Courseiva

AWS Certified Developer Associate DVA-C02 (DVA-C02) — Questions 526–600

1135 questions total · 16pages · All types, answers revealed

Page 7

Page 8 of 16

Page 9
526
MCQmedium

A company's application uses Amazon S3 to store user-uploaded images. Users report that recently uploaded images are sometimes not immediately available for viewing. The application uses S3 Event Notifications to trigger a Lambda function that processes images and stores metadata in DynamoDB. What is the MOST likely cause of the delay?

A.Lambda function has a cold start that adds several seconds to processing time.
B.S3 is eventually consistent for new object writes, so the object may not be immediately available.
C.S3 Event Notifications may have a slight delay, and the application polls for the processed image before the notification triggers Lambda.
D.DynamoDB has insufficient read capacity causing throttling on metadata retrieval.
AnswerC

S3 Event Notifications are delivered asynchronously and on a best-effort basis, meaning there can be an inherent, variable delay between an object being uploaded and the corresponding Lambda function being invoked. If the application immediately polls for the *processed* image after the initial upload, it creates a race condition where the polling might occur before the S3 event has triggered the Lambda function to process the image, or before the processing itself has completed and the processed image is stored. This asynchronous nature and potential latency in event delivery are a common cause for such perceived delays.

Why this answer

S3 Event Notifications are delivered asynchronously and can take seconds to minutes to reach Lambda, so if the application polls for the processed image or metadata immediately after upload, it may query before Lambda has run. This race condition between the upload and the notification-driven processing is the most likely cause of the intermittent delay.

Exam trap

DVA-C02 often tests whether candidates still believe S3 is eventually consistent for new writes (it has been strongly consistent since 2020) and whether they understand that event notifications are asynchronous, so the trap is blaming cold starts or DynamoDB throttling instead of the notification latency and polling race.

How to eliminate wrong answers

Option A is wrong because Lambda cold starts add hundreds of milliseconds to a few seconds, not the kind of noticeable delay described, and they would not cause 'sometimes not immediately available' behavior tied to polling. Option B is wrong because since December 2020 S3 provides strong read-after-write consistency for new object PUTs, so the object is immediately readable — the old eventual-consistency model no longer applies. Option D is wrong because DynamoDB read throttling would produce errors or retries, not a delay in image availability, and the scenario describes metadata retrieval rather than capacity exhaustion.

527
MCQhard

A developer is building an application that uses Amazon DynamoDB as a data store. The application reads the same item frequently but writes rarely. The developer wants to reduce read costs. Which DynamoDB feature should the developer use?

A.DynamoDB Accelerator (DAX)
B.DynamoDB Global Tables
C.DynamoDB Auto Scaling
D.Time to Live (TTL)
AnswerA

DynamoDB Accelerator (DAX) is an in-memory cache designed to provide microsecond response times for read-heavy workloads, significantly reducing the number of read capacity units (RCUs) consumed from the underlying DynamoDB table. When an application reads data through DAX, if the item is in the cache, it's served directly, bypassing DynamoDB and incurring no RCU cost. This makes DAX highly effective for applications requiring low-latency access to frequently read data, directly lowering operational costs associated with read throughput.

Why this answer

DynamoDB Accelerator (DAX) is an in-memory cache that reduces read latency from single-digit milliseconds to microseconds. Since the application reads the same item frequently but writes rarely, DAX can serve repeated read requests from its cache, significantly reducing the number of read capacity units consumed against the DynamoDB table and thus lowering read costs.

Exam trap

The trap here is that candidates often confuse DAX with ElastiCache or assume that Auto Scaling reduces costs, but DAX is the only DynamoDB-native service that directly reduces read costs by caching frequently accessed items.

How to eliminate wrong answers

Option B is wrong because Global Tables provide multi-region replication for disaster recovery and low-latency writes, not read cost reduction. Option C is wrong because Auto Scaling adjusts provisioned throughput based on traffic patterns but does not reduce per-read costs; it only prevents throttling. Option D is wrong because Time to Live (TTL) automatically expires old items to reduce storage costs, not read costs.

528
MCQmedium

A developer is using Amazon API Gateway with a Lambda authorizer to secure a REST API. The developer wants to pass user context from the authorizer to the backend Lambda function. How should the developer accomplish this?

A.Include the user context in the principal identifier returned by the authorizer.
B.Encode the user context in the authorization token.
C.Use a custom header that maps to a resource path parameter.
D.Return a context object from the Lambda authorizer that maps to integration request parameters.
AnswerD

The Lambda authorizer's output includes an optional `context` object, which is a key-value map designed specifically for passing arbitrary, trusted information to the backend integration. API Gateway automatically makes the properties within this `context` object available for mapping to various integration request parameters, such as HTTP headers, query string parameters, or even parts of the request body. This mechanism ensures that validated user context, like user ID or roles, is securely and explicitly delivered to the downstream service.

Why this answer

The Lambda authorizer can return a context object alongside the IAM policy. This context object can be mapped to integration request parameters (such as headers or path parameters) using API Gateway's mapping templates or passthrough behavior. The backend function then receives the user context via those parameters.

Option D is correct because returning a context object from the authorizer and mapping it to integration request parameters is the standard method. Option A is incorrect because the principal identifier is a single field, not suitable for passing multiple context values. Option B is incorrect because the authorization token is the input to the authorizer, not the output.

Option C is incorrect because custom headers are not automatically mapped to resource path parameters; such a mapping would not pass user context from the authorizer.

529
Drag & Dropmedium

Drag and drop the steps to set up a custom domain for an API Gateway API in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First have a domain, get a certificate, create custom domain in API Gateway, map to stage, and update DNS.

530
MCQhard

A company runs a containerized application on Amazon ECS using the Fargate launch type. The application needs to store temporary data that must persist across container restarts but does not need to be shared across multiple tasks. The data should be automatically deleted when the task stops. Which storage option should the developer use?

A.Attach an Amazon EBS volume to the task.
B.Use the ephemeral storage provided by Fargate.
C.Mount an Amazon EFS file system to the container.
D.Create a Docker volume using the 'tmpfs' driver.
AnswerB

Fargate tasks are provisioned with a certain amount of ephemeral storage, typically 20 GB by default, which is local to the task's underlying compute environment. This storage is designed for temporary data, such as application logs, caches, or scratch space, and persists for the entire lifecycle of the Fargate task. While it is deleted once the task stops, it remains available and consistent across restarts of individual containers within that same task, making it suitable for short-lived data that doesn't require long-term persistence.

Why this answer

Fargate provides ephemeral storage (up to 20 GB by default) that persists data across container restarts within the same task but is automatically deleted when the task stops. This matches the requirement for temporary data that does not need to be shared across tasks and is cleaned up upon task termination.

Exam trap

The trap here is that candidates confuse 'persist across container restarts' with 'persist across task stops,' leading them to choose Amazon EFS or EBS, which are designed for long-term persistence, while Fargate's ephemeral storage perfectly meets the temporary, task-scoped requirement.

How to eliminate wrong answers

Option A is wrong because Amazon EBS volumes cannot be directly attached to Fargate tasks; EBS volumes are only supported with EC2 launch type and require instance-level attachment, not task-level. Option C is wrong because Amazon EFS provides persistent, shared file storage that persists beyond the task lifecycle and is designed for multi-task sharing, which contradicts the requirement for data to be automatically deleted when the task stops. Option D is wrong because Docker volumes using the 'tmpfs' driver store data in memory, not on disk, and do not persist across container restarts; they are ephemeral and lost when the container stops.

531
MCQhard

A developer is deploying a web application on Amazon EKS. The application needs to read configuration data from an Amazon S3 bucket at startup. The developer wants to ensure that the configuration is securely accessed without embedding AWS credentials in the application code. Which solution should the developer use?

A.Use IAM roles for service accounts (IRSA) to assign an IAM role to the pod.
B.Store the AWS credentials in AWS Secrets Manager and retrieve them at startup.
C.Assign an IAM instance profile to the EC2 instances running the EKS nodes.
D.Embed the AWS access key and secret key in a Kubernetes ConfigMap.
AnswerA

IAM roles for service accounts (IRSA) is the recommended and most secure method for granting AWS permissions to applications running in EKS pods. It leverages an OpenID Connect (OIDC) provider associated with the EKS cluster to allow Kubernetes service accounts to assume specific IAM roles. This mechanism provides fine-grained, pod-level permissions, ensuring that each pod receives only the necessary temporary AWS credentials, thereby adhering strictly to the principle of least privilege and enhancing overall security.

Why this answer

IAM roles for service accounts (IRSA) allows you to associate an IAM role with a Kubernetes service account, which the pod can assume to obtain temporary AWS credentials via the AWS STS endpoint. This eliminates the need to embed long-term credentials in the application code or environment variables, and the credentials are automatically rotated by the AWS SDK. The pod retrieves the configuration from S3 using the assumed role's permissions, ensuring secure access.

Exam trap

The trap here is that candidates may confuse IRSA with IAM instance profiles, thinking that assigning a role to the node is sufficient, but IRSA is the correct method for pod-level IAM permissions in EKS.

How to eliminate wrong answers

Option B is wrong because storing AWS credentials in AWS Secrets Manager still requires the application to retrieve them at startup, which introduces a credential management overhead and a potential attack surface if the retrieval itself is not secured; it does not eliminate the need to handle long-term credentials. Option C is wrong because assigning an IAM instance profile to the EC2 nodes grants permissions to all pods running on those nodes, violating the principle of least privilege and potentially allowing unintended access to the S3 bucket. Option D is wrong because embedding AWS access keys in a Kubernetes ConfigMap exposes the credentials in plaintext within the cluster, which is a severe security risk and violates AWS best practices.

532
MCQhard

A developer needs to grant a user in another AWS account (Account B) read-only access to objects in an Amazon S3 bucket owned by Account A. The developer has already added a bucket policy that grants s3:GetObject access to the IAM user in Account B. However, the user in Account B still gets Access Denied when trying to read objects. What additional configuration is required?

A.The user in Account B must have an IAM policy that allows s3:GetObject on the bucket ARN
B.The bucket must be made public by unchecking 'Block all public access'
C.The developer must create a new IAM role in Account A and have the user in Account B assume that role
D.The user in Account B must use the S3 console instead of the AWS CLI
AnswerA

Cross-account access requires both a bucket policy that grants the user permissions and an IAM policy in the user's account that allows the action. The IAM policy is necessary because the default is to deny all actions.

Why this answer

The bucket policy in Account A grants s3:GetObject access to the IAM user in Account B, but this alone is insufficient. For cross-account access, the IAM user in Account B must also have an IAM policy attached that explicitly allows s3:GetObject on the bucket ARN. Without this, the user’s own account denies the request before it reaches Account A’s bucket policy, resulting in Access Denied.

Exam trap

The trap here is that candidates assume a bucket policy alone is sufficient for cross-account access, overlooking the requirement for an explicit IAM policy in the requesting account to allow the action.

How to eliminate wrong answers

Option B is wrong because making the bucket public by unchecking 'Block all public access' would grant anonymous access to everyone, which violates the principle of least privilege and is not required for a specific cross-account user. Option C is wrong because while creating an IAM role in Account A and having the user in Account B assume it is a valid alternative approach, it is not the additional configuration required here—the developer has already chosen a bucket policy approach, and the missing piece is the IAM policy in Account B. Option D is wrong because the S3 console and AWS CLI both enforce the same IAM permissions; the issue is a lack of permissions, not the tool used.

533
MCQeasy

A developer is troubleshooting a slow Amazon RDS MySQL database query. The query is frequently executed and takes 5 seconds to complete. Which AWS service should the developer use to analyze the query performance?

