Courseiva

AWS Certified Developer Associate DVA-C02 (DVA-C02) — Questions 451–525

1135 questions total · 16pages · All types, answers revealed

Page 6

Page 7 of 16

Page 8
451
MCQeasy

A developer is building a serverless application using AWS Lambda to process files uploaded to an S3 bucket. The Lambda function needs to read the uploaded file, transform it, and write the result to a DynamoDB table. Which IAM policy statement should be attached to the Lambda execution role?

A.{"Effect":"Allow","Action":["s3:GetObject","dynamodb:PutItem"],"Resource":"*"}
B.{"Effect":"Allow","Action":["s3:PutObject","dynamodb:PutItem"],"Resource":"*"}
C.{"Effect":"Allow","Action":["s3:GetObject","dynamodb:UpdateItem"],"Resource":"*"}
D.{"Effect":"Allow","Action":["s3:GetObject","dynamodb:GetItem"],"Resource":"*"}
AnswerA

s3:GetObject correctly grants permission to download the uploaded file's bytes from the S3 bucket for processing, and dynamodb:PutItem correctly grants permission to insert or overwrite the transformed result as a new item, which matches the function's actual read-from-S3, write-to-DynamoDB data flow exactly.

Why this answer

The Lambda function needs to read the uploaded file from S3 (requiring s3:GetObject) and write the transformed result to DynamoDB (requiring dynamodb:PutItem). Option A correctly grants both actions with a wildcard resource, which is acceptable for a learning scenario but should be scoped in production. This matches the exact permissions needed for the described workflow.

Exam trap

The trap here is confusing the direction of data flow: candidates mistakenly choose write permissions for S3 (s3:PutObject) or read permissions for DynamoDB (dynamodb:GetItem), failing to map the correct action to each service based on whether data is being read from or written to that service.

How to eliminate wrong answers

Option B is wrong because it grants s3:PutObject (write to S3) instead of s3:GetObject (read from S3); the Lambda only reads the uploaded file, not writes back to S3. Option C is wrong because it grants dynamodb:UpdateItem (modify an existing item) instead of dynamodb:PutItem (create a new item); the requirement is to write the result, which implies inserting a new record, not updating an existing one. Option D is wrong because it grants dynamodb:GetItem (read from DynamoDB) instead of dynamodb:PutItem; the Lambda writes to DynamoDB, not reads from it.

452
MCQhard

A development team is building a real-time chat application using Amazon API Gateway WebSocket APIs and AWS Lambda. The application needs to maintain a connection to each user and broadcast messages to all connected clients. Which approach should the developer use to scale the application efficiently?

A.Store connection IDs in Amazon DynamoDB and use the API Gateway Management API to send messages to all connections.
B.Use Amazon ElastiCache to cache connection IDs and have Lambda send messages using the Redis pub/sub feature.
C.Use Amazon SNS to publish messages to all connected clients via the WebSocket API.
D.Use Amazon SQS to queue messages and have Lambda poll the queue to send messages to all connections.
AnswerA

This is the correct and standard architectural pattern for serverless WebSocket applications on AWS. When a client connects, API Gateway invokes an onConnect Lambda function which stores the unique connectionId in a DynamoDB table. To send a message to all connected clients, a backend service (e.g., another Lambda function) retrieves all active connectionId's from DynamoDB and then iteratively calls the API Gateway Management API's postToConnection action for each ID, pushing the message directly to the client.

Why this answer

DynamoDB provides a scalable, serverless key-value store to persist WebSocket connection IDs, and the API Gateway Management API allows Lambda to send messages directly to any connected client via its connection ID. This combination efficiently handles the broadcast requirement without managing infrastructure, as Lambda can iterate over stored connection IDs and call the Management API for each message.

Exam trap

The trap here is that candidates may confuse the pub/sub or queuing services (SNS, SQS, ElastiCache) as direct communication channels to WebSocket clients, overlooking that API Gateway requires the Management API for server-to-client messaging and that DynamoDB is the simplest way to store and retrieve connection IDs at scale.

How to eliminate wrong answers

Option B is wrong because ElastiCache with Redis pub/sub is designed for decoupled messaging between services, not for directly sending messages to WebSocket clients via API Gateway; it would require additional custom logic to map Redis channels to connection IDs and invoke the Management API. Option C is wrong because Amazon SNS is a pub/sub notification service that pushes messages to endpoints like HTTP/S, email, or Lambda, but it cannot directly send messages to WebSocket connections managed by API Gateway. Option D is wrong because Amazon SQS is a message queue that decouples producers and consumers, but it does not provide a mechanism to send messages to WebSocket clients; Lambda would still need to poll the queue and use the Management API, adding latency and complexity without benefit for real-time broadcasting.

453
MCQmedium

A company runs a batch processing job on Amazon ECS using Fargate. The job processes files from an S3 bucket and writes results to another S3 bucket. The job runs once per day and takes about 30 minutes. The company wants to reduce costs by stopping the ECS service when not in use. Which solution should the developer implement?

A.Use an AWS Lambda function to run the job and configure a scheduled event in Amazon EventBridge.
B.Use AWS Batch with a Fargate launch type and schedule the job with Amazon EventBridge.
C.Use Amazon ECS Service Auto Scaling to scale the service down to zero tasks when not in use.
D.Use an Amazon EC2 Auto Scaling group to launch an instance, run the job, and then terminate.
AnswerB

AWS Batch is specifically designed for running batch computing workloads, efficiently managing job queues, compute environments, and job execution. Utilizing the Fargate launch type eliminates the need to provision and manage EC2 instances, providing a serverless experience where resources are automatically provisioned and scaled down to zero when jobs are not running. Scheduling the job with Amazon EventBridge ensures reliable, time-based invocation of the batch process, making this a robust, serverless, and cost-effective solution for a 30-minute batch job.

Why this answer

AWS Batch with a Fargate launch type is the ideal solution because it is purpose-built for batch processing jobs that run to completion. By scheduling the job with Amazon EventBridge, you can trigger the job once per day, and AWS Batch automatically provisions the Fargate compute environment only when the job runs, then scales down to zero after completion—eliminating costs during idle periods. This approach directly addresses the requirement to reduce costs by stopping the ECS service when not in use, without manual intervention.

Exam trap

The trap here is that candidates often confuse ECS Service Auto Scaling with AWS Batch's job-based scaling; while ECS can scale to zero tasks, it does not automatically manage job completion and termination, leading to residual costs and complexity, whereas AWS Batch is designed for exactly this use case.

How to eliminate wrong answers

Option A is wrong because while a Lambda function could process files from S3, it has a maximum execution timeout of 15 minutes, which is insufficient for a job that takes about 30 minutes, and it cannot directly write results to another S3 bucket in the same manner as a batch job. Option C is wrong because Amazon ECS Service Auto Scaling can scale the desired count to zero, but it does not automatically stop the service after the job completes; the service remains defined and incurs costs for the Fargate infrastructure even at zero tasks (e.g., load balancer or network costs), and it lacks native job scheduling and lifecycle management for batch workloads. Option D is wrong because using an EC2 Auto Scaling group to launch an instance for a 30-minute job is inefficient; it requires managing the instance lifecycle, patching, and termination, and incurs costs for the running instance and associated resources, whereas Fargate with AWS Batch provides a serverless, cost-effective alternative that scales to zero automatically.

454
MCQeasy

A developer is deploying a containerized application on Amazon ECS using Fargate. The application needs to store sensitive configuration data, including database passwords, that must be rotated regularly. Which service should the developer use to manage these secrets securely?

A.Amazon S3 with server-side encryption
B.AWS Secrets Manager
C.Amazon DynamoDB with server-side encryption
D.AWS Systems Manager Parameter Store
AnswerB

AWS Secrets Manager stores the database passwords and supports automatic rotation through Lambda rotation functions, meeting the regular-rotation requirement. ECS Fargate tasks retrieve secrets at launch via the secrets parameter, so credentials never persist in task definitions or images.

Why this answer

AWS Secrets Manager is the correct choice because it is purpose-built for securely storing, retrieving, and automatically rotating sensitive configuration data such as database passwords. It integrates natively with Amazon ECS (via the `secrets` container definition parameter) and supports automatic rotation using AWS Lambda, which meets the requirement for regular rotation without custom code.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (which can store secrets but lacks native rotation) with AWS Secrets Manager, overlooking the explicit requirement for 'regular rotation' in the question.

How to eliminate wrong answers

Option A is wrong because Amazon S3 with server-side encryption provides static encryption at rest but lacks native secret rotation capabilities and does not integrate directly with ECS task definitions for injecting secrets as environment variables. Option C is wrong because Amazon DynamoDB with server-side encryption is a NoSQL database service designed for high-performance data storage, not for managing secrets with built-in rotation or fine-grained access control for secret lifecycle management. Option D is wrong because AWS Systems Manager Parameter Store can store secrets (using SecureString parameters) but does not support automatic rotation of secrets; it requires custom automation to rotate values, whereas the question explicitly requires regular rotation.

455
MCQhard

A company uses AWS CodeCommit for source control. A developer needs to automate the build and test process for every commit to the 'develop' branch. The developer creates a CodeBuild project and wants to trigger it automatically. What is the most efficient way to set up this automation?

A.Create a CloudWatch Events rule that triggers CodeBuild on code commit events
B.Configure a webhook in CodeCommit to call CodeBuild directly
C.Create a CodePipeline with a source stage from CodeCommit and a build stage from CodeBuild
D.Use an SQS queue to receive SNS notifications from CodeCommit and trigger CodeBuild
AnswerC

Creating an AWS CodePipeline with CodeCommit as the source stage and CodeBuild as the build stage is the most appropriate and recommended solution. CodePipeline is purpose-built for continuous integration and continuous delivery (CI/CD) workflows, offering seamless, native integration between these services. It automatically detects changes in the CodeCommit repository, orchestrates the build process in CodeBuild, and manages artifact passing between stages, providing a fully automated and efficient pipeline.

Why this answer

AWS CodePipeline is the most efficient and fully managed way to orchestrate a continuous integration workflow. It natively integrates CodeCommit as a source action that automatically detects changes on the specified branch (e.g., 'develop') and triggers a CodeBuild build stage without any custom scripting or additional infrastructure. This provides built-in retry, status tracking, and seamless integration with other AWS services.

Exam trap

The trap here is that candidates may overcomplicate the solution by considering event-driven services like CloudWatch Events or SQS, when the simplest and most efficient approach is to use CodePipeline's native source-to-build integration, which is purpose-built for this exact scenario.

How to eliminate wrong answers

Option A is wrong because CloudWatch Events (now Amazon EventBridge) can trigger CodeBuild on CodeCommit events, but this requires creating a custom event rule and does not provide the native pipeline orchestration, artifact handling, or stage sequencing that CodePipeline offers; it is less efficient and more manual to maintain. Option B is wrong because CodeCommit does not support configuring webhooks to directly call CodeBuild; webhooks are typically used with third-party Git providers (e.g., GitHub, Bitbucket) and CodeCommit uses repository triggers that can invoke AWS Lambda or SNS, not directly call CodeBuild. Option D is wrong because using an SQS queue to receive SNS notifications from CodeCommit and then triggering CodeBuild adds unnecessary complexity and latency; it requires setting up SNS, SQS, and a custom polling mechanism, which is far less efficient than the native integration provided by CodePipeline.

456
MCQhard

A developer runs the AWS CLI command shown. The Lambda function returns a 200 status code but the output file is null and the response includes FunctionError: Unhandled. What does this indicate?

A.The Lambda function timed out.
B.The Lambda function threw an unhandled exception.
C.The payload was too large for synchronous invocation.
D.The Lambda function was not found.
AnswerB

When a Lambda function throws an unhandled exception, the Lambda service captures this error and returns a 200 OK HTTP status code to the invoker, but includes a special X-Amz-Function-Error header with the value Unhandled. This header explicitly indicates that the function's execution failed due to an exception that was not caught and handled within the function's code, even though the invocation request itself was successfully received and processed by the Lambda service.

Why this answer

The presence of `FunctionError: Unhandled` in the response of an `aws lambda invoke` command indicates that the Lambda function encountered an error (such as an unhandled exception or runtime crash) that was not caught by the function's code. Even though the function failed, the Invoke API itself successfully completed the transaction of invoking the function, which is why it returns an HTTP status code of 200.

Exam trap

The trap here is that candidates often assume a 200 status code means success, but AWS Lambda's synchronous invocation returns HTTP 200 even for function errors, with the `FunctionError` field distinguishing success from failure.

How to eliminate wrong answers

Option A is wrong because a timeout would produce a `FunctionError: Unhandled` only if the timeout exception itself is unhandled, but the specific error message for a timeout is `Task timed out after X seconds` and the response would include a `StatusCode` of 200 with `FunctionError: Unhandled` only if the runtime throws an unhandled exception after the timeout; however, the question states the output file is null and the response includes `FunctionError: Unhandled`, which directly matches an unhandled exception, not a timeout. Option C is wrong because the payload size limit for synchronous invocation is 6 MB, and exceeding it would result in a `413 Request Entity Too Large` error or a `PayloadTooLarge` exception, not a 200 status code with `FunctionError: Unhandled`. Option D is wrong because if the Lambda function were not found, the AWS CLI command would return a `ResourceNotFoundException` error with a 404 status code, not a 200 status code.

457
MCQmedium

A developer is using AWS SAM to define a serverless application. The application includes an AWS Lambda function and an Amazon API Gateway REST API. The developer wants to configure the API Gateway stage to enable logging and set the stage name based on the SAM parameter Stage. In the SAM template, which property of the AWS::Serverless::Api resource should the developer use to set the stage name?

A.StageName
B.DefinitionBody
C.StageDescription
D.EndpointConfiguration
AnswerA

The StageName property within an AWS::Serverless::Api resource in AWS SAM is precisely what defines the name of the Amazon API Gateway deployment stage. This critical property allows developers to specify a logical identifier for a particular deployment, such as Prod, Dev, or Test, which is essential for managing different environments. It frequently leverages SAM parameters, like !Ref Stage, enabling dynamic stage naming based on deployment inputs, ensuring flexibility and reusability across various CI/CD pipelines.

Why this answer

The `StageName` property of the `AWS::Serverless::Api` resource directly sets the stage name for the API Gateway REST API. By using a SAM parameter like `Stage` (e.g., `StageName: !Ref Stage`), the developer can dynamically control the stage name at deployment time. This is the intended and simplest way to configure the stage name in an AWS SAM template.

Exam trap

The trap here is that candidates confuse `StageName` with `StageDescription` (Option C) because both relate to stage configuration, but `StageDescription` only provides metadata and does not control the actual stage identifier used in the API endpoint URL.

How to eliminate wrong answers

Option B (`DefinitionBody`) is wrong because it defines the OpenAPI specification for the API, not the stage name; it can include a `stageName` field within the OpenAPI definition, but that is not the SAM-level property for setting the stage name. Option C (`StageDescription`) is wrong because it provides a description of the stage (e.g., for documentation or tagging), not the stage name itself. Option D (`EndpointConfiguration`) is wrong because it specifies the endpoint type (e.g., REGIONAL, EDGE, PRIVATE) for the API, not the stage name.

458
MCQmedium

A company has a DynamoDB table that stores order data. The table has a partition key of OrderID and a sort key of OrderDate. The company frequently queries orders by CustomerID, which is not a key attribute. The queries are slow and consume a lot of read capacity. Which design change would MOST improve query performance?

A.Increase the provisioned read capacity for the table.
B.Create a Global Secondary Index (GSI) with CustomerID as the partition key.
C.Change the table's primary key to use CustomerID as the partition key.
D.Use a FilterExpression on the CustomerID attribute in a Scan operation.
AnswerB

Creating a Global Secondary Index (GSI) with `CustomerID` as its partition key is the most effective solution for efficiently querying items based on `CustomerID`. A GSI stores a copy of a subset of the base table's attributes, indexed by its own primary key (in this case, `CustomerID`). This allows `Query` operations to directly access items matching a specific `CustomerID` without scanning the entire base table, significantly improving performance and reducing cost for targeted lookups.

Why this answer

Creating a Global Secondary Index (GSI) with CustomerID as the partition key allows DynamoDB to efficiently query orders by CustomerID using the index's key structure, avoiding full table scans. This directly addresses the slow performance and high read capacity consumption by enabling targeted lookups instead of scanning all items and filtering.

Exam trap

The trap here is that candidates often think increasing provisioned capacity (Option A) or using FilterExpression (Option D) will fix performance, but they fail to recognize that these do not change the underlying inefficient data access pattern of scanning all items.

How to eliminate wrong answers

Option A is wrong because increasing provisioned read capacity only adds more throughput capacity but does not change the underlying query pattern; the query still performs a full Scan or inefficient query, so it would still be slow and consume more capacity units. Option C is wrong because changing the table's primary key to CustomerID would break existing access patterns that rely on OrderID as the partition key, and it would not support queries by OrderID without a separate index. Option D is wrong because using a FilterExpression on a Scan operation still reads every item in the table, consuming the same amount of read capacity and providing no performance improvement; FilterExpressions only reduce the data returned, not the data read.

