Courseiva

AWS Certified Developer Associate DVA-C02 (DVA-C02) — Questions 301–375

1135 questions total · 16pages · All types, answers revealed

Page 4

Page 5 of 16

Page 6
301
MCQeasy

A developer notices that an S3 bucket used for static website hosting returns 403 Forbidden for anonymous requests. The bucket policy allows s3:GetObject for Principal "*". What is the most likely issue?

A.The bucket does not have server access logging enabled.
B.The bucket ACL does not allow public read.
C.The bucket policy is not attached to the correct bucket.
D.The S3 Block Public Access settings are enabled.
AnswerD

Amazon S3 Block Public Access settings provide a crucial security control designed to prevent unintended public exposure of S3 buckets and objects. These settings, configurable at both the account and bucket level, explicitly override all other access control mechanisms, including permissive bucket policies and object ACLs, that would otherwise grant public access. If these Block Public Access settings are enabled, they will effectively block all public access to the static website, regardless of any correctly configured bucket policies or ACLs intended to allow public reads.

Why this answer

D is correct because S3 Block Public Access settings, when enabled at the account or bucket level, override any bucket policy or ACL that grants public access. Even though the bucket policy allows s3:GetObject for Principal "*", the Block Public Access settings explicitly deny all public requests, resulting in a 403 Forbidden error for anonymous users.

Exam trap

The trap here is that candidates often assume a bucket policy granting public access is sufficient, overlooking the S3 Block Public Access settings which silently override such policies and cause 403 errors.

How to eliminate wrong answers

Option A is wrong because server access logging is a feature for logging requests to the bucket, not a permission control; it does not affect whether requests are allowed or denied. Option B is wrong because the bucket policy already grants public read access via Principal "*", and while ACLs can also grant public read, the bucket policy takes precedence; the issue is not the ACL but an overriding deny. Option C is wrong because the question states the bucket policy is attached and allows s3:GetObject, so the policy is correctly associated; the problem lies with a separate security mechanism.

302
MCQhard

A company runs a monolithic application on EC2 Behind an Application Load Balancer. They want to migrate to a microservices architecture using ECS Fargate. What is the most important optimization to ensure minimal downtime during the migration?

A.Use a blue/green deployment strategy with weighted target groups.
B.Increase the EC2 instance size to handle the microservices load.
C.Deploy all microservices in a single ECS service for simplicity.
D.Scale horizontally by adding more EC2 instances.
AnswerA

A blue/green deployment strategy is ideal for migrating a monolithic application to microservices with minimal downtime. It involves running two identical environments: the existing 'blue' version and the new 'green' version with microservices. Weighted target groups, typically configured on an Application Load Balancer (ALB) or Route 53, allow for a controlled, gradual shift of traffic from the blue to the green environment, enabling real-time testing and easy rollback if issues occur.

Why this answer

A blue/green deployment strategy with weighted target groups allows you to gradually shift traffic from the existing monolithic EC2 application (blue) to the new microservices on ECS Fargate (green) while monitoring for errors. This minimizes downtime by enabling instant rollback if issues arise, and it leverages Application Load Balancer (ALB) features like stickiness and health checks to ensure a seamless transition without disrupting active connections.

Exam trap

The trap here is that candidates confuse scaling strategies (horizontal/vertical) with deployment strategies, assuming that adding more capacity or consolidating services will inherently reduce downtime, when in fact only a controlled traffic-shifting method like blue/green with weighted routing ensures minimal disruption during a live migration.

How to eliminate wrong answers

Option B is wrong because increasing EC2 instance size does not address the migration to microservices or ECS Fargate; it only scales the monolithic application vertically, which contradicts the goal of moving to a serverless container architecture and does not reduce downtime during migration. Option C is wrong because deploying all microservices in a single ECS service defeats the purpose of microservices isolation, scaling, and independent deployment; it introduces tight coupling and increases the blast radius of failures, leading to higher downtime risk. Option D is wrong because scaling horizontally by adding more EC2 instances only scales the monolithic application, not the microservices on Fargate, and does not provide a controlled traffic-shifting mechanism to minimize downtime during migration.

303
MCQmedium

A developer configured an S3 bucket to trigger a Lambda function on object creation. The Lambda function processes the object and then deletes it. Some objects are not being processed. What should the developer do to ensure all objects are processed?

A.Assign a new IAM role to the Lambda function with S3 permissions.
B.Enable S3 versioning on the bucket.
C.Send S3 events to an SQS queue and configure the Lambda function to poll the queue.
D.Increase the Lambda function timeout.
AnswerC

Direct S3-to-Lambda invocations are 'at-least-once' but can occasionally miss events under specific conditions or if the Lambda invocation fails without successful retry. By sending S3 events to an SQS queue first, SQS acts as a durable buffer, ensuring messages are reliably stored and can be retried if the Lambda function fails to process them. The Lambda function then polls the SQS queue, pulling messages and processing them, leveraging SQS's built-in retry mechanisms and dead-letter queue capabilities for robust event handling and guaranteed delivery.

Why this answer

Sending S3 events to an SQS queue decouples event delivery from Lambda invocation. If the Lambda function fails or throttles, the event remains in the queue and can be retried, ensuring no objects are missed. Without a queue, S3 events that fail to invoke Lambda (e.g., due to concurrency limits) are lost, leading to unprocessed objects.

Exam trap

The trap here is that candidates assume the issue is a permission or timeout problem, when in fact the root cause is the loss of S3 event notifications due to Lambda throttling or transient failures, which a queue-based architecture resolves.

How to eliminate wrong answers

Option A is wrong because the Lambda function already processes and deletes objects, so it must already have S3 permissions; assigning a new IAM role would not fix lost events. Option B is wrong because enabling S3 versioning preserves object versions but does not affect event delivery reliability or retry behavior. Option D is wrong because increasing the Lambda function timeout addresses execution duration, not the loss of events due to throttling or invocation failures.

304
MCQhard

A company uses AWS CodePipeline to deploy a critical web application. The pipeline has a source stage (CodeCommit), a build stage (CodeBuild), and a deploy stage (CodeDeploy). During a recent deployment, the CodeDeploy stage failed because the target EC2 instances were not in a healthy state. The developer needs to ensure that the pipeline automatically rolls back the deployment to the last successful version if the deployment fails. What should the developer do?

A.In the CodeDeploy deployment group, enable automatic rollback when a deployment fails.
B.Use AWS CloudFormation to manage the deployment and enable rollback on failure.
C.Configure a CloudWatch alarm to trigger a rollback in CodePipeline.
D.Modify the CodePipeline stage to include a manual approval step that checks health before proceeding.
AnswerA

AWS CodeDeploy deployment groups offer a built-in feature to automatically roll back a deployment when it fails. This configuration ensures that if any step within the deployment process, such as application installation or health checks, reports a failure, CodeDeploy will automatically revert the instances in the deployment group to the last successfully deployed application revision. This mechanism is specifically designed to maintain application availability and quickly recover from faulty deployments without manual intervention.

Why this answer

CodeDeploy deployment groups have a built-in automatic rollback configuration that can be enabled to revert to the last successful deployment revision when a deployment fails. This feature directly addresses the requirement without requiring additional services or manual steps, as it operates within the CodeDeploy service itself.

Exam trap

The trap here is that candidates may confuse CodePipeline's built-in rollback capabilities with CodeDeploy's automatic rollback, or incorrectly assume that CloudWatch alarms or manual approvals can directly perform rollbacks without custom logic.

How to eliminate wrong answers

Option B is wrong because AWS CloudFormation is an infrastructure-as-code service for managing resources, not a deployment service for CodePipeline; enabling rollback on failure in CloudFormation would roll back the stack, not the CodeDeploy deployment. Option C is wrong because CloudWatch alarms can trigger actions like SNS notifications or Auto Scaling, but they cannot directly trigger a rollback in CodePipeline or CodeDeploy without custom Lambda functions or additional configuration. Option D is wrong because a manual approval step only pauses the pipeline for human review before proceeding; it does not automatically roll back a failed deployment to the last successful version.

305
MCQeasy

A developer wants to grant a user in a different AWS account access to an S3 bucket. The developer has written a bucket policy that allows the user's IAM user ARN. However, the access is still denied. What is the most likely reason?

A.The user's IAM user policy does not explicitly allow the required S3 action
B.The bucket policy does not have a principal of '*' to allow external accounts
C.The bucket is in a different region than the user's account
D.The user is using the wrong S3 endpoint (e.g., path-style vs virtual-hosted)
AnswerA

For cross-account S3 access, both the resource-based bucket policy and the identity-based IAM user policy must explicitly grant the necessary permissions. If the user's IAM policy lacks an `Allow` statement for actions like `s3:GetObject` or `s3:PutObject`, even if the bucket policy permits the external account, the request will be denied. This dual authorization model ensures granular control from both the resource owner and the identity owner.

Why this answer

When granting cross-account access to an S3 bucket, both the bucket policy (resource-based policy) and the user's IAM policy (identity-based policy) must explicitly allow the action. The bucket policy alone is insufficient if the user's IAM policy does not include an explicit Allow for the S3 action, because IAM denies by default. Even though the bucket policy grants access, the user's own IAM policy must also permit the operation for the request to succeed.

Exam trap

The trap here is that candidates assume a bucket policy alone is sufficient for cross-account access, forgetting that the external user's IAM policy must also explicitly allow the action, as IAM denies all actions by default.

How to eliminate wrong answers

Option B is wrong because a bucket policy does not require a principal of '*' to allow external accounts; you can specify the exact IAM user ARN as the principal, which is more secure and correct. Option C is wrong because S3 is a global service and bucket policies work across regions; the region of the bucket and the user's account does not affect access control. Option D is wrong because the S3 endpoint type (path-style vs virtual-hosted) affects URL format but does not impact authorization; access is denied due to IAM permissions, not endpoint choice.

306
MCQeasy

A developer is using AWS Lambda to process events from an Amazon Kinesis stream. The function has been failing with 'ProvisionedThroughputExceededException' errors when writing to a DynamoDB table. What should the developer do to resolve this issue?

A.Decrease the batch size of the Kinesis event source mapping.
B.Implement retry logic with exponential backoff in the Lambda function.
C.Increase the number of shards in the Kinesis stream.
D.Increase the memory allocated to the Lambda function.
AnswerB

Implementing retry logic with exponential backoff in the Lambda function is the standard and most effective approach for handling `ProvisionedThroughputExceededException`. This exception indicates a temporary throttling by DynamoDB when its provisioned capacity is exceeded. Exponential backoff allows the Lambda function to automatically reattempt failed writes after increasing delays, giving DynamoDB time to recover capacity and successfully process the request, thereby smoothing out write spikes and preventing data loss.

Why this answer

The 'ProvisionedThroughputExceededException' error indicates that the Lambda function is exceeding the write capacity units (WCUs) provisioned for the DynamoDB table. Implementing retry logic with exponential backoff in the Lambda function allows it to handle throttling gracefully by pausing and retrying failed writes, which is the standard AWS-recommended pattern for managing DynamoDB throttling.

Exam trap

The trap here is that candidates often confuse scaling the source (Kinesis shards) or the compute (Lambda memory) with managing the downstream resource's capacity limits, leading them to choose options that increase parallelism rather than implementing proper retry and backoff logic.

How to eliminate wrong answers

Option A is wrong because decreasing the batch size of the Kinesis event source mapping reduces the number of records per invocation but does not address the root cause of exceeding DynamoDB's provisioned throughput; it may only reduce the burst of writes but not prevent throttling if the table's capacity is insufficient. Option C is wrong because increasing the number of shards in the Kinesis stream increases the parallelism of Lambda invocations, which can actually exacerbate the throttling issue by sending more concurrent write requests to DynamoDB. Option D is wrong because increasing the memory allocated to the Lambda function only affects CPU and network performance, not the rate at which it writes to DynamoDB; it does not resolve throughput limit errors.

307
MCQhard

A developer is building a serverless application using API Gateway and Lambda. The API must be accessed only by authenticated users from a specific AWS Cognito User Pool. Which method should be used?

A.Create a Lambda authorizer that checks the token against Cognito.
B.Use an IAM authorizer with a policy that allows only Cognito roles.
C.Use a resource policy on API Gateway to restrict by source IP.
D.Configure a Cognito Authorizer on the API Gateway method.
AnswerD

Configuring a Cognito user pool authorizer directly on the API Gateway method tells API Gateway to automatically validate the Authorization header's JWT against the specified user pool's public keys and required scopes before invoking the Lambda backend, requiring zero custom authorization code and rejecting any request lacking a valid token issued by that pool.

Why this answer

API Gateway can use a Cognito Authorizer to validate tokens from a specific user pool.

308
MCQeasy

A developer is deploying a web application using AWS Elastic Beanstalk. The application requires a relational database. The developer wants the database to be automatically created and configured as part of the Elastic Beanstalk environment. Which approach should they use?

A.Use Amazon DynamoDB as the database and configure it in the Elastic Beanstalk environment.
B.Create an RDS database manually and configure the application to connect to it using environment properties.
C.Embed a SQLite database file in the application deployment package.
D.Configure the Elastic Beanstalk environment to include an RDS database instance.
AnswerD

Elastic Beanstalk provides direct, integrated support for provisioning and managing an Amazon RDS database instance as part of the environment. When configured this way, Elastic Beanstalk automatically creates, manages, and injects the necessary database connection details (such as endpoint, username, and password) as environment variables for the application. This significantly simplifies deployment, scaling, and the overall lifecycle management of the database alongside the application.

Why this answer

The correct approach is to configure the Elastic Beanstalk environment to include an RDS database instance. Elastic Beanstalk allows you to provision an RDS database as part of the environment, automatically handling creation, configuration, and connection details. This integrates the database lifecycle with the environment, simplifying management.

Exam trap

DVA-C02 often tests the difference between integrated and manually configured resources, and candidates may incorrectly assume that manual creation is required for production or that DynamoDB is a relational database.

How to eliminate wrong answers

Option A is wrong because DynamoDB is a NoSQL database, not relational, and Elastic Beanstalk does not natively provision DynamoDB as part of the environment. Option B is wrong because creating an RDS database manually does not automatically configure it as part of the Elastic Beanstalk environment; it requires manual setup and connection configuration. Option C is wrong because embedding a SQLite database file is not suitable for a scalable web application and does not provide a managed relational database service.

309
Multi-Selecteasy

A developer is building a serverless application using AWS Lambda. The Lambda function needs to access a VPC to connect to an RDS database. Which TWO resources must the developer configure to allow the Lambda function to access the VPC?

Select 2 answers
A.A NAT gateway in the VPC.
B.A security group that allows inbound/outbound traffic to the RDS database.
C.VPC subnet IDs for the Lambda function.
D.An IAM role with permissions to access RDS.
E.An internet gateway attached to the VPC.
AnswersB, C

A security group acts as a virtual firewall for your RDS database instance, controlling both inbound and outbound traffic at the instance level. To allow a Lambda function to connect to RDS, the RDS security group must have an inbound rule permitting traffic on the database port (e.g., 3306 for MySQL) from the security group associated with the Lambda function's ENI. This ensures network-level access is granted for the serverless application.

Why this answer

A security group acts as a virtual firewall for the Lambda function, controlling inbound and outbound traffic. To connect to an RDS database in a VPC, the Lambda function's security group must allow outbound traffic to the RDS database's security group on the database port (e.g., 3306 for MySQL), and the RDS security group must allow inbound traffic from the Lambda security group. This two-way rule ensures the Lambda function can establish a TCP connection to the database.

Exam trap

The trap here is that candidates often confuse the resources needed for VPC access (subnet IDs and security groups) with network infrastructure components (NAT gateway, internet gateway) or database-level permissions (IAM role), but the question specifically asks for the two resources that enable the Lambda function to connect to the VPC network layer, not the database service itself.

310
MCQeasy

A company is using AWS CodeBuild to compile a Java application. The build takes a long time because Maven dependencies are downloaded each time. How can the developer reduce build time?

