Courseiva

AWS Certified Developer Associate DVA-C02 (DVA-C02) — Questions 151–225

1135 questions total · 16pages · All types, answers revealed

Page 2

Page 3 of 16

Page 4
151
Multi-Selectmedium

Which THREE actions can be performed using AWS Lambda and Amazon S3 event notifications? (Choose three.)

Select 3 answers
A.Resize an image when a new image is uploaded to an S3 bucket.
B.Generate a pre-signed URL for an object.
C.Scan an uploaded file for viruses.
D.Enable versioning on the S3 bucket.
E.Transcode a video when a new video file is created.
AnswersA, C, E

When an object is uploaded to an S3 bucket, S3 can publish an event notification (e.g., s3:ObjectCreated:Put) to an AWS Lambda function. The Lambda function can then retrieve the newly uploaded image, perform image manipulation like resizing using libraries (e.g., Pillow in Python), and save the processed image back to S3, potentially in a different bucket or with a different key. This is a classic serverless image processing pattern.

Why this answer

AWS Lambda can be triggered by S3 event notifications for object creation events. When a new image is uploaded to an S3 bucket, the event notification invokes a Lambda function that can process the image, such as resizing it using libraries like Pillow or Sharp, and save the resized version back to S3.

Exam trap

AWS often tests the distinction between actions that can be automated via S3 event notifications triggering Lambda (asynchronous processing of existing objects) versus actions that require direct SDK calls or bucket-level configuration changes.

152
Multi-Selectmedium

A company is implementing a CI/CD pipeline using AWS CodePipeline and CodeBuild. The pipeline deploys a serverless application. Which TWO actions should be taken to securely manage the database credentials used by the application?

Select 2 answers
A.Embed the credentials in the Lambda function code.
B.Store the credentials in the buildspec.yml file in the CodeCommit repository.
C.Pass the credentials as CloudFormation parameters during deployment.
D.Use AWS Lambda environment variables with encryption using a KMS key.
E.Use AWS Secrets Manager to store the credentials and retrieve them in CodeBuild using an IAM role.
AnswersD, E

Storing sensitive information as AWS Lambda environment variables, encrypted with an AWS Key Management Service (KMS) key, is a secure and recommended practice. Lambda automatically encrypts these variables at rest using the specified KMS key and decrypts them at runtime when the function is invoked. This method prevents credentials from being exposed in plain text within the code or configuration, enhancing security and simplifying secret rotation.

Why this answer

AWS Lambda environment variables can be encrypted at rest using a KMS key, providing a secure way to store sensitive data like database credentials without hardcoding them in the function code. This approach ensures that the credentials are decrypted only when the Lambda function executes, and access to the KMS key can be controlled via IAM policies. Option E is also correct because AWS Secrets Manager is a dedicated service for managing secrets throughout their lifecycle, and CodeBuild can retrieve them securely using an IAM role with appropriate permissions, eliminating the need to store secrets in code or configuration files.

Exam trap

The trap here is that candidates may think CloudFormation parameters (Option C) are secure because they are not hardcoded, but they overlook that parameters can be exposed in plaintext in stack outputs, events, and parameter store, and they lack built-in encryption and rotation capabilities compared to Secrets Manager.

153
MCQmedium

Refer to the exhibit. An IAM policy is attached to a user. The user reports that they can access objects in the S3 bucket from their office IP address (192.0.2.15) but cannot access from home (203.0.113.5). What is the most likely reason?

A.The policy requires requests to originate from a VPC.
B.The bucket policy does not allow the user.
C.The policy restricts access based on source IP address.
D.The policy denies all s3:GetObject actions.
AnswerC

The policy includes an aws:SourceIp condition scoped to the office IP range (192.0.2.15), so any request originating from a different address, such as the home IP 203.0.113.5, fails the condition evaluation and the Allow statement does not apply, resulting in implicit denial of the request from home.

Why this answer

The correct option is C: the policy restricts access based on source IP address. Since the user can access the S3 bucket from the office IP 192.0.2.15 but not from the home IP 203.0.113.5, the IAM policy most likely includes a Condition element using aws:SourceIp (or NotIpAddress) that allows only the office IP range. Options A, B, and D do not fit: a VPC requirement would not explain why the office IP works, a bucket policy denying the user would block both locations, and a blanket Deny on s3:GetObject would also block access from the office.

154
MCQeasy

A developer wants to deploy a containerized application on AWS. The application requires persistent storage that can be accessed by multiple containers running on different EC2 instances. Which AWS service should the developer use?

A.Amazon Elastic File System (EFS)
B.Amazon Elastic Block Store (EBS)
C.Amazon Simple Storage Service (S3)
D.Amazon DynamoDB
AnswerA

Amazon Elastic File System (EFS) provides a scalable, fully managed, shared file system that can be mounted by multiple container instances (e.g., running on EC2 or Fargate) simultaneously. This allows containerized applications to access common data, such as configuration files, user-generated content, or persistent state, ensuring data consistency and availability across all containers. Its POSIX compliance makes it suitable for traditional file system operations required by many applications.

Why this answer

Amazon EFS provides a fully managed, scalable, and elastic NFS file system that can be mounted concurrently on multiple EC2 instances across different Availability Zones. This makes it the ideal choice for a containerized application requiring shared persistent storage accessible by multiple containers running on different instances, as it supports the NFSv4.1 and NFSv4.0 protocols for simultaneous access.

Exam trap

The trap here is that candidates often confuse EBS with EFS, assuming EBS supports multi-instance access by default, but EBS volumes are single-instance attached unless using the limited multi-attach feature, which is not designed for general-purpose shared file system use.

How to eliminate wrong answers

Option B (Amazon EBS) is wrong because EBS volumes are block-level storage devices that can only be attached to a single EC2 instance at a time (except for specific multi-attach EBS configurations, which are limited to io1/io2 volumes and a small number of instances, not suitable for general multi-container access across different instances). Option C (Amazon S3) is wrong because S3 is an object storage service accessed via HTTP/HTTPS APIs, not a file system mountable via NFS, and it does not provide low-latency file-level locking or POSIX-like semantics required for shared file system access by containers. Option D (Amazon DynamoDB) is wrong because DynamoDB is a NoSQL key-value and document database, not a file storage service, and it is designed for structured data access patterns, not for storing and sharing container files or directories.

155
MCQhard

An application running on EC2 instances behind an Application Load Balancer (ALB) occasionally returns HTTP 503 errors. The instances are in an Auto Scaling group. Which action should be taken to resolve this issue?

A.Enable cross-zone load balancing on the ALB.
B.Review the ALB access logs to identify the target response codes.
C.Increase the ALB idle timeout setting.
D.Increase the size of the EC2 instances.
AnswerB

ALB access logs record target response codes and timing, revealing whether 503s originate from unhealthy targets, connection limits or application errors. Reviewing them identifies the actual failure source before remediation, satisfying the need to diagnose rather than guess at scaling or health-check changes.

Why this answer

HTTP 503 errors from an ALB indicate that the targets (EC2 instances) are not responding successfully. Reviewing ALB access logs reveals the specific target response codes (e.g., 503 from the target itself or connection timeouts), which helps pinpoint whether the issue is due to overloaded instances, application errors, or health check failures. This diagnostic step is essential before making any configuration changes.

Exam trap

The trap here is that candidates often jump to scaling or instance size changes (Option D) without first using access logs to diagnose whether the 503s originate from the ALB or the targets, leading to ineffective fixes.

How to eliminate wrong answers

Option A is wrong because cross-zone load balancing is enabled by default on ALBs and affects traffic distribution across Availability Zones, not the root cause of 503 errors from unresponsive targets. Option C is wrong because the ALB idle timeout setting controls how long the ALB keeps a connection open without data transfer; increasing it does not resolve 503 errors caused by target failures or overload. Option D is wrong because simply increasing EC2 instance size may mask the problem but does not address the underlying cause (e.g., application bugs, scaling policies, or health check misconfigurations) and could lead to unnecessary cost.

156
MCQhard

A company has a monolithic application running on an EC2 instance that needs to be migrated to a microservices architecture on AWS. The development team wants to use AWS services to handle service discovery, configuration management, and secrets management. Which combination of AWS services should the team use?

A.Use Amazon ECS Service Discovery for service discovery, AWS Config for configuration, and AWS Systems Manager Parameter Store for secrets.
B.Use AWS Cloud Map for service discovery, AWS AppConfig for configuration, and AWS Secrets Manager for secrets.
C.Use AWS Cloud Map for service discovery, AWS Systems Manager Parameter Store for configuration, and AWS Secrets Manager for secrets.
D.Use AWS Service Discovery for service discovery, EC2 Image Builder for configuration, and AWS Key Management Service (KMS) for secrets.
AnswerB

This option correctly identifies the purpose-built AWS services for each requirement. AWS Cloud Map provides a unified service registry for all application resources, enabling dynamic discovery for EC2-based applications through DNS or API calls. AWS AppConfig is specifically designed for safe, controlled deployment and management of application configurations, including validation and rollback capabilities. AWS Secrets Manager is the most secure and feature-rich service for storing, rotating, and managing sensitive credentials and API keys.

Why this answer

AWS Cloud Map provides service discovery for microservices by registering service instances and enabling DNS-based or API-based resolution. AWS AppConfig manages application configuration with validation and controlled rollouts, and AWS Secrets Manager handles secrets management with automatic rotation and fine-grained access control. Together, these services meet the specific needs of service discovery, configuration management, and secrets management in a microservices architecture.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (which can store secrets but lacks automatic rotation and advanced access control) with AWS Secrets Manager, or mistakenly think AWS Config is suitable for application configuration management when it is actually for resource compliance and auditing.

How to eliminate wrong answers

Option A is wrong because AWS Config is designed for resource compliance and auditing, not for managing application configuration; it cannot push configuration updates or handle feature flags. Option C is wrong because AWS Systems Manager Parameter Store is a general-purpose parameter store that lacks built-in secrets rotation and advanced access control compared to Secrets Manager, making it less suitable for secrets management in a microservices context. Option D is wrong because 'AWS Service Discovery' is not a standalone AWS service (the correct service is AWS Cloud Map), EC2 Image Builder is for creating machine images, not configuration management, and AWS KMS is a key management service, not a secrets management service.

157
MCQhard

The exhibit shows an IAM policy attached to a user who needs to deploy applications using AWS CodeDeploy. The user reports that they cannot create a deployment for the MyApplication/MyDeploymentGroup. What is the most likely reason?

A.The policy restricts the user to a different deployment group.
B.The user does not have permission to call the codedeploy:CreateDeployment action.
C.The user does not have permission to call codedeploy:GetDeployment and codedeploy:GetDeploymentGroup.
D.The policy does not include permission on the application resource.
AnswerD

The `codedeploy:CreateDeployment` action requires explicit permissions on both the CodeDeploy application resource and the deployment group resource. While the policy correctly specifies the deployment group ARN (e.g., `arn:aws:codedeploy:...:deploymentgroup/MyApplication/MyDeploymentGroup`), it critically omits the necessary `application` ARN (e.g., `arn:aws:codedeploy:...:application/MyApplication`). This omission means the user lacks the required authorization on the application itself to successfully initiate a deployment.

Why this answer

The IAM policy shown in the exhibit likely grants permissions on the deployment group resource (e.g., arn:aws:codedeploy:region:account:deploymentgroup:MyApplication/MyDeploymentGroup) but omits the corresponding application resource (arn:aws:codedeploy:region:account:application:MyApplication). AWS CodeDeploy requires permissions on both the application and the deployment group for operations like CreateDeployment. Without the application-level permission, the request is implicitly denied, causing the failure.

Thus, the most likely reason is that the policy does not include permission on the application resource.

Exam trap

DVA-C02 often tests the misconception that permissions on a deployment group alone are sufficient for CodeDeploy operations, when in fact permissions on both the application and deployment group resources are required.

How to eliminate wrong answers

Option A is wrong because the policy explicitly grants access to the correct deployment group (as shown in the exhibit), so it does not restrict to a different one. Option B is wrong because the policy includes the codedeploy:CreateDeployment action, so the user does have permission to call that action. Option C is wrong because GetDeployment and GetDeploymentGroup are read-only actions not required for creating a deployment; the failure is due to missing write permission on the application resource, not read permissions.

158
MCQmedium

A developer is using AWS CodeDeploy to perform a canary deployment for an AWS Lambda function. The deployment should first shift 10% of traffic to the new version, and then shift the remaining 90% after 5 minutes. Which deployment configuration should be used?

A.AllAtOnce
B.Canary10Percent5Minutes
C.Linear10PercentEvery10Minutes
D.BlueGreen
AnswerB

The Canary10Percent5Minutes CodeDeploy configuration precisely implements a canary deployment by initially shifting 10% of traffic to the new Lambda function version. After a 5-minute bake time, during which the new version can be monitored for errors or performance degradation, the remaining 90% of traffic is automatically shifted. This phased approach allows for early detection of issues with minimal user impact, aligning perfectly with the requirements of a canary release strategy.

Why this answer

The Canary10Percent5Minutes deployment configuration is specifically designed for canary deployments with AWS Lambda, shifting 10% of traffic to the new version immediately and then automatically shifting the remaining 90% after a 5-minute interval. This matches the requirement exactly, as CodeDeploy uses this predefined configuration to orchestrate the traffic shift in two steps with a built-in wait period.

Exam trap

The trap here is that candidates often confuse deployment configurations (like Canary10Percent5Minutes) with deployment types (like BlueGreen), or they misremember the exact traffic percentages and intervals, leading them to select Linear10PercentEvery10Minutes or AllAtOnce instead of the precise configuration that matches the 10% initial shift and 5-minute wait.

How to eliminate wrong answers

Option A is wrong because AllAtOnce shifts 100% of traffic to the new version immediately, with no gradual traffic shifting or canary phase, which does not meet the requirement for a 10% initial shift and a 5-minute wait. Option C is wrong because Linear10PercentEvery10Minutes shifts traffic in 10% increments every 10 minutes, which would take 90 minutes to complete the full shift and does not match the specified 5-minute wait after the initial 10% shift. Option D is wrong because BlueGreen is a deployment type, not a deployment configuration; it refers to the strategy of routing all traffic to a new environment after validation, but CodeDeploy requires a specific traffic-shifting configuration (like Canary10Percent5Minutes) to control the canary behavior within a blue/green deployment.

159
MCQeasy

A developer is building a microservices application that processes event messages from multiple sources. The application requires at-least-once delivery, but message ordering is not important. Which Amazon SQS queue type should the developer use?

A.Standard queue
B.FIFO queue
C.Dead-letter queue
D.Delay queue
AnswerA

Standard queues are the default SQS queue type, designed for high throughput and best-effort ordering. They guarantee at-least-once message delivery, meaning a message might be delivered more than once, which requires consumers to be idempotent. This queue type is ideal for microservices where strict message ordering is not critical, and the application can handle occasional duplicates or out-of-order processing efficiently.

Why this answer

Amazon SQS Standard queues provide at-least-once delivery and best-effort ordering, making them ideal for microservices that can tolerate duplicate messages and do not require strict message sequencing. Since the application processes events from multiple sources and message ordering is not important, a Standard queue meets the requirements without the throughput limitations of FIFO queues.

Exam trap

The trap here is that candidates often confuse the 'at-least-once' delivery requirement with the need for ordering, leading them to choose FIFO queues, but the question explicitly states ordering is not important, making Standard queues the correct and more performant choice.

How to eliminate wrong answers

Option B is wrong because FIFO queues guarantee exactly-once processing and strict message ordering, which are unnecessary here and would impose a throughput limit of 3,000 transactions per second (with batching) or 300 without, adding cost and complexity. Option C is wrong because a dead-letter queue is not a primary queue type for receiving messages; it is a secondary queue used to capture messages that fail processing after a specified number of receive attempts. Option D is wrong because a delay queue is not a distinct queue type but a feature of Standard or FIFO queues that introduces an initial message delay (up to 15 minutes), which does not address the core requirement of at-least-once delivery.

160
MCQmedium

Refer to the exhibit. A developer invoked a Lambda function and received this response. What does the FunctionError field indicate?

A.The function executed successfully.
B.The function threw an unhandled exception.
C.The function was throttled.
D.The function timed out.
AnswerB

When FunctionError is set to 'Unhandled', it means the function code threw an exception or exited abnormally without a surrounding try/catch (or equivalent) that intercepted it, so the Lambda runtime itself caught the failure and reported it back in the invoke response. The response payload also typically contains an errorMessage and stack trace describing the exception.

Why this answer

FunctionError: Unhandled indicates that the function threw an exception that was not caught by the code. Option A is wrong because StatusCode 200 means invocation succeeded. Option C is wrong because throttling would return 429.

Option D is wrong because configuration errors would return 400.

161
MCQhard

A developer is using AWS CodePipeline to deploy a serverless application. The pipeline has a source stage (CodeCommit), a build stage (CodeBuild), and a deploy stage (CloudFormation). The developer wants to automatically roll back the deployment if the CloudFormation stack update fails. Which configuration should be used?