A.AWS CloudTrail
B.Amazon RDS Performance Insights
C.Amazon CloudWatch Logs
D.AWS X-Ray
AnswerB

Performance Insights is purpose-built for this scenario: it visualizes database load as Average Active Sessions, breaks load down by SQL statement, wait event, host, and user, and lets the developer pinpoint exactly which query is consuming the most database time and why.

Why this answer

Amazon RDS Performance Insights is the correct service to analyze query performance on an RDS MySQL database. It provides a dashboard that visualizes database load and helps identify the top SQL statements, wait events, and users consuming the most resources. This allows the developer to pinpoint the slow query and understand its impact.

Exam trap

DVA-C02 often tests the confusion between monitoring services like CloudWatch and specialized database performance tools like Performance Insights, leading candidates to choose CloudWatch Logs for query analysis.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity and management events, not database query performance. Option C is wrong because Amazon CloudWatch Logs can capture database logs, but it does not provide the detailed performance analysis and visualization that Performance Insights offers; it would require manual parsing and analysis. Option D is wrong because AWS X-Ray is used for tracing requests in distributed applications, not for analyzing database query performance.

534
MCQeasy

A developer needs to store application configuration settings that may change at runtime and wants to avoid redeploying the application. Which AWS service should be used?

A.AWS Systems Manager Parameter Store
B.AWS Secrets Manager
C.Amazon DynamoDB
D.AWS AppConfig
AnswerD

AWS AppConfig is purpose-built for managing and deploying application configurations dynamically and safely across various environments. It provides robust features such as configuration validation against a schema, staged rollouts (e.g., linear, canary deployments) to gradually expose changes, and automatic rollback capabilities if errors are detected. This ensures that configuration changes are applied reliably without requiring code deployments or service restarts, minimizing impact on end-users and maintaining application stability.

Why this answer

AWS AppConfig is purpose-built for managing application configuration that changes at runtime, supporting feature flags, dynamic configuration, and safe deployments with validation and rollback. It allows applications to fetch configuration via the AppConfig agent or API without redeploying, and integrates with CloudWatch alarms for automatic rollback on errors.

Exam trap

DVA-C02 often tests the confusion between Parameter Store (static config/secrets) and AppConfig (dynamic runtime config with safe deployment) — candidates must recognize that 'changes at runtime without redeployment' points to AppConfig.

How to eliminate wrong answers

Option A is wrong because Systems Manager Parameter Store is designed for static configuration values and secrets, not for runtime feature flags with safe deployment and validation — it lacks AppConfig's gradual rollout and automatic rollback capabilities. Option B is wrong because Secrets Manager is specifically for storing and rotating secrets (database credentials, API keys), not general application configuration that changes at runtime. Option C is wrong because DynamoDB is a NoSQL database for application data storage, not a configuration management service — using it for config requires custom polling logic and lacks validation/rollback features.

535
MCQeasy

An e-commerce platform uses AWS CodePipeline to deploy a web application to an Auto Scaling group behind an Application Load Balancer. The deployment strategy must minimize downtime and allow immediate rollback if the new version fails health checks. Which deployment configuration meets these requirements?

A.Use blue/green deployment with an immutable infrastructure.
B.Use all-at-once deployment to the Auto Scaling group.
C.Use canary deployment shifting 10% traffic for 5 minutes.
D.Use in-place rolling update with a batch size of 50%.
AnswerA

Blue/green deployment with immutable infrastructure creates an entirely new, identical environment (green) with the updated application version, leaving the existing production environment (blue) untouched. Once the green environment passes all health checks and tests, traffic is atomically shifted from blue to green. This strategy ensures zero downtime during deployment and provides an instant rollback capability by simply reverting traffic back to the healthy, unchanged blue environment if any issues arise with the new version.

Why this answer

Blue/green deployment with immutable infrastructure minimizes downtime by running the new version (green) alongside the old (blue) and switching traffic only after health checks pass. If the new version fails, rollback is immediate by routing traffic back to the blue environment without redeploying. AWS CodePipeline supports this via CodeDeploy with a blue/green configuration, ensuring zero-downtime deployments and instant rollback capability.

Exam trap

The trap here is that candidates confuse canary or rolling updates with immediate rollback capability, but only blue/green provides an instant traffic switch without redeployment, as the old environment remains intact.

How to eliminate wrong answers

Option B is wrong because all-at-once deployment replaces all instances simultaneously, causing downtime during the deployment and no ability to rollback without redeploying the old version. Option C is wrong because canary deployment shifts only 10% traffic for 5 minutes, which does not guarantee immediate rollback of the entire fleet if the new version fails; it requires manual or automated traffic shifting back, which is not instantaneous. Option D is wrong because in-place rolling update with a batch size of 50% replaces instances gradually but still causes partial downtime and requires a full redeployment to rollback, as the old instances are terminated during the update.

536
Multi-Selectmedium

A company is using AWS CodeBuild to build a Docker image and push it to Amazon ECR. Which permissions are required for the CodeBuild service role? (Choose THREE.)

Select 3 answers
A.ecr:PutImage
B.ecr:DescribeRepositories
C.ecr:CreateImage
D.ecr:BatchGetImage
E.ecr:GetAuthorizationToken
AnswersA, B, E

The `ecr:PutImage` permission is absolutely essential for CodeBuild to successfully publish a Docker image to an Amazon ECR repository. This API call is responsible for uploading the Docker image manifest and all its associated image layers, effectively registering the new image version within the specified repository and making it available for subsequent deployments or pulls.

Why this answer

`ecr:PutImage` is the permission required to push a Docker image to an Amazon ECR repository. When CodeBuild completes a build and runs `docker push`, it calls the ECR API `PutImage` to upload the image manifest. Without this permission, the push operation will fail with an access denied error.

Exam trap

The trap here is that candidates may confuse `ecr:PutImage` with the non-existent `ecr:CreateImage` or mistakenly think `ecr:BatchGetImage` is needed for pushing, when in fact it is only used for pulling images.

537
Multi-Selectmedium

Which TWO actions can be taken to enable automatic rollback for an AWS CloudFormation stack update that fails? (Select TWO.)

Select 2 answers
A.Set the '--on-failure' parameter to 'ROLLBACK' during stack update.
B.Specify a CloudWatch alarm in the '--rollback-configuration' parameter during stack update.
C.Use a change set to review the changes before updating.
D.Apply a stack policy that denies updates to critical resources.
E.Set the '--disable-rollback' parameter to 'false' during stack update.
AnswersB, E

Specifying a CloudWatch alarm within the '--rollback-configuration' parameter during a stack update is a powerful mechanism for enabling automatic rollback. This configuration allows CloudFormation to monitor the specified alarm(s) for a defined period after the update completes. If any of these alarms transition into an ALARM state, CloudFormation will automatically initiate a rollback of the stack to its previous stable state, ensuring operational stability.

Why this answer

The `--rollback-configuration` parameter allows you to specify a CloudWatch alarm that, when triggered during a stack update, automatically initiates a rollback. This is the intended mechanism for monitoring-based automatic rollback, as CloudFormation will monitor the alarm state and revert the update if the alarm enters the ALARM state. Option E is correct because setting `--disable-rollback` to `false` explicitly enables automatic rollback on any stack update failure, which is the default behavior but can be explicitly configured for clarity.

Exam trap

The trap here is that candidates confuse the `--on-failure` parameter (which only applies to stack creation) with stack update rollback, or they assume that a stack policy or change set can trigger automatic rollback, when in fact only `--rollback-configuration` and `--disable-rollback` control automatic rollback behavior during updates.

538
MCQeasy

A developer stores database credentials for an application running on Amazon EC2. The security team requires that the credentials be automatically rotated every 30 days to reduce the risk of compromise. Which AWS service should the developer use to store and automatically rotate the credentials?

A.AWS Systems Manager Parameter Store
B.AWS Secrets Manager
C.AWS Key Management Service (KMS)
D.IAM Roles for EC2
AnswerB

AWS Secrets Manager is purpose-built for managing, retrieving, and rotating database credentials, API keys, and other secrets throughout their lifecycle. It provides native, automatic rotation capabilities for various services, including Amazon RDS, Amazon Redshift, and Amazon DocumentDB, with configurable schedules (e.g., every 30 days). This eliminates the need for manual rotation or complex custom solutions, significantly enhancing security posture by regularly changing credentials.

Why this answer

AWS Secrets Manager is the correct choice because it is specifically designed to securely store database credentials and other secrets, and it provides built-in, configurable automatic rotation (e.g., every 30 days) using AWS Lambda. This meets the security team's requirement without custom scripting or infrastructure management.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store (which can store secrets but lacks native automatic rotation) with AWS Secrets Manager, leading them to choose Parameter Store for its lower cost or familiarity, despite the explicit rotation requirement.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager Parameter Store can store credentials but does not natively support automatic rotation; rotation would require custom automation with Lambda or other services, making it less suitable for this requirement. Option C is wrong because AWS Key Management Service (KMS) is a key management service for encryption keys, not for storing or rotating database credentials; it can encrypt secrets but does not manage rotation of the credentials themselves. Option D is wrong because IAM Roles for EC2 provide temporary credentials for AWS API access, not for storing or rotating database credentials; they cannot be used to store or rotate application-level database passwords.

539
MCQhard

A company runs a critical application on AWS Lambda that processes real-time data from Kinesis Data Streams. The function is idempotent, but occasionally duplicate records are processed due to retries. The company wants to ensure exactly-once processing. Which approach should the developer implement?

A.Use an SQS FIFO queue between Kinesis and Lambda.
B.Use a DynamoDB table to store processed record IDs and perform deduplication in the Lambda function.
C.Enable Lambda reserved concurrency to limit retries.
D.Reduce the batch size in the event source mapping.
AnswerB

Implementing a deduplication mechanism within the Lambda function using a DynamoDB table is the standard and most effective approach for achieving exactly-once processing semantics from Kinesis. The Lambda function can store a unique identifier for each processed record (e.g., a combination of Kinesis shard ID and sequence number) in a DynamoDB table. Before processing a new record, the function checks if its ID already exists in DynamoDB; if so, it skips processing, ensuring that even if Kinesis retries delivery, the record's side effects occur only once.

Why this answer

DynamoDB provides a scalable, low-latency store for tracking processed record IDs, enabling the Lambda function to check for duplicates before processing. Since the function is idempotent but retries cause duplicates, a DynamoDB-based deduplication layer ensures exactly-once semantics without altering the event source or introducing ordering constraints.

Exam trap

The trap here is that candidates often assume SQS FIFO queues guarantee exactly-once processing end-to-end, but they overlook that Kinesis itself does not provide exactly-once delivery, so duplicates can still originate from the stream before reaching the queue.

How to eliminate wrong answers

Option A is wrong because inserting an SQS FIFO queue between Kinesis and Lambda does not eliminate duplicates from Kinesis itself; Kinesis can still deliver the same record multiple times, and SQS FIFO does not deduplicate across different message groups or handle Kinesis-level retries. Option C is wrong because Lambda reserved concurrency limits the number of concurrent executions but does not prevent duplicate records from being processed; retries can still occur within the same or different invocations. Option D is wrong because reducing the batch size in the event source mapping reduces the number of records per invocation but does not prevent Kinesis from redelivering the same record on retries, so duplicates persist.

540
MCQeasy

A developer is using AWS CodeDeploy to deploy an application to an EC2 instance. The deployment fails with the error 'ScriptMissing' during the BeforeInstall lifecycle event. What is the most likely cause?

A.The BeforeInstall lifecycle event is not defined in the appspec.yml
B.The script file specified in the appspec.yml for the BeforeInstall hook is not present on the instance
C.The CodeDeploy agent on the instance is not running
D.The instance does not have the necessary permissions to execute the script
AnswerB

This is the correct explanation. When CodeDeploy executes a deployment, it first downloads the application revision to the instance. If the appspec.yml specifies a script for the BeforeInstall hook, and the CodeDeploy agent cannot locate that script file at the specified path within the downloaded revision on the target instance, it will explicitly fail with a "ScriptMissing" error. This error precisely indicates that the expected script file is physically absent from the instance's file system where the agent is looking.