459
MCQhard

A developer is troubleshooting an AWS Lambda function that is invoked from an Amazon S3 bucket via event notifications. The function processes images and stores metadata in Amazon DynamoDB. The developer notices that some images are being processed multiple times, resulting in duplicate entries in DynamoDB. The S3 event notification is configured to send events to the Lambda function with the 's3:ObjectCreated:*' event type. The function uses the 'uuid' library to generate a unique ID for each image upon processing. What is the most likely cause of the duplicate processing?

A.S3 event notifications are delivered at least once, and the Lambda function is not idempotent.
B.The Lambda function's concurrency is set too high, causing race conditions.
C.The DynamoDB table does not have a primary key that prevents duplicates.
D.The S3 bucket is configured with versioning, causing multiple object creation events.
AnswerA

S3 event notifications operate on an "at least once" delivery model, meaning that a single S3 event, such as an object creation, might trigger the associated Lambda function multiple times. If the Lambda function's logic is not designed to be idempotent, each duplicate invocation will independently process the event and perform its side effects, leading to duplicate data entries or actions. Implementing idempotency, often by using a unique identifier from the S3 event (like the object key) as a check, is crucial to prevent these redundant operations.

Why this answer

Amazon S3 event notifications are delivered on an 'at least once' basis, meaning the same event can be sent to Lambda multiple times. If the Lambda function is not idempotent—i.e., processing the same event multiple times produces duplicate side effects—then duplicate DynamoDB entries will occur. The use of a 'uuid' library inside the function does not help because a new UUID is generated on each invocation, so the same image gets different IDs and is stored as a separate item each time.

Exam trap

The trap here is that candidates assume generating a unique ID inside the function solves duplication, but they miss that idempotency requires using a stable, external identifier (like the S3 object key) to detect and skip already-processed events.

How to eliminate wrong answers

Option B is wrong because high concurrency can cause race conditions, but the core issue here is duplicate event delivery, not concurrent writes; even with low concurrency, duplicate events would still be processed. Option C is wrong because the DynamoDB table's primary key design does not cause duplicate processing; it only affects whether duplicate writes are rejected or overwritten—the problem is that the function is invoked multiple times for the same image. Option D is wrong because S3 versioning generates separate object versions, each with a unique version ID, and the 's3:ObjectCreated:*' event fires once per version; versioning does not cause multiple events for the same object version.

460
MCQhard

An ECS blue/green deployment with CodeDeploy and an Application Load Balancer fails because the replacement task set never receives test traffic. Which configuration should be checked?

A.S3 bucket versioning
B.Lambda provisioned concurrency
C.The test listener and target group mapping in the deployment group
D.DynamoDB TTL
AnswerC

In an AWS CodeDeploy Blue/Green deployment for Amazon ECS, the test listener and its mapping to a new target group are fundamental for validating the new task set (the 'green' environment). CodeDeploy uses this listener to route a small amount of traffic, or traffic from a specific test client, to the new target group associated with the updated application tasks. This crucial step allows for pre-validation and ensures the new application version is healthy and functional before the final production traffic cutover, enabling safe rollouts and easy rollbacks.

Why this answer

In an ECS blue/green deployment with CodeDeploy and an Application Load Balancer, the test listener and its associated target group are responsible for routing test traffic to the replacement task set. If the replacement task set never receives test traffic, the most likely cause is that the test listener is not correctly mapped to the target group in the CodeDeploy deployment group configuration. This mapping ensures that traffic from the test listener is directed to the replacement task set during the deployment lifecycle.

Exam trap

The trap here is that candidates may confuse the test listener with the production listener or assume the issue is with the ALB itself, rather than recognizing that the test listener-to-target-group mapping in the CodeDeploy deployment group is the specific configuration that controls test traffic routing.

How to eliminate wrong answers

Option A is wrong because S3 bucket versioning is unrelated to ECS deployment traffic routing; it is used for object version control and rollback in S3, not for CodeDeploy traffic routing. Option B is wrong because Lambda provisioned concurrency is a feature for managing concurrent execution capacity of Lambda functions, not for ECS task set traffic routing in blue/green deployments. Option D is wrong because DynamoDB TTL (Time to Live) is a feature for automatically expiring items in DynamoDB tables, and it has no role in CodeDeploy or ALB traffic routing.

461
MCQhard

Refer to the exhibit. A developer runs an AWS CLI command on an EC2 instance and receives the error shown. The instance has an IAM role attached with the necessary permissions. What is the most likely cause of this error?

A.The CLI command is not supported on EC2 instances.
B.The CLI is not configured to use the instance profile credentials; environment variables or config file might be overriding.
C.The IAM role does not have the required permissions for the CLI command.
D.The instance does not have an IAM role attached.
AnswerB

This option correctly identifies a common troubleshooting scenario. The AWS CLI follows a specific credential resolution order, where environment variables (e.g., AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY) and entries in the ~/.aws/credentials file take precedence over instance profile credentials. If explicit, but invalid or incomplete, credentials are set in these higher-priority locations, the CLI will attempt to use them first and fail with a "missing credentials" error, even if a valid instance profile is attached to the EC2 instance.

Why this answer

The error indicates that the AWS CLI cannot find credentials. Even though the EC2 instance has an IAM role attached, the CLI will not automatically use instance profile credentials if environment variables (e.g., AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY) or a config file (e.g., ~/.aws/credentials) are present with different or invalid values. The CLI's credential provider chain checks environment variables first, then the config file, and only falls back to the instance metadata service (IMDS) if no other credentials are found.

Therefore, overriding settings are the most likely cause.

Exam trap

The trap here is that candidates assume the IAM role is automatically used by the CLI, but they overlook that environment variables or a local AWS credentials file can override the instance profile credentials, causing a 'Unable to locate credentials' error even when the role is correctly attached.

How to eliminate wrong answers

Option A is wrong because the AWS CLI is fully supported on EC2 instances and can run any command the instance's IAM role permits. Option C is wrong because the error message explicitly states 'Unable to locate credentials,' not a permissions error; if the role lacked permissions, the error would be 'AccessDenied' or similar. Option D is wrong because the question states the instance has an IAM role attached, so the role exists; the issue is that the CLI is not using it.

462
MCQhard

An application running on EC2 needs to access an S3 bucket. The developer has assigned an IAM role to the EC2 instance with a policy that allows s3:GetObject on the bucket. However, the application is still getting access denied errors. What should the developer check?

A.Check that the application is using HTTPS instead of HTTP.
B.Check the S3 bucket policy for an explicit deny statement that applies to the IAM role.
C.Check that the EC2 instance has permissions to decrypt the KMS key used by S3.
D.Check that the EC2 instance is in the same VPC as the S3 bucket.
AnswerB

AWS IAM policy evaluation logic dictates that an explicit deny statement always overrides any allow statements, regardless of where they are defined. If the S3 bucket policy contains an explicit deny that matches the EC2 instance's IAM role or the request's attributes, access will be blocked. This powerful mechanism ensures that specific access restrictions are enforced even if broader permissions are granted elsewhere, making it a critical check.

Why this answer

Even if the IAM role attached to the EC2 instance allows s3:GetObject, an S3 bucket policy with an explicit deny statement that applies to that role will override the allow. IAM policy evaluation logic dictates that an explicit deny in any policy (resource-based or identity-based) takes precedence over any allow, resulting in access denied errors.

Exam trap

The trap here is that candidates assume an IAM role with an allow policy is sufficient, overlooking that S3 bucket policies can contain explicit deny statements that override the role's permissions.

How to eliminate wrong answers

Option A is wrong because S3 supports both HTTP and HTTPS, and using HTTP does not cause access denied errors; HTTPS is recommended for encryption in transit but not a requirement for authorization. Option C is wrong because the question does not mention S3 server-side encryption with KMS, and without a KMS key being used, KMS permissions are irrelevant to the access denied error. Option D is wrong because S3 buckets are global resources and do not reside in a VPC; EC2 instances can access S3 over the internet or via a VPC endpoint, but being in the same VPC is not a requirement for access.

463
Multi-Selectmedium

A company uses AWS Elastic Beanstalk to deploy a web application. The application uses an Amazon RDS database. The developer wants to ensure that the database connection string is not hard-coded in the application code. Which THREE methods can the developer use to pass the connection string securely? (Choose THREE.)

Select 3 answers
A.Read the connection string from Amazon RDS tags.
B.Use AWS Secrets Manager.
C.Use Elastic Beanstalk environment properties.
D.Store the connection string in a configuration file in the application bundle.
E.Use AWS Systems Manager Parameter Store.
AnswersB, C, E

AWS Secrets Manager is purpose-built for this task: it stores the connection string as a secret encrypted by a KMS key, provides fine-grained access control through IAM policies, and natively supports automatic rotation for Amazon RDS credentials. The application can retrieve the secret at runtime using the AWS SDK, and you can even integrate it with Elastic Beanstalk via a custom resource or startup script. This minimizes human exposure and lets you change credentials without rebuilding or redeploying the application.

Why this answer

Option B is correct because AWS Secrets Manager is purpose-built to store and retrieve secrets such as database connection strings, supporting encryption at rest with KMS and fine-grained access via IAM, so the application can fetch the string at runtime instead of hard-coding it. Option C is correct because Elastic Beanstalk environment properties are injected into the application as environment variables (for example, RDS_HOSTNAME, RDS_USERNAME, RDS_PASSWORD that Beanstalk itself sets for attached RDS instances), letting the code read the connection string from the environment rather than embedding it. Option E is correct because AWS Systems Manager Parameter Store can hold the connection string as a SecureString parameter encrypted with KMS, and the application can retrieve it via the SSM API or the EC2/Beanstalk instance role.

Option A is not appropriate because RDS tags are metadata for resource organization, cost allocation, and access control, not a secure mechanism for delivering secrets to an application. Option D is not appropriate because a configuration file inside the application bundle is still effectively hard-coded and travels with the source artifact, so it does not securely externalize the connection string.

Exam trap

DVA-C02 often tests the difference between secure secret storage (Secrets Manager, Parameter Store) and insecure embedding (config files, tags) — the trap is picking a config file because it 'isn't in the code' even though it is still in the deployment bundle.

464
MCQeasy

A developer wants to upload a large file (5 GB) to an Amazon S3 bucket using the AWS SDK. Which approach is MOST efficient and resilient?

A.Generate a presigned URL and use a third-party tool to upload.
B.Invoke an AWS Lambda function to upload the file.
C.Use the Multipart Upload API to upload the file in parts.
D.Use the PutObject API call with the entire file.
AnswerC

The Amazon S3 Multipart Upload API is the recommended and most efficient method for uploading large objects, specifically designed for files up to 5 TB. It allows a 5 GB file to be broken into smaller, independently uploaded parts, significantly improving throughput and resilience. This approach enables parallel uploads, easy resumption of failed parts, and enhanced fault tolerance against network issues, making it ideal for this scenario.

Why this answer

The Multipart Upload API is specifically designed for large objects (over 100 MB, recommended for 5 GB). It allows uploading a file in parallel parts, which improves throughput and resilience by enabling retries of individual failed parts without restarting the entire upload. This approach also supports pausing and resuming uploads, making it the most efficient and resilient method for a 5 GB file.

Exam trap

The trap here is that candidates may assume the PutObject API (Option D) is sufficient for large files because it supports up to 5 GB, but they overlook the lack of parallel uploads and partial failure recovery, which the Multipart Upload API provides and is explicitly recommended by AWS for files over 100 MB.

How to eliminate wrong answers

Option A is wrong because generating a presigned URL delegates the upload to a third-party tool, which introduces external dependencies and does not inherently provide the parallel upload or retry capabilities of the Multipart Upload API, reducing resilience and control. Option B is wrong because invoking an AWS Lambda function to upload the file is inefficient; Lambda has a maximum execution timeout of 15 minutes and a deployment package size limit of 250 MB (unzipped), making it unsuitable for handling a 5 GB upload directly, and it adds unnecessary complexity and latency. Option D is wrong because the PutObject API call has a maximum object size limit of 5 GB in a single PUT operation, but it does not support parallel uploads or partial retries; if the upload fails, the entire file must be re-uploaded, making it less resilient and efficient for large files compared to Multipart Upload.

465
MCQeasy

A developer has an Amazon S3 bucket containing private user documents. The application must generate a time-limited URL for users to download their own documents without requiring the users to have AWS credentials. Which solution should the developer use?

A.Use CloudFront signed URLs with an origin access identity (OAI) to restrict access to the S3 bucket.
B.Create a pre-signed URL for each object using the AWS SDK with an appropriate expiration time.
C.Set a bucket policy that allows public read access for the specific users based on their IP addresses.
D.Provide the users with IAM user credentials that have read access to the bucket.
AnswerB

Creating a pre-signed URL for each object using the AWS SDK is the most secure and efficient method for granting temporary access to private S3 objects. This URL, generated with the developer's AWS credentials and a specified expiration time, allows any recipient to perform a specific action (e.g., GET) on the object directly from S3 without needing their own AWS credentials. It provides granular, time-limited access, perfectly aligning with the need for secure access to private user documents.

Why this answer

Pre-signed URLs allow temporary, time-limited access to private S3 objects without requiring the user to have AWS credentials. The developer generates the URL server-side using the AWS SDK, embedding an expiration time, and the user can download the object directly via HTTP GET. This meets the requirement of granting ephemeral access to specific documents for unauthenticated users.

Exam trap

The trap here is that candidates often confuse pre-signed URLs with CloudFront signed URLs, thinking the CDN is required for time-limited access, but pre-signed URLs work directly with S3 and are simpler for single-object, time-limited downloads without needing CloudFront.

How to eliminate wrong answers

Option A is wrong because CloudFront signed URLs with OAI are used to control access at the CDN edge, but they still require the developer to manage CloudFront distributions and signing keys; the question asks for a simpler, direct S3 solution without requiring users to have AWS credentials. Option C is wrong because setting a bucket policy for public read access based on IP addresses would expose the bucket to all users from those IPs, violating the requirement for per-user, per-document private access and not providing time-limited URLs. Option D is wrong because providing IAM user credentials to end users is a security anti-pattern; it would require distributing long-term credentials, violating the principle of least privilege and the requirement that users not have AWS credentials.

466
MCQeasy

The exhibit shows a CloudFormation template that creates an S3 bucket with versioning enabled. After deploying the stack, a developer uploads an object to the bucket. Later, the developer updates the object by uploading a new version. The developer wants to retrieve the original object. What is the correct way to do this?

A.Restore the original object using the S3 Object Lambda.
B.Use the S3 Batch Operations to revert to the original version.
C.The original object is overwritten and cannot be retrieved.
D.Use the S3 console or CLI to list object versions and retrieve the version ID of the original object.
AnswerD

S3 Versioning automatically retains every version of an object whenever it is modified or deleted, assigning each a unique version ID. To retrieve the original object, one must first identify its specific version ID among the stored versions. Both the AWS Management Console and the AWS Command Line Interface (CLI) offer functionalities to list all object versions, enabling precise retrieval of the desired historical state.

Why this answer

With S3 versioning enabled, uploading a new version of an object does not overwrite the original — it creates a new version and retains the previous one. The developer can retrieve the original by listing object versions (via console or aws s3api list-object-versions) to find the original version ID, then downloading that specific version.

Exam trap

DVA-C02 often tests the misconception that uploading a new object overwrites the old one — candidates must remember that versioning retains prior versions retrievable by version ID.

How to eliminate wrong answers

Option A is wrong because S3 Object Lambda transforms data during retrieval (e.g., redaction, format conversion); it does not restore or retrieve prior versions. Option B is wrong because S3 Batch Operations performs bulk actions on existing objects (copy, tag, invoke Lambda) and is not a version-reversion mechanism. Option C is wrong because versioning explicitly prevents overwriting — the original version remains retrievable, so this statement is factually incorrect.

467
MCQhard

A company uses AWS CodeDeploy to deploy an application to EC2 instances. The deployment fails with the error: 'The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available, or some instances in your deployment group are experiencing problems.' The deployment group consists of 4 EC2 instances. The deployment configuration is 'CodeDeployDefault.OneAtATime'. The CodeDeploy agent logs on the failed instance show: 'Error: Script at specified location: scripts/install_dependencies.sh failed with exit code 1.' What should the developer do to resolve this issue?

A.Change the deployment configuration to 'CodeDeployDefault.AllAtOnce'.
B.Review the install_dependencies.sh script for errors and correct them.
C.Reinstall the CodeDeploy agent on the failed instance.
D.Increase the number of EC2 instances in the deployment group.
AnswerB

The problem statement indicates that the install_dependencies.sh script failed, which is a critical step in the CodeDeploy application lifecycle hooks, typically executed during the BeforeInstall or Install phase. When this script fails, CodeDeploy marks the instance deployment as unsuccessful because the necessary dependencies or setup steps were not completed. Identifying and correcting syntax errors, missing commands, incorrect paths, or permission issues within this specific script will directly resolve the root cause of the deployment failures, allowing subsequent deployments to succeed.

Why this answer

The error message clearly indicates that the install_dependencies.sh script failed with exit code 1 on the instance. The root cause is a problem within the script itself (e.g., a failed package install, missing dependency, or syntax error). The developer must review and correct the script to resolve the deployment failure.

Exam trap

DVA-C02 often tests whether candidates focus on the actual error message (script exit code 1) versus superficial fixes like changing deployment configuration or reinstalling the agent — the trap is ignoring the script-level root cause.