A.Add a stack policy to the CloudFormation stack to prevent updates.
B.Set the deployment to use AWS CodeDeploy and enable rollback.
C.Configure a manual approval action in the pipeline to trigger a rollback.
D.Configure the CloudFormation stack to roll back on failure using the RollbackConfiguration.
AnswerD

Configuring the CloudFormation stack with a `RollbackConfiguration` is the correct and most effective method for automatically rolling back a failed stack update. This feature allows you to specify CloudWatch alarms that CloudFormation monitors during and after a stack update. If any specified alarm enters an `ALARM` state within a defined monitoring period, CloudFormation will automatically initiate a rollback to the stack's previous stable state, ensuring service stability.

Why this answer

CloudFormation natively supports automatic rollback on stack update failure through the `RollbackConfiguration` property. When a stack update fails, CloudFormation can automatically revert to the last known good state, which is exactly what the developer needs for a serverless deployment pipeline. This configuration can be set in the CloudFormation template or passed as a parameter during the deploy action in CodePipeline.

Exam trap

The trap here is that candidates may confuse CloudFormation's built-in rollback capability with external services like CodeDeploy, or assume that manual approval is required for rollback, when in fact CloudFormation can handle it automatically via `RollbackConfiguration`.

How to eliminate wrong answers

Option A is wrong because a stack policy prevents updates to specific resources but does not provide rollback on failure; it would block the deployment entirely. Option B is wrong because CodeDeploy is used for deploying applications to EC2, Lambda, or ECS, not for CloudFormation stack updates; it cannot manage CloudFormation rollbacks. Option C is wrong because a manual approval action pauses the pipeline for human review but does not automatically trigger a rollback; it requires manual intervention to initiate a rollback, which contradicts the requirement for automatic rollback.

162
MCQmedium

A developer notices that an AWS Lambda function configured with a VPC is timing out when trying to access an Amazon S3 bucket. The function has the necessary IAM permissions. What is the most likely cause?

A.Lambda functions cannot be configured inside a VPC.
B.The Lambda function's execution role lacks S3 permissions.
C.The Lambda function does not have a route to the internet or a VPC endpoint for S3.
D.The security group attached to the Lambda function does not allow outbound traffic to S3.
AnswerC

This is correct. When a Lambda function is configured inside a VPC, it loses internet access by default. To access S3, the function needs either a VPC endpoint for S3 or a route to the internet via a NAT Gateway/Instance. Without this, the function times out.

Why this answer

When a Lambda function is attached to a VPC, it loses the default internet access it normally has and can only reach resources within that VPC's subnets. To reach S3, the function must either route through a NAT gateway/instance to the public internet or use an S3 Gateway VPC Endpoint, which provides private connectivity without traversing the internet.

Exam trap

DVA-C02 often tests the misconception that security groups block outbound traffic by default — they don't (they're stateful and allow all egress unless restricted), so the real culprit in VPC-attached Lambda timeouts is almost always missing NAT or VPC endpoint routing.

How to eliminate wrong answers

Option A is wrong because Lambda functions absolutely can be configured inside a VPC — this is a supported and common configuration. Option B is wrong because the question explicitly states the function already has the necessary IAM permissions, so the execution role is not the issue. Option D is wrong because security groups are stateful and by default allow all outbound traffic; the more common cause of S3 timeouts from VPC-attached Lambda is the missing route/endpoint, not the security group egress rules.

163
MCQhard

A developer creates the CloudFormation stack with the template above. After the stack is created, messages that are not processed after 5 receives are moved to the DLQ. However, the developer notices that the RedrivePolicy references a queue ARN that is hardcoded. What is the best practice to avoid this hardcoded ARN?

A.Use Ref to reference the DLQ's QueueName and construct the ARN.
B.Use Fn::Sub to substitute the queue name into a hardcoded ARN template.
C.Use Fn::ImportValue to import the DLQ ARN from another stack.
D.Use Fn::GetAtt with "Arn" attribute on the DLQ resource.
AnswerD

Fn::GetAtt is the correct and most robust intrinsic function for retrieving a specific attribute from a resource defined within the same CloudFormation template. For an AWS::SQS::Queue resource, the Arn attribute directly provides the complete Amazon Resource Name (ARN) of the queue. This approach dynamically fetches the fully qualified ARN, eliminating the need for hardcoding account IDs, regions, or manual string construction, ensuring accuracy and portability across environments.

Why this answer

`Fn::GetAtt` with the `Arn` attribute retrieves the actual Amazon Resource Name (ARN) of the Dead Letter Queue (DLQ) resource dynamically at stack creation time. This avoids hardcoding the ARN, making the template portable across accounts and regions. The RedrivePolicy property requires the full ARN of the DLQ, and `Fn::GetAtt` is the intrinsic function designed to return resource attributes like ARN.

Exam trap

The trap here is that candidates often confuse `Ref` (which returns the QueueName or Queue URL) with `Fn::GetAtt` (which returns the ARN), leading them to choose Option A or attempt manual ARN construction with `Fn::Sub`.

How to eliminate wrong answers

Option A is wrong because `Ref` on an SQS queue returns the QueueName (or Queue URL in some contexts), not the ARN, and constructing the ARN manually is error-prone and not a best practice. Option B is wrong because `Fn::Sub` with a hardcoded ARN template still contains a static ARN pattern (e.g., `arn:aws:sqs:${AWS::Region}:${AWS::AccountId}:queue-name`), which is fragile if the queue name changes or if the stack is deployed to a different partition (e.g., GovCloud). Option C is wrong because `Fn::ImportValue` is used to import outputs from another stack, but the DLQ is defined within the same stack, so cross-stack referencing is unnecessary and adds complexity.

164
MCQmedium

A developer runs the following AWS CLI query against a DynamoDB table named 'Orders' and receives a ValidationException: ``` aws dynamodb query \ --table-name Orders \ --key-condition-expression "OrderID = :orderID" \ --expression-attribute-values '{":orderID":{"S":"12345"}}' ``` What is the MOST likely cause?

A.The expression attribute values are incorrectly formatted
B.The table's partition key is not named 'OrderID'
C.The table does not exist
D.The query needs to use a sort key
AnswerB

A DynamoDB Query operation fundamentally requires that its KeyConditionExpression explicitly references the table's defined partition key attribute. If the table's actual partition key is named something other than 'OrderID' (e.g., 'CustomerID' or 'PK'), then attempting to use 'OrderID' in the KeyConditionExpression will result in a ValidationException. This error occurs because the query is trying to apply a key condition to an attribute that is not recognized as the table's primary partition key.

Why this answer

DynamoDB's Query operation requires that the KeyConditionExpression reference the table's actual partition key name exactly. If the Orders table's partition key is not named 'OrderID', the query fails with a ValidationException. The expression attribute values are formatted correctly, and a sort key is not required to query by partition key alone.

Exam trap

The trap here is that candidates often assume the error is due to missing a sort key or incorrect value formatting, but DynamoDB's strict schema validation means the partition key name must exactly match the table's definition, which is a common oversight.

How to eliminate wrong answers

Option A is wrong because expression attribute values (e.g., :v1) are syntactically correct in the query and DynamoDB would not throw an error for formatting unless they were missing or had invalid types. Option C is wrong because if the table did not exist, DynamoDB would return a 'ResourceNotFoundException', not a validation error related to key conditions. Option D is wrong because a query can be performed using only a partition key (with an equality condition) without a sort key; the error is not about missing a sort key but about an incorrect partition key name.

165
MCQhard

A company runs a web application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application uses an Amazon RDS MySQL database. Recently, the application started experiencing frequent database connection timeouts. The development team discovered that the application is not closing database connections properly, leading to exhausted database connections. The team wants a solution that does not require code changes. Which option should they choose?

A.Configure Amazon RDS Proxy in front of the RDS instance and update the application to connect through the proxy.
B.Enable Multi-AZ on the RDS instance to handle failover and reduce connection timeouts.
C.Migrate the database to Amazon Aurora and enable Auto Scaling for read replicas.
D.Increase the max_connections parameter in the RDS parameter group to allow more concurrent connections.
AnswerA

Configuring Amazon RDS Proxy in front of the RDS instance is the most effective solution because it provides connection pooling and multiplexing. RDS Proxy maintains a pool of established database connections and reuses them for new application requests, significantly reducing the overhead on the database and making the application more resilient to transient connection issues or inefficient connection handling, such as connection leaks. This approach prevents connection exhaustion without requiring extensive application code changes to fix the underlying connection management issues.

Why this answer

Amazon RDS Proxy provides connection pooling, allowing the application to reuse database connections efficiently, reducing the number of open connections without code changes. Option B is incorrect: Multi-AZ provides high availability and failover but does not address connection leaks or exhaustion. Option C is incorrect: Migrating to Aurora with Auto Scaling for read replicas adds scalability for read traffic but does not fix connection leaks; it also requires migration effort.

Option D is incorrect: Increasing max_connections may temporarily alleviate the symptom but does not solve the underlying issue of connections not being closed, and it can lead to resource contention.

166
MCQmedium

A company is using Amazon API Gateway to expose a REST API. The API must authenticate requests using an external OAuth 2.0 provider. Which API Gateway feature should be used?

A.IAM authorization
B.Resource policy
C.Lambda authorizer
D.Amazon Cognito User Pools
AnswerC

A Lambda authorizer (formerly custom authorizer) is a powerful and flexible mechanism where API Gateway invokes a custom AWS Lambda function before forwarding the request to the backend. This Lambda function receives the incoming request's authorization header, allowing it to execute arbitrary custom logic to validate the external OAuth token. The function can perform tasks like calling an OAuth provider's introspection endpoint, verifying JWT signatures against public keys, or checking token claims, ultimately returning an IAM policy that grants or denies access to the API resources based on the token's validity.

Why this answer

A Lambda authorizer (formerly known as a custom authorizer) allows you to implement custom authentication logic using an external OAuth 2.0 provider. The Lambda function receives the OAuth 2.0 bearer token from the request, validates it against the external provider's token introspection endpoint or by verifying the JWT signature, and returns an IAM policy that grants or denies access to the API Gateway method.

Exam trap

The trap here is that candidates often confuse Amazon Cognito User Pools with a generic OAuth 2.0 integration, but Cognito is a specific AWS-managed IdP and cannot validate tokens issued by an external OAuth 2.0 provider like Auth0 or Okta.

How to eliminate wrong answers

Option A is wrong because IAM authorization uses AWS Signature Version 4 (SigV4) to sign requests with IAM credentials, which is designed for internal AWS authentication and cannot integrate with an external OAuth 2.0 provider. Option B is wrong because a resource policy controls access at the API level based on IP addresses, VPC endpoints, or AWS accounts, but it does not handle token validation or OAuth 2.0 flows. Option D is wrong because Amazon Cognito User Pools is a managed identity provider that issues its own JWTs, but the requirement explicitly states using an external OAuth 2.0 provider, and Cognito cannot delegate authentication to an arbitrary third-party OAuth 2.0 server.

167
MCQhard

A developer is deploying a multi-container Docker application on Amazon ECS using the Fargate launch type. The application consists of a web server and a background worker. The web server must be scaled independently and must be accessible from the internet via an Application Load Balancer. The worker should not be accessible from the internet. Which ECS configuration should the developer use?

A.Create one ECS service with both containers in the same task definition, but only expose the web server port.
B.Create two separate ECS services, each with its own task definition, and place the web server in a public subnet with the worker in a private subnet.
C.Create one ECS service with two tasks, each containing one container.
D.Create one ECS service with two containers in the same task, and use a service discovery to expose the worker.
AnswerB

This approach correctly leverages ECS services for independent lifecycle management and scaling of distinct application components. By defining separate task definitions and services for the web server and worker, each can be scaled independently based on its specific load requirements, optimizing resource utilization. Placing the web server service in a public subnet, typically behind an Application Load Balancer, allows it to serve internet traffic, while the worker service in a private subnet ensures it remains isolated from direct public access, enhancing security and adhering to best practices for backend components.

Why this answer

It uses two separate ECS services, each with its own task definition, allowing independent scaling of the web server and worker. Placing the web server in a public subnet with an Application Load Balancer makes it internet-accessible, while the worker in a private subnet is isolated from direct internet traffic, meeting the security requirement.

Exam trap

The trap here is that candidates assume containers in the same task definition can be independently scaled or that service discovery alone provides network isolation, but in ECS, containers in the same task share the same resources and scaling lifecycle, and service discovery does not restrict internet access.

How to eliminate wrong answers

Option A is wrong because placing both containers in the same task definition forces them to be scaled together as a unit, preventing independent scaling of the web server, and exposing only the web server port does not isolate the worker from the internet since both containers share the same network namespace. Option C is wrong because creating one ECS service with two tasks, each containing one container, does not allow independent scaling of the web server and worker; the service scales all tasks together, and the worker task would still be in the same subnet as the web server unless explicitly placed in a private subnet, which is not specified. Option D is wrong because placing both containers in the same task (same task definition) again couples their scaling and lifecycle, and using service discovery (AWS Cloud Map) does not prevent the worker from being internet-accessible; service discovery only provides DNS-based service resolution within a VPC, not network isolation.

168
MCQhard

A company has a microservices architecture running on Amazon ECS with Fargate. Each service exposes an API through an Application Load Balancer (ALB). The development team needs to implement canary deployments for one of the services. What is the MOST efficient way to achieve this?

A.Create two ECS services behind the same ALB, each with a different task definition, and use sticky sessions.
B.Use Amazon Route 53 weighted routing policies to distribute traffic between two ALBs.
C.Configure the ALB to use weighted target groups, each pointing to a different task set of the same ECS service.
D.Use AWS CodeDeploy with an ECS blue/green deployment configuration that supports canary traffic shifting.
AnswerD

AWS CodeDeploy does support blue/green deployments for ECS, including advanced traffic shifting strategies like canary. However, for a scenario focused purely on gradual traffic shifting between two versions of an application within the same ECS service, directly configuring weighted target groups on the ALB is a simpler and more native approach. CodeDeploy introduces an orchestration layer that, while powerful for complex deployment pipelines, might be overkill when the ALB's built-in capabilities can achieve the desired canary deployment with less overhead.

Why this answer

AWS CodeDeploy natively supports blue/green and canary deployments (e.g., ECSCanary10Percent5Minutes) for Amazon ECS. While ALB weighted target groups and ECS Task Sets are the underlying mechanisms used during these deployments, managing them manually (Option C) requires using the EXTERNAL deployment controller and writing custom orchestration code, which is highly inefficient. CodeDeploy automates this entire process seamlessly.

Exam trap

Candidates often think that because ALB supports weighted target groups, they should configure them manually for ECS canary deployments. However, for ECS, AWS CodeDeploy is the standard and most efficient tool to automate canary traffic shifting using those target groups.

How to eliminate wrong answers

Option A is wrong because creating two separate ECS services behind the same ALB with sticky sessions would route users to a fixed service based on session affinity, not allow gradual traffic shifting; it also adds operational overhead of managing multiple services. Option B is wrong because using Route 53 weighted routing between two ALBs introduces DNS-level latency and complexity, and does not support fine-grained traffic shifting at the application layer; it also requires managing two separate ALBs and DNS propagation delays. Option D is wrong because AWS CodeDeploy with blue/green deployment is designed for full traffic shifts (e.g., 10% then 100%) and requires additional setup and orchestration, making it less efficient than directly using ALB weighted target groups for canary deployments within a single ECS service.

169
MCQmedium

A developer is designing a serverless application using API Gateway, Lambda, and DynamoDB. The API must authenticate users using a JWT token. Which API Gateway feature should the developer use to validate the JWT before invoking the Lambda function?

A.Use an IAM authorizer with a resource policy.
B.Use an Amazon Cognito user pool authorizer.
C.Use a Lambda authorizer (custom authorizer).
D.Use an API Gateway resource policy to allow only authenticated IPs.
AnswerC

A Lambda authorizer, also known as a custom authorizer, offers the flexibility to implement bespoke authentication and authorization logic using an AWS Lambda function. This function receives the incoming request's authorization token, such as a custom JWT, and can perform any necessary validation, including signature verification, expiration checks, and claim validation against an issuer's public key or custom business rules. If the token is valid, the Lambda function returns an IAM policy allowing access to the API Gateway resources, making it ideal for validating custom JWTs from any identity provider.

Why this answer

A Lambda authorizer (custom authorizer) is required to validate JWTs issued by a third-party identity provider (IdP) in API Gateway REST APIs. While Amazon Cognito user pool authorizers can natively validate Cognito-issued JWTs, they cannot validate tokens from external providers. A Lambda authorizer allows you to run custom code to verify the signature, expiration, and claims of any third-party JWT before routing the request to the backend Lambda function.

Exam trap

The exam often tests your ability to choose between a Cognito authorizer and a Lambda authorizer. Remember: if the JWT is from Cognito, use the Cognito user pool authorizer (no custom code needed). If the JWT is from a third-party IdP (like Auth0, Okta, or a custom server), you must use a Lambda authorizer (for REST APIs) or a JWT authorizer (for HTTP APIs).

How to eliminate wrong answers

Option A is wrong because an IAM authorizer with a resource policy authenticates requests using AWS Signature Version 4, not JWT tokens, and is designed for AWS service-to-service or IAM user access, not for validating third-party JWTs. Option B is wrong because an Amazon Cognito user pool authorizer is a managed solution that validates JWTs issued only by a Cognito user pool; it cannot validate JWTs from other identity providers, which is the requirement in this scenario. Option D is wrong because an API Gateway resource policy controls access based on source IP addresses or AWS accounts, not on JWT token validation, and does not authenticate individual users.