Why this answer

The 'ScriptMissing' error in AWS CodeDeploy indicates that the deployment failed because a script file referenced in the appspec.yml for a lifecycle event (in this case, BeforeInstall) could not be found on the EC2 instance. CodeDeploy expects the script to be present at the specified path after the archive is extracted; if the file is missing or the path is incorrect, the agent reports this error. Option B correctly identifies that the script file is not present on the instance.

Exam trap

The trap here is that candidates confuse 'ScriptMissing' with permission issues or agent connectivity problems, but AWS CodeDeploy has distinct error codes for each failure mode, and 'ScriptMissing' specifically points to a missing file, not execution or agent status.

How to eliminate wrong answers

Option A is wrong because if the BeforeInstall lifecycle event is not defined in the appspec.yml, CodeDeploy would simply skip that event and not produce a 'ScriptMissing' error — the error specifically occurs when a hook is defined but its script is absent. Option C is wrong because if the CodeDeploy agent were not running, the deployment would fail with an 'AgentNotRunning' or 'InstanceUnreachable' error, not a 'ScriptMissing' error. Option D is wrong because insufficient permissions to execute the script would result in a 'ScriptFailed' error (e.g., exit code 126 or 127), not a 'ScriptMissing' error — the agent first checks for the file's existence before attempting execution.

541
Multi-Selectmedium

Which TWO are best practices for securing an AWS account? (Choose 2)

Select 2 answers
A.Disable AWS CloudTrail to reduce costs
B.Disable password rotation to avoid user inconvenience
C.Use the root user for daily administrative tasks
D.Enable multi-factor authentication (MFA) for privileged users
E.Use IAM roles for applications that run on EC2 instances
AnswersD, E

MFA adds a second authentication factor, such as a time-based one-time password (TOTP) from a hardware or virtual device, significantly reducing the risk of unauthorized access even if a password is compromised. For privileged users with access to sensitive resources, MFA is a critical control defined in the AWS Well-Architected Framework. It protects against credential theft and phishing attacks.

Why this answer

The best practices for securing an AWS account include enabling multi-factor authentication (MFA) for privileged users (Option D) and using IAM roles for applications that run on EC2 instances (Option E). Option A is incorrect because disabling CloudTrail reduces visibility into API activity, which is a security risk. Option B is incorrect because disabling password rotation weakens security posture.

Option C is incorrect because the root user should be reserved for a limited set of tasks and not used daily.

Exam trap

This question tests knowledge of AWS security best practices. A common trap is to assume that disabling CloudTrail saves costs without considering security implications, or that password rotation should be disabled for convenience.

542
MCQmedium

An AWS Lambda function processes messages from an Amazon SQS queue and writes results to an Amazon DynamoDB table. The function is configured with a reserved concurrency of 5 and a batch size of 10. CloudWatch metrics show high throttling and a growing queue backlog. The function's execution time averages 1 second per message. What is the MOST effective action to reduce throttling while improving throughput?

A.Increase the reserved concurrency to 20.
B.Increase the batch size to 100.
C.Decrease the reserved concurrency to 2.
D.Increase the provisioned write capacity of the DynamoDB table.
AnswerA

Increasing reserved concurrency allows Lambda to scale and invoke more function instances concurrently. This directly reduces throttling and allows the function to process more messages from the SQS queue simultaneously, improving throughput and reducing backlog.

Why this answer

The Lambda function is throttling because its reserved concurrency of 5 limits it to 5 concurrent executions. With a batch size of 10 and 1-second execution time, the function can process at most 5 * 10 = 50 messages per second. Increasing reserved concurrency to 20 allows 20 concurrent executions, raising throughput to 200 messages per second, which directly reduces throttling and clears the backlog.

Exam trap

The trap here is that candidates may confuse Lambda throttling with downstream resource throttling (like DynamoDB) and choose to increase write capacity, or they may think increasing batch size alone will solve the problem without considering the concurrency bottleneck.

How to eliminate wrong answers

Option B is wrong because increasing batch size to 100 would cause each invocation to process more messages, but with only 5 concurrent executions, the function would still be limited to 5 invocations at a time, and the 1-second execution time per message would scale linearly, likely causing timeouts or increased latency without addressing the root cause of throttling. Option C is wrong because decreasing reserved concurrency to 2 would reduce throughput to 20 messages per second, worsening throttling and backlog. Option D is wrong because increasing DynamoDB write capacity addresses potential write throttling from DynamoDB, but the CloudWatch metrics show Lambda throttling, not DynamoDB throttling; the bottleneck is Lambda concurrency, not the database.

543
MCQmedium

A developer is using AWS CloudFormation to deploy a stack that includes an Amazon EC2 instance with user data. The user data script installs software and configures the application. The developer wants to ensure that the stack creation waits for the user data script to complete before marking the stack as CREATE_COMPLETE. What should the developer do?

A.Add a DependsOn attribute to the EC2 instance resource.
B.Use a CloudFormation WaitCondition and a WaitConditionHandle.
C.Add a CreationPolicy with a timeout to the EC2 instance resource and use cfn-signal in the user data.
D.Configure the EC2 instance to run the user data script as a service.
AnswerC

Adding a `CreationPolicy` with a `ResourceSignal` property, including a `Timeout` and `Count`, to an EC2 instance resource instructs CloudFormation to wait for a specified number of success signals from the instance before marking its creation as complete. The `cfn-signal` helper script, executed within the instance's user data, sends these signals back to CloudFormation, indicating the successful completion of the user data script and any application setup. This ensures the instance is fully configured and ready before the stack proceeds.

Why this answer

The correct approach is to add a CreationPolicy to the EC2 instance resource and use cfn-signal in the user data script. The CreationPolicy tells CloudFormation to wait for a signal from the instance before considering the resource created. The user data script runs, installs software, and then calls cfn-signal to indicate success.

If the signal is not received within the timeout, the stack creation fails. Option A (DependsOn) only orders resource creation, not waits for user data. Option B (WaitCondition) is a legacy method that is more complex; CreationPolicy is the recommended modern approach.

Option D (running as a service) does not send any signal to CloudFormation.

544
MCQmedium

A developer is using AWS CodePipeline to automate deployments. The pipeline has a manual approval action that requires a developer to approve before deploying to production. The developer wants to receive an email notification when an approval action is pending. Which AWS service should be used to send the notification?

A.Amazon Simple Email Service (SES)
B.AWS Lambda
C.Amazon Simple Notification Service (SNS)
D.Amazon CloudWatch Logs
AnswerC

Amazon Simple Notification Service (SNS) is a highly scalable, fully managed pub/sub messaging service that enables you to send messages to a large number of subscribers or endpoints. CodePipeline natively integrates with SNS, allowing developers to configure notifications for pipeline state changes, approval actions, or execution failures to an SNS topic. This topic can then reliably deliver these alerts via various protocols, including email, SMS, or to other AWS services, making it the direct and most efficient solution for email notifications.

Why this answer

Amazon Simple Notification Service (SNS) is the correct choice because it is a pub/sub messaging service designed to send notifications to subscribers via email, SMS, or other protocols. CodePipeline can publish events to an SNS topic when an approval action is pending, and the developer can subscribe an email endpoint to that topic to receive the notification directly.

Exam trap

The trap here is that candidates may confuse Amazon SES with SNS because both can send emails, but SES is a dedicated email-sending service requiring manual integration, whereas SNS is the native event notification service that directly integrates with CodePipeline's approval actions.

How to eliminate wrong answers

Option A is wrong because Amazon Simple Email Service (SES) is a platform for sending transactional and marketing emails, but it is not integrated with CodePipeline's event-driven notifications; SES requires explicit API calls or SMTP configuration and does not natively subscribe to CodePipeline events. Option B is wrong because AWS Lambda is a compute service that can process events, but it is not a notification delivery service; while Lambda could be used to send emails via SES, it adds unnecessary complexity and is not the direct service for sending email notifications from a CodePipeline approval action. Option D is wrong because Amazon CloudWatch Logs is a service for storing, monitoring, and accessing log files; it does not send notifications and is not designed for real-time alerting to email endpoints.

545
Multi-Selecteasy

A developer is using AWS Step Functions to orchestrate a workflow. The developer wants to handle errors and retries for a task. Which TWO fields can be used in a state definition to configure error handling? (Choose TWO.)

Select 2 answers
A.Retry
B.Catch
C.FailureState
D.ErrorOutput
E.ErrorAction
AnswersA, B

In AWS Step Functions, the "Retry" field within a state definition allows a developer to specify a retry policy for transient errors. It defines which errors ("ErrorEquals"), how many times ("MaxAttempts"), and with what delay ("IntervalSeconds" and "BackoffRate") the state should be re-executed before failing. This mechanism is crucial for building resilient workflows that can automatically recover from temporary issues without manual intervention.

Why this answer

The `Retry` field in an AWS Step Functions state definition defines an array of retry policies, specifying which errors to retry, the maximum number of retry attempts, the interval between retries, and the backoff rate. Option B is correct because the `Catch` field defines an array of fallback states or state machine transitions that are executed when a specific error occurs after all retry attempts are exhausted, allowing the workflow to handle errors gracefully.

Exam trap

The trap here is that candidates often confuse the `Retry` and `Catch` fields with non-existent fields like `FailureState` or `ErrorAction`, or they mistakenly think `ErrorOutput` is used to capture error details, when in fact Step Functions uses `ResultPath` to include error information in the state output.

546
MCQeasy

A developer is deploying a new version of a Lambda function using an AWS CodePipeline pipeline. The deployment fails during the 'Deploy' stage with an error indicating that the function's code is too large. What should the developer do to resolve this issue?

A.Upload the Lambda deployment package to Amazon S3 and reference it from the function
B.Increase the Lambda function's timeout setting
C.Use Amazon CloudFront to distribute the Lambda code
D.Enable AWS X-Ray tracing on the Lambda function
AnswerA

The AWS Lambda service imposes a direct upload limit of 50 MB for deployment packages. For larger codebases or dependencies, developers must upload the deployment package, which can be up to 250 MB unzipped, to an Amazon S3 bucket. Referencing the S3 object's key and version from the Lambda function configuration allows the service to retrieve the code, circumventing the direct upload size constraint and enabling successful deployment of substantial applications.

Why this answer

AWS Lambda has a hard limit of 50 MB for direct uploads via the console or API. When a deployment package exceeds this limit, the correct approach is to upload the package to Amazon S3 and configure the Lambda function to reference the S3 object. CodePipeline can then use the S3 location to deploy the function, bypassing the direct upload size restriction.

Exam trap

The trap here is that candidates may confuse Lambda's execution timeout or memory limits with the deployment package size limit, or incorrectly assume that CloudFront can serve as a storage backend for Lambda code.

How to eliminate wrong answers

Option B is wrong because increasing the timeout setting does not affect the deployment package size limit; timeouts control execution duration, not code storage. Option C is wrong because CloudFront is a content delivery network (CDN) for caching and distributing static content, not a service for storing or deploying Lambda code; it cannot resolve a code size limit. Option D is wrong because enabling X-Ray tracing adds monitoring and debugging capabilities but does not change the Lambda deployment package size quota.

547
MCQmedium

A developer is troubleshooting an application that uses Amazon ElastiCache for Redis to improve performance. The application periodically experiences high latency during peak hours. The developer checks the ElastiCache metrics and sees that the 'Evictions' metric is consistently high and the 'CacheHitRate' metric is low. The cluster has a single node with a cache.t3.small instance type. Which action will most likely improve the cache hit rate and reduce latency?

