Courseiva

AWS Certified Developer Associate DVA-C02 (DVA-C02) — Questions 226–300

1135 questions total · 16pages · All types, answers revealed

Page 3

Page 4 of 16

Page 5
226
Multi-Selecteasy

Which TWO AWS services can be used to decouple microservices in a distributed application? (Choose TWO.)

Select 2 answers
A.Amazon CloudWatch
B.Elastic Load Balancer (ELB)
C.Amazon Simple Notification Service (SNS)
D.Amazon Simple Queue Service (SQS)
E.Amazon Route 53
AnswersC, D

Amazon SNS is a fully managed publish/subscribe messaging service that effectively decouples microservices by allowing publishers to send messages to a central topic. This topic then fans out those messages to multiple subscribed endpoints or services asynchronously, ensuring that the publisher does not need to know about or directly interact with the consumers. This pattern promotes loose coupling, independent scaling, and fault tolerance across the system.

Why this answer

Amazon Simple Notification Service (SNS) is a fully managed pub/sub messaging service that enables microservices to communicate asynchronously by broadcasting messages to multiple subscribers (e.g., SQS queues, Lambda functions, HTTP endpoints). This decouples the producer from the consumers, allowing each microservice to scale and fail independently without blocking the sender.

Exam trap

The trap here is that candidates confuse Elastic Load Balancer (ELB) with a message broker, but ELB operates at the transport layer (TCP/HTTP) for synchronous load balancing, not for asynchronous decoupling via queues or pub/sub messaging.

227
MCQhard

A developer is using Amazon CloudFront to distribute content from an S3 bucket. The bucket is configured as an origin with Origin Access Control (OAC). Recently, some users have reported that they receive 403 Forbidden errors when accessing certain objects. The developer checks the CloudFront distribution and confirms that the OAC is set up correctly. The S3 bucket policy allows the CloudFront service principal to get objects. The developer also notes that the objects in question have been updated recently. What is the MOST likely cause of the 403 errors?

A.The objects are encrypted with SSE-C (server-side encryption with customer-provided keys).
B.The OAC configuration is not correctly associated with the CloudFront distribution.
C.The S3 bucket policy denies access to the CloudFront service principal.
D.The CloudFront distribution is configured to use the S3 website endpoint instead of the REST endpoint.
AnswerA

CloudFront cannot retrieve objects encrypted with SSE-C (Server-Side Encryption with Customer-Provided Keys) because it does not have a mechanism to store or pass the customer-provided encryption key to Amazon S3 during the object retrieval request. When CloudFront attempts to fetch such an object, S3 requires the encryption key as part of the request for decryption. Without the key, S3 denies access, resulting in a 403 Forbidden error, making SSE-C fundamentally incompatible with CloudFront's caching and distribution model.

Why this answer

The most likely cause is that the objects are encrypted with SSE-C. CloudFront cannot serve objects encrypted with SSE-C because it does not have the encryption key. When CloudFront requests such objects from S3, S3 returns a 403 Forbidden error.

The other options are incorrect: Option B is wrong because the OAC is correctly configured; Option C is wrong because the bucket policy allows the CloudFront service principal; Option D is wrong because using the S3 website endpoint would not cause a 403 for encrypted objects—it would cause a different error or redirect.

228
MCQhard

A company uses AWS CodePipeline with CodeBuild to deploy a Node.js application. The build fails intermittently with 'npm ERR! network' errors. What is the most likely cause and solution?

A.A unit test is failing; fix the test code.
B.The npm cache is corrupted; clear the cache in CodeBuild.
C.The build environment lacks outbound internet access; configure a NAT gateway or use a VPC endpoint for npm.
D.The npm token has expired; regenerate the token.
AnswerC

An ECONNRESET error signifies that the remote server unexpectedly closed the connection, often due to the client's inability to establish or maintain network connectivity. For CodeBuild projects running in a private VPC subnet, outbound internet access is crucial for npm install to fetch packages from public registries. Configuring a NAT Gateway in a public subnet or utilizing a VPC endpoint for specific services like S3 (if npm packages are stored there) provides the necessary outbound path, resolving such network-related build failures.

Why this answer

The 'npm ERR! network' error indicates that npm cannot reach the registry to download packages. If AWS CodeBuild is configured to run inside a VPC, it requires outbound internet access to reach the public npm registry. If CodeBuild is configured with multiple subnets and some of them lack a route to a NAT gateway, the builds will fail intermittently depending on which subnet the build container is provisioned in.

To resolve this, ensure all configured subnets have a route to a NAT gateway, or host your packages in AWS CodeArtifact and use a VPC endpoint to access them privately.

Exam trap

Candidates often assume 'npm ERR! network' is always a local cache or token issue, overlooking the VPC networking configuration. Another trap is forgetting that CodeBuild in a VPC requires a NAT gateway for internet access, and misconfiguring routing in even one of the selected subnets will cause intermittent build failures.

How to eliminate wrong answers

Option A is wrong because unit test failures produce different error messages (e.g., 'Test failed' or assertion errors), not 'npm ERR! network'. Option B is wrong because a corrupted npm cache would cause 'npm ERR! cache' or checksum errors, not network errors; clearing the cache would not resolve a connectivity issue. Option D is wrong because an expired npm token would result in 'npm ERR! code E401' or 'Unauthorized' errors, not network errors.

229
MCQhard

A company uses AWS OpsWorks for configuration management and deployment of applications on EC2 instances. The company wants to migrate to AWS Systems Manager for automation and patching. Which Systems Manager capability should be used to execute scripts and commands on EC2 instances as part of a deployment?

A.AWS Systems Manager Patch Manager
B.AWS Systems Manager State Manager
C.AWS Systems Manager Automation
D.AWS Systems Manager Run Command
AnswerD

AWS Systems Manager Run Command is the ideal capability for executing arbitrary scripts and commands on EC2 instances remotely and securely. It allows administrators to run shell scripts, PowerShell commands, or predefined Systems Manager documents directly on managed instances without needing SSH access. This direct, on-demand execution makes it perfectly suited for running deployment scripts as part of a configuration management process.

Why this answer

AWS Systems Manager Run Command is the correct capability because it allows you to remotely and securely execute scripts and commands on EC2 instances as part of a deployment. Run Command is designed for one-time or on-demand execution, which aligns with the need to run deployment scripts. State Manager is for ongoing configuration management, not for one-time deployment tasks.

Exam trap

Candidates may mistakenly choose State Manager because it can also run scripts as part of a desired state, but the question specifically asks for executing scripts 'as part of a deployment', which is typically a one-time action. Run Command is purpose-built for ad-hoc command execution, making it the right choice.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Patch Manager is specifically for automating the patching of operating systems and applications, not for executing arbitrary scripts or commands as part of a deployment. Option C is wrong because AWS Systems Manager Automation is used for automating complex, multi-step operational tasks (e.g., AMI creation or instance recovery) and requires an Automation document, not for simple script execution on individual instances. Option D is wrong because AWS Systems Manager Run Command executes scripts or commands on demand, but it does not enforce a persistent desired state or schedule; State Manager is the correct choice for ongoing deployment and configuration management.

230
MCQhard

A developer is troubleshooting an issue where an S3 bucket policy is not granting cross-account access to a user in another AWS account. The bucket policy uses a Principal element with the AWS account ID. What is the most likely reason for the failure?

A.The bucket is encrypted with SSE-S3, which blocks cross-account access.
B.The bucket policy must use the user's ARN instead of the account ID.
C.The bucket policy cannot grant access to users in another account.
D.The IAM user in the other account does not have an IAM policy that allows the S3 action.
AnswerD

For successful cross-account access to an S3 bucket, a 'two-way street' of permissions is required. While the S3 bucket policy must explicitly grant access to the external account or user, the IAM user in that external account must also possess an identity-based IAM policy that permits the specific S3 actions, such as s3:GetObject or s3:PutObject. If the user's IAM policy is missing or too restrictive, even with a permissive bucket policy, access will be denied, as both policies must allow the action.

Why this answer

The most likely reason is that the IAM user in the other account does not have an IAM policy that allows the S3 action. For cross-account access, both the bucket policy (resource-based) and the IAM policy (identity-based) must grant the necessary permissions. Even if the bucket policy allows the account, the user's IAM policy must also allow the action.

Exam trap

DVA-C02 often tests the misconception that a bucket policy alone is sufficient for cross-account access, ignoring the need for the user's IAM policy to also allow the action.

How to eliminate wrong answers

Option A is wrong because SSE-S3 encryption does not block cross-account access; encryption is orthogonal to permissions. Option B is wrong because the bucket policy can use the account ID as the principal; it does not require the user's ARN. Option C is wrong because bucket policies can grant access to users in another account; it is a common practice for cross-account access.

231
MCQeasy

A developer is building a RESTful API using Amazon API Gateway. The API experiences high traffic spikes, and many requests are for the same data (e.g., a product catalog). The developer wants to reduce the load on the backend Lambda functions and improve response times for repeated requests. Which feature should the developer enable?

A.Enable API Gateway caching and set a TTL.
B.Use CloudFront with the API Gateway as an origin.
C.Enable throttling on the API Gateway usage plan.
D.Use a DynamoDB Accelerator (DAX) cluster for the backend database.
AnswerA

Enabling API Gateway caching directly addresses the problem by storing responses for a specified Time-To-Live (TTL). When subsequent identical requests arrive within the TTL, API Gateway serves the response from its managed cache, completely bypassing the backend Lambda function. This significantly reduces the load on the Lambda function, lowers invocation costs, and improves API response times for repeated requests.

Why this answer

API Gateway caching stores responses from backend Lambda functions for a configurable time-to-live (TTL). When a request for the same data (e.g., a product catalog) arrives within the TTL period, API Gateway serves the cached response directly, reducing the number of invocations to the Lambda function and improving response latency. This directly addresses the need to reduce load on the backend and improve response times for repeated requests.

Exam trap

The trap here is that candidates often confuse API Gateway caching with CloudFront caching, thinking that CloudFront alone reduces backend load, but CloudFront caches at the edge and still forwards cache misses to API Gateway, which then invokes Lambda; only API Gateway caching directly reduces Lambda invocations for repeated requests.

How to eliminate wrong answers

Option B is wrong because CloudFront with API Gateway as an origin adds a CDN layer that caches responses at edge locations, but it does not reduce the load on the backend Lambda functions for repeated requests to the same API endpoint; it primarily improves latency for geographically distributed users and can still forward requests to API Gateway, which then invokes Lambda. Option C is wrong because enabling throttling on the API Gateway usage plan limits the rate of requests to protect the backend from being overwhelmed, but it does not cache responses or improve response times for repeated requests; it may actually reject or delay requests. Option D is wrong because using a DynamoDB Accelerator (DAX) cluster caches database queries at the data layer, but the problem is about reducing load on Lambda functions and improving response times for API requests, not about optimizing database access; DAX does not cache API responses or reduce Lambda invocations.

232
MCQmedium

A company is using AWS CodePipeline to automate its CI/CD pipeline. The pipeline has a build stage that uses AWS CodeBuild. The developer wants to run unit tests and only proceed to the deploy stage if the tests pass. Which configuration should the developer use to achieve this?

A.Configure a manual approval step before the deploy stage.
B.Configure Amazon CloudWatch alarms to stop the pipeline if tests fail.
C.Configure the build stage to run tests and fail the build if tests fail; CodePipeline will automatically stop.
D.Configure AWS Lambda to invoke a function that checks test results and manually stops the pipeline.
AnswerC

The AWS CodeBuild action within a CodePipeline build stage is specifically designed to execute build commands and tests. If any command within the CodeBuild `buildspec.yml` exits with a non-zero status, CodeBuild reports a failure to CodePipeline. CodePipeline then automatically recognizes this failed action, stops the current pipeline execution, and prevents any subsequent stages, such as deployment, from being initiated, ensuring a 'fail fast' approach.

Why this answer

AWS CodeBuild can be configured to run unit tests as part of the build phase. If any test fails, CodeBuild exits with a non-zero status, causing the build to fail. CodePipeline automatically stops the pipeline execution when a stage fails, preventing the deploy stage from running.

This is the native and simplest way to gate deployment on test success.

Exam trap

The trap here is that candidates may over-engineer a solution (like Lambda or manual approval) when the native failure propagation in CodePipeline already handles the requirement automatically.

How to eliminate wrong answers

Option A is wrong because a manual approval step requires human intervention to proceed, but it does not automatically check test results; tests could fail and the pipeline would still wait for approval, which is not the desired automated behavior. Option B is wrong because Amazon CloudWatch alarms monitor metrics and can trigger notifications or actions, but they cannot directly stop a CodePipeline execution; they are not integrated to halt pipeline stages based on test failures. Option D is wrong because invoking a Lambda function to manually stop the pipeline adds unnecessary complexity and latency; CodePipeline already has built-in failure handling that stops the pipeline when a stage fails, making a custom Lambda solution redundant and less reliable.

233
MCQhard

A company has a legacy application running on an EC2 instance that stores database credentials in a plain text configuration file. The security team requires that credentials be stored securely and rotated every 90 days. The developer must minimize changes to the application code. The application currently reads the configuration file from the file system. Which solution meets these requirements?

A.Encrypt the configuration file using AWS KMS and store the encrypted file on S3.
B.Use AWS Secrets Manager to store the credentials and configure automatic rotation with a Lambda function. Modify the application to retrieve the secret from Secrets Manager.
C.Store the credentials in environment variables on the EC2 instance.
D.Store the credentials in AWS Systems Manager Parameter Store as a SecureString and retrieve them at application startup.
AnswerB

AWS Secrets Manager is the most appropriate solution for managing application credentials, offering robust features like automatic rotation. By integrating with a custom Lambda function, Secrets Manager can programmatically rotate credentials for databases, API keys, or other services on a defined schedule, significantly enhancing the security posture. The application only needs to be modified to retrieve the current secret value from Secrets Manager at runtime, abstracting the actual credential management and minimizing code changes.

Why this answer

AWS Secrets Manager provides built-in support for automatic credential rotation using a Lambda function, meeting the 90-day rotation requirement without manual intervention. By modifying the application to retrieve the secret via the Secrets Manager API, the credentials are no longer stored in plain text, satisfying the security team's mandate. This approach minimizes code changes because the application only needs to replace the file read with an API call, preserving the existing logic structure.

Exam trap

The trap here is that candidates often confuse AWS Secrets Manager with Systems Manager Parameter Store, assuming both support automatic rotation, but Parameter Store does not provide built-in rotation capabilities, making Secrets Manager the only correct choice for automated rotation requirements.

How to eliminate wrong answers

Option A is wrong because encrypting the configuration file and storing it on S3 does not address rotation; the encrypted file would still need to be manually updated every 90 days, and the application would require code changes to decrypt the file. Option C is wrong because environment variables on the EC2 instance are not encrypted at rest by default and do not support automatic rotation; they also expose credentials in process listings or logs. Option D is wrong because AWS Systems Manager Parameter Store as a SecureString does not support automatic rotation natively; while it can store encrypted parameters, rotation would require custom automation, and the application would still need code changes to retrieve the parameter via the AWS SDK.

234
MCQmedium

The developer runs a scan on the DynamoDB table 'orders' with a filter expression to find items with order_status equal to 'SHIPPED'. The output shows ScannedCount of 10000 but Count of 0. Which statement is correct?

A.The scan retrieved 10,000 items from the table, but none matched the filter condition.
B.The scan only returned items that matched the filter, so there are no items with status SHIPPED.
C.The filter expression syntax is incorrect, causing the scan to return zero items.
D.The scan applied the filter before reading items, so only matching items were scanned.
AnswerA

The `ScannedCount` metric in DynamoDB represents the total number of items read from the table before any `FilterExpression` is applied. If the `ScannedCount` is 10,000 and the `Count` (number of items returned after filtering) is 0, it indicates that all 10,000 items were successfully retrieved from the table, but none of them met the criteria specified in the `FilterExpression`. This is a common scenario when the filter condition is very specific or no matching data exists.

Why this answer

In DynamoDB, a Scan operation retrieves all items in the table or index up to the 1 MB limit, then applies any filter expression client-side. The ScannedCount of 10,000 indicates that 10,000 items were read from the table, but the Count of 0 means none of those items satisfied the filter condition (order_status = 'SHIPPED'). This is the expected behavior: filters are applied after the data is read, not before.

Exam trap

The trap here is that candidates often confuse ScannedCount with Count, assuming that the filter is applied before reading (like a SQL WHERE clause), when in fact DynamoDB scans all items first and then filters, so ScannedCount reflects total items read and Count reflects matches only.