170
MCQeasy

A developer is deploying a new version of an application to Amazon ECS using AWS CodeDeploy. The application uses a blue/green deployment strategy. After the deployment, traffic is automatically shifted to the new task set. However, the developer wants to test the new version with a small percentage of users before shifting all traffic. What should the developer do?

A.Create a new ECS task definition with a different CPU/memory allocation.
B.Use CodeDeploy to perform a canary deployment that shifts 10% of traffic initially.
C.Configure the target group to route traffic to a specific task set.
D.Use ECS service auto scaling to gradually increase the number of tasks.
AnswerB

Using CodeDeploy to perform a canary deployment is the correct approach for gradually shifting traffic to a new application version in ECS. CodeDeploy integrates with ECS and an Application Load Balancer (ALB) to manage two target groups (one for the old task set, one for the new). It progressively updates the ALB listener rules to route a specified percentage of traffic, like 10% initially, to the new version, allowing for controlled rollout and easy rollback.

Why this answer

CodeDeploy supports canary deployments for ECS, which allow you to shift a specified percentage of traffic to the new task set initially (e.g., 10%) and then, after a configured interval, shift the remaining traffic. This matches the requirement to test with a small percentage of users before shifting all traffic. Option B directly implements this canary strategy.

Exam trap

The trap here is that candidates confuse 'canary deployment' (traffic shifting) with 'auto scaling' (task count scaling) or think that modifying the task definition or target group alone can achieve gradual traffic routing.

How to eliminate wrong answers

Option A is wrong because changing CPU/memory allocation in the task definition does not control traffic shifting; it affects resource provisioning and may cause deployment failures but does not route a percentage of traffic to the new version. Option C is wrong because target groups route traffic to all healthy tasks in a service, not to a specific task set; you cannot use a target group to selectively route a small percentage to one task set without additional traffic-shifting logic. Option D is wrong because ECS service auto scaling adjusts the number of tasks based on load, not the percentage of traffic directed to a new version; it does not implement a canary traffic shift.

171
MCQmedium

A developer deploys an application on EC2 instances behind an Application Load Balancer (ALB). The application uses sticky sessions (session affinity) based on a cookie. Users report that they are intermittently logged out during their session. What is the MOST likely cause?

A.The deregistration delay value is too low, causing connections to be dropped during scaling events.
B.The ALB health check interval is too short, causing healthy instances to be marked unhealthy frequently.
C.Cross-zone load balancing is disabled, causing uneven traffic distribution.
D.The stickiness cookie expiration duration is set too low, causing the cookie to expire before the user's session ends.
AnswerD

The ALB's stickiness configuration includes a cookie duration setting (1 second to 7 days) that determines how long the AWSALB cookie remains valid; if this duration is shorter than a typical user session, the cookie expires mid-session, the ALB then routes the next request to a different, possibly unauthenticated, backend instance, and the application-level session appears to log the user out.

Why this answer

If the stickiness cookie expiration duration is set too low, the cookie will expire before the user's session ends, causing the load balancer to route the user to a different instance and losing session state. Option A is wrong because deregistration delay affects how long an instance remains in service during scaling events, but does not directly cause intermittent logouts during a session. Option B is wrong because a short health check interval might cause healthy instances to be marked unhealthy, but this would result in dropped connections, not specifically intermittent logouts due to session stickiness.

Option C is wrong because cross-zone load balancing affects traffic distribution across zones, not session stickiness.

172
Multi-Selectmedium

A company is using AWS Lambda functions that access an RDS database. Which THREE practices should be followed to secure the database credentials?

Select 3 answers
A.Use AWS Secrets Manager to store and automatically rotate the credentials.
B.Use a security group to decrypt the credentials.
C.Encrypt the credentials using AWS KMS and pass them as encrypted environment variables to Lambda.
D.Store the credentials in the Lambda function code.
E.Place the Lambda function inside a VPC and use a security group to allow access to RDS.
AnswersA, C, E

AWS Secrets Manager is a dedicated service designed for securely storing, managing, and automatically rotating credentials, API keys, and other secrets. By integrating with Secrets Manager, Lambda functions can retrieve the latest database credentials at runtime using an IAM role, eliminating the need to hardcode or embed them. This approach enhances security by centralizing secret management and enforcing regular credential rotation, significantly reducing the risk of compromise.

Why this answer

Option A is correct because AWS Secrets Manager is purpose-built to store database credentials securely and can automatically rotate RDS credentials on a schedule using a Lambda rotation function, eliminating hard-coded or long-lived secrets. Option C is correct because Lambda environment variables can be encrypted at rest with an AWS KMS customer managed key, so credentials are not stored in plaintext and the function decrypts them at runtime using its execution role permissions. Option E is correct because placing the Lambda function in the same VPC as the RDS instance and using a security group to permit traffic only to the database port (e.g., 3306 for MySQL or 5432 for PostgreSQL) restricts network access to the database.

Option B is incorrect because security groups are stateful virtual firewalls that filter network traffic; they do not decrypt credentials. Option D is incorrect because embedding credentials in Lambda function code exposes them in source control, deployment packages, and logs, which is an insecure anti-pattern.

Exam trap

The trap here is that candidates often confuse network-level controls (security groups) with cryptographic operations, or assume that encrypting environment variables with KMS is sufficient, overlooking that Secrets Manager provides rotation and centralized audit capabilities that KMS alone does not.

173
MCQeasy

A developer is deploying a web application using AWS Elastic Beanstalk. The application experiences high traffic during peak hours. The developer wants to ensure that the environment can scale out quickly without manual intervention. Which Elastic Beanstalk configuration should be used?

A.Use a scheduled scaling action to increase capacity during peak hours.
B.Manually add EC2 instances during peak hours.
C.Set the environment to use a fixed number of EC2 instances.
D.Configure Auto Scaling triggers based on CloudWatch alarms.
AnswerD

Configuring Auto Scaling triggers based on CloudWatch alarms provides a robust and dynamic solution for automatically adjusting EC2 instance capacity in response to real-time application load. CloudWatch monitors key metrics like CPU utilization or network I/O, and when predefined thresholds are breached, it triggers Auto Scaling policies to add or remove instances. This ensures optimal performance and cost efficiency by scaling resources precisely when needed, without manual intervention or reliance on predictable schedules.

Why this answer

Elastic Beanstalk integrates with Auto Scaling to automatically adjust the number of EC2 instances based on demand. By configuring Auto Scaling triggers that respond to CloudWatch alarms (e.g., CPU utilization > 70%), the environment can scale out quickly and without manual intervention during peak hours.

Exam trap

The trap here is that candidates often confuse scheduled scaling (Option A) with dynamic scaling, not realizing that scheduled actions cannot handle unpredictable spikes, while CloudWatch-triggered Auto Scaling provides real-time, event-driven scaling.

How to eliminate wrong answers

Option A is wrong because scheduled scaling actions are time-based and cannot adapt to unpredictable traffic spikes; they only add capacity at fixed times. Option B is wrong because manually adding EC2 instances defeats the purpose of automation and does not scale out quickly without manual intervention. Option C is wrong because using a fixed number of EC2 instances prevents any scaling, leading to either over-provisioning or under-provisioning during high traffic.

174
Multi-Selectmedium

A company is deploying a new microservice using AWS Lambda and Amazon API Gateway. Which THREE steps should be included in the deployment pipeline? (Choose three.)

Select 3 answers
A.Deploy the API Gateway API to a stage.
B.Create or update the API Gateway REST API resources and methods.
C.Invalidate the Amazon CloudFront cache.
D.Update the Route 53 DNS record to point to the new API.
E.Build the Lambda function code and create a deployment package.
AnswersA, B, E

After defining the API's resources, methods, and integrations, the API Gateway REST API must be explicitly deployed to a stage to make it publicly accessible. A stage acts as a logical reference to a specific version of your API, allowing for independent configuration of settings like throttling, caching, and logging. This deployment step publishes the API, generating an invoke URL that clients can use to access the microservice.

Why this answer

Deploying the API Gateway API to a stage is essential because it makes the API publicly available at a specific URL (e.g., https://api-id.execute-api.region.amazonaws.com/prod). Without a stage deployment, any updates to the API resources and methods remain in draft state and are not accessible to clients.

Exam trap

The trap here is that candidates may confuse the deployment of the Lambda function (which is a separate step) with the deployment of the API Gateway API, or incorrectly assume that DNS updates or cache invalidation are mandatory steps in a standard serverless deployment pipeline.

175
MCQhard

A developer is using AWS KMS to encrypt data in an S3 bucket. The developer wants to ensure that the S3 bucket uses server-side encryption with AWS KMS managed keys (SSE-KMS) by default. Which configuration should be applied?

A.Add a bucket policy that denies PutObject without the 'x-amz-server-side-encryption' header set to 'aws:kms'.
B.Configure the bucket to use SSE-C with a customer-provided key.
C.Set the bucket's default encryption to SSE-S3.
D.Set the bucket's default encryption to SSE-KMS with a KMS key.
AnswerD

Configuring the S3 bucket's default encryption to SSE-KMS with a specified AWS KMS key ensures that all new objects uploaded to the bucket are automatically encrypted using that KMS key. This method directly leverages AWS KMS for key management, providing centralized control, auditability through CloudTrail, and integration with IAM policies, precisely meeting the requirement to use AWS KMS for data encryption.

Why this answer

Setting the bucket's default encryption to SSE-KMS with a KMS key ensures that all objects uploaded to the S3 bucket are automatically encrypted using server-side encryption with AWS KMS managed keys (SSE-KMS). This configuration enforces encryption at rest without requiring the client to specify encryption headers in the request, meeting the requirement for default SSE-KMS encryption.

Exam trap

The trap here is that candidates often confuse enforcing encryption via a bucket policy (Option A) with setting a default encryption configuration, but the policy only denies non-compliant requests without establishing a default, whereas the default encryption setting automatically applies encryption to all objects regardless of request headers.

How to eliminate wrong answers

Option A is wrong because a bucket policy that denies PutObject without the 'x-amz-server-side-encryption' header set to 'aws:kms' enforces encryption on a per-request basis but does not set a default encryption configuration for the bucket; it only rejects requests that lack the header, leaving the bucket without a default encryption setting. Option B is wrong because SSE-C uses a customer-provided key, not an AWS KMS managed key, and is not the SSE-KMS method specified in the requirement. Option C is wrong because SSE-S3 uses Amazon S3 managed keys, not AWS KMS managed keys, and thus does not fulfill the requirement for SSE-KMS.

176
MCQeasy

A developer needs to store a large number of binary files (e.g., images) that are accessed infrequently but must be retrievable within minutes. The storage solution should be cost-effective. Which Amazon S3 storage class is MOST suitable?

A.S3 Intelligent-Tiering
B.S3 One Zone-Infrequent Access
C.S3 Glacier Instant Retrieval
D.S3 Standard
AnswerC

S3 Glacier Instant Retrieval is specifically designed for long-lived, infrequently accessed data that requires millisecond retrieval, making it ideal for a "large number of binary files." It offers a significantly lower per-GB storage cost than S3 Standard or S3 Standard-IA, while still providing high durability across multiple Availability Zones. This class perfectly balances cost-efficiency for infrequent access with the necessity of immediate data availability when needed.

Why this answer

S3 Glacier Instant Retrieval is the most suitable because it is designed for long-lived, infrequently accessed data that requires retrieval in milliseconds (within minutes), offering a lower storage cost than S3 Standard while still providing rapid access. The question specifies 'retrievable within minutes' and 'cost-effective,' which aligns with Glacier Instant Retrieval's sub-second retrieval times and lower storage price point compared to S3 Standard or Intelligent-Tiering for data accessed rarely.

Exam trap

The trap here is that candidates confuse 'retrievable within minutes' with the longer retrieval times of S3 Glacier Flexible Retrieval (minutes to hours) or S3 Glacier Deep Archive (hours), and overlook that S3 Glacier Instant Retrieval provides millisecond retrieval while still being cost-effective for infrequently accessed data.

How to eliminate wrong answers

Option A is wrong because S3 Intelligent-Tiering automatically moves data between access tiers based on usage patterns, but it is not the most cost-effective for data that is accessed infrequently and predictably; it incurs a monitoring and automation fee that makes it more expensive than a direct infrequent-access class for this use case. Option B is wrong because S3 One Zone-Infrequent Access stores data in a single Availability Zone, which risks data loss if that AZ fails, and the question does not specify tolerance for such risk; it is also not optimized for retrieval within minutes as it is designed for infrequent access but with the same millisecond retrieval as Standard, making it less cost-effective than Glacier Instant Retrieval for this scenario. Option D is wrong because S3 Standard is designed for frequently accessed data with low latency and high throughput, but it is the most expensive storage class and not cost-effective for infrequently accessed data, violating the cost-effectiveness requirement.

177
MCQmedium

A developer is deploying a web application on Amazon ECS with a Fargate launch type. The application needs to securely access an Amazon DynamoDB table. How should the developer grant permissions?

A.Store AWS credentials in the container image
B.Define a task role for the ECS task with DynamoDB permissions
C.Assign an IAM role to the ECS service and use it from the container
D.Use an EC2 instance profile and mount it to the container
AnswerB

Defining an IAM task role for an Amazon ECS task is the recommended and most secure method for granting AWS permissions to applications running within containers. When a task starts, it assumes this specified IAM role, which then provides temporary, frequently rotated credentials to the container's processes. This mechanism ensures that the application can securely interact with AWS services like DynamoDB without needing to store any long-lived credentials directly, adhering to the principle of least privilege and significantly enhancing security posture.

Why this answer

The developer should define a task role for the ECS task with DynamoDB permissions. In ECS with Fargate, the task role is an IAM role that containers can assume to make AWS API calls. This provides secure, temporary credentials without embedding secrets in the container image.

Exam trap

DVA-C02 often tests the distinction between task execution roles and task roles, and candidates may confuse the two or assume that EC2 instance profiles work for Fargate.

How to eliminate wrong answers

Option A is wrong because storing AWS credentials in the container image is insecure and not recommended; credentials can be exposed if the image is compromised. Option C is wrong because assigning an IAM role to the ECS service is not how containers get permissions; the service role is used by ECS itself, not by the application code. Option D is wrong because EC2 instance profiles are for EC2 instances, not for Fargate tasks; Fargate tasks do not have access to instance metadata.

178
MCQmedium

A company has an S3 bucket containing confidential data. The security team wants to ensure that the bucket is never publicly accessible, even if a bucket policy or ACL is incorrectly set to allow public access. Which S3 feature should the developer enable?

A.Enable S3 Transfer Acceleration to ensure faster uploads.
B.Enable S3 Block Public Access (bucket-level).
C.Enable S3 Server Access Logging to monitor access.
D.Enable S3 Object Lock to prevent objects from being deleted.
AnswerB

S3 Block Public Access provides an additional layer of security that prevents any public access, even if a bucket policy or ACL inadvertently allows it. It is the recommended way to ensure a bucket is never public.

Why this answer

S3 Block Public Access (bucket-level) provides a definitive override that prevents any public access to the bucket, regardless of any bucket policies or ACLs that might otherwise grant public access. This feature acts as a safety net, ensuring that even if a policy or ACL is misconfigured to allow public access, the block public access settings will deny all public requests at the S3 service level before any policy evaluation occurs.

Exam trap

The trap here is that candidates often confuse monitoring features (like logging) or object protection features (like Object Lock) with access control mechanisms, failing to recognize that S3 Block Public Access is the only feature specifically designed to enforce a hard block on public access regardless of other configurations.

How to eliminate wrong answers

Option A is wrong because S3 Transfer Acceleration is a performance feature that speeds up uploads over long distances using AWS edge locations, and it has no impact on access control or public accessibility. Option C is wrong because S3 Server Access Logging only records access requests for auditing purposes; it does not prevent public access or enforce any security restrictions. Option D is wrong because S3 Object Lock is designed to prevent objects from being deleted or overwritten for a specified retention period, but it does not control or block public read access to the bucket.

179
MCQeasy

Refer to the exhibit. An IAM policy is attached to a user. What is the effect when the user tries to upload an object to s3://example-bucket/secret/file.txt?

A.The upload fails because the Deny statement explicitly denies access to the secret/ prefix.
B.The upload fails only if the user is not the bucket owner.
C.The upload succeeds because the Deny statement does not match the specific action.
D.The upload succeeds because the Allow statement grants s3:PutObject on the bucket.
AnswerA

The IAM policy evaluation logic dictates that an explicit Deny statement always takes precedence over any Allow statement. In this scenario, the Deny statement explicitly targets resources within the `secret/` prefix of `my-bucket` using `arn:aws:s3:::my-bucket/secret/*` and applies to all S3 actions (`s3:*`). Therefore, any attempt to upload an object to this specific prefix will be explicitly denied, regardless of other Allow permissions.

Why this answer

The Deny statement in the IAM policy explicitly denies the s3:PutObject action for any object with the prefix secret/ in the example-bucket. Since the user is trying to upload to s3://example-bucket/secret/file.txt, which matches the Deny condition, the request is denied regardless of any Allow statements. AWS IAM policy evaluation is explicit deny by default, meaning a Deny always overrides an Allow.