A.Scale up to a larger node type (e.g., cache.t3.medium) to increase available memory.
B.Enable cluster mode and distribute data across multiple shards to reduce memory pressure.
C.Change the eviction policy to 'allkeys-lfu' to better manage which keys are evicted.
D.Add a read replica for the Redis cluster to offload read traffic.
AnswerA

Scaling up to a larger node type directly increases the available RAM for the Redis instance. This additional memory allows the cache to store more data, significantly reducing the frequency of key evictions caused by memory pressure. Consequently, the cache hit rate improves, as more requested data is found in cache, leading to lower latency and better application performance by minimizing database lookups.

Why this answer

The high 'Evictions' and low 'CacheHitRate' metrics indicate that the Redis node is running out of memory, forcing it to evict keys to make room for new data. Scaling up to a larger node type (cache.t3.medium) increases the available memory, allowing more data to be cached and reducing evictions, which directly improves the cache hit rate and reduces latency.

Exam trap

The trap here is that candidates may focus on optimizing eviction policies or adding replicas, but the core issue is insufficient memory capacity, which only scaling up can resolve.

How to eliminate wrong answers

Option B is wrong because enabling cluster mode and distributing data across multiple shards does not increase the total memory per node; it only partitions data, and if the total memory across shards is insufficient, evictions will still occur. Option C is wrong because changing the eviction policy to 'allkeys-lfu' only changes which keys are evicted (least frequently used) but does not address the root cause of insufficient memory; evictions will continue at the same rate. Option D is wrong because adding a read replica offloads read traffic but does not increase the primary node's memory, so evictions and low cache hit rate will persist on the primary node.

548
Multi-Selecteasy

A developer is using AWS X-Ray to trace requests through a microservices application. The developer notices that some traces are incomplete. Which TWO actions can help ensure complete traces?

Select 2 answers
A.Use the X-Ray SDK to instrument the application code.
B.Open port 2000 on the security groups for TCP traffic.
C.Deploy the X-Ray daemon as a centralized service in a separate instance.
D.Install the CloudWatch agent on all instances.
E.Ensure the X-Ray daemon is running on all EC2 instances.
AnswersA, E

The X-Ray SDK must be integrated directly into the application code because it is what creates trace data in the first place. For supported web frameworks, middleware or interceptors automatically capture incoming HTTP requests, generate a trace ID, manage segments and subsegments, and propagate the X-Amzn-Trace-Id header to downstream services. The SDK then sends completed segments to the local X-Ray daemon over UDP port 2000 for eventual upload to the X-Ray API. Without this code-level instrumentation, a request never becomes a trace, regardless of daemon status or network configuration.

Why this answer

Option A is correct because the X-Ray SDK must be used to instrument the application code so that it emits segment data and propagates trace headers across service calls; without instrumentation, downstream services cannot contribute subsegments and traces remain incomplete. Option E is correct because the X-Ray daemon must be running on every EC2 instance (or equivalent compute) to receive UDP segment data from the SDK on port 2000 and forward it to the X-Ray API; a missing daemon on any instance means those segments are dropped, producing incomplete traces. Option B is not correct because opening port 2000 in a security group is not required for the daemon to receive local UDP traffic from the SDK on the same host, and it does not by itself fix incomplete traces.

Option C is not correct because the X-Ray daemon is designed to run locally on each instance (or as a sidecar/daemon set), not as a single centralized service, so centralizing it would not ensure all instances' segments are captured. Option D is not correct because the CloudWatch agent collects metrics and logs, not X-Ray trace segments, so it does not contribute to complete X-Ray traces.

Exam trap

The trap is thinking that network configuration (port 2000) or centralized daemon deployment solves incomplete traces, when the real requirements are SDK instrumentation and a running daemon on every instance.

549
MCQeasy

A developer is building a serverless application using AWS Lambda. The Lambda function needs to write logs to CloudWatch Logs. What is the recommended way to grant the necessary permissions?

A.Use AWS KMS to encrypt the log data and grant permissions.
B.Attach an IAM execution role with CloudWatch Logs permissions.
C.Create a resource-based policy on the Lambda function.
D.Store AWS access keys in environment variables.
AnswerB

Attaching an IAM execution role to the Lambda function is the standard and most secure method for granting it permissions to interact with other AWS services. When the Lambda function executes, it assumes this role, which dictates its authorized actions. To enable the function to write logs to CloudWatch, the attached IAM role must include policies explicitly granting permissions such as `logs:CreateLogGroup`, `logs:CreateLogStream`, and `logs:PutLogEvents`.

Why this answer

AWS Lambda uses an IAM execution role to obtain temporary credentials for accessing other AWS services. To allow a Lambda function to write logs to CloudWatch Logs, you must attach an IAM role with a policy that includes permissions for the `logs:CreateLogGroup`, `logs:CreateLogStream`, and `logs:PutLogEvents` actions. This is the standard and recommended security practice for granting permissions to Lambda functions.

Exam trap

The trap here is that candidates often confuse resource-based policies (which control who can invoke the function) with execution roles (which control what the function can do), leading them to incorrectly select option C.

How to eliminate wrong answers

Option A is wrong because AWS KMS is used for encryption key management, not for granting permissions; it does not provide IAM-level access control for writing logs. Option C is wrong because resource-based policies on a Lambda function control who can invoke the function, not what the function itself can do (like writing to CloudWatch Logs); permissions for the function's actions are defined in its execution role. Option D is wrong because storing AWS access keys in environment variables is a security anti-pattern; Lambda should never use long-term credentials, and instead relies on the IAM execution role to provide temporary, automatically rotated credentials.

550
Multi-Selecteasy

A company uses AWS CodeBuild to compile and test a Java application. The build process takes a long time because dependencies are downloaded every time. Which TWO actions can reduce build time? (Choose TWO.)

Select 2 answers
A.Increase the compute type of the build environment to have more CPU and memory.
B.Change the build runtime to a language that compiles faster.
C.Configure the build project to run builds in parallel.
D.Enable local caching in the CodeBuild project to reuse dependency files between builds.
E.Use Amazon S3 to cache dependencies and restore them at the start of each build.
AnswersD, E

Local caching in CodeBuild stores specific directories, such as /root/.m2 for Maven or /root/.gradle for Gradle, on the build instance's local disk, keyed by the project and optionally by a custom cache key. On subsequent builds, if the same instance is reused, downloaded dependency JARs are restored from the local cache instead of being fetched from the internet, eliminating the network latency that dominates a cold build. To make it effective, you must configure a cache key that changes only when dependencies actually change, so identical builds skip the download entirely.

Why this answer

Option D is correct because enabling local caching in the CodeBuild project (e.g., LOCAL_SOURCE_CACHE, LOCAL_DOCKER_LAYER_CACHE, or a local cache for dependency directories) lets CodeBuild retain downloaded dependencies on the build host between builds, so Maven/Gradle artifacts are not re-downloaded each time, directly cutting build duration. Option E is correct because CodeBuild supports S3 caching, where dependency files (such as the Maven ~/.m2 or Gradle ~/.gradle directories) are uploaded to an S3 bucket after a build and restored at the start of subsequent builds, eliminating repeated downloads even across fresh hosts. Option A is not correct because increasing compute type only adds CPU/memory and does not address the network-bound dependency download bottleneck, so it does not reliably reduce the time spent fetching dependencies.

Option B is not correct because changing the build runtime to a 'faster-compiling language' is not applicable—the application is Java and the runtime must support Java compilation. Option C is not correct because running builds in parallel increases throughput of multiple builds but does not shorten the duration of an individual build's dependency download phase.

Exam trap

DVA-C02 often tests the misconception that more compute or parallel builds solve slow builds, when the actual issue is repeated dependency downloads that require caching.

551
MCQmedium

An application running on an EC2 instance needs to access a DynamoDB table. The instance is in a private subnet without internet access. Which method should be used to grant the instance access to DynamoDB securely?

A.Store AWS credentials in a file on the instance and use them in the application
B.Configure security group rules to allow outbound traffic to DynamoDB
C.Attach a NAT gateway to the private subnet and use IAM user credentials
D.Create a VPC endpoint for DynamoDB and attach an IAM role to the instance
AnswerD

Creating a VPC endpoint for DynamoDB establishes a private, secure connection directly from the VPC to the DynamoDB service, bypassing the public internet and enhancing data security and network performance. Concurrently, attaching an IAM role to the EC2 instance provides temporary, automatically rotated credentials that the application can assume, adhering to the principle of least privilege and eliminating the need to store static credentials on the instance. This combination offers both secure network access and robust authentication.

Why this answer

A VPC Gateway Endpoint for DynamoDB allows EC2 instances in a private subnet to access DynamoDB without traversing the internet or requiring a NAT gateway. By attaching an IAM role to the EC2 instance, the application can securely obtain temporary credentials via the instance metadata service, eliminating the need to store long-term credentials on the instance.

Exam trap

The trap here is that candidates often confuse security groups with network routing, assuming that allowing outbound traffic to DynamoDB's IP range is sufficient, but without a VPC endpoint or internet gateway, the traffic has no route to reach the DynamoDB service.

How to eliminate wrong answers

Option A is wrong because storing AWS credentials in a file on the instance is a security risk and violates the principle of least privilege; it also requires managing long-term keys, which can be rotated or compromised. Option B is wrong because security groups control network traffic at the instance level, but DynamoDB is a managed service outside the VPC; without a VPC endpoint or internet access, security group rules alone cannot route traffic to DynamoDB. Option C is wrong because a NAT gateway would provide internet access, but it introduces additional cost and complexity, and using IAM user credentials on the instance still requires managing long-term keys; the recommended approach is to use an IAM role with a VPC endpoint.

552
MCQmedium

A developer is building a serverless application using an API Gateway HTTP API and Lambda. The developer needs to authenticate users with a JWT token. Which API Gateway feature should be used?

A.Lambda Authorizer
B.IAM Authorizer
C.JWT Authorizer
D.Amazon Cognito User Pools
AnswerC

An API Gateway JWT authorizer (also known as a native OIDC/OAuth 2.0 authorizer) is specifically designed to validate JSON Web Tokens (JWTs) issued by a third-party OpenID Connect (OIDC) or OAuth 2.0 compliant identity provider. It declaratively configures the issuer URL and audience, allowing API Gateway to automatically fetch public keys, verify the token's signature, expiration, and claims without custom code. This makes it the most direct and efficient solution for authenticating existing JWTs.

Why this answer

API Gateway HTTP APIs support JWT Authorizers natively. This feature allows API Gateway to validate JSON Web Tokens (JWTs) directly without invoking a Lambda function, verifying the token's signature, expiry, and issuer against a configured identity provider (such as Amazon Cognito or any OIDC-compliant provider). This is the most efficient and cost-effective way to handle JWT authentication in HTTP APIs.

Exam trap

The trap is that candidates often assume they need a custom Lambda Authorizer to validate JWTs, or confuse REST API authorizers with HTTP API authorizers. For HTTP APIs, a native JWT Authorizer should be used instead of a custom Lambda Authorizer to reduce latency and cost.

How to eliminate wrong answers

Option A is wrong because a Lambda Authorizer (formerly Custom Authorizer) is used when you need custom validation logic beyond simple JWT verification, such as calling an external identity provider or performing complex claims mapping; it introduces unnecessary latency and cost for straightforward JWT validation. Option B is wrong because IAM Authorizer uses AWS Signature Version 4 (SigV4) for request signing and is intended for AWS service-to-service or IAM user authentication, not for validating externally-issued JWTs. Option D is wrong because Amazon Cognito User Pools is a full identity provider that issues JWTs, but it is not an API Gateway authorizer feature; you would still need to use a JWT Authorizer or Lambda Authorizer to validate those tokens in API Gateway.