How to eliminate wrong answers

Option B is wrong because it incorrectly states that the scan only returned items that matched the filter; in reality, the scan returns all items up to the limit, and the filter is applied afterward, so Count reflects only matches. Option C is wrong because if the filter expression syntax were incorrect, DynamoDB would return a validation error (e.g., ValidationException), not a Count of 0 with a valid ScannedCount. Option D is wrong because it claims the filter is applied before reading items; DynamoDB always reads items first and then applies the filter, which is why ScannedCount can be larger than Count.

235
MCQhard

A developer is deploying a microservices application on Amazon ECS using Fargate. The developer wants to implement a blue/green deployment strategy using AWS CodeDeploy. The current production environment uses an Application Load Balancer (ALB). What is the minimum configuration required to enable blue/green deployments?

A.An ALB with two target groups, one for blue and one for green.
B.An ALB with a single target group and an Amazon CloudFront distribution.
C.An ECS service discovery namespace.
D.A Network Load Balancer (NLB) with a single target group.
AnswerA

An Application Load Balancer (ALB) with two distinct target groups, one designated for the "blue" (current production) environment and another for the "green" (new version) environment, is the standard and most effective architecture for blue/green deployments. The ALB acts as a stable entry point, and its listener rules can be precisely updated to shift traffic from the blue target group to the green target group after successful validation, enabling zero-downtime deployments and immediate rollback capabilities. This setup allows both versions to run concurrently, facilitating thorough testing of the new version before promoting it to full production traffic.

Why this answer

AWS CodeDeploy for Amazon ECS requires an Application Load Balancer (ALB) with two target groups to handle traffic routing during a blue/green deployment. The blue target group serves the current production version, while the green target group serves the new version. CodeDeploy shifts traffic from blue to green by updating the ALB listener rules, and after a successful deployment, the green target group becomes the new production target.

Exam trap

The trap here is that candidates assume a single target group is sufficient because they think blue/green only requires swapping task definitions, but CodeDeploy explicitly needs two target groups to manage traffic routing and rollback independently.

How to eliminate wrong answers

Option B is wrong because a single target group cannot support blue/green deployments, as CodeDeploy needs two distinct target groups to route traffic between the old and new task sets; adding CloudFront does not replace this requirement. Option C is wrong because ECS service discovery namespace is used for internal service-to-service DNS resolution, not for traffic routing or deployment strategies like blue/green. Option D is wrong because a Network Load Balancer (NLB) with a single target group cannot be used with CodeDeploy for ECS blue/green deployments, as CodeDeploy requires an ALB with HTTP/HTTPS listener rules to shift traffic between target groups; NLBs operate at layer 4 and do not support the necessary traffic shifting mechanism.

236
MCQmedium

A company uses AWS Organizations to manage multiple accounts. The security team wants to ensure that all S3 buckets across all accounts are encrypted with SSE-S3. What is the MOST effective way to enforce this?

A.Create an IAM policy that denies non-SSE-S3 encryption and attach it to all users.
B.Use AWS Config rules to detect buckets without SSE-S3 and send alerts.
C.Use an SCP in AWS Organizations to deny s3:PutBucketEncryption unless the encryption algorithm is AES256.
D.Use S3 bucket policies to deny PutObject if encryption is not SSE-S3.
AnswerC

Service Control Policies (SCPs) in AWS Organizations provide a powerful *preventive* control mechanism that applies centrally across all member accounts within an Organizational Unit (OU) or the entire organization. By implementing an SCP to explicitly deny the s3:PutBucketEncryption action unless the encryption algorithm is AES256, it effectively prevents any account from configuring S3 buckets without the required SSE-S3 encryption, ensuring compliance at the infrastructure level.

Why this answer

AWS Organizations allows you to create service control policies (SCPs) that can be applied to all accounts in the organization. An SCP can deny the s3:PutBucketEncryption action unless the encryption algorithm is AES256 (SSE-S3). This centrally enforces encryption across all accounts.

Option A is incorrect because IAM policies must be attached to each user or group individually, and they cannot be enforced across all accounts centrally. Option B is reactive (detection only) and does not prevent non-compliant actions. Option D can enforce encryption on object uploads but does not prevent configuration of bucket-level encryption settings.

237
MCQmedium

A developer is deploying an application using AWS Elastic Beanstalk. The application reads and writes data to an Amazon RDS database. The developer wants to ensure that database credentials are not stored in the application code or configuration files. What should the developer do?

A.Store the credentials as environment properties in the Elastic Beanstalk environment configuration.
B.Encrypt the credentials and store them in an Amazon S3 bucket. Have the application download them at startup.
C.Use AWS Secrets Manager to store the credentials and retrieve them in the application code.
D.Store the credentials in a separate configuration file and include it in the application source bundle.
AnswerC

Secrets Manager stores credentials securely and retrieves them via API calls, but the question requires that credentials are never stored in application code or configuration files. The correct approach uses IAM database authentication with RDS, eliminating static credentials entirely by granting the Elastic Beanstalk environment’s IAM role direct access to the database. Secrets Manager is tempting because it is designed for secure credential storage and rotation, and would be correct if the application needed static credentials that could not be eliminated, such as when RDS does not support IAM authentication.

Why this answer

AWS Secrets Manager is specifically designed to protect secrets (such as database credentials, API keys, and OAuth tokens) needed to access applications, services, and IT resources. It enables you to easily rotate, manage, and retrieve database credentials throughout their lifecycle. Storing credentials in Elastic Beanstalk environment properties (Option A) is a security risk because they are stored in plaintext within the environment configuration, can be exposed via the AWS Console/API to users with Beanstalk permissions, and do not support automatic rotation.

Exam trap

Candidates often choose Elastic Beanstalk environment properties (Option A) because it is a built-in feature of Elastic Beanstalk. However, AWS security best practices dictate using AWS Secrets Manager or Systems Manager Parameter Store (SecureString) for sensitive data like database credentials to ensure encryption at rest and support credential rotation.

How to eliminate wrong answers

Option B is wrong because storing encrypted credentials in an S3 bucket and downloading them at startup introduces complexity and potential security risks, such as exposing the S3 bucket or requiring the application to manage decryption keys, which violates the principle of not storing credentials in the application. Option C is wrong because while AWS Secrets Manager is a secure service for storing credentials, the question specifically asks for a solution within Elastic Beanstalk's native capabilities, and using Secrets Manager would require additional SDK calls and IAM permissions, which is not the simplest or most direct approach for this scenario. Option D is wrong because including a separate configuration file in the application source bundle still stores credentials in the deployment artifact, which defeats the purpose of keeping them out of the code and configuration files.

238
Multi-Selecteasy

A developer is troubleshooting a slow Amazon RDS for MySQL database. The application experiences high latency on write operations. Which TWO actions can improve write performance?

Select 2 answers
A.Add a read replica to offload read traffic.
B.Increase the allocated storage size to get better I/O performance.
C.Enable deletion protection.
D.Increase the DB instance class to a larger size.
E.Enable Multi-AZ deployment for high availability.
AnswersB, D

Increasing the allocated storage size, particularly for General Purpose SSD (gp2) volumes, directly improves I/O performance because throughput and IOPS scale with storage capacity. Larger gp2 volumes provide a higher baseline IOPS and accumulate I/O credits faster, enabling sustained burst performance and mitigating I/O bottlenecks. This ensures the database can read and write data to disk more efficiently, which is critical for write-intensive workloads.

Why this answer

Option B is correct because Amazon RDS storage performance is tied to the allocated storage size: increasing the allocated storage (especially into higher gp2/gp3 or io1/io2 tiers) raises the available IOPS and throughput, which directly reduces write latency. Option D is correct because moving to a larger DB instance class provides more vCPU, memory, and dedicated EBS bandwidth, allowing the database to process write operations faster and relieve resource contention. Option A is not correct because a read replica only offloads read traffic and does not improve write performance on the primary.

Option C is not correct because deletion protection is a safety feature that prevents accidental deletion and has no effect on I/O performance. Option E is not correct because Multi-AZ provides high availability via synchronous standby replication, not write performance improvement; in fact, it can add slight write overhead.

Exam trap

Candidates often mistakenly believe that enabling Multi-AZ (Option E) or adding Read Replicas (Option A) will help with write performance. In reality, Multi-AZ increases write latency due to synchronous replication, and Read Replicas only scale read operations.

239
MCQmedium

A company has an S3 bucket that stores sensitive data. The data is encrypted at rest using an AWS KMS customer managed key (CMK). The security team wants to ensure that only a specific IAM role in the same account can decrypt the objects. Which configuration should the developer implement?

A.Add a bucket policy that denies s3:GetObject unless the request uses a specific IAM role.
B.Add a key policy that allows the IAM role to perform kms:Decrypt and denies all other principals.
C.Configure the S3 bucket with default encryption using the KMS key.
D.Create an IAM policy that grants kms:Decrypt only to the specific role.
AnswerB

A KMS key policy is the primary and mandatory control mechanism for defining who can use a Customer Master Key (CMK) for cryptographic operations, including kms:Decrypt. By explicitly allowing kms:Decrypt for the specified IAM role and implementing a default deny for all other principals, this policy directly enforces that only the designated role possesses the necessary permission to decrypt data encrypted with this specific KMS key. This ensures granular control over the sensitive data's accessibility in plaintext form.

Why this answer

KMS key policies directly control who can use the key for cryptographic operations like kms:Decrypt. By explicitly allowing only the specific IAM role and denying all other principals (including the root account), the key policy ensures that only that role can decrypt the S3 objects, regardless of any other IAM or bucket policies. This is the most secure and direct way to restrict decryption at the key level.

Exam trap

The trap here is that candidates often assume IAM policies alone can grant decryption access, but KMS key policies are the authoritative gatekeeper for key usage, and without an explicit Allow in the key policy, even an IAM policy with kms:Decrypt will fail.

How to eliminate wrong answers

Option A is wrong because a bucket policy denying s3:GetObject based on the IAM role does not control decryption; it controls read access to the object metadata and data, but if the object is encrypted with KMS, the request must also have kms:Decrypt permission, which the bucket policy cannot grant or deny. Option C is wrong because configuring default encryption with the KMS key only ensures new objects are encrypted at rest, but does not restrict which principals can decrypt them; any principal with kms:Decrypt on the key can still decrypt. Option D is wrong because an IAM policy granting kms:Decrypt to the role is insufficient if the key policy does not also allow the role; KMS key policies are the primary access control mechanism, and if the key policy denies all principals except the role, an IAM policy alone cannot override that denial.

240
MCQmedium

A developer runs the AWS CLI command shown in the exhibit. The output includes 'FunctionError': 'Unhandled'. What does this indicate?

A.The function threw an error that was caught by the code.
B.The function timed out.
C.The function threw an unhandled exception.
D.The function was not invoked successfully.
AnswerC

'FunctionError': 'Unhandled' is set by the Lambda runtime whenever the function code throws or rejects an exception that isn't caught anywhere in the handler, meaning the error propagated all the way up and terminated the invocation.

Why this answer

'Unhandled' indicates that the function code threw an exception that was not caught by any try-catch block. Option A is incorrect because a caught error would typically result in a 'Handled' status in the function logs, not 'Unhandled'. Option B is incorrect because a timeout error would produce a different error message, such as 'Task timed out', not 'Unhandled'.

Option D is incorrect because an invocation failure (e.g., permissions or configuration issues) would result in an error before the function runs, not an 'Unhandled' function error.

241
MCQeasy

A developer invokes a Lambda function using the AWS CLI. The response shows StatusCode 200 and FunctionError: Unhandled. What does this indicate?

A.The Lambda function threw an exception that was not caught by the code.
B.The Lambda function timed out before completing.
C.The Lambda function executed successfully without errors.
D.The AWS CLI failed to invoke the function due to permissions.
AnswerA

The presence of the `X-Amz-Function-Error` header in the response, along with a `StatusCode: 200`, is the definitive indicator that the Lambda service successfully received and attempted to execute the function, but the function's code itself encountered an unhandled exception. This means an error occurred within the function's runtime environment that was not caught by a `try-catch` block or equivalent error handling mechanism. Consequently, the Lambda service reported the internal function error back to the invoker.

Why this answer

A is correct because a StatusCode 200 from an AWS Lambda invocation via the AWS CLI indicates that the invocation request itself was accepted and processed by the Lambda service, but the presence of FunctionError: Unhandled means the function code threw an exception that was not caught by any try-catch block or error handler. This results in the Lambda service returning a 200 HTTP status for the invocation request while signaling the error via the FunctionError field in the response payload.

Exam trap

The trap here is that candidates often assume a 200 HTTP status code always means success, but AWS Lambda uses 200 for all synchronous invocations that reach the service, and the actual error state is indicated by the FunctionError field in the response body, not the HTTP status code.

How to eliminate wrong answers

Option B is wrong because a Lambda timeout would return a StatusCode 200 with FunctionError: Unhandled only if the timeout exception itself is unhandled, but the specific error for a timeout is 'Task timed out' and would be caught by the runtime as a handled error if the function has a catch-all; however, the question's FunctionError: Unhandled specifically indicates an unhandled exception, not a timeout. Option C is wrong because a successful execution without errors would return StatusCode 200 with no FunctionError field or FunctionError: None, not FunctionError: Unhandled. Option D is wrong because an AWS CLI permissions failure would result in an HTTP 403 (Forbidden) or 400 (Bad Request) status code, not a 200, and the invocation would not reach the function code at all.

242
MCQhard

A developer is building a REST API using Amazon API Gateway with a Lambda integration. The API must validate that the 'Authorization' header contains a valid JWT token before invoking the backend. Which approach provides the LOWEST latency for token validation?

A.Use a VPC Link to connect to a private server for validation.
B.Validate the token inside the Lambda function integrated with the API.
C.Use API Gateway request validation to check the header format.
D.Use a Lambda authorizer (formerly custom authorizer) on the API Gateway.
AnswerD

A Lambda authorizer, previously known as a custom authorizer, is a dedicated Lambda function invoked by API Gateway *before* the request reaches the backend integration. This authorizer receives the incoming token, performs custom validation logic (e.g., JWT signature verification, expiration checks), and returns an IAM policy that either permits or denies access to the requested API resource. Crucially, API Gateway can cache the policy generated by the authorizer, significantly reducing latency and computational overhead for subsequent requests with the same valid token.

Why this answer

A Lambda authorizer (formerly custom authorizer) runs before the backend Lambda invocation, caching the JWT validation result for a configurable TTL (default 300 seconds). This avoids re-validating the token on every request, providing the lowest latency for token validation compared to validating inside the backend Lambda.

Exam trap

It is a common misconception that API Gateway request validation can handle JWT token validation, but it only validates structural format (e.g., header presence), not cryptographic signature verification.

How to eliminate wrong answers

Option A is wrong because a VPC Link connects to a private server inside a VPC, which adds network latency and complexity without any caching or pre-invocation validation benefit. Option B is wrong because validating the token inside the integrated Lambda function requires the backend to run on every request, even for invalid tokens, increasing latency and cost. Option C is wrong because API Gateway request validation only checks header presence and format (e.g., regex), not the cryptographic validity of a JWT token.

243
MCQeasy

A developer needs to access a DynamoDB table from a Lambda function. The Lambda function is in the same AWS account as the DynamoDB table. What is the most secure way to grant the Lambda function access to the DynamoDB table?

A.Use the AWS account root user credentials.
B.Store the AWS access key and secret access key in the Lambda environment variables.
C.Create an IAM role with a policy that grants DynamoDB access and assign it as the Lambda execution role.
D.Use a resource-based policy on the DynamoDB table to allow the Lambda function.
AnswerC

Creating an IAM role with a policy that grants specific DynamoDB access and assigning it as the Lambda execution role is the secure and recommended AWS best practice. This approach provides the Lambda function with temporary, automatically rotated credentials, adhering to the principle of least privilege by allowing access only to the necessary DynamoDB actions and resources without ever exposing static, long-lived credentials.

Why this answer

The most secure and standard way to grant a Lambda function access to DynamoDB is to create an IAM role with a policy that grants the necessary DynamoDB actions (e.g., dynamodb:GetItem, dynamodb:PutItem) and assign that role as the Lambda execution role. This follows the principle of least privilege and avoids hardcoding credentials, as Lambda automatically assumes this role and manages temporary security credentials. While DynamoDB supports resource-based policies, the Lambda execution role (identity-based policy) remains the standard and recommended approach for granting a Lambda function access to resources within the same account.

Exam trap

Candidates might be tempted by resource-based policies (Option D). While DynamoDB does support resource-based policies, they are primarily used for cross-account access or specific administrative controls. For a Lambda function in the same account, the standard, most secure, and recommended practice is to use the Lambda execution role (identity-based policy).