Exam trap

The trap here is that candidates often assume an Allow statement will always grant access, forgetting that an explicit Deny in IAM policies takes precedence over any Allow, even if the Deny is more specific.

How to eliminate wrong answers

Option B is wrong because the bucket owner status is irrelevant; IAM policies are evaluated based on the attached policy, not ownership, and the Deny statement applies to all users. Option C is wrong because the Deny statement explicitly matches the s3:PutObject action (implied by 'upload an object') and the secret/ prefix, so it does match the specific action. Option D is wrong because while the Allow statement grants s3:PutObject on the bucket, the explicit Deny for the secret/ prefix overrides it, causing the upload to fail.

180
Multi-Selectmedium

A developer wants to encrypt data in an S3 bucket using server-side encryption with AWS KMS (SSE-KMS). Which TWO steps are required?

Select 2 answers
A.Set the default encryption on the bucket to SSE-KMS.
B.Enable MFA Delete on the bucket.
C.Create a bucket policy that denies unencrypted requests.
D.Grant the IAM role kms:GenerateDataKey and kms:Decrypt permissions.
E.Enable versioning on the bucket.
AnswersA, D

Setting default encryption on the S3 bucket to SSE-KMS is the direct and required control because it instructs S3 to automatically apply KMS-based encryption to every new object written to the bucket, regardless of whether the upload request includes encryption headers. This setting meets the requirement without forcing changes to the application code, and it ensures that any object uploaded without explicit encryption is still encrypted at rest.

Why this answer

Option A is correct because configuring the bucket's default encryption to SSE-KMS ensures that objects uploaded without an explicit encryption header are automatically encrypted with AWS KMS keys (aws:kms), which is the core requirement for using SSE-KMS at the bucket level. Option D is correct because any principal writing or reading SSE-KMS-encrypted objects must have kms:GenerateDataKey (to obtain a data key for encryption) and kms:Decrypt (to decrypt the data key) permissions on the relevant KMS key; without these, S3 requests fail with AccessDenied. Option B is not required because MFA Delete only protects object version deletion and does not relate to enabling SSE-KMS.

Option C is not required because a deny-unencrypted-requests bucket policy is an optional hardening measure, not a prerequisite for SSE-KMS. Option E is not required because versioning is independent of server-side encryption configuration.

Exam trap

DVA-C02 often tests the misconception that enabling SSE-KMS is purely a bucket setting, when the IAM role also needs explicit KMS permissions (GenerateDataKey and Decrypt) or uploads/downloads will fail.

181
MCQmedium

A company runs a web application on AWS Elastic Beanstalk. The application currently runs in a single environment. The developer wants to deploy a new version with zero downtime and be able to test the new version thoroughly before it receives any production traffic. Which deployment strategy should the developer use?

A.Perform a rolling deployment with a batch size of one instance at a time.
B.Use an immutable deployment to launch a new set of instances and then swap the Auto Scaling group.
C.Create a new environment (green) with the new version, run tests against it, and then swap the environment URLs so that production points to the green environment.
D.Use a rolling deployment with additional batch to launch new instances before terminating old ones.
AnswerC

This strategy describes a blue/green deployment, which is ideal for comprehensive pre-production testing. A completely new "green" Elastic Beanstalk environment is provisioned with the new application version, running in parallel to the existing "blue" production environment. This isolated green environment allows for extensive functional and performance testing without impacting live users. Once validated, a DNS CNAME swap instantly redirects all production traffic to the new green environment, ensuring zero downtime and a quick rollback option by swapping back if needed.

Why this answer

It describes a blue/green deployment strategy, which creates a separate 'green' environment with the new application version, allowing thorough testing before swapping the environment URLs (CNAME records) in Elastic Beanstalk. This ensures zero downtime because the swap is instantaneous and the original 'blue' environment remains untouched until the swap occurs.

Exam trap

The trap here is that candidates confuse immutable deployments (which replace instances but not the environment) with blue/green deployments (which replace the entire environment), leading them to choose Option B because both involve launching new instances, but only blue/green allows pre-production testing without traffic exposure.

How to eliminate wrong answers

Option A is wrong because a rolling deployment with a batch size of one instance at a time updates instances in-place, which still causes a brief period where old and new versions coexist and does not allow testing the new version before it receives production traffic. Option B is wrong because an immutable deployment launches a new set of instances and then swaps the Auto Scaling group, but it does not provide a separate environment for pre-production testing; the new instances immediately serve traffic after the swap. Option D is wrong because a rolling deployment with an additional batch launches new instances before terminating old ones, which reduces downtime but still updates the existing environment in-place and does not allow isolated testing of the new version before it receives traffic.

182
MCQhard

A company runs a production web application on EC2 instances behind an Application Load Balancer. Users report intermittent 502 errors. The developers find that the ALB access logs show 'target_response_code' of 502 for some requests. What is the MOST likely cause?

A.The EC2 instances are unable to resolve DNS for the ALB.
B.The security group for the EC2 instances is blocking traffic from the ALB.
C.The EC2 instances are closing idle connections prematurely due to a short keep-alive timeout.
D.The ALB health checks are failing and the target group has unhealthy instances.
AnswerC

When an Application Load Balancer (ALB) forwards a request to a target EC2 instance, it maintains a persistent connection using HTTP keep-alive. If the EC2 instance's web server (e.g., Apache, Nginx, or application server) has a `keep-alive_timeout` configured to be shorter than the ALB's idle timeout (default 60 seconds) or the time it takes for the ALB to send the full request or receive the full response, the instance might prematurely close the TCP connection. This abrupt closure, while the ALB is still expecting a response or attempting to send data, results in the ALB receiving an unexpected connection termination, which it translates into an HTTP 502 Bad Gateway error for the client.

Why this answer

The 502 Bad Gateway error from an Application Load Balancer indicates that the target (EC2 instance) closed the connection before the ALB could finish writing the request or reading the response. This commonly occurs when the keep-alive timeout on the EC2 instance is set too low, causing idle connections to be closed prematurely. Option A is incorrect because DNS resolution issues would not cause a 502; they would cause a 503 or connection failure.

Option B is incorrect because a security group blocking traffic would result in health check failures and a 503, not a 502. Option D is incorrect because unhealthy instances would cause a 503, not a 502.

183
MCQeasy

A developer needs to store application configuration data (key-value pairs) that can be accessed by multiple microservices running on EC2 instances. The configuration data changes infrequently but must be retrievable with low latency. Which AWS service should the developer use?

A.AWS Systems Manager Parameter Store
B.AWS AppConfig
C.Amazon S3
D.Amazon DynamoDB
AnswerA

AWS Systems Manager Parameter Store is a secure and scalable storage for configuration data and secrets. While it offers versioning and integration with other AWS services, it primarily functions as a parameter store. It lacks advanced features specifically designed for application configuration management, such as schema validation, phased deployments (e.g., canary or linear rollouts), or automatic rollback capabilities based on application health, which are crucial for safely deploying configuration changes at scale.

Why this answer

AWS Systems Manager Parameter Store is designed specifically to store configuration data (such as database strings, license codes, or general key-value pairs) and secrets. It provides a centralized, secure, and hierarchical store that can be easily accessed by EC2 instances and microservices with low latency. Standard parameters are free of charge, making it the ideal choice for infrequently changing configuration data.

Exam trap

Candidates often confuse AWS Systems Manager Parameter Store with AWS AppConfig or Secrets Manager. While AppConfig is used for dynamic configuration deployment (with features like gradual rollouts and validators), Parameter Store is the correct and standard service for simply storing and retrieving static or infrequently changing key-value configuration data.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Parameter Store is a parameter store for configuration data and secrets, but it lacks built-in features for controlled configuration deployments, validation, and local caching for low-latency retrieval; it is better suited for simple parameter storage without the deployment management capabilities of AppConfig. Option C is wrong because Amazon S3 is an object storage service that can store configuration files, but it does not provide low-latency retrieval for frequent access by microservices (due to HTTP-based access latency) and lacks native features for configuration validation, rollback, or managed deployments. Option D is wrong because Amazon DynamoDB is a NoSQL database designed for high-throughput, low-latency read/write operations on dynamic data, but it is overkill for infrequently changing configuration data and requires additional application logic for caching, validation, and deployment management, which AppConfig provides out of the box.

184
Multi-Selecthard

Which TWO actions should a developer take to securely manage database credentials in a serverless application?

Select 2 answers
A.Store credentials in AWS Secrets Manager and enable automatic rotation.
B.Use IAM database authentication for Amazon RDS.
C.Store credentials in a text file within the Lambda deployment package.
D.Hardcode credentials in environment variables.
E.Use security groups to allow only the Lambda function to access the database.
AnswersA, B

AWS Secrets Manager provides a dedicated, highly secure service for storing, retrieving, and managing sensitive information like database credentials. Enabling automatic rotation ensures that credentials are regularly updated without manual intervention, significantly reducing the risk window if a secret is compromised. This approach aligns with security best practices by centralizing secret management and automating lifecycle operations, enhancing overall application security posture.

Why this answer

Option A is correct because AWS Secrets Manager is purpose-built for storing and retrieving secrets such as database credentials, and enabling automatic rotation ensures credentials are periodically changed without manual intervention, reducing the risk of long-lived credential exposure. Option B is correct because IAM database authentication for Amazon RDS lets the Lambda function use its IAM role to generate a short-lived authentication token instead of a static password, eliminating the need to store database credentials at all. Option C is incorrect because embedding credentials in a text file inside the Lambda deployment package exposes them to anyone with access to the code artifact and provides no rotation or auditing.

Option D is incorrect because hardcoding credentials in environment variables leaves them in plaintext and visible in the Lambda configuration, and they cannot be rotated automatically. Option E is incorrect because security groups only control network-level access to the database and do not manage or protect the credentials themselves.

Exam trap

AWS often tests the distinction between network-level controls (security groups) and credential management, leading candidates to mistakenly select security groups as a method for securing credentials rather than managing them.

185
MCQhard

A developer is using AWS CodePipeline to automate a multi-stage pipeline. The pipeline includes a manual approval step before deploying to production. The developer wants to receive an email notification when the pipeline reaches the approval step. Which service should the developer use?

A.Configure CodePipeline to send an email using the 'Email' action
B.Use Amazon CloudWatch Logs to monitor the pipeline logs and trigger an alarm
C.Use Amazon Simple Email Service (SES) to send an email from the pipeline
D.Use Amazon CloudWatch Events to detect the pipeline state change and trigger an SNS notification
AnswerD

Amazon CloudWatch Events (now EventBridge) provides a robust mechanism for monitoring and reacting to state changes across AWS services, including CodePipeline. CodePipeline emits events for various execution states, such as pipeline execution, stage execution, and action execution. A CloudWatch Event rule can be configured to specifically detect a CodePipeline stage entering a `WAITING_FOR_APPROVAL` state, and then trigger an Amazon SNS topic to send immediate notifications to subscribed users or systems. This approach leverages the native eventing capabilities of AWS services for efficient, real-time communication.

Why this answer

CloudWatch Events (now part of Amazon EventBridge) can detect pipeline state changes such as a manual approval step entering a 'waiting' state. You can create a rule that matches this event and targets an Amazon SNS topic to send an email notification. Option A is incorrect because CodePipeline does not have an 'Email' action built-in.

Option B is incorrect because CloudWatch Logs is used for monitoring log data, not for triggering notifications directly. Option C is incorrect because while Amazon SES can send emails, it is not directly integrated with CodePipeline; the recommended approach is to use CloudWatch Events with SNS for notifications.

186
MCQhard

A company is using AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment fails with 'The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available for deployment, or some instances in your deployment group are experiencing problems.' The developer wants to identify the specific error on a failed instance. Which AWS CLI command should the developer use?

A.aws deploy get-deployment
B.aws deploy get-deployment-instance
C.aws deploy list-deployments
D.aws deploy list-deployment-instances
AnswerB

This command is specifically designed to retrieve comprehensive details for a single target instance within a CodeDeploy deployment. It provides the instance's lifecycle event status (e.g., BeforeInstall, Install, ApplicationStop), any associated error messages, and the instance's overall status within that deployment. This granular information is crucial for diagnosing why a deployment failed on a particular instance, offering insights into specific script failures or configuration issues.

Why this answer

The `aws deploy get-deployment-instance` command retrieves detailed information about a single instance in a deployment group, including the specific error messages and lifecycle event logs that caused the instance to fail. This allows the developer to diagnose the root cause of the failure on a particular instance, which is exactly what is needed when the overall deployment fails with a generic error message.

Exam trap

The trap here is that candidates often confuse `list-deployment-instances` (which only returns instance IDs) with `get-deployment-instance` (which returns detailed error data), leading them to choose the list command when they actually need the detailed diagnostic output.

How to eliminate wrong answers

Option A is wrong because `aws deploy get-deployment` returns high-level deployment summary information (status, total instances, error count) but does not provide per-instance error details or lifecycle event logs. Option C is wrong because `aws deploy list-deployments` only lists deployment IDs and basic metadata (e.g., application name, creation time) for a given application or deployment group, not instance-level failure information. Option D is wrong because `aws deploy list-deployment-instances` returns a list of instance IDs associated with a deployment, but does not include the detailed error messages or lifecycle event logs needed to identify the specific error on a failed instance.

187
MCQeasy

A developer is writing an AWS Lambda function in Python that needs to download a file from Amazon S3, process it, and upload the result to a different S3 bucket. The function currently runs within the default 3-second timeout, but the developer expects the file size to increase. What is the MOST cost-effective way to handle the increase in processing time?

A.Increase the Lambda function's timeout to a value higher than the expected processing time.
B.Increase the Lambda function's timeout to 15 minutes.
C.Use Lambda provisioned concurrency to keep the function warm.
D.Refactor the code to use AWS Step Functions to orchestrate the processing.
AnswerA

AWS Lambda functions have a configurable timeout setting, which defines the maximum duration a function can execute before being terminated. By increasing this timeout to a value exceeding the anticipated processing time, the developer directly resolves the issue of the function being prematurely terminated. This is the most straightforward and cost-effective approach for a single Lambda function needing more execution time, without introducing additional architectural complexity.

Why this answer

Increasing the Lambda function's timeout is the most cost-effective solution because it directly addresses the expected increase in processing time without incurring additional costs. Lambda pricing is based on the number of invocations and duration (in GB-seconds), so extending the timeout only charges for the actual time the function runs, not for idle time or additional services. This approach avoids the complexity and cost of Step Functions or provisioned concurrency, which would add unnecessary overhead for a simple sequential task.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing Step Functions or provisioned concurrency, thinking they are needed for long-running tasks, when the simplest and most cost-effective fix is merely adjusting the Lambda timeout.

How to eliminate wrong answers

Option B is wrong because increasing the timeout to 15 minutes is excessive and may exceed the Lambda maximum execution timeout of 15 minutes, but more importantly, it does not address cost-effectiveness—it simply sets a maximum limit without considering the actual processing time. Option C is wrong because provisioned concurrency is designed to reduce cold start latency for latency-sensitive applications, not to handle longer processing times, and it incurs additional costs for keeping functions initialized. Option D is wrong because refactoring to use AWS Step Functions introduces unnecessary complexity and cost for a simple download-process-upload workflow; Step Functions are better suited for orchestrating multiple independent tasks or handling retries and error handling across services, not for extending a single function's execution time.

188
MCQmedium

Refer to the exhibit. A developer ran this CLI command and received the output shown. The application is retrieving the secret but getting an authentication error from the database. What is the MOST likely issue?

A.The secret is not marked as AWSCURRENT.
B.The application is not correctly parsing the JSON SecretString.
C.The CLI command should have used the --secret-string parameter.
D.The secret ID is incorrect.
AnswerB

AWS Secrets Manager typically stores credentials as a JSON string within the `SecretString` field, containing key-value pairs like `{"username":"user", "password":"p@ss"}`. Applications must correctly parse this JSON to extract individual components, such as the password. If the application fails to properly deserialize the JSON or handle special characters within the password value, it might attempt to use the entire unparsed string or an incorrect substring, leading to authentication failures.

Why this answer

The CLI command successfully retrieved the secret, as shown by the output containing the secret value. The application, however, is failing with an authentication error from the database. This indicates that the secret was retrieved but the application is likely misinterpreting the JSON structure of the SecretString.

If the secret is stored as a JSON object (e.g., containing username and password fields), the application must parse the JSON and extract the correct field (e.g., 'password'). If it treats the entire JSON string as the password, it will pass an invalid credential to the database, causing an authentication error.

Exam trap

The trap here is that candidates assume any retrieval error is due to an incorrect secret ID or missing label, but the question explicitly states the secret was retrieved successfully, shifting the issue to how the application processes the retrieved value.

How to eliminate wrong answers

Option A is wrong because the secret is successfully retrieved, and the AWSCURRENT label is automatically applied to the latest version of a secret; if it were missing, the retrieval would fail entirely, not cause a parsing issue. Option C is wrong because the CLI command used 'get-secret-value' which is the correct command to retrieve a secret; the '--secret-string' parameter is used when creating or updating a secret, not when retrieving it. Option D is wrong because the secret ID is correct—the command returned a valid secret value without an error, proving the ID was accurate.

189
MCQhard

A company uses Amazon API Gateway with a Lambda authorizer to control access to its APIs. The Lambda authorizer returns an IAM policy that grants access to the API. Recently, the company noticed that some API calls are being throttled due to high latency from the authorizer. What is the MOST effective way to reduce latency?

