Courseiva

AWS Certified Developer Associate DVA-C02 (DVA-C02) — Questions 376–450

1135 questions total · 16pages · All types, answers revealed

Page 5

Page 6 of 16

Page 7
376
MCQeasy

A developer needs to store session state data for a web application running on multiple EC2 instances. The data must be highly available and durable. Which AWS service should be used?

A.Amazon ElastiCache
B.Amazon S3
C.Amazon EBS
D.Amazon CloudFront
AnswerA

Amazon ElastiCache provides managed in-memory data stores, such as Redis or Memcached, which offer extremely low-latency access and high throughput. This makes it an ideal choice for storing frequently accessed, transient session state data for web applications. By centralizing session state in ElastiCache, application servers can remain stateless, allowing for seamless horizontal scaling and high availability across multiple instances without losing user sessions.

Why this answer

Amazon ElastiCache is the correct choice because it provides a managed, in-memory caching service that is ideal for storing session state data with high availability and durability. By using ElastiCache for Redis or Memcached, session data is stored outside of individual EC2 instances, ensuring that if an instance fails, the session state is preserved and can be accessed by other instances in the application tier. ElastiCache supports replication and automatic failover, meeting the requirements for high availability and durability.

Exam trap

The trap here is that candidates often confuse Amazon ElastiCache with Amazon DynamoDB or Amazon S3 for session storage, but the question specifically requires a highly available and durable in-memory solution, and ElastiCache is the only option that provides low-latency, shared session state across multiple EC2 instances with built-in replication and failover.

How to eliminate wrong answers

Option B (Amazon S3) is wrong because S3 is an object storage service designed for large-scale data storage and retrieval, not for low-latency session state access; its eventual consistency model and higher latency make it unsuitable for real-time session management. Option C (Amazon EBS) is wrong because EBS provides block-level storage volumes attached to a single EC2 instance, so session data stored on an EBS volume is not shared across multiple instances and becomes unavailable if the instance fails, violating the high availability requirement. Option D (Amazon CloudFront) is wrong because CloudFront is a content delivery network (CDN) that caches static and dynamic content at edge locations; it does not provide a storage mechanism for session state data and is not designed for transactional, stateful data persistence.

377
MCQhard

A developer is creating a CloudFormation template to deploy a microservices architecture. The template includes an Amazon ECS service with an Application Load Balancer. The developer wants to ensure that the load balancer is created before the ECS service. How should the developer achieve this?

A.Use the Ref function in the ECS service to reference the load balancer.
B.Use the DependsOn attribute in the ECS service resource to reference the load balancer.
C.Define the load balancer before the ECS service in the template.
D.Use the Fn::GetAtt function to reference the load balancer.
AnswerB

The DependsOn attribute explicitly defines a creation, update, and deletion dependency between resources. By adding DependsOn: MyLoadBalancer to the ECS service resource, CloudFormation is instructed to ensure that MyLoadBalancer is completely provisioned and stable before it attempts to create or update the ECS service. This guarantees the load balancer is ready to accept registrations from ECS tasks, preventing deployment failures due to timing issues.

Why this answer

The DependsOn attribute explicitly defines resource creation order in AWS CloudFormation. By setting DependsOn on the ECS service to reference the load balancer, the template ensures the load balancer is fully created before the ECS service attempts to register with it, preventing deployment failures due to missing dependencies.

Exam trap

The trap here is that candidates assume the order of resource definitions in the template dictates creation order, but CloudFormation only guarantees order through explicit DependsOn or implicit dependencies from intrinsic functions like Ref or Fn::GetAtt used in resource properties.

How to eliminate wrong answers

Option A is wrong because the Ref function only returns a value (e.g., the load balancer's ARN or name) but does not enforce creation order; CloudFormation may still attempt to create the ECS service before the load balancer if there is no explicit dependency. Option C is wrong because the order of resource definitions in a CloudFormation template does not guarantee creation order; CloudFormation determines resource creation order based on intrinsic dependencies, not the sequence in the template file. Option D is wrong because Fn::GetAtt, like Ref, retrieves attribute values but does not create a dependency that ensures the load balancer is created before the ECS service; it only establishes a dependency if the attribute is used in a property that requires the resource to exist.

378
Multi-Selectmedium

A developer is designing a mobile application that needs to upload files to Amazon S3. The developer wants to use temporary credentials to avoid storing long-term AWS credentials on the device. Which TWO services should the developer use together?

Select 2 answers
A.AWS Security Token Service (STS)
B.Amazon Cognito
C.Amazon S3 Transfer Acceleration
D.AWS Identity and Access Management (IAM)
E.AWS Key Management Service (KMS)
AnswersA, B

AWS Security Token Service (STS) is fundamental for granting temporary, limited-privilege credentials to users or services that don't have long-term IAM credentials. For mobile applications, STS is often used indirectly via services like Amazon Cognito, which federates identities and then calls STS to issue session tokens. Developers can also directly use STS API operations, such as AssumeRoleWithWebIdentity, to exchange tokens from external identity providers for temporary AWS access keys, enabling secure, time-bound access to AWS resources.

Why this answer

AWS Security Token Service (STS) is used to generate temporary, limited-privilege credentials for accessing AWS resources, such as S3 buckets. Amazon Cognito provides identity pools that can automatically obtain and refresh STS tokens for authenticated users, eliminating the need to store long-term AWS credentials on the mobile device. Together, they enable secure, temporary credential management for file uploads.

Exam trap

The trap here is that candidates often confuse IAM (which manages long-term credentials) with STS (which issues temporary credentials), or they mistakenly think S3 Transfer Acceleration or KMS can handle authentication, when in fact only STS and Cognito together solve the temporary credential requirement for mobile apps.

379
MCQeasy

A developer is creating an API with Amazon API Gateway that needs to accept binary data (e.g., images) and store them directly in an S3 bucket. The developer wants to minimize backend complexity. Which integration type should be used?

A.AWS service integration with S3
B.Lambda proxy integration
C.HTTP integration
D.Mock integration
AnswerA

AWS service integration enables API Gateway to directly invoke actions on other AWS services, such as S3, without requiring an intermediate compute layer like Lambda. For storing objects, this integration type allows API Gateway to map incoming request bodies directly to S3 PUT object operations. This approach significantly minimizes backend complexity and latency by leveraging S3's native capabilities for object storage, making it the most efficient solution for directly accepting and storing data.

Why this answer

AWS service integration with S3 allows API Gateway to directly proxy binary data (e.g., images) to an S3 bucket without invoking a Lambda function or other backend. This minimizes backend complexity because the API Gateway handles the request transformation and passes the payload directly to S3 via the PutObject API action, eliminating the need for custom code.

Exam trap

The trap here is that candidates often default to Lambda proxy integration for any data processing task, overlooking that direct AWS service integration can handle binary uploads to S3 without any compute layer, which is the simplest and most cost-effective approach.

How to eliminate wrong answers

Option B (Lambda proxy integration) is wrong because it introduces unnecessary backend complexity by requiring a Lambda function to receive the binary data and then upload it to S3, adding compute cost and latency. Option C (HTTP integration) is wrong because it would require a separate HTTP endpoint (e.g., on EC2 or on-premises) to receive the data and then forward it to S3, defeating the goal of minimizing backend complexity. Option D (Mock integration) is wrong because it only returns static responses from API Gateway without actually storing any data in S3, so it cannot fulfill the requirement of persisting binary data.

380
MCQeasy

A developer wants to encrypt data in transit between an API Gateway REST API and its clients. Which configuration should be used?

A.Use a custom domain name with a certificate from ACM.
B.Implement client-side encryption using a JavaScript library.
C.Use the default HTTPS endpoint provided by API Gateway.
D.Attach an AWS WAF web ACL to the API Gateway.
AnswerC

The default HTTPS endpoint provided by API Gateway automatically ensures that all data transmitted between the client and the API Gateway is encrypted in transit. AWS manages the SSL/TLS certificates and the underlying infrastructure, providing robust transport layer security (TLS) out-of-the-box. This inherent feature means developers do not need to perform additional steps to secure the communication channel.

Why this answer

API Gateway REST APIs automatically provide an HTTPS endpoint using TLS for data in transit encryption. This default endpoint uses an Amazon-issued certificate, ensuring encryption between clients and API Gateway without any additional configuration. The developer only needs to use the default HTTPS URL provided by API Gateway to satisfy the requirement.

Exam trap

The trap here is that candidates often overcomplicate the solution by assuming a custom domain or additional services like WAF are needed for encryption, when the default HTTPS endpoint already provides TLS encryption for data in transit.

How to eliminate wrong answers

Option A is wrong because using a custom domain name with a certificate from ACM is an optional feature for branding or custom DNS, not a requirement for encrypting data in transit; the default HTTPS endpoint already provides encryption. Option B is wrong because client-side encryption using a JavaScript library encrypts data before sending it over the network, but it does not address the requirement of encrypting data in transit between the client and API Gateway; the transport layer (TLS) is already encrypted by the default HTTPS endpoint, and client-side encryption adds unnecessary complexity and is not a standard approach for transport encryption. Option D is wrong because AWS WAF is a web application firewall that protects against common web exploits, not a mechanism for encrypting data in transit; it operates at the application layer and does not provide TLS/SSL encryption.

381
MCQmedium

A Lambda function processing SQS messages is failing with concurrency errors. The function is configured with reserved concurrency of 5. The SQS queue has a batch size of 10. What is the most effective way to prevent throttling?

A.Reduce the batch size to 1 to spread out invocations.
B.Increase the Lambda function memory to get more concurrency.
C.Increase the reserved concurrency to a higher value.
D.Set the SQS queue's concurrency limit to match the Lambda reserved concurrency.
AnswerC

Increasing the reserved concurrency for the Lambda function dedicates a specific number of concurrent execution slots exclusively to that function. This guarantees that the function will always have that many concurrent instances available, preventing it from being throttled by the overall account-level concurrency limit or by other functions consuming available capacity. By reserving more concurrency, the function can process a higher parallel load from SQS without interruption, directly addressing throttling issues.

Why this answer

The function is throttling due to insufficient reserved concurrency. With a batch size of 10, each SQS batch triggers one invocation, but the function's reserved concurrency of 5 limits concurrent executions to 5. Increasing reserved concurrency allows more concurrent invocations to handle the SQS messages without throttling.

Exam trap

The trap here is that candidates often confuse batch size with concurrency, thinking reducing batch size reduces load, but it actually increases invocation count and worsens throttling.

How to eliminate wrong answers

Option A is wrong because reducing the batch size to 1 would increase the number of invocations per message, worsening concurrency pressure and potentially increasing throttling. Option B is wrong because increasing Lambda memory does not affect concurrency limits; memory and concurrency are independent settings. Option D is wrong because SQS queues do not have a configurable concurrency limit; Lambda's event source mapping manages polling, and setting a non-existent queue concurrency limit is not a valid action.

382
MCQeasy

A developer is creating an AWS Lambda function that processes messages from an Amazon SQS queue. The function should process each message only once. Which SQS queue type should the developer use?

A.Amazon SQS does not support exactly-once processing.
B.Dead-letter queue
C.FIFO queue
D.Standard queue
AnswerC

An Amazon SQS FIFO queue is the correct choice for scenarios requiring exactly-once processing and strict message ordering. It achieves this by preventing duplicate messages from being sent to the queue using a deduplication ID or content-based deduplication, and by ensuring that a message is delivered to a consumer, processed, and deleted before the next message in its message group is delivered. This guarantee is critical for applications where message order and uniqueness are paramount, such as financial transactions or order processing systems.

Why this answer

Amazon SQS FIFO (First-In-First-Out) queues guarantee exactly-once processing within a message group. They use a deduplication ID (either content-based or explicitly provided) to prevent duplicate message delivery, ensuring that each message is processed only once by the consumer.

Exam trap

The trap here is that candidates often assume Standard queues are sufficient because they are the default, but they overlook the fact that Standard queues provide at-least-once delivery, not exactly-once, which directly contradicts the requirement to process each message only once.

How to eliminate wrong answers

Option A is wrong because Amazon SQS does support exactly-once processing through FIFO queues, which provide deduplication and ordered delivery. Option B is wrong because a dead-letter queue is a secondary queue used to capture messages that fail processing after a specified number of attempts; it does not itself provide exactly-once processing guarantees. Option D is wrong because Standard queues offer at-least-once delivery, meaning the same message can be delivered multiple times, which violates the requirement for exactly-once processing.

383
MCQhard

A developer is using AWS Lambda to process sensitive data. The Lambda function needs to access a DynamoDB table that is encrypted with a customer-managed CMK. The developer is using the default Lambda execution role. What must be done to allow Lambda to decrypt the DynamoDB table?

A.Add a policy to the Lambda execution role allowing dynamodb:GetItem.
B.Add a policy to the KMS key that allows the Lambda execution role to perform kms:Decrypt.
C.Configure a VPC endpoint for DynamoDB.
D.Modify the Lambda function to call KMS Decrypt API.
AnswerB

The KMS key policy must allow the Lambda execution role to perform kms:Decrypt. This is required because DynamoDB uses server-side encryption with KMS, and the service needs to decrypt data on behalf of the Lambda function.

Why this answer

The DynamoDB table is encrypted with a customer-managed CMK. The Lambda execution role must be granted permission to use that key. This is done by adding a statement to the KMS key's key policy that allows the Lambda execution role to perform kms:Decrypt.

DynamoDB will then perform the decryption on behalf of Lambda. Option A is incorrect because dynamodb:GetItem alone does not grant KMS decrypt permissions. Option C is incorrect because a VPC endpoint is not related to KMS permissions.

Option D is incorrect because Lambda does not need to directly call the KMS Decrypt API; the key policy handles the authorization.

384
MCQeasy

A developer needs to grant an IAM role in the same AWS account read-only access to objects in a specific S3 bucket. The bucket is configured with a bucket policy that has an explicit Deny statement denying all principals except the root user. Which approach should the developer use to grant the required access?

A.Modify the bucket policy to allow the IAM role explicitly, or remove the Deny statement
B.Attach an IAM policy to the role that allows s3:GetObject on the bucket
C.Use an S3 access point instead of the bucket directly
D.Make the bucket public to allow all access
AnswerA

To grant an IAM role read-only access when an explicit Deny exists in the bucket policy, the Deny statement must be modified or removed. AWS IAM policy evaluation logic dictates that an explicit Deny always takes precedence over any Allow statement, whether from an identity-based policy (on the role) or a resource-based policy (on the bucket). Adjusting the bucket policy to explicitly allow the specific IAM role for `s3:GetObject` actions, or ensuring the existing Deny no longer applies to that role, is the only way to permit access.

Why this answer

The bucket policy contains an explicit Deny that overrides any allow permissions, including those granted by an IAM policy attached to the role. To grant the IAM role read-only access, the developer must either remove the Deny statement or add an explicit Allow for the role in the bucket policy, because an explicit Deny in a resource-based policy cannot be overridden by an identity-based policy.

Exam trap

The trap here is that candidates assume an IAM policy attached to the role is sufficient to override a bucket policy's explicit Deny, but they forget that explicit Deny always wins regardless of the source of the allow.

How to eliminate wrong answers

Option B is wrong because attaching an IAM policy that allows s3:GetObject to the role is insufficient; the explicit Deny in the bucket policy will still block access, as explicit Deny statements take precedence over any allow. Option C is wrong because an S3 access point uses the same underlying bucket policy; the explicit Deny in the bucket policy would still apply to requests made through the access point unless the bucket policy is modified. Option D is wrong because making the bucket public would grant access to everyone, which violates the principle of least privilege and does not specifically grant read-only access to the IAM role.

385
MCQhard

A company uses an Amazon S3 bucket to store sensitive documents. The security team requires that all objects uploaded to the bucket must be encrypted at rest using server-side encryption with a customer-managed KMS key (SSE-KMS). A developer needs to enforce this by denying any PutObject request that does not specify the required encryption. Which bucket policy condition should be used?