A.Use a higher compute type for the build project.
B.Use a custom AMI with pre-installed dependencies.
C.Increase the timeout value for the build.
D.Configure a cache in Amazon S3 for the Maven repository.
AnswerD

For Java applications, a significant portion of build time is often consumed by downloading project dependencies from remote Maven repositories. Configuring a CodeBuild cache to store the local Maven repository (~/.m2 directory) in an Amazon S3 bucket allows these dependencies to be persisted and reused across subsequent builds. This dramatically reduces build duration by eliminating redundant network transfers and dependency resolution steps, as CodeBuild can efficiently restore the cache before the build starts, making it highly effective for improving build performance.

Why this answer

Configuring an Amazon S3 cache for the Maven repository allows CodeBuild to reuse previously downloaded dependencies across builds, eliminating the need to re-download them each time. This significantly reduces build time by leveraging the local cache stored in S3, which is a best practice for dependency-heavy builds like Java applications with Maven.

Exam trap

The trap here is that candidates may confuse CodeBuild's cache with EC2-based solutions (like custom AMIs) or assume that increasing compute resources solves all performance issues, when the actual bottleneck is network latency for repeated downloads.

How to eliminate wrong answers

Option A is wrong because using a higher compute type (e.g., more CPU/memory) does not address the root cause of repeated network downloads; it only speeds up the build steps themselves, not the dependency resolution. Option B is wrong because CodeBuild does not support custom AMIs; it uses managed build environments based on Docker images, and pre-installing dependencies in a custom image would require a custom Docker image, not an AMI. Option C is wrong because increasing the timeout value only prevents the build from failing due to time limits; it does not reduce the actual time spent downloading dependencies.

311
Multi-Selectmedium

A company wants to securely store database credentials for a Lambda function. The credentials must be automatically rotated. Which TWO services should be used together?

Select 2 answers
A.AWS KMS
B.AWS Secrets Manager
C.AWS CloudHSM
D.AWS Lambda
E.AWS Systems Manager Parameter Store
AnswersB, D

AWS Secrets Manager is a dedicated service for securely storing and managing secrets, including database credentials. It provides robust features for automatic rotation of secrets, which is crucial for enhancing security by regularly changing credentials without manual intervention. Furthermore, it integrates seamlessly with various AWS databases and services, simplifying the process of retrieving and using secrets in applications, making it the ideal solution.

Why this answer

AWS Secrets Manager is the correct service because it is purpose-built for securely storing, retrieving, and automatically rotating database credentials and other secrets. It integrates natively with AWS Lambda and supports automatic rotation via a built-in rotation function or a custom Lambda function, meeting the requirement for automated credential rotation without manual intervention.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store with Secrets Manager because both can store secrets, but Parameter Store lacks automatic rotation, which is explicitly required in the question.

312
MCQeasy

A developer is building an AWS Lambda function that needs to retrieve a database password securely. The password is stored in AWS Secrets Manager and is rotated every 30 days. The function must minimize the number of API calls to Secrets Manager. Which approach should the developer use?

A.Store the database password as an encrypted environment variable in the Lambda function.
B.Call Secrets Manager on every invocation to get the latest secret.
C.Retrieve the secret from Secrets Manager once outside the handler function, cache it in a global variable, and refresh the cache if the secret fails.
D.Use AWS Systems Manager Parameter Store SecureString instead of Secrets Manager.
AnswerC

Retrieving the secret from Secrets Manager once outside the handler function and caching it in a global variable is an optimal pattern for Lambda. This approach leverages the execution environment's persistence, significantly reducing latency and cost by minimizing `GetSecretValue` API calls across warm invocations. If the secret is rotated, the cached value will eventually fail authentication, triggering a refresh from Secrets Manager to retrieve the latest version, ensuring both efficiency and up-to-date security.

Why this answer

It retrieves the secret once during the Lambda cold start (outside the handler), caches it in a global variable, and only refreshes the cache if the secret fails (e.g., due to rotation). This minimizes API calls to Secrets Manager while still handling secret rotation gracefully, as the cached secret remains valid until a failure occurs.

Exam trap

The trap here is that candidates assume 'minimize API calls' means never calling Secrets Manager again, but the correct approach allows a single call per cold start with a fallback refresh on failure, not zero calls forever.

How to eliminate wrong answers

Option A is wrong because storing the password as an encrypted environment variable does not support automatic rotation—the value is static until the function is redeployed, violating the requirement that the password is rotated every 30 days. Option B is wrong because calling Secrets Manager on every invocation maximizes API calls, incurring unnecessary cost and latency, and contradicts the requirement to minimize API calls. Option D is wrong because switching to Systems Manager Parameter Store does not inherently reduce API calls; the same caching strategy would still be needed, and the question specifically asks about Secrets Manager, not an alternative service.

313
MCQmedium

A developer is using AWS CodeDeploy to deploy an application to an EC2 Auto Scaling group. The developer wants to monitor the deployment and automatically roll back if a specified Amazon CloudWatch alarm is triggered during the deployment. Which CodeDeploy feature should the developer configure?

A.Deployment group alarm configuration
B.Deployment configuration with alarm
C.Revision rollback
D.EC2 instance health check
AnswerA

AWS CodeDeploy deployment groups can be configured with one or more Amazon CloudWatch alarms. When a deployment is in progress or completes, CodeDeploy continuously monitors these alarms for any state changes. If any configured alarm transitions to an ALARM state, CodeDeploy can be set to automatically roll back the deployment, reverting the application to its previous stable version. This mechanism ensures that problematic deployments are quickly undone, minimizing impact on end-users.

Why this answer

The Deployment group alarm configuration in AWS CodeDeploy allows you to specify Amazon CloudWatch alarms that, when triggered during a deployment, automatically initiate a rollback. This feature is configured at the deployment group level and ensures that if a predefined alarm (e.g., high error rate or latency) enters the ALARM state, CodeDeploy stops the deployment and reverts to the last known good revision. This provides automated, policy-driven rollback without manual intervention.

Exam trap

The trap here is that candidates confuse the deployment group alarm configuration (which monitors CloudWatch alarms during deployment) with a deployment configuration (which controls traffic shifting and failure thresholds), leading them to select Option B instead of A.

How to eliminate wrong answers

Option B is wrong because 'Deployment configuration with alarm' is not a valid CodeDeploy feature; CodeDeploy deployment configurations define traffic routing and failure thresholds, not alarm-based rollback triggers. Option C is wrong because 'Revision rollback' is a manual or automated action that can be initiated by the deployment group alarm configuration, but it is not a feature you configure to monitor alarms—it is the outcome of the alarm trigger. Option D is wrong because 'EC2 instance health check' refers to the health checks performed by Auto Scaling or Elastic Load Balancing to determine instance health, not to CloudWatch alarm-based rollback logic in CodeDeploy.

314
MCQmedium

A developer is troubleshooting an AWS Lambda function that returns timeout errors when calling an external HTTPS API. The function is configured with a 30-second timeout and runs in a VPC with a public subnet and NAT Gateway. The developer checks CloudWatch logs and sees that the function is timing out at exactly 30 seconds. What is the most likely cause?

A.The NAT Gateway is not configured with a route to the internet.
B.The Lambda function's security group does not allow outbound traffic.
C.The external API's response time exceeds 30 seconds.
D.The Lambda function's VPC does not have an internet gateway.
AnswerB

This is the correct explanation. When a Lambda function is configured within a VPC, its network interfaces are subject to the associated security group rules. If the egress (outbound) rules of the security group do not explicitly permit traffic on the required port (e.g., HTTPS on port 443) to the external API's IP range or `0.0.0.0/0`, the connection attempt will be blocked. This blockage prevents the TCP handshake from completing, causing the function to wait indefinitely until its configured execution timeout is reached.

Why this answer

Lambda functions running in a VPC do not automatically get internet access; they require a route to a NAT Gateway or NAT instance. Even with a NAT Gateway, the Lambda function's security group must allow outbound traffic (e.g., HTTPS on port 443) to reach the external API. Without this rule, outbound packets are dropped, causing the function to hang until the configured timeout (30 seconds) expires, resulting in a timeout error.

Exam trap

The trap here is that candidates assume a NAT Gateway alone provides internet access to Lambda, overlooking that security group egress rules must explicitly allow outbound traffic to the destination.

How to eliminate wrong answers

Option A is wrong because the NAT Gateway is explicitly stated to be present, and a NAT Gateway requires a route to the internet (via an Internet Gateway) to function; if it were misconfigured, the function would likely fail immediately or at a different timeout, not exactly at 30 seconds. Option C is wrong because the function times out at exactly 30 seconds, matching its configured timeout, not at a variable time based on API response; if the API exceeded 30 seconds, the timeout would still occur at 30 seconds, but the question asks for the most likely cause given the VPC setup. Option D is wrong because the VPC does not need an Internet Gateway for outbound traffic through a NAT Gateway; the NAT Gateway itself resides in a public subnet and uses an Internet Gateway, but the Lambda function's VPC configuration is separate—the issue is security group egress rules, not the presence of an Internet Gateway.

315
MCQmedium

A company uses AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment fails with the error 'The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available for deployment, or some instances in your deployment group are experiencing problems.' Which of the following is the MOST likely cause?

A.The new application version fails the configured health checks on the instances.
B.The deployment group does not exist.
C.The IAM role for CodeDeploy does not have sufficient permissions.
D.The CodeDeploy agent is not installed on the instances.
AnswerA

CodeDeploy deployments are often configured with health checks, either through integration with Elastic Load Balancers or custom scripts defined in the `appspec.yml` file (e.g., in `AfterInstall` or `ApplicationStart` hooks). If the newly deployed application version fails to pass these configured health checks on the target instances, CodeDeploy automatically detects this issue. This failure triggers a pre-configured rollback to the last known good application version, ensuring service continuity and preventing the deployment of faulty code into production environments.

Why this answer

The error message indicates that instances failed deployment, which is most commonly caused by the new application version failing the health checks configured in the deployment group. CodeDeploy uses these health checks (e.g., ELB health checks or custom scripts) to determine if an instance is healthy after deployment; if the application crashes or returns non-200 status codes, CodeDeploy marks the instance as failed and aborts the deployment.

Exam trap

The trap here is that candidates often confuse deployment failures caused by health check failures with infrastructure issues like missing IAM roles or agents, but the specific error message about 'too many individual instances failed deployment' directly points to application-level health check failures, not permission or agent problems.

How to eliminate wrong answers

Option B is wrong because if the deployment group did not exist, CodeDeploy would return a 'DeploymentGroupDoesNotExistException' error, not a generic instance failure error. Option C is wrong because insufficient IAM permissions would cause a different error, such as 'AccessDeniedException' when CodeDeploy tries to call EC2 or Auto Scaling APIs, not a per-instance deployment failure. Option D is wrong because if the CodeDeploy agent is not installed, the instance would show as 'Unknown' or 'Not Registered' in the deployment group, and the error would be about missing agent, not about too many instances failing health checks.

316
MCQeasy

A developer needs to grant a Lambda function permission to write logs to CloudWatch Logs. Which IAM entity should be used?

A.Attach an inline policy to the Lambda function.
B.Create an IAM execution role with the necessary permissions and associate it with the function.
C.Use a service control policy (SCP) to allow logging.
D.Add a resource-based policy to the Lambda function.
AnswerB

Creating an IAM execution role with the necessary permissions and associating it with the Lambda function is the correct and standard approach. This execution role defines the specific actions the Lambda function is authorized to perform when it executes, such as reading from S3, writing to DynamoDB, or publishing logs to CloudWatch. The Lambda service assumes this role on behalf of your function, ensuring adherence to the principle of least privilege.

Why this answer

Lambda functions require an IAM execution role to obtain temporary credentials for accessing other AWS services. This role must include a trust policy allowing Lambda to assume it and a permissions policy granting the specific actions (e.g., logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents) on CloudWatch Logs. Associating this role with the function is the standard and secure way to grant permissions.

Exam trap

The trap here is confusing the entity that receives permissions (the Lambda function) with the mechanism that grants them (an execution role), leading candidates to incorrectly select attaching a policy directly to the function or using a resource-based policy.

How to eliminate wrong answers

Option A is wrong because an inline policy is attached to an IAM user, group, or role, not directly to a Lambda function; Lambda functions do not have IAM policies attached to them. Option C is wrong because Service Control Policies (SCPs) are used to set permission boundaries across an entire AWS organization or organizational unit, not to grant permissions to individual Lambda functions. Option D is wrong because resource-based policies are used to grant other AWS services or accounts access to the Lambda function itself (e.g., allowing an S3 bucket to invoke the function), not to grant the function permissions to other services like CloudWatch Logs.

317
MCQhard

A company runs a containerized application on Amazon ECS with Fargate. The application writes logs to stdout. The operations team wants to send these logs to a centralized log management tool that requires logs in JSON format. What is the BEST way to achieve this without modifying application code?

A.Use the FireLens log driver to route logs to Fluent Bit and then to the tool
B.Use the awslogs log driver and configure a JSON output format
C.Install the CloudWatch Logs agent on the container
D.Modify the application to output logs in JSON format
AnswerA

The FireLens log driver is the appropriate solution for routing and transforming container logs on Amazon ECS, especially when running on AWS Fargate. It integrates seamlessly with Fluent Bit or Fluentd as a sidecar container, enabling powerful log processing capabilities like parsing unstructured logs into JSON, filtering, and routing them to various destinations beyond CloudWatch Logs. This approach centralizes log management without requiring modifications to the application code itself, aligning with best practices for containerized environments.

Why this answer

FireLens is an ECS log driver that integrates with Fluent Bit or Fluentd to route, filter, and transform container logs without modifying application code. By using FireLens with Fluent Bit, you can configure a JSON parser to convert stdout logs into JSON format before forwarding them to the centralized log management tool, meeting the requirement exactly.

Exam trap

The trap here is that candidates assume the awslogs log driver can format logs as JSON (it cannot) or that installing an agent on Fargate containers is possible (it is not), leading them to overlook FireLens as the only serverless-compatible, code-free option for log transformation and routing.

How to eliminate wrong answers

Option B is wrong because the awslogs log driver sends logs to Amazon CloudWatch Logs in plain text, not JSON, and it does not support configuring a JSON output format; it is designed for direct CloudWatch ingestion, not third-party tools. Option C is wrong because installing the CloudWatch Logs agent on a container is not supported in Fargate (which is serverless and does not allow host-level agents), and even if it were, it would not transform logs to JSON. Option D is wrong because it requires modifying application code, which the question explicitly prohibits.

318
Multi-Selectmedium

A developer is building a web application that uses Amazon Cognito for user authentication. Which TWO actions should be taken to secure the application?

Select 2 answers
A.Enable multi-factor authentication (MFA) for users.
B.Disable token expiration to avoid frequent re-authentication.
C.Use HTTPS for all communication between the client and the application.
D.Use IAM users for authentication instead of Cognito.
E.Store user tokens in local storage for persistence.
AnswersA, C

Enabling multi-factor authentication (MFA) for users significantly enhances the security posture of a web application. MFA adds a crucial second layer of verification beyond just a password, requiring users to provide something they know (their password) and something they have (like a code from an authenticator app or a hardware token). This makes it substantially more difficult for unauthorized individuals to gain access, even if they manage to compromise a user's primary credentials, aligning with robust identity and access management best practices.

Why this answer

Enabling multi-factor authentication (MFA) adds an extra layer of security beyond just a password, requiring users to provide a second factor (e.g., a one-time code from an authenticator app or SMS). This significantly reduces the risk of unauthorized access due to compromised credentials. Amazon Cognito supports MFA natively, allowing developers to enforce it for user pools.

Exam trap

The trap here is that candidates often think disabling token expiration improves user experience, but they overlook the critical security risk of token theft and the need for short-lived tokens (e.g., 1 hour for access tokens) combined with refresh tokens to balance security and usability.

319
MCQhard

A developer is troubleshooting performance issues in an application that uses Amazon DynamoDB as the primary data store. The application reads a large set of items using a Query operation on a Global Secondary Index (GSI). The developer notices high read latency and throttled requests on the GSI. The base table has sufficient read capacity. The GSI is projected with KEYS_ONLY. Which action would most likely reduce the latency and throttling?

A.Increase the read capacity units (RCU) of the base table.
B.Change the GSI projection to ALL.
C.Increase the read capacity units (RCU) of the GSI.
D.Create a Local Secondary Index instead.
AnswerC

Throttling on a Global Secondary Index (GSI) is a direct indication that its provisioned read capacity units (RCU) are insufficient to handle the current read request volume. Since GSIs have their own distinct capacity settings, increasing the RCU specifically for the GSI directly addresses this bottleneck. This action allows the index to process more read operations per second, thereby alleviating throttling and improving application performance and latency.