How to eliminate wrong answers

Option A is wrong because changing to AllAtOnce would deploy to all instances simultaneously, potentially causing more failures, and does not fix the underlying script error. Option C is wrong because reinstalling the CodeDeploy agent would not fix a script that exits with code 1 — the agent is functioning correctly by reporting the failure. Option D is wrong because adding more instances does not address the script error and would likely result in more failed deployments.

468
Multi-Selecthard

An API backed by Lambda returns high p95 latency after deployment. Which two telemetry sources are most useful first?

Select 2 answers
A.AWS Billing console only
B.CloudWatch Lambda duration/init duration/logs
C.S3 Inventory reports
D.X-Ray traces across API Gateway and Lambda
AnswersB, D

CloudWatch provides critical metrics like `Duration` and `Init Duration` for Lambda functions, directly revealing execution and cold start times. Analyzing the p95 percentile of these metrics pinpoints specific latency bottlenecks. Furthermore, detailed CloudWatch Logs offer granular insights into the function's internal execution flow, external service calls, and potential code-level inefficiencies contributing to high latency.

Why this answer

CloudWatch Lambda duration and init duration metrics directly measure the time your function spends executing and initializing, which are the primary drivers of p95 latency. Logs can reveal cold starts, timeouts, or inefficient code paths that cause high latency. These are the most immediate telemetry sources to identify performance bottlenecks in the Lambda function itself.

Exam trap

The trap here is that candidates often overlook the combination of CloudWatch metrics and X-Ray traces, mistakenly thinking that only one telemetry source (like CloudWatch logs) is sufficient, or they confuse billing data with performance monitoring.

469
MCQmedium

A developer is building a serverless application using AWS Step Functions. The workflow must execute hundreds of thousands of short-lived tasks per day, each taking less than 30 seconds. The tasks need to run in parallel, and a small number of duplicate executions are acceptable. Which type of Step Functions workflow should the developer choose?

A.Standard Workflow
B.Express Workflow
C.AWS Lambda function with synchronous invocation
D.Amazon Simple Workflow Service (SWF)
AnswerB

Express Workflows are optimized for high-volume, short-duration executions (under 5 minutes) with at-least-once delivery. They can handle hundreds of thousands of executions per second at a lower cost, making them suitable for this use case.

Why this answer

Express Workflows are designed for high-volume, short-duration (under 5 minutes) event-processing workloads, executing hundreds of thousands of state transitions per second with at-least-once semantics. Since the tasks are short-lived (under 30 seconds), run in parallel, and tolerate a small number of duplicate executions, Express Workflow is the correct choice because it offers lower cost and higher throughput than Standard Workflow, which guarantees exactly-once execution and is better suited for long-running, auditable workflows.

Exam trap

The trap here is that candidates often assume Standard Workflow is always the default choice for Step Functions, overlooking the specific requirements for high throughput, short duration, and tolerance for duplicates that make Express Workflow the correct answer.

How to eliminate wrong answers

Option A is wrong because Standard Workflow is designed for long-running, durable workflows with exactly-once execution and a maximum execution duration of one year, making it over-provisioned and more expensive for high-volume, short-lived tasks where duplicate executions are acceptable. Option C is wrong because AWS Lambda synchronous invocation is not a Step Functions workflow type; it is a compute invocation pattern that lacks the orchestration, state management, and parallel execution capabilities provided by Step Functions. Option D is wrong because Amazon Simple Workflow Service (SWF) is a legacy service for long-running, human-in-the-loop workflows, not optimized for high-throughput, short-lived automated tasks, and it requires managing workers and deciders, adding operational overhead.

470
MCQhard

A developer receives the above error when trying to launch an EC2 instance. What is the most likely cause?

A.The account has reached its EC2 instance limit
B.The developer is trying to launch the instance in a restricted VPC
C.An SCP at the organizational level denies ec2:RunInstances
D.The developer's IAM policy does not allow ec2:RunInstances
AnswerC

Service Control Policies (SCPs) in AWS Organizations are designed to set maximum available permissions for all IAM entities within affected accounts. An explicit deny statement within an SCP overrides any allow statements in IAM policies, effectively preventing the "ec2:RunInstances" action from being performed, even if the user's IAM policy explicitly allows it. The error message directly indicating an explicit deny by an SCP precisely matches this behavior.

Why this answer

The error message explicitly mentions a service control policy (SCP) that denies the action, indicating that an SCP at the organizational level is blocking the ec2:RunInstances action. Option C is therefore correct. Option A is incorrect because instance limit errors show a message about reaching the maximum number of instances, not an SCP denial.

Option B is incorrect because VPC restrictions typically produce errors related to network constraints, not an explicit SCP reference. Option D is incorrect because an IAM policy denial would result in an 'UnauthorizedOperation' error, not one mentioning SCP.

471
Multi-Selecthard

A company is deploying a containerized application on Amazon ECS using the Fargate launch type. The application must be highly available across multiple Availability Zones. The developer needs to configure the ECS service. Which THREE configuration options are required? (Choose THREE.)

Select 3 answers
A.Create an Auto Scaling group for the Fargate tasks.
B.Set the desired number of tasks to at least 2.
C.Associate an Application Load Balancer with the ECS service.
D.Configure the service to place tasks in at least two subnets in different Availability Zones.
E.Use a DynamoDB table to store task state.
AnswersB, C, D

Setting the desired number of tasks to at least two is a fundamental practice for achieving high availability and fault tolerance in a containerized application. If a single task becomes unhealthy, crashes, or needs to be replaced during a deployment, the remaining tasks can continue to process requests, preventing service interruption. This redundancy ensures the application remains operational even with individual task failures.

Why this answer

Option B is correct because setting the desired task count to at least 2 ensures that more than one task replica runs, which is necessary for high availability so that the service survives the failure of a single task. Option C is correct because associating an Application Load Balancer with the ECS service distributes incoming traffic across the running tasks and performs health checks, enabling traffic to be routed only to healthy tasks in multiple AZs. Option D is correct because configuring the service to place tasks in at least two subnets in different Availability Zones spreads the tasks across distinct AZs, which is the fundamental requirement for multi-AZ high availability in ECS.

Option A is not required because AWS Fargate is a serverless launch type that does not use EC2 Auto Scaling groups; scaling is handled through ECS Service Auto Scaling instead. Option E is not required because ECS manages task state internally, and DynamoDB is not part of the ECS service configuration for high availability.

Exam trap

Candidates often confuse the EC2 launch type with the Fargate launch type. Auto Scaling groups (Option A) are used to scale EC2 instances in an ECS cluster using the EC2 launch type, whereas Fargate manages the underlying infrastructure serverlessly. Additionally, while external state storage (Option E) is a best practice for stateless applications, it is not an ECS service configuration requirement for high availability.

472
MCQeasy

A developer needs to analyze real-time streaming data from thousands of devices. The data consists of JSON messages that must be processed and stored in Amazon S3. Which AWS service should the developer use to ingest and buffer the streaming data?

A.Amazon S3
B.AWS Lambda
C.Amazon Simple Queue Service (SQS)
D.Amazon Kinesis Data Streams
AnswerD

Amazon Kinesis Data Streams is a fully managed, scalable service specifically engineered for real-time ingestion, processing, and analysis of large streams of data records. It provides the necessary throughput and low latency to capture continuous data from various sources, making it ideal for real-time analytics, log processing, and live dashboards. Multiple applications can concurrently consume data from a stream, enabling diverse real-time use cases.

Why this answer

Amazon Kinesis Data Streams is designed for real-time ingestion and buffering of large-scale streaming data, such as JSON messages from thousands of devices. It can capture and store data in shards for up to 365 days, allowing downstream consumers (e.g., Lambda, Kinesis Data Analytics) to process the data before storing it in Amazon S3. This makes it the correct choice for ingesting and buffering the streaming data before persistent storage.

Exam trap

The trap here is that candidates often confuse Amazon SQS with Kinesis Data Streams, but SQS is a pull-based queue for decoupling microservices, not a streaming data platform with shard-based parallelism and long-term retention, which is required for ingesting high-throughput real-time data from thousands of devices.

How to eliminate wrong answers

Option A is wrong because Amazon S3 is an object storage service, not a streaming ingestion or buffer service; it cannot ingest real-time streaming data directly without an intermediary like Kinesis or API Gateway. Option B is wrong because AWS Lambda is a serverless compute service that can process streaming data but is not designed to ingest or buffer data; it runs on demand and has a maximum execution timeout of 15 minutes, making it unsuitable as a primary ingestion buffer. Option C is wrong because Amazon SQS is a message queue service for decoupling applications, but it is not optimized for real-time streaming from thousands of devices; it lacks shard-level parallelism, has a maximum message size of 256 KB, and does not support ordered replay or long-term buffering like Kinesis Data Streams.

473
Multi-Selecteasy

A developer is tasked with securing a legacy application that stores secrets in environment variables. Which THREE AWS services can be used to improve the security posture?

Select 3 answers
A.AWS Key Management Service (KMS)
B.AWS Certificate Manager
C.AWS CloudHSM
D.AWS Systems Manager Parameter Store
E.AWS Secrets Manager
AnswersA, D, E

AWS KMS is the correct answer because it provides the encryption key management that secures secrets at rest. KMS creates and protects Customer Master Keys (CMKs) that can encrypt data keys via envelope encryption, and both Systems Manager Parameter Store and Secrets Manager rely on KMS to encrypt their stored secret values. While KMS itself is not a secrets repository, it is the foundational service that makes secure secret storage possible. For this legacy application, using KMS to encrypt secrets either directly or through integration with other AWS services satisfies the security requirement.

Why this answer

AWS Key Management Service (KMS) (A) is correct because it provides managed encryption keys that can be used to encrypt secrets at rest, and it integrates with services like Secrets Manager and Parameter Store to protect the underlying data with customer master keys (CMKs). AWS Systems Manager Parameter Store (D) is correct because it offers a centralized, secure store for configuration data and secrets, supports SecureString parameters encrypted via KMS, and can be referenced by applications instead of hardcoding values in environment variables. AWS Secrets Manager (E) is correct because it is purpose-built for storing, rotating, and retrieving secrets such as database credentials and API keys, with native KMS encryption and fine-grained IAM access control.

AWS Certificate Manager (B) is not correct because it manages and provisions TLS/SSL certificates for services like ELB and CloudFront, not application secrets. AWS CloudHSM (C) is not correct because it provides dedicated hardware security modules for cryptographic operations and key storage, but it is not a secrets management service for replacing environment-variable-stored secrets.

Exam trap

DVA-C02 often tests the distinction between secret storage services and certificate/HSM services — candidates pick ACM or CloudHSM thinking 'security,' but those do not store application secrets.

474
MCQeasy

A company requires that all data in Amazon S3 be encrypted at rest using server-side encryption with a customer-managed KMS key. The developer needs to ensure that any object uploaded without the x-amz-server-side-encryption header set to aws:kms is denied. How can this be enforced?

A.Use a bucket policy that denies s3:PutObject if the encryption condition is not met.
B.Configure default encryption on the bucket with SSE-KMS.
C.Enable S3 Object Lock.
D.Use a CloudTrail trail to monitor uploads.
AnswerA

A bucket policy with a Deny effect on the s3:PutObject action can explicitly check for the presence of server-side encryption headers. By using a condition like StringNotEquals on s3:x-amz-server-side-encryption or Null for its absence, the policy will reject any upload that does not specify the required encryption. This mechanism directly enforces the company's encryption mandate at the point of ingestion, preventing non-compliant data from being stored.

Why this answer

An S3 bucket policy with a condition that denies s3:PutObject unless the `s3:x-amz-server-side-encryption` header equals `aws:kms` enforces server-side encryption with a customer-managed KMS key at the API level. This policy explicitly rejects any upload that does not include the required encryption header, ensuring compliance even if default encryption is bypassed or misconfigured.

Exam trap

The trap here is that candidates often confuse default encryption (which silently applies encryption but does not deny non-compliant uploads) with a bucket policy that actively denies requests, leading them to choose Option B as a simpler but ineffective solution.

How to eliminate wrong answers

Option B is wrong because configuring default encryption on the bucket with SSE-KMS only applies encryption to objects uploaded without an explicit encryption header; it does not deny uploads that omit the header, so objects can still be uploaded without the required `x-amz-server-side-encryption` header. Option C is wrong because S3 Object Lock is designed to prevent object deletion or overwrites for compliance or retention purposes, not to enforce encryption requirements during upload. Option D is wrong because CloudTrail trails only log API calls for auditing and monitoring; they cannot enforce or deny S3 PutObject operations based on encryption headers.

475
MCQeasy

A developer wants to deploy a serverless application using AWS CloudFormation. The application consists of an API Gateway, Lambda functions, and DynamoDB tables. The developer wants to ensure that the stack can be updated without resource interruption when possible. Which CloudFormation feature should the developer use?

A.Use a Lambda alias with a DeploymentPreference update policy
B.Use a ChangeSet to review changes before applying them
C.Use a StackPolicy to protect critical resources
D.Use a Custom Resource to manage updates
AnswerA

CloudFormation's `AWS::Lambda::Alias` resource, when combined with a `DeploymentPreference` update policy, facilitates controlled, gradual traffic shifting between a Lambda function's current version and a newly deployed version. This strategy leverages AWS CodeDeploy to manage the rollout, allowing for canary deployments or linear shifts, which ensures that updates are applied without service interruption by routing traffic incrementally and automatically rolling back if issues are detected.

Why this answer

The `DeploymentPreference` update policy on a Lambda alias enables canary, linear, or all-at-once traffic shifting during stack updates. This allows the developer to update Lambda function versions without interrupting existing invocations, as traffic is gradually routed to the new version while the old version continues to serve requests until the transition completes.

Exam trap

The trap here is that candidates often confuse ChangeSets (which only preview changes) with the actual update mechanism, or they mistakenly think StackPolicies or Custom Resources can control update behavior, when in fact only the `DeploymentPreference` update policy on a Lambda alias provides the traffic-shifting capability needed for uninterrupted updates.

How to eliminate wrong answers

Option B is wrong because a ChangeSet only provides a preview of the changes that will be applied to the stack; it does not prevent resource interruption during the update itself. Option C is wrong because a StackPolicy is used to prevent accidental updates or deletions of specific resources by denying update/delete actions, but it does not control how updates are rolled out to avoid interruption. Option D is wrong because a Custom Resource is used to handle provisioning of resources not natively supported by CloudFormation, not to manage update strategies for Lambda functions.

476
MCQmedium

A developer needs to allow an EC2 instance to read from a DynamoDB table. Which is the best practice to grant permissions?

A.Create an IAM role with the required permissions and attach it to the EC2 instance.
B.Generate an IAM user access key and store it in the application configuration.
C.Hardcode the AWS credentials in the application code.
D.Add the DynamoDB table ARN to the EC2 instance's security group.
AnswerA

Attaching an IAM role to an EC2 instance is the recommended and most secure method for granting AWS service permissions. This approach leverages temporary credentials automatically provided to the instance via the EC2 instance metadata service, eliminating the need to store static, long-term credentials on the instance itself. The role defines specific permissions, such as dynamodb:GetItem or dynamodb:Query, allowing the EC2 instance to interact with DynamoDB securely and with the principle of least privilege.

Why this answer

The best practice for granting an EC2 instance permissions to access DynamoDB is to create an IAM role with the required permissions and attach it to the instance. This eliminates the need to manage long-term credentials, as the instance automatically retrieves temporary security credentials from the instance metadata service (IMDS) via the AWS Security Token Service (STS). This approach follows the principle of least privilege and ensures credentials are rotated automatically.

Exam trap

The trap here is that candidates may confuse security groups (network-level access control) with IAM policies (identity-based access control) and incorrectly think adding a DynamoDB table ARN to a security group can grant data access, when in fact security groups only control network traffic and cannot authorize API calls to DynamoDB.

How to eliminate wrong answers

Option B is wrong because storing an IAM user access key in the application configuration introduces long-term static credentials that must be manually rotated, increasing the risk of exposure and violating AWS best practices for EC2. Option C is wrong because hardcoding AWS credentials in application code is a severe security risk, as the credentials can be exposed through version control, logs, or decompilation, and it also prevents automatic rotation. Option D is wrong because security groups are stateful firewalls that control network traffic at the instance level, not IAM permissions; they cannot grant access to DynamoDB, which operates over HTTPS and requires identity-based authentication.

477
MCQmedium

A developer needs to grant temporary access to an Amazon S3 bucket for a user from a different AWS account. The developer wants to use the most secure method that does not require sharing long-term credentials. Which approach should the developer take?

A.Create an IAM user in the developer's account and share the access keys
B.Use S3 bucket policy with a condition for the external account's IAM user
C.Use cross-account IAM roles with STS AssumeRole
D.Use S3 access control lists (ACLs) with the external user's canonical user ID
AnswerC

Using cross-account IAM roles with AWS Security Token Service (STS) AssumeRole is the most secure and recommended method for granting temporary access. The external user's identity assumes a pre-defined role in the developer's account, which then issues temporary, time-limited credentials (access key ID, secret access key, and session token). This approach eliminates the need to share long-term keys, provides fine-grained control over permissions, and automatically revokes access after the session duration expires.