A."Condition": {"StringNotEquals": {"s3:x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-east-1:123456789012:key/abc123"}}
B."Condition": {"StringNotEquals": {"s3:x-amz-server-side-encryption": "aws:kms"}}
C."Condition": {"Null": {"s3:x-amz-server-side-encryption-aws-kms-key-id": "true"}}
D."Condition": {"ArnNotEquals": {"s3:x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-east-1:123456789012:key/abc123"}}
AnswerA

This policy condition correctly enforces the use of a *specific* AWS KMS key for Server-Side Encryption (SSE-KMS) when objects are uploaded to the S3 bucket. The `s3:x-amz-server-side-encryption-aws-kms-key-id` condition key checks the value of the `x-amz-server-side-encryption-aws-kms-key-id` request header. By using `StringNotEquals` with the desired KMS key ARN, any PUT object request that does *not* specify this exact ARN in the header will be denied, effectively mandating its use. This ensures sensitive documents are encrypted with the designated corporate key.

Why this answer

The condition `s3:x-amz-server-side-encryption-aws-kms-key-id` with `StringNotEquals` explicitly denies any PutObject request that does not specify the exact customer-managed KMS key ARN. This enforces SSE-KMS with a specific key, meeting the security team's requirement that all objects must be encrypted at rest using that key.

Exam trap

The trap here is that candidates often confuse the condition key for the encryption type (`s3:x-amz-server-side-encryption`) with the condition key for the specific KMS key ID (`s3:x-amz-server-side-encryption-aws-kms-key-id`), leading them to pick Option B which only enforces SSE-KMS but not a specific customer-managed key.

How to eliminate wrong answers

Option B is wrong because `s3:x-amz-server-side-encryption` with `aws:kms` only checks that SSE-KMS is used, but does not enforce a specific customer-managed KMS key; it would allow any KMS key, including the default AWS-managed key. Option C is wrong because the `Null` condition on `s3:x-amz-server-side-encryption-aws-kms-key-id` would deny requests where the key ID is not present, but it would not enforce that the key is the specific customer-managed key; it could be any KMS key ID. Option D is wrong because `ArnNotEquals` is not a valid condition operator for S3 bucket policies; the correct operator for string comparison is `StringNotEquals`.

386
MCQeasy

A developer needs to encrypt data in an S3 bucket. The company requires that the encryption key be managed by AWS but with the ability to audit key usage. Which S3 encryption option should the developer use?

A.Server-Side Encryption with AWS KMS (SSE-KMS).
B.Client-side encryption.
C.Server-Side Encryption with S3-Managed Keys (SSE-S3).
D.Server-Side Encryption with Customer-Provided Keys (SSE-C).
AnswerA

This option is ideal when the company requires robust control and auditability over encryption keys. With SSE-KMS, S3 encrypts objects using a customer master key (CMK) stored in AWS Key Management Service. This enables detailed logging of key usage requests through AWS CloudTrail, providing an essential audit trail for compliance, while AWS KMS handles the secure storage and management of the CMK.

Why this answer

SSE-KMS uses AWS Key Management Service (KMS) to manage the encryption keys, and it provides audit trails of key usage via AWS CloudTrail. This meets the requirement of AWS-managed keys with auditability. SSE-S3 uses S3-managed keys but does not provide detailed audit logs of key usage.

Client-side encryption and SSE-C involve customer-managed keys, which do not meet the 'managed by AWS' requirement.

Exam trap

DVA-C02 often tests the difference between SSE-S3 and SSE-KMS regarding auditability; candidates may incorrectly assume SSE-S3 provides key usage logs, but only SSE-KMS integrates with CloudTrail for auditing.

How to eliminate wrong answers

Option B is wrong because client-side encryption means the customer manages the keys and encryption process, which does not meet the requirement that the key be managed by AWS. Option C is wrong because SSE-S3 uses S3-managed keys, but it does not provide the ability to audit key usage; CloudTrail does not log individual S3 object encryption key usage for SSE-S3. Option D is wrong because SSE-C requires the customer to provide and manage the encryption keys, so AWS does not manage them, and auditability is limited to the customer's own key management.

387
MCQmedium

A developer is using AWS SAM to deploy a serverless application. The template includes a Lambda function that connects to an RDS MySQL database. The function works correctly in the developer's account but fails with a timeout when deployed to a production account. What is the MOST likely cause?

A.The Lambda function timeout is set too low for the database query.
B.The Lambda function is not attached to the same VPC as the RDS instance.
C.The SAM template does not support RDS as an event source.
D.The Lambda function uses a runtime that is not compatible with the MySQL client.
AnswerB

For a Lambda function to securely and privately access an Amazon RDS instance, it must be configured to operate within the same Virtual Private Cloud (VPC) as the database. RDS instances are typically deployed into private subnets without public internet access, requiring the Lambda function to be placed within that VPC to establish a private network connection. If the Lambda is not attached to the correct VPC, it will be unable to resolve the private IP address or reach the RDS endpoint, leading to connection failures.

Why this answer

The most likely cause is that the Lambda function is not attached to the same VPC as the RDS instance. Lambda functions run in a VPC by default only if explicitly configured; without VPC attachment, the function cannot reach the RDS database's private IP address, leading to a connection timeout. The developer's account may have had the RDS instance publicly accessible or the Lambda function was inadvertently in the same VPC, but the production account likely uses a private RDS instance in a VPC that the Lambda function is not connected to.

Exam trap

The trap here is that candidates often assume a Lambda function can always reach an RDS database by default, overlooking the critical VPC configuration requirement for private resources.

How to eliminate wrong answers

Option A is wrong because a low Lambda function timeout would cause a timeout error, but the symptom is a connection timeout (the function fails to connect at all), not a query execution timeout; the core issue is network connectivity, not the timeout value. Option C is wrong because SAM templates do not need to define RDS as an event source; Lambda connects to RDS via the database client library in the function code, not through an event source mapping. Option D is wrong because the Lambda function works correctly in the developer's account, proving the runtime is compatible with the MySQL client; the failure is environment-specific, not runtime-related.

388
MCQmedium

The developer invokes a Lambda function using the AWS CLI and gets the output shown. What is the most likely cause of the error?

A.The Lambda function code has a syntax error.
B.The Lambda function's execution role lacks permissions.
C.The event payload does not contain the expected data.
D.The Lambda function timed out.
AnswerC

When a Lambda function's code attempts to access a property or key within the `event` object that does not exist in the incoming JSON payload, it will result in a `TypeError`. For instance, if the code expects `event.detail.itemId` but the payload only contains `{"id": "123"}`, accessing `event.detail` would return `undefined`. Subsequently, attempting to access `itemId` on `undefined` would raise a `TypeError` because `undefined` has no properties, indicating a mismatch between expected and actual data structure.

Why this answer

When a Lambda function is invoked with a payload that does not match the handler's expected schema, the function raises a runtime error such as KeyError or TypeError, which surfaces as a function error in the CLI output. The most likely cause is a malformed or unexpected event payload rather than an infrastructure issue.

Exam trap

DVA-C02 often tests the distinction between a function-level error (bad payload, unhandled exception) and a service-level error (permissions, timeout) — candidates misread the CLI output and blame IAM when the payload is the real culprit.

How to eliminate wrong answers

Option A is wrong because a syntax error would prevent deployment entirely — Lambda validates code at upload, so the function would not be invocable. Option B is wrong because missing execution role permissions typically produce an AccessDeniedException from an AWS API call inside the function, not a generic handler error on the payload. Option D is wrong because a timeout produces a Task timed out after X seconds message and a 200 response with a timeout error, not a payload-related error.

389
Multi-Selectmedium

A developer is deploying a web application using AWS Elastic Beanstalk. Which TWO configuration files can be used to customize the software that runs on the EC2 instances? (Select TWO.)

Select 2 answers
A..platform/hooks/
B.Dockerfile
C..ebextensions/*.config
D.appspec.yml
E.buildspec.yml
AnswersA, C

Elastic Beanstalk utilizes the `.platform/hooks/` directory to execute custom scripts at specific points during the application deployment lifecycle. These hooks, categorized as pre-init, pre-build, pre-deploy, and post-deploy, enable developers to perform tasks like installing dependencies, running database migrations, or modifying server configurations. This provides fine-grained control over the environment's setup and application startup process.

Why this answer

The `.platform/hooks/` directory is a feature of Elastic Beanstalk's platform-specific configuration that allows you to run custom scripts at specific lifecycle events (e.g., prebuild, postdeploy) on the EC2 instances. This is the modern replacement for the older `.ebextensions` approach for running commands during deployment, and it directly customizes the software running on the instances.

Exam trap

The trap here is that candidates often confuse Elastic Beanstalk configuration files with other AWS services' configuration files (like CodeDeploy's appspec.yml or CodeBuild's buildspec.yml) or assume a Dockerfile is universally applicable, when in fact only `.platform/hooks/` and `.ebextensions/*.config` are the two valid options for customizing software on EC2 instances in Elastic Beanstalk.

390
MCQeasy

A developer needs to store temporary session data for a web application running on Amazon EC2 behind an Application Load Balancer. The data must be accessible across multiple EC2 instances. Which AWS service should the developer use?

A.Amazon ElastiCache
B.Amazon EBS
C.Amazon DynamoDB
D.Amazon S3
AnswerA

Amazon ElastiCache, offering managed Redis or Memcached, is the optimal choice for storing temporary session data. Its in-memory nature provides sub-millisecond latency and high throughput, crucial for frequently accessed session information. By externalizing session state from individual web servers, ElastiCache enables horizontal scaling of application instances and ensures session continuity even if an instance fails, preventing the need for sticky sessions.

Why this answer

Amazon ElastiCache is the correct choice because it provides a managed, in-memory caching service (e.g., Redis or Memcached) that can store temporary session data with sub-millisecond latency. Since the data must be accessible across multiple EC2 instances behind an Application Load Balancer, ElastiCache offers a centralized, highly available data store that all instances can read from and write to, ensuring session persistence regardless of which instance handles a request.

Exam trap

The trap here is that candidates often confuse 'temporary session data' with 'persistent user data' and choose DynamoDB for its scalability, overlooking that ElastiCache is purpose-built for low-latency, ephemeral storage with automatic eviction policies.

How to eliminate wrong answers

Option B (Amazon EBS) is wrong because EBS volumes are block-level storage attached to a single EC2 instance in a specific Availability Zone; they cannot be shared across multiple instances for concurrent read/write access. Option C (Amazon DynamoDB) is wrong because while it is a fully managed NoSQL database that can store session data, it is a persistent, disk-based database with higher latency than an in-memory cache, and it is overkill for temporary session data that does not require durability. Option D (Amazon S3) is wrong because S3 is an object storage service designed for high-durability, long-term storage with eventual consistency (unless using S3 Select or versioning), and its higher latency and lack of native sub-millisecond access make it unsuitable for real-time session data that must be read and written on every request.

391
MCQmedium

A developer is using AWS Elastic Beanstalk to deploy a web application. The application uses an Amazon RDS database instance that is included in the Elastic Beanstalk environment. The developer wants to update the application code without affecting the database. What is the recommended approach?

A.Update the application code directly on the EC2 instances without redeploying the environment.
B.Create a new environment configuration, update the code, and swap the CNAME of the environments.
C.Decouple the database from the Elastic Beanstalk environment by creating a separate RDS instance and connecting the application to it externally.
D.Use Elastic Beanstalk's platform updates while keeping the database attached to the environment.
AnswerC

Decoupling the database by provisioning a standalone Amazon RDS instance outside the Elastic Beanstalk environment ensures its independent lifecycle management, allowing for separate scaling, backups, and patching. The application then connects to this external database using environment properties, guaranteeing data persistence and availability even if the Elastic Beanstalk environment is rebuilt, terminated, or updated, which is critical for production workloads.

Why this answer

When an RDS instance is included in an Elastic Beanstalk environment, it is tied to the environment's lifecycle. If the environment is terminated or rebuilt, the database is also deleted. Decoupling the database by creating a standalone RDS instance and connecting the application to it externally ensures the database persists independently of application deployments, allowing code updates without risking data loss.

Exam trap

The trap here is that candidates assume swapping CNAMEs between environments (blue/green deployment) is sufficient to protect the database, but they overlook that the database is still lifecycle-managed within each environment and will be lost if the original environment is terminated.

How to eliminate wrong answers

Option A is wrong because directly updating code on EC2 instances bypasses Elastic Beanstalk's managed deployment process, leading to configuration drift and loss of rollback capability. Option B is wrong because swapping CNAMEs between environments does not decouple the database; the new environment would still have its own lifecycle-managed RDS instance, and the original database remains tied to the old environment. Option D is wrong because platform updates only update the Elastic Beanstalk platform version, not the application code, and the database remains lifecycle-coupled, so any environment rebuild or termination would still affect the database.

392
MCQmedium

A developer is building a chat application using WebSockets. The application runs on multiple EC2 instances and needs to broadcast messages to all connected clients. Which AWS service can handle the WebSocket connections and route messages?

A.Amazon SQS with long polling
B.Application Load Balancer with WebSocket support
C.Amazon CloudFront with WebSocket support
D.Amazon API Gateway WebSocket API
AnswerD

Amazon API Gateway WebSocket API is purpose-built for managing persistent, bidirectional communication channels required by real-time applications like chat. It natively handles WebSocket connection management, including connection establishment and termination, and provides robust mechanisms to send messages to specific clients or broadcast messages to all connected clients, often integrating with backend services like AWS Lambda for message processing.

Why this answer

Amazon API Gateway WebSocket API is the correct choice because it natively manages WebSocket connections, maintains persistent bidirectional communication, and can broadcast messages to all connected clients using callback URLs. It handles connection lifecycle (connect, disconnect, default) and integrates with AWS Lambda or other backends to route messages efficiently.

Exam trap

The trap here is that candidates confuse Application Load Balancer's WebSocket support (which only proxies connections to a single target) with the need for a managed service that can broadcast to multiple clients, leading them to choose ALB over API Gateway.

How to eliminate wrong answers

Option A is wrong because Amazon SQS is a message queue service that uses polling (long or short) and does not support WebSocket connections or real-time bidirectional communication. Option B is wrong because Application Load Balancer supports WebSocket connections but only for routing traffic to backend targets; it cannot broadcast messages to all connected clients or manage the WebSocket protocol's pub/sub patterns. Option C is wrong because Amazon CloudFront does not natively support WebSocket connections; it is a CDN optimized for HTTP/HTTPS and cannot maintain persistent WebSocket state or route messages.

393
MCQeasy

A company is using AWS CloudFormation to deploy a stack that includes an Amazon EC2 instance with an attached Amazon EBS volume. The developer wants to ensure that the EBS volume is deleted when the EC2 instance is terminated. The developer has set the DeletionPolicy attribute on the EBS volume resource to Delete. However, after terminating the EC2 instance through the console, the EBS volume is still present. The stack still exists. What is the most likely reason the volume was not deleted?

A.The EBS volume has a DeleteOnTermination attribute set to false.
B.The DeletionPolicy attribute only takes effect when the CloudFormation stack is deleted, not when an individual resource is terminated.
C.The EBS volume is the root device of the EC2 instance.
D.The EC2 instance was terminated manually, not through a stack update.
AnswerB

The DeletionPolicy attribute in AWS CloudFormation is specifically designed to control the fate of resources when their containing CloudFormation stack is deleted. It dictates whether a resource should be retained, snapshotted, or deleted during a DELETE stack operation. Therefore, if an individual EC2 instance is terminated, either manually or through an update that replaces the instance, the DeletionPolicy defined on its associated EBS volume resource within the CloudFormation template will not be evaluated or applied.

Why this answer

The DeletionPolicy attribute in CloudFormation governs what happens to a resource when it is removed from the stack template or when the stack itself is deleted — not when the underlying resource (the EC2 instance) is terminated by other means. Terminating the EC2 instance through the console does not trigger CloudFormation to evaluate the DeletionPolicy on the EBS volume, so the volume persists. To have the volume deleted on instance termination, the volume must have DeleteOnTermination=true on the block device mapping, which is an EC2-level attribute, not a CloudFormation DeletionPolicy concern.

Exam trap

DVA-C02 often tests the misconception that CloudFormation DeletionPolicy controls resource deletion during any lifecycle event, when in fact it only applies to stack deletion or resource removal from the template.