A.Enable caching for the Lambda authorizer responses.
B.Use a custom authorizer instead of a Lambda authorizer.
C.Reduce the TTL of the authorizer cache.
D.Increase the memory allocated to the Lambda authorizer function.
AnswerA

Enabling caching for Lambda authorizer responses significantly optimizes API Gateway performance and cost. Once an authorizer successfully authenticates a request and returns a policy, API Gateway stores this decision for a configurable duration. Subsequent requests with the same identity source within the cache's Time-To-Live (TTL) period will bypass the Lambda authorizer invocation entirely, drastically reducing latency and Lambda execution costs.

Why this answer

Enabling caching for the Lambda authorizer responses allows API Gateway to reuse the IAM policy returned by the authorizer for subsequent requests that match the same cache key, without invoking the Lambda function again. This eliminates the latency of the authorizer invocation on cache hits, directly addressing the throttling caused by high authorizer latency.

Exam trap

The trap here is that candidates may assume increasing Lambda memory (Option D) is the universal fix for Lambda performance issues, but in this context the latency stems from the invocation overhead and network round-trip, not from CPU-bound processing, making caching the more effective solution.

How to eliminate wrong answers

Option B is wrong because 'custom authorizer' is an ambiguous term; in API Gateway, a Lambda authorizer is already a type of custom authorizer, and switching to a different implementation (e.g., a Cognito user pool authorizer) would not necessarily reduce latency and may not support the required IAM policy-based access control. Option C is wrong because reducing the TTL of the authorizer cache would cause the cache to expire more frequently, increasing the number of Lambda invocations and potentially worsening latency and throttling. Option D is wrong because while increasing Lambda memory can reduce execution time for compute-intensive tasks, the primary bottleneck here is the invocation overhead and network round-trip, not CPU-bound processing; caching addresses the root cause more effectively.

190
MCQeasy

An organization wants to deploy a microservices architecture using AWS Lambda functions. They need to manage environment variables for each function across different stages (dev, test, prod). Which approach is the MOST secure and maintainable?

A.Use AWS Systems Manager Parameter Store with separate paths for each stage.
B.Use AWS CloudFormation parameters to pass values at deployment.
C.Hardcode the environment variables in each Lambda function code.
D.Store environment variables in the Lambda function configuration.
AnswerA

AWS Systems Manager Parameter Store supports hierarchical paths such as /myapp/dev/db_url and /myapp/prod/db_url, enabling a single Lambda function to retrieve stage-specific configuration at runtime via GetParameter. This keeps configuration external to code, can be secured with IAM policies and KMS encryption for SecureString parameters, and supports versioning and change history. It is the correct approach because it is centralized, stage-aware, and directly accessible from Lambda without redeploying infrastructure.

Why this answer

AWS Systems Manager Parameter Store allows you to store configuration data and secrets as parameters with hierarchical paths (e.g., /myapp/dev/db-url, /myapp/prod/db-url). This centralizes management, supports versioning, and enables fine-grained IAM access control per stage. Lambda functions can retrieve these parameters at runtime, ensuring that sensitive values are not exposed in code or function configuration.

This approach is both secure (encryption via KMS, audit via CloudTrail) and maintainable (update once, applies everywhere).

Exam trap

DVA-C02 often tests the misconception that Lambda environment variables are secure enough for secrets, but they are stored in plaintext and lack centralized management; candidates must recognize that Parameter Store (or Secrets Manager) is the preferred secure and maintainable solution for cross-stage configuration.

How to eliminate wrong answers

Option B is wrong because CloudFormation parameters are resolved at deployment time and become part of the stack, making it difficult to update values without redeploying; they also lack built-in encryption and fine-grained access control for secrets. Option C is wrong because hardcoding environment variables in code is a severe security risk (secrets in source control) and violates the principle of least privilege; it also makes changes require code redeployment. Option D is wrong because Lambda environment variables are stored in plaintext (though can be encrypted with KMS) and are limited to 4 KB total; they are not centrally managed across stages and require updating each function individually, which is not maintainable for microservices.

191
MCQeasy

A team uses AWS CodePipeline to automate deployments. They notice that a deployment to Amazon ECS fails because the task definition is not updated. The pipeline includes a source stage from CodeCommit, a build stage using AWS CodeBuild, and a deploy stage to Amazon ECS. What is the most likely missing step?

A.The pipeline has a manual approval step before deployment.
B.The deploy stage action is set to 'Create a new ECS service'.
C.The task definition is not registered in the Amazon ECS console.
D.The build stage does not output the updated task definition as an artifact.
AnswerD

The build stage in AWS CodePipeline is responsible for compiling code, building container images, and crucially, generating output artifacts that subsequent stages will consume. For an Amazon ECS deployment, this often includes an updated task definition JSON file (referencing the new container image) or an `imageDetails.json` file. If the build stage fails to correctly output this updated task definition as a designated artifact, the deploy stage will not receive the necessary information to deploy the latest application version. Consequently, the deploy stage might either fail due to missing input or, more subtly, proceed by using an older, cached, or default task definition, resulting in the application not reflecting the most recent code changes.

Why this answer

In a CodePipeline that deploys to Amazon ECS, the build stage must output the updated task definition file (typically `imagedefinitions.json` or a task definition JSON) as an artifact. Without this artifact, the deploy stage cannot reference the new task definition revision, so it continues using the old one, causing the deployment to fail.

Exam trap

The trap here is that candidates assume the task definition is automatically updated by the deploy action or that manual registration in the ECS console is required, when in fact the build stage must explicitly output the updated definition as an artifact for the pipeline to use.

How to eliminate wrong answers

Option A is wrong because a manual approval step would pause the pipeline but not affect whether the task definition is updated; it does not cause the deployment to fail due to an outdated task definition. Option B is wrong because setting the deploy stage action to 'Create a new ECS service' would create a new service instead of updating the existing one, which is not the missing step for updating the task definition. Option C is wrong because the task definition does not need to be manually registered in the ECS console; the pipeline should register it automatically via the deploy action, and the issue is that the updated definition is not passed as an artifact.

192
MCQmedium

A company wants to enforce multi-factor authentication (MFA) for all users accessing the AWS Management Console. The company has an existing IAM setup with users and groups. Which approach should the developer recommend to enforce MFA?

A.Enable MFA at the account level using the AWS Account settings.
B.Attach an IAM policy to each user that denies all actions unless the user has MFA present.
C.Enable MFA on the root user and require all users to use the root user credentials with MFA.
D.Create a new IAM group for MFA users and add users to that group.
AnswerB

This is the correct and recommended method for enforcing MFA. An IAM policy can include a Condition element, such as "aws:MultiFactorAuthPresent": "true", within a Deny statement for all actions ("Action": "*", "Resource": "*") or within an Allow statement that only permits actions if MFA is present. This policy, when attached to users or groups, effectively prevents them from performing any AWS actions unless they authenticate with MFA, thereby enforcing its use across the account.

Why this answer

It uses an IAM policy with a condition key (`aws:MultiFactorAuthPresent`) to deny all actions when MFA is not present. This is the standard AWS-recommended approach to enforce MFA for IAM users accessing the Management Console, as it applies a deny-all-except-MFA effect at the user level without requiring account-level changes.

Exam trap

The trap here is that candidates assume MFA can be enforced at the account level (Option A) or by simply adding users to a group (Option D), but AWS requires an explicit IAM policy with a condition key to deny unauthenticated MFA actions.

How to eliminate wrong answers

Option A is wrong because AWS does not support enabling MFA at the account level for all users; MFA must be configured per IAM user or via a policy. Option C is wrong because sharing root user credentials violates security best practices and AWS prohibits using root user for everyday tasks; MFA on root does not enforce MFA for other IAM users. Option D is wrong because simply creating a group and adding users does not enforce MFA; a policy with a condition key must be attached to the group to deny actions without MFA.

193
MCQeasy

A company uses AWS CodeCommit and wants to automatically trigger a build in AWS CodePipeline when code is pushed to the master branch. Which action should be taken?

A.Configure a CloudWatch Events rule to start the pipeline on repository changes
B.Add a webhook in CodeCommit to directly invoke CodePipeline
C.Set up a scheduled pipeline that polls CodeCommit every minute
D.Use an S3 trigger to start the pipeline when code is uploaded
AnswerA

CloudWatch Events (now Amazon EventBridge) is the standard and most efficient mechanism for integrating AWS CodeCommit with AWS CodePipeline. CodeCommit automatically publishes events, such as ReferenceUpdated for code pushes, to CloudWatch Events. A rule can then be configured to filter these specific events from the CodeCommit repository and branch, triggering a CodePipeline execution as its target. This creates a real-time, event-driven CI/CD workflow.

Why this answer

AWS CodePipeline can be configured to automatically start when changes are pushed to a CodeCommit repository by using an Amazon CloudWatch Events rule. The rule listens for CodeCommit repository state changes (e.g., 'ReferenceCreated' or 'ReferenceUpdated' events on the master branch) and targets the pipeline as a CloudWatch Events target, triggering the pipeline execution without polling or manual intervention.

Exam trap

The trap here is that candidates often confuse CodeCommit's integration with webhooks (which work with external Git providers) and assume CodeCommit supports them natively, or they overcomplicate the solution by suggesting polling or S3 triggers instead of using the native CloudWatch Events integration.

How to eliminate wrong answers

Option B is wrong because CodeCommit does not support webhooks to directly invoke CodePipeline; webhooks are used with third-party Git providers like GitHub or Bitbucket, not with CodeCommit. Option C is wrong because scheduling a pipeline to poll every minute is inefficient and not a native integration; CodePipeline does not natively poll CodeCommit at a fixed interval, and CloudWatch Events provides a real-time, event-driven approach. Option D is wrong because an S3 trigger is used for S3 bucket events, not for CodeCommit repository changes; CodeCommit events are not published to S3, and this approach would require unnecessary intermediate steps.

194
MCQmedium

A developer is building a serverless application using AWS SAM that includes an API Gateway REST API and a Lambda function. The developer wants to pass environment variables to the Lambda function based on the deployment stage (dev/prod). The stage name is provided as a SAM parameter. How should the developer define this in the SAM template?

A.Define a SAM Parameter for the stage name, and reference it in the Lambda function's Environment property
B.Use the Globals section of the SAM template to set environment variables
C.Hard-code the environment variables with different values in the template
D.Use an AWS Systems Manager Parameter Store parameter and reference it in the function
AnswerA

Defining a SAM Parameter for the stage name is the correct and recommended approach. This allows the stage name to be passed as an input during the `sam deploy` command, which then populates a CloudFormation parameter. The Lambda function's `Environment.Variables` property can then reference this parameter using `!Ref` or `Fn::Sub`, dynamically injecting the correct stage name into the function's runtime environment based on the deployment target.

Why this answer

AWS SAM allows you to define parameters (e.g., StageName) and reference them directly in the Lambda function's Environment property using CloudFormation intrinsic functions like !Ref. This enables dynamic injection of environment variables based on the deployment stage without modifying the template structure, aligning with Infrastructure as Code best practices for multi-environment deployments.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing Parameter Store (Option D) for dynamic values, missing that SAM parameters are the simplest native mechanism for stage-specific environment variables without external service dependencies.

How to eliminate wrong answers

Option B is wrong because the Globals section sets default values for all functions in the template, but it cannot dynamically vary environment variables per deployment stage without additional logic like conditions or parameters, making it unsuitable for stage-specific values. Option C is wrong because hard-coding environment variables for each stage would require maintaining separate templates or manual edits, violating the principle of reusable, parameterized templates and increasing error risk. Option D is wrong because while AWS Systems Manager Parameter Store can store values, referencing it directly in the function does not inherently tie the value to the SAM deployment stage; you would still need a parameter or mapping to select the correct Parameter Store path per stage, making Option A more straightforward.

195
MCQmedium

A company is using AWS Lambda functions behind an Amazon API Gateway REST API. Users report intermittent 503 errors. The Lambda function code appears correct. Which action is MOST likely to resolve the issue?

A.Increase the Lambda function memory allocation.
B.Increase the Lambda function timeout.
C.Request a service quota increase for Lambda concurrent executions.
D.Increase the API Gateway throttling limits.
AnswerC

A 503 Service Unavailable error from Lambda indicates that the service is currently unable to handle the request, most commonly because the account's or function's concurrent execution quota has been reached. Each AWS account has a default regional concurrency limit for Lambda functions, and exceeding this limit causes subsequent invocation attempts to be throttled. Requesting a service quota increase directly addresses this bottleneck, allowing more Lambda instances to run in parallel and process incoming API Gateway requests.

Why this answer

Intermittent 503 errors from API Gateway often indicate that Lambda concurrent execution limits have been reached. When the number of simultaneous invocations exceeds the account-level or function-level reserved concurrency, API Gateway returns a 503 'Service Unavailable' response. Increasing the Lambda concurrent executions quota allows more invocations to be processed without throttling.

Exam trap

The trap here is that candidates confuse API Gateway throttling limits (which return 429 errors) with Lambda concurrency limits (which return 503 errors), leading them to incorrectly choose option D.

How to eliminate wrong answers

Option A is wrong because increasing memory allocation improves CPU performance and execution speed, but does not resolve throttling due to concurrency limits. Option B is wrong because increasing the timeout only allows the function to run longer, but does not prevent new invocations from being rejected when concurrency is exhausted. Option D is wrong because API Gateway throttling limits (e.g., 10,000 requests per second by default) are typically much higher than Lambda concurrency limits, and the 503 error is caused by Lambda throttling, not API Gateway throttling.

196
MCQmedium

A company is using AWS CodePipeline to automate the deployment of a microservices application to Amazon ECS. The pipeline has the following stages: Source (GitHub), Build (CodeBuild), Deploy (ECS). The Deploy stage uses an ECS task definition and updates the service. Recently, the pipeline failed at the Deploy stage with the error: 'The task definition family is inactive.' The developer checks the ECS console and sees that the task definition family exists but is inactive. The developer also notices that the pipeline uses a parameter 'TASK_DEFINITION_FAMILY' with the value 'my-app'. What is the most likely cause?

A.The task definition family 'my-app' does not exist in the ECS cluster.
B.The environment variables in the task definition are not correctly set.
C.The IAM role for ECS does not have permission to register new task definitions.
D.The pipeline is referencing the task definition family name without a specific revision number, and the latest revision is inactive.
AnswerD

When a pipeline references only the task definition family name (e.g., 'my-app') without pinning a revision number, ECS resolves it to the family's most recent revision; if that latest revision was deregistered and marked inactive, for example after a manual cleanup or rollback, the deploy action fails with exactly this 'family is inactive' error, so the fix is to reference an active revision explicitly or re-register one.

Why this answer

The error 'The task definition family is inactive' indicates that the pipeline is using the task definition family name 'my-app' without specifying a revision number. When a task definition family is marked as inactive, it means the latest revision in that family is inactive. CodePipeline requires a specific active revision number to deploy successfully.

Therefore, the most likely cause is that the pipeline is referencing only the family name, and the latest revision is inactive. Option D correctly identifies this issue. Option A is incorrect because the family exists.

Option B is incorrect because environment variables are unrelated to the error. Option C is incorrect because the pipeline's IAM role permissions are not the issue; the error is about the task definition state, not permissions.

197
MCQeasy

A developer needs to enforce encryption in transit for all traffic between an application and an RDS database. Which configuration should be used?

A.Configure the security group to only allow traffic on port 443.
B.Create a VPC peering connection between the application and database subnets.
C.Enable encryption at rest using AWS KMS.
D.Set the 'require_secure_transport' parameter to 'ON' in the DB parameter group.
AnswerD

Setting the 'require_secure_transport' parameter to 'ON' within the RDS DB parameter group is the correct method to enforce encryption in transit. This parameter, available for databases like MySQL and PostgreSQL, configures the database server to reject any client connection attempts that do not utilize SSL/TLS. By doing so, it ensures that all successful connections to the RDS instance are encrypted, protecting data as it travels over the network between the application and the database.

Why this answer

Setting the 'require_secure_transport' parameter to 'ON' in the DB parameter group enforces TLS/SSL encryption for all connections to the RDS database. This ensures that data in transit between the application and the database is encrypted, meeting the requirement for encryption in transit.

Exam trap

The trap here is that candidates often confuse encryption at rest (Option C) with encryption in transit, or assume that network-level controls like security groups (Option A) or VPC peering (Option B) inherently encrypt traffic, when they do not.

How to eliminate wrong answers

Option A is wrong because port 443 is used for HTTPS traffic, not for native database connections (e.g., MySQL uses port 3306, PostgreSQL uses 5432), and security groups do not enforce encryption—they only control network access. Option B is wrong because VPC peering connects networks but does not provide encryption for traffic; it only facilitates routing between VPCs without encrypting the data in transit. Option C is wrong because encryption at rest using AWS KMS protects data stored on disk, not data transmitted between the application and the database; it addresses a different security concern.

198
MCQeasy

A company wants to enforce that all uploads to an Amazon S3 bucket must be encrypted using server-side encryption with a specific AWS KMS customer managed key (CMK). The developer needs to write an IAM policy condition that denies any s3:PutObject request that does not use the specified KMS key. Which IAM condition key should be used?