Why this answer

Using cross-account IAM roles with AWS Security Token Service (STS) AssumeRole allows the external user to obtain temporary, limited-privilege credentials without sharing any long-term access keys. This approach follows the principle of least privilege and eliminates the risk of exposed static credentials, as the temporary credentials automatically expire after a configurable duration (default 1 hour, max 12 hours).

Exam trap

The trap here is that candidates often confuse S3 bucket policies with cross-account access, thinking a bucket policy alone can grant temporary credentials, when in fact bucket policies only authorize access based on the requester's existing (long-term) credentials and do not issue temporary tokens.

How to eliminate wrong answers

Option A is wrong because sharing IAM user access keys exposes long-term credentials that never expire, violating the requirement for temporary access and increasing the risk of credential leakage. Option B is wrong because an S3 bucket policy with a condition for an external account's IAM user still requires that external user to use their own long-term IAM credentials to sign requests, which does not grant temporary access and does not eliminate long-term credential sharing. Option D is wrong because S3 ACLs use canonical user IDs (the account's AWS-assigned identifier) and require the external user to authenticate with their own long-term credentials; ACLs also do not provide temporary credentials and are considered a legacy access control mechanism that is less secure and less flexible than IAM roles.

478
MCQmedium

A REST API requires request validation before invoking Lambda to reduce unnecessary function executions for malformed payloads. Where should validation be configured?

A.Inside the Lambda timeout setting
B.In the IAM execution role
C.In the S3 bucket policy
D.In API Gateway request models and validators
AnswerD

API Gateway provides built-in request validation capabilities through the use of request models and validators. Developers can define JSON Schema models for the request body, headers, and query parameters. When enabled for a specific API method, API Gateway automatically validates incoming requests against these defined models *before* invoking the backend integration, such as a Lambda function, returning a 400 Bad Request error for invalid payloads.

Why this answer

API Gateway provides built-in request validation using models (JSON Schema) and validators. By configuring validation at the API Gateway layer, malformed payloads are rejected before they reach the Lambda function, reducing unnecessary invocations and associated costs. This is the correct approach because API Gateway acts as the entry point for REST APIs and can enforce payload structure without invoking the backend.

Exam trap

The trap here is that candidates may confuse Lambda's execution role or timeout settings with request validation, not realizing that API Gateway is the correct layer to filter malformed payloads before they trigger Lambda.

How to eliminate wrong answers

Option A is wrong because the Lambda timeout setting controls how long a function can run, not whether it is invoked; it cannot prevent invocation for malformed payloads. Option B is wrong because the IAM execution role defines permissions for the Lambda function to access other AWS services, not request validation. Option C is wrong because S3 bucket policies control access to S3 objects, not API request validation; they are unrelated to REST API payload checking.

479
Multi-Selecthard

Which THREE steps are required to set up a continuous delivery pipeline using AWS CodePipeline, CodeBuild, and CodeDeploy? (Select THREE.)

Select 3 answers
A.Set up an Amazon RDS database to store deployment logs.
B.Create a deploy stage with CodeDeploy to deploy the artifacts.
C.Configure an AWS Lambda function to trigger the pipeline.
D.Create a build stage with CodeBuild to compile and test the code.
E.Create a source stage that retrieves code from a repository.
AnswersB, D, E

A deploy stage is an absolutely essential component of any continuous delivery pipeline, responsible for taking the validated build artifacts and deploying them to the target environment. AWS CodeDeploy is the primary service used within CodePipeline for this purpose, supporting deployments to Amazon EC2 instances, AWS Lambda functions, and Amazon ECS services. This stage automates the release process, ensuring that the application is consistently and reliably delivered to production or staging environments after successful compilation and testing.

Why this answer

Option B is correct because a CodePipeline continuous delivery pipeline requires a deploy stage, and CodeDeploy is the AWS service used in that stage to deploy the built artifacts to targets such as EC2 instances, Lambda functions, or ECS services. Option D is correct because CodeBuild provides the build stage where the source code is compiled, tested, and packaged into deployable artifacts, which is a core step in a CodePipeline workflow. Option E is correct because every CodePipeline must begin with a source stage that retrieves the code from a repository such as AWS CodeCommit, GitHub, or Amazon S3, which then triggers the pipeline on changes.

Option A is incorrect because CodePipeline and CodeDeploy do not require an Amazon RDS database to store deployment logs; logs are handled by CloudWatch Logs and S3 artifacts. Option C is incorrect because CodePipeline is natively triggered by source changes or EventBridge rules, not by a custom Lambda function, so creating a Lambda trigger is not a required setup step.

Exam trap

The trap here is that candidates often think a database or a Lambda trigger is a required component, but the core pipeline only needs source, build, and deploy stages; additional services like RDS or Lambda are optional and not part of the minimal setup.

480
Multi-Selecthard

A developer is designing a serverless application using AWS Lambda and API Gateway. The application needs to authenticate users via a third-party identity provider (IdP). Which TWO services can be used to manage user authentication?

Select 2 answers
A.Amazon Cognito User Pools
B.AWS IAM
C.AWS Lambda custom authorizer
D.AWS Security Token Service (STS)
E.AWS Secrets Manager
AnswersA, C

Amazon Cognito User Pools act as a robust, managed user directory service that handles user sign-up, sign-in, and access control for web and mobile applications. It natively supports federation with various third-party Identity Providers (IdPs) such as Google, Facebook, Apple, and enterprise SAML/OIDC providers, allowing users to authenticate using their existing social or corporate credentials. After successful authentication, Cognito issues standard JWTs (ID and Access tokens) that can be used to authorize access to API Gateway and other AWS services.

Why this answer

Amazon Cognito User Pools is a fully managed identity service that provides user sign-up, sign-in, and access control for web and mobile applications. It integrates directly with third-party identity providers (IdPs) such as Facebook, Google, or SAML-based providers, making it the correct choice for managing user authentication in a serverless application with API Gateway and Lambda.

Exam trap

The trap here is that candidates often confuse AWS IAM (which manages AWS resource permissions) with user authentication, or they assume STS alone can authenticate users, when in fact STS only issues tokens after authentication has already occurred via another service like Cognito or an IdP.

481
MCQmedium

A company is using Amazon S3 to store sensitive documents. The security team requires that all access to the bucket be logged for audit purposes, but the company wants to avoid AWS CloudTrail data event charges and needs detailed HTTP request/response records. Which feature should be enabled?

A.S3 server access logging
B.Amazon CloudWatch Logs
C.S3 Inventory
D.AWS CloudTrail
AnswerA

S3 server access logging is the correct mechanism for recording detailed information about every request made to an S3 bucket, including successful and failed requests. These logs capture crucial details such as the requester's IP address, the operation performed (e.g., GET, PUT), the object key, the time of the request, and HTTP status codes. This comprehensive logging is essential for auditing access to sensitive documents and understanding usage patterns directly at the object level.

Why this answer

S3 server access logging provides detailed records for requests made to an S3 bucket, including the requester, bucket name, request time, action, and response status. Unlike AWS CloudTrail data events, which incur additional charges per 100,000 events, S3 server access logging is free to enable (you only pay for the storage of the log files). This makes it the ideal choice for detailed HTTP-level logging without extra service costs.

Exam trap

Candidates often confuse S3 server access logging with AWS CloudTrail. While CloudTrail is the standard for API auditing, CloudTrail data events (required for object-level logging like GetObject/PutObject) incur significant costs at scale. S3 server access logging is the cost-effective choice when you need to log S3 HTTP requests and want to avoid CloudTrail data event charges.

How to eliminate wrong answers

Option B is wrong because Amazon CloudWatch Logs is a service for monitoring, storing, and accessing log files from AWS resources like EC2 or Lambda, but it does not natively capture S3 access logs without additional configuration (e.g., using S3 event notifications to push logs to CloudWatch). Option C is wrong because S3 Inventory provides a list of objects and their metadata (e.g., size, encryption status) for compliance and lifecycle management, but it does not log access requests or actions performed on the bucket. Option D is wrong because AWS CloudTrail records management events (e.g., bucket creation, policy changes) and data events (e.g., GetObject, PutObject) for S3, but it is not the primary feature for detailed, request-level logging; S3 server access logging is the dedicated feature for granular access logs, while CloudTrail is often used for governance and compliance at a higher level.

482
MCQmedium

A developer notices that an Amazon RDS for MySQL DB instance's CPU utilization is consistently above 90% during peak hours. Which AWS service can the developer use to analyze the database queries and identify the root cause?

A.AWS X-Ray
B.Amazon CloudWatch Logs
C.Amazon RDS Performance Insights
D.AWS Trusted Advisor
AnswerC

Amazon RDS Performance Insights is the dedicated service for monitoring and analyzing database performance by visualizing database load. It collects and presents key performance metrics, including Average Active Sessions (AAS), wait events, and the full text of top SQL queries, allowing developers to quickly identify bottlenecks and understand *why* a database is slow. Its interactive dashboard provides granular insights into the database engine's activity, pinpointing specific queries, users, or hosts consuming the most resources and enabling targeted optimization.

Why this answer

Amazon RDS Performance Insights is the correct service for analyzing database queries and identifying the root cause of high CPU utilization. Performance Insights provides a database performance analysis feature that offers a visual dashboard and query-level metrics, enabling developers to pinpoint resource-intensive queries. AWS X-Ray is used for tracing application requests, not database queries.

CloudWatch Logs is for log data storage and monitoring, not query-level analysis. Trusted Advisor provides cost and security recommendations, not database performance insights. Therefore, Performance Insights is the appropriate tool for this scenario.

483
MCQmedium

A developer is using Amazon S3 to host a static website. The website uses JavaScript to fetch data from an API Gateway endpoint. Users report that the website loads but API calls fail with HTTP 403 errors. The developer checks the S3 bucket policy and finds it allows public read access. What is the most likely cause?

A.The S3 bucket policy blocks access from the API Gateway domain.
B.The S3 bucket is not configured for static website hosting.
C.The API Gateway API key is not included in the JavaScript code.
D.The S3 bucket does not have CORS configuration to allow cross-origin requests from the API Gateway domain.
AnswerC

When an API Gateway method is configured to require an API key, every incoming request must include a valid `x-api-key` header. If the JavaScript code making the API call omits this essential header, or provides an incorrect or expired key, API Gateway will reject the request with a `403 Forbidden` status code. This indicates that the request reached API Gateway but was denied due to a lack of proper authentication credentials.

Why this answer

The website loads from S3, but the API calls to API Gateway fail with 403. This is often due to missing API key. If the API Gateway endpoint requires an API key and the JavaScript code does not include it in the request headers, API Gateway returns a 403 Forbidden error.

Option C is correct because the most likely cause is that the API key is not included in the JavaScript code, leading to the 403 response.

Exam trap

Candidates often confuse CORS issues with API key requirements. While CORS can cause errors, a 403 Forbidden error from API Gateway often indicates that an API key is required but not provided. The trap is to assume it is a CORS problem without checking the API key requirement.

How to eliminate wrong answers

Option A is wrong because the S3 bucket policy controls access to S3 objects, not outbound API calls from JavaScript; the 403 error originates from the browser's CORS enforcement, not from S3 blocking the API Gateway domain. Option B is wrong because the website loads successfully, confirming static website hosting is already enabled; the issue is with cross-origin API calls, not S3 hosting configuration. Option C is wrong because API keys are optional for API Gateway and, if required, would cause a 403 from API Gateway itself (e.g., 'Missing Authentication Token'), not a browser-level CORS 403; the error is due to missing CORS headers, not missing API keys.

484
MCQmedium

A team is using AWS CodeBuild to compile and test code. The build takes longer than expected. The team wants to reduce build times by caching dependencies. Which option should the team use to cache dependencies in CodeBuild?

A.Amazon DynamoDB
B.Amazon EFS
C.Amazon ECR
D.Local caching or Amazon S3 caching
AnswerD

AWS CodeBuild natively supports both local caching and Amazon S3 caching to significantly speed up build times. Local caching stores a cache directory on the build host's file system, reusing dependencies across subsequent builds on the same host. Amazon S3 caching, a more scalable option, uploads and downloads a compressed cache archive to and from an S3 bucket, making the cache available across different build hosts and providing durability and shareability for build dependencies and artifacts.

Why this answer

AWS CodeBuild supports two caching modes: local caching and Amazon S3 caching. Local caching stores dependencies on the build host's local file system, while S3 caching stores them in an S3 bucket. Both options reduce build times by reusing previously downloaded dependencies across builds, avoiding redundant downloads.

Exam trap

The trap here is that candidates may confuse caching mechanisms with storage services like DynamoDB or EFS, or assume that ECR (used for container images) can cache dependencies, when CodeBuild specifically supports only local and S3 caching for dependency reuse.

How to eliminate wrong answers

Option A is wrong because Amazon DynamoDB is a NoSQL database service, not a caching mechanism for build dependencies; it is used for storing structured data, not for caching build artifacts or dependency files. Option B is wrong because Amazon EFS is a scalable file system for use with AWS services and on-premises resources, but it is not a caching option supported by CodeBuild for build dependencies; CodeBuild does not natively integrate with EFS for caching. Option C is wrong because Amazon ECR is a container image registry, used for storing and managing Docker images, not for caching build dependencies; it is unrelated to dependency caching in CodeBuild.

485
MCQmedium

A company is using Amazon S3 to store sensitive documents. The security team requires that all data be encrypted at rest using AWS KMS with a Customer Managed Key (CMK). The developer enabled default encryption on the S3 bucket with the CMK. However, some PUT requests are failing with 'Access Denied'. What is the MOST likely cause?

A.The S3 bucket's object ownership is set to BucketOwnerPreferred.
B.The KMS key policy does not grant the IAM user/role permissions to use the key.
C.The KMS key is in a different AWS Region than the S3 bucket.
D.The S3 bucket policy denies PutObject without encryption.
AnswerB

When an IAM user or role attempts to upload an object to S3 using server-side encryption with AWS KMS (SSE-KMS), S3 makes a request to AWS KMS on behalf of the uploader to generate a data key. This operation specifically requires the IAM principal to have `kms:GenerateDataKey` permissions on the specified AWS KMS key. If the KMS key policy does not explicitly allow or implicitly denies this action for the calling principal, the `PutObject` request will fail with an `Access Denied` error because S3 cannot obtain the necessary encryption key from KMS.

Why this answer

When default encryption is enabled on an S3 bucket with a KMS CMK, the S3 service uses the CMK to encrypt objects at rest. However, the IAM user or role making the PUT request must have explicit permissions to use that CMK, typically via the kms:GenerateDataKey and kms:Decrypt actions in the KMS key policy. If the key policy does not grant these permissions to the principal, the request fails with an 'Access Denied' error, even though the bucket policy and IAM permissions are otherwise correct.

Exam trap

The trap here is that candidates often assume enabling default encryption on the bucket is sufficient, overlooking that the IAM principal must also be explicitly authorized to use the KMS key via the key policy or IAM policy.

How to eliminate wrong answers

Option A is wrong because S3 bucket object ownership (BucketOwnerPreferred) controls whether objects uploaded by other AWS accounts are owned by the bucket owner, not encryption permissions; it does not cause 'Access Denied' on PUT requests when using a CMK. Option C is wrong because KMS keys are regional resources, and S3 buckets can only use KMS keys from the same region as the bucket; if the key were in a different region, the bucket configuration would fail at setup, not cause intermittent PUT failures. Option D is wrong because a bucket policy denying PutObject without encryption would cause failures for unencrypted requests, but the developer has already enabled default encryption with the CMK, so requests are encrypted; the error is due to KMS key permissions, not encryption enforcement.

486
Multi-Selecthard

A developer needs to securely distribute temporary AWS credentials to authenticated mobile users. Which two components are commonly involved?

Select 2 answers
A.Amazon Cognito identity pools
B.AWS root access keys
C.IAM roles with scoped permissions
D.An unrestricted S3 bucket policy
AnswersA, C

Amazon Cognito identity pools are specifically designed to provide temporary, limited-privilege AWS credentials to users authenticated through various identity providers, including Cognito User Pools, social logins, or SAML. Upon successful authentication, an identity pool exchanges the user's token for a set of temporary AWS credentials, allowing mobile or web applications to directly access specified AWS services with fine-grained permissions defined by an associated IAM role. This mechanism ensures secure, temporary access without embedding long-lived credentials in client applications.

Why this answer

Amazon Cognito identity pools allow you to exchange identity tokens (from a user pool or external IdP) for temporary AWS credentials via the AWS Security Token Service (STS). These credentials are scoped to an IAM role with fine-grained permissions, enabling secure, least-privilege access to AWS resources from mobile apps without embedding long-term keys.

Exam trap

The trap here is that candidates confuse Cognito user pools (which handle authentication and issue JWTs) with identity pools (which provide temporary AWS credentials), or mistakenly think root keys or open bucket policies are acceptable for mobile distribution.

487
MCQhard

A Lambda function needs to read from a DynamoDB table and send messages to an SQS queue. The function's IAM role should follow the principle of least privilege. Which policy statement should be attached to the role?