553
MCQhard

A Lambda function using a Kinesis event source repeatedly retries one bad record and blocks progress in the shard. Which feature helps isolate failed records after retry limits?

A.Increase memory to 10 GB only
B.Disable batch processing
C.Configure failure handling with bisect batch on error and an on-failure destination where supported
D.Convert the stream to an S3 bucket
AnswerC

Configuring `ReportBatchItemFailures` (often referred to as "bisect batch on error" in the console) for a Kinesis event source allows the Lambda function to return a partial success, indicating which specific records within a batch failed. Lambda then automatically retries only the failed records, potentially splitting the batch further to isolate the problematic items. Combining this with an on-failure destination, such as an SQS queue or SNS topic, ensures that records that ultimately cannot be processed are sent to a dead-letter queue for analysis and manual intervention, preventing them from indefinitely blocking the stream processing.

Why this answer

Lambda's Kinesis event source mapping supports a 'bisect batch on error' feature that splits a failed batch into two smaller batches, allowing the bad record to be isolated and retried separately. Additionally, configuring an on-failure destination (e.g., an SQS queue or SNS topic) sends the record to a dead-letter destination after the retry limit is exhausted, preventing the shard from blocking progress.

Exam trap

The trap here is that candidates often think increasing memory or disabling batch processing will solve the blocking issue, but they fail to recognize that only explicit failure handling with bisect and a dead-letter destination can isolate and remove the bad record without manual intervention.

How to eliminate wrong answers

Option A is wrong because increasing memory to 10 GB only allocates more CPU and memory to the function, but does not address the root cause of a single bad record blocking the shard; it does not provide any mechanism to isolate or skip failed records. Option B is wrong because disabling batch processing (setting batch size to 1) would still cause the same blocking behavior—each record would be processed individually, but a persistent bad record would still be retried indefinitely, blocking the shard. Option D is wrong because converting the stream to an S3 bucket is not a direct replacement for Kinesis event processing; S3 does not support the same record-level retry and failure handling semantics, and this would require a complete architectural change, not a simple configuration fix.

554
MCQeasy

A developer is building a web application that requires user authentication. The application will run on Amazon EC2 instances behind an Application Load Balancer. The developer wants to offload authentication to a managed service that supports social login providers. Which AWS service should the developer use?

A.AWS Identity and Access Management (IAM)
B.Amazon Cognito
C.AWS Directory Service
D.AWS Single Sign-On
AnswerB

Amazon Cognito is the correct choice because it is specifically engineered to provide secure and scalable user directories for web and mobile applications. Cognito User Pools enable easy sign-up, sign-in, and access control for application users, supporting multi-factor authentication and integration with social identity providers like Google, Facebook, and Apple. It offloads the complexity of user management and authentication from your application backend.

Why this answer

Amazon Cognito is the correct choice because it is a fully managed identity service designed for web and mobile applications, providing user authentication, authorization, and support for social login providers (e.g., Google, Facebook, Amazon) via OAuth 2.0 and OpenID Connect. It offloads the entire authentication workflow from the EC2 instances and ALB, integrating seamlessly with the ALB's authentication action to validate tokens before traffic reaches the application.

Exam trap

The trap here is that candidates often confuse IAM's role-based access control with user authentication, overlooking that IAM cannot handle social login providers or external user identity federation for customer-facing apps.

How to eliminate wrong answers

Option A is wrong because AWS IAM is for managing AWS service access and permissions for users and roles, not for external user authentication with social login providers; it lacks built-in support for social identity federation. Option C is wrong because AWS Directory Service provides managed Microsoft Active Directory or LDAP-based directories for enterprise identity, which does not natively support social login providers like Google or Facebook. Option D is wrong because AWS Single Sign-On (now AWS IAM Identity Center) is designed for workforce identity and SSO across AWS accounts and business applications, not for customer-facing web app authentication with social logins.

555
Multi-Selecteasy

Which TWO deployment methods can be used to update an AWS Lambda function with no downtime? (Select TWO.)

Select 2 answers
A.Update the function code using update-function-code.
B.Use a weighted alias to gradually shift traffic to a new version.
C.Create a new version and update the alias to point to the new version.
D.Create a new Lambda function and delete the old one.
E.Update the function configuration to increase memory.
AnswersB, C

This deployment method enables a canary release strategy, ensuring zero downtime. A new Lambda function version is published, and an alias is configured to distribute traffic between the existing stable version and the new version based on specified weights (e.g., 90% old, 10% new). This allows for gradual rollout, real-time monitoring of the new version's performance, and immediate rollback by adjusting weights if issues arise.

Why this answer

A weighted alias allows you to route a small percentage of traffic to a new Lambda version while keeping the majority on the current version, enabling canary deployments with zero downtime. Option C is correct because creating a new version and updating the alias to point to it performs an instant, atomic switch, ensuring all traffic is served by the new version without any interruption.

Exam trap

The trap here is that candidates often think update-function-code is a safe deployment method, but it modifies the mutable $LATEST version, which can cause downtime if an alias points to $LATEST and the update is not atomic.

556
MCQmedium

A developer is using AWS CodeDeploy to deploy an application to an Auto Scaling group of EC2 instances. The developer wants to minimize the number of instances that are taken out of service at any given time during the deployment. Which predefined deployment configuration should the developer use?

A.AllAtOnce
B.OneAtATime
C.HalfAtATime
D.Custom with 50% at a time
AnswerB

The OneAtATime deployment configuration updates instances sequentially, taking only one instance out of service at any given moment while the remaining instances continue to serve traffic. This rolling update strategy ensures that the application maintains high availability throughout the deployment process, significantly minimizing the impact on end-users. It is the most effective method for ensuring continuous service and reducing downtime in an Auto Scaling environment.

Why this answer

The OneAtATime deployment configuration shifts traffic to one new instance at a time, ensuring that only a single instance is taken out of service during the deployment. This minimizes the number of instances removed from the Auto Scaling group at any given moment, which directly meets the developer's requirement to reduce service disruption.

Exam trap

The trap here is that candidates might think 'HalfAtATime' is not a predefined configuration, but AWS CodeDeploy does offer 'HalfAtATime' as a predefined option. However, 'HalfAtATime' takes half the instances out of service at once, which does not minimize the number. The correct choice to minimize instances taken out of service is 'OneAtATime'.

How to eliminate wrong answers

Option A (AllAtOnce) is wrong because it deploys to all instances simultaneously, taking the entire fleet out of service at once, which maximizes disruption. Option C (HalfAtATime) is wrong because it is not a predefined deployment configuration in AWS CodeDeploy; the correct predefined option for deploying to half the instances is 'HalfAtATime' but it would take 50% of instances out of service at a time, which is more than the single instance the developer wants. Option D (Custom with 50% at a time) is wrong because while custom configurations are possible, the developer specifically asked for a predefined configuration, and using a custom one would not be the simplest or most direct solution; moreover, deploying 50% at a time would still take more instances out of service than the desired minimum.

557
MCQhard

A company requires that all API calls to create an Amazon S3 bucket must include a specific tag (e.g., 'CostCenter'). Which IAM policy condition key should a developer use to enforce this requirement?

A.aws:RequestTag
B.aws:ResourceTag
C.s3:ExistingObjectTag
D.aws:TagKeys
AnswerA

This condition key checks tags that are included in the API request. You can require a specific tag key and value to be present on the CreateBucket request, ensuring that all buckets are tagged at creation.

Why this answer

The `aws:RequestTag` condition key evaluates the tags that are included in the API request itself. When a developer attempts to create an S3 bucket, the IAM policy can use `aws:RequestTag` to require that a specific tag key (e.g., 'CostCenter') is present in the `CreateBucket` request. This ensures that the tag is applied at creation time, enforcing the company's tagging requirement.

Exam trap

The trap here is that candidates confuse `aws:RequestTag` (tags in the request) with `aws:ResourceTag` (tags on an existing resource), leading them to choose the wrong condition key for enforcing tagging at resource creation.

How to eliminate wrong answers

Option B is wrong because `aws:ResourceTag` evaluates the tags already attached to an existing resource, not the tags in the creation request, so it cannot enforce tagging at bucket creation. Option C is wrong because `s3:ExistingObjectTag` is used to conditionally allow actions based on tags on existing objects within a bucket, not on the bucket creation request itself. Option D is wrong because `aws:TagKeys` is used to restrict which tag keys can be used in a request, but it does not require that a specific tag key be present; it only controls the allowed set of keys.

558
MCQmedium

A company is using AWS Key Management Service (KMS) to encrypt data in S3. The security team wants to ensure that only the company's AWS account can access the KMS key. What should be done?

A.Disable the KMS key and re-enable it only when needed.
B.Modify the key policy to remove any statements that allow access from external AWS accounts.
C.Use an S3 bucket policy to deny access to any user not from the company's account.
D.Attach an IAM policy to the key that denies access to external accounts.
AnswerB

KMS key policies are the definitive and mandatory access control mechanism for every AWS KMS key, dictating precisely which IAM identities and AWS accounts can perform cryptographic operations. By meticulously reviewing the key policy and removing any specific `Statement` blocks that grant `kms:*` or targeted permissions like `kms:Decrypt` or `kms:GenerateDataKey` to external AWS account IDs or cross-account IAM roles, the company can precisely revoke unauthorized access without impacting legitimate internal usage. This is the most granular and secure method to manage KMS key access.

Why this answer

Modifying the key policy to remove any statements that allow access from external AWS accounts ensures that only the company's AWS account can use the KMS key. The key policy explicitly defines who can access the key, and removing external account access restricts it to the key owner's account. Option A is incorrect because disabling the key prevents all use, not just external access.

Option C is incorrect because an S3 bucket policy cannot control access to the KMS key itself; it only governs S3 operations. Option D is incorrect because IAM policies can grant or deny access, but the key policy must also allow the account; however, the key policy already allows the account's IAM users by default if they have the right permissions, but the requirement is to ensure only the company's account can access, which is achieved by removing external account access from the key policy.

559
Multi-Selecthard

A company is using AWS CodePipeline for CI/CD. The pipeline has a build stage using AWS CodeBuild, and a deploy stage using AWS CodeDeploy. The deployment is failing with 'Error: Health checks failed'. Which TWO steps should the developer take to troubleshoot this issue? (Select TWO.)

Select 2 answers
A.Verify that the target group's health check path and port are correctly configured.
B.Check the S3 bucket where the build artifacts are stored.
C.Check the CodeDeploy deployment logs for detailed error messages.
D.Check the CodeBuild build logs for errors.
E.Increase the number of EC2 instances in the Auto Scaling group.
AnswersA, C

CodeDeploy's health check failures during an in-place or blue/green deployment are most often caused by the target group's health check path returning a non-2xx response or the port not matching what the application actually listens on, so confirming this configuration directly addresses the failure signal.

Why this answer

Options A and C are correct. Verifying the target group's health check path and port (A) ensures that the load balancer's health check matches the application's actual endpoint, which is a common cause of health check failures. Checking the CodeDeploy deployment logs (C) provides detailed error messages from the deployment process, which can pinpoint why the health checks are failing.

Option B (checking S3 bucket) is not directly related to health check failures, as artifacts are typically stored correctly if the build succeeded. Option D (checking CodeBuild logs) is irrelevant because the build stage succeeded. Option E (increasing instances) does not address the root cause of health check failures.

560
MCQhard

An API Gateway HTTP API should allow access only to users authenticated by an external OIDC provider. Which authorizer type is most appropriate?