A.s3:x-amz-server-side-encryption
B.kms:EncryptionContext
C.s3:x-amz-server-side-encryption-aws-kms-key-id
D.kms:KeyArn
AnswerC

This is the correct condition key to enforce the use of a specific AWS KMS customer master key (CMK) for server-side encryption on S3 uploads. It directly evaluates the value provided in the x-amz-server-side-encryption-aws-kms-key-id request header during a PutObject operation. By specifying a particular KMS key ARN with this condition, an S3 bucket policy can deny any upload requests that do not include or match the designated CMK.

Why this answer

The `s3:x-amz-server-side-encryption-aws-kms-key-id` condition key allows you to enforce that a specific AWS KMS customer managed key (CMK) ARN is used for server-side encryption on S3 PutObject requests. By using this condition key in a Deny statement, you can reject any upload that does not specify the required KMS key ID, ensuring encryption compliance.

Exam trap

The trap here is that candidates confuse the condition key for enforcing encryption type (Option A) with the condition key for enforcing a specific KMS key ID (Option C), or mistakenly think that a KMS-specific condition key like `kms:KeyArn` can be used in an S3 policy, when in fact it only applies to KMS API calls.

How to eliminate wrong answers

Option A is wrong because `s3:x-amz-server-side-encryption` only checks whether the `x-amz-server-side-encryption` header is set to `AES256` or `aws:kms`, but it cannot enforce a specific KMS key ID. Option B is wrong because `kms:EncryptionContext` is used to control access based on encryption context in KMS operations, not to enforce which KMS key is used for S3 server-side encryption. Option D is wrong because `kms:KeyArn` is a condition key for KMS API actions (like `kms:Decrypt` or `kms:GenerateDataKey`), not for S3 PutObject requests, and it cannot be used directly in an S3 bucket policy to enforce encryption key selection.

199
MCQhard

A developer is using AWS X-Ray to trace a serverless application. The application uses an AWS Lambda function to query a DynamoDB table. The trace shows that the DynamoDB subsegment takes a significant portion of the total response time. The developer wants to reduce the DynamoDB query latency. Which service should the developer integrate with the Lambda function to achieve the lowest latency for repeated read queries?

A.DynamoDB Accelerator (DAX)
B.Amazon ElastiCache for Redis
C.DynamoDB Global Tables
D.DynamoDB Streams
AnswerA

DynamoDB Accelerator (DAX) is a fully managed, in-memory cache specifically designed to sit in front of DynamoDB tables. It provides microsecond response times for read-heavy workloads by caching frequently accessed data, significantly improving performance for serverless applications. DAX is API-compatible with DynamoDB, requiring minimal application code changes to integrate and benefit from its high-performance caching capabilities, making it ideal for reducing read latency.

Why this answer

DynamoDB Accelerator (DAX) is a fully managed, highly available, in-memory cache for DynamoDB that delivers up to 10x read performance improvement by reducing response times from milliseconds to microseconds for repeated read queries. By integrating DAX with the Lambda function, the developer can cache the results of frequent DynamoDB queries directly in memory, bypassing the read capacity units and the underlying storage engine, which directly addresses the latency bottleneck shown in the X-Ray trace.

Exam trap

The trap here is that candidates often choose ElastiCache for Redis because it is a well-known caching solution, but they overlook that DAX is purpose-built for DynamoDB and provides lower latency with zero application-level cache management, making it the correct choice for reducing DynamoDB query latency in a serverless application.

How to eliminate wrong answers

Option B (Amazon ElastiCache for Redis) is wrong because it is a general-purpose caching solution that requires the developer to manually manage cache invalidation, data synchronization, and application-level logic to keep the cache consistent with DynamoDB, adding complexity and potential latency overhead compared to DAX's native DynamoDB integration. Option C (DynamoDB Global Tables) is wrong because it is designed for multi-region replication and disaster recovery, not for reducing read latency within a single region; it actually increases write latency due to cross-region replication and does not cache repeated read queries. Option D (DynamoDB Streams) is wrong because it captures a time-ordered sequence of item-level changes in a DynamoDB table for event-driven processing (e.g., triggering Lambda functions), but it does not provide any caching or read acceleration functionality.

200
Multi-Selecthard

Which THREE are valid methods to authenticate to AWS APIs? (Choose 3)

Select 3 answers
A.Temporary security credentials from AWS STS
B.Database password stored in Secrets Manager
C.Credentials from an EC2 instance profile
D.CloudFront key pair
E.IAM user access key ID and secret access key
AnswersA, C, E

Temporary security credentials from AWS STS are a valid authentication method because they provide short-lived access keys plus a session token that are used with Signature Version 4 to sign AWS API calls. These credentials are obtained by calling AssumeRole, GetFederationToken, or related STS APIs, and they are ideal for federated users, cross-account roles, and scenarios requiring limited-time access. The session token is mandatory when signing requests with these credentials.

Why this answer

Option A is correct because AWS STS issues temporary security credentials (access key ID, secret access key, and session token) via APIs like AssumeRole, GetSessionToken, or GetFederationToken, and these credentials are accepted by AWS APIs for signing requests with SigV4. Option C is correct because an EC2 instance profile delivers temporary IAM role credentials to the instance through the Instance Metadata Service (IMDS), which the AWS SDK and CLI automatically use to sign API calls. Option E is correct because a long-term IAM user access key ID and secret access key are the classic SigV4 signing credentials used to authenticate programmatic requests to AWS APIs.

Option B is not a valid AWS API authentication method because a database password in Secrets Manager is a secret for connecting to a database, not an AWS credential, even though Secrets Manager itself is accessed using AWS credentials. Option D is not valid because a CloudFront key pair is used to create signed URLs or signed cookies for private content distribution, not to authenticate requests to AWS service APIs.

Exam trap

DVA-C02 often tests the difference between AWS API authentication and other service-specific credentials; candidates may incorrectly select CloudFront key pairs or database passwords because they are AWS-related, but they do not authenticate to AWS APIs.

201
MCQmedium

A developer is building a serverless application using AWS Lambda to process events from an Amazon SQS queue. The Lambda function is CPU-bound and currently experiences timeouts. What is the MOST cost-effective way to reduce execution time?

A.Increase the SQS batch window size
B.Switch the Lambda runtime from Python to Node.js
C.Increase the Lambda function's memory allocation
D.Enable Provisioned Concurrency for the function
AnswerC

Increasing a Lambda function's memory allocation is the most direct and effective way to improve performance for CPU-bound tasks. AWS Lambda provisions CPU power proportionally to the configured memory. Therefore, allocating more memory provides the function with a larger share of CPU resources, enabling it to complete computationally intensive operations faster and reduce overall execution time.

Why this answer

Increasing the Lambda function's memory allocation is the most cost-effective way to reduce execution time for a CPU-bound function because Lambda allocates CPU proportionally to memory. More memory means more vCPU capacity, which directly speeds up CPU-bound processing. This reduces the function's duration, and since Lambda billing is based on compute time (GB-seconds), the total cost can decrease even if the per-GB-second rate is higher.

Exam trap

The trap here is that candidates assume increasing memory only helps memory-bound workloads, but AWS Lambda's CPU allocation scales with memory, making it the primary lever for CPU-bound performance improvements.

How to eliminate wrong answers

Option A is wrong because increasing the SQS batch window size only delays event retrieval, it does not reduce the Lambda function's execution time or address CPU-bound timeouts. Option B is wrong because switching the runtime from Python to Node.js does not guarantee a performance improvement for CPU-bound tasks; the bottleneck is CPU capacity, not language overhead, and this change introduces migration risk without a cost-effective guarantee. Option D is wrong because Provisioned Concurrency keeps functions initialized and ready to handle bursts of traffic, but it does not reduce the execution time of a single invocation; it adds cost for pre-warmed instances without addressing the CPU-bound timeout issue.

202
Multi-Selecteasy

Which THREE factors should a developer consider when choosing between a blue/green deployment and a rolling deployment for an Amazon ECS service?

Select 3 answers
A.Rolling deployments require manual intervention to rollback
B.Rolling deployments update a subset of tasks at a time, which may cause slower rollback
C.Blue/green deployments are always cheaper than rolling deployments
D.Blue/green deployments require running two versions of the application simultaneously
E.Blue/green deployments provide instant rollback by switching traffic back to the old environment
AnswersB, D, E

Rolling deployments operate by gradually replacing a small subset of old application instances with new ones until all are updated. This phased approach means that if a critical issue is discovered, the rollback process must also proceed in stages, replacing the faulty new instances with the previous stable version across the entire fleet. Consequently, the time required to fully revert to a stable state can be considerably longer compared to other strategies, making this a valid consideration.

Why this answer

Rolling deployments in Amazon ECS update a subset of tasks at a time, which means if a rollback is needed, the deployment must reverse the updates incrementally, potentially taking longer than a blue/green deployment where traffic can be switched back instantly. This slower rollback is a key trade-off when choosing between the two strategies.

Exam trap

The trap here is that candidates may assume rolling deployments always require manual rollback (Option A) when in fact ECS supports automatic rollback via the service's 'deployment circuit breaker' feature, and they may overlook the cost implications of running dual environments in blue/green deployments (Option C).

203
MCQmedium

A development team is using AWS CodeBuild to compile and test their code. They want to store build artifacts in an Amazon S3 bucket. The buildspec.yml file includes an artifacts section. Which configuration correctly specifies the output artifacts?

A.artifacts: files: - '**/*' discard-paths: no
B.artifacts: base-directory: 'build' files: '**/*'
C.artifacts: file: '**/*' discard-paths: no
D.artifacts: path: '**/*' discard-paths: false
AnswerA

This configuration correctly specifies that all files and directories from the build output directory should be included as artifacts. The `files` key expects a YAML list of glob patterns, where `**/*` matches everything recursively from the `base-directory` (or root of the build output if not specified). Setting `discard-paths: no` ensures that the original directory structure of the collected files is preserved within the generated artifact archive, which is crucial for maintaining file organization during deployments.

Why this answer

It uses the correct `files` key with a glob pattern `'**/*'` to include all files, and `discard-paths: no` preserves the directory structure in the S3 bucket. In CodeBuild, the `artifacts` section requires `files` (not `file` or `path`) to specify which files to output, and `discard-paths` controls whether the relative path is kept.

Exam trap

The trap here is confusing the `files` key (plural, required) with `file` (singular, invalid) or `path` (used in other AWS services like CodePipeline), leading candidates to select options with incorrect key names.

How to eliminate wrong answers

Option B is wrong because `files` must be a list (e.g., `['**/*']`), not a string `'**/*'`; CodeBuild expects a sequence of file patterns, and a single string will cause a validation error. Option C is wrong because it uses `file:` instead of `files:`; the correct key is `files` (plural), and `file` is not a valid artifact configuration key. Option D is wrong because it uses `path:` instead of `files:`; `path` is not a valid key in the artifacts section—the correct key is `files` to define the file patterns to include.

204
MCQhard

A developer is building a serverless application using AWS Lambda and Amazon API Gateway. The developer wants to enable caching for API responses to reduce latency and cost. Which step is REQUIRED to enable caching?

A.Enable caching in the Lambda function code
B.Set the TTL in the API Gateway method request integration
C.Create a cache cluster in API Gateway for the stage
D.Use Amazon ElastiCache and modify the Lambda function to check cache
AnswerC

This is the correct approach for reducing latency by caching API responses directly within API Gateway. To enable caching, a cache cluster must be provisioned and associated with a specific API Gateway stage, where you define its capacity (e.g., 0.5 GB to 237 GB) and the default Time-To-Live (TTL) for cached responses. Once enabled, API Gateway intercepts requests, serves cached responses if available and valid, and only invokes the backend Lambda function when a cache miss occurs or the cache entry expires.

Why this answer

API Gateway caching requires a dedicated cache cluster to be enabled and configured at the stage level. This cluster stores API responses and serves them directly from the cache for identical requests, reducing the number of calls to the backend Lambda function and lowering latency. Without creating and enabling this cache cluster in the API Gateway stage settings, caching cannot function.

Exam trap

The trap here is that candidates often confuse API Gateway's built-in caching with external caching solutions like ElastiCache or assume that caching can be enabled solely by modifying Lambda code or integration settings, when in fact a dedicated cache cluster must be explicitly created and enabled at the API Gateway stage level.

How to eliminate wrong answers

Option A is wrong because caching is not implemented within the Lambda function code; Lambda functions are stateless and do not natively cache API responses. Option B is wrong because the TTL (time-to-live) for API Gateway caching is configured in the stage settings or per-method cache settings, not in the method request integration. Option D is wrong because while Amazon ElastiCache could be used for custom caching logic, it is not a required step for enabling API Gateway's built-in caching; the question asks for the required step to enable caching in API Gateway, which is to create a cache cluster in API Gateway for the stage.

205
MCQeasy

A developer is building a serverless application using AWS Lambda and Amazon DynamoDB. The Lambda function needs to read and write items to a DynamoDB table. What is the BEST way to securely provide the Lambda function with the necessary AWS credentials?

A.Store the AWS access key and secret key in the Lambda environment variables.
B.Create an IAM role with DynamoDB permissions and attach it to the Lambda function.
C.Create an IAM user with programmatic access and store the credentials in the Lambda code.
D.Use the Lambda function's default full admin access provided by AWS.
AnswerB

Creating an IAM role with specific DynamoDB permissions and attaching it to the Lambda function is the AWS-recommended and most secure approach. When the Lambda function executes, it automatically assumes this IAM role, which provides temporary, short-lived credentials to interact with DynamoDB. This method adheres to the principle of least privilege by granting only necessary permissions and eliminates the need to manage static credentials within the function code or configuration, significantly enhancing security.

Why this answer

The best practice for granting AWS Lambda functions access to DynamoDB is to create an IAM role with the necessary DynamoDB permissions (e.g., dynamodb:GetItem, dynamodb:PutItem) and attach that role to the Lambda function. This follows the principle of least privilege and leverages AWS Identity and Access Management (IAM) roles, which provide temporary, automatically rotated credentials via the AWS Security Token Service (STS). This approach eliminates the need to manage long-term access keys and ensures secure, auditable access.

Exam trap

The trap here is that candidates may think environment variables (Option A) are a secure storage mechanism because they are not in the code, but they fail to recognize that long-term access keys are still exposed and violate the IAM roles best practice for serverless applications.

How to eliminate wrong answers

Option A is wrong because storing AWS access keys and secret keys in Lambda environment variables is insecure and violates best practices; environment variables can be exposed in logs or through the Lambda console, and long-term credentials increase the risk of compromise. Option C is wrong because creating an IAM user with programmatic access and embedding the credentials in Lambda code is a security anti-pattern; it requires manual credential rotation, exposes secrets in code, and bypasses the automatic credential management provided by IAM roles. Option D is wrong because AWS does not provide 'default full admin access' to Lambda functions; the Lambda function must have an explicit IAM role attached, and granting full admin access would violate the principle of least privilege and create a severe security risk.

206
MCQhard

A developer is building a real-time chat application using Amazon API Gateway WebSockets and AWS Lambda. The developer notices that messages are sometimes delivered out of order. What should the developer do to ensure ordered message delivery?

A.Increase the Lambda function's memory allocation
B.Use API Gateway's built-in message ordering feature
C.Set the 'sequenceNumber' property in the WebSocket message
D.Use an Amazon SQS FIFO queue to buffer messages before processing
AnswerD

An Amazon SQS FIFO (First-In, First-Out) queue is specifically designed to guarantee the exact order in which messages are sent and received. By buffering chat messages in an SQS FIFO queue before they are processed by a Lambda function, the application ensures that messages from a specific message group (e.g., a chat room or user conversation) are delivered to the Lambda function strictly in the order they were sent. This mechanism prevents race conditions and ensures sequential processing, which is crucial for maintaining the integrity of a real-time chat conversation.

Why this answer

WebSocket connections run over TCP, which guarantees in-order delivery of frames from the client to Amazon API Gateway. However, when API Gateway routes these messages to AWS Lambda, Lambda executes concurrently. This concurrent execution can lead to messages being processed, written to a database, or broadcasted to other clients out of order.

To guarantee ordered processing, messages can be buffered using an Amazon SQS FIFO (First-In-First-Out) queue before being processed by Lambda, ensuring they are handled in the exact order they were received.

Exam trap

Candidates often mistake TCP/WebSocket transport guarantees for application-level processing guarantees. While the network protocol ensures packets arrive at API Gateway in order, the downstream serverless backend (Lambda) processes them concurrently, destroying that order unless a sequencing mechanism like SQS FIFO is introduced.

How to eliminate wrong answers

Option A is wrong because increasing Lambda memory allocation improves compute performance but does not affect the order in which WebSocket messages are received or processed; ordering is a network and queuing concern, not a resource allocation one. Option B is wrong because API Gateway WebSockets does not have a built-in message ordering feature; the WebSocket protocol (RFC 6455) does not guarantee ordering, and API Gateway does not add such a feature. Option C is wrong because setting a 'sequenceNumber' property in the WebSocket message is a client-side or application-level metadata field that does not enforce ordering at the infrastructure level; the Lambda function would still need to reorder messages manually, and without a FIFO mechanism, concurrent processing can still cause out-of-order delivery.