A.{"Effect":"Allow","Action":["dynamodb:*"],"Resource":"arn:aws:dynamodb:us-east-1:123456789012:table/MyTable"}
B.{"Effect":"Allow","Action":["dynamodb:GetItem"],"Resource":"arn:aws:dynamodb:us-east-1:123456789012:table/MyTable"}, {"Effect":"Allow","Action":["sqs:SendMessage"],"Resource":"arn:aws:sqs:us-east-1:123456789012:MyQueue"}
C.{"Effect":"Allow","Action":["dynamodb:GetItem","sqs:SendMessage","sqs:ReceiveMessage"],"Resource":"*"}
D.{"Effect":"Allow","Action":["dynamodb:GetItem","dynamodb:PutItem"],"Resource":"*"}
AnswerB

This policy correctly applies the principle of least privilege by granting only the "dynamodb:GetItem" action, which is necessary for reading data from the specified DynamoDB table. Additionally, it provides the "sqs:SendMessage" action, which is precisely what the Lambda function requires to interact with the designated SQS queue. Each permission is scoped to its specific resource, ensuring minimal access.

Why this answer

Option B is correct because it grants only the specific DynamoDB read action (GetItem) needed to read from the table and the specific SQS write action (SendMessage) needed to send messages to the queue, scoped to the exact resource ARNs. This adheres to the principle of least privilege by not allowing any unnecessary operations or resources. Wrapping the statements in an array makes the policy snippet syntactically valid.

Exam trap

The trap here is that candidates often choose a wildcard resource or overly broad actions (like dynamodb:* or sqs:*) because they think it's simpler, failing to recognize that the principle of least privilege requires scoping both actions and resources to the minimum necessary.

How to eliminate wrong answers

Option A is wrong because it grants all DynamoDB actions (dynamodb:*) on the table, which includes write, delete, and administrative operations far beyond the required read-only access. Option C is wrong because it uses a wildcard resource (*) for both DynamoDB and SQS, which would allow access to any table or queue in the account, violating least privilege. Option D is wrong because it includes dynamodb:PutItem (a write action) that is not needed, and also uses a wildcard resource (*) instead of restricting to the specific table ARN.

488
MCQmedium

A developer is deploying a serverless application using AWS SAM. The application includes an API Gateway endpoint backed by a Lambda function. The developer wants to enable canary deployments to shift 10% of traffic to the new version for 5 minutes before routing all traffic. Which configuration should the developer add to the SAM template?

A.DeploymentPreference with Type: Canary10Percent5Minutes
B.Add a CodeDeploy application and deployment group manually
C.DeploymentPreference with Type: Linear10PercentEvery1Minute
D.DeploymentPreference with Type: AllAtOnce
AnswerA

For serverless applications deployed with AWS SAM, `DeploymentPreference` integrates with AWS CodeDeploy to manage traffic shifting. A `Canary10Percent5Minutes` strategy first routes 10% of traffic to the new Lambda function version for 5 minutes. If no alarms are triggered during this period, CodeDeploy automatically shifts the remaining 90% of traffic to the new version, providing a controlled rollout and minimizing impact from potential issues. This phased approach is ideal for validating new deployments in a production environment.

Why this answer

The `DeploymentPreference` property with `Type: Canary10Percent5Minutes` instructs AWS SAM to use AWS CodeDeploy to shift 10% of traffic to the new Lambda version for 5 minutes, then automatically route the remaining 90% after the canary period ends. This matches the requirement exactly, leveraging SAM's built-in integration with CodeDeploy for canary deployments.

Exam trap

The trap here is that candidates confuse `Canary10Percent5Minutes` with `Linear10PercentEvery1Minute`, thinking both are canary deployments, but only the former holds traffic at 10% for a fixed duration before shifting all at once, while the latter shifts incrementally every minute.

How to eliminate wrong answers

Option B is wrong because manually adding a CodeDeploy application and deployment group is unnecessary and error-prone; AWS SAM automatically creates and manages the CodeDeploy resources when you specify `DeploymentPreference` in the template. Option C is wrong because `Linear10PercentEvery1Minute` shifts traffic in 10% increments every minute, which does not match the requirement of a single 10% shift for 5 minutes before routing all traffic. Option D is wrong because `AllAtOnce` routes 100% of traffic to the new version immediately, bypassing any canary or gradual deployment strategy.

489
Multi-Selecteasy

Which TWO strategies can be used to reduce the risk of a failed deployment when using AWS CodeDeploy? (Select TWO.)

Select 2 answers
A.Configure automatic rollback based on CloudWatch alarms.
B.Use a canary deployment to shift traffic gradually.
C.Disable health checks to prevent false positives.
D.Require a manual approval step before deployment.
E.Deploy to all instances at once to ensure consistency.
AnswersA, B

When a deployment causes performance degradation or errors, CloudWatch alarms can detect these issues by monitoring key metrics such as error rates, latency, or CPU utilization. Configuring automatic rollback to trigger upon these alarm states ensures that the application quickly reverts to a stable previous version, minimizing the blast radius and user impact of a faulty deployment. This proactive measure significantly reduces the duration of service disruption and enhances reliability.

Why this answer

AWS CodeDeploy can automatically trigger a rollback when a CloudWatch alarm is breached, such as when error rates or latency exceed a threshold. This reduces the risk of a failed deployment by reverting to the last known good state without manual intervention. Option B is correct because a canary deployment shifts a small percentage of traffic to the new version first, allowing you to monitor for issues before routing all traffic, minimizing blast radius.

Exam trap

The trap here is that candidates often confuse manual approval (a pre-deployment gate) with a rollback mechanism, or they mistakenly think disabling health checks reduces false positives, when in fact health checks are critical for detecting failures during deployment.

490
MCQeasy

A developer needs to grant an IAM user read-only access to an S3 bucket named 'my-bucket'. Which IAM policy statement should be attached?

A.{"Effect":"Allow","Action":"s3:*","Resource":"arn:aws:s3:::my-bucket/*"}
B.{"Effect":"Allow","Action":["s3:GetObject","s3:ListBucket"],"Resource":["arn:aws:s3:::my-bucket","arn:aws:s3:::my-bucket/*"]}
C.{"Effect":"Deny","Action":"s3:GetObject","Resource":"arn:aws:s3:::my-bucket/*"}
D.{"Effect":"Allow","Action":["s3:PutObject","s3:DeleteObject"],"Resource":"arn:aws:s3:::my-bucket/*"}
AnswerB

Pairing s3:ListBucket with the bucket-level ARN and s3:GetObject with the object-level wildcard ARN correctly grants exactly the two actions needed for read-only access: enumerating the bucket's contents and downloading individual objects, while granting no write or delete permissions on either the bucket or its objects.

Why this answer

It grants read-only access by allowing the `s3:GetObject` action (to read objects) and the `s3:ListBucket` action (to list objects in the bucket). The resources are correctly specified: `arn:aws:s3:::my-bucket` for the bucket-level `ListBucket` action and `arn:aws:s3:::my-bucket/*` for the object-level `GetObject` action. This combination provides the minimal permissions needed for read-only access without allowing write or delete operations.

Exam trap

The trap here is that candidates often forget to include both the bucket ARN and the object ARN, or they mistakenly use a single ARN like `arn:aws:s3:::my-bucket/*` for both actions, which would fail for `s3:ListBucket` because it requires the bucket-level ARN.

How to eliminate wrong answers

Option A is wrong because it allows all S3 actions (`s3:*`) on the bucket, which grants full administrative access, not read-only. Option C is wrong because it uses a `Deny` effect on `s3:GetObject`, which explicitly blocks read access, the opposite of what is needed. Option D is wrong because it allows `s3:PutObject` and `s3:DeleteObject`, which are write and delete operations, not read-only.

491
MCQhard

An application receives webhooks from a partner. The developer must verify that each request was signed by the partner and not modified in transit. What should the application validate?

A.The source port number
B.The CloudWatch log stream name
C.The HMAC or digital signature over the payload using the shared/public key material
D.The API Gateway request ID only
AnswerC

An HMAC (Hash-based Message Authentication Code) or a digital signature provides cryptographic proof of both the sender's identity (authentication) and the message's integrity (non-tampering). The sender computes this value over the webhook payload using either a shared secret key (for HMAC) or their private key (for a digital signature). The receiver then independently computes the expected value using the same shared secret or the sender's public key, verifying that the request originated from the legitimate partner and that the data has not been altered in transit.

Why this answer

Webhook verification relies on validating a cryptographic signature (HMAC or digital signature) computed over the request payload using a pre-shared secret or public key. This ensures the payload was signed by the partner and has not been tampered with during transit, as any modification would invalidate the signature. The application must recompute the HMAC or verify the digital signature using the partner's public key and compare it to the signature provided in the request header.

Exam trap

The trap here is that candidates confuse request metadata (like source port or request ID) with cryptographic verification mechanisms, assuming any unique identifier can prove authenticity, when only HMAC or digital signatures provide integrity and sender verification.

How to eliminate wrong answers

Option A is wrong because the source port number is a transient network-layer attribute that can be spoofed or changed by NAT/firewalls, and it provides no cryptographic proof of authenticity or integrity. Option B is wrong because a CloudWatch log stream name is an AWS-specific logging resource identifier unrelated to request signing or payload integrity verification. Option D is wrong because an API Gateway request ID is a unique identifier for debugging and tracing, not a cryptographic mechanism to verify the sender's identity or detect payload tampering.

492
Multi-Selectmedium

A DynamoDB table shows throttling on one partition key value. Which two signs point to a hot partition problem?

Select 2 answers
A.Most traffic targets the same partition key
B.The table has point-in-time recovery enabled
C.Consumed capacity is uneven despite total table capacity being available
D.CloudTrail is enabled in all regions
AnswersA, C

DynamoDB distributes data across partitions based on the partition key. When a disproportionate amount of read or write traffic targets a small subset of partition key values, those specific partitions become 'hot.' Each partition has a maximum throughput limit, typically 3000 RCU and 1000 WCU. Exceeding this limit on a single partition, even if the overall table capacity is sufficient, results in throttling requests directed at that hot partition.

Why this answer

A hot partition occurs when a single partition key value receives a disproportionate share of read/write traffic, causing throttling on that partition even if the table's total provisioned capacity is not fully utilized. This imbalance means the partition's capacity is exhausted while other partitions remain underutilized, leading to request throttling for that specific key.

Exam trap

The trap here is that candidates confuse overall table capacity with partition-level capacity, assuming throttling only happens when total consumed capacity exceeds provisioned capacity, rather than recognizing that uneven key distribution can cause throttling on a single partition.

493
MCQhard

A developer wants to enforce that all requests to an Amazon S3 bucket must use HTTPS (TLS). The bucket is used for static website hosting. Which bucket policy condition should be used to deny requests that do not use HTTPS?

A."aws:SecureTransport": "false"
B."aws:SecureTransport": "true"
C."aws:SourceVpc": "true"
D."aws:Referer": "https"
AnswerA

This option correctly enforces HTTPS. When used in a Deny statement within an S3 bucket policy, the condition `"aws:SecureTransport": "false"` explicitly blocks any request that is *not* using HTTPS. By denying all unencrypted requests, the policy effectively mandates that all successful interactions with the S3 bucket must utilize HTTPS (TLS) for data in transit, ensuring secure communication.

Why this answer

The `aws:SecureTransport` condition key evaluates to `false` when the request is not sent over HTTPS (TLS). By using a Deny effect with this condition set to `false`, the policy blocks any HTTP requests to the S3 bucket, ensuring all traffic uses encrypted connections. This is a standard approach for enforcing TLS on S3 buckets, including those used for static website hosting.

Exam trap

The trap here is that candidates often confuse `aws:SecureTransport` with `aws:SourceVpc` or `aws:Referer`, or mistakenly think setting the condition to `true` in a Deny statement will block non-HTTPS traffic, when in fact it would block HTTPS traffic instead.

How to eliminate wrong answers

Option B is wrong because setting `aws:SecureTransport` to `true` would allow only HTTPS requests, but the question requires denying non-HTTPS requests; a Deny policy with `true` would block HTTPS traffic, which is the opposite of the desired outcome. Option C is wrong because `aws:SourceVpc` is used to restrict requests to those originating from a specific VPC, not to enforce HTTPS; setting it to `true` is invalid as this condition key expects a VPC ID, not a boolean. Option D is wrong because `aws:Referer` is used to restrict requests based on the HTTP Referer header (e.g., to prevent hotlinking), not to enforce HTTPS; the value `https` is a protocol scheme, not a valid referer pattern, and this condition does not check transport security.

494
MCQmedium

A developer needs to call AWS APIs from application code running on EC2. Which credential source should the AWS SDK use by default?

A.Static credentials committed to Git
B.A credentials file copied into the AMI
C.The root account access key
D.Temporary credentials from the instance profile role
AnswerD

Attaching an IAM role to an EC2 instance via an instance profile is the recommended and most secure method for granting AWS API access to applications running on that instance. This mechanism automatically provides temporary, frequently rotated credentials to the instance metadata service, which applications can retrieve without needing to store any long-term static keys. This significantly enhances security, simplifies credential management, and adheres to the principle of least privilege by allowing granular permissions.

Why this answer

The AWS SDK on EC2 automatically retrieves temporary credentials from the instance metadata service (IMDS) at http://169.254.169.254/latest/meta-data/iam/security-credentials/. These credentials are provided by the IAM role attached to the EC2 instance (the instance profile role) and are rotated automatically, eliminating the need to store long-term credentials on the instance.

Exam trap

The trap here is that candidates may think manually embedding credentials (via a file or environment variable) is acceptable, but the AWS SDK on EC2 is designed to use the instance profile role by default, and any static credential source is both insecure and not the default behavior.

How to eliminate wrong answers

Option A is wrong because committing static credentials to Git is a severe security risk and violates AWS best practices; the SDK does not default to Git-stored credentials. Option B is wrong because copying a credentials file into the AMI embeds long-term credentials in the image, which can be exposed if the AMI is shared or reused, and the SDK does not default to an AMI-embedded file. Option C is wrong because root account access keys are highly privileged, static, and should never be used in application code; the SDK does not default to root keys.

495
Multi-Selecteasy

A developer is troubleshooting an AWS Lambda function that is timing out. The function is configured with a 3-second timeout. Which of the following could cause the function to timeout? (Choose THREE.)

Select 3 answers
A.The function's reserved concurrency is set to 0.
B.The function has a dead-letter queue configured.
C.The function is configured to access a VPC without a NAT gateway.
D.The function experiences a cold start.
E.The function's deployment package is larger than 50 MB.
AnswersC, D, E

When a Lambda function is configured to access a VPC but lacks a NAT gateway, outbound internet traffic fails. If the function makes external calls (e.g., to DynamoDB or external APIs), these requests will hang until the function times out.

Why this answer

Lambda timeouts occur when the function execution exceeds the configured timeout. Option A is incorrect because setting reserved concurrency to 0 causes immediate throttling (TooManyRequestsException), not a timeout. Option B is incorrect because a dead-letter queue is for asynchronous invocation failures, not timeouts.

Option C is correct: if the function is in a VPC without a NAT gateway, it cannot access external networks, leading to network timeouts. Option D is correct: cold starts can delay execution due to initialization, potentially exceeding the timeout. Option E is correct: a deployment package larger than 50 MB can increase cold start time significantly, causing the function to timeout.

Exam trap

Candidates may mistakenly think reserved concurrency of 0 causes a timeout, but it actually causes immediate throttling. The real trap is that cold starts and large deployment packages can both contribute to timeouts, especially when the timeout is short.

496
MCQeasy

A developer wants to invoke an AWS Lambda function every hour to perform a maintenance task. Which AWS service should be used to schedule the invocation?

A.Amazon Simple Queue Service (SQS)
B.AWS Step Functions
C.Amazon CloudWatch Events (EventBridge)
D.Amazon Simple Notification Service (SNS)
AnswerC

Amazon CloudWatch Events, now largely integrated into Amazon EventBridge, is the definitive AWS service for triggering Lambda functions on a schedule. It enables developers to create rules that define specific time-based patterns, such as cron expressions or fixed-rate intervals, to directly invoke target Lambda functions. This provides a robust, serverless, and highly scalable solution for automating periodic tasks and time-driven events within the AWS ecosystem.

Why this answer

Amazon CloudWatch Events (now part of Amazon EventBridge) is the correct service for scheduling periodic invocations of AWS Lambda functions. It allows you to create a rule with a cron or rate expression (e.g., `rate(1 hour)`) that triggers the Lambda function on a defined schedule. This is the native, serverless way to run code on a recurring timer without managing any infrastructure.

Exam trap

The trap here is that candidates often confuse 'scheduling' with 'messaging' and pick SQS or SNS, not realizing that only EventBridge (CloudWatch Events) provides native cron/rate-based triggers for Lambda.

How to eliminate wrong answers

Option A is wrong because Amazon SQS is a message queue service for decoupling application components; it does not have a built-in scheduler to invoke Lambda on a recurring schedule. Option B is wrong because AWS Step Functions is a workflow orchestration service that can invoke Lambda, but it is designed for stateful, multi-step processes, not for simple time-based scheduling (it lacks native cron/rate triggers). Option D is wrong because Amazon SNS is a pub/sub notification service; it can trigger Lambda from messages, but it cannot generate scheduled events on its own.

497
Multi-Selecthard

A company is implementing a CI/CD pipeline for a containerized application using Amazon ECS and AWS CodePipeline. The team wants to ensure zero-downtime deployments. Which THREE strategies should the team implement? (Choose THREE.)