How to eliminate wrong answers

Option A is wrong because although DeleteOnTermination=false would indeed prevent deletion on instance termination, the question states the developer set DeletionPolicy=Delete, and the scenario is about CloudFormation behavior — the more likely reason is that DeletionPolicy simply doesn't apply to instance termination; also, the question doesn't state DeleteOnTermination is false. Option C is wrong because whether the volume is the root device is irrelevant to DeletionPolicy behavior; root volumes have their own DeleteOnTermination default (true) but that's not the cause here. Option D is wrong because terminating the instance manually versus through a stack update makes no difference — DeletionPolicy is only evaluated on stack deletion or resource removal from the template, not on instance termination regardless of how it's initiated.

394
MCQeasy

A developer is using Amazon DynamoDB with provisioned throughput. The application is receiving ProvisionedThroughputExceededException errors. What is the BEST way to handle this error?

A.Contact AWS Support to increase the DynamoDB service limits.
B.Reduce the read and write capacity units.
C.Implement exponential backoff and retry in the application code.
D.Switch the table to on-demand capacity mode.
AnswerC

Implementing exponential backoff and retry logic in the application code is a standard best practice for gracefully handling transient errors like `ProvisionedThroughputExceededException` in DynamoDB. This mechanism automatically retries failed requests after progressively longer delays, allowing the throttled table time to recover or for its burst capacity to replenish. It prevents a flood of immediate retries from overwhelming the table further, enabling the application to adapt to temporary capacity limitations.

Why this answer

The ProvisionedThroughputExceededException indicates that the application has exceeded the provisioned read/write capacity units for the DynamoDB table. The best practice to handle this error is to implement exponential backoff and retry logic in the application code, which progressively increases the wait time between retries to reduce request volume and allow the throttling to subside. This approach is recommended by AWS for handling throttling errors gracefully without manual intervention.

Exam trap

The trap here is that candidates often confuse 'handling the error' with 'preventing the error' and choose to switch to on-demand mode (Option D) instead of implementing proper retry logic, which is the immediate and correct response to a throttling exception.

How to eliminate wrong answers

Option A is wrong because contacting AWS Support to increase DynamoDB service limits does not address the root cause of exceeding provisioned throughput; service limits are separate from provisioned capacity and increasing them does not resolve throttling. Option B is wrong because reducing read and write capacity units would decrease the table's throughput, making throttling more likely, not less. Option D is wrong because switching to on-demand capacity mode is a valid long-term solution for unpredictable workloads but is not the best immediate fix for handling the exception in existing code; it also incurs higher costs and does not teach the application to handle throttling programmatically.

395
MCQeasy

A developer needs to share an S3 bucket with a third-party AWS account. The third-party will upload files to the bucket using their own IAM users. The developer creates a bucket policy that grants s3:PutObject to the third-party account's root user. However, the third-party reports that their IAM users cannot upload files. What is the MOST likely reason?

A.The third-party's IAM users do not have an IAM policy allowing s3:PutObject.
B.The bucket policy must include a condition requiring encryption.
C.The bucket policy should grant access to the IAM user ARN instead of the root user.
D.The developer must create IAM users in their own account for the third-party.
AnswerA

Even if the S3 bucket policy grants permission to the third-party's account, the specific IAM user or role within that third-party account must also possess an identity-based policy that explicitly allows the s3:PutObject action. Without this corresponding identity-based permission, the request will be denied, as AWS IAM operates on an explicit allow principle where both sides must concur for cross-account access.

Why this answer

For cross-account access to S3, both the resource-based policy (bucket policy) and the identity-based policy (IAM policy attached to the third-party's IAM users) must grant the required permission. The bucket policy correctly grants s3:PutObject to the third-party account, but the third-party's IAM users also need an IAM policy allowing s3:PutObject. Without that identity-based permission, the request is denied even though the bucket policy allows it.

Exam trap

DVA-C02 often tests the misconception that a bucket policy alone is sufficient for cross-account access, when in fact the third-party's IAM users also need an identity-based policy allowing the action.

How to eliminate wrong answers

Option B is wrong because encryption conditions are optional and not required for uploads; while a bucket policy can enforce encryption, its absence does not block uploads. Option C is wrong because granting access to the account root ARN in a bucket policy is a valid way to delegate permissions to the entire account, and the third-party's IAM users would still need identity-based permissions. Option D is wrong because the developer should not create IAM users in their own account for the third-party; the third-party uses their own IAM users, and cross-account access is granted via bucket policy and identity-based policies in the third-party account.

396
Multi-Selecthard

A company uses AWS CodePipeline to automate deployments of a microservices application to Amazon ECS with Fargate. The pipeline has a deploy stage that uses Amazon ECS Blue/Green deployment. The deployment fails intermittently with a 'Task failed to start' error. The developer needs to troubleshoot the issue. Which THREE steps should the developer take? (Choose three.)

Select 3 answers
A.Review the CodeBuild build logs for errors.
B.Check the Amazon ECS service events for the task failure reason.
C.Validate that the task definition JSON is correctly formatted and references the correct container images.
D.Check the CloudFormation stack events for the ECS service.
E.Verify that the task execution IAM role has permissions to pull the container image from ECR.
AnswersB, C, E

The Amazon ECS service events tab is the authoritative source for recent service-level warnings and alarms, including deployment failures and stopped tasks. Each event often contains the exact error such as "CannotPullContainerError: Access Denied" or "task failed to start" along with a timestamp and the task ID. This is the first place an engineer should look because it directly records the reason ECS could not run the task.

Why this answer

Option B is correct because Amazon ECS service events provide the most direct diagnostic messages for tasks that fail to start, including reasons such as image pull failures, resource constraints, or unhealthy load balancer targets. Option C is correct because a malformed task definition JSON or an incorrect container image reference will prevent ECS from launching the task, producing exactly the 'Task failed to start' symptom. Option E is correct because the task execution IAM role must have permissions such as ecr:GetAuthorizationToken and ecr:BatchGetImage to pull the image from ECR; missing permissions cause task startup failures.

Option A is not appropriate because CodeBuild logs relate to the build stage, not the ECS deploy stage where the task fails to start. Option D is not appropriate because the pipeline uses Amazon ECS Blue/Green deployment, not a CloudFormation stack, so CloudFormation stack events would not explain the ECS task failure.

Exam trap

The trap is chasing the build stage (CodeBuild logs) or stack-level tooling (CloudFormation events) when the failure is at ECS task startup — candidates must recognize that ECS service events and the execution role are the authoritative sources for 'task failed to start'.

397
MCQhard

A Lambda function connects to an RDS database and causes too many database connections during traffic spikes. Which service should be introduced?

A.AWS Glue Data Catalog
B.Amazon RDS Proxy
C.Amazon Route 53 Resolver
D.AWS WAF
AnswerB

Amazon RDS Proxy is a fully managed, highly available database proxy that significantly improves application resilience and scalability for RDS databases. It establishes and maintains a pool of database connections, reusing them efficiently for new application connections from services like Lambda. This reduces the overhead of establishing new connections, prevents Lambda's concurrent invocations from overwhelming the RDS database with too many open connections, and handles credential management securely.

Why this answer

Amazon RDS Proxy sits between your Lambda function and the RDS database, managing a pool of established database connections. During traffic spikes, Lambda can rapidly scale up concurrent executions, each potentially opening a new database connection, which can exhaust the database's maximum connections. RDS Proxy reuses connections from the pool, reducing the number of open connections and preventing database overload, while also improving connection handling efficiency for serverless applications.

Exam trap

The trap here is that candidates might confuse AWS WAF (a web firewall) or Route 53 (DNS) with database connection management, or incorrectly think that Glue Data Catalog can somehow cache or pool database connections, when in fact only RDS Proxy directly addresses the connection scaling issue for Lambda and RDS.

How to eliminate wrong answers

Option A is wrong because AWS Glue Data Catalog is a metadata repository for data assets in AWS Glue and Athena, not a connection pooling or proxy service for RDS databases. Option C is wrong because Amazon Route 53 Resolver is a DNS service for resolving domain names within VPCs, and it does not manage database connections or connection pooling. Option D is wrong because AWS WAF is a web application firewall that protects against common web exploits like SQL injection and cross-site scripting, but it does not handle database connection management or pooling.

398
MCQhard

Refer to the exhibit. A developer runs the AWS CLI command to invoke a Lambda function. The command succeeds, but the function returns an error. The developer wants to see the error message and logs from the function execution. What should the developer add to the command?

A.--client-context string
B.--qualifier alias
C.--invocation-type Event
D.--log-type Tail
AnswerD

The --log-type Tail parameter is specifically designed to retrieve the last 4 KB of log data generated by a synchronous Lambda function invocation. When used with RequestResponse invocation type, this option includes the base64-encoded log output in the LogResult field of the CLI response. This provides immediate access to recent execution logs directly within the terminal, which is invaluable for debugging and quick verification of function behavior.

Why this answer

The `--log-type Tail` parameter instructs the AWS CLI to retrieve the last 4 KB of log data from the function's execution and base64-encode it in the response. This allows the developer to see the error message and logs directly without needing to query CloudWatch Logs separately. The command must also use `--invocation-type RequestResponse` (the default) to get a synchronous response containing the logs.

Exam trap

The trap here is that candidates often confuse `--invocation-type Event` (async) with the ability to retrieve logs, not realizing that only synchronous invocations (`RequestResponse`) return execution results and logs via `--log-type Tail`.

How to eliminate wrong answers

Option A is wrong because `--client-context string` passes arbitrary JSON data to the Lambda function as part of the invocation request, but it does not retrieve or display any logs or error messages from the execution. Option B is wrong because `--qualifier alias` specifies a version or alias of the function to invoke, which controls which code runs but does not affect log retrieval. Option C is wrong because `--invocation-type Event` triggers an asynchronous invocation, which returns a 202 response immediately without any function output or logs, making it impossible to see error messages in the response.

399
MCQhard

A developer is trying to update a CloudFormation stack that includes a Lambda function. The stack rolls back with the error shown. What is the most likely cause?

A.The Lambda function's execution role lacks permissions to write logs to CloudWatch.
B.The Lambda function's deployment package is not stored in Amazon S3.
C.The Lambda function's code is too large for the deployment.
D.The Lambda function's execution role does not have a trust policy that allows Lambda to assume it.
AnswerD

The execution role for an AWS Lambda function requires a trust policy that explicitly permits the `lambda.amazonaws.com` service principal to perform the `sts:AssumeRole` action. Without this crucial trust relationship, the Lambda service is unable to assume the specified role, preventing the successful creation or update of the function and resulting in an `AccessDeniedException` during the CloudFormation deployment.

Why this answer

The error message indicates that the IAM role cannot be assumed by Lambda. This typically means the trust policy of the execution role does not include 'lambda.amazonaws.com' as a trusted entity. Option A is incorrect because the error is about assuming the role, not about writing logs.

Option B is incorrect because the error is not about the deployment package location. Option C is incorrect because the error is not about code size.

400
MCQmedium

A developer is using AWS CodePipeline to deploy a web application. The pipeline includes a source stage from CodeCommit, a build stage using CodeBuild, and a deploy stage using CodeDeploy to EC2 instances. The application stores sensitive data in an S3 bucket. The developer needs to ensure that the S3 bucket is only accessible from the EC2 instances and not from any other AWS service or account. The EC2 instances have an IAM role that allows s3:GetObject. What additional configuration is required?

A.Use SSE-KMS encryption on the bucket.
B.Enable S3 Block Public Access on the bucket.
C.Add a bucket policy that allows access only from the VPC endpoint or specific IP addresses of the EC2 instances.
D.Move the sensitive data to a different S3 bucket and update the application.
AnswerC

A well-crafted S3 bucket policy can precisely define which principals, from which network locations, can perform specific actions on the bucket and its objects. By incorporating conditions that check for a VPC endpoint ID (using `aws:sourceVpce`) or specific source IP addresses (using `aws:SourceIp` for public IPs or `aws:VpcSourceIp` for private IPs within a VPC), access can be strictly limited to the intended EC2 instances or services operating within a controlled network environment. This granular control directly addresses the requirement to restrict access to authorized resources.

Why this answer

A bucket policy that restricts access to the S3 bucket from a specific VPC endpoint or the EC2 instances' IP addresses ensures that only requests originating from those sources are allowed. This complements the IAM role's s3:GetObject permission by adding a network-level condition, preventing other AWS services or accounts from accessing the bucket even if they have valid IAM credentials. The condition key `aws:SourceVpce` or `aws:SourceIp` in the bucket policy enforces this restriction.

Exam trap

The trap here is that candidates often confuse encryption (SSE-KMS) or public access controls (Block Public Access) with network-level access restrictions, failing to realize that IAM permissions alone are insufficient to prevent access from other AWS services or accounts that have their own valid credentials.

How to eliminate wrong answers

Option A is wrong because SSE-KMS encryption protects data at rest but does not control access to the bucket; it only ensures data is encrypted, not who can read it. Option B is wrong because S3 Block Public Access prevents public access from the internet but does not restrict access from other AWS services or accounts that have valid IAM credentials. Option D is wrong because moving the data to a different bucket does not solve the access control issue; the same problem would persist unless additional restrictions are applied.

401
Multi-Selecteasy

Which TWO AWS services can be used to deploy and manage containerized applications? (Choose two.)

Select 2 answers
A.Amazon EC2
B.Amazon ECS
C.Amazon RDS
D.AWS Lambda
E.Amazon EKS
AnswersB, E

Amazon Elastic Container Service (ECS) is a fully managed container orchestration service that allows you to easily deploy, manage, and scale Docker containers on AWS. It provides robust capabilities for defining tasks, services, and clusters, abstracting away the underlying infrastructure management. You can choose between the serverless AWS Fargate launch type, where AWS manages the compute capacity, or the EC2 launch type, giving you more control over the underlying instances.

Why this answer

Amazon ECS (Elastic Container Service) is a fully managed container orchestration service that allows you to run Docker containers at scale. It integrates with AWS Fargate for serverless compute or EC2 for more control, and it handles cluster management, scheduling, and scaling of containerized applications.

Exam trap

The trap here is that candidates may confuse Amazon EC2 (a compute instance) with a container management service, or think AWS Lambda can manage containers long-term, but Lambda is designed for short-lived, event-driven functions, not persistent container orchestration.

402
Multi-Selecthard

A company has an IAM policy that allows s3:GetObject for all users in the account. However, a specific user is receiving access denied errors. Which THREE possible causes should the developer investigate?

Select 3 answers
A.An SCP at the organization level denies s3:GetObject.
B.The user is using an incorrect region endpoint.
C.The user's IAM role has an attached policy that denies s3:GetObject.
D.The S3 bucket is in a different AWS account.
E.A bucket policy explicitly denies the user.
AnswersA, C, E

Service control policies in AWS Organizations override account-level IAM grants, so an SCP denying s3:GetObject blocks access even though the identity policy allows it. This satisfies the stem's constraint: a user with an explicit allow still receives Access Denied, because SCPs cap effective permissions for all principals in the member account.

Why this answer

Option A is correct because AWS Organizations service control policies (SCPs) act as permissions guardrails that limit the maximum permissions for accounts in the organization; an SCP that denies s3:GetObject overrides the account-level IAM allow, producing Access Denied. Option C is correct because an explicit Deny in any attached IAM policy (identity-based) always wins over an Allow in the same or another policy, so a deny statement for s3:GetObject on the user's role blocks the action. Option E is correct because S3 bucket policies are resource-based policies evaluated alongside IAM policies, and an explicit Deny in the bucket policy for that user (or principal) overrides the account's Allow, resulting in Access Denied.

Option B is not correct because using an incorrect regional endpoint typically causes connection or redirect errors (e.g., 301/PermanentRedirect), not an authorization Access Denied for a valid request. Option D is not correct because cross-account access is possible when the bucket policy grants permission to the external principal; being in a different account alone does not cause Access Denied.

Exam trap

DVA-C02 often tests the misconception that an Allow in an IAM policy is sufficient for access, when in fact any explicit Deny at the SCP, identity, or bucket-policy layer overrides it.

403
MCQmedium

A company uses AWS OpsWorks to manage a stack of EC2 instances. After a deployment, the application becomes unresponsive. The engineer suspects that a configuration file was not updated correctly. What is the best way to verify the deployed configuration?