How to eliminate wrong answers

Option A is wrong because using the AWS account root user credentials is a severe security risk; root credentials have unrestricted access and should never be used for programmatic access, especially in Lambda functions. Option B is wrong because storing AWS access keys and secret access keys in Lambda environment variables exposes long-term credentials that could be leaked through logs or function output, and they lack automatic rotation. Option D is wrong because resource-based policies on DynamoDB tables do not support granting access to Lambda functions directly; DynamoDB resource-based policies only allow cross-account access or service principal grants, not individual Lambda function ARNs, and Lambda functions must assume an IAM role to access DynamoDB.

244
MCQhard

A developer is using Amazon API Gateway with a Lambda authorizer to control access to APIs. The authorizer is failing with a 500 error. The Lambda function logs show 'User: arn:aws:iam::123456789012:role/MyLambdaRole is not authorized to perform: sts:AssumeRole'. What is the most likely cause?

A.The Lambda authorizer is not returning a valid policy.
B.The Lambda function's resource-based policy is missing.
C.The API Gateway does not have permission to invoke the Lambda function.
D.The Lambda function's execution role does not have sts:AssumeRole permission for the target role.
AnswerD

The error message "AssumeRole permission denied" directly indicates that the AWS Lambda function, during its execution, attempted to call the AWS Security Token Service (STS) AssumeRole API operation to temporarily assume another IAM role, but its own execution role lacked the necessary sts:AssumeRole permission for that specific target role. The Lambda execution role defines what permissions the function has to interact with other AWS services. Without sts:AssumeRole explicitly granted for the target role in its policy, the function cannot obtain temporary credentials to perform actions under that role's permissions, leading to this specific authorization failure.

Why this answer

The error message indicates that the Lambda function's execution role (MyLambdaRole) attempted to call sts:AssumeRole but was denied. This occurs when the Lambda function's code tries to assume another IAM role (e.g., to access a resource in another account or service) but the execution role lacks the necessary sts:AssumeRole permission for that target role. Option D correctly identifies this root cause.

Option A is incorrect because an invalid policy from the authorizer would generate a different error (e.g., 403 or 401). Option B is incorrect because resource-based policies are for granting cross-account access to the Lambda function, not for assuming roles. Option C is incorrect because while API Gateway needs permission to invoke the Lambda function, a missing invoke permission would cause a different error (e.g., 500 with 'The API Gateway is not authorized to invoke the Lambda function'), not an sts:AssumeRole error.

245
MCQmedium

A company runs a containerized web application on Amazon ECS using Fargate. The application needs to store files in Amazon S3. The developer wants to follow the principle of least privilege for the ECS task IAM role. Which IAM policy should be attached to the task role?

A.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:*","Resource":"*"}]}
B.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:*","Resource":"arn:aws:s3:::example-bucket/*"}]}
C.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:PutObject","Resource":"arn:aws:s3:::example-bucket/*"}]}
D.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":["s3:GetObject","s3:PutObject"],"Resource":"arn:aws:s3:::example-bucket/*"}]}
AnswerC

This policy precisely adheres to the principle of least privilege, granting only the `s3:PutObject` action, which is the exact permission required for the web application to upload files to Amazon S3. The resource is correctly scoped to `arn:aws:s3:::example-bucket/*`, ensuring the application can only write objects into the specified bucket and not affect other S3 resources or perform any other S3 operations. This minimal permission set significantly enhances security by limiting potential damage if the task's credentials were ever compromised.

Why this answer

It grants only the s3:PutObject action on the specific S3 bucket, which is the minimum permission required for the application to store files. This adheres to the principle of least privilege by not including unnecessary read or list actions. The task role should be scoped to the exact resource and action needed.

Exam trap

The trap here is that candidates often choose Option D thinking both read and write are needed for storing files, but the question explicitly states 'store files' which implies write-only, making the read permission unnecessary and a violation of least privilege.

How to eliminate wrong answers

Option A is wrong because it grants full s3:* access to all S3 resources, which violates least privilege by allowing any S3 operation on any bucket. Option B is wrong because it grants all s3:* actions on the specified bucket, which includes read, delete, and administrative actions not needed for storing files. Option D is wrong because it includes s3:GetObject, which is unnecessary for a write-only use case and violates least privilege by granting read access.

246
Multi-Selecthard

A developer needs to securely expose an API running on an EC2 instance behind an Application Load Balancer. The API should only be accessible to authenticated users via a custom authorization header. Which steps should be taken? (Choose TWO.)

Select 2 answers
A.Create a Lambda authorizer that validates the custom header
B.Enable AWS WAF on the ALB to inspect the header
C.Use Amazon Cognito User Pools to validate the header
D.Use Amazon API Gateway instead of ALB
E.Configure the ALB to use the Lambda authorizer
AnswersA, D

A Lambda authorizer on the Application Load Balancer inspects the custom authorization header, validates the token, and returns an IAM policy allowing or denying the request. This enforces authentication at the load balancer before traffic reaches the EC2 instance.

Why this answer

Option A is correct because a Lambda authorizer (formerly custom authorizer) is the API Gateway mechanism designed to validate a custom authorization header by running a Lambda function that returns an IAM policy allowing or denying the request. Option D is correct because Amazon API Gateway natively supports Lambda authorizers and custom authorization headers, whereas an ALB does not provide this capability, so the API must be fronted by API Gateway to enforce header-based authentication. Option B is incorrect because AWS WAF inspects HTTP requests for threats like SQL injection or XSS and cannot perform custom token/header authorization logic.

Option C is incorrect because Cognito User Pools validate JWTs issued by Cognito, not arbitrary custom authorization headers. Option E is incorrect because ALBs have no native integration with Lambda authorizers; that feature exists only in API Gateway.

Exam trap

The trap is that candidates may assume ALB can use Lambda authorizers similar to API Gateway, but ALB lacks this feature. The correct solution is to use API Gateway with a Lambda authorizer instead of relying on ALB for custom authorization.

247
MCQmedium

A developer is building a system that reads messages from an Amazon SQS queue, processes them, and stores results in an Amazon DynamoDB table. The developer wants to use a managed service to coordinate the processing steps, including error handling and retry logic, without provisioning any servers. Which AWS service should the developer use?

A.AWS Step Functions
B.Amazon Simple Workflow Service (SWF)
C.AWS Glue
D.Amazon MQ
AnswerA

AWS Step Functions is a serverless workflow service that enables developers to build resilient, distributed applications using visual state machines. It excels at orchestrating complex, multi-step processes, integrating seamlessly with Amazon SQS to consume messages and coordinate subsequent actions across various AWS services. Step Functions provides built-in state management, error handling, and retry policies, making it ideal for creating reliable, fault-tolerant workflows initiated by SQS messages.

Why this answer

AWS Step Functions is a serverless orchestration service that lets you coordinate multiple AWS services into a workflow. It directly supports error handling, retry logic, and conditional branching, making it ideal for managing the processing steps of messages from SQS through to DynamoDB without provisioning any servers.

Exam trap

The trap here is that candidates confuse Amazon MQ (a message broker) with a workflow orchestrator, or mistakenly think SWF is the correct choice because it was historically used for workflow coordination, but Step Functions is the modern, serverless, and fully managed alternative that directly integrates with SQS and DynamoDB.

How to eliminate wrong answers

Option B is wrong because Amazon Simple Workflow Service (SWF) is a legacy workflow service that requires you to manage workers (deciders and activity workers) and does not natively integrate with SQS or DynamoDB as seamlessly as Step Functions; it also lacks the built-in retry and error-handling patterns of Step Functions. Option C is wrong because AWS Glue is a serverless ETL service designed for data preparation and transformation, not for orchestrating message processing workflows with SQS and DynamoDB. Option D is wrong because Amazon MQ is a managed message broker service for Apache ActiveMQ and RabbitMQ, not a workflow orchestration service; it provides message queuing but does not handle coordination, error handling, or retry logic across processing steps.

248
Multi-Selecteasy

A web application running on Amazon EC2 instances behind an Application Load Balancer (ALB) is experiencing intermittent 503 errors. Which TWO steps should be taken to diagnose the issue?

Select 2 answers
A.Check the Route 53 health checks for the domain.
B.Check the CPU utilization of the EC2 instances.
C.Check the target group health check settings and instance health status.
D.Check the security group rules for the ALB.
E.Check the EBS volume type of the EC2 instances.
AnswersB, C

High CPU utilization on EC2 instances can severely impact their ability to process requests and respond to health checks in a timely manner. If instances are consistently overloaded, they may fail the Application Load Balancer's (ALB) health checks, causing the ALB to mark them as unhealthy. Consequently, the ALB will stop routing traffic to these instances and return 503 Service Unavailable errors to clients, as it has no healthy targets to forward requests to.

Why this answer

High CPU utilization on EC2 instances can cause them to become unresponsive or fail to respond to health checks within the ALB's configured timeout, leading to 503 errors. The ALB routes traffic only to healthy targets; if instances are overwhelmed, they may fail health checks or drop requests, resulting in a 503 response to clients.

Exam trap

The trap here is that candidates may confuse Route 53 health checks (DNS-level) with ALB target group health checks (application-level), or assume that security groups or EBS volumes are the root cause of HTTP 503 errors when they are not directly related to load balancer routing failures.

249
Multi-Selecteasy

A developer is using Amazon API Gateway to expose a Lambda function as a REST API. The API should only be accessible from a specific VPC. Which TWO steps are required to achieve this? (Choose TWO.)

Select 2 answers
A.Create a VPC endpoint for API Gateway.
B.Attach a resource policy to the API Gateway API that denies access unless the request originates from the VPC.
C.Use an API key that is only known within the VPC.
D.Configure the Lambda function to be VPC-enabled.
E.Create a VPC endpoint for Lambda.
AnswersA, B

Creating an interface VPC endpoint for API Gateway establishes a private connection from your VPC to the API Gateway service using AWS PrivateLink. This allows clients within your VPC to access the API Gateway endpoint without traversing the public internet, ensuring that all traffic remains within the AWS network and is restricted to the specified VPC.

Why this answer

Creating a VPC endpoint for API Gateway (of type `execute-api`) allows API Gateway to be accessed privately from within a specific VPC without traversing the public internet. This endpoint uses AWS PrivateLink to provide a private IP address within the VPC, ensuring traffic stays within the AWS network.

Exam trap

The trap here is that candidates often think enabling the Lambda function to be VPC-enabled (Option D) is sufficient to restrict API access, but this only affects the Lambda's outbound connectivity, not the inbound API Gateway endpoint.

250
MCQmedium

An application running on Amazon ECS with Fargate is experiencing high latency. The application writes logs to Amazon CloudWatch Logs. Which AWS service can be used to analyze the logs to pinpoint the cause of the latency?

A.Amazon CloudWatch Logs
B.Amazon CloudWatch Logs Insights
C.AWS X-Ray
D.Amazon S3
AnswerB

Amazon CloudWatch Logs Insights is specifically designed for interactively searching, analyzing, and visualizing log data to troubleshoot operational problems and identify performance bottlenecks. It allows users to run powerful queries using a purpose-built query language to filter, aggregate, and extract specific information from log events, making it ideal for pinpointing the root causes of latency within application logs. This direct analytical capability is crucial for diagnosing issues.

Why this answer

Amazon CloudWatch Logs Insights is the correct choice because it is purpose-built for interactively querying and analyzing log data stored in CloudWatch Logs. It allows you to run SQL-like queries (using a query language) to filter, aggregate, and visualize log events, which is essential for pinpointing latency patterns, such as slow API calls or database queries, without needing to export logs to another service.

Exam trap

The trap here is that candidates confuse CloudWatch Logs (storage/monitoring) with CloudWatch Logs Insights (query/analysis), assuming the former can perform deep log analysis, when in fact it only supports basic metric filters and real-time monitoring.

How to eliminate wrong answers

Option A is wrong because Amazon CloudWatch Logs itself is a log storage and monitoring service, not a query engine; it can only view raw log streams or set metric filters, not perform ad-hoc analytical queries to diagnose latency. Option C is wrong because AWS X-Ray is a distributed tracing service that traces requests through microservices, but it does not analyze CloudWatch Logs; it uses its own trace data and segments, not log files. Option D is wrong because Amazon S3 is an object storage service; while logs can be exported to S3, it provides no built-in querying capability for log analysis without additional services like Athena.

251
MCQeasy

A developer is writing an AWS Lambda function that needs to read a secret from AWS Secrets Manager. The function is written in Python. What is the BEST practice for retrieving the secret?

A.Use AWS Systems Manager Parameter Store to store the secret.
B.Retrieve the secret inside the handler function every time it is invoked.
C.Store the secret in an environment variable.
D.Retrieve the secret outside the handler function and cache it in a global variable.
AnswerD

Retrieving secrets outside the handler function, typically during the Lambda function's initialization phase, and caching them in a global variable is an optimal strategy for performance and cost efficiency. This approach ensures the secret is fetched only once per execution environment (during a cold start) and then reused for subsequent invocations (warm starts), significantly reducing latency and API call costs associated with repeated secret retrieval.

Why this answer

The best practice because retrieving the secret outside the handler function (at initialization time) and caching it in a global variable avoids making a Secrets Manager API call on every invocation. This reduces latency, cost, and the risk of hitting API rate limits. The cached value persists across warm starts within the same execution environment, aligning with AWS Lambda's lifecycle best practices.

Exam trap

The trap here is that candidates may think retrieving the secret inside the handler (Option B) is simpler or more reliable, but they overlook the performance and cost implications of repeated API calls, as well as the Lambda execution environment reuse model that makes caching outside the handler both safe and efficient.

How to eliminate wrong answers

Option A is wrong because it suggests using AWS Systems Manager Parameter Store instead of Secrets Manager, which does not address the requirement of reading a secret from Secrets Manager; Parameter Store is a different service with different features (e.g., no automatic rotation). Option B is wrong because retrieving the secret inside the handler function on every invocation leads to unnecessary API calls, increased latency, and potential throttling, especially under high concurrency. Option C is wrong because storing secrets in environment variables is insecure; environment variables are visible in the Lambda console, logs, and can be exposed through function configuration, violating security best practices.

252
MCQmedium

A company uses AWS CodeCommit for source control and AWS CodeBuild for building a Java application. They have a CodePipeline that deploys the built artifacts to an Auto Scaling group using CodeDeploy. Recently, the build stage started failing with the error: 'BUILD FAILED: Could not resolve dependencies for project'. The developer checks the buildspec.yml and sees that it uses Maven to download dependencies from a private repository. The developer also notices that the build environment is a managed Docker image. What is the most likely cause?

A.The CodeBuild project does not have the necessary IAM permissions to access the private Maven repository.
B.The build environment does not have network access to the private Maven repository because it is not configured with a VPC.
C.The buildspec.yml has a syntax error in the 'phases' section.
D.The Java compiler version is incompatible with the project.
AnswerB

CodeBuild projects, by default, run in a managed AWS environment with public internet access but are isolated from private Amazon Virtual Private Cloud (VPC) networks. To access a private Maven repository residing within a private subnet of a VPC, an on-premises network via Direct Connect/VPN, or another private network, the CodeBuild project must be explicitly configured to run within a specified VPC. This configuration provisions Elastic Network Interfaces (ENIs) in the designated subnets, allowing the build environment to establish private network connectivity to the repository.

Why this answer

CodeBuild runs in a managed Docker image that, by default, has internet access but no route to private VPC resources such as an internal Maven repository. To reach a private repository hosted inside a VPC, the CodeBuild project must be configured with VPC settings (VPC ID, subnets, security groups). Without that, Maven cannot resolve dependencies and the build fails.

Exam trap

DVA-C02 often tests the misconception that IAM permissions alone control access to private repositories, when the real issue is network reachability from CodeBuild's managed environment into a VPC.

How to eliminate wrong answers

Option A is wrong because IAM permissions govern AWS API access, not network reachability to a private Maven repository; the error is a resolution/network failure, not an authorization failure. Option C is wrong because a buildspec syntax error would produce a YAML or phase parsing error, not a Maven dependency resolution error. Option D is wrong because a Java version mismatch would produce a compilation or UnsupportedClassVersionError, not a dependency resolution failure.

253
MCQeasy

A developer is deploying a serverless application using AWS SAM. The developer wants to define a Lambda function that is invoked by an Amazon API Gateway REST API. Which SAM resource type should the developer use to define the API?

A.AWS::Serverless::SimpleTable
B.AWS::Serverless::Api
C.AWS::ApiGateway::RestApi
D.AWS::Serverless::Function
AnswerB

This is the correct AWS Serverless Application Model (SAM) resource for defining an Amazon API Gateway REST API within a serverless application. `AWS::Serverless::Api` allows developers to specify API endpoints, methods, and integrations with backend services like AWS Lambda functions. This resource abstracts away much of the underlying CloudFormation complexity required to set up a robust and scalable API Gateway, making it the idiomatic choice for exposing HTTP endpoints.