Select 3 answers
A.Use a blue/green deployment strategy with an Application Load Balancer.
B.Use a rolling update with a fixed batch size of 100% of tasks.
C.Use ECS service auto scaling to maintain desired count during deployment.
D.Configure the ECS service with health check grace period.
E.Stop all existing tasks before starting new tasks.
AnswersA, C, D

A blue/green deployment provisions an entirely new (green) set of ECS tasks alongside the running (blue) set, and the ALB shifts traffic over only once the green tasks pass health checks. Because the old environment stays live until cutover, users never hit a moment with zero healthy targets, and rollback is instant by simply routing back to blue.

Why this answer

Option A is correct because a blue/green deployment with an Application Load Balancer lets CodeDeploy shift traffic from the original ECS task set to the new (green) task set only after the new tasks pass health checks, and it can roll back instantly if validation fails, so users never hit a failed deployment. Option C is correct because ECS service auto scaling keeps the desired task count at the level the service needs during and after deployment, ensuring enough healthy tasks remain registered with the load balancer to absorb traffic while replacements are being launched. Option D is correct because the health check grace period prevents ECS from killing newly started tasks before they have finished booting and begun responding to ALB health checks, avoiding false unhealthy verdicts that would otherwise cause task churn and downtime.

Option B is not appropriate because a rolling update with a batch size of 100% replaces all tasks at once, which removes all healthy capacity simultaneously and can cause an outage. Option E is not appropriate because stopping all existing tasks before starting new ones creates a hard outage, directly violating the zero-downtime requirement.

Exam trap

The trap is selecting options that sound like they improve deployment but actually cause downtime, such as 'rolling update with 100% batch size' or 'stop all tasks first'; candidates must recognize that zero-downtime requires maintaining capacity and gradually shifting traffic.

498
MCQeasy

A developer is building a serverless application and wants to invoke an AWS Lambda function every hour to perform a cleanup task. Which AWS service should the developer use to schedule the invocation?

A.AWS Step Functions
B.Amazon SNS
C.Amazon SQS
D.Amazon EventBridge (CloudWatch Events)
AnswerD

Amazon EventBridge, which evolved from CloudWatch Events, is a serverless event bus service that makes it easy to connect applications together using data from your own applications, integrated SaaS applications, and AWS services. It excels at creating rules that match incoming events and route them to targets, including Lambda functions. Crucially, EventBridge supports cron-like expressions and fixed-rate schedules, making it the ideal service for invoking Lambda functions at specified times or recurring intervals.

Why this answer

Amazon EventBridge (formerly CloudWatch Events) is the correct service for scheduling AWS Lambda invocations on a recurring basis. It provides a cron or rate expression to trigger a Lambda function at a defined interval, such as every hour, without the need for managing any servers or additional infrastructure.

Exam trap

The trap here is that candidates often confuse Amazon EventBridge with Amazon CloudWatch Logs or assume Step Functions is needed for any time-based workflow, but Step Functions is for stateful orchestration, not simple scheduled invocations.

How to eliminate wrong answers

Option A is wrong because AWS Step Functions is a workflow orchestration service designed to coordinate multiple AWS services into state machines, not for scheduling standalone recurring events. Option B is wrong because Amazon SNS is a pub/sub messaging service for sending notifications or fan-out messages, not a scheduler for invoking Lambda on a time-based trigger. Option C is wrong because Amazon SQS is a message queue service for decoupling application components; it cannot initiate Lambda invocations based on a time schedule.

499
MCQmedium

A developer is monitoring an AWS Lambda function that is triggered by an Amazon SQS queue. The function's CloudWatch metrics show a high number of throttles. The function has a reserved concurrency of 10 and the SQS queue has a large backlog of messages. The function processes each message in about 2 seconds and has a timeout of 60 seconds. Which action will most effectively reduce the throttles and increase throughput?

A.Increase the reserved concurrency of the Lambda function to 50
B.Increase the batch size in the SQS event source mapping to 100
C.Increase the function timeout to 120 seconds
D.Decrease the reserved concurrency to 5
AnswerA

Increasing the reserved concurrency for a Lambda function dedicates a specific number of concurrent execution slots exclusively to that function. This action guarantees that the function can scale up to 50 simultaneous invocations, preventing it from being throttled by the account's general unreserved concurrency pool. For an SQS-triggered Lambda, this directly enables more parallel processing of messages, significantly improving throughput and reducing the backlog in the queue.

Why this answer

The high throttles indicate that the Lambda function's reserved concurrency of 10 is insufficient to handle the incoming messages from the SQS queue. By increasing reserved concurrency to 50, you allow more concurrent executions, which reduces throttling and increases throughput. The function's 2-second processing time and 60-second timeout are not the bottleneck; the concurrency limit is.

Exam trap

The trap here is that candidates may think increasing batch size or timeout will help, but they overlook that the root cause is the reserved concurrency cap, which directly limits the number of concurrent executions and is the primary driver of throttles.

How to eliminate wrong answers

Option B is wrong because increasing the batch size to 100 would cause the function to receive more messages per invocation, but with a reserved concurrency of 10, the function can only process 10 batches concurrently, so throttles would persist and latency could increase due to longer processing per batch. Option C is wrong because increasing the timeout to 120 seconds does not address the concurrency limit; the function already completes in 2 seconds, so a longer timeout has no effect on throttles. Option D is wrong because decreasing reserved concurrency to 5 would reduce the number of concurrent executions, worsening throttles and decreasing throughput.

500
MCQeasy

A developer is deploying a serverless application using AWS SAM. The application includes an API Gateway endpoint and a Lambda function. The developer wants to ensure that the Lambda function can be invoked only by the API Gateway and not directly. Which configuration should be used?

A.Configure a VPC endpoint policy that allows only API Gateway.
B.Add a resource-based policy with 'aws:SourceAccount' condition.
C.Add a resource-based policy with 'aws:SourceVpce' condition set to the API Gateway VPC endpoint ID.
D.Add a resource-based policy with 'aws:SourceArn' condition set to the API Gateway ARN.
AnswerD

Adding a resource-based policy with an `aws:SourceArn` condition set to the specific API Gateway ARN is the most effective and secure method to restrict Lambda function invocation. This policy ensures that only requests originating from that particular API Gateway instance (e.g., `arn:aws:execute-api:region:account-id:api-id/*/*`) are authorized to invoke the Lambda function. This fine-grained control prevents unauthorized direct invocations of the Lambda function, enforcing that all traffic must flow through the API Gateway.

Why this answer

Adding a resource-based policy with an `aws:SourceArn` condition set to the API Gateway ARN ensures that the Lambda function can only be invoked by that specific API Gateway. This uses the AWS Identity and Access Management (IAM) condition key to restrict the `lambda:InvokeFunction` action based on the ARN of the invoking resource, preventing direct invocation from other sources like the AWS CLI or SDK.

Exam trap

The trap here is that candidates confuse resource-based policies with VPC-based controls, often selecting `aws:SourceVpce` (Option C) thinking API Gateway invokes Lambda through a VPC endpoint, but API Gateway uses a public endpoint or private integration without a VPC endpoint for Lambda invocation.

How to eliminate wrong answers

Option A is wrong because a VPC endpoint policy controls traffic through a VPC endpoint, not invocation permissions for Lambda; it does not restrict which service can invoke the function. Option B is wrong because `aws:SourceAccount` condition only checks the AWS account ID of the caller, not the specific resource (API Gateway), so any service in the same account could still invoke the function. Option C is wrong because `aws:SourceVpce` condition checks for a VPC endpoint ID, but API Gateway does not use a VPC endpoint for invocation; it uses a public endpoint or a private integration, making this condition ineffective.

501
MCQhard

A company is using AWS CodeDeploy to deploy an application to an Auto Scaling group. The deployment fails with the error 'The overall deployment failed because too many individual instances failed to deploy.' The CodeDeploy agent logs show that the BeforeInstall lifecycle event script returned a non-zero exit code. What is the MOST likely cause of this issue?

A.The application revision is missing from the S3 bucket.
B.The BeforeInstall script has a bug that causes it to exit with a non-zero status.
C.The IAM instance profile does not have permissions to call CodeDeploy APIs.
D.The CodeDeploy agent is not running on the instances.
AnswerB

CodeDeploy strictly interprets any non-zero exit status from a lifecycle event script, such as BeforeInstall, as a critical failure. This indicates that the script, intended to prepare the environment or install prerequisites, did not complete successfully. Consequently, the deployment on that specific instance is immediately halted, and the overall deployment is marked as failed, preventing further potentially problematic steps.

Why this answer

The error message explicitly states that the CodeDeploy agent logs show the BeforeInstall lifecycle event script returned a non-zero exit code. This directly indicates that the script itself failed during execution, which is the most likely cause of the deployment failure. The BeforeInstall script is a custom script run by the CodeDeploy agent on each instance, and a non-zero exit code signals an error condition that halts the deployment for that instance.

Exam trap

The trap here is that candidates often confuse a script failure (non-zero exit code) with infrastructure or permission issues, but the question explicitly provides the agent log detail pointing to the BeforeInstall script, making the script bug the direct and most likely cause.

How to eliminate wrong answers

Option A is wrong because if the application revision were missing from the S3 bucket, the error would occur earlier in the process (during the download phase) and the CodeDeploy agent logs would show a different error, such as 'Failed to download revision' or a 403/404 HTTP status code, not a non-zero exit code from the BeforeInstall script. Option C is wrong because insufficient IAM instance profile permissions to call CodeDeploy APIs would prevent the agent from registering with the service or pulling deployment instructions, resulting in errors like 'Unable to register instance' or 'AccessDeniedException', not a script exit code failure. Option D is wrong because if the CodeDeploy agent were not running, the instances would not appear in the deployment at all, and the error would be 'No instances found' or 'Instance not available', not a script execution failure with a non-zero exit code.

502
Matchingmedium

Match each HTTP status code to its meaning.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

OK

Created

Bad Request

Forbidden

Internal Server Error

Why these pairings

Correct matches: 200 OK, 404 Not Found, 500 Internal Server Error. Common confusions include mixing 200 and 201, or 404 and 403.

503
Multi-Selecthard

Which TWO are best practices for optimizing DynamoDB performance? (Choose two.)

Select 2 answers
A.Use SQS to decouple write-heavy workloads and handle spikes.
B.Use partition keys with high cardinality to distribute traffic evenly.
C.Provision maximum write capacity units to handle any spike.
D.Use Scan operations instead of Query for retrieving data.
E.Enable strongly consistent reads for all read operations.
AnswersA, B

SQS acts as a buffer, decoupling the producer (application) from the consumer (DynamoDB). During write-heavy workloads or sudden traffic spikes, SQS queues the requests, allowing the application to continue processing without being throttled by DynamoDB's provisioned capacity. A separate worker process can then consume messages from SQS at a controlled rate, ensuring DynamoDB's write capacity units (WCUs) are not exceeded and operations are processed reliably. This prevents throttling errors and improves overall system resilience.

Why this answer

Using SQS to decouple write-heavy workloads allows DynamoDB to absorb traffic spikes by buffering writes in a queue, preventing throttling and enabling batch processing. This pattern, often called 'queue-based load leveling,' ensures that DynamoDB's provisioned capacity is not overwhelmed by sudden bursts, improving overall system resilience and cost efficiency.

Exam trap

The trap here is that candidates often confuse 'handling spikes' with over-provisioning capacity (Option C) instead of using decoupling patterns like SQS, or they mistakenly believe that Scan operations are acceptable for frequent data retrieval, ignoring the cost and performance penalties.

504
MCQhard

A developer is deploying an application on Amazon ECS with Fargate. The application needs to access an S3 bucket that contains sensitive data. The developer wants to avoid storing AWS credentials in the container image. What is the MOST secure way to grant the application access to the S3 bucket?

A.Create an IAM task role with a policy that allows S3 access and specify it in the task definition.
B.Set the AWS credentials as environment variables in the task definition.
C.Store the credentials in an EFS volume and mount it to the container.
D.Use an IAM instance profile attached to the underlying EC2 instance.
AnswerA

An ECS task IAM role, specified in the task definition, causes the ECS agent to inject temporary, automatically-rotated credentials into the container via the task metadata endpoint, so the application's SDK picks up scoped S3 permissions without any long-lived secret ever being stored or configured.

Why this answer

An IAM task role for ECS tasks allows the container to assume the role without storing credentials. Option B is wrong because environment variables are not secure. Option C is wrong because mounting credentials in a volume is insecure.

Option D is wrong because IAM instance profiles are for EC2 instances, not Fargate tasks.

505
MCQhard

Refer to the exhibit. A developer tried to create a CloudFormation stack that includes an EC2 instance. The stack creation failed and rolled back. What should the developer do to get more details about the failure?

A.Review the CloudFormation template syntax.
B.Use the `detect-stack-drift` command.
C.Run `aws cloudformation describe-stack-events` for the stack.
D.Update the stack with the same template to see the error.
AnswerC

describe-stack-events returns the chronological, resource-by-resource event log including the exact CREATE_FAILED status reason (such as an invalid AMI ID, insufficient IAM permissions, or a capacity error) for each logical resource, making it the direct way to identify the root cause.

Why this answer

When a CloudFormation stack fails and rolls back, the authoritative source of failure details is the stack events log. Running aws cloudformation describe-stack-events returns the ordered event stream, including the specific resource that failed and the status reason containing the underlying error message.

Exam trap

DVA-C02 often tests whether candidates know that stack events (not template syntax or drift detection) contain the runtime failure reason, and candidates sometimes pick drift detection because it sounds diagnostic.

How to eliminate wrong answers

Option A is wrong because reviewing template syntax alone does not reveal runtime failures such as insufficient IAM permissions, AMI not found, or subnet capacity issues that occur during resource creation. Option B is wrong because detect-stack-drift compares actual resource configuration against the template and is unrelated to diagnosing a failed creation. Option D is wrong because re-updating with the same template would fail again and does not surface the original error details any better than the events log.

506
MCQmedium

A developer is building a RESTful API using Amazon API Gateway and Lambda. The API should support CORS for a specific origin (https://example.com) and allow only GET and POST methods. Which configuration in the OPTIONS method response will satisfy these requirements?

A.Access-Control-Allow-Origin: https://example.com, Access-Control-Allow-Methods: GET,POST
B.Access-Control-Allow-Origin: *, Access-Control-Allow-Methods: GET,POST,OPTIONS
C.Access-Control-Allow-Origin: https://example.com, Access-Control-Allow-Methods: GET,POST,OPTIONS
D.Access-Control-Allow-Origin: https://example.com, Access-Control-Allow-Headers: Content-Type
AnswerA

This configuration correctly specifies `https://example.com` as the only permitted origin, adhering to the principle of least privilege for cross-origin requests. By listing `GET,POST` in `Access-Control-Allow-Methods`, the server explicitly informs the browser which actual HTTP methods are allowed for the resource, satisfying the preflight request's requirements without exposing unnecessary methods like `OPTIONS` itself.

Why this answer

The OPTIONS method response must include the `Access-Control-Allow-Origin` header set to the specific origin `https://example.com` to restrict CORS access, and the `Access-Control-Allow-Methods` header must list only the allowed HTTP methods (`GET,POST`). The OPTIONS method itself is a preflight request and does not need to be listed in the allowed methods; it is automatically handled by the browser. This configuration satisfies the requirement of supporting CORS for a single origin and only GET and POST methods.

Exam trap

The trap here is that candidates often mistakenly include `OPTIONS` in the `Access-Control-Allow-Methods` header, thinking it must be listed because the preflight request uses that method, but the correct behavior is to only list the actual HTTP methods (GET, POST) that the API supports for the main request.

How to eliminate wrong answers

Option B is wrong because it uses a wildcard origin (`*`), which does not satisfy the requirement for a specific origin (`https://example.com`), and it incorrectly includes `OPTIONS` in the allowed methods list, which is unnecessary and could cause confusion. Option C is wrong because it includes `OPTIONS` in the `Access-Control-Allow-Methods` header; the OPTIONS method is the preflight request itself and should not be listed as an allowed method in the response. Option D is wrong because it specifies `Access-Control-Allow-Headers` instead of `Access-Control-Allow-Methods`, and it omits the required `Access-Control-Allow-Methods` header entirely, so the browser would not know which HTTP methods are permitted.

507
MCQeasy

A developer is creating a CI/CD pipeline for a serverless application using AWS CodePipeline. The application consists of an AWS Lambda function, an Amazon API Gateway REST API, and an Amazon DynamoDB table. Which action should the developer take to automate the deployment of the API Gateway updates?

A.Use AWS Lambda to update the API Gateway configuration.
B.Store the API Gateway Swagger file in Amazon S3 and trigger a deployment.
C.Use AWS CloudFormation to define and deploy the API Gateway.
D.Use AWS CodeBuild to compile and deploy the API Gateway configuration.
AnswerC

AWS CloudFormation is the recommended and most robust service for defining and deploying AWS resources, including API Gateway, as Infrastructure as Code (IaC). It allows developers to declaratively specify the entire API Gateway configuration in a template, enabling automated, repeatable, and version-controlled deployments with built-in rollback capabilities, which is crucial for maintaining consistency and reliability in CI/CD pipelines.