Why this answer

A Global Secondary Index (GSI) has its own provisioned read capacity, separate from the base table. When a Query operation reads from a GSI, it consumes RCUs from the GSI's capacity, not the base table's. Since the base table has sufficient read capacity but the GSI is experiencing throttling and high latency, increasing the GSI's RCU directly addresses the bottleneck by allowing more read requests per second against the index.

Exam trap

The trap here is that candidates often assume increasing the base table's capacity will resolve all read performance issues, failing to recognize that GSIs have independent capacity allocations and that throttling on a GSI requires adjusting the index's RCU, not the base table's.

How to eliminate wrong answers

Option A is wrong because increasing the base table's RCU does not affect the GSI's throughput; the GSI has its own independent capacity settings, and throttling on the GSI is caused by insufficient RCU on the index itself. Option B is wrong because changing the GSI projection to ALL would increase the size of each item returned, consuming more RCUs per query and potentially worsening latency and throttling, not reducing it. Option D is wrong because a Local Secondary Index (LSI) shares the base table's partition key and RCU/WCU, but it does not solve the issue of insufficient read capacity on the index; additionally, LSIs cannot be created after table creation if not initially defined, and they have different partition key constraints that do not address the GSI-specific throttling.

320
MCQmedium

A developer is using AWS Secrets Manager to store database credentials. The application runs on EC2 and needs to retrieve the secret. Which approach is the most secure?

A.Store the secret in an environment variable in the user data script.
B.Use an IAM role attached to the EC2 instance with permissions to access the secret, and call the AWS SDK to retrieve it at runtime.
C.Retrieve the secret at application startup and store it in a configuration file.
D.Download the secret from an S3 bucket using pre-signed URLs.
AnswerB

Attaching an IAM role to an EC2 instance provides a secure and scalable way to grant temporary, automatically rotated credentials to applications running on the instance. The application can then use the AWS SDK to programmatically retrieve the secret from AWS Secrets Manager at runtime, ensuring secrets are never hardcoded or stored persistently on the instance. This approach adheres to the principle of least privilege and eliminates the need for manual credential management.

Why this answer

It follows the principle of least privilege and avoids hardcoding or storing secrets in insecure locations. By attaching an IAM role to the EC2 instance, the application can securely retrieve the secret from AWS Secrets Manager at runtime using the AWS SDK, without ever exposing the secret in code, configuration files, or environment variables. This approach leverages IAM's temporary credentials from the instance metadata service (IMDS) to authenticate the SDK call, ensuring the secret is never persisted locally.

Exam trap

The trap here is that candidates often think storing secrets in environment variables or configuration files is acceptable because it's 'runtime only,' but the exam emphasizes that any persistent or accessible storage of secrets violates security best practices, and only IAM roles with SDK retrieval provide the necessary isolation and rotation support.

How to eliminate wrong answers

Option A is wrong because storing the secret in an environment variable via user data script exposes it in the EC2 instance's metadata and process list, making it accessible to any user or process on the instance and violating security best practices. Option C is wrong because storing the secret in a configuration file after retrieval persists it on disk, increasing the risk of exposure through file system access, backups, or logs, and defeats the purpose of using Secrets Manager for dynamic rotation. Option D is wrong because downloading the secret from an S3 bucket using pre-signed URLs requires storing the secret in S3 first, which introduces additional management overhead and potential exposure, and pre-signed URLs can be intercepted or leaked, whereas Secrets Manager provides native encryption and access control.

321
MCQeasy

A developer is using AWS CodeCommit as a source repository. They want to automatically build and test code whenever a new branch is created. Which AWS service should they use to trigger the pipeline?

A.Amazon CloudWatch Events
B.Amazon S3 event notification
C.Amazon Simple Notification Service (SNS)
D.AWS Lambda
AnswerA

Amazon CloudWatch Events (now Amazon EventBridge) is the correct service for capturing and reacting to events from AWS CodeCommit. It allows developers to create rules that match specific repository activities, such as pushes to a branch or pull request state changes. These rules then route the events to various targets, including AWS CodePipeline to initiate a build, an AWS Lambda function for custom logic, or an Amazon SNS topic for notifications, making it the central hub for event-driven automation.

Why this answer

Amazon CloudWatch Events (now part of Amazon EventBridge) can capture AWS CodeCommit repository events, such as the creation of a new branch. By setting a rule that matches the 'Reference Created' event type, you can automatically trigger an AWS CodePipeline pipeline execution, enabling continuous integration for new branches.

Exam trap

The trap here is that candidates may confuse the service that emits the event (CodeCommit) with the service that routes the event to the pipeline (CloudWatch Events/EventBridge), leading them to incorrectly select Lambda or SNS as the trigger mechanism.

How to eliminate wrong answers

Option B is wrong because Amazon S3 event notifications are designed for object-level events in S3 buckets (e.g., PUT, DELETE), not for Git repository events like branch creation in CodeCommit. Option C is wrong because Amazon SNS is a pub/sub messaging service for sending notifications, not a trigger mechanism for directly invoking a pipeline; it would require an intermediary to process the message and start the pipeline. Option D is wrong because AWS Lambda can be invoked by CodeCommit events via CloudWatch Events, but it is not the service that directly triggers the pipeline; the question asks which service triggers the pipeline, and Lambda would need custom code to call the pipeline API, whereas CloudWatch Events can natively target CodePipeline.

322
MCQhard

An application running on an EC2 instance needs to access a DynamoDB table. The instance is in a private subnet. What is the most secure way to grant access without using long-lived credentials?

A.Create a VPC endpoint for DynamoDB and attach a security group to allow access.
B.Store IAM user access keys in the application configuration file.
C.Create an IAM role with DynamoDB access and attach it to the EC2 instance profile.
D.Use a security group to allow the EC2 instance to communicate with DynamoDB.
AnswerC

Attaching an IAM role with DynamoDB access to an EC2 instance profile is the AWS best practice for granting permissions to applications running on EC2 instances. This mechanism allows the EC2 instance to obtain temporary, frequently rotated credentials from the instance metadata service (IMDS). The application can then use these temporary credentials to make authorized API calls to AWS services like DynamoDB, eliminating the need to store static, long-lived credentials on the instance and enhancing security.

Why this answer

It uses an IAM role attached to the EC2 instance profile, which allows the instance to obtain temporary security credentials from the AWS Security Token Service (STS). This eliminates the need for long-lived credentials and follows the principle of least privilege. The instance can securely access DynamoDB without storing any secrets on the instance.

Exam trap

The trap here is that candidates often confuse network-level controls (VPC endpoints or security groups) with identity-based access control, mistakenly thinking that enabling private connectivity alone grants API access to DynamoDB.

How to eliminate wrong answers

Option A is wrong because a VPC endpoint for DynamoDB enables private network connectivity but does not grant IAM permissions; without an IAM role or credentials, the EC2 instance cannot authenticate to DynamoDB. Option B is wrong because storing IAM user access keys in the application configuration file introduces long-lived credentials that can be compromised, violating the security best practice of using temporary credentials. Option D is wrong because security groups control network traffic at the instance level and cannot authenticate or authorize API calls to DynamoDB; DynamoDB access requires IAM permissions, not network rules.

323
MCQmedium

A developer needs to grant an IAM user in the same AWS account access to a specific object in an S3 bucket. The bucket policy currently grants access only to the bucket owner (the root account). Which identity-based policy statement should the developer add to the IAM user's permissions?

A.A bucket policy that allows s3:GetObject for the user.
B.An IAM policy that allows s3:GetObject for the specific object ARN.
C.An S3 access point policy.
D.An IAM policy that allows s3:ListBucket for the bucket.
AnswerB

This is the correct and most direct method for granting an IAM user access to a specific S3 object. An IAM policy is an identity-based policy attached directly to the IAM user (or their group/role), explicitly defining their permissions. By allowing s3:GetObject for the specific object's Amazon Resource Name (ARN), the user is directly granted the necessary permission to retrieve that object's content, provided no explicit deny exists elsewhere.

Why this answer

An IAM policy attached directly to the user can grant s3:GetObject permission for a specific object ARN (e.g., arn:aws:s3:::bucket-name/object-key). This identity-based policy overrides the bucket policy's default deny for the root-only access, as long as there is no explicit deny in the bucket policy. The bucket policy restricts access to the root account, but an explicit allow in an IAM policy can still grant access to the user since IAM policies and bucket policies are evaluated together, and an explicit allow in either can permit the action unless an explicit deny exists.

Exam trap

The trap here is that candidates confuse resource-based policies (bucket policies) with identity-based policies (IAM policies) and assume that a bucket policy is the only way to grant S3 access, overlooking that IAM policies can grant access to specific objects even when the bucket policy restricts access to the root account.

How to eliminate wrong answers

Option A is wrong because a bucket policy is a resource-based policy, not an identity-based policy; the question specifically asks for an identity-based policy statement to add to the IAM user's permissions. Option C is wrong because an S3 access point policy is a separate resource-based policy attached to an access point, not an identity-based policy attached to the IAM user; it does not directly grant permissions to the user's identity. Option D is wrong because s3:ListBucket is a bucket-level action that lists objects in the bucket, not a specific object-level action; it does not grant access to a specific object and is irrelevant for granting GetObject on a particular object ARN.

324
MCQeasy

A developer is troubleshooting an EC2 instance that cannot connect to the internet. The instance has a public IP address and is in a public subnet with a route to an internet gateway. The security group allows all outbound traffic. What is the most likely cause?

A.The subnet's route table does not have a route to an internet gateway.
B.The security group's outbound rules are too restrictive.
C.The network ACL's outbound rules are blocking traffic.
D.The instance does not have a public IP address.
AnswerC

Unlike security groups, network ACLs are stateless, meaning outbound and return inbound traffic must each be explicitly permitted by separate rule evaluations; if the outbound NACL rules block traffic to the internet, or the inbound rules fail to allow the ephemeral port range needed for return traffic, connectivity will fail even with a correctly configured route table and permissive security group.

Why this answer

Network ACLs are stateless and block traffic unless explicitly allowed. The security group allows all outbound traffic, but if the network ACL's outbound rules are too restrictive, traffic can be blocked. Option A is wrong because the subnet has a route to an internet gateway.

Option B is wrong because the security group allows all outbound traffic. Option D is wrong because the instance has a public IP address.

325
MCQeasy

A developer is building a serverless application using AWS Lambda and Amazon DynamoDB. The Lambda function reads from a DynamoDB table. The function fails with a timeout error when processing large items. What is the MOST efficient solution?

A.Increase the Lambda function memory.
B.Increase the Lambda function timeout.
C.Enable Lambda provisioned concurrency.
D.Increase the DynamoDB read capacity units.
AnswerA

Increasing Lambda function memory allocates more CPU and network bandwidth, which can accelerate execution for CPU-bound or network-intensive tasks. However, if the function's processing time inherently exceeds its configured timeout, simply adding more memory will not prevent termination. The function will still be stopped once the timeout limit is reached, regardless of its available resources, making this an indirect and often insufficient solution for a timeout issue.

Why this answer

In AWS Lambda, CPU power is allocated proportionally to the configured memory. When a Lambda function times out while processing large items or files, it is typically due to CPU bottlenecks (such as serialization, deserialization, or processing overhead). Increasing the memory (Option A) automatically increases the CPU power, which speeds up execution and resolves the timeout.

Simply increasing the timeout (Option B) allows the function to run longer but does not address the performance bottleneck and can lead to higher latency and costs.

Exam trap

Candidates often think that a timeout error should always be fixed by increasing the timeout limit (Option B). However, for resource-intensive tasks like processing large items, increasing the memory (Option A) is the most efficient solution because it scales CPU power, reducing execution time and often lowering overall costs.

How to eliminate wrong answers

Option A is wrong because increasing memory also increases CPU and network throughput, but the issue is time, not resource constraints; the function may still timeout if the processing duration exceeds the new timeout. Option C is wrong because provisioned concurrency keeps functions initialized to reduce cold starts, but does not extend the maximum execution duration for a single invocation. Option D is wrong because the error is a Lambda timeout, not a DynamoDB throttling issue; increasing read capacity units would not affect how long the Lambda function takes to process items.

326
MCQhard

A developer applied the above bucket policy to an S3 bucket. What is the outcome?

A.Anonymous users are allowed to read objects.
B.Only write requests are denied if not using HTTPS.
C.All requests to the bucket must use HTTPS; otherwise, they are denied.
D.The policy has no effect because it uses Deny.
AnswerC

This statement is correct. The bucket policy uses an `Effect: Deny` combined with a `Condition` that `aws:SecureTransport` is `false`. This configuration explicitly blocks any request made to the S3 bucket that does not utilize HTTPS encryption. Consequently, all successful interactions with the bucket must occur over a secure transport layer, enforcing HTTPS for data in transit.

Why this answer

The bucket policy includes a `Deny` effect with a `StringNotEquals` condition on `aws:SecureTransport`, which denies any request that does not use HTTPS. Since the `Principal` is set to `*`, this applies to all users, including anonymous users. Therefore, any request made over HTTP is denied, effectively requiring HTTPS for all access.

Exam trap

The trap here is that candidates often think a `Deny` statement with a condition is ineffective or only applies to specific actions, but in reality, the `Deny` with `StringNotEquals` on `aws:SecureTransport` explicitly blocks all non-HTTPS requests, making it a powerful enforcement mechanism.

How to eliminate wrong answers

Option A is wrong because the policy denies all requests that are not HTTPS, and anonymous users are subject to this condition; they are not allowed to read objects unless they use HTTPS. Option B is wrong because the policy denies all requests (both read and write) that do not use HTTPS, not just write requests. Option D is wrong because the policy does have an effect: it uses `Deny` with a condition, which is a valid and enforceable S3 bucket policy statement that blocks non-HTTPS requests.

327
MCQhard

A developer is troubleshooting an AWS Lambda function that processes messages from an Amazon SQS queue. The function is configured with a batch size of 10 and a maximum concurrency of 5. The function frequently reports errors related to message processing timeouts. The function code is idempotent. Which combination of actions will reduce the number of timeouts and improve processing efficiency?

A.Increase the function timeout to 30 seconds and set the SQS visibility timeout to 6 minutes.
B.Increase the batch size to 20 and increase the function timeout to 30 seconds.
C.Reduce the batch size to 5 and increase the maximum concurrency to 10.
D.Increase the maximum concurrency to 10 and set the SQS visibility timeout to 30 seconds.
AnswerC

Reducing the SQS batch size to 5 messages per invocation decreases the amount of work each Lambda instance must perform, thereby lowering the execution time and reducing the likelihood of timeouts. Simultaneously, increasing the maximum concurrency to 10 allows more Lambda instances to run in parallel, effectively processing multiple smaller batches concurrently. This combination optimizes for faster individual processing while scaling out to maintain or improve overall message throughput.

Why this answer

Reducing the batch size to 5 decreases the number of messages processed per invocation, lowering the processing time and reducing the likelihood of timeouts. Increasing maximum concurrency to 10 allows more Lambda functions to run in parallel, improving overall throughput. Option A is wrong: increasing the Lambda timeout to 30 seconds alone does not address the root cause (overloaded invocations), and setting the SQS visibility timeout to 6 minutes may cause delayed retries if messages fail.

Option B is wrong: increasing the batch size to 20 would increase the processing time per invocation, exacerbating timeouts. Option D is wrong: increasing concurrency to 10 helps parallelism but does not reduce the per-invocation workload; setting visibility timeout to 30 seconds is too short, risking message duplication if processing exceeds that time.

328
MCQmedium

Refer to the exhibit. A developer ran the above commands to inspect a KMS key. What can be determined about this key?

A.The key is disabled.
B.The key can be used in multiple AWS regions.
C.The key is an AWS managed key.
D.The key is a customer managed key.
AnswerD

The KeyManager field explicitly reads CUSTOMER, which is the definitive indicator that this key was created directly by the account owner and is a customer managed key, giving the account full control over its policy, rotation, and lifecycle.