Why this answer

AWS::Serverless::Api defines an API Gateway REST API in SAM. Option A is wrong because AWS::Serverless::SimpleTable defines a DynamoDB table, not an API. Option C is wrong because AWS::ApiGateway::RestApi is a raw CloudFormation resource, not a SAM shorthand resource type.

Option D is wrong because AWS::Serverless::Function defines a Lambda function, not an API.

254
MCQmedium

A developer is using AWS Elastic Beanstalk to deploy a web application. The developer wants to run database migration scripts as part of the deployment process before the new application version starts serving traffic. Which Elastic Beanstalk configuration file should the developer use to define the migration commands?

A..ebextensions/<filename>.config with container_commands
B..ebextensions/<filename>.config with commands
C.Procfile
D.buildspec.yml
AnswerA

Elastic Beanstalk's .ebextensions/<filename>.config with container_commands are executed after the application and web server have been fully set up and are ready, but critically, before the new application version begins serving live traffic. This precise timing is ideal for database migrations, as the application can connect to the database to perform schema updates without impacting active users on the old version, ensuring a smooth transition for the new deployment.

Why this answer

`container_commands` in `.ebextensions/<filename>.config` runs commands after the application and web server have been set up but before the new application version starts serving traffic. This makes it the ideal place to execute database migration scripts that must complete before the environment accepts requests, ensuring data consistency.

Exam trap

The trap here is confusing `commands` with `container_commands`; candidates often pick `commands` because they sound similar, but they run at different lifecycle stages, and only `container_commands` guarantees execution after the application stack is ready but before traffic is routed.

How to eliminate wrong answers

Option B is wrong because `commands` in `.ebextensions/<filename>.config` runs before the application and web server are set up, so the database migration scripts would execute too early, potentially before the application dependencies or environment variables are ready. Option C is wrong because a `Procfile` is used to specify the processes that run your application (e.g., web server, worker), not to define deployment lifecycle commands like database migrations. Option D is wrong because `buildspec.yml` is a configuration file for AWS CodeBuild, not for Elastic Beanstalk; it defines build phases and commands for a CI/CD pipeline, not deployment hooks within Elastic Beanstalk.

255
MCQhard

An application running on Amazon ECS (Fargate) uses an Application Load Balancer (ALB) with connection draining enabled. The application is experiencing intermittent 502 (Bad Gateway) errors during rolling updates of the ECS service. The developer notices that the ALB is routing requests to tasks that are in the 'Draining' state. The ECS service is configured with a deployment circuit breaker that automatically rolls back a failed deployment. What is the most likely cause of the 502 errors?

A.The ALB's idle timeout is too short, causing connections to be dropped before the application responds.
B.The ALB's connection draining timeout is set to 0 seconds, causing connections to be dropped immediately when deregistering targets.
C.The ECS deployment circuit breaker is incorrectly configured to roll back on health check failures.
D.The application is not handling the SIGTERM signal from ECS, causing it to terminate abruptly while the ALB still routes traffic to it.
AnswerD

When ECS stops a task, it sends a SIGTERM signal to allow the application to gracefully shut down. If the application does not catch this signal and stop accepting new connections or complete in-flight requests before exiting, the ALB may still send traffic to the task after it stops, resulting in 502 errors. This is a common issue during rolling updates.

Why this answer

When ECS sends a SIGTERM signal to a Fargate task during a rolling update, the task is expected to gracefully shut down. If the application does not handle SIGTERM, it terminates immediately, but the ALB may still have the task registered as a target and continue routing requests to it. Since the task is already dead or unresponsive, the ALB receives no valid HTTP response and returns a 502 Bad Gateway error.

Connection draining is enabled, but it only works if the task signals the ALB that it is deregistering; without proper SIGTERM handling, the task dies before the draining process completes.

Exam trap

The trap here is that candidates often assume connection draining is a silver bullet that prevents all errors during rolling updates, but they overlook that the application must handle SIGTERM to allow the draining process to work as intended.

How to eliminate wrong answers

Option A is wrong because the ALB's idle timeout (default 60 seconds) controls how long the ALB keeps a connection open without data transfer; it does not cause 502 errors during rolling updates, as 502s stem from the target not responding, not from idle timeouts. Option B is wrong because setting connection draining timeout to 0 seconds would cause immediate deregistration, which would prevent routing to draining tasks, not cause 502 errors; the problem here is that tasks are still receiving traffic while draining, which is the opposite scenario. Option C is wrong because the deployment circuit breaker rolls back the entire deployment on health check failures, but it does not cause 502 errors during the update; it is a recovery mechanism, not a root cause of the errors.

256
Multi-Selectmedium

A company wants to encrypt data at rest in Amazon RDS for MySQL. Which TWO actions should be taken?

Select 2 answers
A.Enable encryption at rest when creating the DB instance.
B.Encrypt individual tables using MySQL native encryption.
C.Enable encryption at rest after the DB instance is created.
D.Use AWS KMS to manage the encryption keys.
E.Use client-side encryption to encrypt data before sending to RDS.
AnswersA, D

Amazon RDS for MySQL supports encryption at rest, which must be configured during the initial creation of the DB instance. This ensures that the underlying storage volume, database snapshots, automated backups, and read replicas are all encrypted from the outset using an AWS Key Management Service (KMS) key. Attempting to enable encryption on an unencrypted instance after creation is not supported directly by RDS.

Why this answer

Amazon RDS for MySQL supports encryption at rest only at the time of DB instance creation. You must enable the encryption option in the console or specify the --storage-encrypted flag in the AWS CLI when launching the instance. Once enabled, RDS automatically encrypts the underlying storage, automated backups, read replicas, and snapshots using AES-256 encryption, with keys managed through AWS KMS.

Exam trap

The trap here is that candidates often assume encryption at rest can be enabled after instance creation (like modifying a DB parameter group) or that MySQL native encryption is available in RDS, but AWS restricts encryption to instance creation time and does not support MySQL's native table encryption within the managed service.

257
MCQhard

A company uses AWS KMS to encrypt data in S3. The security team wants to ensure that all KMS keys are rotated every year. Which action should be taken?

A.Manually rotate the KMS key every year
B.Create a new KMS key and update all applications to use it
C.Enable automatic key rotation
D.Use AWS CloudWatch Events to trigger a Lambda function that rotates the key
AnswerC

Automatic key rotation re-wraps the KMS key material annually without changing the key ID or ARN, so existing ciphertext and applications continue working. Enabling it on each customer managed key meets the yearly rotation requirement with no manual intervention.

Why this answer

AWS KMS supports automatic key rotation for customer-managed KMS keys. When enabled, KMS rotates the key material annually without requiring any manual intervention or application changes. This satisfies the security team's requirement for yearly rotation while maintaining the same key ID and existing encrypted data accessibility.

Exam trap

The trap here is that candidates may think manual rotation or creating a new key is required because they confuse KMS key rotation with S3 bucket key rotation or assume that automatic rotation changes the key ID, which would break references to the key.

How to eliminate wrong answers

Option A is wrong because manual rotation requires creating a new key and updating applications, which is error-prone and does not automatically re-encrypt existing data. Option B is wrong because creating a new KMS key and updating applications introduces operational overhead and does not rotate the existing key; it replaces it, potentially breaking access to previously encrypted data. Option D is wrong because AWS CloudWatch Events triggering a Lambda function is unnecessary and overly complex; KMS already provides a built-in, fully managed automatic rotation feature that does not require custom scripting or event-driven orchestration.

258
MCQeasy

A developer needs to generate temporary credentials for a user to access an S3 bucket for 30 minutes. Which AWS service should be used?

A.IAM role
B.Amazon Cognito
C.AWS Key Management Service (KMS)
D.AWS Security Token Service (STS)
AnswerD

AWS Security Token Service (STS) is the dedicated AWS service for creating and providing temporary, limited-privilege credentials for AWS users, federated users, or applications. Developers utilize STS API operations like AssumeRole, GetFederationToken, or GetSessionToken to obtain these credentials, which consist of an access key ID, a secret access key, and a session token. These temporary credentials can be configured with a specific duration, such as 30 minutes, making them ideal for secure, short-lived access to AWS resources.

Why this answer

AWS Security Token Service (STS) is the correct service for generating temporary, limited-privilege credentials to access AWS resources. It can issue credentials with a configurable expiration period, such as 30 minutes, via the AssumeRole API call. This directly meets the requirement for time-bound access to an S3 bucket.

Exam trap

The trap here is that candidates confuse IAM roles (a permission container) with the service that actually issues temporary credentials (STS), leading them to select Option A instead of D.

How to eliminate wrong answers

Option A is wrong because an IAM role is a set of permissions, not a mechanism to generate temporary credentials; you must use STS (e.g., AssumeRole) to obtain temporary credentials for a role. Option B is wrong because Amazon Cognito is designed for user identity and authentication in web/mobile apps, not for directly generating temporary AWS credentials for a single S3 bucket access scenario; it uses identity pools which rely on STS under the hood but adds unnecessary complexity. Option C is wrong because AWS Key Management Service (KMS) manages encryption keys and cannot generate any type of credentials, temporary or otherwise.

259
MCQmedium

A developer is running a web application on multiple Amazon EC2 instances behind an Application Load Balancer (ALB). The application needs to store user session state that must be available across all instances. The session data is small and temporary but must survive individual instance failures. Which AWS service should the developer use to store this session state?

A.Store session state in an Amazon ElastiCache cluster
B.Store session state in the /tmp directory of each EC2 instance
C.Use an Amazon SQS queue to persist session data
D.Store session state in an Amazon S3 bucket
AnswerA

Amazon ElastiCache provides a fully managed, in-memory caching service, making it an excellent choice for storing web application session state. By centralizing session data in an ElastiCache Redis or Memcached cluster, all EC2 instances can access and update the same session information, ensuring session stickiness and persistence even if a user's subsequent request is routed to a different instance. Its low-latency access and high availability features, including replication and automatic failover, are critical for responsive and resilient user experiences in distributed environments.

Why this answer

Amazon ElastiCache (e.g., using Redis or Memcached) provides a centralized, in-memory data store that is external to the EC2 instances. This allows all instances behind the ALB to read and write the same session state, ensuring consistency across the fleet. Because the data is stored in a managed cluster, it survives individual instance failures and is ideal for small, temporary session data that requires low-latency access.

Exam trap

The trap here is that candidates often confuse 'survive instance failures' with 'persistent storage' and choose S3 or SQS, overlooking that session state requires low-latency, in-memory access with automatic expiry, which only ElastiCache provides among the options.

How to eliminate wrong answers

Option B is wrong because storing session state in the /tmp directory of each EC2 instance is ephemeral—data is lost if the instance terminates or fails, and it is not shared across instances, breaking the requirement for cross-instance availability. Option C is wrong because Amazon SQS is a message queue service designed for decoupling and asynchronous communication, not for storing session state; it lacks the low-latency, key-value lookup capabilities needed for session management. Option D is wrong because Amazon S3 is an object storage service with higher latency and no built-in support for fast, atomic read/write operations on small session data, making it unsuitable for real-time session state storage.

260
MCQeasy

A developer needs to securely store database credentials for a Lambda function. The credentials should be automatically rotated every 30 days. Which AWS service should the developer use?

A.AWS Key Management Service (KMS) to encrypt the credentials.
B.Store the credentials in an IAM role's trust policy.
C.AWS Secrets Manager.
D.AWS Systems Manager Parameter Store with a SecureString parameter.
AnswerC

AWS Secrets Manager is the correct service for securely storing and managing database credentials because it is purpose-built for this task. It offers robust features like automatic rotation of credentials for supported databases, integration with other AWS services, and fine-grained access control. This automation significantly reduces the operational burden and enhances security by ensuring credentials are regularly updated without manual intervention.

Why this answer

AWS Secrets Manager is the correct choice because it is specifically designed to securely store, manage, and automatically rotate database credentials and other secrets. It supports native rotation of credentials for Amazon RDS, Redshift, and DocumentDB with built-in Lambda rotation functions, and can be configured to rotate on a schedule (e.g., every 30 days) without custom code. The service also integrates directly with Lambda via the AWS SDK to retrieve secrets at runtime, ensuring credentials are never hardcoded.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (which can store secrets with SecureString) with AWS Secrets Manager, but the key differentiator is that Secrets Manager provides built-in automatic rotation, which is explicitly required by the question.

How to eliminate wrong answers

Option A is wrong because AWS KMS is a key management service for encrypting data at rest, but it does not store credentials or provide automatic rotation; it only provides the encryption key, not the secret management lifecycle. Option B is wrong because IAM role trust policies define which principals can assume the role, not where to store credentials; storing credentials in a trust policy is not supported and would be a security risk. Option D is wrong because while Systems Manager Parameter Store with SecureString can store encrypted parameters, it does not natively support automatic rotation of credentials; you would need to build a custom rotation solution, whereas Secrets Manager provides built-in rotation capabilities.

261
Matchingmedium

Match each AWS security feature to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Temporary permissions for services

Stateful firewall for EC2

Web application firewall

DDoS protection

SSL/TLS certificate management

Why these pairings

The correct matches are IAM with access control, Security Groups with EC2 firewall, KMS with encryption key management, and CloudTrail with API auditing. Common confusions include mistaking IAM for CloudTrail and Security Groups for NACLs.

262
Multi-Selecthard

A company uses AWS CloudFormation to manage infrastructure. The development team wants to implement a CI/CD pipeline that automatically updates a CloudFormation stack when code is pushed to a CodeCommit repository. The pipeline should also run tests before deploying. Which THREE services should be used together to achieve this? (Choose THREE.)

Select 3 answers
A.AWS CodeBuild
B.Amazon CloudWatch Events
C.AWS CodeDeploy
D.AWS CodePipeline
E.AWS CodeCommit
AnswersA, D, E

In a CloudFormation CI/CD pipeline, AWS CodeBuild is crucial for validating templates using tools like `cfn-lint`, running unit tests on custom resources or Lambda functions, and packaging deployment artifacts. It can also be used to transform CloudFormation templates, for instance, by using `sam build` for SAM templates, before they are deployed. CodeBuild's compute environment executes commands defined in a `buildspec.yml` file, making it the workhorse for all pre-deployment processing and quality checks within the pipeline.

Why this answer

AWS CodeBuild is correct because it can compile source code, run tests, and produce artifacts that are ready for deployment. In this CI/CD pipeline, CodeBuild executes the test suite after code is pushed to CodeCommit, ensuring that only validated code proceeds to update the CloudFormation stack.

Exam trap

The trap here is that candidates may confuse AWS CodeDeploy with CloudFormation stack updates, but CodeDeploy handles application-level deployments (e.g., code to instances) while CloudFormation manages infrastructure provisioning and updates, so CodeDeploy is not used for stack updates in this context.

263
MCQhard

A company runs a web application on EC2 instances behind an Application Load Balancer. The application uses a PostgreSQL database on RDS. The security team requires that database credentials never be stored in application code or configuration files. Which solution meets this requirement?

A.Store the credentials in a Systems Manager Parameter Store parameter and retrieve them at application startup.
B.Store the credentials in an encrypted S3 bucket and have the application read the config file at startup.
C.Hardcode the credentials in a Lambda function that is called to get the credentials.
D.Use AWS Secrets Manager to store the credentials and retrieve them at runtime with automatic rotation.
AnswerD

AWS Secrets Manager is purpose-built for securely storing, managing, and retrieving database credentials, API keys, and other secrets throughout their lifecycle. It integrates directly with various AWS services and databases to provide robust automatic rotation, ensuring credentials are regularly updated without manual intervention. Retrieving secrets at runtime, rather than just at startup, minimizes the exposure window and allows for dynamic credential updates without requiring application restarts, significantly enhancing the overall security posture.

Why this answer

AWS Secrets Manager is designed specifically for securely storing and automatically rotating database credentials. It integrates natively with RDS for PostgreSQL, enabling automatic rotation without code changes. The application retrieves credentials at runtime via the AWS SDK, ensuring they are never stored in code or configuration files.

Exam trap

The trap here is that candidates confuse Systems Manager Parameter Store (which can store secrets but lacks automatic rotation) with Secrets Manager, leading them to choose Option A despite the rotation requirement.

