates from S3 itself are rare and typically caused by retries due to failures, not by eventual consistency. Option B is wrong because a Dead Letter Queue (DLQ) does not cause retries; it captures events that have exhausted their retry attempts, and retries are controlled by the Lambda function's asynchronous invocation retry policy (up to 2 additional attempts), not by the DLQ. Option C is wrong because while idempotency is a best practice to handle duplicates, it is not the cause of the duplicates; the question asks for the most likely cause, not a solution.

148
Multi-Selecteasy

Which THREE practices help protect data at rest in Amazon S3?

Select 3 answers
A.Enable versioning.
B.Enable MFA Delete.
C.Enable server-side encryption for the bucket.
D.Enable cross-region replication.
E.Use bucket policies to deny uploads without encryption headers.
AnswersB, C, E

MFA Delete provides a critical layer of security by requiring multi-factor authentication for two highly sensitive operations: permanently deleting an object version or changing the versioning state of a bucket. This mechanism significantly reduces the risk of accidental or malicious data loss, as an attacker would need both the AWS account credentials and physical access to the MFA device to perform these actions. By preventing unauthorized permanent deletion, MFA Delete protects the integrity and continued existence of data at rest.

Why this answer

MFA Delete (B) is correct because it requires multi-factor authentication to permanently delete object versions or change the versioning state of the bucket, protecting stored data from unauthorized deletion or tampering. Server-side encryption (C) is correct because SSE-S3, SSE-KMS, or SSE-C encrypts objects at rest within S3, rendering the stored data unreadable without the appropriate keys. Bucket policies that deny uploads without encryption headers (E) are correct because they enforce encryption at write time, ensuring objects cannot be stored unencrypted in the bucket.

Versioning (A) only preserves object versions and aids recovery; it does not itself encrypt or otherwise protect data at rest. Cross-region replication (D) copies objects to another region for durability and availability, but it does not protect the data at rest from unauthorized access.

Exam trap

The trap here is that candidates often confuse versioning (which provides data protection through object recovery) with data-at-rest security (which requires encryption or access controls like MFA Delete), leading them to select versioning as a valid practice for protecting data at rest.

149
MCQhard

A developer is using an S3 bucket to store sensitive files. The bucket policy includes a condition that requires TLS for all requests. A user reports that they can access the bucket via the AWS Management Console but not via an application using HTTP. What is the likely issue?

A.The application is using an expired IAM access key.
B.The bucket policy denies HTTP requests via aws:SecureTransport condition.
C.The S3 bucket is in a different region.
D.The application is not signing requests with Signature Version 4.
AnswerB

A bucket policy with an aws:SecureTransport condition set to false explicitly denies any request that is not sent over HTTPS. The AWS Management Console always uses the HTTPS protocol, so requests from the console satisfy the condition and succeed. However, the application is sending plain HTTP requests, which fail the condition and receive a 403 Access Denied, exactly matching the reported behavior.

Why this answer

The condition aws:SecureTransport requires HTTPS; the application uses HTTP, which violates the policy.

150
Multi-Selectmedium

A company is deploying a new web application on Amazon EC2 instances behind an Application Load Balancer. The application must be deployed with no downtime. The deployment uses AWS CodeDeploy with a Blue/Green deployment configuration. Which TWO actions should be taken to achieve zero-downtime deployment? (Choose TWO.)

Select 2 answers
A.Create a new load balancer for the new environment.
B.Create a new Auto Scaling group with the new application version and register it with the ALB.
C.Update the existing Auto Scaling group with the new application version.
D.Terminate the old EC2 instances immediately after deploying the new ones.
E.Gradually shift traffic from the old environment to the new environment using the ALB.
AnswersB, E

Registering a newly created Auto Scaling group running the new application version into the existing ALB is the foundational blue/green action. The new ASG is placed in its own target group, so its instances can pass health checks and receive test traffic without altering the old ASG. This isolates the new environment while keeping the old one fully available for a controlled cutover.

Why this answer

Option B is correct because a CodeDeploy blue/green deployment for EC2 requires provisioning a replacement environment — a new Auto Scaling group running the new application revision — and registering it with the existing Application Load Balancer so it can serve traffic. Option E is correct because zero downtime is achieved by having the ALB gradually shift traffic from the original (blue) target group to the replacement (green) target group, using CodeDeploy's traffic-shifting controls (e.g., all-at-once, linear, or canary) before the old instances are terminated. Option A is wrong because creating a separate load balancer is unnecessary and would not provide the controlled traffic rerouting that CodeDeploy performs through the ALB's target groups.

Option C is wrong because updating the existing Auto Scaling group in place is an in-place deployment, not blue/green, and would replace instances without the parallel green environment needed for zero downtime. Option D is wrong because terminating the old instances immediately removes the safety net and can cause dropped connections; the original environment must be kept until traffic has fully shifted and the deployment succeeds.

Exam trap

DVA-C02 often tests the misconception that Blue/Green requires a new load balancer or that old instances should be terminated immediately — candidates must remember that the ALB and target groups enable traffic shifting and that old instances are retained for rollback.

Page 1

Page 2 of 16

Page 3