Why this answer

The KeyManager field shows 'CUSTOMER', indicating it is a customer managed key. Option A is incorrect because KeyState is 'Enabled', so the key is not disabled. Option B is incorrect because MultiRegion is false, so the key is not multi-region.

Option C is incorrect because the key is customer managed, not AWS managed.

329
MCQmedium

A developer is using AWS CodeBuild to build a Java application. The build fails with the error 'BUILD_CONTAINER_UNABLE_TO_PULL_IMAGE'. What is the most likely cause?

A.The build environment does not have enough memory.
B.The Docker image specified in the build environment does not exist or the repository is not accessible.
C.The build command has a syntax error.
D.The buildspec.yml file does not define artifacts.
AnswerB

A "pull image" error in AWS CodeBuild directly signifies that the CodeBuild service was unable to retrieve the specified Docker image from its source repository. This can occur if the image name or tag is incorrect, leading to the image not being found, or if CodeBuild lacks the necessary IAM permissions to access a private repository like Amazon ECR. Network connectivity issues to the repository or misconfigured repository policies could also prevent a successful image pull, halting the build before any commands execute.

Why this answer

The error 'BUILD_CONTAINER_UNABLE_TO_PULL_IMAGE' in AWS CodeBuild indicates that the service cannot pull the specified Docker image from the repository. This occurs when the image name/tag is incorrect, the image does not exist in the specified registry (e.g., Amazon ECR or Docker Hub), or the CodeBuild service role lacks the necessary permissions (e.g., ecr:GetDownloadUrlForLayer, ecr:BatchGetImage) to access the repository. Option B correctly identifies this as the most likely cause.

Exam trap

The trap here is that candidates often confuse build-phase errors (like syntax errors in commands) with environment setup errors (like image pull failures), leading them to select options related to build commands or artifacts instead of recognizing the error message's specific reference to container image retrieval.

How to eliminate wrong answers

Option A is wrong because insufficient memory would cause a different error, such as 'BUILD_CONTAINER_MEMORY_LIMIT_EXCEEDED' or a container OOM kill, not an image pull failure. Option C is wrong because a syntax error in the build command would result in a build phase failure (e.g., 'Error: command not found' or a non-zero exit code), not a container image pull error. Option D is wrong because the absence of artifacts in buildspec.yml would cause a build success but no output, or a warning, not a container image pull failure.

330
MCQmedium

A company is using AWS Secrets Manager to rotate database credentials automatically. The rotation Lambda function fails with a timeout. Which action should be taken to resolve this issue?

A.Reduce the rotation schedule interval.
B.Increase the Lambda function timeout.
C.Place the Lambda function in a VPC with a NAT gateway.
D.Store the rotation schedule in EC2 user data.
AnswerB

AWS Secrets Manager leverages a Lambda function to execute the actual database credential rotation logic. When this Lambda function's execution duration exceeds its configured timeout setting, the function is forcibly terminated, preventing the successful completion of the rotation process. Increasing the Lambda function's timeout directly provides more execution time, allowing the rotation logic to connect to the database, modify credentials, and update Secrets Manager without premature termination.

Why this answer

The Lambda function is timing out during the rotation process, which indicates that the default 3-second timeout is insufficient for the rotation logic. Increasing the Lambda function timeout (Option B) directly addresses this by allowing the function more time to complete the rotation, such as calling the Secrets Manager API, updating the database, and verifying the new credentials.

Exam trap

The trap here is that candidates may confuse a timeout with a network issue and incorrectly choose to place the Lambda in a VPC with a NAT gateway, when the real problem is simply that the default execution duration is too short for the rotation logic.

How to eliminate wrong answers

Option A is wrong because reducing the rotation schedule interval does not fix a timeout during execution; it only makes the rotation happen more frequently, potentially exacerbating the issue. Option C is wrong because placing the Lambda function in a VPC with a NAT gateway is unrelated to a timeout; it is used to enable internet access for Lambda functions in a VPC, but rotation timeouts are typically due to insufficient execution time, not network connectivity. Option D is wrong because storing the rotation schedule in EC2 user data is irrelevant; Secrets Manager rotation is managed by Lambda, not EC2, and user data is used for instance bootstrapping, not for scheduling rotation.

331
MCQhard

A developer is building a multi-region application using Amazon DynamoDB global tables. The application needs to read data from a replica table in a different region shortly after a write in the primary region. The developer notices that reads sometimes return stale data. Which of the following explains this behavior?

A.Global tables use asynchronous replication, introducing unavoidable replication lag.
B.The developer must use DynamoDB Streams to capture changes and replicate them separately.
C.The developer must enable strong consistency reads on the replica table.
D.The global table must be configured with write forwarding.
AnswerA

DynamoDB Global Tables are built upon an asynchronous, multi-master replication model, which inherently leads to eventual consistency across regions. This design means there will always be an unavoidable, albeit typically brief, replication lag between regions. Data written to one region is propagated to other replica regions with a small delay, ensuring high availability and low latency writes globally but not immediate read consistency across regions.

Why this answer

Amazon DynamoDB global tables use asynchronous replication to propagate writes from one region to all other replica tables. This means that after a write in the primary region, there is an inherent replication lag (typically sub-second but can be higher under load or network issues) before the change is visible in other regions. The developer observes stale reads because the read is hitting a replica that has not yet received the update, which is expected behavior for eventually consistent reads on global tables.

Exam trap

The trap here is that candidates often assume DynamoDB global tables provide immediate consistency across regions (like synchronous replication) or that they can simply switch to strong consistency reads on replicas, but the exam tests the understanding that global tables are eventually consistent and that strong consistency is not available on replica tables.

How to eliminate wrong answers

Option B is wrong because DynamoDB Streams are used to capture item-level changes for custom processing (e.g., triggering Lambda functions), but they are not required for replication in global tables—global tables handle replication internally using the DynamoDB replication protocol. Option C is wrong because strong consistency reads are not supported on replica tables in a global table setup; only eventually consistent reads are available on replicas, so enabling strong consistency reads is not an option. Option D is wrong because write forwarding is a feature that allows a write request to a replica to be forwarded to the primary region for execution, but it does not affect the read consistency or replication lag when reading from a replica after a write in the primary region.

332
MCQmedium

A developer is using AWS Elastic Beanstalk to deploy a web application. The application uses an in-environment Amazon RDS database instance. The developer needs to update the application code without risking data loss. The database must not be affected by environment operations such as termination or updates. What is the recommended approach?

A.Create a standalone Amazon RDS instance and reconfigure the application to use it instead of the in-environment database.
B.Take a snapshot of the database before each deployment and restore it after the deployment completes.
C.Use the Elastic Beanstalk environment's 'Swap environment URLs' feature to perform a blue/green deployment.
D.Create a new Elastic Beanstalk environment with a new RDS instance and migrate data manually.
AnswerA

Elastic Beanstalk's in-environment databases are tightly coupled to the environment's lifecycle, meaning they are terminated along with the environment, leading to data loss. By provisioning a standalone Amazon RDS instance, the database becomes an independent, persistent resource. This decouples the data layer from the application environment, ensuring data persistence across environment updates, terminations, or blue/green deployments, making it the recommended best practice for production applications.

Why this answer

Decoupling the RDS database from the Elastic Beanstalk environment by creating a standalone RDS instance ensures that the database is not tied to the environment's lifecycle. In-environment databases are automatically deleted when the environment is terminated or updated, risking data loss. By reconfiguring the application to point to an external RDS instance, the database persists independently of environment operations, meeting the requirement to avoid data loss during code updates or environment changes.

Exam trap

The trap here is that candidates may assume the 'Swap environment URLs' blue/green deployment (Option C) inherently protects the database, but they overlook that in-environment databases are still tied to the environment lifecycle, so the original database can be lost when the old environment is terminated.

How to eliminate wrong answers

Option B is wrong because taking a snapshot before each deployment and restoring it after does not prevent data loss during the deployment window; any writes between the snapshot and restore would be lost, and it introduces unnecessary complexity and downtime. Option C is wrong because the 'Swap environment URLs' feature for blue/green deployment swaps traffic between two environments, but if both environments use in-environment databases, the database in the original environment is still at risk of deletion or data loss during termination or updates. Option D is wrong because creating a new environment with a new RDS instance and manually migrating data does not guarantee zero data loss during the migration process, and it duplicates effort without addressing the core issue of decoupling the database from the environment lifecycle.

333
MCQeasy

A developer is deploying a Node.js application to AWS Elastic Beanstalk. The application uses environment variables for database credentials. What is the BEST way to securely provide these credentials to the application?

A.Store the credentials in a file in the source code repository.
B.Store the credentials in the application's configuration file within the deployment package.
C.Hardcode the credentials in the application code.
D.Set environment properties in the Elastic Beanstalk environment configuration.
AnswerD

Elastic Beanstalk environment properties are injected as process environment variables at instance launch, keeping credentials out of source code and configuration files. They are stored encrypted at rest by the platform and can reference Secrets Manager or SSM Parameter Store values.

Why this answer

Elastic Beanstalk allows you to set environment properties in the environment configuration, which are injected as environment variables into the application's runtime. This approach keeps sensitive credentials out of the source code and deployment artifacts, adhering to the principle of least privilege and secure credential management. For a Node.js application, these environment variables can be accessed via `process.env`, providing a secure and flexible way to manage database credentials without hardcoding or storing them in files.

Exam trap

The trap here is that candidates may think storing credentials in a configuration file (Option B) is acceptable because it separates code from configuration, but they overlook that the configuration file is still part of the deployment package and can be accessed by anyone with access to the artifact or the running environment.

How to eliminate wrong answers

Option A is wrong because storing credentials in a file in the source code repository exposes them to anyone with access to the repository, violating security best practices and potentially leading to credential leakage in version control history. Option B is wrong because including credentials in the application's configuration file within the deployment package embeds them in the deployable artifact, making them accessible to anyone who can access the deployment package or the running environment's filesystem. Option C is wrong because hardcoding credentials in the application code is a severe security risk, as it exposes secrets in the codebase, makes rotation difficult, and violates the principle of separating configuration from code.

334
MCQeasy

A developer is creating an IAM policy for an Amazon S3 bucket that must allow read access to a specific object only. Which policy element should be used to restrict access to the object?

A.Action
B.Condition
C.Principal
D.Resource
AnswerD

The Resource element is precisely where the specific AWS entity or entities that a policy statement applies to are defined. To restrict access to a particular S3 object, its unique Amazon Resource Name (ARN) must be explicitly listed in this field. This directly scopes the policy's permissions to 'that object only,' ensuring fine-grained control over access to individual S3 objects rather than an entire bucket.

Why this answer

The Resource element in an IAM policy specifies the object or bucket to which the policy applies. To allow read access to a specific object only, you must specify the object's ARN (e.g., arn:aws:s3:::bucket-name/object-key) in the Resource element. This restricts the policy's effect to that object.

Exam trap

DVA-C02 often tests the confusion between Action and Resource, where candidates mistakenly believe Action restricts the object, when Resource is the element that specifies the target object.

How to eliminate wrong answers

Option A is wrong because the Action element specifies the API operations (e.g., s3:GetObject) but does not restrict which object the action applies to. Option B is wrong because the Condition element adds constraints (e.g., IP address, MFA) but does not identify the target object; it is used in conjunction with Resource. Option C is wrong because the Principal element specifies who is allowed or denied access (e.g., an IAM user or role), not which object is accessed.

335
MCQmedium

A developer is deploying a web application using AWS Elastic Beanstalk. The application uses a MySQL database. During deployment, the developer needs to apply database schema migrations. Which approach should the developer use to run database migrations as part of the Elastic Beanstalk deployment?

A.Use an .ebextensions configuration file to run a migration script during deployment.
B.Configure an RDS event subscription to trigger a Lambda function that runs migrations.
C.Run the migration script as a scheduled task using CloudWatch Events.
D.Use AWS CodeDeploy's AppSpec file to run the migration script.
AnswerA

Using an .ebextensions configuration file is the correct approach because Elastic Beanstalk processes these files during deployment, allowing developers to execute custom commands on the EC2 instances. Specifically, `container_commands` or `commands` within these YAML files can run database migration scripts at a specific point in the application deployment lifecycle. This ensures the database schema is updated in sync with the new application code before it starts serving traffic.

Why this answer

Elastic Beanstalk supports .ebextensions configuration files that can execute custom commands or scripts during deployment. By placing a migration script (e.g., a shell script that runs `mysql` commands or a framework migration tool) in the `.ebextensions` directory and using the `commands` or `container_commands` key, the developer can ensure the migration runs automatically after the application is deployed but before the new environment serves traffic. This approach integrates the migration into the deployment lifecycle without external dependencies.

Exam trap

The trap here is that candidates often confuse the deployment lifecycle hooks of different AWS services (e.g., CodeDeploy's AppSpec vs. Elastic Beanstalk's .ebextensions) and assume any migration script can be plugged into any deployment tool, ignoring that Elastic Beanstalk has its own proprietary configuration mechanism.

How to eliminate wrong answers

Option B is wrong because RDS event subscriptions notify about database events (e.g., failover, backup completion) but do not trigger Lambda functions directly; while you could use EventBridge to route RDS events to Lambda, this approach is asynchronous and unrelated to the deployment lifecycle, so it cannot guarantee migrations run exactly during an Elastic Beanstalk deployment. Option C is wrong because running migrations as a scheduled task using CloudWatch Events would execute at fixed times, not in sync with the deployment process, leading to potential schema mismatches or race conditions. Option D is wrong because AWS CodeDeploy's AppSpec file is used for deployments managed by CodeDeploy, not Elastic Beanstalk; Elastic Beanstalk has its own deployment mechanism and does not read or execute AppSpec files.

336
Multi-Selectmedium

A company is using Amazon S3 to store large objects. Users report that uploads are slow. Which THREE actions should the developer take to optimize upload performance?

Select 3 answers
A.Use multipart upload for objects over 100 MB.
B.Use S3 Select to upload only specific parts of the object.
C.Enable S3 Transfer Acceleration.
D.Transition objects to S3 Glacier after upload.
E.Use multiple S3 prefixes to increase request rate.
AnswersA, C, E

Multipart upload splits a large object into independent parts that are uploaded in parallel, which dramatically increases throughput and enables efficient retries for individual failed parts. The AWS SDKs automatically apply multipart upload when an object exceeds the 100 MB threshold, and it is the recommended approach for objects over 100 MB because it also allows you to pause and resume uploads, reducing the impact of network interruptions.

Why this answer

Multipart upload improves throughput for large objects over 100 MB by uploading parts in parallel. Option C is correct because S3 Transfer Acceleration uses CloudFront edge locations to reduce latency for uploads over long distances. Option E is correct because using multiple S3 prefixes (i.e., parallelizing requests across different key prefixes) can increase the request rate and overall throughput.

Option B is incorrect because S3 Select is used to retrieve subsets of data from an object, not to upload. Option D is incorrect because transitioning to S3 Glacier is for data lifecycle management, not for improving upload performance.

337
MCQeasy

A developer notices that an EC2 instance running a web application is unreachable via its public IP. The instance passes status checks but security group rules appear correct. What should the developer check NEXT?

A.Verify that the instance has an Elastic IP associated.
B.Check the network ACL associated with the subnet for rules that may block traffic.
C.Review the route table for a route to an internet gateway.
D.Inspect the IAM role attached to the instance for network permissions.
AnswerB

Network ACLs are stateless, meaning both inbound and outbound rules must be explicitly evaluated for traffic to flow, unlike security groups which are stateful and automatically allow return traffic. In this scenario, the instance passes status checks and security group rules appear correct, so the developer must verify whether the subnet’s network ACL is blocking inbound or outbound traffic, satisfying the constraint that the issue lies at the subnet boundary rather than the instance or security group.

Why this answer

The instance passes status checks, the route table is confirmed to have a route to an internet gateway, and security group rules appear correct. Since the instance is still unreachable via its public IP, the next logical step is to check the network ACL (NACL) associated with the subnet. NACLs are stateless and can block inbound or outbound traffic even if security groups allow it.

NACLs evaluate rules in order by rule number, and a deny rule (or missing allow rule) for the required ephemeral ports (e.g., 1024-65535 for return traffic) could silently drop packets.

Exam trap

Candidates often assume security group rules are the only network filter and overlook the stateless nature of network ACLs, which can block traffic even when security groups and route tables are correctly configured.