How to eliminate wrong answers

Option A is wrong because Systems Manager Parameter Store does not natively support automatic rotation of RDS credentials; it is a parameter store, not a secrets manager with built-in rotation. Option B is wrong because storing credentials in an S3 bucket, even encrypted, still requires the application to read a configuration file at startup, which violates the requirement that credentials never be stored in configuration files. Option C is wrong because hardcoding credentials in a Lambda function still stores them in code, which is explicitly prohibited by the security requirement.

264
Multi-Selectmedium

Which TWO actions can improve the performance of an Amazon DynamoDB table that experiences frequent throttling due to hot partitions? (Choose TWO.)

Select 2 answers
A.Disable auto scaling to provision fixed capacity
B.Enable DynamoDB Accelerator (DAX) for caching
C.Increase the read capacity units (RCUs) of the table
D.Add a random suffix to the partition key values
E.Use a global secondary index (GSI) with a different partition key
AnswersB, D

Enabling DynamoDB Accelerator (DAX) significantly improves read performance by providing an in-memory cache for frequently accessed data. DAX intercepts read requests before they reach the DynamoDB table, serving cached items with microsecond latency. This drastically reduces the read load on the underlying DynamoDB table, effectively mitigating read-related throttling issues and enhancing application responsiveness for read-intensive workloads.

Why this answer

DynamoDB Accelerator (DAX) is an in-memory cache that reduces the number of read requests hitting the underlying table, thereby alleviating pressure on hot partitions. By serving frequently accessed items from DAX, the table experiences fewer throttled read requests, improving overall performance without changing the data model.

Exam trap

The trap here is that candidates often assume increasing provisioned capacity (RCUs/WCUs) will solve throttling, but they overlook the partition-level throughput limit that makes hot partitions a distribution problem, not a capacity problem.

265
MCQhard

A developer is using IAM roles for Amazon EC2 to grant permissions to an application. The application makes API calls to DynamoDB and S3. After deploying, the application fails to access DynamoDB. The developer verifies the IAM role has the correct DynamoDB permissions. What is the most likely cause?

A.The IAM role does not have a trust policy for EC2.
B.The IAM role is not attached to the EC2 instance profile.
C.The DynamoDB table is in a different region than the EC2 instance.
D.The application is using the wrong AWS SDK.
AnswerB

An IAM role cannot be directly attached to an EC2 instance; it must be associated via an Instance Profile. The Instance Profile acts as a container for the IAM role, making its temporary credentials available to applications running on the EC2 instance through the instance metadata service. If the IAM role is not correctly embedded within an Instance Profile and that profile is not attached to the EC2 instance, the application will lack the necessary credentials to assume the role and perform actions like accessing DynamoDB.

Why this answer

For an EC2 instance to use an IAM role, the role must be attached to an EC2 instance profile, which is the container that passes the role's credentials to the instance via the instance metadata service. Even if the IAM role has the correct DynamoDB permissions, if it is not associated with the instance profile, the application will not receive temporary credentials and will fail to access DynamoDB.

Exam trap

The trap here is that candidates assume simply having the correct IAM role with proper permissions is sufficient, overlooking the mandatory step of attaching the role to an EC2 instance profile for credential delivery.

How to eliminate wrong answers

Option A is wrong because the IAM role does have a trust policy for EC2 (it must, otherwise the role could not be assumed by EC2 at all); the issue is the lack of attachment to the instance profile. Option C is wrong because DynamoDB is a global service that can be accessed across regions via its global endpoints, and region mismatch does not cause access failures when permissions are correct. Option D is wrong because the AWS SDK automatically handles credential retrieval from the instance metadata service; using a different SDK version or language does not prevent credential resolution if the role is properly attached.

266
Multi-Selecthard

A developer is deploying a serverless application using the AWS Serverless Application Model (SAM). The application includes an API Gateway REST API and a Lambda function. The developer wants to enable access logging for the API Gateway. Which THREE resources or configurations are required? (Choose THREE.)

Select 3 answers
A.A stage with access logging enabled in the API Gateway.
B.A Lambda function that processes the access logs.
C.An IAM role that grants API Gateway permission to write to CloudWatch Logs.
D.An Amazon CloudWatch Logs log group.
E.An IAM role for the Lambda function with logs:PutLogEvents permission.
AnswersA, C, D

Enabling access logging on a specific API Gateway stage is a fundamental configuration step for capturing API traffic. This setting dictates that API Gateway will generate detailed information about every request and response passing through that stage, including caller IP, request latency, and response status. Without this explicit enablement on the stage, no access logs will be generated, regardless of other logging infrastructure being in place. Therefore, it is a prerequisite for any access logging functionality.

Why this answer

API Gateway access logging is configured at the stage level. The developer must enable access logging on a specific stage (e.g., prod, dev) and specify a destination CloudWatch Logs log group and a logging format (e.g., JSON or CLF). Without enabling it on the stage, no access logs are generated regardless of other configurations.

Exam trap

The trap here is that candidates often confuse the IAM role needed for API Gateway to write logs (Option C) with the Lambda execution role (Option E), or incorrectly think a Lambda function must process the logs (Option B) when API Gateway writes them directly to CloudWatch Logs.

267
MCQhard

A developer is configuring cross-account access for an S3 bucket. The source account (111111111111) wants to allow the target account (222222222222) to write objects to the bucket. The developer attaches the following bucket policy to the bucket in the source account: { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::222222222222:root" }, "Action": "s3:PutObject", "Resource": "arn:aws:s3:::example-bucket/*" } ] } However, the write operation fails with AccessDenied. What is the most likely cause?

A.The target account has not attached an IAM policy granting the user or role s3:PutObject
B.The bucket has an S3 ACL that denies the target account
C.The bucket policy does not allow s3:PutObject for the target account
D.The bucket is encrypted with SSE-KMS and the target account lacks KMS permissions
AnswerA

For successful cross-account access to an S3 bucket, both the resource-based policy (the S3 bucket policy) on the target bucket AND an identity-based policy (IAM policy) attached to the user or role in the requesting (target) account must explicitly grant the necessary permissions. Even if the bucket policy allows the action, the requesting IAM principal must also have an IAM policy allowing it to perform s3:PutObject. This "two-policy" evaluation model ensures comprehensive security, making this the correct reason for denial if the IAM policy is missing.

Why this answer

Cross-account S3 access requires both a bucket policy that grants the target account principal (or a resource-based policy) AND an IAM policy in the target account that explicitly allows the user or role to perform the s3:PutObject action. Without the target account's IAM policy, the request is denied even if the bucket policy permits it, as the target account's principal lacks the necessary permissions to make the call.

Exam trap

The trap here is that candidates assume a bucket policy alone is sufficient for cross-account access, overlooking the requirement for an IAM policy in the target account to authorize the principal making the request.

How to eliminate wrong answers

Option B is wrong because S3 ACLs are legacy and, while they can grant cross-account permissions, the bucket policy is the primary mechanism here; an ACL denying the target account would cause a different error (e.g., AccessDenied with a different message) but is not the most likely cause given the bucket policy is already in place. Option C is wrong because the question states the developer attaches the bucket policy to allow the target account to write objects, so the bucket policy presumably includes s3:PutObject; if it didn't, the error would be expected, but the most likely cause is the missing IAM policy in the target account. Option D is wrong because SSE-KMS requires additional KMS key permissions (kms:GenerateDataKey, kms:Decrypt) for the target account, but the error would be a KMS-related AccessDenied, not a generic s3:PutObject failure; the question does not mention KMS, so this is less likely than the missing IAM policy.

268
MCQmedium

A developer is writing a Lambda function that processes events from an Amazon S3 bucket. The function needs to access a DynamoDB table to store metadata about the S3 objects. Which of the following is the MOST efficient way to initialize the DynamoDB client in the Lambda function?

A.Store the DynamoDB table name as a global variable and create the client inside the handler.
B.Use a static variable inside the handler to cache the DynamoDB client.
C.Create the DynamoDB client inside the Lambda handler function every invocation.
D.Create the DynamoDB client outside the Lambda handler function, in the global scope.
AnswerD

Creating the DynamoDB client outside the Lambda handler function, in the global scope, is the recommended best practice for optimizing Lambda performance. This ensures the client is initialized only once when the Lambda execution environment is first created during a cold start. For subsequent 'warm' invocations within the same execution environment, the pre-initialized client is reused, significantly reducing latency by avoiding repeated client setup overhead and connection establishment.

Why this answer

Initializing the DynamoDB client outside the Lambda handler (in global scope) allows the client to be reused across multiple invocations within the same execution environment. This avoids the overhead of creating a new client on every invocation, which reduces latency and conserves resources. AWS Lambda reuses the global scope for subsequent invocations after the first, making this the most efficient approach.

Exam trap

The trap here is that candidates may think creating the client inside the handler is safer for avoiding stale connections, but AWS Lambda's execution environment reuse makes global initialization both safe and more efficient.

How to eliminate wrong answers

Option A is wrong because storing the table name as a global variable is acceptable, but creating the client inside the handler on every invocation still incurs unnecessary initialization overhead. Option B is wrong because using a static variable inside the handler does not prevent the client from being recreated on each invocation; static variables in Python are effectively global but the client creation inside the handler still runs on every call. Option C is wrong because creating the DynamoDB client inside the handler on every invocation wastes time and resources, as the client could be reused across invocations in the same execution environment.

269
MCQmedium

A developer monitors an AWS Lambda function that processes messages from an Amazon SQS queue. CloudWatch logs show that the function's execution time has increased significantly over the past week, and it now frequently times out at the 5-minute timeout. The function's code has not been changed recently. The function makes calls to an Amazon DynamoDB table. What is the most likely cause of the increased execution time?

A.The DynamoDB table's read capacity units are underprovisioned, causing throttling.
B.The SQS queue's visibility timeout is too short, causing duplicate processing.
C.The Lambda function's memory is too low, causing CPU throttling.
D.The DynamoDB table's indexes are missing, causing full table scans.
AnswerA

When a Lambda function attempts to read from a DynamoDB table with insufficient Read Capacity Units (RCUs), DynamoDB will throttle the requests. This throttling results in ProvisionedThroughputExceededException errors, forcing the Lambda function to implement retry logic, which significantly prolongs its execution time. Repeated retries against a persistently throttled table can cause the function to approach or exceed its configured timeout, indicating a clear resource bottleneck.

Why this answer

The most likely cause is that the DynamoDB table's read capacity units are underprovisioned, leading to throttling (ProvisionedThroughputExceededException). When DynamoDB throttles requests, the Lambda function must retry them, which adds latency and can cause the function to exceed its 5-minute timeout. Since the code hasn't changed, this points to a scaling or capacity issue on the DynamoDB side.

Exam trap

The trap here is that candidates may confuse DynamoDB throttling with Lambda timeout configuration, overlooking that gradual performance degradation often points to downstream resource contention rather than function configuration.

How to eliminate wrong answers

Option B is wrong because a short SQS visibility timeout would cause duplicate processing, not increased execution time; duplicates would result in more invocations, not slower individual runs. Option C is wrong because low memory in Lambda causes CPU throttling only if the function is CPU-bound; memory allocation affects CPU proportionally, but the described symptom (increased execution time without code changes) is not typically caused by memory alone. Option D is wrong because missing indexes would cause full table scans, which would increase execution time from the start, not gradually over a week; this would be a code or schema issue, not a gradual degradation.

270
MCQhard

A developer deployed a new version of an AWS Lambda function that is part of a serverless application. The function uses an Amazon DynamoDB table as a data store. After deployment, the developer notices that the function's latency has increased significantly for some requests. CloudWatch traces show that the increase is due to DynamoDB throttle events. The function is configured with a reserved concurrency of 100 and the DynamoDB table has 5 read capacity units (RCUs) and 5 write capacity units (WCUs). What is the most effective way to reduce the throttling while maintaining application performance?

A.Decrease the reserved concurrency of the Lambda function to 10
B.Increase the read and write capacity units on the DynamoDB table
C.Enable DynamoDB Accelerator (DAX) for caching reads
D.Enable auto scaling on the DynamoDB table
AnswerB

Increasing the read and write capacity units (RCU/WCU) on the DynamoDB table directly raises its maximum sustained throughput. These units define the number of strongly consistent reads and 1KB writes the table can handle per second. By provisioning more capacity, the table can accommodate a higher volume of operations, directly mitigating throttling errors that occur when request rates exceed the current limits.

Why this answer

The primary cause of the throttling is insufficient DynamoDB capacity to handle the request volume from the Lambda function. Increasing the read and write capacity units (RCUs/WCUs) directly addresses the throttle events by providing more throughput to match the function's concurrency of 100. This is the most effective solution because it resolves the bottleneck at the data store level without reducing the application's ability to process requests concurrently.

Exam trap

The trap here is that candidates may choose auto scaling (Option D) thinking it dynamically handles spikes, but they overlook that auto scaling has a significant lag and cannot prevent immediate throttling, whereas increasing the base capacity is the immediate and effective solution.

How to eliminate wrong answers

Option A is wrong because decreasing reserved concurrency to 10 would reduce the number of concurrent Lambda invocations, which would lower the request rate to DynamoDB and potentially reduce throttling, but it would also severely degrade application performance by limiting throughput and increasing latency for legitimate traffic. Option C is wrong because DynamoDB Accelerator (DAX) is an in-memory cache that only accelerates read operations (GetItem, Query, Scan) and does not help with write throttling or reduce write capacity consumption; the question does not specify that the throttling is read-only, and DAX cannot mitigate write capacity throttling. Option D is wrong because enabling auto scaling on the DynamoDB table would adjust capacity over time based on traffic patterns, but it cannot react instantly to sudden spikes in demand; auto scaling has a lag of several minutes, so it would not prevent the immediate throttle events that are already occurring, and it does not address the need for a higher baseline capacity to match the Lambda's concurrency.

271
MCQmedium

A company runs a web application on EC2 instances behind an Application Load Balancer (ALB). Users report intermittent 503 errors. The ALB health checks are failing for a few instances, but the instances themselves are running and have healthy application processes. What is the MOST likely cause?

A.The ALB is not scaled to handle the traffic.
B.The security group for the EC2 instances is not allowing traffic from the ALB.
C.The DNS resolution via Route53 is misconfigured.
D.Sticky sessions are not enabled on the ALB.
AnswerB

The security group associated with the EC2 instances acts as a virtual firewall, controlling inbound and outbound traffic. For ALB health checks to succeed, the EC2 instance's security group must have an inbound rule that explicitly permits traffic from the ALB's security group or its private IP range on the health check port. If this rule is missing or misconfigured, the ALB's health check probes will be blocked at the network level, preventing a successful connection and causing the ALB to mark the instance as unhealthy.

Why this answer

The ALB health checks are failing despite the instances and application processes being healthy, which indicates a network-level issue. The most likely cause is that the EC2 instances' security group is not allowing inbound traffic from the ALB's security group on the health check port (e.g., HTTP/HTTPS). Without this rule, the ALB cannot reach the health check endpoint, marking the instances as unhealthy and causing intermittent 503 errors when traffic is routed to those instances.

Exam trap

The trap here is that candidates often assume health check failures are always due to application issues (e.g., process crashes) rather than network-layer misconfigurations like security group rules, especially when the instance appears healthy from within the OS.

How to eliminate wrong answers

Option A is wrong because the ALB scales automatically based on traffic patterns and does not require manual scaling; 503 errors from insufficient capacity would be persistent, not intermittent, and would affect all instances. Option C is wrong because DNS misconfiguration via Route53 would cause resolution failures (e.g., NXDOMAIN) or routing to the wrong endpoint, not intermittent 503 errors from healthy instances behind an ALB. Option D is wrong because sticky sessions (session affinity) do not affect health checks or 503 errors; they only control how requests are distributed to the same target, and their absence would not cause health check failures.

272
MCQhard

A developer receives an Access Denied error when trying to download an object from an S3 bucket. The developer's IAM policy is shown in the exhibit. The bucket policy also grants access. What is the MOST likely cause?

A.The S3 bucket has block public access enabled.
B.The S3 bucket uses SSE-KMS and the user lacks kms:Decrypt permission.
C.The IAM policy does not allow s3:GetObject.
D.The bucket policy denies access to the user.
AnswerB

When an object is encrypted with SSE-KMS, retrieving it requires not only s3:GetObject permission on the object but also kms:Decrypt permission on the specific KMS key used to encrypt it; if the IAM policy grants only the S3 action and omits the KMS action, the decrypt call fails and S3 surfaces this as an Access Denied error even though the S3-level permissions look correct.

Why this answer

If the bucket is encrypted with a KMS key, the user must also have kms:Decrypt permission. Option A is wrong because the policy explicitly allows s3:GetObject. Option C is wrong because the bucket policy also grants access, so it's not a bucket policy issue.

Option D is wrong because public access is not required if IAM policies allow access.