A.Use AWS Systems Manager Run Command to execute a script that outputs the configuration.
B.Check the OpsWorks stack's logs for any JSON syntax errors in the custom JSON.
C.SSH into an instance and inspect the configuration files in /var/lib/aws/opsworks.
D.Review the application logs in Amazon CloudWatch Logs for configuration errors.
AnswerC

When OpsWorks manages an EC2 instance, it uses Chef to apply configuration. The `/var/lib/aws/opsworks` directory on the instance is the authoritative location where Chef recipes, generated configuration files, and custom JSON are stored and executed. Directly inspecting these files allows a developer to verify the exact configuration that was actually deployed and applied to the instance, which is crucial for diagnosing why an application might be unresponsive due to misconfiguration.

Why this answer

OpsWorks stores its configuration data, including the applied custom JSON and stack settings, in /var/lib/aws/opsworks on each EC2 instance. By SSHing into the instance and inspecting these files, the engineer can directly verify whether the configuration file was updated correctly after deployment, bypassing any application-level logging or abstraction.

Exam trap

The trap here is that candidates assume CloudWatch Logs or Systems Manager Run Command are the best tools for configuration verification, overlooking the fact that OpsWorks stores its deployed configuration locally on the instance in a specific directory that can only be inspected directly via SSH.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Run Command can execute scripts, but it does not provide direct access to the OpsWorks-specific configuration files stored on the instance; it would require the script to read those files, which is less direct than SSH inspection. Option B is wrong because OpsWorks stack logs may show JSON syntax errors in custom JSON, but they do not reveal whether the configuration file was correctly applied to the instance after deployment; syntax errors are only one possible cause. Option D is wrong because application logs in CloudWatch Logs may indicate configuration errors, but they are an indirect indicator and may not reflect the exact state of the configuration file on disk, especially if the application fails before logging.

404
MCQeasy

A developer is using AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment is configured with a 'OneAtATime' deployment configuration. The developer notices that the deployment is taking a long time. What is the most likely reason?

A.The deployment group is configured with an incorrect load balancer.
B.The Auto Scaling group has a large number of instances, and deploying one at a time is slow.
C.The deployment configuration is set to 'AllAtOnce', but the developer intended 'OneAtATime'.
D.The CodeDeploy agent on the instances is not running.
AnswerB

The OneAtATime deployment configuration deliberately updates exactly one instance at a time, waiting for each instance's lifecycle event hooks (BeforeInstall, ApplicationStop, Install, AfterInstall, ApplicationStart, ValidateService) to complete successfully before moving to the next; with a large Auto Scaling group, this strictly sequential process multiplies the per-instance deployment time by the total instance count, making the overall deployment noticeably slow by design.

Why this answer

The 'OneAtATime' deployment configuration deploys to one instance at a time, so if the Auto Scaling group has a large number of instances, the deployment will take a long time. Option A is incorrect because the load balancer configuration does not directly affect deployment speed when using 'OneAtATime'. Option C is incorrect because the deployment configuration is correctly set to 'OneAtATime', not 'AllAtOnce'.

Option D is incorrect because if the CodeDeploy agent were not running, the deployment would likely fail entirely, not just be slow.

405
MCQeasy

A developer deploys a new version of an AWS Lambda function using the AWS CLI. After deployment, the function returns stale results. What is the most likely cause?

A.The function's environment variables are cached and not updated.
B.The Lambda function alias is still pointing to the previous version.
C.The Amazon CloudFront distribution is caching the old response.
D.The Lambda function's code is cached by the Lambda service.
AnswerB

Lambda aliases provide a stable endpoint for invoking a function, but they are explicitly configured to point to a specific function version. If a developer deploys a new version of the Lambda function but fails to update the associated alias to reference this new version, any invocations made through that alias will continue to execute the code and configuration of the older version it still references. This is a common operational oversight leading to unexpected behavior where new code doesn't appear to be running.

Why this answer

When a developer deploys a new version of a Lambda function using the AWS CLI without updating the function alias, the alias continues to point to the previous version. Invoking the function via the alias (e.g., via an API Gateway endpoint or a CloudFront origin) will execute the old code, returning stale results. The `$LATEST` version is updated, but unless the alias is repointed, it does not automatically use the new code.

Exam trap

The trap here is that candidates may assume deploying new code automatically updates the invoked version, overlooking that aliases must be explicitly repointed to the new version to change which code is executed.

How to eliminate wrong answers

Option A is wrong because environment variables are not cached; they are read from the function's configuration at invocation time and are updated immediately when the function is deployed with new environment variables. Option C is wrong because CloudFront caching is a separate concern; while it can serve stale responses, the question states the function itself returns stale results, and CloudFront would only cache the HTTP response, not the Lambda execution output directly. Option D is wrong because the Lambda service does not cache the function's code in a way that persists across deployments; the new code is immediately available when the function version is updated, and the issue is about which version is being invoked, not code caching.

406
Multi-Selecthard

A developer is designing a system to store sensitive user data in Amazon S3. The data must be encrypted at rest and the encryption keys must be rotated annually. Which services can be used to meet these requirements? (Choose TWO.)

Select 2 answers
A.Amazon S3 SSE-KMS
B.AWS Secrets Manager
C.AWS Certificate Manager (ACM)
D.AWS KMS
E.AWS CloudHSM
AnswersA, D

SSE-KMS encrypts S3 objects at rest using AWS KMS customer managed keys, and KMS supports automatic annual key rotation, satisfying both the encryption and rotation requirements. It is the server-side option that keeps key management within KMS.

Why this answer

Option A (Amazon S3 SSE-KMS) is correct because server-side encryption with AWS KMS keys (SSE-KMS) encrypts objects at rest in S3 and supports automatic annual key rotation when the underlying KMS customer managed key has rotation enabled. Option D (AWS KMS) is correct because it is the service that creates and manages the customer managed keys used for encryption and provides built-in annual automatic key rotation (every 365 days) for symmetric KMS keys. Option B (AWS Secrets Manager) is not for encrypting S3 object data at rest; it stores and rotates secrets such as database credentials.

Option C (AWS Certificate Manager) manages TLS/SSL certificates for encryption in transit, not S3 data-at-rest encryption keys. Option E (AWS CloudHSM) provides dedicated hardware security modules and does not by itself deliver S3 at-rest encryption with annual key rotation as required.

Exam trap

The trap here is that candidates often confuse AWS KMS with AWS CloudHSM, thinking both support automatic key rotation, but CloudHSM requires manual rotation and lacks native S3 integration for SSE.

407
MCQmedium

A Lambda function must share reusable validation code across several functions without packaging the same library into every deployment artifact. What should be used?

A.Lambda layer
B.API Gateway usage plan
C.S3 multipart upload
D.CloudWatch metric filter
AnswerA

A Lambda layer is a ZIP archive containing supplementary code or data, such as libraries, custom runtimes, or common utility functions. By packaging reusable validation logic into a layer, multiple Lambda functions can reference it, significantly reducing deployment package sizes and promoting code consistency. This mechanism directly addresses the need to share common code across various serverless functions efficiently.

Why this answer

Lambda layers allow you to centrally manage reusable code (e.g., validation libraries) and share it across multiple Lambda functions without packaging it into each deployment artifact. When you attach a layer to a function, the layer's content is extracted into the /opt directory, making it available at runtime. This avoids duplication and simplifies updates, as you only need to update the layer version rather than every function's deployment package.

Exam trap

The trap here is that candidates may confuse Lambda layers with other AWS services that handle 'sharing' (like API Gateway usage plans for sharing API access) or 'packaging' (like S3 multipart upload for large files), but only Lambda layers are designed to share code and dependencies across functions without repackaging.

How to eliminate wrong answers

Option B is wrong because API Gateway usage plans are used to throttle and quota API requests, not to share code across Lambda functions. Option C is wrong because S3 multipart upload is a mechanism for uploading large objects in parts, not for distributing reusable code to Lambda functions. Option D is wrong because CloudWatch metric filters are used to extract metric data from log streams, not to share or package code for Lambda.

408
MCQeasy

A developer is writing a Lambda function that processes images uploaded to an S3 bucket. The function needs to extract metadata from the image. Which S3 feature can be used to automatically trigger the Lambda function?

A.S3 Events
B.S3 Inventory
C.S3 Transfer Acceleration
D.S3 Batch Operations
AnswerA

S3 Event Notifications are the correct mechanism for triggering real-time actions in response to object changes within an S3 bucket. When an image is uploaded, S3 can publish an event to a configured destination, such as an AWS Lambda function. This allows for immediate, automated processing like image resizing, watermarking, or metadata extraction as soon as the object creation event occurs.

Why this answer

Amazon S3 Events can be configured to send a notification when an object is created (e.g., via PutObject) in an S3 bucket. This event can directly invoke an AWS Lambda function, making it the correct service to automatically trigger the function upon image upload. The developer simply needs to set up an S3 event notification with the Lambda function as the destination.

Exam trap

The trap here is that candidates may confuse S3 Batch Operations (which can invoke Lambda functions for batch processing) with real-time event triggers, but Batch Operations require a manual job initiation and do not automatically fire on each upload.

How to eliminate wrong answers

Option B (S3 Inventory) is wrong because it is used to generate a list of objects and their metadata for auditing or compliance, not to trigger real-time event-driven actions. Option C (S3 Transfer Acceleration) is wrong because it only speeds up uploads over long distances using edge locations, it has no mechanism to invoke Lambda functions. Option D (S3 Batch Operations) is wrong because it performs bulk actions (like copying or tagging) on existing objects via a job, not real-time event triggering upon object creation.

409
MCQeasy

A developer uses AWS CodePipeline with a manual approval step before deployment. The developer wants to ensure that if a new commit is pushed while a pipeline execution is waiting for approval, the waiting execution is canceled and a new one starts with the latest commit. Which pipeline execution mode should be configured?

A.Queued
B.Superseded
C.Parallel
D.Single
AnswerB

Superseded mode is designed to prioritize the most recent changes by immediately stopping any currently active pipeline execution, including those paused at a manual approval step. Upon cancellation of the in-progress execution, a brand new pipeline execution is initiated using the latest source code revisions. This ensures that developers can quickly iterate and deploy updates without waiting for older, potentially stalled, deployments to complete, making it ideal for continuous integration/continuous delivery (CI/CD) workflows where rapid feedback is crucial.

Why this answer

The Superseded execution mode is designed to automatically cancel any in-progress pipeline execution when a new commit is pushed, and start a new execution with the latest source changes. This ensures that the manual approval step does not block newer commits, as the waiting execution is replaced by the one triggered by the latest commit. In contrast, other modes either queue or run executions in parallel, which would not cancel the waiting approval step.

Exam trap

The trap here is that candidates may confuse Superseded with Queued, thinking that queuing will handle the latest commit, but Queued only delays execution without canceling the waiting approval step.

How to eliminate wrong answers

Option A is wrong because Queued mode places new executions in a queue, waiting for the current execution to complete before starting the next one, which would not cancel the waiting approval step. Option C is wrong because Parallel mode allows multiple executions to run concurrently, which would not cancel the waiting execution and could lead to multiple approvals or deployments. Option D is wrong because Single mode is not a valid execution mode in AWS CodePipeline; the valid modes are Queued, Superseded, and Parallel.

410
MCQhard

A development team wants to automate the deployment of a microservices application on Amazon ECS with Fargate. The team uses AWS CodePipeline for CI/CD. Each microservice has its own source repository and Dockerfile. The team wants to build Docker images, push them to Amazon ECR, and deploy them to ECS. Which approach minimizes manual effort and follows best practices?

A.Use AWS CodeDeploy to deploy to ECS with a blue/green deployment.
B.Use AWS CloudFormation to create the infrastructure and manually trigger updates.
C.Use AWS CodePipeline with a build stage in CodeBuild and a deploy stage that uses the ECS deploy provider.
D.Use AWS CodeBuild to build and push images, then manually update the ECS service.
AnswerC

CodePipeline can orchestrate source, a CodeBuild stage that builds the Docker image and pushes it to ECR (producing an imagedefinitions.json artifact), and a deploy stage using the built-in Amazon ECS deploy action provider, which updates the task definition and service automatically on every commit with no manual steps.

Why this answer

AWS CodePipeline provides a fully automated CI/CD pipeline. With the ECS deploy provider, CodePipeline can update the ECS service with the new task definition directly, eliminating manual steps. Option A is incorrect because adding CodeDeploy for blue/green deployments introduces unnecessary complexity for a basic ECS deployment; the ECS deploy provider in CodePipeline handles it without additional services.

Option B is incorrect because it requires manual triggering of CloudFormation updates, which does not achieve full automation. Option D is incorrect because it requires manual intervention to update the ECS service, contradicting the goal of minimizing manual effort.

411
MCQeasy

A developer is designing a microservices architecture where each service runs in its own Amazon ECS container. Services need to communicate with each other. The developer wants to simplify service discovery and load balancing. Which AWS service should the developer use?

A.AWS Cloud Map
B.Elastic Load Balancing
C.Amazon ECS service discovery
D.Amazon Route 53
AnswerA

AWS Cloud Map provides a robust service discovery solution by registering dynamically changing microservices with custom names, allowing other services to discover them via API calls or DNS queries. It integrates seamlessly with Amazon ECS, enabling tasks to register and deregister automatically as they scale or become unhealthy. This dynamic registration is crucial for ephemeral microservices, ensuring services can find each other reliably without hardcoding network locations.

Why this answer

AWS Cloud Map is the correct choice because it provides a fully managed service discovery solution that allows microservices to dynamically discover each other using DNS or HTTP API calls. It integrates natively with Amazon ECS, enabling services to register themselves and resolve other services by logical names, which simplifies service discovery and load balancing across containers.

Exam trap

The trap here is that candidates often confuse the ECS service discovery feature (which is just a configuration option) with a standalone AWS service, leading them to pick option C instead of recognizing that AWS Cloud Map is the underlying service that actually provides the discovery mechanism.

How to eliminate wrong answers

Option B is wrong because Elastic Load Balancing (ELB) is a load balancer that distributes traffic to targets, but it does not provide service discovery; it requires manual configuration of target groups and does not automatically register/deregister ECS services as they scale. Option C is wrong because Amazon ECS service discovery is not a standalone AWS service; it is a feature that leverages AWS Cloud Map under the hood, so the correct service to use is Cloud Map itself. Option D is wrong because Amazon Route 53 is a DNS service primarily for domain name resolution and routing internet traffic, not designed for dynamic service discovery of ephemeral containers in ECS; it lacks native integration with ECS task registration and health checks for service discovery.

412
MCQmedium

A company is using AWS Lambda functions to process events from Amazon S3. The functions are writing logs to CloudWatch Logs. Recently, they noticed that some logs are missing and the functions are experiencing throttling errors. What is the MOST likely cause?

A.The CloudWatch Logs log group retention policy is set too low.
B.The Lambda function's reserved concurrency is set to a low value.
C.The Lambda function's IAM role lacks permissions to write to CloudWatch Logs.
D.The S3 bucket is sending too many event notifications.
AnswerB

Reserved concurrency explicitly caps the maximum number of simultaneous executions for a specific Lambda function. When the rate of incoming events or requests attempts to invoke the function beyond this configured limit, subsequent invocation requests are immediately throttled. This mechanism ensures that the function does not consume more concurrency than allocated, preventing it from impacting other functions or exceeding account-level limits, directly resulting in throttling errors for excess requests.

Why this answer

The most likely cause of throttling errors is that the Lambda function's reserved concurrency is set too low. When a Lambda function's reserved concurrency limit is reached, additional invocation requests are throttled, resulting in missing logs. Option A is incorrect because log group retention affects log storage, not Lambda throttling.

Option C is incorrect because IAM permissions affect the ability to write logs, not throttling. Option D is incorrect because while S3 can send many events, Lambda's concurrency limit is the direct cause of throttling.

413
Multi-Selecteasy

A developer needs to monitor the performance of an Amazon RDS for MySQL database. Which TWO metrics should the developer monitor to detect a potential CPU bottleneck?