How to eliminate wrong answers

Option A is wrong because an Elastic IP is not required for public IP reachability; an instance with a public IP assigned by AWS (from the subnet's auto-assign public IP setting) is reachable without an Elastic IP, so this check is premature and not the next step. Option C is wrong because the route table must have a route to an internet gateway for public traffic, but the question states the instance is unreachable via its public IP, and a missing route would typically cause a different symptom (e.g., no connectivity at all) rather than passing status checks; also, route tables are often checked earlier in troubleshooting, but the question specifies security groups appear correct, making NACL the more likely culprit. Option D is wrong because IAM roles control permissions for AWS API actions (e.g., S3, DynamoDB), not network-level traffic to/from the instance; network permissions are governed by security groups and NACLs, not IAM.

338
MCQmedium

A developer needs an S3 upload workflow where clients upload large files directly to S3 without exposing AWS credentials through the browser. What should the backend generate?

A.Pre-signed URLs with appropriate expiration and object restrictions
B.Long-lived IAM access keys for each client
C.A public-read bucket policy
D.An S3 Inventory report
AnswerA

Pre-signed URLs grant temporary, time-limited access to specific S3 objects or prefixes without requiring AWS credentials directly from the client. They are generated by an AWS credential holder and can be configured with specific permissions (e.g., PutObject), an expiration time, and even conditions on the upload like content type or size. This approach securely delegates upload capability to unauthenticated clients for a defined period, aligning perfectly with the requirement for client uploads without exposing long-term credentials.

Why this answer

Pre-signed URLs allow the backend to generate time-limited, permission-restricted URLs that clients can use to upload objects directly to S3 without exposing AWS credentials. The backend signs the URL with IAM credentials, and the client uses the URL to perform the PUT operation, ensuring secure, credential-free uploads.

Exam trap

The trap here is that candidates may confuse pre-signed URLs with public bucket policies or long-lived keys, thinking that any form of direct access requires exposing credentials, when in fact pre-signed URLs provide temporary, scoped access without credential leakage.

How to eliminate wrong answers

Option B is wrong because long-lived IAM access keys would expose permanent credentials in the browser, violating the requirement to avoid credential exposure and creating a severe security risk. Option C is wrong because a public-read bucket policy allows anyone to read objects but does not provide a secure, controlled upload mechanism; it would also expose the bucket to unauthorized writes if not carefully restricted. Option D is wrong because an S3 Inventory report is a listing of objects for auditing or lifecycle management, not a mechanism for uploading files.

339
MCQeasy

A developer is creating an IAM policy to allow an EC2 instance to read objects from a specific S3 bucket named 'my-app-data'. The policy should be attached to an IAM role that will be assumed by the EC2 instance. Which policy statement meets this requirement?

A.{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:*", "Resource": "arn:aws:s3:::my-app-data/*" } ] }
B.{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:GetObject", "Resource": "*" } ] }
C.{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "s3:GetObject", "s3:PutObject" ], "Resource": "arn:aws:s3:::my-app-data/*" } ] }
D.{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "s3:GetObject", "Resource": "arn:aws:s3:::my-app-data/*" } ] }
AnswerD

This policy correctly grants only the necessary read access to the specified S3 resources. The "Action": "s3:GetObject" precisely allows the retrieval of objects, which is a read-only operation. Furthermore, the "Resource": "arn:aws:s3:::my-app-data/*" correctly limits this permission to objects within the 'my-app-data' bucket, adhering to the principle of least privilege by preventing access to other buckets or broader S3 actions.

Why this answer

It grants only the s3:GetObject permission on the specific S3 bucket 'my-app-data' and its objects, which is the minimum required to allow an EC2 instance to read objects from that bucket. The policy is designed to be attached to an IAM role that the EC2 instance assumes, following the principle of least privilege.

Exam trap

The trap here is that candidates often choose overly permissive policies (like s3:* or including s3:PutObject) or forget to scope the resource to the specific bucket, leading to security misconfigurations that fail the principle of least privilege.

How to eliminate wrong answers

Option A is wrong because it allows all S3 actions (s3:*) on the bucket objects, which is overly permissive and violates the requirement to only allow read access. Option B is wrong because it allows s3:GetObject on all S3 resources (*), which grants read access to any S3 bucket, not just 'my-app-data', and is a security risk. Option C is wrong because it includes s3:PutObject in addition to s3:GetObject, which allows write access to the bucket, exceeding the requirement of read-only access.

340
Multi-Selecteasy

A company wants to enforce multi-factor authentication (MFA) for all IAM users accessing the AWS Management Console. Which THREE actions are required?

Select 3 answers
A.Instruct users to use their MFA device when logging in
B.Configure a password policy that requires MFA
C.Create a service control policy (SCP) to enforce MFA
D.Enable MFA for each IAM user
E.Create an IAM policy that denies access unless MFA is present
AnswersA, D, E

This option describes the user's required action once MFA is properly configured and enforced. After an MFA device is associated with an IAM user and an IAM policy requires its use, users must actively provide the time-based one-time password (TOTP) from their virtual or hardware MFA device during the authentication process to successfully log into the AWS Management Console or make API calls. This is the final step in the MFA workflow from the user's perspective.

Why this answer

Option D is correct because MFA must first be enabled/assigned for each IAM user (via the IAM console, CLI, or API, associating a virtual or hardware MFA device) before it can be enforced. Option A is correct because users must actually supply the MFA code at sign-in; the AWS Management Console login flow prompts for the MFA token after the password, and without that second factor the session cannot be established. Option E is correct because an IAM policy using the aws:MultiFactorAuthPresent condition key (typically with a Deny statement, e.g., denying all actions when aws:MultiFactorAuthPresent is false) enforces MFA programmatically for console access.

Option B is not correct because a password policy controls password complexity, length, reuse, and expiration—it has no MFA enforcement capability. Option C is not correct because SCPs apply only to AWS Organizations accounts (setting permission guardrails) and do not enforce MFA for individual IAM users in a single account.

Exam trap

Candidates often think that password policies can enforce MFA, but AWS IAM password policies only control password complexity, expiration, and reuse. They cannot enforce MFA. Similarly, while SCPs can deny actions without MFA at the Organization level, they do not configure or enable MFA for individual IAM users.

341
MCQeasy

A developer is using Amazon DynamoDB to store session data for a web application. The application experiences read-heavy traffic and the developer wants to reduce latency. Which feature should be used to improve read performance?

A.DynamoDB Global Tables
B.DynamoDB Streams
C.DynamoDB Accelerator (DAX)
D.DynamoDB Time to Live (TTL)
AnswerC

DynamoDB Accelerator (DAX) is a fully managed, highly available, in-memory cache specifically designed for DynamoDB. It provides microsecond response times for read-heavy workloads by caching frequently accessed data, significantly reducing the load on the underlying DynamoDB table. DAX is API-compatible with DynamoDB, allowing developers to integrate it with minimal application code changes to achieve substantial read performance improvements.

Why this answer

DynamoDB Accelerator (DAX) is a fully managed, in-memory cache that delivers up to 10x read performance improvement by reducing response times from milliseconds to microseconds. For read-heavy workloads like session data, DAX offloads read traffic from the DynamoDB table, reducing latency and providing a seamless caching layer without application code changes.

Exam trap

The trap here is that candidates confuse DynamoDB Global Tables (which reduce latency for cross-region reads) with a single-region read cache, but Global Tables do not improve read performance within the same region — DAX is the correct service for that purpose.

How to eliminate wrong answers

Option A is wrong because DynamoDB Global Tables provide multi-region replication for disaster recovery and low-latency writes across regions, but they do not improve read performance within a single region. Option B is wrong because DynamoDB Streams capture item-level changes for event-driven processing or replication, but they do not cache data or reduce read latency. Option D is wrong because DynamoDB Time to Live (TTL) automatically expires old session data to manage storage costs, but it has no impact on read performance or latency.

342
MCQeasy

Refer to the exhibit. A developer created this CloudFormation template. After deployment, the stack creation fails with 'Bucket name already exists'. What should the developer do to fix the issue?

A.Change the BucketName to include a random suffix.
B.Remove the MyQueue resource.
C.Remove the VersioningConfiguration from the bucket.
D.Set SqsManagedSseEnabled to false.
AnswerA

A hard-coded S3 BucketName such as MyBucket is not guaranteed to be globally unique; S3 bucket names are shared across all AWS accounts and regions, so the name may already be registered by another account. Changing the value to include a random suffix, for example by appending the AWS::AccountId or AWS::StackName pseudo parameter through Fn::Join or Fn::Sub, ensures a unique bucket name and allows the stack to create successfully.

Why this answer

The error 'Bucket name already exists' occurs because S3 bucket names are globally unique across all AWS accounts. The CloudFormation template hardcodes a BucketName that someone else already owns. The fix is to make the name unique, typically by appending a random suffix or using CloudFormation's auto-generated name (by omitting BucketName).

This ensures the stack can create a new bucket without collision.

Exam trap

DVA-C02 often tests the misconception that S3 bucket names are scoped to an account or region, when they are actually globally unique, leading candidates to overlook the need for a unique name.

How to eliminate wrong answers

Option B is wrong because removing the MyQueue resource does not address the S3 bucket name conflict and would break the application's messaging functionality. Option C is wrong because removing VersioningConfiguration does not resolve the global uniqueness requirement for bucket names. Option D is wrong because SqsManagedSseEnabled is a property of the SQS queue, not the S3 bucket, and toggling it has no effect on the bucket name collision.

343
MCQeasy

A company wants to encrypt data at rest in Amazon S3. Which AWS service can be used to manage the encryption keys?

A.AWS Certificate Manager (ACM)
B.AWS CloudHSM
C.AWS Identity and Access Management (IAM)
D.AWS Key Management Service (KMS)
AnswerD

AWS Key Management Service (KMS) is a fully managed service designed to simplify the creation, storage, and control of encryption keys used across various AWS services. It integrates seamlessly with Amazon S3 to provide server-side encryption with KMS-managed keys (SSE-KMS), where S3 utilizes your customer master keys (CMKs) to encrypt and decrypt objects. KMS ensures the secure lifecycle management and auditability of these cryptographic keys, which are fundamental for robust data-at-rest encryption in S3.

Why this answer

AWS Key Management Service (KMS) is the service that manages encryption keys for Amazon S3's server-side encryption with KMS (SSE-KMS). Option A is wrong because AWS Certificate Manager (ACM) handles SSL/TLS certificates, not encryption keys for S3. Option B is wrong because AWS CloudHSM provides hardware-based key management but is not directly integrated with S3 for SSE; KMS is the managed service for this use case.

Option C is wrong because AWS Identity and Access Management (IAM) controls access permissions, not encryption key management.

344
MCQeasy

A company uses AWS Elastic Beanstalk to deploy a web application. The development team wants to deploy a new version of the application to a separate environment for testing before switching production traffic. Which deployment strategy should be used?

A.Immutable deployment.
B.All at once deployment.
C.Blue/green deployment.
D.Rolling deployment.
AnswerC

Blue/green deployment is the correct strategy because it involves provisioning an entirely new, separate Elastic Beanstalk environment (the "green" environment) running the updated application version. This new environment can be thoroughly tested and validated in isolation without affecting the live "blue" environment. Once testing is complete, traffic is seamlessly redirected to the new environment by swapping the CNAME URL, enabling zero-downtime updates and providing an immediate rollback path by simply reverting the URL swap.

Why this answer

Blue/green deployment (Option C) creates a separate, independent environment (green) for the new version, allowing thorough testing before swapping the environment's URLs to route production traffic to the green environment. This minimizes risk and enables quick rollback. Option A (immutable) launches a new Auto Scaling group in the same environment but does not isolate the new version in a separate environment; Option B (all at once) updates all instances simultaneously in the same environment, causing downtime; Option D (rolling) updates instances in batches in the same environment, exposing some users to the new version during deployment.

345
MCQmedium

Why is the Lambda function not being invoked?

A.The Lambda execution role does not have permission to be invoked by S3.
B.The Lambda permission does not specify the correct source account.
C.The Lambda function has a runtime that is not supported.
D.The S3 bucket does not have a notification configuration for the Lambda function.
AnswerD

For an S3 bucket to trigger a Lambda function, a specific event notification configuration must be set up on the bucket. This configuration specifies which S3 events (e.g., s3:ObjectCreated:*) should trigger the Lambda function and identifies the target Lambda ARN. Without this explicit configuration, S3 will not publish events to the Lambda function, resulting in no invocation regardless of other permissions.

Why this answer

The most likely reason the Lambda function is not being invoked is that the S3 bucket does not have a notification configuration for the Lambda function. For S3 to invoke a Lambda function, you must configure an event notification on the bucket that specifies the Lambda function as the destination. Without this configuration, S3 will not send events to Lambda, and the function will never be invoked.

Exam trap

DVA-C02 often tests the difference between execution role permissions and resource-based policies. Candidates might think the execution role needs invoke permission, but actually S3 needs permission to invoke Lambda, which is granted via a resource-based policy, and the notification configuration must exist.

How to eliminate wrong answers

Option A is wrong because the Lambda execution role does not need permission to be invoked by S3; instead, S3 needs permission to invoke the Lambda function, which is granted via a resource-based policy on the Lambda function. Option B is wrong because while the Lambda permission must specify the correct source account, if it doesn't, S3 would receive an error when trying to invoke, but the function might still be invoked if the permission is correct; however, the question asks for the most likely reason for no invocation, and missing notification configuration is more fundamental. Option C is wrong because an unsupported runtime would cause the function to fail when invoked, not prevent invocation entirely.

346
MCQeasy

A developer is deploying a new version of a Lambda function using the AWS CLI. The function is part of a serverless application that processes S3 events. The developer wants to ensure that the new version is production-ready and that the old version is still available for rollback. Which CLI command should the developer use to create a new version of the Lambda function?

A.aws lambda publish-version --function-name my-function
B.aws lambda update-function-configuration --function-name my-function --handler new-handler
C.aws lambda update-function-code --function-name my-function --zip-file fileb://my-code.zip
D.aws lambda create-function --function-name my-function --zip-file fileb://my-code.zip
AnswerA

The `aws lambda publish-version` command is the correct method to create an immutable snapshot of a Lambda function's code and configuration. This action assigns a unique, sequential version number to the current state of the `$LATEST` function, making it available for consistent invocation, rollbacks, and integration with aliases for controlled deployments. It explicitly captures the function's current definition.

Why this answer

The `aws lambda publish-version` command creates an immutable, versioned snapshot of the Lambda function's code and configuration, which is required for production-ready deployments. This ensures the old version remains available for rollback while the new version is published with a unique version number (e.g., $LATEST, 1, 2). The command explicitly publishes the current $LATEST version as a new numbered version, making it production-ready without affecting existing versions.

Exam trap

The trap here is that candidates confuse deploying code with `update-function-code` (which only updates $LATEST) with publishing a new version, assuming that any code update automatically creates a version; in reality, you must explicitly run `publish-version` to create an immutable, numbered version for production use and rollback.

How to eliminate wrong answers

Option B is wrong because `update-function-configuration` only modifies the function's configuration settings (e.g., handler, runtime, environment variables) and does not create a new version; it updates the $LATEST version in place, leaving no immutable snapshot for rollback. Option C is wrong because `update-function-code` only deploys new code to the $LATEST version, overwriting the existing code without creating a new numbered version; the old code is lost unless a version was previously published. Option D is wrong because `create-function` is used to create a new Lambda function from scratch, not to deploy a new version of an existing function; it would fail if the function already exists or create a separate function, which does not preserve the old version for rollback.

347
MCQeasy

A developer needs to allow an EC2 instance to read items from a DynamoDB table. Which is the best practice for granting permissions?

A.Store IAM user access keys on the instance
B.Use root user credentials
C.Attach an IAM role with the required permissions to the EC2 instance
D.Apply a service control policy (SCP) to the instance
AnswerC

Attaching an IAM role with the required permissions to an EC2 instance is the secure and recommended method for granting AWS services access to other AWS resources. When an IAM role is associated with an EC2 instance via an instance profile, the instance can automatically obtain temporary, frequently rotated credentials from the AWS Security Token Service (STS). This eliminates the need to embed or store static access keys on the instance, significantly reducing the risk of credential compromise and adhering to the principle of least privilege.