273
Multi-Selecteasy

A developer is designing a serverless application using AWS Lambda. The function needs to process messages from an Amazon SQS queue. The developer wants to configure the Lambda function to be triggered by the SQS queue. Which TWO actions are required? (Choose TWO.)

Select 2 answers
A.Attach an IAM execution role to Lambda with permission to receive messages from SQS.
B.Configure a resource-based policy on the SQS queue to allow Lambda invocation.
C.Create an event source mapping in Lambda to poll the SQS queue.
D.Set up a dead-letter queue for failed messages.
E.Place the Lambda function in a VPC to access the SQS queue.
AnswersA, C

The Lambda function's IAM execution role must include permissions such as sqs:ReceiveMessage, sqs:DeleteMessage, and sqs:GetQueueAttributes. These permissions are essential for the Lambda service, acting on behalf of the function, to successfully poll the SQS queue, retrieve messages, and then delete them after successful processing. Without these explicit permissions, the Lambda function would be unable to interact with the SQS queue as an event source, preventing message consumption.

Why this answer

Option A is correct because the Lambda function's IAM execution role must grant permissions such as sqs:ReceiveMessage, sqs:DeleteMessage, and sqs:GetQueueAttributes so the service can poll and consume messages from the SQS queue on the function's behalf. Option C is correct because SQS is a pull-based source, so you must create an event source mapping that tells the Lambda service to poll the queue, batch records, and invoke the function with those messages. Option B is not required because SQS integration uses the execution role for polling rather than a resource-based policy invoking Lambda directly, as would be the case for push-based sources like S3 or SNS.

Option D is not required, though a dead-letter queue or Lambda destinations can optionally handle failed messages. Option E is not required because Lambda can reach SQS over the AWS network without being placed in a VPC.

Exam trap

Candidates often confuse the integration pattern of SQS with push-based services like S3 or SNS. For S3 or SNS, you must configure a resource-based policy on the Lambda function to allow the service to invoke it. For SQS, Lambda uses an Event Source Mapping (polling model) where the Lambda service polls SQS using the Lambda function's execution role, meaning no resource-based policies are needed on either side.

274
Multi-Selecthard

A developer is using AWS Secrets Manager to rotate database credentials. The rotation Lambda function fails with an error. Which THREE steps should the developer take to troubleshoot? (Choose THREE.)

Select 3 answers
A.Check VPC Flow Logs for the Lambda function's ENI.
B.Verify that the Lambda function has network access to the database.
C.Ensure the KMS key used to encrypt the secret is rotated.
D.Verify that the Lambda function's IAM role has permission to update the secret.
E.Check the CloudWatch Logs for the Lambda function.
AnswersB, D, E

For the Lambda function to successfully rotate database credentials, it must establish a network connection to the database instance. If the database resides within a VPC, the Lambda function must be configured to execute within that same VPC or a peered VPC, with appropriate security groups and network ACLs allowing outbound connections to the database's port and inbound connections from the Lambda's Elastic Network Interface (ENI). Lack of network reachability is a common cause of rotation failures.

Why this answer

The Lambda function must have network access to the database to perform the rotation (e.g., connecting to the database to change the password). Without network connectivity, the rotation cannot complete. Option D is correct because the Lambda function's IAM role needs permission to call `secretsmanager:PutSecretValue` and `secretsmanager:GetSecretValue` to update the secret in Secrets Manager.

Option E is correct because CloudWatch Logs capture the Lambda function's execution output, including any error messages, stack traces, or logs from the rotation logic, which are essential for diagnosing failures.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (which show network traffic) with CloudWatch Logs (which show application logs), and they may think that rotating the KMS key is necessary for secret rotation, when in fact KMS key rotation is automatic and unrelated to the rotation process.

275
MCQhard

A developer is designing a serverless application that processes images uploaded to an S3 bucket. Each image must be resized and then stored in a different S3 bucket. The process must be asynchronous and fault-tolerant. Which AWS service should trigger the Lambda function?

A.Amazon S3 Event Notifications
B.Amazon SQS
C.Amazon API Gateway
D.AWS Step Functions
AnswerA

Amazon S3 Event Notifications are the native mechanism for S3 buckets to publish events, such as object creation (s3:ObjectCreated:*), to various destinations. These notifications can directly invoke AWS Lambda functions asynchronously, providing a highly scalable and decoupled way to trigger serverless processing whenever new data arrives in an S3 bucket. This direct integration eliminates the need for intermediary services for simple object-triggered workflows, making it the most suitable and efficient choice for this scenario.

Why this answer

Amazon S3 Event Notifications are the correct trigger because they natively support event-driven architectures where S3 object creation events (e.g., s3:ObjectCreated:Put) can directly invoke a Lambda function. This enables asynchronous processing of uploaded images without any intermediate polling or custom integration, ensuring fault tolerance through Lambda's built-in retry mechanism and dead-letter queue (DLQ) support.

Exam trap

The trap here is that candidates often confuse the service that triggers the Lambda (S3 Event Notifications) with the service that stores or routes the event data (SQS or Step Functions), leading them to pick an option that adds unnecessary complexity or is designed for a different use case.

How to eliminate wrong answers

Option B (Amazon SQS) is wrong because SQS is a message queue service that requires a separate producer to send messages; while S3 can publish events to SQS, the question asks for the service that triggers the Lambda function, and SQS itself does not trigger Lambda unless configured as an event source mapping, which adds unnecessary complexity for a direct S3-to-Lambda use case. Option C (Amazon API Gateway) is wrong because API Gateway is designed for creating RESTful or WebSocket APIs to handle synchronous HTTP requests, not for reacting to S3 object creation events asynchronously. Option D (AWS Step Functions) is wrong because Step Functions is a workflow orchestration service that coordinates multiple AWS services, not a direct trigger for Lambda; using it here would introduce an unnecessary orchestration layer when a simple S3 event notification suffices.

276
MCQhard

A developer is troubleshooting an AWS Lambda function that experiences high latency for the first few invocations after being idle. The function is written in Python and uses a large library (e.g., Pandas). The function connects to an RDS database in a VPC. What is the most effective way to reduce the latency for the first invocation after idle?

A.Increase the function's memory allocation to 3008 MB.
B.Enable provisioned concurrency on the function.
C.Move the large library to a Lambda layer.
D.Replace the RDS database with Amazon DynamoDB.
AnswerB

Provisioned concurrency pre-initializes a specified number of execution environments for a Lambda function, ensuring they are ready to process requests immediately. This effectively eliminates cold start latency for invocations routed to these pre-warmed instances, as the entire initialization phase (including code download, runtime bootstrapping, and `init` code execution) has already completed. It guarantees consistently low latency for critical, latency-sensitive applications by maintaining a pool of ready-to-go containers.

Why this answer

Provisioned concurrency keeps a specified number of execution environments initialized and ready to respond immediately, eliminating the cold start latency that occurs after a period of idle time. This is the most direct solution for reducing latency on the first invocation after idle, especially for functions with large libraries like Pandas that take significant time to load.

Exam trap

The trap here is that candidates often confuse cold start mitigation strategies like increasing memory or using layers with the only AWS feature that truly eliminates cold starts for idle functions: provisioned concurrency.

How to eliminate wrong answers

Option A is wrong because increasing memory allocation can improve CPU performance and reduce cold start time slightly, but it does not eliminate the cold start itself; the function still needs to load the large library and establish the VPC connection from scratch after idle. Option C is wrong because moving the library to a Lambda layer does not reduce cold start latency; layers are simply a packaging mechanism and the library still must be loaded into memory during initialization. Option D is wrong because replacing RDS with DynamoDB addresses database connection latency, not the cold start latency caused by loading the large Python library and initializing the function runtime.

277
Multi-Selectmedium

A company is using AWS KMS to encrypt data in S3. Which TWO actions are required to allow an IAM user to decrypt objects in a specific S3 bucket?

Select 2 answers
A.Attach a policy to the user allowing s3:GetObject on the bucket.
B.Attach a policy to the user allowing kms:Encrypt.
C.Attach a policy to the user allowing s3:PutObject.
D.Attach a policy to the user allowing kms:GenerateDataKey.
E.Attach a policy to the user allowing kms:Decrypt on the KMS key.
AnswersA, E

To retrieve any object from an S3 bucket, regardless of its encryption status, the principal (user or role) must have explicit permission to perform the s3:GetObject action. This action grants the ability to download the object's data, which is a fundamental prerequisite before any decryption process can even begin. Without this permission, S3 will deny the request to access the object entirely, making decryption impossible.

Why this answer

To decrypt an object stored in S3 using server-side encryption with AWS KMS (SSE-KMS), the IAM user must have the s3:GetObject permission to retrieve the encrypted object from the bucket. Without this permission, the user cannot even initiate the GetObject request, regardless of KMS permissions.

Exam trap

The trap here is that candidates often forget that decrypting an SSE-KMS encrypted object requires both S3 read permissions and KMS decrypt permissions, leading them to select only one of the two required actions.

278
MCQmedium

A developer notices that an AWS Lambda function processing S3 events is being retried frequently due to throttling errors from Amazon DynamoDB. The function writes records to a DynamoDB table and has reserved concurrency set to 100. The DynamoDB table uses on-demand capacity mode. What should the developer do to reduce retries and improve overall throughput?

A.Increase the Lambda function's reserved concurrency to 500.
B.Implement exponential backoff and retry in the Lambda function code for DynamoDB API calls.
C.Disable the Lambda function's S3 event source mapping and use Amazon SQS to buffer events.
D.Switch the DynamoDB table to provisioned capacity with a high write capacity unit setting.
AnswerB

Implementing exponential backoff and retry in the Lambda function code for DynamoDB API calls is the most effective solution. This pattern automatically handles transient errors like throttling by retrying failed requests with progressively longer delays between attempts. This approach allows DynamoDB time to recover from temporary capacity constraints, significantly increasing the success rate of API calls without overwhelming the database, thus making the Lambda function more resilient.

Why this answer

Implementing exponential backoff and retry in the Lambda function code for DynamoDB API calls directly addresses the throttling errors. Even with on-demand capacity, DynamoDB can throttle requests if they exceed the table's burst capacity or if there are hot partitions. Exponential backoff reduces the retry rate, allowing DynamoDB to recover and improving overall throughput without changing the Lambda concurrency or capacity mode.

Exam trap

The trap here is that candidates assume increasing Lambda concurrency or switching to provisioned capacity will solve throttling, but the real issue is the retry strategy at the application layer, not the infrastructure scaling.

How to eliminate wrong answers

Option A is wrong because increasing reserved concurrency to 500 would only increase the number of concurrent Lambda invocations, which would exacerbate DynamoDB throttling by sending more requests simultaneously. Option C is wrong because disabling the S3 event source mapping and using SQS to buffer events would add latency and complexity but does not address the root cause of DynamoDB throttling; it only decouples the invocation, not the write errors. Option D is wrong because switching to provisioned capacity with a high write capacity unit setting does not guarantee elimination of throttling; on-demand mode already scales automatically, and the issue is likely due to request patterns or hot partitions, not capacity mode.

279
MCQmedium

A developer is deploying a web application using AWS Elastic Beanstalk. The application needs to store session state. The developer wants to ensure that session data is not lost if an EC2 instance is terminated. Which solution should the developer implement?

A.Store session data in an Amazon EBS volume.
B.Store session data in an Amazon S3 bucket.
C.Store session data in the instance store.
D.Store session data in an Amazon ElastiCache cluster.
AnswerD

Amazon ElastiCache, particularly when configured with Redis, provides a highly scalable, in-memory data store offering extremely low-latency read and write access essential for responsive session management. It supports high availability through replication and automatic failover, ensuring session data persistence and resilience against node failures. This centralized caching layer allows multiple web servers to efficiently share and access session state, enabling stateless application design crucial for scalability and seamless user experience across instances.

Why this answer

Amazon ElastiCache provides a managed, highly available, and durable in-memory cache that can store session state externally from EC2 instances. By using ElastiCache (e.g., Redis with replication and persistence), session data survives instance termination because it is stored in a separate, resilient service, not on the local instance.

Exam trap

The trap here is that candidates often confuse persistent storage (EBS) with shared, low-latency session storage, failing to recognize that EBS volumes are instance-attached and not designed for cross-instance session sharing, while ElastiCache provides the necessary distributed, in-memory session store.

How to eliminate wrong answers

Option A is wrong because an Amazon EBS volume is tied to a single Availability Zone and, while persistent, it is attached to a specific EC2 instance; if the instance is terminated, the EBS volume may be detached but the session data is not automatically shared across instances and requires manual reattachment, making it unsuitable for stateless session management. Option B is wrong because Amazon S3 is an object storage service designed for large, static objects and high-latency access; it is not optimized for low-latency session state reads/writes and incurs significant overhead per request, making it impractical for real-time session handling. Option C is wrong because the instance store provides temporary, block-level storage that is physically attached to the host computer; data is lost when the instance is stopped, terminated, or fails, directly contradicting the requirement to preserve session data after instance termination.

280
Multi-Selectmedium

A company uses AWS Organizations with multiple accounts. The security team wants to enforce that all S3 buckets are encrypted with AES-256 (SSE-S3) and that no public access is allowed. Which TWO methods can be used to enforce these requirements across all accounts? (Choose TWO.)

Select 2 answers
A.Use AWS Config rules with automatic remediation to detect and fix non-compliant buckets.
B.Attach an IAM policy to all IAM users in each account that denies unencrypted operations.
C.Use an SCP in the root organizational unit to deny 's3:PutBucketPublicAccessBlock' and enforce encryption settings.
D.Enable AWS CloudTrail to log all S3 API calls and send alerts.
E.Use AWS Trusted Advisor to check for unencrypted buckets.
AnswersA, C

AWS Config rules continuously evaluate S3 buckets against predefined or custom compliance standards, such as requiring server-side encryption or blocking public access. When a non-compliant bucket is detected, Config can automatically trigger remediation actions, like applying a default encryption policy or enabling S3 Block Public Access, ensuring ongoing adherence to security policies across all accounts where the rule is deployed. This proactive approach ensures that any newly created or modified non-compliant buckets are swiftly brought into compliance without manual intervention.

Why this answer

AWS Config rules can evaluate S3 bucket configurations against desired settings (e.g., encryption enabled, public access blocked) and trigger automatic remediation via AWS Systems Manager Automation documents to fix non-compliant buckets. This provides continuous enforcement across all accounts in the organization without manual intervention.

Exam trap

The trap here is that candidates often confuse SCPs with IAM policies, thinking SCPs can grant permissions (they only deny), or they assume CloudTrail or Trusted Advisor can enforce security requirements when they are only detective or advisory tools.

281
Multi-Selectmedium

A company is implementing a CI/CD pipeline using AWS CodeCommit, CodeBuild, and CodeDeploy. The developer wants to ensure that the pipeline automatically deploys to production only after a manual approval step. Which TWO actions should the developer take?

Select 2 answers
A.Create a CloudWatch Events rule to trigger a Lambda function that waits for approval.
B.Add a manual approval action in the CodePipeline pipeline.
C.Configure the approval action to require a specified IAM user or group to approve.
D.Use a CodeDeploy lifecycle hook to pause the deployment.
E.Configure an SNS topic to send an email to the approver.
AnswersB, C

Adding a manual approval action in the CodePipeline pipeline is the standard and correct way to introduce a human approval gate. When the pipeline reaches this action, it automatically pauses and waits for an authorized user to approve or reject via the AWS Management Console, CLI, or SDK (using the ApproveManualApproval or RejectManualApproval APIs). This native action supports IAM-based access control, optional SNS notifications, and an auditable approval history, and it integrates directly with the pipeline's state machine.

Why this answer

Option B is correct because AWS CodePipeline natively supports a manual approval action that pauses the pipeline at a chosen stage until an approver acts, which is exactly the mechanism needed to gate production deployments. Option C is correct because the manual approval action can be configured with an IAM principal (user, role, or group) whose members are authorized to approve or reject, enforcing controlled authorization for the production gate. Option A is not appropriate because a CloudWatch Events rule invoking a Lambda function is an event-driven workaround, not the built-in approval mechanism, and Lambda cannot natively 'wait' for human approval without complex polling.

Option D is incorrect because CodeDeploy lifecycle hooks pause during a deployment for scripts or validation, not for a human approval gate before the deployment stage. Option E is incorrect because an SNS topic can notify approvers of a pending approval, but notification alone does not implement the required approval gate.

Exam trap

DVA-C02 often tests whether candidates know that CodePipeline has a built-in manual approval action, tempting them to build custom Lambda/SNS approval workflows that are unnecessary and do not actually gate the pipeline.