A.IAM authorizer
B.API key authorizer
C.JWT authorizer configured for the issuer and audience
D.S3 bucket policy
AnswerC

A JWT authorizer for an HTTP API validates JSON Web Tokens (JWTs) presented by clients, ensuring they are signed by a trusted issuer and intended for the specific API. By configuring the issuer (iss) and audience (aud) claims, the authorizer cryptographically verifies the token's authenticity and its intended recipient. This mechanism precisely controls access by allowing only requests with valid, unexpired tokens from a recognized identity provider, making it ideal for OAuth 2.0 and OpenID Connect flows.

Why this answer

An HTTP API Gateway with an external OIDC provider requires a JWT authorizer. The JWT authorizer validates the token's signature, issuer, and audience against the OIDC provider's configuration, ensuring only authenticated users gain access. This is the native AWS mechanism for integrating third-party OIDC identity providers like Auth0 or Okta.

Exam trap

The trap here is that candidates confuse the JWT authorizer with the Lambda authorizer, thinking a custom Lambda is always required for OIDC, but the JWT authorizer natively supports OIDC without custom code when the provider issues standard JWTs.

How to eliminate wrong answers

Option A is wrong because an IAM authorizer uses AWS Signature Version 4 for signing requests with IAM credentials, not OIDC tokens, and is designed for AWS-authenticated principals, not external identity providers. Option B is wrong because an API key authorizer only validates a static key passed in the header, which provides no authentication of the user's identity and cannot verify OIDC tokens. Option D is wrong because an S3 bucket policy controls access to S3 resources, not API Gateway endpoints, and has no mechanism to validate OIDC tokens.

561
MCQmedium

A developer is building a REST API with Amazon API Gateway and needs to authorize requests based on a custom JSON Web Token (JWT) that includes claims for user roles. Which authorization mechanism should the developer use?

A.Lambda authorizer
B.IAM authorizer
C.Amazon Cognito user pools authorizer
D.API Gateway resource policy
AnswerA

A Lambda authorizer, formerly known as a custom authorizer, is an AWS Lambda function that API Gateway invokes before forwarding the request to the backend integration. It receives the incoming custom JWT token, validates it against custom logic (e.g., verifying signature, issuer, audience, and expiration), and then returns an IAM policy document. This policy dictates whether the principal is authorized to access the requested API Gateway method, providing ultimate flexibility for any token type.

Why this answer

A Lambda authorizer (formerly known as a custom authorizer) is the correct choice because it allows the developer to validate a custom JWT and extract claims such as user roles directly within the Lambda function. This enables fine-grained authorization logic that can inspect the JWT payload, verify its signature using a custom or third-party key, and return an IAM policy based on the claims, which API Gateway then enforces for the incoming request.

Exam trap

The trap here is that candidates often confuse a Lambda authorizer with a Cognito user pools authorizer, assuming any JWT can be validated by Cognito, but Cognito only accepts tokens it issued, not custom JWTs from other providers.

How to eliminate wrong answers

Option B is wrong because an IAM authorizer uses AWS Signature Version 4 to sign requests with IAM credentials, not a custom JWT; it cannot inspect or validate JWT claims like user roles. Option C is wrong because Amazon Cognito user pools authorizer only works with JWTs issued by a Cognito user pool, not with a custom JWT from an external identity provider or self-issued token. Option D is wrong because an API Gateway resource policy controls access at the account or VPC level based on source IP, VPC endpoint, or AWS account, not on individual request-level JWT claims or user roles.

562
MCQmedium

A developer manages a web application deployed on an AWS Elastic Beanstalk environment with multiple Amazon EC2 instances. The developer needs to deploy a new version of the application with zero downtime. The new version requires a different instance type and additional software packages. Which deployment strategy should the developer use?

A.Rolling
B.All at once
C.Rolling with additional batch
D.Immutable
AnswerD

Immutable deployment creates a new set of instances with the updated application version and any configuration changes, including instance type. It launches the new instances in a temporary Auto Scaling group, then swaps them with the old ones, ensuring zero downtime. This strategy meets both requirements: zero downtime and a different instance type.

Why this answer

Immutable deployment is the only strategy that supports changing instance types and other configuration settings while maintaining zero downtime. It creates a full new set of instances with the new configuration, then swaps them in. Other strategies either cause downtime or cannot alter the environment's instance type.

Exam trap

The trap here is assuming that rolling with additional batch can change instance types because it adds instances, but it only adds instances of the same type.

563
MCQeasy

A developer needs to allow an IAM user to perform only specific actions on an S3 bucket. Which type of policy should be attached to the IAM user?

A.A service control policy
B.A bucket policy
C.A trust policy
D.An IAM policy
AnswerD

An IAM policy is a JSON document that explicitly defines permissions, specifying what actions are allowed or denied on which AWS resources, and under what conditions. These policies are directly attached to IAM identities such as users, groups, or roles, making them the fundamental mechanism for granting specific permissions to an IAM user. By attaching a tailored IAM policy to a user, a developer can precisely control and limit the actions that user is authorized to perform across AWS services.

Why this answer

An IAM policy (Option D) is the correct choice because it is an identity-based policy that can be directly attached to an IAM user, group, or role to grant or deny permissions for specific actions on AWS resources, including S3 buckets. This allows the developer to precisely control which S3 actions (e.g., s3:GetObject, s3:PutObject) the user can perform on a particular bucket, meeting the requirement of limiting the user to specific actions.

Exam trap

AWS often tests the distinction between identity-based policies (IAM policies) and resource-based policies (bucket policies), where candidates mistakenly choose a bucket policy thinking it can control user permissions directly, but bucket policies are tied to the resource, not the user identity.

How to eliminate wrong answers

Option A is wrong because a service control policy (SCP) is used in AWS Organizations to set permission boundaries for all accounts in an organization, not to grant permissions to individual IAM users. Option B is wrong because a bucket policy is a resource-based policy attached directly to an S3 bucket, not to an IAM user; while it can grant cross-account access, it does not control permissions for a specific IAM user within the same account. Option C is wrong because a trust policy is attached to an IAM role to define which principals (e.g., users, services) can assume that role, not to grant direct permissions for S3 actions to an IAM user.

564
MCQmedium

The exhibit shows an IAM policy attached to a user. The user reports being unable to upload files to S3 bucket 'my-bucket'. What is the MOST likely cause?

A.The user needs s3:PutObjectAcl permission
B.The bucket policy denies the upload
C.The policy does not allow s3:ListBucket
D.The user does not have s3:GetObject permission
AnswerB

An explicit `Deny` statement in an S3 bucket policy always takes precedence over any `Allow` statement in an attached IAM user policy, even if the IAM policy grants the necessary `s3:PutObject` permission. AWS's authorization logic dictates that if any policy in the evaluation path contains an explicit deny for a requested action, that action is forbidden, regardless of other allow statements. This ensures that bucket owners maintain ultimate control over their resources.

Why this answer

The user has an IAM policy that grants s3:PutObject on 'my-bucket', but the bucket policy explicitly denies s3:PutObject for that user. Since an explicit deny in a resource-based policy overrides any allow in an identity-based policy, the upload fails. AWS IAM evaluates all policies, and a single explicit deny results in a final decision of deny.

Exam trap

The trap here is that candidates assume an IAM allow is sufficient, forgetting that resource-based policies (like S3 bucket policies) can override with an explicit deny, making the user unable to upload despite having the correct IAM permissions.

How to eliminate wrong answers

Option A is wrong because s3:PutObjectAcl is only needed if the upload request includes a canned ACL or requires modifying object ACLs; the basic upload action s3:PutObject does not require it. Option C is wrong because s3:ListBucket is required for listing objects, not for uploading a single object; the upload action only needs s3:PutObject. Option D is wrong because s3:GetObject is for reading/downloading objects, not for uploading; the user's inability to upload is unrelated to read permissions.

565
MCQmedium

A developer is using Amazon DynamoDB as the data store for a serverless application. The application experiences high read traffic, and the developer wants to reduce latency. The data is not frequently updated. Which DynamoDB feature should the developer use?

A.DynamoDB Auto Scaling
B.DynamoDB Global Tables
C.DynamoDB Accelerator (DAX)
D.DynamoDB Time to Live (TTL)
AnswerC

DynamoDB Accelerator (DAX) is a fully managed, highly available, in-memory cache specifically designed for DynamoDB. It provides microsecond response times for read-heavy workloads by caching items and query results, significantly reducing the load on the underlying DynamoDB table. DAX acts as a transparent proxy, allowing applications to continue using the DynamoDB API while benefiting from accelerated read performance.

Why this answer

DynamoDB Accelerator (DAX) is a fully managed, in-memory cache that reduces read latency for DynamoDB tables from single-digit milliseconds to microseconds. Since the data is not frequently updated, DAX can serve repeated read requests from its cache without hitting the underlying table, making it ideal for high-read, low-write workloads.

Exam trap

The trap here is that candidates may confuse DAX with Global Tables, thinking that replicating data across regions reduces latency, but the question specifies reducing latency within a single region, where DAX's in-memory caching is the correct solution.

How to eliminate wrong answers

Option A is wrong because DynamoDB Auto Scaling adjusts provisioned throughput capacity based on traffic patterns, which helps manage cost and performance but does not reduce read latency. Option B is wrong because DynamoDB Global Tables provide multi-region replication for disaster recovery and low-latency reads across regions, but they do not improve read latency within a single region. Option D is wrong because DynamoDB Time to Live (TTL) automatically deletes expired items to manage storage costs, and has no impact on read performance or latency.

566
MCQeasy

A developer runs a CloudTrail lookup command and sees a CreateKey event. What does this event represent?

A.An existing KMS key was rotated.
B.A new database encryption key was created.
C.A new KMS customer master key was created.
D.A new service-linked key was created.
AnswerC

This option is correct because the `CreateKey` API is the fundamental operation in AWS Key Management Service (KMS) used to provision a new Customer Master Key (CMK). A CMK is the primary resource you manage in KMS for cryptographic operations. Therefore, a CloudTrail lookup showing a `CreateKey` event precisely indicates that a new, unique KMS customer master key has been successfully generated and made available within the AWS account.

Why this answer

The `CreateKey` event in AWS CloudTrail indicates that a new KMS customer master key (CMK) was created. This is the only operation that generates a `CreateKey` event; key rotation, database encryption key creation, and service-linked key creation use different API calls (e.g., `RotateKey`, `CreateGrant`, or `CreateKey` with a different service principal).

Exam trap

The trap here is that candidates assume `CreateKey` only applies to CMKs, but AWS services also use this API for service-linked keys; however, the exam expects you to recognize that the event name is generic and the context (e.g., `userIdentity` or `requestParameters`) determines the key type.

How to eliminate wrong answers

Option A is wrong because key rotation is performed via the `RotateKey` API or automatic rotation settings, not `CreateKey`. Option B is wrong because database encryption keys are typically managed by the database service (e.g., RDS, DynamoDB) using KMS grants or direct CMK usage, not a standalone `CreateKey` event. Option D is wrong because service-linked keys are created by AWS services on your behalf using a different API call (e.g., `CreateKey` with a service principal), but the event name is still `CreateKey`; however, the question's context implies a standard CMK creation, and service-linked keys are a specific subset that would be logged with a different `requestParameters` (e.g., `KeyUsage` and `Origin`).

567
MCQhard

A company runs a critical application on Amazon EC2 instances behind an Application Load Balancer (ALB). The application experiences intermittent errors where some requests return HTTP 503 (Service Unavailable) errors. The developers have verified that the application code is healthy and the EC2 instances pass health checks. The ALB health check is configured to hit a specific endpoint (/health) with a healthy threshold of 2 and an unhealthy threshold of 2. The health check interval is 30 seconds, and the timeout is 5 seconds. The application's /health endpoint sometimes takes up to 6 seconds to respond due to a dependency on a third-party service. The developers want to minimize the 503 errors without changing the application code. Which action should the developer take?