Select 2 answers
A.FreeStorageSpace
B.DatabaseConnections
C.CPUUtilization
D.NetworkThroughput
E.ReadLatency
AnswersB, C

DatabaseConnections measures the number of client connections currently established with the database instance. A consistently high or rapidly increasing number of database connections can significantly contribute to CPU contention, as each connection consumes resources and requires the CPU to manage session overhead, execute queries, and handle context switching. While not a direct CPU usage percentage, monitoring this metric is crucial because an excessive connection count is a common cause of elevated CPU utilization and performance degradation.

Why this answer

High CPUUtilization (Option C) directly indicates the CPU is under heavy load, which is the primary symptom of a CPU bottleneck. DatabaseConnections (Option B) is correct because an excessive number of concurrent connections can overwhelm the CPU as each connection requires context switching and query processing, leading to CPU saturation. Monitoring both metrics together helps distinguish between a CPU bottleneck caused by high query load versus one caused by connection overhead.

Exam trap

The trap here is that candidates often focus solely on CPUUtilization and overlook DatabaseConnections, not realizing that a high number of connections can itself be the root cause of CPU saturation, especially in bursty connection scenarios.

414
MCQeasy

A developer is building a serverless REST API using Amazon API Gateway and AWS Lambda. The API should return JSON responses to client requests. The developer is using the Lambda proxy integration. What is the simplest way to return a JSON response from the Lambda function?

A.Return a string from the Lambda handler.
B.Return a dictionary containing 'statusCode', 'headers', and 'body' with 'body' as a JSON string.
C.Use API Gateway integration response and mapping templates to transform the Lambda output.
D.Return a JSON object from Lambda and set a Content-Type header in the API Gateway method response.
AnswerB

This format precisely adheres to the API Gateway Lambda proxy integration contract, where the Lambda function is solely responsible for constructing the entire HTTP response. By returning a dictionary containing `statusCode`, `headers` (as a dictionary of key-value pairs), and a `body` field (which itself must be a string, often a JSON string), the Lambda function provides all necessary information for API Gateway to directly pass through to the client. This ensures the client receives a properly formatted HTTP response with the correct status, custom headers, and a valid JSON payload.

Why this answer

With Lambda proxy integration, API Gateway passes the entire request to the Lambda function and expects the function to return a specific response format. The simplest way to return a JSON response is to return a dictionary (or object) containing 'statusCode', 'headers', and 'body', where 'body' is a JSON string. This format is required by API Gateway to correctly interpret the Lambda output and forward it to the client.

Exam trap

The trap here is that candidates often think returning a JSON object directly from Lambda is sufficient, but they overlook the requirement that the body must be a JSON string and the response must include the exact 'statusCode', 'headers', and 'body' keys for API Gateway proxy integration to work correctly.

How to eliminate wrong answers

Option A is wrong because returning a plain string from the Lambda handler will cause API Gateway to fail or return an unexpected response, as it expects a properly formatted response object. Option C is wrong because using API Gateway integration response and mapping templates adds unnecessary complexity; with proxy integration, the Lambda function itself is responsible for formatting the response, and mapping templates are not used. Option D is wrong because simply returning a JSON object from Lambda without the required 'statusCode', 'headers', and 'body' structure will not be parsed correctly by API Gateway, and setting a Content-Type header in the method response does not address the required Lambda response format.

415
MCQhard

A developer is building a real-time chat application using WebSocket APIs in Amazon API Gateway. The backend is an AWS Lambda function that stores connection IDs in an Amazon DynamoDB table. After a few days, the application stops working for new users. The developer checks CloudWatch Logs and sees that the Lambda function is returning 'AccessDeniedException' when calling DynamoDB. What is the MOST likely cause?

A.The Lambda function code was updated but the IAM role was not reattached.
B.The Lambda function uses an outdated AWS SDK version.
C.The API Gateway route was updated without redeploying the API.
D.The DynamoDB table was recreated and the Lambda function's IAM role still references the old table ARN.
AnswerD

When a DynamoDB table is recreated, it is assigned a completely new Amazon Resource Name (ARN), even if it has the same name. IAM policies grant permissions to specific resources, often identified by their ARN. If the Lambda function's IAM role policy explicitly referenced the old table's ARN, recreating the table invalidates that specific resource permission. Consequently, the Lambda function attempting to access the newly created table (with its new ARN) would correctly receive an AccessDeniedException because its IAM role lacks permission for that specific new resource.

Why this answer

The most likely cause is that the DynamoDB table was recreated, which changes its ARN. The Lambda function's IAM role still references the old table ARN, so when the function attempts to perform DynamoDB operations (e.g., PutItem for storing connection IDs), the request is denied because the role no longer has permissions on the new table. This is a common issue when infrastructure is rebuilt without updating IAM policies.

Exam trap

The trap here is that candidates may confuse 'AccessDeniedException' with a network or API configuration issue (like an outdated SDK or missing redeployment), rather than recognizing it as a classic IAM permissions problem tied to resource ARN changes.

How to eliminate wrong answers

Option A is wrong because IAM roles are attached to Lambda functions at the function level, not to the code; updating code does not detach the role. Option B is wrong because an outdated SDK version would cause errors like 'UnknownOperationException' or 'UnsupportedMediaType', not 'AccessDeniedException', which is an IAM permissions error. Option C is wrong because API Gateway route updates without redeployment would cause 404 or 503 errors at the API level, not an 'AccessDeniedException' from Lambda when calling DynamoDB.

416
MCQmedium

A company manages multiple AWS accounts using AWS Organizations. A developer needs to allow an IAM role in the production account to read objects from an S3 bucket in the development account. The bucket is encrypted with an AWS KMS customer managed key (CMK) in the development account. Which of the following is required to enable this cross-account access?

A.Grant the production account's root user access to the KMS key and the S3 bucket.
B.Add a bucket policy allowing the production account's IAM role and a KMS key policy granting the same role.
C.Create an IAM role in the production account with permissions to access the S3 bucket and KMS key.
D.Enable S3 bucket logging to allow cross-account access.
AnswerB

To enable secure cross-account access, a bucket policy must explicitly grant the production account's IAM role permissions for S3 actions like `s3:GetObject` on the bucket. Concurrently, a KMS key policy is essential to grant the *same* IAM role `kms:Decrypt` permissions, allowing it to decrypt objects encrypted with that KMS key. This combination of resource-based policies on the S3 bucket and KMS key establishes the necessary trust relationship, ensuring the production account's role can both access the bucket and decrypt its contents.

Why this answer

Cross-account access to an S3 bucket encrypted with a KMS customer managed key requires both a bucket policy that grants the production account's IAM role s3:GetObject permission and a KMS key policy that grants the same role kms:Decrypt permission. The bucket policy authorizes the S3 operation, while the key policy authorizes decryption of the object; both policies must explicitly allow the cross-account principal.

Exam trap

The trap here is that candidates often assume a bucket policy alone is sufficient for cross-account access, forgetting that KMS-encrypted objects require a separate key policy grant for the decrypt permission.

How to eliminate wrong answers

Option A is wrong because granting the production account's root user access is overly broad and unnecessary; the principle of least privilege requires granting only the specific IAM role, not the entire root account. Option C is wrong because creating an IAM role in the production account with permissions to access the S3 bucket and KMS key does not solve the cross-account authorization; the development account's bucket policy and KMS key policy must explicitly allow the production account's role, not just the role having permissions in its own account. Option D is wrong because enabling S3 bucket logging only records access events and does not grant any cross-account permissions; it is irrelevant to authorization.

417
MCQhard

A company runs a microservices application on Amazon ECS with Fargate. The application includes a service that processes messages from an SQS queue. The service's CPU utilization is consistently above 80%, and messages are accumulating in the queue. The service is configured with a desired count of 2 tasks and auto scaling based on CPU utilization. What should a developer do to improve message processing throughput?

A.Increase the desired count of tasks to 5.
B.Increase the task size to use more CPU and memory.
C.Change the auto scaling metric to use the SQS queue's ApproximateNumberOfMessagesVisible.
D.Decrease the batch size of messages polled from SQS.
AnswerC

Switching the target tracking metric to ApproximateNumberOfMessagesVisible makes scaling decisions proportional to the actual backlog size rather than an indirect CPU proxy, so the service adds tasks precisely when the queue grows and removes them as it drains, directly improving throughput.

Why this answer

The correct answer because using the SQS queue's ApproximateNumberOfMessagesVisible metric for auto scaling is more responsive to the actual workload than CPU utilization. When messages accumulate in the queue, scaling based on queue depth triggers task additions sooner, improving throughput. Option A is wrong because simply increasing the desired count without a dynamic scaling policy may not adapt to varying load and could lead to over-provisioning or under-provisioning.

Option B is wrong because increasing task size (CPU/memory) does not directly address the scaling trigger; it might help a single task process more, but the bottleneck is the number of tasks. Option D is wrong because decreasing the batch size reduces the number of messages processed per poll, which would decrease throughput, not improve it.

418
MCQmedium

A developer is using AWS CodePipeline to deploy a web application to an Auto Scaling group. The pipeline includes a deploy action that uses CodeDeploy. The deployment fails with the error: 'The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available, or some instances in your deployment group are experiencing problems.' Which of the following is the MOST likely cause?

A.The CodeDeploy agent is not sending logs to CloudWatch.
B.The deployment configuration has a minimum healthy instances setting that is too restrictive.
C.The application's lifecycle hooks are failing during the ApplicationStop event.
D.The instances were launched from an AMI that does not have the CodeDeploy agent installed.
AnswerB

CodeDeploy deployment configurations, such as `CodeDeployDefault.OneAtATime` or custom settings, include a `minimum healthy instances` threshold. If this setting is too restrictive, for example, requiring 100% of instances to remain healthy during a rolling update, the deployment will fail when even a single instance is taken offline for the update. The deployment cannot proceed if the number of healthy instances drops below the specified minimum, leading to a "too few healthy instances" error.

Why this answer

The error message indicates that the deployment failed because too many instances were unhealthy or failed. The most likely cause is that the deployment configuration's minimum healthy hosts setting is too restrictive, meaning it requires a higher percentage of healthy instances during deployment than the environment can sustain, causing CodeDeploy to stop the deployment when the threshold is breached.

Exam trap

The trap here is that candidates often confuse individual instance failures (e.g., missing agent, hook errors) with the deployment group-level threshold error, leading them to pick options that explain why a single instance failed rather than why the entire deployment was aborted.

How to eliminate wrong answers

Option A is wrong because the CodeDeploy agent not sending logs to CloudWatch would cause a lack of monitoring data, but it would not directly cause the deployment to fail with the given error; the deployment would proceed but logs would be missing. Option C is wrong because lifecycle hooks failing during the ApplicationStop event would cause individual instance failures, but the error message specifically points to a global deployment failure due to too few healthy instances, which is a deployment configuration issue, not a hook failure. Option D is wrong because if instances were launched from an AMI without the CodeDeploy agent, the agent would not run and the deployment would fail on each instance individually, but the error message about 'too few healthy instances' is a deployment group-level threshold issue, not a missing agent problem.

419
MCQeasy

A developer is using AWS Lambda to process files uploaded to an S3 bucket. The Lambda function needs to read the files and write results to a DynamoDB table. What is the MOST secure way to grant the necessary permissions?

A.Attach a resource-based policy to the S3 bucket and DynamoDB table allowing access from the Lambda function.
B.Create an IAM execution role for Lambda with permissions to read from S3 and write to DynamoDB.
C.Configure the S3 bucket policy to allow the Lambda function's ARN.
D.Store AWS access keys in the Lambda environment variables.
AnswerB

An IAM execution role is the recommended and most secure method for granting a Lambda function permissions to interact with other AWS services. When a Lambda function assumes this role, it receives temporary credentials, allowing it to perform actions like reading from an S3 bucket and writing to a DynamoDB table, as defined by the role's attached IAM policies. This approach adheres to the principle of least privilege and eliminates the need for hardcoding or managing static credentials within the function's configuration.

Why this answer

The most secure and AWS-recommended pattern is to create an IAM execution role for the Lambda function that grants least-privilege access to the specific S3 bucket and DynamoDB table. Lambda assumes this role at invocation, so no long-lived credentials exist and permissions are centrally managed.

Exam trap

DVA-C02 often tests whether candidates confuse resource-based policies (which grant others access to a resource) with execution roles (which grant a compute service access to other resources), leading them to pick a bucket policy instead of an IAM role.

How to eliminate wrong answers

Option A is wrong because resource-based policies on S3 and DynamoDB are used for cross-account or service-principal access, not for granting a Lambda function in the same account its execution permissions; Lambda still needs an execution role. Option C is wrong because an S3 bucket policy granting the Lambda ARN does not give Lambda permission to call DynamoDB and is not the mechanism Lambda uses to obtain credentials. Option D is wrong because storing AWS access keys in environment variables is an anti-pattern that exposes long-lived credentials in plaintext and violates least-privilege and rotation best practices.

420
MCQhard

A developer is building a REST API using API Gateway and Lambda. The API must support multiple HTTP methods and use a custom domain name with an SSL certificate. The developer wants to enable caching for the /products GET endpoint to reduce latency. Which step is essential to enable caching for this specific endpoint?

A.Set the TTL (time-to-live) for the /products GET method to a non-zero value.
B.Enable caching on the /products GET method and specify cache key parameters.
C.Flush the API cache to start fresh.
D.Enable caching on the API stage and set the 'Cache Status' to 'AVAILABLE'.
AnswerB

To implement caching for a specific API Gateway method like /products GET, caching must first be enabled at the API stage level. Subsequently, individual methods can be configured to utilize this cache. This involves explicitly enabling caching for the /products GET method and defining cache key parameters, which dictate how requests are uniquely identified for caching purposes, often including query string parameters, headers, or path parameters. This ensures relevant responses are stored and retrieved efficiently.

Why this answer

Enabling caching on a specific method (e.g., /products GET) in API Gateway allows you to configure cache key parameters, which control how the cache key is generated based on request parameters. This is essential for per-endpoint caching, as it ensures that only responses for the /products GET endpoint are cached, reducing latency for that specific method without affecting other endpoints.

Exam trap

The trap here is that candidates often confuse enabling caching at the stage level (which caches all methods) with enabling it on a specific method, and they overlook the requirement to specify cache key parameters for per-endpoint control.

How to eliminate wrong answers

Option A is wrong because setting a non-zero TTL on the /products GET method is not a step to enable caching; TTL is configured after caching is enabled and controls how long cached responses are retained, not the enabling itself. Option C is wrong because flushing the API cache clears existing cached data but does not enable caching; it is a maintenance action, not an enabling step. Option D is wrong because enabling caching on the API stage caches all methods in the stage by default, not specifically the /products GET endpoint, and the 'Cache Status' to 'AVAILABLE' is a status indicator, not an action to enable per-method caching.

421
MCQhard

A team wants CloudFormation to prevent accidental deletion of a production DynamoDB table during stack updates. What should they configure?

A.A larger write capacity setting
B.A Lambda layer
C.An API Gateway usage plan
D.DeletionPolicy or UpdateReplacePolicy Retain as appropriate
AnswerD

CloudFormation provides the `DeletionPolicy` and `UpdateReplacePolicy` attributes specifically to control the lifecycle of resources during stack operations. Setting `DeletionPolicy` to `Retain` ensures that a resource is not deleted when its containing stack is deleted or the resource is removed from the template. Similarly, `UpdateReplacePolicy` set to `Retain` prevents the old physical resource from being deleted if it is replaced during a stack update, directly addressing the requirement to prevent accidental resource deletion.

Why this answer

The DeletionPolicy attribute with a value of Retain instructs AWS CloudFormation to preserve the DynamoDB table when its stack resource is deleted during a stack update or stack deletion. Similarly, UpdateReplacePolicy Retain ensures that if a resource replacement is required during an update, the existing table is kept rather than deleted. This directly prevents accidental data loss by overriding CloudFormation's default behavior of deleting resources that are removed from the template or replaced.

Exam trap

The trap here is that candidates may confuse operational settings (like write capacity) or unrelated services (Lambda layers, API Gateway) with CloudFormation's resource lifecycle policies, missing the direct purpose of DeletionPolicy and UpdateReplacePolicy.