282
MCQhard

A developer is using Amazon DynamoDB to store session data for a web application. The application reads and writes a single item per user session. The traffic pattern shows occasional spikes. The developer wants to minimize read and write costs. Which DynamoDB capacity mode should the developer choose?

A.Reserved capacity
B.On-demand capacity
C.Provisioned capacity with manual scaling
D.Provisioned capacity with auto scaling
AnswerB

DynamoDB On-demand capacity mode is specifically designed for workloads with unpredictable traffic patterns and sudden, sharp spikes. It operates on a pay-per-request model, automatically scaling throughput up or down instantly to accommodate actual traffic volume without requiring any capacity planning. This eliminates the risk of throttling during peak loads and avoids over-provisioning during quiet periods, making it ideal for highly variable session data.

Why this answer

On-demand capacity mode is ideal for unpredictable traffic patterns with occasional spikes because it automatically scales read and write throughput based on actual usage, charging only for consumed operations. Since the application reads and writes a single item per session and experiences spikes, on-demand eliminates the need to provision for peak capacity, minimizing costs compared to over-provisioning.

Exam trap

The trap here is that candidates may confuse 'Reserved capacity' with a valid DynamoDB option or assume that auto scaling (Option D) is always the cheapest for variable traffic, but on-demand is specifically designed for unpredictable spikes to avoid over-provisioning costs and throttling.

How to eliminate wrong answers

Option A is wrong because DynamoDB does not offer a 'Reserved capacity' pricing model; that concept applies to services like Amazon EC2 or RDS, not DynamoDB. Option C is wrong because provisioned capacity with manual scaling requires you to predict and manually adjust capacity for spikes, which risks either throttling during spikes or over-provisioning and higher costs during low traffic. Option D is wrong because provisioned capacity with auto scaling still requires you to set a minimum and maximum capacity, and during sudden spikes, auto scaling may lag behind, causing throttling or requiring over-provisioning to avoid it, whereas on-demand handles spikes instantly without configuration.

283
MCQeasy

A developer is troubleshooting an AWS Lambda function that is failing with an 'AccessDenied' error when trying to write to an S3 bucket. The function's execution role has the following policy. What is the most likely cause of the failure? (Policy: { 'Version': '2012-10-17', 'Statement': [ { 'Effect': 'Allow', 'Action': 's3:PutObject', 'Resource': 'arn:aws:s3:::my-bucket/*' } ] })

A.The resource ARN does not include the bucket itself; it only includes objects
B.The S3 bucket has a bucket policy that denies the Lambda role access.
C.The action 's3:PutObject' is not allowed for Lambda execution roles
D.The action 's3:PutObject' is not sufficient; need 's3:*'
AnswerB

AWS policy evaluation logic dictates that an explicit `Deny` statement in any policy always overrides an `Allow` statement, even if the `Allow` is present in an identity-based policy attached to the Lambda execution role. If the S3 bucket's resource policy explicitly denies the Lambda role access for `s3:PutObject`, this denial will take precedence, preventing the Lambda function from uploading objects despite its own role permissions. This is a common security control for resource owners.

Why this answer

The IAM policy attached to the Lambda execution role correctly allows s3:PutObject on the bucket's objects. However, when a bucket policy explicitly denies access to the role or does not grant the required permissions, it takes precedence over the identity-based policy, resulting in an 'AccessDenied' error. Therefore, the most likely cause is a restrictive bucket policy.

Exam trap

Candidates often focus solely on the identity-based policy and forget that a bucket policy can override it. Even with a correctly scoped role policy, a bucket policy denying access will cause AccessDenied.

284
MCQhard

The exhibit shows an IAM policy attached to a Lambda function's execution role. The function writes objects to an S3 bucket that is encrypted with a KMS key (the key specified in the policy). When the function tries to write an object, it receives an access denied error. What is the MOST likely missing permission?

A.kms:GenerateDataKey is missing.
B.The KMS key policy does not allow the Lambda function role.
C.s3:GetObject is missing for the bucket.
D.kms:ReEncrypt is missing.
AnswerA

When S3 performs server-side encryption with AWS KMS (SSE-KMS), it requires the calling principal, such as the Lambda function's execution role, to have the kms:GenerateDataKey permission. This specific permission allows S3 to request a unique data key from KMS to encrypt the object data itself. Without this crucial permission, S3 cannot obtain the necessary encryption key to perform the server-side encryption during the PutObject operation, leading to a failure.

Why this answer

When writing an object to an S3 bucket encrypted with SSE-KMS, the caller must have kms:GenerateDataKey permission so S3 can obtain a data key to encrypt the object. Without it, the write fails with AccessDenied even if s3:PutObject is granted. The other options either describe a different failure mode or a permission not required for a simple PutObject.

Exam trap

DVA-C02 often tests the misconception that S3 permissions alone are sufficient for encrypted buckets — candidates forget that SSE-KMS writes also require kms:GenerateDataKey (and reads require kms:Decrypt).

How to eliminate wrong answers

Option B is wrong because while the KMS key policy must allow the role, the question states the key is specified in the policy and the error is about a missing permission — the most likely cause is a missing IAM action, not a key policy issue (and key policy problems would typically be described differently). Option C is wrong because s3:GetObject is needed for reading objects, not writing them; the function is performing a write. Option D is wrong because kms:ReEncrypt is used when re-encrypting data between keys, which is not part of a standard S3 PutObject with SSE-KMS.

285
MCQmedium

A developer is using Amazon DynamoDB as the data store for a web application. The application experiences frequent throttling errors. Which action can reduce throttling without changing the application code?

A.Add a secondary index
B.Decrease the provisioned write capacity
C.Enable DynamoDB Auto Scaling
D.Increase the provisioned read capacity only
AnswerC

Enabling DynamoDB Auto Scaling, powered by AWS Application Auto Scaling, is the most effective solution for preventing throttling due to fluctuating workloads. Auto Scaling dynamically adjusts the table's provisioned read and write capacity units (RCUs/WCUs) up or down in response to actual traffic patterns and utilization metrics. By automatically increasing capacity during peak demand and decreasing it during lulls, it ensures sufficient throughput to avoid throttling while optimizing costs.

Why this answer

DynamoDB Auto Scaling automatically adjusts the provisioned throughput capacity based on actual traffic patterns, using the AWS Application Auto Scaling service. This prevents throttling by increasing capacity during demand spikes and reduces costs by scaling down during low traffic, all without requiring any code changes.

Exam trap

The trap here is that candidates often assume throttling can only be fixed by manually increasing capacity (Option D) or by optimizing queries (Option A), but they overlook the managed scaling solution that requires no code changes.

How to eliminate wrong answers

Option A is wrong because adding a secondary index does not directly increase the base read/write capacity of the table; it only provides alternative query patterns and can even increase consumed capacity if not designed carefully. Option B is wrong because decreasing provisioned write capacity would worsen throttling by reducing the available throughput, directly contradicting the goal of reducing throttling. Option D is wrong because increasing only read capacity does not address write throttling, and the question describes 'frequent throttling errors' without specifying read or write, so a balanced solution is needed.

286
MCQmedium

A developer is running a Docker container on Amazon ECS with Fargate. The container logs are not appearing in CloudWatch Logs even though the task definition has a logConfiguration specifying the awslogs driver and a log group. What is the MOST likely missing configuration?

A.The container image does not have the awslogs log driver installed.
B.The task execution role lacks the necessary IAM permissions to write to CloudWatch Logs.
C.The CloudWatch Logs log group does not exist.
D.The EC2 instance profile does not have CloudWatch Logs permissions.
AnswerB

For an Amazon ECS task to successfully send container logs to CloudWatch Logs, the assigned Task Execution IAM role must possess specific permissions. These include logs:CreateLogStream to create the necessary log stream within the specified log group and logs:PutLogEvents to write log data to that stream. Without these critical permissions, the ECS agent will be unable to interact with CloudWatch Logs, resulting in logging failures.

Why this answer

For Fargate tasks, the awslogs driver uses the task execution role (not the task role) to call logs:CreateLogStream and logs:PutLogEvents. If that role lacks these permissions, the container starts but log delivery silently fails, which is the most common cause of missing CloudWatch logs.

Exam trap

DVA-C02 often tests the confusion between the task execution role and the task role — candidates pick 'execution role lacks permissions' correctly only if they know the awslogs driver runs under the execution role, not the application task role.

How to eliminate wrong answers

Option A is wrong because the awslogs driver is built into the ECS/Fargate agent and Docker daemon — it is not something installed in the container image. Option C is wrong because ECS auto-creates the log group if it does not exist, and a missing group would not be the 'most likely' cause when the task definition already specifies one. Option D is wrong because Fargate has no EC2 instance profile; that concept applies only to EC2 launch type tasks.

287
Multi-Selectmedium

A developer is designing a system that must meet PCI DSS compliance. Which THREE AWS services can help with logging and monitoring security events?

Select 3 answers
A.Amazon CloudWatch Logs
B.Amazon VPC Flow Logs
C.AWS CloudTrail
D.AWS Key Management Service (KMS)
E.AWS Config
AnswersA, C, E

Amazon CloudWatch Logs provides a scalable and centralized service for ingesting, storing, and analyzing logs from various sources, including EC2 instances, Lambda functions, and custom applications. This service is crucial for meeting PCI DSS requirements for comprehensive audit trails, enabling the collection of system-level events, application logs, and security logs necessary for monitoring and incident response. Its ability to aggregate logs from disparate sources into a single, queryable repository significantly aids in demonstrating compliance with logging and monitoring mandates.

Why this answer

Amazon CloudWatch Logs is correct because it provides a centralized service for collecting, monitoring, and storing log data from various AWS resources and applications. For PCI DSS compliance, CloudWatch Logs can ingest security-related logs (e.g., from EC2, Lambda, or on-premises servers) and enable real-time monitoring, metric filters, and alarms to detect and respond to security events. It also supports log retention policies and encryption at rest using AWS KMS, which are required for audit trails under PCI DSS Requirement 10.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (network metadata) with security event logging, or mistakenly think KMS is a logging service because it is used for encryption, but neither generates or monitors security events as required by PCI DSS.

288
MCQhard

A Step Functions workflow calls three independent Lambda functions and should continue only after all results are available. Which state pattern should be used?

A.Choice state
B.Wait state
C.Parallel state
D.Fail state
AnswerC

The Parallel state is specifically designed to execute multiple independent branches of a workflow concurrently. Each branch within a Parallel state runs simultaneously, allowing for the efficient, parallel invocation of services like AWS Lambda functions. The state completes only when all its branches have finished their execution, aggregating their outputs into a single result, which perfectly addresses the requirement of calling three independent Lambda functions at the same time.

Why this answer

The Parallel state in AWS Step Functions is designed to execute multiple branches of work concurrently and then aggregate their outputs into a single array. This is exactly what is needed when three independent Lambda functions must all complete before the workflow continues, as the Parallel state waits for all branches to finish before proceeding to the next state.

Exam trap

The trap here is that candidates may confuse the Parallel state with the Map state, but the Map state is for processing items in an array with the same logic, not for running distinct independent tasks.

How to eliminate wrong answers

Option A is wrong because a Choice state is used for conditional branching based on input data, not for executing multiple tasks concurrently. Option B is wrong because a Wait state only introduces a delay in the workflow and does not execute or coordinate multiple Lambda functions. Option D is wrong because a Fail state is used to stop the execution and mark it as failed, not to run parallel tasks.

289
MCQhard

A developer notices that an AWS Lambda function, which processes messages from an SQS queue, is taking longer than expected. The function has a reserved concurrency of 5 and a batch size of 10. The SQS queue has a large backlog. CloudWatch metrics show that the function's throttles are high. The function is idempotent and can process up to 100 messages per invocation. What is the most effective way to increase throughput without increasing reserved concurrency?

A.Increase the batch size to 100.
B.Increase reserved concurrency to 10.
C.Change the function timeout to 15 minutes.
D.Enable SQS short polling to reduce latency.
AnswerA

By increasing the SQS batch size to 100, the Lambda function processes up to 100 messages in a single invocation. Since the function is capable of handling this volume, this optimization significantly reduces the total number of Lambda invocations required to process a given message backlog. Fewer invocations directly translate to a lower invocation rate, effectively alleviating the throttling issues experienced by the function and optimizing resource utilization.

Why this answer

Increasing the batch size to 100 directly reduces the number of Lambda invocations required to process the backlog, thereby decreasing throttling without increasing reserved concurrency. The function's capacity to handle up to 100 messages per invocation makes this alignment optimal. SQS event source mappings support batch sizes up to 10,000 for standard queues, so a batch size of 100 is feasible.

Short polling (option D) would not improve throughput; it causes frequent empty responses and does not reduce throttling. Increasing reserved concurrency violates the constraint, and changing timeout (option C) does not address throttling.

Exam trap

A common pitfall is assuming that Lambda's SQS batch size is limited to 10. In fact, for standard queues the maximum is 10,000. Since the function can process up to 100 messages per invocation, increasing the batch size to 100 directly increases throughput without increasing reserved concurrency.

Candidates may also incorrectly consider increasing reserved concurrency, which is explicitly outside the scope of the question.

How to eliminate wrong answers

Option B is wrong because increasing reserved concurrency would increase the number of concurrent executions, which directly contradicts the requirement to not increase reserved concurrency. Option C is wrong because increasing the function timeout does not increase throughput; it only allows longer processing time per invocation, but the bottleneck is throttling due to concurrency limits, not execution duration. Option D is wrong because enabling SQS short polling reduces latency for message retrieval but does not increase the number of messages processed per invocation or reduce throttling; it may even increase the number of empty responses.

290
MCQhard

An application running on Amazon ECS Fargate is experiencing intermittent high latency and timeout errors. The application makes API calls to an external third-party service. The ECS service is configured with a target group using HTTP health checks. The ALB health check logs show occasional 503 responses. What is the MOST likely cause?

A.The security group for the ECS tasks is blocking inbound traffic from the ALB.
B.The ECS tasks are running out of CPU credits, causing slow response times.
C.The ECS service is configured with a task placement strategy that is causing tasks to be stopped and restarted frequently.
D.The application is not properly handling timeouts to the third-party service, causing the health check endpoint to hang.
AnswerD

When an application's health check endpoint makes a synchronous call to a third-party service without proper timeout handling, a slow or unresponsive external dependency can cause the health check to hang indefinitely. This prolonged unresponsiveness will eventually exceed the Application Load Balancer's configured health check timeout threshold. Consequently, the ALB will mark the task as unhealthy and return a 503 error for requests routed to it, leading to intermittent service disruptions as tasks are cycled.

Why this answer

The application's health check endpoint is likely hanging because the application does not handle timeouts when calling the third-party service. This causes the ALB health check to time out and return 503, leading to tasks being marked unhealthy and potentially restarted, which increases latency and timeouts.

Exam trap

DVA-C02 often tests the difference between infrastructure misconfigurations and application-level issues. Candidates may jump to security groups or CPU credits, but the intermittent nature and 503s on health checks point to application timeouts. Also, Fargate does not have CPU credits, which is a common distractor.

How to eliminate wrong answers

Option A is wrong because if the security group blocked inbound traffic from the ALB, the health checks would consistently fail, not intermittently. Option B is wrong because Fargate tasks do not use CPU credits; that is an EC2 burstable instance concept. Option C is wrong because a task placement strategy causing frequent restarts would likely show tasks stopping and starting, but the symptom of intermittent 503s on health checks points to application-level hangs.

291
MCQmedium

A company wants to encrypt data in transit between an on-premises application and an Amazon RDS instance. Which of the following should be implemented?

A.Use an AWS Site-to-Site VPN connection
B.Use SSL/TLS for the database connection
C.Place the RDS instance in a private subnet and use a bastion host
D.Enable encryption at rest on the RDS instance
AnswerB

SSL/TLS (Secure Sockets Layer/Transport Layer Security) is the industry standard protocol for encrypting data in transit directly between a client application and a database server. It establishes a secure, encrypted channel, ensuring confidentiality, integrity, and authentication of the data exchanged. For an RDS instance, configuring the database client to use SSL/TLS guarantees that all data transmitted between the on-premises application and the RDS database is encrypted throughout its journey, fulfilling the requirement for data encryption in transit.

Why this answer

Encrypting data in transit between an on-premises application and Amazon RDS requires enabling SSL/TLS on the database connection. RDS supports SSL/TLS for all supported engines, and the client must be configured to use the RDS certificate authority to establish an encrypted channel. This directly protects data as it travels over the network from the application to the database endpoint.

Exam trap

DVA-C02 often tests the distinction between encryption in transit and encryption at rest, so the trap is selecting a network-level control like VPN or a storage-level control like encryption at rest instead of the application-level SSL/TLS connection.