A.Increase the health check timeout to 10 seconds to accommodate the slow /health endpoint.
B.Decrease the unhealthy threshold to 1 so that instances are marked unhealthy after one failed health check.
C.Increase the deregistration delay to 300 seconds to allow connections to drain.
D.Decrease the health check interval to 10 seconds to detect health changes faster.
AnswerA

The /health endpoint can take six seconds, exceeding the five-second timeout, so the ALB marks instances unhealthy and returns 503s. Raising the timeout to ten seconds lets the health check succeed, keeping instances in service without code changes.

Why this answer

Increasing the health check timeout to 10 seconds allows the /health endpoint to respond within the timeout period, preventing the ALB from marking the instance as unhealthy due to a slow response. Since the endpoint sometimes takes up to 6 seconds, a 5-second timeout is too short, causing health checks to fail intermittently. By increasing the timeout, the health checks will succeed, and the ALB will not remove the instance from service, thus reducing 503 errors.

Exam trap

The trap is that candidates might think decreasing the unhealthy threshold or interval would help, but those actions would make the situation worse; the key is to match the timeout to the application's response time.

How to eliminate wrong answers

Option B is wrong because decreasing the unhealthy threshold to 1 would make the ALB mark instances unhealthy faster, potentially increasing 503 errors if a single health check fails. Option C is wrong because increasing the deregistration delay affects connection draining during instance deregistration, not health check failures; it does not address the root cause. Option D is wrong because decreasing the health check interval to 10 seconds would make health checks more frequent, but with a 5-second timeout, the slow endpoint would still cause failures; it might even increase the number of failed health checks.

568
MCQeasy

A developer needs to allow an EC2 instance to access an S3 bucket without storing credentials on the instance. Which approach is the most secure?

A.Create an IAM user with access keys and store them on the instance.
B.Use S3 bucket policy to allow the EC2 instance's public IP.
C.Store the access keys in Systems Manager Parameter Store and retrieve at runtime.
D.Use an IAM role for EC2 with a policy granting S3 access.
AnswerD

An IAM role attached to the instance delivers temporary credentials through the instance metadata service, rotated automatically by AWS. No long-term access keys are stored on disk or in code, eliminating the credential-exposure risk the stem prohibits.

Why this answer

An IAM role attached to an EC2 instance delivers temporary, automatically rotated credentials via the Instance Metadata Service (IMDS), so no long-lived secrets ever touch the instance filesystem. The role's trust policy allows ec2.amazonaws.com to assume it, and the attached permissions policy scopes exactly which S3 actions and resources are allowed. This is AWS's recommended pattern for granting AWS service access to compute resources.

Exam trap

DVA-C02 often tests the misconception that storing credentials in Parameter Store or Secrets Manager is equivalent to using an IAM role — both still involve static secrets, whereas roles provide short-lived, auto-rotated credentials.

How to eliminate wrong answers

Option A is wrong because embedding IAM user access keys on an instance creates long-lived static credentials that can be exfiltrated from disk or environment variables and must be manually rotated. Option B is wrong because S3 bucket policies cannot authenticate by source public IP for an EC2 instance reliably — the instance's public IP is dynamic (changes on stop/start), and IP-based conditions do not provide identity-based authorization. Option C is wrong because Parameter Store still stores static IAM user credentials that must be retrieved and held in memory by the application, so the secret still exists and can leak; it only moves the storage location, not the underlying risk.

569
Multi-Selecthard

A Lambda function processes a batch of SQS messages. Which two configurations reduce duplicate or failed-message impact?

Select 2 answers
A.Set visibility timeout to zero
B.Use a visibility timeout longer than expected processing time
C.Disable the dead-letter queue
D.Configure a dead-letter queue and partial batch response where appropriate
AnswersB, D

Utilizing an SQS visibility timeout that is longer than the expected message processing time is a fundamental best practice for reliable asynchronous processing. This ensures that once a Lambda function receives a message, it has sufficient exclusive time to process it successfully and delete it from the queue before it becomes visible to other consumers. This prevents duplicate processing attempts and ensures that each message is handled at least once without unnecessary retries by other instances.

Why this answer

A visibility timeout longer than the expected processing time prevents other consumers from reprocessing a message while it is still being handled, reducing duplicates. Option D is correct because a dead-letter queue captures messages that repeatedly fail processing, allowing analysis and preventing them from blocking the queue, while partial batch response enables the function to return a list of failed message IDs so that only those messages become visible again, reducing reprocessing of successful ones.

Exam trap

The trap here is that candidates often think setting visibility timeout to zero or disabling the DLQ simplifies processing, but in reality, these actions increase duplicate or failed-message impact by removing mechanisms that control reprocessing and isolate problematic messages.

570
Multi-Selectmedium

A company needs to store application secrets such as database passwords and API keys. The secrets must be automatically rotated every 30 days. Which THREE AWS services or features can be used together to meet this requirement? (Choose THREE.)

Select 3 answers
A.AWS Lambda to implement the rotation function
B.AWS CloudHSM
C.AWS Systems Manager Parameter Store
D.AWS Secrets Manager
E.AWS KMS to encrypt the secrets
AnswersA, D, E

AWS Lambda functions are essential for implementing the automatic rotation of secrets managed by AWS Secrets Manager. Secrets Manager invokes a pre-configured Lambda function on a scheduled basis to programmatically change the credentials in the target database or service. This function handles the logic for creating new credentials, updating the secret in Secrets Manager, and then deprecating the old credentials, ensuring secure and automated secret lifecycle management without manual intervention.

Why this answer

AWS Lambda is correct because it can be used as a custom rotation function for AWS Secrets Manager. Secrets Manager natively supports automatic rotation using a Lambda function that updates the secret value in both the service and the database or third-party service. This allows the company to meet the 30-day rotation requirement by scheduling the Lambda function via a CloudWatch Events rule or Secrets Manager's built-in rotation schedule.

Exam trap

The trap here is that candidates often confuse AWS Systems Manager Parameter Store with Secrets Manager, but Parameter Store lacks native automatic rotation, making it unsuitable for this requirement without additional custom infrastructure.

571
MCQhard

A developer is using AWS CodeDeploy to deploy a new version of an application to an Auto Scaling group. The deployment fails because the new instances do not pass the health check. The developer wants to automatically roll back the deployment if the health check fails. Which CodeDeploy setting should be configured?

A.Set the deployment configuration to AllAtOnce to speed up the process.
B.Configure a lifecycle hook to terminate failing instances.
C.Use a blue/green deployment strategy instead of in-place.
D.Enable automatic rollback in the deployment group configuration.
AnswerD

Enabling automatic rollback within the CodeDeploy deployment group configuration is the most direct and effective solution for ensuring recovery from problematic deployments. This feature allows CodeDeploy to monitor the health of a new deployment using specified CloudWatch alarms or other health checks. Upon detecting a failure, it automatically reverts all instances in the deployment group to the last known good application revision, minimizing downtime and operational overhead by providing a self-healing mechanism.

Why this answer

AWS CodeDeploy provides a built-in automatic rollback feature that can be configured at the deployment group level. When enabled, if a deployment fails (e.g., due to health check failures), CodeDeploy automatically reverts to the last known successful deployment, ensuring minimal downtime and manual intervention.

Exam trap

The trap here is that candidates often confuse deployment strategies (like blue/green or in-place) with rollback mechanisms, not realizing that rollback is a separate configuration setting that must be explicitly enabled regardless of the deployment strategy.

How to eliminate wrong answers

Option A is wrong because changing the deployment configuration to AllAtOnce does not enable rollback; it only deploys to all instances simultaneously, which could increase the blast radius of a failed deployment. Option B is wrong because lifecycle hooks are used to perform custom actions (e.g., draining connections) during instance launch or termination, not to trigger automatic rollbacks of a deployment. Option C is wrong because while blue/green deployment can reduce risk, it does not inherently provide automatic rollback on health check failure; rollback must be explicitly enabled in the deployment group configuration.

572
MCQeasy

A developer is designing a REST API using Amazon API Gateway that experiences high traffic with many repeated requests for the same data. The developer wants to reduce backend load and improve response times. Which feature should the developer enable on the API Gateway method?

A.Enable API Gateway caching
B.Implement caching in the Lambda function using a local cache
C.Use an Amazon ElastiCache Redis cluster and modify the Lambda function to check the cache first
D.Place an Amazon CloudFront distribution in front of API Gateway
AnswerA

Enabling API Gateway caching directly addresses the problem by storing responses from the backend integration (e.g., Lambda) for a configurable Time-To-Live (TTL). This significantly reduces the number of identical requests that reach the backend service, offloading the compute and database resources. It operates at the API Gateway layer, making it highly efficient for repeated requests to the same API method and improving overall API responsiveness.

Why this answer

API Gateway caching stores responses from backend endpoints for a configurable Time-to-Live (TTL). When a request for the same data arrives, API Gateway serves the cached response directly without invoking the backend, reducing load and improving latency. This is the most straightforward and managed solution for repeated requests at the API layer.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing a distributed cache like ElastiCache or a CDN like CloudFront, when the simplest and most cost-effective managed service (API Gateway caching) directly addresses the requirement at the API layer.

How to eliminate wrong answers

Option B is wrong because implementing a local cache inside a Lambda function is ephemeral and not shared across concurrent invocations, so it cannot reduce backend load for repeated requests from different clients. Option C is wrong because while ElastiCache Redis can cache data, it requires additional code in the Lambda function to check the cache first, adding complexity and latency compared to API Gateway's built-in caching. Option D is wrong because CloudFront caches content at the edge, but it does not reduce backend load for API Gateway itself unless combined with API Gateway caching; CloudFront alone still forwards cache misses to API Gateway, which then invokes the backend.

573
MCQmedium

A developer is deploying a static website to Amazon S3. The website uses client-side JavaScript to make API calls to an AWS Lambda function via Amazon API Gateway. The developer wants to enable cross-origin resource sharing (CORS) on the API Gateway to allow the S3 website to make requests. After enabling CORS on the API Gateway and redeploying the API, the browser still reports CORS errors. The developer checks the API Gateway configuration and sees that the OPTIONS method is not defined. The developer has already enabled CORS via the API Gateway console, which should have created the OPTIONS method. However, it did not appear. What should the developer do to resolve the issue?

A.Update the JavaScript in the website to use a different HTTP method.
B.Update the S3 bucket policy to allow cross-origin requests from any origin.
C.Modify the Lambda function to return CORS headers in its response.
D.Manually add an OPTIONS method to the API Gateway resource and configure the CORS headers in the integration response.
AnswerD

To resolve CORS issues, API Gateway must be explicitly configured to handle the browser's preflight OPTIONS request. This involves manually adding an OPTIONS method to the API Gateway resource and setting up a mock integration response that includes the required Access-Control-Allow-Origin, Access-Control-Allow-Methods, and Access-Control-Allow-Headers in its headers, allowing the browser to proceed with the actual request.

Why this answer

When API Gateway's CORS console feature fails to create the OPTIONS method (often due to permissions, resource policy conflicts, or the resource already having a mock integration), the developer must manually create an OPTIONS method on the resource, set the integration type to MOCK, and configure the integration response with the Access-Control-Allow-Origin, Access-Control-Allow-Headers, and Access-Control-Allow-Methods headers. The browser's preflight request (OPTIONS) must receive those headers before the actual GET/POST is sent, so a missing OPTIONS method guarantees CORS failure regardless of what the backend returns.

Exam trap

DVA-C02 often tests the misconception that enabling CORS in the console is always sufficient, when in fact the OPTIONS method must exist and return the correct headers for the preflight to succeed.