207
MCQmedium

A developer is using AWS CodeDeploy to deploy an application to an EC2 Auto Scaling group. The application must remain fully available; only one instance should be taken offline at a time. The developer wants to configure the deployment to update instances one by one, ensuring that the deployment fails fast if any instance fails to deploy. Which deployment configuration should the developer choose?

A.CodeDeployDefault.AllAtOnce
B.CodeDeployDefault.HalfAtATime
C.CodeDeployDefault.OneAtATime
D.CodeDeployDefault.BlueGreen
AnswerC

The CodeDeployDefault.OneAtATime configuration updates only one instance in the target deployment group at a time. This strategy ensures maximum application availability by keeping the vast majority of instances serving traffic throughout the deployment process. It minimizes the blast radius of any potential deployment failure and allows for quick rollback or termination of the deployment if issues are detected on the single updated instance, making it ideal for critical applications requiring continuous operation.

Why this answer

CodeDeployDefault.OneAtATime, is correct because it deploys the application to one instance at a time, ensuring that only one instance is taken offline during the deployment. This satisfies the requirement for the application to remain fully available. Additionally, this configuration fails fast: if any instance fails to deploy, the deployment stops immediately, preventing further instances from being updated.

Exam trap

The trap here is that candidates may confuse deployment configurations (like OneAtATime) with deployment types (like BlueGreen), or incorrectly assume that HalfAtATime updates instances one by one when it actually updates half the fleet at a time.

How to eliminate wrong answers

Option A is wrong because CodeDeployDefault.AllAtOnce deploys to all instances simultaneously, which would take all instances offline at once and violate the requirement for only one instance to be offline at a time. Option B is wrong because CodeDeployDefault.HalfAtATime deploys to half the instances at a time, which would take more than one instance offline simultaneously, not meeting the one-at-a-time requirement. Option D is wrong because CodeDeployDefault.BlueGreen is a deployment type that shifts traffic between two environments (blue and green), not a deployment configuration that controls the number of instances updated at a time within a single Auto Scaling group; it also does not inherently provide a one-at-a-time update pattern.

208
MCQmedium

A company uses AWS CloudFormation to deploy infrastructure. The developer needs to pass a list of security group IDs to an EC2 instance launch configuration. The security groups are created in another stack. How should the developer obtain the security group IDs?

A.Use Fn::GetAtt to retrieve the IDs from the other stack's resources.
B.Use Fn::ImportValue to import the exported outputs from the other stack.
C.Use a nested stack to include the security group resources in the same template.
D.Use Fn::Ref to reference the security group IDs directly.
AnswerB

The Fn::ImportValue intrinsic function is the correct mechanism for referencing outputs from other CloudFormation stacks. It allows a stack to consume values that have been explicitly exported by another stack using the Fn::Export function in its `Outputs` section, referencing the unique name provided during export. This design pattern promotes modularity and enables decoupled infrastructure deployments by facilitating secure and managed cross-stack communication.

Why this answer

Fn::ImportValue is designed to retrieve exported outputs from another CloudFormation stack. When security groups are created in a separate stack, the developer must export their IDs using the Export field in the Outputs section of that stack, and then use Fn::ImportValue in the current stack to reference those exported values. This is the standard cross-stack reference mechanism in CloudFormation, enabling decoupled infrastructure management.

Exam trap

The trap here is that candidates often confuse Fn::GetAtt and Fn::ImportValue, mistakenly thinking that GetAtt can retrieve attributes across stacks, when in fact it is strictly intra-stack, while ImportValue is the only native CloudFormation function for cross-stack references.

How to eliminate wrong answers

Option A is wrong because Fn::GetAtt retrieves attributes of resources within the same stack, not from another stack; it cannot reference resources across stack boundaries. Option C is wrong because using a nested stack would require restructuring the template and embedding the security group resources, which contradicts the requirement that they are created in another stack and does not solve the cross-stack reference problem. Option D is wrong because Fn::Ref returns the logical ID or physical ID of a resource only within the same template; it cannot resolve values from a different stack.

209
MCQmedium

A developer is setting up a CI/CD pipeline using AWS CodePipeline to deploy an application to Amazon ECS. The pipeline has a source stage that pulls code from an AWS CodeCommit repository. The developer wants the pipeline to execute only when commits are pushed to the 'main' branch. How should the developer configure this?

A.Create an Amazon CloudWatch Events rule that triggers the pipeline only when the branch is 'main'.
B.Configure the pipeline's source stage to include the branch name in the CodeCommit action configuration.
C.Use an AWS Lambda function in the source stage to filter the branch.
D.Set a branch filter pattern in the pipeline trigger settings.
AnswerB

When configuring a CodePipeline, the CodeCommit source action within the source stage includes a mandatory `BranchName` parameter. By specifying the desired branch, such as 'main', directly in this configuration, CodePipeline is explicitly instructed to monitor only that particular branch for new commits. This native integration ensures that the pipeline automatically initiates an execution solely upon pushes to the designated branch, making it the most direct and efficient method for branch-specific triggering.

Why this answer

AWS CodePipeline allows you to specify a branch name directly in the source action configuration for CodeCommit. When you configure the source stage, you can set the 'BranchName' parameter to 'main', which ensures the pipeline only triggers on commits pushed to that specific branch. This is the simplest and most direct method to filter by branch without additional services or custom logic.

Exam trap

The trap here is that candidates might overthink the solution by considering external services like CloudWatch Events or Lambda, when the correct answer is a simple configuration option already built into the CodePipeline source stage.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Events rules can trigger a pipeline on various events, but they do not natively filter by branch name; you would need to add a custom event pattern or use a Lambda function to inspect the branch, which is unnecessary and more complex than the built-in branch filter. Option C is wrong because using an AWS Lambda function in the source stage to filter the branch adds unnecessary complexity and cost; CodePipeline already supports branch filtering natively in the source action configuration. Option D is wrong because CodePipeline does not have a 'pipeline trigger settings' feature with a branch filter pattern; branch filtering is configured within the source stage action, not as a separate trigger setting.

210
MCQmedium

A company uses an IAM role to allow an EC2 instance to access an S3 bucket. The role's trust policy allows the EC2 service, and the permissions policy grants s3:GetObject on the bucket. The application on the instance receives 'Access Denied' errors when trying to read objects. What is the most likely cause?

A.The IAM role's trust policy does not allow the EC2 service.
B.The S3 bucket has default encryption enabled.
C.The EC2 instance does not have an instance profile associated with the IAM role.
D.The S3 bucket policy explicitly denies s3:GetObject.
AnswerC

An EC2 instance requires an instance profile to assume an IAM role and obtain temporary security credentials. The instance profile acts as a container for the IAM role, allowing the EC2 instance to retrieve these credentials via its metadata service. Without an instance profile explicitly associated with the EC2 instance, the instance lacks the necessary mechanism to assume the designated IAM role, rendering it unable to acquire the permissions required to interact with other AWS services like S3.

Why this answer

The most likely cause is that the EC2 instance does not have an instance profile associated with the IAM role. An IAM role must be attached to an EC2 instance via an instance profile, which acts as a container for the role. Without this association, the instance cannot obtain temporary credentials from the AWS Security Token Service (STS) to sign API requests, resulting in 'Access Denied' errors even if the role's trust and permissions policies are correctly configured.

Exam trap

The trap here is that candidates often assume the IAM role's trust and permissions policies are sufficient, overlooking the mandatory instance profile association required for EC2 to use the role.

How to eliminate wrong answers

Option A is wrong because the trust policy allowing the EC2 service is correctly configured, as stated in the question; if it were not, the role could not be assumed at all, but the error occurs at the S3 access level, not at the role assumption level. Option B is wrong because default encryption on an S3 bucket does not affect IAM permissions for reading objects; it only encrypts objects at rest, and the application would still be able to read objects if it has the correct IAM permissions. Option D is wrong because the question states the permissions policy grants s3:GetObject, and there is no indication of a bucket policy; an explicit deny in a bucket policy would override the IAM role's allow, but the scenario does not mention any bucket policy, making this an unlikely primary cause.

211
MCQmedium

A developer needs to package and deploy a serverless application with Lambda functions, API Gateway, and DynamoDB using concise syntax. Which framework is AWS-native for this purpose?

A.AWS Serverless Application Model
B.AWS Control Tower
C.Amazon Macie
D.AWS Backup
AnswerA

AWS Serverless Application Model (SAM) is an open-source framework specifically designed to build, package, and deploy serverless applications on AWS. It extends AWS CloudFormation by providing a simplified syntax for defining serverless resources like Lambda functions, APIs, and databases. Using the SAM CLI, developers can easily test applications locally, package their code and dependencies, and deploy them to the AWS cloud as CloudFormation stacks, streamlining the entire serverless development lifecycle.

Why this answer

The AWS Serverless Application Model (SAM) is an AWS-native framework that uses a simplified YAML or JSON syntax to define and deploy serverless resources such as Lambda functions, API Gateway, and DynamoDB. It extends AWS CloudFormation, allowing developers to package and deploy with concise syntax using the `sam build` and `sam deploy` commands, making it the correct choice for this purpose.

Exam trap

The trap here is that candidates may confuse AWS SAM with general-purpose infrastructure-as-code tools like Terraform or AWS CloudFormation, but the question specifically asks for a framework with concise, AWS-native syntax for serverless applications, which SAM uniquely provides.

How to eliminate wrong answers

Option B is wrong because AWS Control Tower is a governance and multi-account management service, not a framework for packaging and deploying serverless applications. Option C is wrong because Amazon Macie is a data security and privacy service that uses machine learning to discover and protect sensitive data, not a deployment framework. Option D is wrong because AWS Backup is a centralized backup service for managing backups across AWS services, not a framework for defining or deploying serverless resources.

212
MCQmedium

A company uses AWS Elastic Beanstalk to deploy a web application. The application requires a database connection string that is different for each environment (development, staging, production). The developer wants to set these values without hardcoding them in the application code. Which configuration method should the developer use?

A.Use the .ebextensions configuration files with environment-specific snippet files
B.Use environment properties in the Elastic Beanstalk console
C.Use Amazon RDS within Elastic Beanstalk
D.Use AWS Systems Manager Parameter Store with an IAM instance profile
AnswerB

Elastic Beanstalk environment properties are the native and recommended mechanism for passing configuration values to your application. These properties are defined directly within the Elastic Beanstalk environment configuration, either via the console, CLI, or configuration files, and are automatically injected as environment variables into the application's runtime on the EC2 instances. This allows for distinct configurations, such as database endpoints or API keys, to be managed separately for development, staging, and production environments without modifying application code.

Why this answer

Elastic Beanstalk environment properties allow you to inject configuration values (like database connection strings) into your application at deployment time without hardcoding them. These properties are set per environment in the Elastic Beanstalk console or via CLI, and the application retrieves them as environment variables, making them environment-specific. While database connection strings are sensitive, environment properties are the simplest configuration method within Elastic Beanstalk for such values.

AWS Systems Manager Parameter Store (Option D) is more secure for secrets but is not a native Elastic Beanstalk feature and requires additional setup; the question specifically asks for a configuration method within Elastic Beanstalk's native capabilities.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing AWS Systems Manager Parameter Store (Option D) for secret management, but the question specifically asks for a configuration method within Elastic Beanstalk's native features, where environment properties are the simplest and most direct approach for environment-specific values, even for sensitive ones like database connection strings.

How to eliminate wrong answers

Option A is wrong because .ebextensions configuration files are used for customizing the Elastic Beanstalk environment (e.g., installing packages, creating files) but not for setting environment-specific database connection strings; they are static per application version, not dynamic per environment. Option C is wrong because Amazon RDS within Elastic Beanstalk is a feature that provisions a database tied to the environment, but it does not solve the problem of setting a connection string that differs per environment—the connection string is automatically generated and managed by Elastic Beanstalk, not manually configured. Option D is wrong because AWS Systems Manager Parameter Store can store secrets, but using it requires additional IAM configuration and code changes to fetch the parameter, which is more complex than the built-in environment properties; the question asks for the simplest method within Elastic Beanstalk's native capabilities.

213
MCQmedium

A developer is creating a REST API using Amazon API Gateway and multiple AWS Lambda functions for different endpoints. The API must support CORS for a web application hosted on a different domain. The developer is using Lambda proxy integration. Which configuration is required to enable CORS?

A.Enable CORS in API Gateway and configure the Lambda functions to return the required CORS headers.
B.Configure API Gateway to return CORS headers and Lambda functions can ignore CORS.
C.Configure Lambda functions to return CORS headers and API Gateway will pass them through automatically.
D.Use a Lambda@Edge function at Amazon CloudFront to add CORS headers.
AnswerA

Enabling CORS in API Gateway generates an OPTIONS method and configures headers for non-proxy integrations, but for proxy integrations, the Lambda must also return the headers. Both steps are needed to ensure full CORS support.

Why this answer

With Lambda proxy integration in API Gateway, the entire request and response are passed through to the Lambda function, which must return the HTTP response including status code, headers, and body. To enable CORS, the Lambda function must include the required CORS headers (e.g., Access-Control-Allow-Origin) in its response. While API Gateway can be configured to add CORS headers for non-proxy integrations, with proxy integration the Lambda function is solely responsible for returning all headers.

Exam trap

The trap here is that candidates assume API Gateway's CORS configuration works universally, but with Lambda proxy integration, the Lambda function has full control over the response headers, making API Gateway's CORS settings ineffective.

How to eliminate wrong answers

Option B is wrong because with Lambda proxy integration, API Gateway cannot independently add CORS headers; the Lambda function controls the entire response. Option C is wrong because API Gateway does not automatically pass through headers from the Lambda function; the Lambda function must explicitly return them in the response object. Option D is wrong because Lambda@Edge is used with CloudFront for edge processing, not for API Gateway CORS configuration, and it would add unnecessary complexity and latency.

214
MCQmedium

A developer is using AWS CloudFormation to deploy a stack that includes an Amazon S3 bucket and an AWS Lambda function. The Lambda function needs to be granted permission to read objects from the S3 bucket. Which resource should the developer define in the CloudFormation template to provide these permissions?

A.AWS::IAM::Role
B.AWS::Lambda::Permission
C.AWS::S3::BucketPolicy
D.AWS::IAM::ManagedPolicy
AnswerA

An AWS::IAM::Role is the correct and standard mechanism for granting a Lambda function the necessary permissions to interact with other AWS services, such as reading from an S3 bucket. This resource defines an identity that the Lambda function assumes during execution, specified by an `AssumeRolePolicyDocument` allowing the `lambda.amazonaws.com` service principal. Attached policies within the role then explicitly define the actions (e.g., `s3:GetObject`) the function is authorized to perform on specified resources.

Why this answer

The Lambda function requires an IAM role (AWS::IAM::Role) with a policy that grants s3:GetObject permissions on the S3 bucket. This role is assumed by the Lambda service at runtime, allowing the function to read objects from the bucket. The role must include a trust policy that allows lambda.amazonaws.com to assume it.

Exam trap

The trap here is that candidates often confuse resource-based policies (like S3 bucket policies or Lambda permission statements) with identity-based policies (like IAM roles), thinking a bucket policy alone can grant the Lambda function access, when in fact the Lambda function needs an IAM role with the appropriate permissions to assume and use.

How to eliminate wrong answers

Option B (AWS::Lambda::Permission) is wrong because it grants a resource-based policy to allow another AWS service or account to invoke the Lambda function, not to grant the Lambda function permissions to access S3. Option C (AWS::S3::BucketPolicy) is wrong because a bucket policy controls access to the S3 bucket from external principals, but it does not grant the Lambda function's execution role the necessary IAM permissions; while a bucket policy could be used to allow the Lambda role, the standard and recommended approach is to attach permissions to the Lambda execution role. Option D (AWS::IAM::ManagedPolicy) is wrong because it defines a reusable policy document but does not create a role; the Lambda function needs an IAM role to assume, not just a managed policy.

215
MCQeasy

A developer is building a serverless web application using AWS Lambda and Amazon DynamoDB. The application needs to perform complex aggregations on data stored in DynamoDB. Which AWS service should the developer use to perform these aggregations efficiently without reading all the data into Lambda?

A.AWS Glue
B.Amazon EMR
C.DynamoDB Streams with AWS Lambda
D.Amazon Redshift
AnswerC

DynamoDB Streams capture a time-ordered sequence of item-level modifications (inserts, updates, and deletes) in a DynamoDB table, providing a near real-time data feed. AWS Lambda functions can subscribe to these streams, processing batches of records as they become available. This serverless pattern allows for efficient, event-driven aggregation updates, such as maintaining counters or summary tables, without requiring expensive full table scans, making it the ideal solution for responsive data insights in a serverless web application.

Why this answer

DynamoDB Streams captures item-level changes in near real-time and can trigger a Lambda function to perform incremental aggregations without scanning the entire table. This pattern avoids reading all data into Lambda, making it efficient for continuous aggregation workloads.

Exam trap

The trap here is that candidates may choose AWS Glue or Amazon EMR because they associate 'complex aggregations' with big data tools, overlooking that DynamoDB Streams with Lambda provides a serverless, incremental aggregation pattern that avoids full table scans.