Why this answer

AWS CloudFormation provides infrastructure as code (IaC) capabilities that allow you to define the entire API Gateway configuration, including resources, methods, integrations, and deployment stages, in a template. When integrated with CodePipeline, CloudFormation can automatically create or update the API Gateway and trigger a deployment as part of the CI/CD pipeline, ensuring consistent and repeatable deployments without manual intervention.

Exam trap

The trap here is that candidates often assume CodeBuild or a custom Lambda function is needed for deployment, but the exam tests whether you recognize that CloudFormation is the native, fully managed IaC service that integrates seamlessly with CodePipeline for deploying API Gateway updates.

How to eliminate wrong answers

Option A is wrong because using a Lambda function to update API Gateway configuration directly via API calls is not a recommended or scalable CI/CD practice; it bypasses infrastructure as code, lacks versioning, and makes rollbacks and auditing difficult. Option B is wrong because simply storing a Swagger file in S3 does not automatically trigger a deployment; you would need additional automation (e.g., a Lambda function or CloudFormation) to import the Swagger definition and create a deployment, making this an incomplete solution. Option D is wrong because CodeBuild is designed to compile source code and run tests, not to deploy API Gateway configurations; it lacks the native capability to manage API Gateway resources and deployments, which is better handled by CloudFormation or the AWS CLI.

508
MCQmedium

A developer is deploying a web application on AWS Elastic Beanstalk. The application requires a fixed IP address for outbound traffic to a third-party API. What is the MOST cost-effective solution?

A.Launch the environment in a VPC with a NAT Gateway in a public subnet.
B.Attach an Internet Gateway to the VPC.
C.Use a VPC endpoint for the third-party API.
D.Assign an Elastic IP to each EC2 instance.
AnswerA

This is the correct approach for instances in private subnets needing outbound internet access to third-party APIs while maintaining private IP addresses. A NAT Gateway, deployed in a public subnet, allows instances in private subnets to initiate outbound connections to the internet. All outbound traffic from these private instances will appear to originate from the NAT Gateway's Elastic IP address, providing a consistent and fixed public IP for the third-party API to whitelist, which is crucial for security policies.

Why this answer

A NAT Gateway in a public subnet provides a fixed public IP address for outbound traffic from private subnets, enabling the web application to communicate with the third-party API while remaining secure. Elastic Beanstalk environments are typically launched in private subnets, and the NAT Gateway is the most cost-effective managed service for this purpose compared to a NAT instance or assigning Elastic IPs to each EC2 instance.

Exam trap

The trap here is that candidates often confuse a NAT Gateway with an Internet Gateway, thinking the latter provides outbound IPs, or they incorrectly assume a VPC endpoint can be used for any external API, when it is limited to AWS services.

How to eliminate wrong answers

Option B is wrong because an Internet Gateway only allows inbound and outbound traffic to and from the internet for resources with public IPs; it does not provide a fixed outbound IP for instances in private subnets. Option C is wrong because a VPC endpoint is used for private connectivity to AWS services (e.g., S3, DynamoDB) via the AWS network, not for accessing third-party APIs over the internet. Option D is wrong because assigning an Elastic IP to each EC2 instance is not cost-effective (each Elastic IP incurs charges when not associated with a running instance) and does not scale well; it also exposes instances directly to the internet, increasing security risks.

509
MCQeasy

A developer is writing an AWS Lambda function that processes messages from an Amazon SQS queue. The function should process each message at least once, but duplicates are acceptable. The function is triggered by a Lambda event source mapping. If the function returns an error, what happens to the message?

A.The message is sent to a dead-letter queue (DLQ).
B.The message is deleted from the queue to prevent duplicate processing.
C.Lambda automatically retries the function with a 1-minute delay.
D.The message remains in the queue and becomes visible after the visibility timeout expires.
AnswerD

When an AWS Lambda function fails to process a message from an SQS queue, the Lambda service does not delete the message. Instead, the message remains in the SQS queue, but it stays hidden from other consumers due to the in-flight visibility timeout that was initiated when Lambda received it. Upon the expiration of this visibility timeout, the message automatically becomes visible again in the queue, making it available for another Lambda invocation attempt or consumption by another service.

Why this answer

When a Lambda function invoked by an SQS event source mapping returns an error, the message is not deleted from the queue. Instead, it remains in the queue and becomes visible again after the visibility timeout expires. This allows the function to retry processing the message, ensuring at-least-once processing.

The default behavior is to retry based on the queue's redrive policy, not to immediately send the message to a DLQ or delete it.

Exam trap

The trap here is that candidates often assume Lambda automatically deletes failed messages or immediately sends them to a DLQ, but the actual behavior is that the message remains in the queue and becomes visible again after the visibility timeout expires, allowing for retries.

How to eliminate wrong answers

Option A is wrong because a message is only sent to a dead-letter queue (DLQ) after the maximum number of retries specified in the queue's redrive policy is exhausted, not on the first error. Option B is wrong because Lambda does not delete a message from the queue on error; deletion only occurs after successful processing to prevent duplicate processing. Option C is wrong because Lambda does not automatically retry with a fixed 1-minute delay; the retry timing is controlled by the SQS visibility timeout, which is configurable and not set to 1 minute by default.

510
MCQeasy

A developer is troubleshooting an AWS Lambda function that is timing out. The function processes S3 events and writes to DynamoDB. The average execution time is 5 seconds, but the function times out after 3 seconds. What is the most likely cause?

A.The S3 bucket is not configured to send event notifications.
B.DynamoDB write capacity is insufficient.
C.The Lambda function timeout is set to 3 seconds.
D.The Lambda function concurrency limit is exceeded.
AnswerC

The Lambda function timeout configuration directly dictates the maximum duration an invocation is allowed to run before the Lambda service forcibly terminates it. If the function's code, including any synchronous downstream calls or complex processing, requires more than 3 seconds to complete, it will inevitably result in a timeout error. The default timeout is often 3 seconds, and increasing this value is the primary solution when a function consistently fails to finish within its allocated execution window.

Why this answer

The function's average execution time is 5 seconds, but it times out at 3 seconds — this mismatch directly indicates the Lambda function's configured timeout value is set to 3 seconds, which is lower than the actual runtime. The timeout setting is a per-function configuration (default 3 seconds, max 15 minutes) that terminates execution when exceeded. Since the workload legitimately needs ~5 seconds, the fix is to increase the timeout to a value above the observed runtime.

Exam trap

DVA-C02 often tests the confusion between a function timing out due to its own configured timeout versus downstream service throttling — candidates see 'DynamoDB' in the stem and jump to capacity, ignoring that the timeout value (3s) exactly matches the default and is below the stated 5s runtime.

How to eliminate wrong answers

Option A is wrong because missing S3 event notifications would prevent the function from being invoked at all, not cause it to time out mid-execution. Option B is wrong because insufficient DynamoDB write capacity would produce throttling errors (ProvisionedThroughputExceededException) or retries, not a hard timeout at exactly 3 seconds. Option D is wrong because exceeding the concurrency limit results in throttled invocations (429 TooManyRequestsException) or queued events, not a function-level timeout during execution.

511
MCQmedium

A developer is building a mobile backend using Amazon API Gateway and AWS Lambda. The API has a single endpoint that accepts POST requests with a JSON payload and stores the data in an Amazon DynamoDB table. The developer wants to implement caching to reduce latency and costs. The data is user-specific and should not be shared between users. The developer configures API Gateway caching with a TTL of 300 seconds. After testing, the developer notices that users are seeing other users' data. What should the developer do to fix this issue?

A.Enable cache key parameters in API Gateway, such as the Authorization header.
B.Store cached responses in DynamoDB and retrieve them based on user ID.
C.Use Lambda@Edge to cache responses at the CloudFront level.
D.Disable API Gateway caching and use DynamoDB Accelerator (DAX) instead.
AnswerA

API Gateway's caching mechanism allows developers to specify request parameters, such as headers, query strings, or path parameters, to be included in the cache key. By enabling the Authorization header as a cache key parameter, API Gateway generates a unique cache entry for each distinct Authorization token presented by a user. This ensures that responses are cached on a per-user basis, preventing data leakage between users while still providing the performance benefits of caching for repeated requests from the same authenticated user.

Why this answer

API Gateway caching by default uses only the request path and method as the cache key, so all POST requests to the same endpoint share a single cache entry. Since the data is user-specific, the cache must include a unique user identifier in the cache key. Enabling cache key parameters (e.g., the Authorization header or a custom user ID header) ensures that each user's request generates a distinct cache key, preventing cross-user data leakage.

This is the correct and minimal fix because it directly addresses the root cause—the cache key not being user-specific—while retaining the performance benefits of API Gateway caching.

Exam trap

DVA-C02 often tests the misconception that enabling API Gateway caching automatically isolates data per user, when in fact the default cache key only includes the method and path, leading to cross-user data leakage unless cache key parameters are explicitly configured.

How to eliminate wrong answers

Option B is wrong because storing cached responses in DynamoDB and retrieving them by user ID is a custom application-level caching solution that adds complexity, cost, and latency; it does not fix the API Gateway cache misconfiguration and would still leave the API Gateway cache leaking data unless disabled. Option C is wrong because Lambda@Edge caches at CloudFront edge locations, but API Gateway caching is separate and still active; moreover, Lambda@Edge is not designed for per-user caching of POST responses and would not solve the issue without also fixing API Gateway. Option D is wrong because disabling API Gateway caching and using DAX only accelerates DynamoDB reads; it does not provide response caching for the API endpoint and would not address the requirement to cache the API response while keeping user data isolated.

512
Multi-Selecteasy

A developer is building a serverless application that uses Amazon S3 for static website hosting and AWS Lambda for dynamic API calls. The developer wants to enable logging of all API requests. Which TWO services can be used to log API requests? (Choose TWO.)

Select 2 answers
A.Amazon CloudWatch Logs
B.AWS CloudTrail
C.VPC Flow Logs
D.Amazon S3 server access logs
E.Amazon Route 53 logs
AnswersA, B

Amazon CloudWatch Logs is the primary service for collecting and monitoring logs from various AWS services and custom applications. For a serverless application utilizing API Gateway, CloudWatch Logs captures detailed execution logs, including request/response payloads, latency, and error messages. These logs are essential for real-time monitoring, debugging, and troubleshooting the runtime behavior of the API Gateway and integrated backend Lambda functions. Configuring API Gateway to send its access and execution logs to CloudWatch Logs provides granular insights into every API call.

Why this answer

Amazon CloudWatch Logs is correct because it can capture and store logs from AWS Lambda function executions. When a Lambda function is invoked via an API request (e.g., through Amazon API Gateway), the function's execution details, including request IDs, timestamps, and error messages, are automatically sent to CloudWatch Logs. This enables developers to monitor and troubleshoot API-driven serverless applications.

Exam trap

The trap here is that candidates often confuse S3 server access logs (which log S3 bucket operations) with API request logging, or mistakenly think VPC Flow Logs can capture HTTP-level API calls when they only capture network-layer traffic.

513
MCQhard

A developer is deploying a microservices architecture on Amazon ECS using Fargate launch type. The services need to communicate with each other. The developer wants to use service discovery so that services can find each other by name. Which AWS service should the developer use?

A.Amazon Route 53 private hosted zones
B.Amazon ECR
C.Application Load Balancer
D.AWS Cloud Map
AnswerD

AWS Cloud Map is the correct choice because it provides a fully managed service discovery solution that allows microservices to locate each other dynamically. It integrates natively with Amazon ECS, automatically registering and deregistering service instances as they scale up or down. This enables applications to discover service endpoints using either API calls or DNS queries, simplifying inter-service communication in a dynamic containerized environment.

Why this answer

AWS Cloud Map is the correct choice because it is a cloud resource discovery service that allows microservices to register their DNS names and health checks, enabling dynamic service discovery. With Amazon ECS and Fargate, services can use AWS Cloud Map namespaces (either API-based or DNS-based) to resolve each other by logical service names, which is essential for inter-service communication in a microservices architecture.

Exam trap

The trap here is that candidates often confuse Route 53 private hosted zones with AWS Cloud Map, not realizing that Cloud Map provides the dynamic registration and health check integration needed for ephemeral containers, whereas Route 53 alone requires manual record management.

How to eliminate wrong answers

Option A is wrong because Amazon Route 53 private hosted zones provide DNS resolution within a VPC but lack the dynamic service registration, health checking, and API-based discovery features that AWS Cloud Map offers for ephemeral Fargate tasks. Option B is wrong because Amazon ECR is a container image registry used for storing and retrieving Docker images, not for service discovery or DNS resolution. Option C is wrong because an Application Load Balancer distributes incoming traffic to targets but does not provide service discovery by name; it is a load balancing layer, not a naming or registration service.

514
MCQeasy

A developer needs to grant an IAM user in Account A access to an S3 bucket in Account B. What is the correct combination of policies?

A.An S3 bucket policy in Account B that allows the IAM user's ARN.
B.An IAM policy in Account A allowing access to the S3 bucket, and a bucket policy in Account B allowing the IAM user.
C.An IAM policy in Account A allowing access, and a bucket ACL in Account B granting access to the IAM user.
D.Create an IAM role in Account B that the user can assume, and attach a bucket policy allowing the role.
AnswerB

This is the correct and most direct combination for granting cross-account S3 access to an IAM user. The IAM policy attached to the user in Account A provides the necessary identity-based permissions for the user to initiate S3 actions. Concurrently, the S3 bucket policy in Account B, a resource-based policy, explicitly grants permission to the specific IAM user's ARN from Account A, overriding the default deny for cross-account access. Both policies must grant permission for the request to be authorized successfully.

Why this answer

Cross-account S3 access requires two policies: an IAM policy in the source account (Account A) granting the user permission to perform S3 actions on the bucket, and a bucket policy in the target account (Account B) that explicitly allows the IAM user's ARN. The bucket policy acts as a resource-based policy that delegates access to the external principal, while the IAM policy authorizes the user to make the request. Without both, the request will be denied by either the source account's implicit deny or the target account's default deny.

Exam trap

The trap here is that candidates often think a bucket policy alone is sufficient for cross-account access (Option A), forgetting that the IAM user's own account must also explicitly authorize the action through an IAM policy.

How to eliminate wrong answers

Option A is wrong because an S3 bucket policy alone in Account B that allows the IAM user's ARN is insufficient — the IAM user in Account A still needs an IAM policy that explicitly grants permission to perform the S3 action, otherwise the request is denied by the source account's implicit deny. Option C is wrong because bucket ACLs do not support granting access to IAM users from another AWS account; ACLs only support AWS accounts or predefined groups, not individual IAM user ARNs. Option D is wrong because while creating an IAM role in Account B and allowing the user to assume it is a valid cross-account access pattern, the question specifically asks for granting access to an IAM user directly, not via role assumption; additionally, the bucket policy would need to allow the role's ARN, not the user's ARN, making this a different mechanism than what the question describes.

515
MCQhard

A company uses a customer managed AWS KMS key to encrypt sensitive data stored in DynamoDB. A Lambda function reads from the DynamoDB table and needs to decrypt the data. The Lambda function's execution role has an IAM policy that allows kms:Decrypt on the key. However, access is denied. What must the developer add to the KMS key policy to resolve the issue?

A.Add a statement granting kms:Decrypt to the Lambda function's execution role.
B.Add a statement granting kms:Decrypt to the Lambda function's resource-based policy.
C.Add a statement granting kms:Decrypt to the Lambda service principal.
D.Add a statement granting kms:Decrypt to the account root user with a condition for the Lambda function.
AnswerA

When a Lambda function needs to interact with a customer-managed AWS KMS key, the key policy associated with that KMS key must explicitly grant permissions to the entity making the request. The Lambda function assumes an IAM execution role, and it is this role that makes API calls to KMS. Therefore, the KMS key policy must include a statement allowing the kms:Decrypt action for the specific ARN of the Lambda function's execution role, ensuring direct access control and adherence to the principle of least privilege.

Why this answer

KMS key policies are resource-based policies that control access to the key itself. Even if the Lambda execution role has an IAM policy granting kms:Decrypt, the KMS key policy must explicitly allow the role (or the user/account) to perform that action. Without this statement in the key policy, the IAM permission is ineffective, resulting in an access denied error.

Exam trap

The trap here is that candidates often assume IAM permissions alone are sufficient for KMS operations, forgetting that KMS key policies act as an additional layer of access control that must explicitly allow the principal.

How to eliminate wrong answers

Option B is wrong because Lambda functions do not have resource-based policies that can grant KMS permissions; KMS actions must be authorized via the key policy or IAM, not a Lambda resource policy. Option C is wrong because granting kms:Decrypt to the Lambda service principal would allow any Lambda function in the account to decrypt using the key, which is overly permissive and not the correct way to grant access to a specific function. Option D is wrong because granting kms:Decrypt to the account root user with a condition for the Lambda function is unnecessarily complex and not a standard pattern; the root user already has full control over the key, and conditions cannot directly reference a Lambda function's identity in a reliable way.

516
MCQmedium

A CodePipeline source stage should start when code is pushed to a repository, without scheduled polling. Which integration pattern should be used?