Why this answer

Attaching an IAM role to the EC2 instance is the AWS best practice because it provides temporary, automatically rotated credentials via the instance metadata service (IMDS), eliminating the need to embed long-lived access keys. The role's policy grants only the required DynamoDB read permissions, following least privilege. This is the standard, secure, and auditable approach for EC2-to-AWS-service authentication.

Exam trap

DVA-C02 often tests the misconception that SCPs or bucket policies can grant permissions to an EC2 instance — candidates confuse organization-level guardrails (SCPs) with identity-based permissions (IAM roles), or think access keys are acceptable for convenience.

How to eliminate wrong answers

Option A is wrong because storing IAM user access keys on an instance is a security anti-pattern: keys are long-lived, can be leaked via logs or snapshots, and require manual rotation. Option B is wrong because using root user credentials violates least privilege and AWS best practice; root should never be used for application access and should have MFA enabled. Option D is wrong because SCPs are applied to AWS Organizations accounts/OU roots to set permission guardrails, not to individual EC2 instances; an SCP cannot grant permissions and does not attach to instances.

348
Multi-Selectmedium

A company wants to audit access to their S3 buckets. Which TWO services can be used to log and monitor S3 API calls?

Select 2 answers
A.AWS Config
B.S3 server access logs
C.AWS CloudTrail
D.AWS KMS
E.Amazon CloudWatch Logs
AnswersB, C

S3 server access logging records every request made to a bucket, including the requester's IP address (or IAM role/account if available), the request operation (e.g., REST.GET.OBJECT), the object key, response status, and timestamps, then delivers these logs to a destination bucket you designate. These logs provide a comprehensive object-level audit trail of both authenticated and unauthenticated access, making them a direct answer to the audit requirement. Keep in mind the logs are delivered on a best-effort basis with no guarantee of completeness, but they are still the standard method for forensic analysis of S3 access.

Why this answer

S3 server access logs (Option B) provide detailed records about requests made to an S3 bucket, including object-level API calls. AWS CloudTrail (Option C) logs management events for S3, such as bucket creation or configuration changes, and can also be configured to log data events for object-level operations. Option A (AWS Config) is used for resource configuration tracking, not API call logging.

Option D (AWS KMS) manages encryption keys. Option E (Amazon CloudWatch Logs) can store logs but does not directly capture S3 API calls; it works with CloudTrail or other sources.

349
Multi-Selecteasy

Which TWO AWS services can be used to protect an application running on EC2 from common web exploits like SQL injection and cross-site scripting?

Select 1 answer
A.Amazon CloudWatch
B.Security Groups
C.AWS WAF
D.AWS Shield Advanced
E.AWS Identity and Access Management (IAM)
AnswersC

AWS WAF is correct because it filters HTTP(S) requests to block SQL injection and cross-site scripting attacks.

Why this answer

AWS WAF is a web application firewall that protects against common web exploits like SQL injection and cross-site scripting by inspecting HTTP(S) requests and blocking malicious patterns. AWS Shield Advanced is a DDoS protection service; it does not directly filter for SQL injection or XSS. Therefore, only AWS WAF is the appropriate service for this specific protection.

Exam trap

The trap here is that candidates often confuse AWS Shield Advanced (a DDoS protection service) with application-layer protection, mistakenly believing it can block web exploits like SQL injection and XSS, when in fact it focuses on volumetric DDoS attacks and does not inspect HTTP payload content.

350
MCQmedium

A developer has an AWS Lambda function that processes messages from an Amazon SQS standard queue. The function is idempotent and currently has a batch size of 10. The developer wants to increase throughput and increases the batch size to 100. After the change, CloudWatch metrics show a significant increase in throttles and the queue backlog is growing. The function's reserved concurrency is set to 10. What is the most effective action to resolve the throttling and improve throughput?

A.Increase the reserved concurrency of the Lambda function
B.Increase the memory allocation of the Lambda function
C.Switch the SQS queue to a FIFO queue
D.Decrease the batch size back to 10
AnswerA

Increasing reserved concurrency directly allocates a dedicated maximum number of simultaneous executions for this specific Lambda function. This prevents the function from being throttled by the account's unreserved concurrency limit or other functions consuming available capacity. By ensuring more invocations can run in parallel, the function can effectively process larger SQS batch sizes without messages backing up, significantly improving overall message consumption rate and throughput.

Why this answer

Increasing the reserved concurrency from 10 to a higher value directly addresses the root cause of throttling. With a batch size of 100, each invocation processes more messages, but the function's reserved concurrency of 10 limits the maximum number of concurrent executions to 10. This means the Lambda service can only invoke the function 10 times at once, regardless of how many messages are in the queue.

By raising reserved concurrency, you allow more concurrent invocations to handle the larger batches, reducing throttling and improving throughput.

Exam trap

The trap here is that candidates often assume throttling is due to function performance (memory or CPU) and choose to increase memory, when in fact the issue is a concurrency limit that prevents the function from scaling to handle the larger batch size.

How to eliminate wrong answers

Option B is wrong because increasing memory allocation improves CPU and network performance per invocation but does not increase the number of concurrent executions allowed, so it cannot resolve throttling caused by hitting the reserved concurrency limit. Option C is wrong because switching to a FIFO queue would reduce throughput due to its strict message ordering and limited concurrency (FIFO queues support a maximum of 300 transactions per second with batching), which is counterproductive when trying to increase throughput. Option D is wrong because decreasing the batch size back to 10 would reduce the number of messages processed per invocation, lowering throughput and failing to address the underlying concurrency bottleneck.

351
MCQmedium

A developer is troubleshooting an AWS Lambda function that is triggered by an S3 event. The function occasionally fails with a timeout error. CloudWatch logs show that the timeout occurs during the processing of large files. The function has a memory setting of 128 MB and a timeout of 3 seconds. The developer wants to process large files without modifying the code. Which parameter should the developer adjust first?

A.Increase the function's memory
B.Increase the function's timeout
C.Increase the function's reserved concurrency
D.Increase the S3 event notification batch size
AnswerA

In AWS Lambda, memory allocation directly correlates with the amount of CPU power provisioned to the function. Increasing the function's memory provides more vCPUs, which can significantly speed up compute-intensive operations and data processing within the function's execution environment. This optimization can reduce the overall execution duration, thereby preventing timeouts and improving performance without requiring any changes to the underlying application code. It's often the first and most effective step for resolving performance bottlenecks.

Why this answer

Increasing the function's memory is the correct first step because Lambda allocates CPU proportionally to memory, and more CPU reduces processing time for CPU-bound tasks like decompressing or parsing large files. This directly addresses the timeout by making the function complete faster, without requiring code changes. The current 128 MB setting is the minimum, which provides the least CPU, so even a modest increase can significantly reduce execution time.

Exam trap

The trap here is that candidates often assume a timeout error must be fixed by increasing the timeout, but the question explicitly states the timeout occurs during processing of large files, indicating a performance bottleneck that memory (and thus CPU) increase can resolve without code changes.

How to eliminate wrong answers

Option B is wrong because increasing the timeout alone does not speed up processing; it only allows the function to run longer, which may mask the underlying performance issue but does not prevent future timeouts on even larger files. Option C is wrong because reserved concurrency controls the number of concurrent executions, not the execution duration of a single invocation; it would not resolve a timeout caused by slow processing. Option D is wrong because the S3 event notification batch size controls how many events are sent per invocation, not the processing speed of a single file; increasing it would only make the function handle more files per invocation, worsening the timeout.

352
MCQmedium

A developer needs to trace a request across API Gateway, Lambda, and downstream AWS service calls. Which service should be enabled?

A.AWS X-Ray
B.AWS Budgets
C.AWS Artifact
D.AWS License Manager
AnswerA

AWS X-Ray is the correct service for tracing requests across distributed applications, such as those involving API Gateway, Lambda functions, and other downstream AWS services. It provides an end-to-end view of requests as they travel through various components, helping identify performance bottlenecks and operational issues. X-Ray generates a service map that visualizes the application's architecture and shows latency data for each node and connection, enabling detailed analysis of request flow and performance. This capability is precisely what's needed to "trace a request" through the specified AWS services.

Why this answer

AWS X-Ray is the correct service because it provides end-to-end tracing for requests flowing through distributed applications, including API Gateway, Lambda functions, and downstream AWS services like DynamoDB or S3. It captures trace data as the request traverses each component, allowing developers to identify performance bottlenecks and errors across the entire request path. X-Ray integrates natively with API Gateway and Lambda via the X-Ray SDK or active tracing configuration, requiring no code changes for basic tracing.

Exam trap

The trap here is that candidates may confuse AWS X-Ray with CloudWatch Logs or CloudTrail, thinking those services provide the same distributed tracing capability, but X-Ray is the only service that correlates trace data across multiple components in a single request.

How to eliminate wrong answers

Option B (AWS Budgets) is wrong because it is a cost management service that monitors AWS spending and sends alerts when usage exceeds thresholds, not a tracing or observability tool. Option C (AWS Artifact) is wrong because it provides access to AWS compliance reports, security documentation, and agreements, such as SOC and PCI reports, not request tracing capabilities. Option D (AWS License Manager) is wrong because it manages software licenses (e.g., Microsoft, Oracle) to prevent license violations, and has no role in tracing API requests or debugging distributed applications.

353
Multi-Selectmedium

Which TWO actions should a developer take to ensure that an AWS CodeDeploy deployment is successful when deploying to an Auto Scaling group? (Choose TWO.)

Select 2 answers
A.Create an IAM service role that allows CodeDeploy to access the instances.
B.Attach an Application Load Balancer to the Auto Scaling group.
C.Enable the Application Discovery Service for the instances.
D.Configure the deployment to use a blue/green deployment type.
E.Install the CodeDeploy agent on each EC2 instance in the Auto Scaling group.
AnswersA, E

Creating an IAM service role is mandatory because CodeDeploy uses this role to assume permissions to call Amazon EC2 and Auto Scaling APIs, letting it enumerate instances, read tags, and perform deployment actions. Without this role, CodeDeploy cannot even start a deployment or resolve the target instances in the Auto Scaling group, making it a fundamental prerequisite.

Why this answer

Option A is correct because CodeDeploy requires an IAM service role (the CodeDeploy service role) that grants it permissions to perform actions on the developer's behalf, such as reading tags, accessing S3 revision bundles, and calling EC2 Auto Scaling APIs to manage instances during deployment. Option E is correct because the CodeDeploy agent must be installed and running on each EC2 instance in the Auto Scaling group so the instance can poll CodeDeploy, receive the revision, and execute the deployment lifecycle event hooks (ApplicationStop, BeforeInstall, AfterInstall, ApplicationStart, ValidateService). Option B is not required because an Application Load Balancer is only needed for load-balanced or blue/green scenarios, not for a basic in-place deployment to an Auto Scaling group.

Option C is incorrect because Application Discovery Service is used for migration planning and discovery, not for CodeDeploy deployments. Option D is not required because CodeDeploy supports in-place deployments to Auto Scaling groups, so blue/green is optional rather than mandatory.

Exam trap

DVA-C02 often tests whether candidates confuse 'nice-to-have' deployment features (ALB, blue/green) with hard prerequisites (IAM service role, CodeDeploy agent) — the exam expects you to identify the minimum required configuration.

354
MCQeasy

A developer is using AWS X-Ray to trace requests through a microservices application. One of the services, Service B, is not appearing in the trace map. What is the MOST likely reason?

A.Service B is using HTTP/2, which is not supported by X-Ray.
B.Service B is running in a different AWS region.
C.The X-Ray sampling rate is set too low.
D.Service B is not instrumented with the X-Ray SDK.
AnswerD

The X-Ray SDK is fundamental for any service to participate in distributed tracing. It's responsible for generating trace segments, capturing metadata, and propagating the trace context to downstream services. Without the X-Ray SDK integrated into Service B's code, the service cannot generate or send any trace data to the X-Ray daemon or service, thus preventing it from appearing on the service map.

Why this answer

For X-Ray to trace requests across services, each service must be instrumented with the X-Ray SDK. If Service B is not instrumented, it won't send trace data, and it won't appear in the trace map.

355
MCQeasy

A company wants to deploy an application using AWS Elastic Beanstalk. The application requires a relational database. What is the BEST practice for managing the database?

A.Create an Amazon RDS database instance separately and configure the application to connect to it.
B.Use the Elastic Beanstalk console to add an RDS database to the environment.
C.Use an S3 bucket to store data.
D.Use Amazon DynamoDB as the database.
AnswerA

Creating an Amazon RDS database instance separately and configuring the application to connect to it is a best practice for decoupling the database from the application's environment. This approach ensures that the database's lifecycle, including scaling, backups, and patching, is independent of the Elastic Beanstalk environment. This prevents accidental data loss if the Beanstalk environment is terminated or rebuilt, providing greater data persistence and operational flexibility.

Why this answer

The best practice for managing a relational database in Elastic Beanstalk is to decouple the database from the application lifecycle by creating an Amazon RDS instance separately. This ensures the database is not deleted when the Elastic Beanstalk environment is terminated, provides better control over backups, scaling, and maintenance, and allows the application to connect via environment variables or configuration files. Using a separate RDS instance aligns with production best practices for durability and operational flexibility.

Exam trap

The trap here is that candidates assume the integrated RDS option in Elastic Beanstalk is the simplest and therefore best approach, but the exam tests the understanding that decoupling the database from the environment lifecycle is the production best practice to avoid accidental data loss.

How to eliminate wrong answers

Option B is wrong because adding an RDS database via the Elastic Beanstalk console ties the database lifecycle to the environment, meaning the database is deleted when the environment is terminated, which is risky for production workloads. Option C is wrong because Amazon S3 is an object storage service, not a relational database; it cannot support SQL queries, transactions, or relational data models required by the application. Option D is wrong because Amazon DynamoDB is a NoSQL key-value and document database, not a relational database; it does not support SQL joins, ACID transactions across multiple tables, or schema enforcement needed for relational workloads.

356
MCQmedium

A developer is creating a REST API using Amazon API Gateway with Lambda proxy integration. The API needs to accept and return binary data such as images or PDF files. The developer has configured the API to use the Lambda proxy integration. What additional configuration is required to support binary data?

A.Set the Content-Type header to application/octet-stream in the Lambda response.
B.In API Gateway, add the binary media types to the API settings, e.g., image/png, application/pdf.
C.Use an API Gateway custom domain with an SSL certificate.
D.Enable API caching with binary support.
AnswerB

This is the correct and essential step for API Gateway to properly handle binary data from a Lambda integration. By explicitly listing media types like `image/png` or `application/pdf` in the API Gateway's binary media types settings, you instruct API Gateway to treat incoming and outgoing payloads of these types as raw binary data. This ensures that API Gateway correctly base64-encodes binary responses from Lambda before sending them to the client and decodes binary requests before passing them to Lambda, preventing data corruption.

Why this answer

With Lambda proxy integration, API Gateway passes the client request as-is to Lambda and returns the Lambda response as-is to the client. To handle binary data, you must explicitly declare the binary media types (e.g., image/png, application/pdf) in the API Gateway REST API settings. This tells API Gateway to base64-encode the binary payload before sending it to Lambda and to decode the base64-encoded response from Lambda back to binary for the client.

Without this configuration, API Gateway treats all payloads as text and will corrupt binary data.

Exam trap

The trap here is that candidates assume Lambda proxy integration automatically handles binary data because it passes everything through, but in reality, API Gateway requires explicit binary media type configuration to avoid corrupting binary payloads during base64 encoding/decoding.

How to eliminate wrong answers

Option A is wrong because setting the Content-Type header to application/octet-stream in the Lambda response alone does not enable API Gateway to handle binary data; API Gateway must be explicitly configured with the binary media types in the API settings, and the Lambda response must also include the correct isBase64Encoded flag set to true. Option C is wrong because using a custom domain with an SSL certificate is related to HTTPS endpoint configuration and custom domain names, not to enabling binary data support in API Gateway. Option D is wrong because API caching is a performance optimization feature that caches responses; it does not provide or enable binary data handling, and there is no 'binary support' toggle in API caching.

357
MCQmedium

A developer is optimizing a Node.js Lambda function that processes CSV files from S3. The function reads the entire file into memory, processes it, and writes results to DynamoDB. For large files, the function runs out of memory. What is the MOST effective optimization?