How to eliminate wrong answers

Option A is wrong because a larger write capacity setting only affects DynamoDB's throughput performance and has no impact on resource lifecycle or deletion prevention. Option B is wrong because a Lambda layer is used to package runtime dependencies for Lambda functions and does not influence CloudFormation's resource deletion behavior. Option C is wrong because an API Gateway usage plan throttles and monitors API requests for billing or rate-limiting purposes and is unrelated to CloudFormation stack resource protection.

422
MCQmedium

A developer is debugging an issue where an Amazon S3 bucket policy is not allowing cross-account access for a user from another AWS account. The bucket policy grants access to the other account's root user. The IAM user in the other account has an IAM policy that allows s3:GetObject on the bucket. When the user tries to download an object, they get an Access Denied error. What is the most likely cause?

A.The bucket is encrypted with SSE-KMS and the user does not have kms:Decrypt permission
B.The bucket policy does not specify the user's ARN
C.The object's ACL is set to private
D.The IAM policy does not include s3:ListBucket
AnswerA

When an S3 object is encrypted with Server-Side Encryption using AWS Key Management Service (SSE-KMS), the requesting principal requires two distinct permissions for GetObject operations. Beyond the s3:GetObject permission on the bucket, an explicit kms:Decrypt permission on the specific AWS KMS key used for encryption is mandatory. Without this crucial KMS permission, even a valid S3 bucket policy allowing s3:GetObject will result in an Access Denied error, as S3 cannot decrypt the object for the user.

Why this answer

The most likely cause is that the bucket is encrypted with SSE-KMS. When an S3 bucket uses AWS KMS customer master keys (CMKs) for server-side encryption, the bucket policy granting access to the root user of the other account is not sufficient. The IAM user in the other account must also have explicit kms:Decrypt permission on the KMS key, because S3 GetObject calls require decrypting the object before returning it.

Without this KMS permission, the request fails with Access Denied even though the S3 bucket policy and IAM policy appear correct.

Exam trap

The trap here is that candidates assume a valid S3 bucket policy and IAM policy are sufficient, forgetting that KMS encryption adds an independent authorization layer that requires explicit kms:Decrypt permissions, which is a common oversight in cross-account S3 access scenarios.

How to eliminate wrong answers

Option B is wrong because the bucket policy grants access to the other account's root user, which covers all IAM users and roles in that account by default; specifying the individual user's ARN is not required. Option C is wrong because object ACLs are evaluated after bucket policies, and if the bucket policy explicitly grants access, a private object ACL would be overridden (unless the bucket policy has a condition denying access). Option D is wrong because s3:ListBucket is only needed for listing objects (e.g., GET Bucket (List Objects) requests), not for downloading a specific object using s3:GetObject.

423
Multi-Selectmedium

Which THREE of the following are valid use cases for AWS Lambda? (Choose three.)

Select 3 answers
A.Processing records from a DynamoDB Stream in real time
B.Running a scheduled task every hour to clean up old database records
C.Serving as a web server for a static website
D.Hosting a long-running web application with WebSockets
E.Processing objects uploaded to an S3 bucket
AnswersA, B, E

AWS Lambda is an excellent choice for processing records from a DynamoDB Stream in real time. DynamoDB Streams provide a time-ordered sequence of item-level modifications, which can be configured as an event source for a Lambda function. This allows the function to automatically invoke and process batches of stream records as soon as changes occur in the DynamoDB table, enabling real-time data processing, analytics, or replication.

Why this answer

Option A is correct because DynamoDB Streams can be configured as an event source for Lambda, which then invokes the function in real time with batches of stream records for processing. Option B is correct because Amazon EventBridge (CloudWatch Events) scheduled rules can invoke a Lambda function on a cron or rate expression, such as hourly, making it suitable for periodic cleanup tasks. Option C is incorrect because static websites are served by services like Amazon S3 static website hosting or CloudFront, not by Lambda, which is an event-driven compute service rather than a persistent web server.

Option D is incorrect because long-running applications with persistent WebSocket connections require continuously running compute such as EC2, ECS, or API Gateway WebSocket APIs backed by appropriate compute, whereas Lambda has a maximum execution timeout of 15 minutes and is not designed for persistent connections. Option E is correct because S3 can be configured to send event notifications (e.g., s3:ObjectCreated:*) that invoke a Lambda function to process uploaded objects.

Exam trap

The trap here is that candidates often confuse Lambda's ability to handle HTTP requests via API Gateway with the idea that Lambda itself can serve as a web server, ignoring its stateless nature and execution timeout constraints.

424
Matchingmedium

Match each AWS tool or feature to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Infrastructure as Code

PaaS for web apps

Automated code deployment

Distributed tracing

Key management encryption

Why these pairings

AWS CodeDeploy automates code deployments, while Amazon CloudWatch provides monitoring. The distractors swap these definitions to test understanding of each service's purpose.

425
MCQeasy

A developer is deploying a serverless application using the AWS Serverless Application Model (SAM). The developer runs 'sam deploy' and receives an error: 'Error: Failed to create changeset for the stack.' What is a common cause of this error?

A.The SAM template contains a syntax error.
B.The S3 bucket specified for artifacts does not exist.
C.The IAM user does not have permission to create CloudFormation stacks.
D.AWS CodeDeploy is not configured for the application.
AnswerA

When `sam deploy` (or `aws cloudformation deploy`) is executed, the CloudFormation service first validates the template's syntax and structure. If the SAM template, which is an extension of CloudFormation, contains a syntax error (e.g., incorrect YAML/JSON formatting, invalid intrinsic function usage, or malformed resource properties), CloudFormation will fail to parse it. This failure occurs early in the deployment process, specifically preventing the successful creation of a changeset, as the service cannot understand the desired state described by the invalid template.

Why this answer

The 'Failed to create changeset for the stack' error typically occurs when the SAM template contains a syntax error, such as invalid YAML formatting, missing required properties, or incorrect resource definitions. AWS CloudFormation validates the template before creating a changeset, and any syntax issue will cause the changeset creation to fail immediately. This is the most common cause because SAM templates are YAML-based and prone to indentation or structural mistakes.

Exam trap

The trap here is that candidates often confuse changeset creation failures with permission or bucket issues, but the error message specifically points to template validation, not infrastructure or IAM problems.

How to eliminate wrong answers

Option B is wrong because if the S3 bucket specified for artifacts does not exist, the error would be 'Unable to upload artifact...' or 'Bucket not found', not a changeset creation failure. Option C is wrong because insufficient IAM permissions to create CloudFormation stacks would result in an 'AccessDenied' or authorization error, not a changeset creation failure. Option D is wrong because AWS CodeDeploy is not required for SAM deployments; SAM uses CloudFormation for infrastructure provisioning, and CodeDeploy is only relevant if you configure a separate deployment pipeline.

426
MCQmedium

A company is using Amazon CloudFront to distribute static content from an S3 bucket. The content is updated frequently, but users see stale content. The developer wants to ensure that new content is served as soon as possible after an update. Which action should be taken?

A.Enable 'Origin Shield' to reduce the number of requests to S3.
B.Set the 'Minimum TTL' to 0 and 'Default TTL' to 0.
C.Set the 'Object Caching' to 0 in the CloudFront distribution.
D.Create a CloudFront invalidation for the updated files.
AnswerD

Creating a CloudFront invalidation request specifically targets and removes specified objects from all CloudFront edge caches globally. Upon successful invalidation, the next request for those objects at any edge location will result in CloudFront fetching the latest version directly from the origin. This is the most direct and effective method to ensure users immediately receive updated content after changes have been deployed to the origin, overriding any existing TTL settings.

Why this answer

CloudFront caches content at edge locations based on TTL settings. When content is updated in the S3 origin, existing cached copies remain stale until they expire or are explicitly invalidated. Creating a CloudFront invalidation for the updated files immediately removes the cached objects from all edge locations, forcing CloudFront to fetch the latest version from S3 on the next request.

This ensures new content is served as soon as possible after an update.

Exam trap

The trap here is that candidates confuse TTL configuration (which controls how long new objects are cached) with invalidation (which removes already-cached objects), leading them to pick options that only affect future caching behavior without addressing the stale content already served.

How to eliminate wrong answers

Option A is wrong because enabling Origin Shield reduces the number of requests to the S3 origin by consolidating them at a regional cache layer, but it does not force CloudFront to serve fresh content; it can actually increase staleness by adding another caching layer. Option B is wrong because setting Minimum TTL and Default TTL to 0 tells CloudFront to respect the Cache-Control max-age=0 header from the origin, but if the S3 object does not have that header (or has a higher max-age), CloudFront will still cache the content for the origin's specified duration; TTL settings alone do not purge already-cached content. Option C is wrong because 'Object Caching' is not a configurable numeric field in CloudFront; the correct setting is 'Minimum TTL', 'Maximum TTL', and 'Default TTL' under the 'Cache Based on Selected Request Headers' behavior, and setting these to 0 does not invalidate existing cached objects.

427
MCQhard

An IAM policy attached to an IAM user. What is the effect of this policy on the user's ability to delete objects in the bucket my-bucket?

A.The user can delete objects from any IP address.
B.The user is denied the ability to delete objects regardless of source IP.
C.The user can delete objects only if the source IP is not 192.0.2.0/24.
D.The user can delete objects only if the source IP is 192.0.2.0/24.
AnswerB

No Allow statement exists for DeleteObject, so implicit deny applies.

Why this answer

The question cannot be answered as written because the IAM policy text is missing. To determine the effect on s3:DeleteObject, the policy's Effect, Action, and Condition (including any IpAddress or NotIpAddress operators) must be provided. Without the policy, no option can be verified as correct.

Exam trap

The trap described assumes a specific policy containing a Deny effect with a NotIpAddress condition, but no such policy is shown in the stem. Candidates cannot apply this reasoning without the actual policy text.

How to eliminate wrong answers

Option A is wrong because the policy includes a `Deny` effect with a `NotIpAddress` condition that denies `s3:DeleteObject` from any IP not in 192.0.2.0/24, and an explicit deny for the 192.0.2.0/24 range, so the user cannot delete from any IP. Option C is wrong because the policy does not allow deletion from IPs outside 192.0.2.0/24; it explicitly denies deletion from those IPs via the `NotIpAddress` condition. Option D is wrong because the policy explicitly denies deletion from the 192.0.2.0/24 range, so the user cannot delete from that IP range either.

428
Multi-Selectmedium

A DynamoDB query must support lookup by email address as well as by user ID. Which two changes may be required?

Select 2 answers
A.Create a secondary index with email as a key
B.Scan the full table for every login
C.Choose projection attributes needed by the query
D.Disable partition keys
AnswersA, C

This is the primary mechanism in DynamoDB to efficiently query data using an attribute other than the table's primary key. By defining a Global Secondary Index (GSI) with email as its partition key, DynamoDB builds a separate, sparse table that allows direct, high-performance lookups based on email addresses. This approach avoids costly full table scans and ensures predictable, low-latency access for user authentication or profile retrieval.

Why this answer

A Global Secondary Index (GSI) or Local Secondary Index (LSI) on the email attribute allows DynamoDB to efficiently query by email address without scanning the entire table. Since the primary key is user ID, querying by email requires an index that uses email as the partition key or sort key. Option C is correct because specifying projection attributes limits the data returned from the index or table, reducing read capacity consumption and improving performance.

Exam trap

The trap here is that candidates may think a Scan is acceptable for low-volume logins, but the exam emphasizes that any production authentication system must use an index to avoid full table scans and meet latency requirements.

429
MCQeasy

A developer is using AWS CloudFormation to create a stack that includes an EC2 instance. The stack creation fails because the instance type is not supported in the selected Availability Zone. What should the developer do?

A.Delete the stack and start over.
B.Change the instance type to one that is supported.
C.Update the stack to specify a different subnet or not specify an Availability Zone.
D.Create the stack in a different region.
AnswerC

Updating the stack to specify a different subnet or removing the explicit Availability Zone (AZ) specification is the most effective and flexible solution. If a specific AZ lacks capacity for the requested instance type, deploying into a different subnet, which is tied to another AZ, can resolve the issue. Alternatively, by not specifying an AZ, CloudFormation can automatically select an available AZ with sufficient capacity for the desired instance type, ensuring successful deployment while maintaining the intended resource configuration. This leverages CloudFormation's intelligence to handle underlying infrastructure constraints.

Why this answer

When an EC2 instance type is not supported in a specific Availability Zone (AZ), the developer can update the CloudFormation stack to either specify a different subnet (which implicitly selects a different AZ) or omit the Availability Zone parameter entirely, allowing AWS to automatically choose an AZ where the instance type is supported. This avoids the need to delete the stack or change the instance type, preserving other stack resources and configurations.

Exam trap

The trap here is that candidates assume the only fix is to change the instance type (Option B) or restart from scratch (Option A), overlooking CloudFormation's ability to update the stack's subnet or AZ selection to match the instance type's availability.

How to eliminate wrong answers

Option A is wrong because deleting the stack and starting over is unnecessary and inefficient; the issue can be resolved by updating the stack's subnet or AZ specification without losing existing resources. Option B is wrong because changing the instance type may not be desirable if the developer specifically needs that instance type for performance or cost reasons; the problem is the AZ constraint, not the instance type itself. Option D is wrong because creating the stack in a different region is an overreaction; the instance type is likely supported in other AZs within the same region, and changing regions could introduce latency, cost, or compliance issues.

430
Multi-Selecteasy

A developer is creating an IAM policy for an EC2 instance to allow it to read from an S3 bucket. Which of the following are required? (Choose TWO.)

Select 2 answers
A.Create an IAM role with s3:GetObject permissions
B.Use KMS to encrypt the S3 objects
C.Configure an S3 bucket policy allowing the role
D.Attach the IAM role to the EC2 instance
E.Create an instance profile and assign a key pair
AnswersA, D

An IAM role is the fundamental identity construct used to grant permissions to AWS services, including EC2 instances. Creating an IAM role with the specific `s3:GetObject` permission ensures that the EC2 instance is authorized to retrieve objects from an S3 bucket, adhering to the principle of least privilege by granting only the necessary read access for the intended operation.

Why this answer

An IAM role is the recommended way to grant temporary, secure credentials to an EC2 instance for accessing AWS services. The s3:GetObject permission allows the instance to read objects from an S3 bucket, which is the specific action required for read access.

Exam trap

The trap here is that candidates often think an S3 bucket policy is always required when using an IAM role, but it is only necessary for cross-account access or when the bucket policy explicitly restricts access; for same-account access, the role's permissions alone are sufficient.

431
MCQmedium

A developer is using AWS CodeDeploy to deploy a new version of an AWS Lambda function. The developer wants to gradually shift traffic from the old version to the new version in 10-minute increments. Which deployment configuration should the developer use?

A.Canary10Percent10Minutes
B.Canary10Percent30Minutes
C.Linear10PercentEvery10Minutes
D.AllAtOnce
AnswerC

This CodeDeploy configuration precisely aligns with the requirement for gradual, incremental traffic shifts. It systematically routes 10% of traffic to the new Lambda version, waits for 10 minutes, then shifts another 10%, repeating this process until 100% of traffic is successfully moved. This ensures a controlled, step-by-step rollout, allowing for continuous monitoring and potential rollback at each 10-minute interval.

Why this answer

The Linear10PercentEvery10Minutes configuration shifts traffic from the old Lambda version to the new version in 10% increments every 10 minutes, which matches the developer's requirement of gradually shifting traffic in 10-minute increments. This is a linear deployment type in AWS CodeDeploy that provides a steady, incremental traffic shift over time.

Exam trap

The trap here is confusing canary deployments (which shift a small percentage immediately and then the remainder after a wait) with linear deployments (which shift traffic in equal increments over time), leading candidates to select a canary configuration when a linear one is required.

How to eliminate wrong answers

Option A is wrong because Canary10Percent10Minutes shifts 10% of traffic to the new version immediately, then waits 10 minutes before shifting the remaining 90% all at once, which does not provide gradual 10-minute increments. Option B is wrong because Canary10Percent30Minutes shifts 10% immediately, then waits 30 minutes before shifting the remaining 90%, which does not match the 10-minute increment requirement. Option D is wrong because AllAtOnce shifts 100% of traffic to the new version immediately with no gradual traffic shifting, which contradicts the developer's requirement.