A.Manual approval only
B.Event-based trigger from the source provider/EventBridge integration
C.A cron job on an EC2 instance
D.CloudWatch Logs Insights
AnswerB

AWS CodePipeline natively supports event-based triggers from integrated source providers such as AWS CodeCommit, GitHub, and Amazon S3. For CodeCommit, a push to a repository branch generates an event that is published to Amazon EventBridge. An EventBridge rule can then be configured to detect this specific event and automatically invoke the CodePipeline, ensuring the pipeline starts immediately upon a code push, which is the most direct and efficient solution.

Why this answer

AWS CodePipeline can integrate with Amazon EventBridge to listen for repository events (e.g., push events from CodeCommit, GitHub, or Bitbucket) and automatically start the pipeline. This event-driven pattern eliminates the need for scheduled polling, providing near-instantaneous execution when code changes are detected.

Exam trap

The trap here is that candidates may confuse manual approval (a pipeline action) with a trigger mechanism, or assume that CloudWatch Logs Insights can initiate pipeline executions, when in fact only EventBridge or webhook-based integrations provide the required event-driven, polling-free source trigger.

How to eliminate wrong answers

Option A is wrong because manual approval is a gate that pauses pipeline execution for human review, not a mechanism to trigger the pipeline on code push. Option C is wrong because a cron job on an EC2 instance would require custom scripting, polling the repository periodically, and introduces unnecessary complexity, latency, and maintenance overhead compared to a native event-driven integration. Option D is wrong because CloudWatch Logs Insights is a query tool for analyzing log data, not a trigger mechanism for CodePipeline source stages.

517
Multi-Selectmedium

Which THREE are valid methods to handle application configuration in AWS? (Choose three.)

Select 3 answers
A.AWS CloudFormation template parameters
B.AWS Secrets Manager
C.AWS IAM roles
D.Lambda environment variables
E.AWS Systems Manager Parameter Store
AnswersB, D, E

AWS Secrets Manager is a dedicated service designed for securely storing, managing, and retrieving sensitive credentials and other secrets, such as database passwords, API keys, and OAuth tokens. Applications can programmatically fetch these secrets at runtime, ensuring that sensitive configuration data is never hardcoded or exposed in plain text within application code or configuration files. It also offers automatic rotation capabilities to enhance security.

Why this answer

AWS Secrets Manager is a valid method for handling application configuration because it securely stores and manages sensitive configuration data such as database credentials, API keys, and other secrets. It supports automatic rotation of secrets, fine-grained access control via IAM policies, and integrates with AWS services like RDS, Redshift, and Lambda. This makes it ideal for managing dynamic configuration values that require high security and lifecycle management.

Exam trap

The trap here is that candidates often confuse IAM roles with configuration storage, thinking that roles can hold configuration data, when in fact roles only define permissions and cannot store key-value pairs or secrets.

518
MCQhard

A developer notices that an AWS Lambda function, which uses Amazon RDS Proxy to connect to an Aurora MySQL database, is experiencing increased latency and occasional connection timeouts. The function is configured with a reserved concurrency of 100 and is deployed in a VPC. The RDS Proxy's maximum connections is set to 1000. CloudWatch metrics show that the DatabaseConnections metric for the proxy is consistently at 1000. What is the most likely cause of the increased latency and timeouts?

A.The Lambda function is not reusing database connections properly, exhausting the proxy connection pool
B.The RDS Proxy target group is not configured with the correct DB instance
C.The Lambda function's execution role is missing the rds-db:connect permission
D.The VPC does not have a NAT Gateway for outbound traffic
AnswerA

Lambda functions are inherently stateless and often short-lived. Without explicit connection pooling implemented within the Lambda function's code (e.g., by declaring the connection object in a global scope), each new invocation will attempt to establish a fresh connection to the RDS Proxy. This rapid creation of new client connections, especially under high concurrency, quickly exhausts the limited connection pool managed by the RDS Proxy, leading to connection failures and increased latency as requests wait for available connections.

Why this answer

The RDS Proxy's DatabaseConnections metric is consistently at 1000, which equals the proxy's maximum connections setting. This indicates the proxy connection pool is fully saturated. When all connections are in use, new connection requests from Lambda invocations must wait, causing increased latency, and if the wait exceeds the timeout, connection timeouts occur.

The most likely cause is that the Lambda function is not reusing database connections (e.g., not using connection pooling or keeping connections open across invocations), exhausting the pool.

Exam trap

The trap here is that candidates may focus on the reserved concurrency (100) versus proxy max connections (1000) and assume the numbers are fine, missing that the real issue is connection reuse per invocation, not the total count.

How to eliminate wrong answers

Option B is wrong because if the target group were misconfigured, the proxy would fail to connect to the database entirely, not just experience latency and timeouts while the connection pool is full. Option C is wrong because missing the rds-db:connect permission would cause immediate authentication failures (e.g., 'Access denied') for all connection attempts, not gradual pool exhaustion. Option D is wrong because Lambda functions in a VPC use Elastic Network Interfaces (ENIs) for outbound traffic to RDS Proxy within the same VPC; a NAT Gateway is only needed for internet-bound traffic, not for connecting to RDS Proxy in the same VPC.

519
Multi-Selectmedium

A developer is implementing a solution to store application logs from multiple EC2 instances. The logs must be stored in a centralized location for analysis. Which services can the developer use to achieve this? (Choose TWO.)

Select 2 answers
A.Amazon CloudWatch Logs
B.AWS CloudTrail
C.Amazon Kinesis Data Analytics
D.Amazon DynamoDB
E.Amazon S3
AnswersA, E

Amazon CloudWatch Logs is a highly scalable and durable service specifically designed for collecting, monitoring, and storing log data from various sources, including EC2 instances, containers, and serverless functions. It provides real-time monitoring, search capabilities, and the ability to set up alarms based on log patterns, making it ideal for operational visibility and troubleshooting application issues. Logs can be retained for specified periods or archived to S3 for long-term storage.

Why this answer

Amazon CloudWatch Logs is correct because it provides a centralized service for collecting, monitoring, and storing log data from EC2 instances. By installing the CloudWatch Logs agent on each EC2 instance, logs are automatically streamed to CloudWatch Logs, where they can be analyzed, searched, and retained for auditing or troubleshooting.

Exam trap

The trap here is that candidates often confuse CloudTrail (which logs AWS API calls) with CloudWatch Logs (which stores application and system logs), leading them to incorrectly select CloudTrail as a solution for application log centralization.

520
MCQhard

A company uses an AWS Lambda function to process files uploaded to an S3 bucket. The Lambda function needs to read the files and write results to a DynamoDB table. The Lambda function is configured with an IAM role that has policies allowing s3:GetObject on the bucket and dynamodb:PutItem on the table. Despite correct permissions, the function fails with an AccessDenied error when trying to put items. What is the most likely cause?

A.The Lambda function is in a VPC without a VPC endpoint for DynamoDB.
B.The DynamoDB table has a resource-based policy that explicitly denies access to the Lambda function's IAM role.
C.The S3 bucket is in a different region, causing cross-region access issues.
D.The DynamoDB table is encrypted with a customer managed KMS key, and the Lambda role does not have kms:Decrypt permission.
AnswerB

AWS evaluates both identity-based policies (attached to the Lambda function's IAM role) and resource-based policies (attached directly to the DynamoDB table) to determine access. An explicit "Deny" statement in *any* applicable policy, including a resource-based policy, always takes precedence over any "Allow" statements. Therefore, even if the Lambda role has an "Allow" policy, an explicit "Deny" on the DynamoDB table itself will result in an "AccessDenied" error.

Why this answer

DynamoDB tables can have resource-based policies that explicitly deny access even if the IAM role has the necessary permissions. Since explicit denies in resource-based policies override any allow in identity-based policies, the Lambda function's IAM role with dynamodb:PutItem permission is still blocked, causing the AccessDenied error.

Exam trap

The trap here is that candidates often assume IAM role permissions alone guarantee access, forgetting that resource-based policies on DynamoDB tables can explicitly deny access, which overrides any allow in identity-based policies.

How to eliminate wrong answers

Option A is wrong because a Lambda function in a VPC without a VPC endpoint for DynamoDB would cause a network timeout or connectivity error, not an AccessDenied error, as DynamoDB calls go over HTTPS and the error would be a timeout or connection failure, not an IAM permission denial. Option C is wrong because S3 and DynamoDB are both global services; cross-region access is fully supported and does not cause AccessDenied errors—the error would be a different type like a timeout or throttling if there were latency issues. Option D is wrong because while KMS permissions are needed for encrypted tables, the error message would be a KMS AccessDenied or a 400 error, not a generic AccessDenied on PutItem, and the question states the function fails specifically when trying to put items, not during encryption/decryption.

521
Multi-Selectmedium

A developer is using AWS Lambda and needs to ensure that the function can access an RDS database securely. Which THREE steps should be taken?

Select 3 answers
A.Place the Lambda function inside a VPC.
B.Store the database credentials in AWS Secrets Manager and retrieve them in the Lambda code.
C.Attach an IAM role to the Lambda function that grants rds:* permissions.
D.Configure the RDS instance to require client certificates.
E.Configure the security group of the RDS instance to allow inbound traffic from the Lambda function's security group.
AnswersA, B, E

By default, Lambda functions run in an AWS-owned VPC and cannot connect to resources in your private subnets. Attaching the function to the same VPC provisions elastic network interfaces in your subnets, giving it private IP connectivity to the RDS instance. This is the foundational step required before any TCP connection to RDS can be established.

Why this answer

Option A is correct because a Lambda function can only reach an RDS instance that resides in a VPC if the function itself is configured with VPC connectivity (subnets and a security group), which is required for private network access to the database. Option B is correct because hardcoding credentials is insecure; storing them in AWS Secrets Manager and retrieving them at runtime (optionally with Lambda's Secrets Manager extension/caching) keeps the database password encrypted and rotatable. Option E is correct because RDS access is controlled by security group rules, so the RDS instance's security group must allow inbound traffic on the database port (e.g., 3306 for MySQL, 5432 for PostgreSQL) referencing the Lambda function's security group as the source.

Option C is not appropriate because rds:* IAM permissions govern the RDS control plane API, not the ability to open a database connection, and Lambda's execution role does not grant network access to RDS. Option D is not required for this scenario; client certificate authentication is an optional RDS TLS feature and is not one of the standard steps to let Lambda connect securely.

Exam trap

DVA-C02 often tests the misconception that IAM permissions alone are sufficient for Lambda-to-RDS access, ignoring the need for VPC networking and security group rules.

522
MCQhard

A service publishes order events to SNS. Several consumers need different filtered subsets of events without changing publisher code. What should the developer configure?

A.Separate AWS accounts for each consumer
B.Lambda code that discards unwanted events after invocation
C.SNS subscription filter policies
D.SQS long polling only
AnswerC

SNS subscription filter policies are the most direct and efficient solution for this requirement. These policies allow each subscriber to define specific rules based on message attributes or the message body. Only messages that fully match a subscriber's defined filter policy are delivered to that particular endpoint, ensuring consumers receive only the relevant "order events" they need. This prevents unnecessary message delivery and optimizes downstream processing by filtering at the source.

Why this answer

SNS subscription filter policies allow each consumer to define a JSON policy on their subscription that selectively delivers only messages matching specified attributes (e.g., event type, region). This enables multiple consumers to receive different filtered subsets of the same SNS topic without modifying the publisher's code, as the filtering happens server-side at the SNS service level.

Exam trap

The trap here is that candidates often confuse client-side filtering (Option B) with server-side filtering, or assume that SQS long polling (Option D) can filter messages, when in fact SNS subscription filter policies are the only native AWS mechanism for server-side message subsetting without publisher changes.

How to eliminate wrong answers

Option A is wrong because separate AWS accounts do not provide message filtering; they would require duplicating the SNS topic and publisher logic across accounts, adding complexity without solving the subset requirement. Option B is wrong because discarding unwanted events in Lambda after invocation wastes compute resources and incurs unnecessary costs, as the Lambda function is still triggered for every message, defeating the purpose of server-side filtering. Option D is wrong because SQS long polling only controls how often the consumer polls for messages, not which messages are delivered; it does not filter message content or attributes.

523
Multi-Selecteasy

Which TWO are valid deployment strategies supported by AWS CodeDeploy? (Choose TWO.)

Select 2 answers
A.Immutable deployment
B.In-place deployment
C.Canary deployment
D.All at once deployment
E.Blue/Green deployment
AnswersB, E

In-place deployment is a valid deployment strategy supported by AWS CodeDeploy, where the application on the existing set of EC2 instances or on-premises servers is directly updated. During this process, CodeDeploy stops the application on each instance, deploys the new application revision, and then restarts the application. Traffic is not shifted between different environments; instead, the application files on the active servers are modified in place, potentially causing brief service interruptions on individual instances as they are updated.

Why this answer

AWS CodeDeploy supports in-place deployments (option B) where the application is updated on the existing instances without provisioning new ones. This is a valid deployment strategy that updates the current fleet by stopping and starting the application, and it is one of the two core strategies explicitly documented by AWS.

Exam trap

The trap here is that candidates confuse deployment strategies (in-place and blue/green) with deployment configuration options (like AllAtOnce) or with strategies from other AWS services (like immutable deployments in Elastic Beanstalk), leading them to select 'All at once' or 'Immutable' as valid CodeDeploy strategies.

524
Multi-Selecthard

A developer is deploying a new version of an AWS Lambda function. The function is behind an API Gateway endpoint. The developer wants to use canary deployments to gradually shift traffic to the new version. Which TWO steps should the developer perform?

Select 2 answers
A.Create a Lambda alias that points to the current version and configure routing to shift a percentage of traffic to the new version.
B.Configure Amazon CloudFront to distribute traffic between two API Gateway endpoints.
C.Update the API Gateway integration to point to the Lambda alias instead of a specific version.
D.Update the Lambda function code and publish a new version.
E.Create a new API Gateway stage for the new version and update DNS.
AnswersA, C

An AWS Lambda alias provides a stable endpoint for your function while allowing you to manage traffic distribution across different versions. By configuring the alias to point to both the current and the new Lambda versions with a weighted routing strategy, a developer can gradually shift a small percentage of traffic to the new version. This enables a controlled canary deployment, allowing for real-time monitoring and quick rollback if issues arise, minimizing impact on users.

Why this answer

Lambda aliases support traffic shifting for canary deployments by allowing you to route a percentage of incoming requests to a new function version while the majority continues to the current version. This is done by configuring the alias's routing configuration with a `RoutingConfig` that specifies the new version and the weight (e.g., 5%) of traffic it should receive. This enables gradual, controlled rollouts without modifying the API Gateway integration endpoint.

Option C is also necessary because the API Gateway integration must point to the Lambda alias (rather than a fixed version) so that the routing configuration on the alias can take effect. Without updating the integration to use the alias, API Gateway would continue to invoke a specific version directly, bypassing the canary routing.

Exam trap

The trap here is that candidates often think canary deployments require separate infrastructure (like CloudFront or multiple stages), but AWS Lambda aliases with routing configuration provide a built-in, serverless-native mechanism for percentage-based traffic shifting without additional services.

525
MCQeasy

A developer is building a serverless REST API using Amazon API Gateway and AWS Lambda. The API will be consumed by a web application hosted on a different domain. The developer needs to enable Cross-Origin Resource Sharing (CORS) for all HTTP methods. What is the most efficient way to achieve this?

A.Enable CORS on the API Gateway resource using the 'Enable CORS' feature in the API Gateway console, which adds the OPTIONS method and appropriate headers.
B.In the Lambda function code, add the 'Access-Control-Allow-Origin' header to every response.
C.Configure Amazon CloudFront in front of API Gateway to handle CORS.
D.Set a bucket policy on the S3 bucket that hosts the web application to allow cross-origin requests.
AnswerA

Enabling CORS directly on the API Gateway resource is the correct and most efficient solution. API Gateway's built-in CORS feature automatically configures the necessary preflight OPTIONS method for the resource. It also injects the required Access-Control-Allow-Origin, Access-Control-Allow-Methods, and Access-Control-Allow-Headers into the method responses and integration responses, ensuring browsers can successfully make cross-origin requests to your API.

Why this answer

API Gateway's 'Enable CORS' feature automatically creates an OPTIONS method for the selected resource and configures the necessary response headers (e.g., Access-Control-Allow-Origin, Access-Control-Allow-Methods, Access-Control-Allow-Headers) to handle preflight requests. This is the most efficient approach as it centralizes CORS configuration at the API Gateway layer, eliminating the need for manual header management in Lambda or additional infrastructure.

Exam trap

The trap here is that candidates assume adding CORS headers only in the Lambda function code is sufficient, overlooking the mandatory preflight OPTIONS request that API Gateway must handle separately.

How to eliminate wrong answers

Option B is wrong because while adding headers in Lambda is necessary for the actual response, it does not handle the preflight OPTIONS request that browsers send before cross-origin requests; without a proper OPTIONS response, CORS will fail. Option C is wrong because CloudFront does not natively handle CORS preflight requests; it can pass through headers but still requires the origin (API Gateway) to be properly configured for CORS, making it an unnecessary extra layer. Option D is wrong because S3 bucket policies control access to S3 objects, not API Gateway endpoints; CORS for the API must be configured on the API Gateway resource itself, not on the web application's hosting bucket.

Page 6

Page 7 of 16

Page 8