A.Increase the Lambda timeout to allow more processing time.
B.Increase the Lambda function memory to 3008 MB.
C.Use the AWS SDK's S3 GetObject with a stream and process in chunks.
D.Use S3 Select to retrieve only necessary columns.
AnswerC

Using the AWS SDK's S3 GetObject with a stream allows the Node.js Lambda function to read the large CSV file incrementally, rather than loading the entire object into memory at once. By processing data in small, manageable chunks as it arrives, the function significantly reduces its peak memory footprint. This approach directly addresses memory exhaustion by avoiding the need to hold the entire file in RAM, making it highly efficient for large file processing.

Why this answer

The core issue is that the Lambda function loads the entire CSV file into memory, causing out-of-memory errors for large files. Streaming the S3 object and processing it in chunks avoids holding the whole file in memory, keeping memory usage low and constant regardless of file size. This directly addresses the root cause—memory exhaustion—rather than just increasing resources or time limits.

It also allows the function to start processing immediately as data arrives, improving efficiency.

Exam trap

DVA-C02 often tests the misconception that increasing memory or timeout solves out-of-memory errors, when the real fix is to change the processing pattern to streaming or chunking.

How to eliminate wrong answers

Option A is wrong because increasing the timeout only allows the function to run longer; it does not reduce memory usage, so the function will still run out of memory before completing. Option B is wrong because increasing memory to 3008 MB (the maximum for Lambda) may delay the problem but does not solve it for arbitrarily large files; the function will still eventually exhaust memory if the file is large enough. Option D is wrong because S3 Select can reduce the amount of data retrieved by filtering columns or rows, but it still returns the entire result set at once, which could still be too large for memory; it does not provide streaming or chunked processing.

358
MCQeasy

A developer is deploying a serverless application using AWS SAM. The application consists of an API Gateway REST API and multiple AWS Lambda functions. The developer wants to deploy the application to a production environment with minimal downtime. Which deployment strategy should the developer use?

A.Create a blue/green deployment using AWS Elastic Beanstalk.
B.Delete the existing stack and deploy a new one.
C.Perform a rolling update by updating functions one by one.
D.Use SAM's built-in canary deployment with traffic shifting.
AnswerD

SAM's built-in canary deployment, integrated with AWS CodeDeploy, provides a robust mechanism for safely deploying serverless applications with gradual traffic shifting. This strategy allows a small percentage of traffic to be routed to the new Lambda version while monitoring for errors via CloudWatch alarms. If issues arise, CodeDeploy can automatically roll back to the previous stable version, minimizing impact and ensuring high availability during updates.

Why this answer

AWS SAM supports built-in canary deployments with traffic shifting, which gradually routes a percentage of traffic to the new version while monitoring CloudWatch alarms. This minimizes downtime and allows automatic rollback if errors occur. It is the recommended strategy for serverless applications on API Gateway and Lambda.

Exam trap

DVA-C02 often tests the misconception that SAM can perform rolling updates on Lambda functions like EC2 Auto Scaling groups, when in fact Lambda uses versions and aliases with traffic shifting.

How to eliminate wrong answers

Option A is wrong because Elastic Beanstalk is for EC2-based applications, not serverless Lambda/API Gateway stacks. Option B is wrong because deleting and redeploying causes downtime and loses stack resources. Option C is wrong because rolling updates are not natively supported for Lambda functions in SAM; Lambda versions and aliases are used for traffic shifting instead.

359
MCQhard

A company uses AWS CodePipeline with a manual approval step before deployment. The developer wants to ensure that if a pipeline execution is waiting for approval and new code is pushed, the awaiting execution is canceled and a new one starts with the latest code. Which pipeline execution mode should be configured?

A.Queued
B.Superseded
C.Parallel
D.Single
AnswerB

The Superseded execution mode is designed to prioritize the latest changes by canceling any currently running pipeline execution when a new source revision is detected. This ensures that the manual approval step, if present, will always apply to the most recent code changes, preventing the deployment of outdated versions. A new pipeline execution is then immediately initiated with the latest code, requiring a fresh approval for the most current state.

Why this answer

The Superseded execution mode is correct because it automatically cancels any currently running or waiting pipeline execution when a new one is triggered, ensuring that only the latest code proceeds through the pipeline. This is ideal for scenarios with manual approval steps where stale executions should not block or delay the deployment of the most recent commit.

Exam trap

The trap here is that candidates may confuse Superseded with Queued, assuming that queuing is the default or safest option, but they miss that Superseded is specifically designed to replace pending executions with the latest code push.

How to eliminate wrong answers

Option A is wrong because Queued mode places executions in a queue and runs them sequentially, meaning a waiting approval would not be canceled and the new push would wait until the previous execution completes. Option C is wrong because Parallel mode allows multiple executions to run concurrently, which would not cancel the awaiting execution and could lead to conflicting deployments. Option D is wrong because Single mode is not a valid execution mode in AWS CodePipeline; the available modes are Queued, Superseded, and Parallel.

360
MCQeasy

A developer needs to grant an IAM user the ability to create and manage CloudFormation stacks. Which IAM policy action should be allowed?

A.cloudformation:CreateStack
B.lambda:CreateFunction
C.ec2:RunInstances
D.s3:CreateBucket
AnswerA

cloudformation:CreateStack is the specific IAM action that authorizes a principal to launch a new CloudFormation stack from a template; combined with related actions like UpdateStack and DeleteStack it forms the core permission set needed to create and manage stacks, making it the directly applicable action for this requirement.

Why this answer

Option A (cloudformation:CreateStack). This action allows the IAM user to create and manage CloudFormation stacks. Option B (lambda:CreateFunction) is for creating Lambda functions, option C (ec2:RunInstances) is for launching EC2 instances, and option D (s3:CreateBucket) is for creating S3 buckets.

None of these other actions are related to CloudFormation stack management.

361
Multi-Selectmedium

A SAM application should gradually shift Lambda traffic and roll back on errors. Which two pieces are needed?

Select 2 answers
A.An S3 lifecycle rule
B.A Lambda alias/deployment preference
C.CloudWatch alarms tied to deployment health
D.A public S3 bucket
AnswersB, C

A Lambda alias, when combined with deployment preferences (often managed by AWS CodeDeploy), is the primary mechanism for implementing gradual traffic shifts for Lambda functions. This approach allows a new version of a Lambda function to incrementally receive a percentage of invocations, enabling canary or linear deployments and controlled rollouts to minimize risk.

Why this answer

AWS SAM uses Lambda aliases with deployment preferences (e.g., Canary10Percent5Minutes or Linear10PercentEvery10Minutes) to gradually shift traffic from the old version to the new version. Option C is correct because CloudWatch alarms can be tied to the deployment preferences to automatically roll back the traffic shift if the alarm enters the ALARM state, indicating errors or degraded health.

Exam trap

The trap here is that candidates often confuse deployment-related features (like S3 lifecycle rules or public buckets) with the actual AWS services (Lambda alias and CodeDeploy) that handle traffic shifting and rollback, leading them to select irrelevant options.

362
Multi-Selecthard

Which TWO approaches can a developer use to automate the deployment of a microservices application to Amazon ECS with Fargate, ensuring that each microservice is independently deployable and can scale based on demand?

Select 2 answers
A.Define all microservices in a single task definition and run them as one service
B.Use a single ECS service with multiple containers per task definition
C.Use a single CodePipeline that builds all microservices together
D.Define each microservice as a separate ECS service with its own task definition
E.Use a separate CodePipeline for each microservice that builds and deploys independently
AnswersD, E

Defining each microservice as a separate ECS service, each with its own dedicated task definition, is the correct architectural pattern for microservices on ECS. This approach enables independent scaling, deployment, and lifecycle management for each individual service, allowing developers to update or scale a single microservice without affecting others. It ensures optimal resource allocation and fault isolation, aligning perfectly with microservice principles.

Why this answer

Defining each microservice as a separate ECS service with its own task definition allows independent deployment, scaling, and lifecycle management. Each service can be updated, rolled back, or scaled based on its own demand without affecting other microservices, which aligns with microservices architecture principles.

Exam trap

The trap here is that candidates confuse 'multiple containers per task' (which still couples them) with 'separate services' (which decouples them), leading them to choose Option B as a valid approach for independent deployment.

363
MCQmedium

A developer is deploying a new version of an AWS Lambda function using the AWS CLI. The deployment fails with a 'ResourceConflictException' error. What is the MOST likely cause?

A.Another deployment is currently in progress for the same Lambda function.
B.The Lambda function code exceeds the maximum allowed size.
C.The Lambda function has an alias that conflicts with the version number.
D.The IAM role associated with the Lambda function does not have sufficient permissions.
AnswerA

AWS Lambda enforces serialization of updates to a function's code or configuration to maintain consistency. If an API call like `UpdateFunctionCode` or `UpdateFunctionConfiguration` is initiated while another update operation is already in progress for the same function, the subsequent call will fail. This contention for the resource's state results in a `ResourceConflictException`, preventing race conditions and ensuring the function's configuration remains coherent.

Why this answer

The 'ResourceConflictException' error in AWS Lambda occurs when you attempt to update a Lambda function while another update operation is already in progress. Lambda enforces a single in-flight update per function to prevent race conditions and ensure state consistency. The AWS CLI command (e.g., update-function-code) will fail immediately if a previous deployment has not completed, even if the previous deployment was triggered by the same or a different client.

Exam trap

The trap here is that candidates confuse 'ResourceConflictException' with permission errors or code size limits, but AWS specifically uses this exception to signal a concurrent update conflict, not a validation or authorization issue.

How to eliminate wrong answers

Option B is wrong because exceeding the maximum code size (250 MB for zip, 50 MB for direct upload) results in a 'RequestEntityTooLargeException' or 'InvalidParameterValueException', not a 'ResourceConflictException'. Option C is wrong because alias names and version numbers are separate namespaces; an alias cannot conflict with a version number, and such a conflict would cause a 'ResourceNotFoundException' or 'InvalidParameterValueException' if you tried to reference a non-existent version. Option D is wrong because insufficient IAM permissions would result in an 'AccessDeniedException' or 'AuthorizationError', not a 'ResourceConflictException'.

364
MCQeasy

A developer is using Amazon API Gateway to create a REST API. The API must support CORS (Cross-Origin Resource Sharing) to allow requests from a web application hosted on a different domain. What must the developer do to enable CORS?

A.Use Amazon CloudFront to proxy the API and add CORS headers.
B.Enable CORS in the API Gateway settings and configure the required headers.
C.Nothing; API Gateway automatically handles CORS.
D.Add CORS headers in the Lambda function code.
AnswerB

API Gateway provides a dedicated feature to enable Cross-Origin Resource Sharing (CORS) directly within its console or via infrastructure as code. This involves configuring the `OPTIONS` method for resources, specifying allowed origins, methods, and headers, and ensuring the necessary `Access-Control-Allow-*` headers are automatically included in responses. This native capability simplifies CORS management, allowing the API Gateway to handle preflight requests and inject the required headers without custom backend logic.

Why this answer

Enabling CORS in API Gateway requires explicit configuration: you must enable CORS on the API Gateway resource, which automatically generates an OPTIONS method and adds the necessary CORS headers (Access-Control-Allow-Origin, Access-Control-Allow-Methods, Access-Control-Allow-Headers) to responses. This is done through the API Gateway console or API configuration, not by the backend Lambda function or CloudFront.

Exam trap

The trap here is that candidates assume API Gateway automatically handles CORS (Option C) or that adding headers only in the Lambda function is sufficient (Option D), forgetting that the browser's preflight OPTIONS request must be handled by API Gateway itself.

How to eliminate wrong answers

Option A is wrong because Amazon CloudFront does not automatically add CORS headers for API Gateway; it can only forward or modify headers if configured, but the CORS headers must originate from the API Gateway or backend. Option C is wrong because API Gateway does not automatically handle CORS; it requires explicit enabling and configuration of CORS headers and the OPTIONS preflight response. Option D is wrong because while you can add CORS headers in the Lambda function code, this only works for non-preflight requests; API Gateway must still handle the OPTIONS preflight request and return the appropriate CORS headers, which is why enabling CORS in API Gateway is the recommended approach.

365
MCQmedium

A developer is deploying a new version of a Lambda function using the AWS CLI. The developer wants to shift 10% of traffic to the new version and then gradually increase to 100% over 10 minutes. Which CLI command should the developer use?

A.aws lambda publish-version --function-name my-function
B.aws lambda create-function --function-name my-function --zip-file fileb://my-code.zip
C.aws lambda update-alias --function-name my-function --name prod --function-version 2 --routing-config AdditionalVersionWeights={"1":0.9}
D.aws lambda invoke --function-name my-function --payload '{}'
AnswerC

This command precisely implements a canary deployment strategy by updating the `prod` alias. It configures the alias to direct 10% of the invocation traffic (calculated as 1.0 minus the specified `AdditionalVersionWeights` for the older version, 0.9) to the newly specified `function-version 2`. The remaining 90% of traffic continues to serve `version 1`, allowing for gradual rollout and monitoring of the new version before a full cutover.

Why this answer

The `update-alias` command with the `--routing-config` parameter allows you to implement canary deployments by assigning a percentage of traffic to a new Lambda function version. In this case, `AdditionalVersionWeights={"1":0.9}` routes 10% of traffic to version 2 (the new version) and 90% to version 1. However, note that this command only sets a static routing configuration; to gradually increase traffic to 100% over 10 minutes, you must update the alias multiple times (e.g., via a script) to adjust the weights progressively.

The command shown is the correct initial step to start the canary deployment.

Exam trap

The trap here is that candidates may confuse `publish-version` (which only creates a version) with the alias routing command needed to actually shift traffic, or they may think `invoke` can be used for deployment, but only `update-alias` with `--routing-config` enables the weighted traffic shift described in the question.

How to eliminate wrong answers

Option A is wrong because `publish-version` only creates a new immutable version of the Lambda function but does not route any traffic to it; it requires a separate alias update to shift traffic. Option B is wrong because `create-function` is used to create a new Lambda function from scratch, not to deploy a new version or manage traffic routing for an existing function. Option D is wrong because `invoke` is used to synchronously invoke a Lambda function with a payload, not to deploy or shift traffic between versions.

366
MCQhard

A company uses AWS CodeBuild for building and testing their application. They have a build project that runs on a Linux environment. They want to run a build in a custom Docker image that is stored in Amazon ECR. How should they configure the build project?

A.Add a 'Dockerfile' to the source code and specify it in the buildspec.
B.In the environment configuration, set the 'Image' field to the ECR image URI.
C.Use a managed image provided by AWS CodeBuild.
D.Configure the pipeline to pass the image URI as an environment variable.
AnswerB

AWS CodeBuild projects allow you to define the build environment by specifying a custom Docker image. This is achieved by navigating to the "Environment" section of the CodeBuild project configuration and setting the "Image" field directly to the Amazon ECR image URI (e.g., `aws_account_id.dkr.ecr.region.amazonaws.com/repository-name:tag`). CodeBuild will then pull this specific image from ECR to execute the build commands, ensuring a consistent and controlled build environment.

Why this answer

AWS CodeBuild allows you to specify a custom Docker image from Amazon ECR by entering its URI directly in the 'Image' field under the environment configuration. This enables the build to run in a container that includes all necessary dependencies, without requiring a Dockerfile in the source code or a managed image.

Exam trap

The trap here is that candidates confuse specifying a Dockerfile to build a new image (Option A) with using an existing custom image as the build environment, leading them to overlook the direct ECR URI configuration in the environment settings.

How to eliminate wrong answers

Option A is wrong because adding a Dockerfile to the source code and specifying it in the buildspec is used for building a new Docker image, not for running the build in an existing custom image from ECR. Option C is wrong because managed images provided by AWS CodeBuild are pre-configured environments (e.g., Ubuntu, Windows) and do not include custom dependencies that the company needs. Option D is wrong because passing the image URI as an environment variable does not instruct CodeBuild to use that image as the runtime environment; the image must be specified in the environment configuration's 'Image' field.

367
MCQeasy

A developer needs to grant cross-account access to an S3 bucket for an IAM user from another AWS account. The developer has added a bucket policy that allows the user's ARN. However, the user still cannot access the bucket. What additional step is required?