432
Multi-Selecteasy

A developer is creating an IAM policy for a Lambda function that needs to read from an SQS queue and write to a DynamoDB table. Which THREE permissions are required? (Select THREE.)

Select 3 answers
A.sqs:DeleteMessage
B.dynamodb:PutItem
C.sqs:ReceiveMessage
D.sqs:SendMessage
E.dynamodb:GetItem
AnswersA, B, C

This permission is essential for a Lambda function processing messages from an SQS queue. After a message is successfully processed, the function must explicitly call `DeleteMessage` to remove it from the queue. Without this action, the message will eventually become visible again after its visibility timeout expires, leading to duplicate processing and potential data inconsistencies, which is critical to avoid for reliable message handling.

Why this answer

A is correct because the Lambda function must delete messages from the SQS queue after processing them to prevent them from being reprocessed. The sqs:DeleteMessage permission is required to call the DeleteMessage API, which removes the message from the queue using its receipt handle. Without this permission, the function would successfully receive and process the message but fail to delete it, causing the message to become visible again after the visibility timeout expires.

Exam trap

The trap here is that candidates often confuse the permissions needed for a Lambda function acting as a consumer (ReceiveMessage and DeleteMessage) with those needed for a producer (SendMessage), or they mistakenly think GetItem is required for writing to DynamoDB when PutItem is the correct write operation.

433
MCQmedium

A developer runs the above command and gets the output shown. What is the developer verifying?

A.Whether the object is encrypted
B.The size and ETag of an object in S3
C.The version ID of the object
D.Whether the user has permissions to access the object
AnswerB

The `aws s3api get-object-attributes` command is specifically engineered to efficiently retrieve various attributes of an S3 object without requiring the download of the object's content. Among the key pieces of metadata it returns are the `ObjectSize`, which provides the total size of the object in bytes, and the `ETag`, an entity tag that serves as a hash of the object's content. These attributes are crucial for integrity checks, conditional requests, and managing storage consumption within S3.

Why this answer

The command retrieves attributes of an object, including its size and ETag. Option A is incorrect because encryption is not checked by this command. Option C is incorrect because version ID is not part of the output shown.

Option D is incorrect because the command does not test permissions; it just returns the object metadata if the user has read access.

434
MCQmedium

A developer is deploying a new version of an AWS Lambda function using the AWS CLI. The developer wants to create a new version and update the alias to point to the new version. Which sequence of CLI commands should the developer use?

A.Update alias, update function code, publish version
B.Create alias, update function code, publish version
C.Publish version, update function code, update alias
D.Update function code, publish version, update alias
AnswerD

First, updating the function code ensures the `$LATEST` version contains the desired new logic. Next, publishing a version creates an immutable snapshot of this updated code, providing a stable reference point. Finally, updating the alias to point to this newly published version allows for controlled traffic shifting, enabling safe deployments, rollbacks, and advanced strategies like canary releases.

Why this answer

The correct sequence is to first update the function code, then publish a new version, and finally update the alias to point to that new version. The `update-function-code` command uploads the new code to the $LATEST version, `publish-version` creates an immutable numbered version from $LATEST, and `update-alias` updates the alias to reference that specific version. This ensures the alias always points to a stable, published version rather than the mutable $LATEST.

Exam trap

The trap here is that candidates often think they can update the alias before publishing the version, or they confuse the order of operations by assuming the alias can point to $LATEST, but the exam requires the alias to reference a specific published version for immutability and rollback safety.

How to eliminate wrong answers

Option A is wrong because it attempts to update the alias before the new version exists, which would fail or point to a non-existent version. Option B is wrong because it creates a new alias instead of updating an existing one, and also attempts to update the alias before the version is published. Option C is wrong because it publishes a version before updating the function code, which would publish the old code, and then updates the function code to $LATEST without publishing a new version, leaving the alias pointing to the old published version.

435
MCQmedium

A developer is building a mobile application that uses Amazon Cognito for user authentication. After a user signs in, the application needs to access an Amazon DynamoDB table. The developer has set up an identity pool with an authenticated role. The IAM role attached to the authenticated identity has a policy allowing the required DynamoDB actions. However, users report that they cannot perform DynamoDB operations. What is the MOST likely cause of this issue?

A.The identity pool is not configured to use the authenticated role.
B.The app is not passing the correct identity ID.
C.The IAM role's trust policy does not allow Cognito to assume it.
D.The DynamoDB table is encrypted with a different KMS key.
AnswerC

The trust policy of an IAM role explicitly defines which entities are permitted to assume that role. For Amazon Cognito Identity Pools to issue temporary AWS credentials to an authenticated user, the IAM role associated with the authenticated identity must have a trust policy that grants the Cognito Identity service principal (cognito-identity.amazonaws.com) the sts:AssumeRole permission. Without this crucial trust relationship, Cognito cannot generate the necessary temporary credentials, leading to 'Access Denied' errors when the application attempts to interact with other AWS services, regardless of the permissions policy attached to the role.

Why this answer

The most likely cause is that the IAM role's trust policy does not include a statement allowing Amazon Cognito (specifically the `cognito-identity.amazonaws.com` service principal) to assume the role. Even if the identity pool is configured to use the authenticated role and the role's permissions policy grants DynamoDB actions, Cognito must be able to assume the role via AWS Security Token Service (STS) `AssumeRoleWithWebIdentity`. Without the correct trust relationship, Cognito cannot obtain temporary credentials for the user, so all DynamoDB operations fail.

Exam trap

The trap here is that candidates often focus on the permissions policy (allowing DynamoDB actions) and overlook the trust policy, which is a separate and critical requirement for Cognito to assume the role and generate credentials.

How to eliminate wrong answers

Option A is wrong because if the identity pool were not configured to use the authenticated role, the developer would not have been able to set it up in the first place; the configuration is a prerequisite that is explicitly stated as done. Option B is wrong because the identity ID is used to identify the user within the identity pool, but passing an incorrect identity ID would cause authentication failures or mismatched credentials, not a permissions issue on DynamoDB after sign-in; the core problem is the lack of a trust policy allowing role assumption. Option D is wrong because KMS key encryption on the DynamoDB table would only cause access failures if the IAM role lacked `kms:Decrypt` permissions or the key policy denied access, but the question states the role's policy allows the required DynamoDB actions, and KMS key mismatch would produce a different error (AccessDeniedException for KMS), not a generic inability to perform DynamoDB operations.

436
MCQeasy

A developer needs to store session state for a stateless web application running on EC2 instances behind an Application Load Balancer. Which AWS service should the developer use to ensure session data is not lost if an instance fails?

A.Amazon S3
B.Amazon DynamoDB
C.Amazon ElastiCache
D.Amazon RDS
AnswerB

DynamoDB is a NoSQL key-value store, not a session state cache; it lacks the low-latency, in-memory read performance and automatic expiry mechanisms that ElastiCache provides for session management. It is tempting because it offers durable, scalable storage for any application data, and would be correct for persisting session history or user profiles across restarts, but the stem requires a solution that prevents data loss during instance failure without introducing the latency of disk-based persistence.

Why this answer

Amazon DynamoDB is a fully managed NoSQL database that provides fast and predictable performance with seamless scalability. It is highly recommended for storing session state in stateless applications because it is serverless, highly durable, and requires no cluster management, unlike ElastiCache. AWS SDKs even offer native session state providers for DynamoDB.

Exam trap

Do not assume ElastiCache is always the only choice for session state. While ElastiCache (Redis) is an excellent in-memory option, DynamoDB is the standard serverless, durable key-value store recommended for session state in many DVA-C02 scenarios because it requires no cluster provisioning or management.

How to eliminate wrong answers

Option A is wrong because Amazon S3 is an object storage service designed for static files and large data blobs, not for low-latency session state access; its read/write latency and lack of native key-value expiration make it unsuitable for real-time session management. Option B is wrong because Amazon DynamoDB, while capable of storing session data, introduces higher latency and cost compared to an in-memory cache like ElastiCache, and its primary use case is for persistent, scalable NoSQL workloads rather than ephemeral session state. Option D is wrong because Amazon RDS is a relational database service that incurs significant overhead for frequent session reads/writes, and its connection pooling and disk-based I/O are not optimized for the sub-millisecond access patterns required for session state in a stateless web application.

437
MCQeasy

A developer needs to allow an IAM user to manage only their own access keys (create, list, update, delete). Which IAM policy statement achieves this?

A.{"Effect":"Allow","Action":"iam:*AccessKey*","Resource":"arn:aws:iam::*:user/${aws:username}"}
B.{"Effect":"Allow","Action":"iam:*AccessKey*","Resource":"arn:aws:iam::*:user/JohnDoe"}
C.{"Effect":"Allow","Action":"iam:*AccessKey*","Resource":"*"}
D.{"Effect":"Allow","Action":["iam:ListAccessKeys","iam:GetAccessKeyLastUsed"],"Resource":"*"}
AnswerA

This policy correctly grants comprehensive permissions for managing access keys through the `iam:*AccessKey*` action wildcard, which includes actions like Create, Delete, and Update. Crucially, the `Resource` element utilizes the `arn:aws:iam::*:user/${aws:username}` policy variable. This dynamic variable ensures that the policy's scope is strictly limited to the IAM user's own user resource, allowing them to create, delete, update, and list *only their own* access keys, thereby adhering to the principle of least privilege and the specific requirement.

Why this answer

It uses the `iam:*AccessKey*` wildcard action to cover all access key management operations (create, list, update, delete) and restricts the resource to `arn:aws:iam::*:user/${aws:username}`. The `${aws:username}` policy variable dynamically resolves to the IAM user's own username, ensuring that each user can only manage their own access keys. This follows the principle of least privilege by scoping permissions to the user's own resource.

Exam trap

The trap here is that candidates often choose Option C (resource `*`) thinking it grants access to all users' keys, but they overlook that the wildcard resource would allow a user to manage other users' keys, violating the 'only their own' requirement.

How to eliminate wrong answers

Option B is wrong because it hardcodes the username 'JohnDoe', which would only allow that specific user to manage their own access keys, not any IAM user as required by the question. Option C is wrong because the resource `*` grants access to all IAM users' access keys, violating the requirement that each user manages only their own keys. Option D is wrong because it only includes read-only actions (`iam:ListAccessKeys` and `iam:GetAccessKeyLastUsed`) and omits the create, update, and delete actions needed to fully manage access keys.

438
Matchingmedium

Match each AWS storage class to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Frequent access, low latency

Automatic cost optimization

Long-term archival

Infrequent access, single AZ

Lowest cost retrieval

Why these pairings

The correct matches are S3 Standard with frequently accessed data, S3 Intelligent-Tiering with automatic cost optimization, S3 Glacier Instant Retrieval with archive and fast retrieval, and S3 One Zone-IA with infrequent data in one AZ. Common confusions include mixing up storage class descriptions.

439
MCQmedium

A developer is deploying a serverless application using AWS SAM. The application includes an API Gateway endpoint that invokes a Lambda function. The developer wants to pass a stage name as a parameter to the Lambda function. How should the developer define the Lambda function's environment variable in the SAM template?

A.Use the parameter reference 'Ref: StageName' in the environment variable mapping.
B.Define the environment variable as 'Stage: dev' in the Lambda function configuration.
C.Use 'Fn::GetAtt: [AWS::StackName, Outputs.StageName]' to get the stage name.
D.Use 'Fn::ImportValue: StageName' to import from another stack.
AnswerA

This is the correct approach for dynamically injecting a value provided at deployment time into a Lambda function's environment variables. `Ref` is a CloudFormation intrinsic function that retrieves the value of a top-level parameter declared in the `Parameters` section of the template. By defining `StageName` as a parameter and referencing it with `Ref: StageName` in the Lambda's environment variable configuration, the developer ensures the stage name (e.g., 'dev', 'prod') is passed during stack creation or update, making the application adaptable across different environments without code changes.

Why this answer

The developer should use the parameter reference 'Ref: StageName' in the environment variable mapping. In AWS SAM, you can reference parameters defined in the template using the Ref intrinsic function. This allows the stage name to be passed as an environment variable to the Lambda function.

Exam trap

DVA-C02 often tests the correct use of intrinsic functions, and candidates may confuse Ref with Fn::GetAtt or Fn::ImportValue, or attempt to reference outputs incorrectly.

How to eliminate wrong answers

Option B is wrong because hardcoding 'Stage: dev' does not allow dynamic parameterization; it would always be 'dev'. Option C is wrong because 'Fn::GetAtt' is used to get attributes of resources, not outputs from the stack; there is no 'Outputs.StageName' attribute on AWS::StackName. Option D is wrong because 'Fn::ImportValue' is used to import values from other stacks, not to reference a parameter within the same template.

440
MCQmedium

A company wants to store database credentials securely and rotate them automatically on a schedule. The credentials are used by an AWS Lambda function to access an Amazon RDS instance. Which AWS service should the developer use to meet these requirements?

A.AWS Secrets Manager
B.AWS Systems Manager Parameter Store
C.AWS Key Management Service (KMS)
D.AWS Certificate Manager (ACM)
AnswerA

AWS Secrets Manager is specifically designed for securely storing and managing secrets such as database credentials, API keys, and other sensitive data. It offers robust capabilities for automatic rotation of credentials, particularly for services like Amazon RDS, Amazon Redshift, and Amazon DocumentDB, significantly enhancing security posture by reducing the lifespan of individual credentials. This built-in automation directly addresses the requirement for secure storage and regular rotation, minimizing the risk of compromise.

Why this answer

AWS Secrets Manager is the correct choice because it is specifically designed to securely store, retrieve, and automatically rotate database credentials on a schedule. It natively supports automatic rotation for Amazon RDS databases (including MySQL, PostgreSQL, Oracle, SQL Server, and MariaDB) by integrating with Lambda to update the credentials in both Secrets Manager and the RDS instance. This meets the requirement for both secure storage and scheduled rotation without custom infrastructure.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (which can store secrets but lacks native rotation) with Secrets Manager, leading them to choose Parameter Store for its lower cost, but the requirement for automatic rotation disqualifies it.

How to eliminate wrong answers

Option B is wrong because AWS Systems Manager Parameter Store does not support automatic rotation of secrets; it requires custom solutions or integration with Secrets Manager for rotation. Option C is wrong because AWS KMS is a key management service for encryption keys, not for storing or rotating secrets like database credentials. Option D is wrong because AWS Certificate Manager (ACM) is used for managing SSL/TLS certificates, not for database credentials or rotation.

441
MCQeasy

A developer in Account A has an Amazon S3 bucket that contains sensitive data. The developer wants to grant an IAM user in Account B read-only access to objects in the bucket. The developer has added a bucket policy in Account A that grants s3:GetObject access to the IAM user's ARN. However, the IAM user in Account B still receives Access Denied errors. What additional configuration is required?

A.Add an IAM policy in Account B that allows the user to perform s3:GetObject on the bucket's ARN.
B.Create an S3 access point and grant the user access through it.
C.Change the bucket policy to grant access to the entire AWS account B instead of the specific user.
D.Enable S3 object ownership and set the bucket ACL to grant read access to the user in Account B.
AnswerA

The core principle for cross-account S3 access dictates that both the resource owner (Account A) and the identity owner (Account B) must explicitly grant permission. While the bucket policy in Account A grants permission *to* Account B, the IAM user in Account B still requires an identity-based policy attached to them that explicitly allows the `s3:GetObject` action on the specified bucket ARN. This two-policy evaluation ensures that both accounts agree on the access, making this the correct and necessary step.

Why this answer

Cross-account access to S3 requires both a bucket policy in the source account (Account A) granting the necessary permissions to the target IAM user, and an IAM identity-based policy in the target account (Account B) that explicitly allows the same action (s3:GetObject) on the bucket's ARN. Without the IAM policy in Account B, the user lacks the authorization to initiate the request, even though the bucket policy permits it. This dual-permission model is a fundamental security requirement for cross-account S3 access.

Exam trap

The trap here is that candidates often assume a bucket policy alone is sufficient for cross-account access, overlooking the mandatory IAM policy in the target account that must explicitly allow the action.