How to eliminate wrong answers

Option A is wrong because a Site-to-Site VPN encrypts traffic at the network layer between the on-premises network and the VPC, but it does not encrypt the database connection itself; if the VPN terminates before the RDS instance, the final leg could still be unencrypted. Option C is wrong because a private subnet and bastion host improve network access control but do not encrypt data in transit. Option D is wrong because encryption at rest protects stored data on disk, not data moving over the network.

292
MCQmedium

A developer is building a REST API using Amazon API Gateway and AWS Lambda. The API must support request validation, request throttling, and API keys. Which API Gateway feature should the developer use to enforce a daily request limit for each API key?

A.Usage plans
B.API keys
C.Throttling settings at the method level
D.AWS WAF
AnswerA

Usage plans in Amazon API Gateway are the definitive mechanism for enforcing per-client quotas and throttling limits. They allow you to associate specific API keys with defined request rates (e.g., requests per second) and burst capacities, as well as total request quotas over a given period. This ensures that individual API consumers adhere to their subscribed service tiers, preventing any single client from monopolizing API resources and providing granular control over API consumption.

Why this answer

Usage plans in API Gateway allow you to set throttling and quota limits per API key, enabling daily request limits for each key. This feature is specifically designed to control usage by associating API keys with a plan that defines rate limits and quotas, such as a daily request cap. Option A is correct because it directly addresses the requirement to enforce a daily request limit per API key.

Exam trap

The trap here is that candidates often confuse API keys with usage plans, thinking that simply enabling API keys automatically enforces throttling or quotas, but API keys alone provide no rate limiting without a usage plan.

How to eliminate wrong answers

Option B is wrong because API keys alone are just identifiers used to authenticate requests; they do not enforce any throttling or quota limits. Option C is wrong because throttling settings at the method level apply globally to all requests for that method, not per API key, and cannot enforce a daily limit per key. Option D is wrong because AWS WAF is a web application firewall that protects against common web exploits, not a feature for managing API usage quotas or throttling per API key.

293
Multi-Selecteasy

A developer is storing secrets such as database passwords. Which TWO AWS services can be used to securely store and retrieve secrets?

Select 2 answers
A.AWS CloudHSM
B.AWS Systems Manager Parameter Store
C.AWS Identity and Access Management (IAM)
D.AWS Secrets Manager
E.Amazon S3
AnswersB, D

AWS Systems Manager Parameter Store is a secure, hierarchical service for storing configuration data and secrets, including database passwords, as String, StringList, or SecureString parameters. SecureString parameters are encrypted with AWS KMS and can be retrieved via the AWS SDK, CLI, or directly from EC2 and Lambda, with IAM policies controlling access. It is a low-cost, no-extra-fee option (beyond KMS) and supports versioning, making it a lightweight and practical choice when you don't need built-in automatic rotation.

Why this answer

AWS Systems Manager Parameter Store (B) is correct because it can store secrets as SecureString parameters, which are encrypted with AWS KMS and can be retrieved programmatically by applications via the SSM API, making it a valid service for storing and retrieving database passwords. AWS Secrets Manager (D) is correct because it is purpose-built for storing, retrieving, and rotating secrets such as database credentials, using KMS encryption and APIs like GetSecretValue. AWS CloudHSM (A) is not correct here because it provides dedicated hardware security modules for cryptographic key operations, not a managed secret storage and retrieval service.

AWS Identity and Access Management (C) manages identities, permissions, and policies rather than storing secret values. Amazon S3 (E) is object storage and, while it can be encrypted, it is not designed as a secrets management service for securely storing and retrieving credentials.

Exam trap

DVA-C02 often tests the distinction between services that store secrets versus those that manage access or keys, causing candidates to confuse IAM or CloudHSM with secret storage solutions.

294
MCQmedium

A developer is managing an application that uses Amazon S3 to store user-uploaded images. The application generates thumbnails using AWS Lambda and stores them in a separate S3 bucket. The security team requires that all objects in both buckets be encrypted at rest using server-side encryption with AWS KMS (SSE-KMS). The developer has configured the Lambda function to use an IAM role with permissions to call KMS Encrypt and Decrypt. However, when a user uploads an image, the Lambda function fails to write the thumbnail with an 'Access Denied' error. The upload bucket has default encryption set to SSE-KMS. What is the MOST likely cause of the failure?

A.The Lambda function is not in a VPC that has access to the KMS key.
B.The output bucket does not have a bucket policy allowing the Lambda function to write.
C.The upload bucket's default encryption is not applied to objects uploaded by Lambda.
D.The Lambda execution role lacks kms:GenerateDataKey permission for the KMS key.
AnswerD

When an S3 object is encrypted using Server-Side Encryption with AWS KMS (SSE-KMS), S3 requires permission to interact with the specified KMS key to generate a unique data key for object encryption. The `kms:GenerateDataKey` permission is essential for the Lambda's execution role to allow S3, acting on the Lambda's behalf, to request and use this data key from AWS KMS. Without this specific permission, the encryption process fails, resulting in an error during the object upload.

Why this answer

SSE-KMS encryption requires the caller to have both kms:Encrypt and kms:GenerateDataKey permissions on the KMS key. The Lambda execution role was granted Encrypt and Decrypt but not GenerateDataKey, so when S3 attempts to encrypt the thumbnail using SSE-KMS, the KMS call fails and S3 returns Access Denied. Adding kms:GenerateDataKey (and typically kms:Decrypt for reads) resolves the issue.

Exam trap

DVA-C02 often tests the misconception that kms:Encrypt is sufficient for SSE-KMS; candidates overlook that S3 uses GenerateDataKey for envelope encryption, so the missing permission is GenerateDataKey, not Encrypt.

How to eliminate wrong answers

Option A is wrong because Lambda does not need to be in a VPC to call KMS; KMS is a public AWS service reachable via the AWS network. Option B is wrong because the error is an Access Denied on the KMS operation, not an S3 bucket policy denial; the output bucket policy is not the root cause here. Option C is wrong because default encryption on the upload bucket applies to objects uploaded to that bucket, not to objects written to the output bucket; the failure is on the thumbnail write, which uses the output bucket's encryption settings.

295
MCQmedium

A developer needs to encrypt secrets (database passwords) that are used by an application running on EC2. The application retrieves the secrets at startup. Which combination of services provides the MOST secure and manageable solution?

A.Store the secrets in AWS Secrets Manager and use an IAM role to access them.
B.Encrypt the secrets with AWS KMS and store them in an S3 bucket with a bucket policy.
C.Store the secrets in AWS Systems Manager Parameter Store with a SecureString parameter.
D.Hardcode the secrets in the application code and encrypt the code.
AnswerA

Secrets Manager stores the database passwords centrally and supports native rotation, while the EC2 instance profile's IAM role grants retrieval permissions without embedding long-lived credentials. This removes hard-coded secrets and satisfies the secure, manageable requirement.

Why this answer

Storing secrets in AWS Secrets Manager and using an IAM role to access them provides the most secure and manageable solution. Secrets Manager is designed for secret management, supports automatic rotation, and integrates with IAM for fine-grained access control. Using an IAM role for EC2 eliminates the need to embed credentials in the application, enhancing security.

Exam trap

DVA-C02 often tests secret management best practices; candidates may choose Parameter Store SecureString as it is also secure, but Secrets Manager is preferred for its automatic rotation and dedicated secret management features.

How to eliminate wrong answers

Option B is wrong because while KMS encryption and S3 storage can be secure, it requires manual management of secrets, lacks automatic rotation, and is more complex to manage access compared to Secrets Manager. Option C is wrong because Systems Manager Parameter Store with SecureString is a valid option, but it lacks some advanced features of Secrets Manager like automatic rotation and cross-account access, and it may require more manual management. Option D is wrong because hardcoding secrets, even if encrypted, is a poor practice; the encryption key must be managed, and the code could be decompiled, exposing secrets.

296
Multi-Selectmedium

A company is using Amazon S3 to store sensitive documents. They must encrypt all objects at rest. Which TWO methods can be used to enforce server-side encryption? (Choose TWO.)

Select 2 answers
A.Set a bucket policy that denies PutObject if x-amz-server-side-encryption header is not present.
B.Enable default encryption on the S3 bucket.
C.Attach an IAM policy that denies all S3 actions unless encryption is specified.
D.Configure an SQS queue policy to require encryption.
E.Use client-side encryption before uploading objects.
AnswersA, B

Setting a bucket policy allows you to define granular permissions and conditions for all principals interacting with the S3 bucket. By using a `Deny` statement with a condition that checks for the absence of the `s3:x-amz-server-side-encryption` header during a `s3:PutObject` action, you can effectively enforce that all new objects uploaded to the bucket must be encrypted at rest using server-side encryption. This ensures compliance across all uploads, regardless of the uploader's individual IAM permissions.

Why this answer

Option A is correct because a bucket policy can include a Deny statement on s3:PutObject with a condition such as StringNotEquals on s3:x-amz-server-side-encryption (or its absence via Null), which blocks any upload that does not request server-side encryption with the required algorithm (for example, AES256 or aws:kms). Option B is correct because enabling default bucket encryption (SSE-S3, SSE-KMS, or DSSE-KMS) causes Amazon S3 to automatically encrypt every object at rest on upload, even when the request does not include the x-amz-server-side-encryption header, thereby enforcing encryption at rest. Option C is not appropriate because an IAM policy denying all S3 actions unless encryption is specified is overly broad and does not itself enforce encryption on PutObject in the precise, header-based way a bucket policy condition does.

Option D is wrong because an SQS queue policy governs access to an SQS queue, not to S3 objects, and has no effect on S3 server-side encryption. Option E is wrong because client-side encryption encrypts data before it reaches S3 and is not a server-side encryption enforcement method.

Exam trap

Candidates often confuse client-side encryption (Option E) with server-side encryption. Additionally, while IAM policies (Option C) can restrict user actions, denying 'all S3 actions' unless encryption is specified is incorrect because read actions (like GetObject) or metadata actions (like ListBucket) do not require encryption headers.

297
Multi-Selecteasy

A developer wants to deploy a static website to AWS. The website content is stored in an S3 bucket. Which combination of actions is required to host the website? (Choose TWO.)

Select 2 answers
A.Enable server access logging.
B.Enable static website hosting on the S3 bucket.
C.Set a bucket policy that restricts access to a specific IP.
D.Configure Amazon CloudFront as a CDN.
E.Set the bucket objects to publicly readable.
AnswersB, E

Enabling static website hosting on the S3 bucket is the essential configuration that activates the bucket's website endpoint (e.g., bucket-name.s3-website-region.amazonaws.com), which serves the site over HTTP and automatically resolves requests to an index document (like index.html) and a custom error document. Without this setting, the bucket only exposes its REST API endpoints, which require Signature Version 4 authentication and cannot render a browser-facing website. Therefore, this is a mandatory step for hosting any static site on Amazon S3.

Why this answer

To host a static website on S3, you must enable static website hosting on the bucket (option B) and make the objects publicly readable (option E). Option A (server access logging) is optional for tracking requests, not required. Option C (restricting access to a specific IP) would prevent public access, which is needed for a public website.

Option D (CloudFront) is an optional CDN service, not a requirement for S3 static website hosting.

298
MCQeasy

A developer is creating a new IAM policy to allow users to list objects in a specific S3 bucket. The policy must follow the principle of least privilege. Which policy statement should the developer use?

A.{"Effect":"Allow","Action":"s3:ListAllMyBuckets","Resource":"*"}
B.{"Effect":"Allow","Action":"s3:ListBucket","Resource":"arn:aws:s3:::example-bucket"}
C.{"Effect":"Allow","Action":"s3:PutObject","Resource":"arn:aws:s3:::example-bucket/*"}
D.{"Effect":"Allow","Action":"s3:GetObject","Resource":"arn:aws:s3:::example-bucket/*"}
AnswerB

Granting only `s3:ListBucket` on the bucket ARN itself satisfies least privilege, because listing objects is a bucket-level operation evaluated against the bucket resource, not the objects within it. Omitting `s3:GetObject` and any wildcard resource prevents unintended read access to object contents.

Why this answer

The s3:ListBucket action controls the ability to list the objects within a specific bucket, and it must be granted on the bucket resource itself (arn:aws:s3:::example-bucket), not on the objects inside it. Option B correctly pairs the least-privilege action with the correct resource ARN, allowing the user to list objects in only that one bucket. This satisfies the principle of least privilege because it grants no access to other buckets and no object-level read/write permissions.

Exam trap

DVA-C02 often tests the confusion between bucket-level actions (s3:ListBucket on the bucket ARN) and object-level actions (s3:GetObject/s3:PutObject on the object ARN), causing candidates to pick an object-level permission when a bucket-level listing permission is required.

How to eliminate wrong answers

Option A is wrong because s3:ListAllMyBuckets grants permission to list every bucket in the AWS account and must be paired with Resource "*", which violates least privilege and does not scope access to the specific bucket. Option C is wrong because s3:PutObject is a write action that uploads objects, not a list action, and it is applied to the object ARN (example-bucket/*) rather than the bucket ARN. Option D is wrong because s3:GetObject retrieves object contents, not bucket listings, and it is also applied to the object ARN instead of the bucket ARN.

299
Multi-Selectmedium

A developer is designing a CI/CD pipeline for a serverless application using AWS CodePipeline. The pipeline must automatically build and deploy the application when changes are pushed to a CodeCommit repository. The application uses AWS CloudFormation for infrastructure provisioning. Which TWO actions should the developer include in the pipeline?

Select 2 answers
A.Use AWS CodeDeploy to deploy the application to EC2 instances.
B.Use AWS CodeCommit as a deployment action.
C.Use AWS CodeBuild to run unit tests and package the application.
D.Use AWS Lambda to run integration tests.
E.Use AWS CloudFormation to create or update the stack.
AnswersC, E

AWS CodeBuild is a fully managed continuous integration service that compiles source code, runs tests, and produces deployable artifacts. For a serverless application, CodeBuild is an ideal choice for the build and test phase within a CI/CD pipeline. It can execute unit tests against the application code, compile any necessary language runtimes, and then package the application code along with its dependencies into a deployment-ready artifact, such as a .zip file, suitable for AWS Lambda.

Why this answer

AWS CodeBuild can compile source code, run unit tests, and produce deployment artifacts, which is a standard build phase in a CI/CD pipeline. Option E is correct because AWS CloudFormation is the native AWS service for provisioning and updating infrastructure as code, making it the appropriate deployment action for a serverless application defined in templates.

Exam trap

The trap here is that candidates often confuse AWS CodeDeploy with CloudFormation for serverless deployments, not realizing that CodeDeploy is for EC2/on-premises and CloudFormation is the correct service for provisioning serverless infrastructure.

300
MCQeasy

A developer is creating a CloudFormation template to deploy an Amazon S3 bucket. The developer wants the bucket to be deleted automatically when the CloudFormation stack is deleted. What should the developer specify in the template?

A.Set the DeletionPolicy attribute to Delete.
B.Specify a unique bucket name to avoid conflicts.
C.Use the DependsOn attribute to specify the bucket depends on the stack.
D.Set the DeletionPolicy attribute to Retain.
AnswerA

When a CloudFormation stack is deleted, resources with DeletionPolicy: Delete are removed from the AWS account. For an S3 bucket, applying DeletionPolicy: Delete ensures that the bucket and all its contents are permanently deleted when the associated CloudFormation stack is terminated. This is the correct approach to ensure the bucket's lifecycle is tied directly to the stack's lifecycle, preventing orphaned resources. This attribute explicitly instructs CloudFormation to remove the resource.

Why this answer

The `DeletionPolicy` attribute in AWS CloudFormation controls what happens to a resource when its stack is deleted. By setting `DeletionPolicy: Delete` on the S3 bucket resource, the developer ensures that the bucket is automatically deleted when the stack is deleted. This is the default behavior for most resources, but explicitly setting it confirms the intent and overrides any other policy like `Retain`.

Exam trap

The trap here is that candidates often confuse `DeletionPolicy` with `UpdatePolicy` or assume that `Retain` is the default, leading them to choose Option D, when in fact `Delete` is the default and correct choice for automatic deletion.

How to eliminate wrong answers

Option B is wrong because specifying a unique bucket name avoids naming conflicts but does not control deletion behavior; CloudFormation can still delete the bucket regardless of its name. Option C is wrong because the `DependsOn` attribute only establishes resource creation order within the stack, not deletion behavior; it does not affect whether the bucket is deleted when the stack is removed. Option D is wrong because setting `DeletionPolicy` to `Retain` explicitly prevents the bucket from being deleted when the stack is deleted, which is the opposite of what the developer wants.

Page 3

Page 4 of 16

Page 5