A.The user must have an IAM policy allowing the required S3 actions on that bucket
B.The bucket must be made public
C.The user must use a different AWS CLI profile
D.The resource-based policy must explicitly allow the user's ARN
AnswerA

For an IAM user in one AWS account to access an S3 bucket in another account, both the resource-based policy (bucket policy) and the identity-based policy (IAM user policy) must explicitly grant the necessary permissions. Even if the bucket policy permits the cross-account access, the IAM user's own policy must also authorize the specific S3 actions. This adherence to the principle of least privilege ensures that the user is explicitly allowed to perform the action from their identity's perspective.

Why this answer

A is correct because cross-account access to an S3 bucket requires both a resource-based policy (the bucket policy) that grants access to the user's ARN and an identity-based policy (an IAM policy attached to the user) that explicitly allows the required S3 actions on that bucket. Without the IAM policy, the user's account denies the request by default, even if the bucket policy permits it. This is the principle of 'permission delegation' in AWS: the resource owner can grant access, but the user's own account must also authorize the action.

Exam trap

The trap here is that candidates assume a bucket policy alone is sufficient for cross-account access, forgetting that the requesting account must also explicitly authorize the action via an IAM policy, which is a common oversight in AWS cross-account scenarios.

How to eliminate wrong answers

Option B is wrong because making the bucket public would grant access to all anonymous users, which is overly permissive and not a secure or necessary step for cross-account access; the bucket policy already specifies the user's ARN. Option C is wrong because using a different AWS CLI profile does not resolve the underlying permission issue; the user's IAM policy must allow the S3 actions regardless of the profile used. Option D is wrong because the developer has already added a bucket policy that explicitly allows the user's ARN, so this step is already done; the missing piece is the user's own IAM policy.

368
MCQmedium

A developer is using AWS Elastic Beanstalk to deploy a web application. The application writes logs to the local file system. The developer wants to ensure that logs are automatically rotated and retained for 30 days. What should the developer do?

A.Modify the application code to write logs directly to an S3 bucket with lifecycle policies.
B.Add a cron job to the EC2 instances that compresses and deletes old logs.
C.Configure the Elastic Beanstalk environment to enable log rotation and set retention period to 30 days.
D.Install the CloudWatch Logs agent on the EC2 instances and configure it to stream logs to CloudWatch Logs with a 30-day retention.
AnswerC

Elastic Beanstalk provides built-in environment properties to manage log rotation and retention directly, making it the most appropriate and integrated solution for this requirement. Developers can configure settings like `LogRotationPeriod` and `LogRotationSizeThreshold` through the Elastic Beanstalk console, CLI, or configuration files. This ensures local log files are automatically rotated and old logs are removed, preventing disk space issues without requiring custom code or manual scripts.

Why this answer

Elastic Beanstalk provides a built-in configuration for log rotation and retention directly in the environment settings. By enabling log rotation and setting the retention period to 30 days, the developer can automatically manage logs without modifying application code or adding external agents. This leverages the Elastic Beanstalk health agent, which handles log rotation on the EC2 instances and stores rotated logs in Amazon S3 with lifecycle policies to enforce the retention period.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing CloudWatch Logs (Option D) because it is a common logging service, but the question specifically asks for automatic rotation and retention on the local file system, which Elastic Beanstalk's built-in feature handles directly without additional services.

How to eliminate wrong answers

Option A is wrong because writing logs directly to S3 from application code bypasses the local file system requirement and introduces unnecessary complexity, such as managing S3 permissions and handling network latency, while Elastic Beanstalk already provides a simpler built-in log rotation mechanism. Option B is wrong because adding a cron job to EC2 instances is a manual, non-scalable approach that does not integrate with Elastic Beanstalk's managed environment; it also lacks centralized retention control and can be lost during instance replacements. Option D is wrong because while CloudWatch Logs agent can stream logs with a 30-day retention, this requires additional setup and costs, and it does not perform local log rotation on the file system; Elastic Beanstalk's native log rotation is more straightforward for this specific requirement.

369
MCQeasy

A developer is deploying a web application on EC2 instances behind an Application Load Balancer (ALB). The application needs to encrypt data in transit between the client and the ALB. Which AWS service should be used to manage the SSL/TLS certificate?

A.AWS Certificate Manager (ACM)
B.AWS Key Management Service (KMS)
C.AWS Secrets Manager
D.AWS Identity and Access Management (IAM)
AnswerA

AWS Certificate Manager (ACM) is the dedicated AWS service for provisioning, managing, and deploying SSL/TLS certificates, including those required for HTTPS on web applications. It integrates seamlessly with services like Application Load Balancer (ALB), allowing you to easily attach certificates to secure traffic. ACM handles the entire certificate lifecycle, including automatic renewal, which significantly reduces the operational overhead of manual certificate management and ensures continuous secure communication between clients and the load balancer.

Why this answer

AWS Certificate Manager (ACM) is the correct service because it provisions, manages, and deploys public and private SSL/TLS certificates that can be associated with an Application Load Balancer (ALB) to encrypt data in transit between clients and the ALB. ACM handles certificate renewal automatically and integrates natively with ALB, removing the need for manual certificate management. This ensures HTTPS termination at the load balancer, securing the client-to-ALB communication.

Exam trap

The trap here is that candidates may confuse AWS KMS (used for encryption at rest) with ACM (used for encryption in transit), or incorrectly assume IAM can manage SSL/TLS certificates for ALBs when it only supports legacy certificate uploads for CloudFront and Elastic Load Balancers in specific cases.

How to eliminate wrong answers

Option B (AWS KMS) is wrong because KMS is a key management service for creating and controlling encryption keys used for data at rest, not for managing SSL/TLS certificates for data in transit. Option C (AWS Secrets Manager) is wrong because Secrets Manager is designed to rotate and manage secrets such as database credentials and API keys, not SSL/TLS certificates for load balancers. Option D (AWS IAM) is wrong because IAM is an identity and access management service for controlling user and resource permissions, and while IAM can support SSL certificates for legacy CloudFront distributions, it does not manage or automate SSL/TLS certificates for ALBs and is not the recommended service for this purpose.

370
MCQmedium

A company is using AWS CodeDeploy to deploy a web application to an Auto Scaling group of EC2 instances. The deployment fails with the error 'The overall deployment failed because too many individual instances failed deployment.' What is the most likely cause?

A.The application specification file (appspec) is missing required hooks.
B.The IAM role for CodeDeploy does not have sufficient permissions to call EC2 APIs.
C.The Auto Scaling group does not have enough instances to meet the minimum healthy count.
D.The number of instances that failed deployment exceeded the configured failure threshold.
AnswerD

CodeDeploy allows you to define a deployment configuration that specifies the maximum number or percentage of instances that can fail during a deployment before the entire deployment is halted. When individual instances within a deployment group encounter issues during any lifecycle event (e.g., script execution failures, application startup errors, or health check failures), their deployment status is marked as failed. If the cumulative count of these failed instances surpasses the predefined failure threshold set in the deployment configuration, CodeDeploy will automatically stop the deployment and mark its overall status as failed, indicating that too many targets could not successfully complete the update.

Why this answer

The error message explicitly states that too many individual instances failed deployment, which means the number of failed instances exceeded the configured failure threshold (either the default or a custom value in the deployment configuration). CodeDeploy stops the deployment when this threshold is breached to prevent a full outage. The most likely cause is that the failure count crossed that limit, often due to a bad revision or environment issue.

Exam trap

DVA-C02 often tests whether candidates focus on the root cause of individual failures instead of recognizing that the error message describes the aggregate failure threshold being exceeded, leading them to pick appspec or IAM options.

How to eliminate wrong answers

Option A is wrong because a missing appspec hook would cause individual instance failures, but the error is specifically about the aggregate failure threshold being exceeded, not the root cause of each failure. Option B is wrong because insufficient IAM permissions would typically cause a different error (e.g., access denied) and would affect all instances uniformly, not trigger the 'too many individual instances failed' message. Option C is wrong because the minimum healthy count affects deployment success but the error message is about failed instances exceeding a threshold, not about insufficient instances.

371
MCQhard

A developer is using AWS Lambda with a VPC configuration. The function needs to access an Amazon RDS instance in the same VPC. The function is timing out after 3 seconds. What is the MOST likely cause?

A.The Lambda function's execution role does not have rds:Connect permission.
B.The Lambda function's security group does not allow outbound traffic to the RDS instance.
C.The Lambda function does not have an RDS proxy configured.
D.The Lambda function timeout is set too low.
AnswerB

When a Lambda function is configured within a VPC, its associated security groups govern both inbound and outbound network traffic. For the Lambda function to successfully establish a connection to an RDS instance, its security group must explicitly have an outbound rule permitting traffic to the RDS instance's private IP address or its security group, specifically on the database's listening port (e.g., 3306 for MySQL, 5432 for PostgreSQL). Without this crucial outbound rule, network packets cannot reach the database, resulting in connection failures.

Why this answer

The most likely cause of the Lambda function timing out when accessing an RDS instance in the same VPC is that the Lambda function's security group does not allow outbound traffic to the RDS instance's security group. Lambda functions in a VPC require security group rules that permit outbound traffic to the database, and inbound rules on the RDS security group to allow traffic from the Lambda function. Option A is incorrect because IAM permissions like rds:Connect are not used for network connectivity; they control API actions.

Option C is incorrect because an RDS proxy is not required for Lambda to connect to RDS; it's an optional feature for connection pooling. Option D is incorrect because although increasing the timeout might temporarily mask the issue, the root cause is a network connectivity problem, not the timeout value itself.

372
MCQmedium

A developer is troubleshooting an AWS Lambda function that writes to an S3 bucket. The function is configured with a resource-based policy that allows the S3 service to invoke the function. However, the function fails with an access denied error when trying to write to S3. What is the MOST likely cause?

A.The Lambda function is configured in a VPC without an S3 VPC endpoint.
B.The Lambda function's execution role does not have an IAM policy that allows s3:PutObject.
C.The Lambda function's trigger (S3 event notification) is misconfigured.
D.The S3 bucket policy does not grant the Lambda function write access.
AnswerB

The Lambda function's execution role is the IAM identity that the function assumes when it runs, dictating what AWS services and resources it is authorized to interact with. If this execution role lacks an IAM policy that explicitly grants the s3:PutObject permission, any attempt by the function to write or upload an object to an S3 bucket will be rejected by AWS Identity and Access Management (IAM). This directly leads to an "Access Denied" error, as the function is not authorized to perform that specific action.

Why this answer

The Lambda function's execution role lacks the necessary IAM permissions (s3:PutObject) to write to the S3 bucket. The resource-based policy only allows S3 to invoke the function, not the function to write. Option A is incorrect because a VPC endpoint would not cause an access denied error for writing if the execution role had permissions.

Option C is incorrect because trigger misconfiguration would prevent invocation, not cause access denied during execution. Option D is incorrect because the S3 bucket policy is not required if the execution role grants write access; the bucket policy controls who can access the bucket, but the execution role is the primary mechanism for Lambda permissions.

373
MCQeasy

A developer wants to store application configuration data that can be accessed by multiple microservices. The data is sensitive and should be encrypted at rest. Which AWS service should be used to meet these requirements?

A.Amazon S3
B.AWS Identity and Access Management (IAM)
C.Amazon DynamoDB
D.AWS Systems Manager Parameter Store
AnswerD

AWS Systems Manager Parameter Store is a highly scalable, secure, and easy-to-use service for storing and managing configuration data and secrets. It supports hierarchical organization, versioning, and secure string types, allowing sensitive data like database credentials or API keys to be encrypted at rest using AWS KMS. Applications can securely retrieve parameters at runtime, making it the ideal solution for centralized application configuration management.

Why this answer

AWS Systems Manager Parameter Store provides a secure, hierarchical store for configuration data and secrets. It supports encryption at rest using AWS KMS, integrates with AWS IAM for fine-grained access control, and is designed for use by multiple microservices via the AWS SDK or CLI. This makes it the ideal choice for storing sensitive application configuration that must be encrypted at rest and accessed by distributed services.

Exam trap

The trap here is that candidates often choose Amazon S3 because they think of storing configuration files (e.g., JSON or YAML) in buckets, but they overlook that Parameter Store is purpose-built for secure, encrypted configuration management with native IAM integration and no need to manage file access or encryption manually.

How to eliminate wrong answers

Option A is wrong because Amazon S3 is an object storage service, not a configuration store; while it supports encryption at rest, it lacks native hierarchical parameter management, versioning of configuration values, and seamless integration with AWS SDKs for parameter retrieval without custom code. Option B is wrong because AWS Identity and Access Management (IAM) is an access management service for controlling permissions, not a data store; it cannot store application configuration data or secrets. Option C is wrong because Amazon DynamoDB is a NoSQL database designed for high-performance, scalable data storage, but it does not provide built-in encryption at rest by default (requires additional configuration with AWS KMS), and it lacks native parameter store features like tiered pricing, automatic rotation, or simple key-value retrieval without provisioning read/write capacity units.

374
MCQeasy

A developer is building a serverless application using AWS Lambda and Amazon API Gateway. The developer wants to restrict access to the API so that only authenticated users can invoke it. Which API Gateway feature should be used?

A.API Gateway Lambda authorizer
B.AWS WAF
C.API Gateway usage plan
D.API Gateway resource policy
AnswerA

An API Gateway Lambda authorizer (formerly custom authorizer) is a serverless function that you provide to control access to your API methods. It intercepts incoming requests, validates bearer tokens (like JWTs or OAuth tokens) or other custom authorization headers, and then returns an IAM policy. This policy explicitly allows or denies the request to proceed to the backend integration, making it ideal for implementing custom authentication and authorization schemes.

Why this answer

A Lambda authorizer (formerly custom authorizer) is correct because it allows API Gateway to invoke a Lambda function that validates a token or request parameters and returns an IAM policy granting or denying access. This is the standard way to implement custom authentication logic (e.g., JWT validation, OAuth) for API Gateway REST or HTTP APIs. It directly restricts invocation to authenticated users based on the authorizer's decision.

Exam trap

DVA-C02 often tests the distinction between authentication and authorization mechanisms, and candidates confuse usage plans (throttling) with authorizers (authentication), or mistakenly select AWS WAF for user authentication.

How to eliminate wrong answers

Option B is wrong because AWS WAF is a web application firewall that filters malicious traffic based on IP, headers, or patterns, but it does not authenticate users or validate identity tokens. Option C is wrong because usage plans are for throttling and quota management per API key, not for authentication. Option D is wrong because resource policies control access at the resource level (e.g., based on IP or VPC endpoint) but do not authenticate individual users.

375
Multi-Selectmedium

A company is using Amazon RDS for MySQL with Multi-AZ deployment. The application writes to the database using the primary endpoint. The company wants to improve read performance and offload read traffic from the primary instance. Which TWO actions should the company take? (Choose TWO.)

Select 2 answers
A.Create an Amazon RDS read replica in the same region.
B.Add another primary instance and configure replication.
C.Modify the application to use the read replica endpoint for SELECT queries.
D.Use the Multi-AZ secondary instance endpoint for read queries.
E.Enable Amazon RDS Proxy to distribute read queries across instances.
AnswersA, C

Creating an Amazon RDS read replica in the same region provides an asynchronously replicated copy of the primary database instance. This replica is specifically designed to handle read-only queries, such as SELECT statements, thereby offloading the read workload from the primary instance. By distributing read traffic, the primary instance's CPU, I/O, and connection utilization are significantly reduced, allowing it to dedicate resources to write operations and maintain optimal performance for critical transactions.

Why this answer

Amazon RDS read replicas are designed to offload read traffic from the primary DB instance. A read replica is an asynchronous copy of the primary that can serve SELECT queries, improving read performance without impacting write operations on the primary. Option C is correct because the application must explicitly use the read replica's endpoint for read queries; the replica does not automatically balance traffic.

Together, creating a read replica and modifying the application to direct SELECT queries to its endpoint achieves the goal of improving read performance and offloading the primary.

Exam trap

The trap here is confusing Multi-AZ standby instances with read replicas—candidates often think the standby can serve reads, but it is a passive replica that only becomes active during failover and has no accessible endpoint for read queries.

Page 4

Page 5 of 16

Page 6