How to eliminate wrong answers

Option B is wrong because creating an S3 access point does not bypass the need for an IAM policy in Account B; access points still require both the bucket policy and the user's IAM policy to grant cross-account permissions. Option C is wrong because granting access to the entire AWS account B instead of the specific user would allow all principals in Account B (including unintended users) to access the bucket, which violates the principle of least privilege and does not resolve the missing IAM policy issue. Option D is wrong because S3 object ownership and bucket ACLs are legacy mechanisms that do not apply to cross-account access when a bucket policy is already in use; ACLs are disabled by default for new buckets and are not a substitute for the required IAM policy in Account B.

442
MCQeasy

A developer needs to securely store database credentials for a Lambda function. Which AWS service should be used?

A.AWS Secrets Manager
B.AWS CloudHSM
C.AWS KMS
D.Amazon DynamoDB
AnswerA

AWS Secrets Manager enables automatic rotation of database credentials on a configurable schedule, satisfying the developer's need to avoid hard-coded secrets in Lambda environment variables. Its built-in integration with Amazon RDS, Redshift, and DocumentDB allows the Lambda function to retrieve current credentials at runtime via the GetSecretValue API, eliminating manual secret management.

Why this answer

AWS Secrets Manager is the correct service because it is purpose-built for securely storing, rotating, and managing database credentials and other secrets throughout their lifecycle. It integrates natively with Lambda via the AWS Secrets Manager API, allowing the function to retrieve credentials at runtime without hardcoding them, and supports automatic rotation using built-in or custom Lambda rotation functions. This makes it the ideal choice for securely handling database credentials in a serverless application.

Exam trap

The trap here is that candidates often confuse AWS KMS (which only manages encryption keys) with AWS Secrets Manager (which manages the full lifecycle of secrets), leading them to choose KMS because they think 'encryption' is the primary requirement, when in fact the question asks for secure storage and management of credentials, not just encryption.

How to eliminate wrong answers

Option B (AWS CloudHSM) is wrong because it provides dedicated hardware security modules (HSMs) for cryptographic key generation and storage, not for managing application secrets like database credentials; it lacks built-in secret rotation and retrieval APIs. Option C (AWS KMS) is wrong because it is a key management service for creating and controlling encryption keys used to encrypt data, not for storing or rotating secrets; while it can encrypt secrets stored elsewhere, it does not natively manage the secret lifecycle. Option D (Amazon DynamoDB) is wrong because it is a NoSQL database designed for high-performance, scalable data storage, not a secrets management service; storing credentials in DynamoDB would require manual encryption, rotation, and access control, increasing security risk and operational overhead.

443
MCQhard

An application uses an Auto Scaling group with a launch configuration that includes a user data script to configure instances. After a scaling event, new instances launch but fail to register with the target group. The existing instances continue to work. What should the developer do to resolve this issue?

A.Modify the existing launch configuration with the correct user data
B.Create a new launch configuration with corrected user data and update the Auto Scaling group
C.Update the Auto Scaling group to use the latest launch configuration version
D.Delete and recreate the Auto Scaling group
AnswerB

This is the correct and standard procedure for updating instance launch parameters for an Auto Scaling group. First, a new launch configuration must be created, incorporating the corrected user data. Subsequently, the Auto Scaling group is updated to reference this newly created launch configuration. New instances launched by the Auto Scaling group will then utilize the updated user data, while existing instances remain unaffected until they are terminated and replaced.

Why this answer

Launch configurations are immutable — once created, they cannot be modified. To fix incorrect user data, the developer must create a new launch configuration with the corrected script and update the Auto Scaling group to reference it. Existing instances keep running with the old configuration, but new instances launched after the update will use the corrected user data and register successfully.

Exam trap

DVA-C02 often tests the immutability of launch configurations — candidates incorrectly assume they can be edited like launch template versions, or confuse the two services entirely.

How to eliminate wrong answers

Option A is wrong because launch configurations cannot be edited after creation; AWS explicitly makes them immutable to preserve versioning integrity. Option C is wrong because launch configurations don't have versions (unlike launch templates) — this option confuses launch configurations with launch templates, which do support versioning. Option D is wrong because deleting and recreating the Auto Scaling group is unnecessary and disruptive; updating the group's launch configuration reference is sufficient.

444
MCQmedium

A company is developing a serverless application using AWS Lambda and API Gateway. The application needs to process user uploads to Amazon S3. The Lambda function must be invoked asynchronously after an object is uploaded to an S3 bucket. Which configuration should the developer use to invoke the Lambda function?

A.Configure the S3 bucket to send events to Lambda by adding a Lambda trigger in the S3 bucket properties.
B.Configure the S3 bucket to send events to an Amazon SQS queue and have Lambda poll the queue.
C.Configure the S3 bucket to send events to Amazon CloudWatch Events and have CloudWatch invoke Lambda.
D.Configure the S3 bucket to send events to an Amazon API Gateway endpoint that triggers the Lambda function.
AnswerA

This is the most direct and efficient method. Amazon S3 natively supports event notifications, allowing you to configure a bucket to send events, such as s3:ObjectCreated:*, directly to an AWS Lambda function. When an object is uploaded, S3 asynchronously invokes the specified Lambda function, passing the event details as payload, which simplifies the architecture and minimizes latency. This setup requires granting S3 permissions to invoke the Lambda function.

Why this answer

S3 can directly invoke Lambda asynchronously via a bucket notification configuration. When an object is uploaded, S3 publishes an event to the Lambda service, which then executes the function without requiring any intermediary services. This is the simplest and most direct way to trigger a Lambda function from an S3 event.

Exam trap

The trap here is that candidates may overcomplicate the solution by introducing unnecessary intermediary services (like SQS or API Gateway) when the direct S3-to-Lambda trigger is the simplest and most appropriate asynchronous invocation method.

How to eliminate wrong answers

Option B is wrong because while S3 can send events to SQS and Lambda can poll the queue, this introduces unnecessary complexity and latency; the requirement is for asynchronous invocation, which S3-to-Lambda direct trigger already provides without an intermediary. Option C is wrong because S3 cannot send events directly to CloudWatch Events; S3 events can be sent to EventBridge (formerly CloudWatch Events) only via S3 Event Notifications configured for EventBridge, and even then, EventBridge would invoke Lambda, but this is not the standard or simplest configuration. Option D is wrong because routing S3 events through API Gateway adds an unnecessary HTTP layer and introduces potential latency and cost; API Gateway is designed for RESTful API endpoints, not for direct S3 event processing.

445
MCQeasy

A developer is deploying an application using AWS Elastic Beanstalk. The application needs to connect to an Amazon RDS database. What is the best practice for storing database credentials?

A.Hardcode the credentials in the application code.
B.Store credentials in Elastic Beanstalk environment properties.
C.Store credentials in an Amazon S3 bucket with public read access.
D.Store credentials in AWS Secrets Manager and retrieve them at runtime.
AnswerD

AWS Secrets Manager is the recommended and most secure service for storing and managing sensitive credentials. It encrypts secrets at rest and in transit, allows for automatic rotation of credentials, and provides fine-grained access control through AWS IAM policies, ensuring only authorized applications or services can retrieve them at runtime. This approach minimizes the exposure window and enhances the overall security posture by centralizing secret management.

Why this answer

AWS Secrets Manager provides a secure, auditable service for rotating and managing database credentials. By retrieving secrets at runtime via the AWS SDK, the application avoids embedding sensitive data in code or configuration, which is a key security best practice for Elastic Beanstalk deployments.

Exam trap

The trap here is that candidates often confuse Elastic Beanstalk environment properties with secure storage, not realizing they are stored in plaintext and accessible via the environment configuration, unlike Secrets Manager which provides encryption and rotation.

How to eliminate wrong answers

Option A is wrong because hardcoding credentials in application code exposes them in version control and static analysis, violating the principle of least privilege and making rotation impossible without redeployment. Option B is wrong because Elastic Beanstalk environment properties are stored in plaintext in the environment configuration and can be viewed by anyone with access to the Elastic Beanstalk console or API, offering no encryption at rest or rotation capabilities. Option C is wrong because storing credentials in an S3 bucket with public read access exposes them to the entire internet, directly violating AWS security best practices and potentially leading to data breaches.

446
MCQhard

A developer is building a real-time chat application using Amazon API Gateway WebSocket APIs and AWS Lambda. The application needs to send messages to connected clients. The developer notices that the 'connectionId' changes every time a client reconnects. How should the developer store the mapping between user identity and connectionId?

A.Use Amazon ElastiCache to store the mapping in memory.
B.Use Amazon DynamoDB to store the mapping, with user identity as the partition key and connectionId as an attribute.
C.Use Amazon RDS to store the mapping in a relational database.
D.Use Amazon S3 to store the mapping as a JSON file.
AnswerB

Amazon DynamoDB is an excellent choice for storing real-time chat application mappings due to its consistent single-digit millisecond latency at any scale. By using the user identity as the partition key, the application can efficiently retrieve the associated connectionId for message routing with high throughput. Its fully managed, highly available, and durable nature ensures the mapping data is always accessible and resilient to failures, making it ideal for critical, frequently accessed application state.

Why this answer

Amazon DynamoDB is the recommended, fully managed, serverless key-value store for persisting WebSocket connection IDs in AWS. It offers single-digit millisecond latency, scales automatically, and integrates seamlessly with AWS Lambda without requiring VPC configuration (unlike Amazon ElastiCache, which typically requires a VPC, adding setup complexity and potential latency for Lambda functions).

Exam trap

Candidates often think of Amazon ElastiCache (Redis/Memcached) first for low-latency key-value storage. However, for serverless WebSocket applications, DynamoDB is the preferred choice because it is fully serverless, does not require VPC placement for the Lambda function (which ElastiCache typically does, increasing complexity and cold start times), and easily handles the rapid read/write patterns of connection mappings at a lower cost.

How to eliminate wrong answers

Option A is wrong because Amazon ElastiCache is an in-memory cache that does not provide data durability; if the cache is restarted or scaled, the mapping is lost, and it requires additional infrastructure management. Option C is wrong because Amazon RDS is a relational database that introduces unnecessary schema complexity, higher latency for simple key-value lookups, and requires connection pooling, which is overkill for storing a simple mapping. Option D is wrong because Amazon S3 is an object store designed for large, infrequently accessed data; storing and retrieving individual mappings as JSON files would introduce high latency and is not suitable for real-time, per-request lookups.

447
MCQmedium

A company uses an S3 bucket to store sensitive customer data. The bucket policy currently allows access to a specific IAM role used by an EC2 instance. A security audit reveals that the bucket is also accessible from an external AWS account. Which action should the security team take to restrict access to only the intended role?

A.Use S3 Object Ownership to disable ACLs.
B.Enable S3 Block Public Access on the bucket.
C.Modify the IAM role trust policy to only allow the EC2 instance.
D.Add a condition in the bucket policy to allow access only when the request includes the specific IAM role ARN.
AnswerD

Adding a condition in the S3 bucket policy is the precise method for restricting access to a specific IAM role. By utilizing a condition key like `aws:PrincipalArn` or `aws:SourceArn` within the bucket policy's `Condition` block, you can ensure that S3 operations are permitted only when the requesting principal's ARN matches the specified IAM role. This directly enforces the principle of least privilege by granting access exclusively to the intended role, even across accounts.

Why this answer

Adding a condition in the bucket policy using the `aws:PrincipalArn` condition key allows you to restrict access exclusively to the specific IAM role ARN. This ensures that even if the bucket policy grants access to an external AWS account, only requests made by the designated IAM role (e.g., `arn:aws:iam::123456789012:role/EC2AppRole`) will be allowed, effectively blocking any other principals, including those from external accounts.

Exam trap

The trap here is that candidates often confuse IAM role trust policies with resource-based policies (like S3 bucket policies), thinking that modifying the trust policy will control access to the bucket, when in fact the bucket policy itself must explicitly restrict the principal.

How to eliminate wrong answers

Option A is wrong because disabling ACLs via S3 Object Ownership does not restrict access based on IAM roles or external accounts; it only controls whether ACLs are used to manage permissions, not the bucket policy or IAM policies. Option B is wrong because S3 Block Public Access only prevents public (anonymous or authenticated AWS users) access, but the external AWS account is a trusted AWS principal, not a public user, so Block Public Access would not block that access. Option C is wrong because the IAM role trust policy controls which entities can assume the role, not which principals can access the S3 bucket; the bucket policy must be modified to restrict access to the role.

448
MCQmedium

A developer is using AWS Elastic Beanstalk to deploy a web application. The application requires a highly available environment across multiple Availability Zones. The developer wants to update the application without any downtime while minimizing the number of new instances launched. Which deployment policy should the developer use?

A.All at once
B.Rolling
C.Rolling with additional batch
D.Immutable
AnswerC

Rolling with additional batch maintains full capacity by launching a new batch before terminating old instances, keeping the environment highly available across Availability Zones. It updates without downtime while launching fewer extra instances than immutable or blue/green.

Why this answer

(Rolling with additional batch) is correct because it launches a new batch of instances before taking the old ones out of service, ensuring full capacity is maintained during the deployment. This provides high availability across multiple Availability Zones while minimizing the number of new instances compared to an immutable deployment, which would double the instance count. The additional batch absorbs the traffic during the rolling update, preventing any downtime.

Exam trap

The trap here is that candidates confuse 'Rolling' with 'Rolling with additional batch', assuming both provide zero downtime, but only the latter guarantees full capacity throughout the update by adding an extra batch to absorb traffic.

How to eliminate wrong answers

Option A is wrong because 'All at once' deploys the new version to all instances simultaneously, causing downtime as all instances are replaced at the same time. Option B is wrong because 'Rolling' updates instances in batches without an extra batch, which reduces capacity during the update and can lead to downtime if the application cannot handle reduced load. Option D is wrong because 'Immutable' launches a completely new set of instances in a new Auto Scaling group, then swaps the environment, which minimizes downtime but launches the maximum number of new instances (doubling the count), contradicting the requirement to minimize new instances.

449
MCQeasy

A developer is troubleshooting a slow-running query in Amazon RDS for MySQL. The query is used by a reporting dashboard. Which AWS service should the developer use to identify the bottleneck?

A.AWS X-Ray
B.AWS CloudTrail
C.Amazon RDS Performance Insights
D.Amazon CloudWatch Logs
AnswerC

Amazon RDS Performance Insights is a purpose-built monitoring tool that provides a visual dashboard to analyze database performance by focusing on active sessions and wait events. It aggregates and displays key metrics, allowing developers to quickly identify the top SQL queries, users, hosts, or wait types that are consuming database resources. This granular, real-time insight is specifically designed for troubleshooting and optimizing slow-running queries within Amazon RDS databases.

Why this answer

Amazon RDS Performance Insights provides a detailed analysis of database performance, including wait events and SQL query performance, helping identify bottlenecks.

450
MCQeasy

A developer is creating an AWS Lambda function to process events from an Amazon SQS queue. The function must process each message exactly once and in order. Which SQS queue type should the developer use?

A.Standard queue.
B.FIFO queue.
C.Dead-letter queue.
D.Delay queue.
AnswerB

Amazon SQS FIFO (First-In-First-Out) queues are designed to guarantee message ordering and exactly-once processing. They ensure that messages are processed in the exact order they are sent and prevent duplicates from being delivered to the consumer, thanks to message deduplication IDs and message group IDs. This makes FIFO queues ideal for applications where the sequence of operations and the prevention of duplicate processing are critical for data integrity.

Why this answer

FIFO queue. FIFO (First-In-First-Out) queues guarantee exactly-once processing and preserve the order of messages, which is required by the use case. Standard queues offer at-least-once delivery and do not guarantee order, making them unsuitable for this requirement.

Exam trap

The trap here is that candidates often confuse the 'exactly-once' and 'in-order' requirements with Standard queues, assuming they can achieve this with idempotent processing, but Standard queues explicitly do not guarantee order and can deliver duplicates.

How to eliminate wrong answers

Option A is wrong because Standard queues provide at-least-once delivery, meaning a message can be delivered more than once, and they do not guarantee message order. Option C is wrong because a Dead-letter queue is not a primary queue type; it is a secondary queue used to store messages that failed processing, not to process events in order with exactly-once semantics. Option D is wrong because a Delay queue is a feature of both Standard and FIFO queues that introduces a message delivery delay, but it does not provide exactly-once processing or ordering guarantees.

Page 5

Page 6 of 16

Page 7