How to eliminate wrong answers

Option A is wrong because AWS Glue is a serverless ETL service designed for batch data processing and cataloging, not for real-time aggregations triggered by DynamoDB changes. Option B is wrong because Amazon EMR is a big data platform for running Apache Spark, Hadoop, or Hive clusters, which is overkill and not serverless for simple aggregations on DynamoDB data. Option D is wrong because Amazon Redshift is a petabyte-scale data warehouse for SQL analytics, not a service for performing aggregations directly on DynamoDB data without moving it first.

216
MCQhard

A company uses AWS CodeDeploy to deploy a web application to an Auto Scaling group. The deployment fails during the 'Install' lifecycle event. The developer checks the logs and finds that the scripts in the 'appspec.yml' file are not being executed because the instances are not in a healthy state. What could be the reason for the instances being unhealthy?

A.The health check grace period on the Auto Scaling group is too short.
B.The Elastic Load Balancer is not configured to route traffic to the Auto Scaling group.
C.The CodeDeploy agent on the instances is outdated.
D.The IAM instance profile does not have permissions to access the S3 bucket where the artifacts are stored.
AnswerA

During an AWS CodeDeploy deployment, new instances launched by an Auto Scaling group or existing instances undergoing a blue/green deployment need adequate time to initialize and for the application to start successfully. If the Auto Scaling group's health check grace period is too short, instances might be prematurely marked unhealthy by the Auto Scaling group before the CodeDeploy agent has finished installing dependencies, starting services, or even completing its deployment lifecycle events. This premature marking can lead to instances being terminated or removed from service before they are fully operational, disrupting the deployment and causing application instability.

Why this answer

If the health check grace period is too short, instances may be marked unhealthy by the Auto Scaling group before the CodeDeploy installation scripts complete. This causes the deployment to fail during the 'Install' lifecycle event. Option B is incorrect because even if the ELB is not configured to route traffic, it would not directly cause instance health check failures during deployment; it would affect traffic routing.

Option C is incorrect because an outdated CodeDeploy agent might cause script execution failures, but the logs indicate scripts are not executed because instances are unhealthy, not because of agent issues. Option D is incorrect because IAM permissions affect access to artifacts, but the error is about instance health, not access denied.

217
MCQeasy

A developer needs to grant a Lambda function read-only access to an S3 bucket. Which IAM entity should be used to attach the permissions?

A.Create an IAM user and provide the credentials to the Lambda function.
B.Attach a resource-based policy to the S3 bucket.
C.Attach a policy to an IAM group and add the Lambda function to the group.
D.Create an IAM role with the necessary permissions and assign it to the Lambda function as the execution role.
AnswerD

This is the correct and AWS-recommended approach for granting permissions to a Lambda function. An IAM role, configured with a trust policy allowing `lambda.amazonaws.com` to assume it, serves as the function's execution role. An attached identity-based permissions policy then explicitly defines the specific actions the Lambda function is authorized to perform, such as `s3:GetObject` for read-only access, ensuring adherence to the principle of least privilege and providing temporary credentials.

Why this answer

Lambda functions require an IAM role (execution role) to obtain temporary AWS credentials via the AWS Security Token Service (STS). This role must have a trust policy allowing Lambda to assume it, and an attached permissions policy granting read-only access to the S3 bucket. This is the standard and secure method for granting permissions to an AWS service like Lambda.

Exam trap

The trap here is that candidates confuse resource-based policies (which grant access to the principal specified in the policy) with identity-based policies (which grant permissions to the principal the policy is attached to), and incorrectly think a bucket policy alone can grant permissions to a Lambda function without an execution role.

How to eliminate wrong answers

Option A is wrong because IAM users are intended for human or application access with long-term credentials, not for AWS services; embedding user credentials in a Lambda function is insecure and violates best practices. Option B is wrong because a resource-based policy on the S3 bucket can grant cross-account access or access to other AWS services, but it cannot directly grant permissions to a Lambda function's execution role; the Lambda function still needs an execution role with the appropriate permissions. Option C is wrong because IAM groups are used to manage permissions for IAM users, not for AWS services; Lambda functions cannot be added to an IAM group.

218
MCQmedium

A developer is designing an application that will process credit card payments and store them temporarily in an Amazon DynamoDB table. The developer must ensure that the payment data is encrypted at rest and that the encryption key is managed by the company's security team using AWS KMS. Which type of encryption should the developer enable on the DynamoDB table?

A.Server-side encryption with a customer-managed KMS key
B.Server-side encryption with an AWS managed KMS key
C.Client-side encryption
D.Static key encryption
AnswerA

Server-side encryption with a customer-managed KMS key (CMK) is the most appropriate choice for sensitive data like credit card payments. This option grants the company's security team full administrative control over the encryption key's policy, rotation schedule, and access permissions within AWS Key Management Service (KMS). Such granular control is often a strict requirement for compliance standards like PCI DSS, ensuring the organization maintains ownership and oversight of its cryptographic assets used for data at rest in DynamoDB.

Why this answer

The requirement specifies that the encryption key must be managed by the company's security team. Server-side encryption (SSE) with a customer-managed KMS key allows the company to create, rotate, and control access to the KMS key used to encrypt the DynamoDB table at rest. This gives the security team full control over the encryption key lifecycle, meeting the stated requirement.

Exam trap

The trap here is that candidates often confuse 'customer-managed KMS key' with 'AWS managed KMS key,' assuming any KMS encryption meets the requirement, but the exam specifically tests the distinction between who manages the key (customer vs. AWS) to enforce security control requirements.

How to eliminate wrong answers

Option B is wrong because server-side encryption with an AWS managed KMS key means AWS owns and manages the key, not the company's security team, so it does not satisfy the requirement for key management by the security team. Option C is wrong because client-side encryption encrypts data before it is sent to DynamoDB, which would require the developer to implement encryption logic in the application and manage keys separately, not using AWS KMS for server-side encryption at rest. Option D is wrong because 'static key encryption' is not a valid encryption type for DynamoDB; DynamoDB supports server-side encryption with AWS KMS keys (AWS managed or customer managed) and not a static key approach.

219
MCQmedium

A developer is deploying a serverless application using AWS SAM. The application consists of an API Gateway endpoint that triggers an AWS Lambda function. The developer wants to enable canary deployments to gradually shift traffic to a new Lambda version. Which SAM resource attribute should the developer configure?

A.ReservedConcurrentExecutions
B.Timeout
C.AutoPublishAlias and DeploymentPreference
D.ProvisionedConcurrency
AnswerC

When deploying serverless applications using AWS SAM or CloudFormation, `AutoPublishAlias` automatically creates or updates an alias to point to the newly deployed Lambda function version. Coupled with `DeploymentPreference`, which integrates with AWS CodeDeploy, this configuration enables sophisticated traffic shifting strategies such as linear or canary deployments. This allows for gradual routing of traffic to the new function version, enabling real-time monitoring for health and performance, and facilitating automated rollbacks if issues are detected, directly addressing the need for controlled traffic shifting.

Why this answer

`AutoPublishAlias` automatically creates and updates a Lambda alias (e.g., `live`) that points to the latest version of your function, while `DeploymentPreference` enables canary, linear, or all-at-once traffic shifting between the old and new alias versions. Together, they allow gradual traffic migration to a new Lambda version without manual alias management.

Exam trap

The trap here is that candidates confuse `ProvisionedConcurrency` or `ReservedConcurrentExecutions` with deployment strategies, but these are performance and scaling controls, not traffic-shifting mechanisms.

How to eliminate wrong answers

Option A is wrong because `ReservedConcurrentExecutions` controls the maximum concurrent invocations for a function to prevent throttling, not traffic shifting between versions. Option B is wrong because `Timeout` sets the maximum execution duration for a Lambda function (up to 900 seconds) and has no role in deployment strategies. Option D is wrong because `ProvisionedConcurrency` pre-warms a specific number of execution environments to reduce cold starts, but it does not manage gradual traffic routing between versions.

220
MCQeasy

A company is deploying a web application on EC2 instances behind an Application Load Balancer. The application needs to authenticate users using a third-party identity provider that supports SAML 2.0. The company wants to use AWS Identity and Access Management (IAM) to manage user permissions. Which solution should the developer implement?

A.Use AWS Security Token Service (STS) to generate temporary credentials for the users.
B.Create an IAM identity provider for the SAML IdP and set up a role with a trust policy that allows federated users to assume it.
C.Store the SAML metadata document in AWS Certificate Manager.
D.Use Amazon Cognito user pools with a SAML identity provider.
AnswerB

This is the correct and standard approach for integrating a SAML-based Identity Provider with AWS. First, an IAM identity provider is created in AWS to register the SAML IdP's metadata document, establishing trust. Subsequently, an IAM role is configured with a trust policy that explicitly permits federated users from that specific SAML IdP to assume it, often based on SAML attributes. This role then defines the specific AWS permissions the federated users will inherit upon successful authentication and assumption.

Why this answer

It describes the standard AWS pattern for SAML 2.0 federation: creating an IAM identity provider for the external SAML IdP, then configuring an IAM role with a trust policy that allows users authenticated by that IdP to assume the role. This enables the application to use IAM to manage permissions for federated users without creating IAM users in the AWS account.

Exam trap

The trap here is that candidates may confuse Amazon Cognito (which also supports SAML) as the only way to federate with a third-party IdP, but the question explicitly requires IAM to manage permissions, making direct IAM SAML federation the correct choice.

How to eliminate wrong answers

Option A is wrong because AWS STS generates temporary credentials, but it does not directly handle SAML authentication; STS is used after federation is established to issue credentials for an assumed role. Option C is wrong because AWS Certificate Manager (ACM) manages SSL/TLS certificates, not SAML metadata documents; SAML metadata is uploaded to IAM when creating the identity provider. Option D is wrong because Amazon Cognito user pools with a SAML IdP is a valid approach for user authentication, but the question specifically requires using IAM to manage user permissions, and Cognito does not integrate with IAM for permission management in the same way as direct IAM SAML federation.

221
MCQmedium

A developer is building a serverless application using AWS Lambda to process files uploaded to an S3 bucket. The files are encrypted with S3 server-side encryption using AWS KMS (SSE-KMS). The Lambda function needs to read the files and store metadata in DynamoDB. Which IAM policy statement should be attached to the Lambda execution role to allow it to decrypt the objects?

A.{"Effect":"Allow","Action":["kms:Encrypt"],"Resource":"*"}
B.{"Effect":"Allow","Action":["kms:Decrypt"],"Resource":"arn:aws:kms:us-east-1:123456789012:key/1234abcd-12ab-34cd-56ef-1234567890ab"}
C.{"Effect":"Allow","Action":["kms:GenerateDataKey"],"Resource":"*"}
D.{"Effect":"Allow","Action":["s3:GetObject"],"Resource":"arn:aws:s3:::my-bucket/*"}
AnswerB

When an object is stored in Amazon S3 using Server-Side Encryption with AWS KMS keys (SSE-KMS), the S3 service encrypts the object data using a unique data key, which is then encrypted by the specified KMS customer master key (CMK). To retrieve and read this object, the calling entity (e.g., a Lambda function) must have explicit `kms:Decrypt` permission on the specific KMS key used for encryption. This allows S3 to use the caller's permissions to request decryption of the data key, enabling the object's content to be returned in plaintext.

Why this answer

The Lambda function needs to decrypt objects encrypted with SSE-KMS. The kms:Decrypt action on the specific KMS key ARN grants the necessary permission to decrypt the S3 object data using AWS KMS. Without this, the Lambda function will receive an access denied error when trying to read the encrypted file.

Exam trap

The trap here is that candidates often assume s3:GetObject alone is sufficient for reading encrypted objects, forgetting that SSE-KMS requires explicit kms:Decrypt permission on the specific KMS key, not just a wildcard or unrelated KMS actions.

How to eliminate wrong answers

Option A is wrong because kms:Encrypt is used to encrypt data, not decrypt it, and the resource wildcard is overly permissive and unnecessary for this use case. Option C is wrong because kms:GenerateDataKey is used to generate a data key for client-side encryption, not to decrypt existing objects; it does not fulfill the requirement to read and decrypt SSE-KMS encrypted files. Option D is wrong because s3:GetObject alone is insufficient; while it allows reading the object, the Lambda function also needs explicit kms:Decrypt permission on the KMS key to decrypt the SSE-KMS encrypted content.

222
MCQhard

A developer attached the following IAM policy to an IAM user: ```json { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::example-bucket/*", "Condition": { "StringEquals": { "s3:x-amz-server-side-encryption": "AES256" } } } ] } ``` The user tries to download an object from example-bucket using the AWS CLI without specifying server-side encryption. What will happen?

A.The download succeeds because the policy allows s3:GetObject
B.The download fails with an AccessDenied error
C.The download succeeds because the object is encrypted with SSE-S3
D.The download fails with a 500 Internal Server Error
AnswerB

The IAM policy attached to the user explicitly includes a condition requiring the `s3:x-amz-server-side-encryption` header with a specific value in the request for `s3:GetObject` to be allowed. If the user attempts to download the object without including this mandatory header in their request, the policy's condition is not met. Consequently, access is denied, resulting in an `AccessDenied` error, typically an HTTP 403 Forbidden status.

Why this answer

The IAM policy allows s3:GetObject only if the request includes server-side encryption set to AES256. Since the user does not specify encryption, the condition is unmet, resulting in an AccessDenied error.

223
MCQeasy

A developer is deploying an AWS Elastic Beanstalk application and notices that the environment's health is degraded because the application is returning HTTP 5xx errors. The developer wants to quickly identify the root cause without redeploying. Which action should the developer take?

A.Increase the environment's instance type to handle more traffic.
B.Retrieve the full logs from the environment using the EB CLI and inspect the application log files.
C.Disable rolling deployments and redeploy the application with a new version.
D.Rebuild the environment to reset the instances and clear any transient issues.
AnswerB

Elastic Beanstalk provides the eb logs command, which bundles and retrieves logs from the environment's instances, including the application server logs, web server logs, and EB platform logs. Inspecting these logs reveals stack traces, errors, and configuration issues causing the 5xx responses. This is the fastest way to diagnose without redeploying.

Why this answer

The eb logs command retrieves logs from the environment's instances, including application and web server logs, which contain the error details needed to diagnose 5xx responses. This is the standard troubleshooting step for Elastic Beanstalk environments. The other options either mask the problem, add cost, or do not provide diagnostic data.

Exam trap

The trap here is assuming that redeploying or rebuilding the environment is a troubleshooting step, when in fact it can destroy the evidence needed to find the root cause.

224
MCQmedium

Refer to the exhibit. A developer runs the AWS CLI command to invoke a Lambda function. The output shows StatusCode 200 and no FunctionError. However, the application that depends on this function's output is not working correctly. What should the developer check next?

A.Check the Lambda function's CloudWatch Logs for any errors or unexpected output.
B.Check the IAM role attached to the Lambda function for insufficient permissions.
C.Check the payload format against the function's expected input.
D.Check the Lambda function's memory and timeout configuration.
AnswerA

If the Lambda function executed successfully (no FunctionError), but the result is not as expected, the primary place to investigate the function's internal logic and output is CloudWatch Logs. The function's console.log (or equivalent in other runtimes) statements, along with any unhandled exceptions or specific return values, are all captured here, providing crucial insights into its runtime behavior and what it actually returned.

Why this answer

A StatusCode 200 with no FunctionError indicates the Lambda function executed and completed without a runtime or invocation error. However, the application may still fail if the function returns incorrect data or has logical errors. Checking CloudWatch Logs is the standard next step to inspect the actual execution logs, print statements, or handled logic errors that would reveal why the output is incorrect.

Exam trap

The trap here is that candidates assume a 200 status code guarantees correct application behavior, but Lambda's success response only indicates the function ran to completion, not that its business logic or output is correct for the caller.

How to eliminate wrong answers

Option B is wrong because insufficient IAM permissions would typically cause an access denied error (e.g., 403) or a FunctionError, not a successful 200 response. Option C is wrong because a payload format mismatch would likely cause a runtime error (e.g., JSON parsing failure) that would appear as a FunctionError or in CloudWatch Logs, not a clean 200. Option D is wrong because memory or timeout issues would result in a timeout error (e.g., Task timed out) or out-of-memory error, both of which would produce a FunctionError or a non-200 status code.

225
MCQhard

A developer optimized an Amazon S3 bucket for high request rates. The bucket receives over 5,000 PUT requests per second. Recently, some requests are failing with a 503 Slow Down error. What is the most likely cause and how should the developer fix it?

A.Use multipart upload for all objects to improve throughput.
B.The request rate exceeds the account-level PUT quota; request a quota increase.
C.The bucket policy is too permissive; restrict access to prevent abuse.
D.Add a random prefix to the object keys to distribute across partitions.
AnswerD

Amazon S3 distributes data across multiple partitions internally, with object keys serving as the basis for this distribution. By adding a random prefix to object keys, requests are spread across a wider range of S3 partitions, preventing a single prefix from becoming a 'hot spot.' This strategy effectively increases the aggregate request rate capacity for the bucket, mitigating 503 'Slow Down' errors by distributing the load.

Why this answer

S3 returns 503 when request rates exceed partition limits. Prefix randomization spreads requests across partitions. Option A is wrong because 503 is not due to permissions.

Option B is wrong because 503 is not a quota limit exceeded error (that would be 400). Option C is wrong because multipart upload is for large objects, not rate limits.

Page 2

Page 3 of 16

Page 4