How to eliminate wrong answers

Option A is wrong because changing the HTTP method does not bypass the browser's CORS preflight requirement — any non-simple request still triggers an OPTIONS preflight. Option B is wrong because S3 bucket policies govern access to S3 objects, not cross-origin permissions for API Gateway responses; CORS is enforced by the browser based on headers returned by the API. Option C is wrong because while Lambda can return CORS headers on the actual response, the browser first sends a preflight OPTIONS request that never reaches Lambda if the OPTIONS method is undefined, so the preflight fails before the Lambda response matters.

574
Multi-Selectmedium

A developer is designing a highly available application using Amazon SQS and AWS Lambda. Which TWO strategies should the developer implement to ensure that messages are processed at least once? (Choose TWO.)

Select 2 answers
A.Configure a Dead Letter Queue (DLQ) to capture failed messages.
B.Enable long polling on the SQS queue.
C.Use a FIFO queue to ensure exactly-once processing.
D.Set the SQS queue's visibility timeout to be greater than the Lambda function's timeout.
E.Use the SQS DeleteMessage API inside the Lambda function only after successful processing.
AnswersD, E

Setting the SQS queue's visibility timeout to be greater than the Lambda function's timeout is crucial for at-least-once processing. If the Lambda function fails or times out before successfully processing and deleting a message, the message will automatically become visible again in the queue once the SQS visibility timeout expires. This ensures that another consumer or a subsequent invocation of the Lambda function can pick up and re-process the message, guaranteeing it is processed at least once.

Why this answer

Setting the SQS queue's visibility timeout to be greater than the Lambda function's timeout ensures that if the Lambda function fails or times out, the message becomes visible again in the queue after the visibility timeout expires, allowing another consumer to retry processing. This prevents messages from being lost due to processing failures, supporting at-least-once processing. Option E is correct because calling the SQS DeleteMessage API only after successful processing ensures that the message is not removed from the queue until it has been fully and correctly handled, so if processing fails, the message remains available for retry.

Exam trap

The trap here is that candidates often confuse the purpose of a Dead Letter Queue (DLQ) as a mechanism for ensuring at-least-once processing, when in fact it is for isolating messages that have exhausted retries, not for guaranteeing delivery.

575
MCQeasy

A developer is building a serverless application using AWS Lambda. The function needs to access an S3 bucket to read a configuration file. What is the best way to provide the Lambda function with the bucket name?

A.Hardcode the bucket name in the Lambda function code.
B.Store the bucket name in an environment variable for the Lambda function.
C.Read the bucket name from a text file stored in the same bucket.
D.Use a KMS key to encrypt the bucket name and decrypt it in the function.
AnswerB

Storing the S3 bucket name in an environment variable is the recommended and most efficient method for passing configuration data to an AWS Lambda function. Environment variables are easily configured through the AWS Management Console, CLI, or Infrastructure as Code tools like CloudFormation or Terraform, allowing updates without modifying or redeploying the function's code. This promotes separation of configuration from code, enhances flexibility across different deployment environments, and improves operational agility.

Why this answer

AWS Lambda environment variables provide a secure, configurable, and decoupled way to pass the S3 bucket name to the function without hardcoding it in the code. This follows the principle of infrastructure as code and allows the same function code to be reused across different environments (e.g., dev, staging, prod) by simply changing the environment variable value. Environment variables are encrypted at rest by default using AWS KMS, ensuring the bucket name is not exposed in plaintext within the code repository.

Exam trap

The trap here is that candidates may overcomplicate the solution by choosing KMS encryption (Option D) or the circular dependency of reading from the same bucket (Option C), when the simplest and most secure approach—environment variables—is the correct answer for decoupling configuration from code.

How to eliminate wrong answers

Option A is wrong because hardcoding the bucket name in the Lambda function code violates the separation of configuration from code, making the function environment-specific and requiring code changes to point to a different bucket. Option C is wrong because reading the bucket name from a text file stored in the same bucket creates a circular dependency: the function needs the bucket name to access the bucket, but it must first read the file from the bucket to get the name, which is impossible without prior knowledge of the bucket. Option D is wrong because using a KMS key to encrypt the bucket name and decrypt it in the function adds unnecessary complexity and overhead; environment variables are already encrypted at rest by default, and the bucket name is not sensitive data that requires custom encryption—this approach does not solve the configuration problem.

576
Multi-Selecteasy

Which TWO are benefits of using AWS CloudFormation for infrastructure deployment? (Choose two.)

Select 2 answers
A.Infrastructure is provisioned consistently across environments.
B.Automatically enforces compliance rules.
C.Automatically rolls back changes if stack creation fails.
D.Replaces the need for a CI/CD pipeline.
E.Provides real-time monitoring of deployed resources.
AnswersA, C

CloudFormation templates define infrastructure as code, specifying resources and their configurations in a declarative manner. By using the same template across development, staging, and production environments, organizations ensure that the infrastructure deployed in each environment is identical and provisioned consistently. This eliminates configuration drift and reduces human error, leading to more reliable and predictable deployments.

Why this answer

AWS CloudFormation uses templates to define infrastructure as code, ensuring that the same set of resources is provisioned identically across multiple environments (e.g., dev, test, prod). This eliminates configuration drift and manual errors by applying the same template consistently, which is a core benefit of infrastructure as code.

Exam trap

The trap here is that candidates often confuse CloudFormation's rollback-on-failure behavior (which is automatic by default) with compliance enforcement or monitoring, leading them to select Option B or E, but CloudFormation does not natively audit or monitor resources.

577
Multi-Selectmedium

Which THREE factors should a developer consider when designing a stateless application on AWS? (Choose 3)

Select 3 answers
A.Avoid storing data on the local file system of the instances
B.Store session state in a shared external datastore like ElastiCache
C.Store session state in the instance memory for low latency
D.Use sticky sessions on the load balancer to maintain session affinity
E.Use a shared database like Amazon DynamoDB for persistent data
AnswersA, B, E

A stateless application must not persist session or transactional data on an instance's local disk, because Auto Scaling can terminate or replace that instance at any time, and any data written only to its EBS root or instance store volume is permanently lost with it.

Why this answer

A stateless application should not store session state locally, so option A is correct. Session state should be stored in an external shared datastore like ElastiCache (option B) or a shared database like DynamoDB (option E). Storing state in instance memory (C) or using sticky sessions (D) would introduce statefulness, which is not desired in a stateless architecture.

578
MCQmedium

A company has a legacy application that generates log files on an EC2 instance. The developer needs to stream these log files to Amazon CloudWatch Logs in real time. The developer installed the CloudWatch agent on the EC2 instance and configured it to monitor the log files. However, the logs are not appearing in CloudWatch Logs. The developer checks the agent status and sees that the agent is running. What is the most likely cause of this issue?

A.The log file format is not compatible with the CloudWatch agent.
B.The EC2 instance is in a private subnet without internet access.
C.The EC2 instance does not have an IAM role with the necessary CloudWatch Logs permissions.
D.The CloudWatch agent configuration file does not specify an existing log group.
AnswerC

For the CloudWatch agent to successfully publish log data, the EC2 instance profile must be associated with an IAM role that grants specific permissions to CloudWatch Logs. Essential permissions include logs:PutLogEvents to send log data, logs:CreateLogStream to create new log streams, and logs:DescribeLogStreams to check existing streams. Without these explicit permissions, the agent will be unauthorized to interact with the CloudWatch Logs service, leading to log ingestion failures.

Why this answer

The CloudWatch agent uses the EC2 instance's IAM role credentials to call the CloudWatch Logs API (logs:CreateLogGroup, logs:CreateLogStream, logs:PutLogEvents). If the instance profile lacks these permissions, the agent process runs but every API call is rejected with AccessDenied, so logs never appear. This is the most common cause when the agent status shows running but no data arrives.

Exam trap

DVA-C02 often tests the assumption that a 'running' agent means it is functioning — candidates overlook that the agent can run while lacking IAM permissions, and they pick network or configuration answers instead of checking the instance role's CloudWatch Logs policy.

How to eliminate wrong answers

Option A is wrong because the CloudWatch agent handles plain text, JSON, and many common log formats; format incompatibility would typically produce parsing warnings, not total absence of logs. Option B is wrong because an instance in a private subnet can still reach CloudWatch Logs through a VPC endpoint (interface endpoint for logs) or NAT gateway; lack of internet access alone is not the most likely cause and is easily remedied. Option D is wrong because the agent auto-creates the log group if it does not exist (given permissions), so a missing log group definition is not the typical failure mode.

579
MCQeasy

A developer needs to securely pass a secret API key to an AWS Lambda function. What is the MOST secure and recommended approach?

A.Store the API key in an Amazon DynamoDB table and query it from the Lambda function.
B.Hardcode the API key in the Lambda function code.
C.Store the API key in an environment variable of the Lambda function.
D.Store the API key in AWS Secrets Manager and retrieve it in the Lambda function code.
AnswerD

AWS Secrets Manager is the recommended and most secure service for storing and managing sensitive data like API keys. It encrypts secrets at rest and in transit, provides robust automatic rotation capabilities, and integrates seamlessly with AWS Lambda for secure retrieval via the AWS SDK. This approach ensures the API key is never exposed in plain text within the application code or configuration, adhering to security best practices and simplifying secret lifecycle management and auditing.

Why this answer

AWS Secrets Manager is a dedicated service for securely storing and managing secrets like API keys. It integrates natively with Lambda, allowing retrieval at runtime with minimal permissions using IAM roles. Option A (DynamoDB) is less secure because it requires managing encryption and access policies manually, and the secret might be exposed in query logs.

Option B (hardcoding) is insecure as the key is visible in source code and version control. Option C (environment variables) can be viewed in the Lambda console and CloudWatch Logs, and they are not encrypted by default unless using encryption helpers. Therefore, Secrets Manager (Option D) is the most secure and recommended approach.

580
MCQeasy

A developer is building a RESTful API using AWS Lambda and Amazon API Gateway. The API needs to support HTTP methods GET, POST, and DELETE. The developer wants to minimize code and operational overhead. Which API Gateway integration type should the developer use?

A.Lambda proxy integration
B.Lambda custom integration
C.HTTP integration
D.Mock integration
AnswerA

Lambda proxy integration is the recommended and most straightforward method for integrating API Gateway with AWS Lambda functions. It passes the entire incoming request, including headers, query parameters, path parameters, and body, directly to the Lambda function as a single JSON object. This simplifies the Lambda function's code, as it receives the raw request and is responsible for formatting the response in a specific API Gateway-compatible JSON structure, minimizing configuration overhead in API Gateway itself.

Why this answer

Lambda proxy integration is correct because API Gateway passes the entire HTTP request (method, path, headers, query string, body) directly to the Lambda function as a structured event, and the function returns a formatted response object. This eliminates the need to write mapping templates or configure method/request/response transformations, minimizing both code and operational overhead. It natively supports GET, POST, DELETE, and any other HTTP method without per-method configuration.

Exam trap

DVA-C02 often tests the difference between proxy and custom integrations, and candidates mistakenly choose custom integration thinking it reduces code, when in fact proxy integration is the one that minimizes code by avoiding mapping templates.

How to eliminate wrong answers

Option B is wrong because Lambda custom integration requires the developer to write mapping templates for request and response payloads, adding code and configuration overhead. Option C is wrong because HTTP integration is used to route requests to an existing HTTP endpoint (e.g., an on-premises or external API), not to a Lambda function. Option D is wrong because mock integration returns a static response without invoking any backend, so it cannot serve a functional RESTful API.

581
MCQmedium

A Lambda function needs temporary scratch space larger than the default while processing images. Which setting should be adjusted?

A.Reserved concurrency
B.Ephemeral storage size for /tmp
C.Function URL auth type
D.Dead-letter queue target
AnswerB

The ephemeral storage size for the "/tmp" directory directly controls the amount of local, temporary disk space available to a Lambda function during its execution. By increasing this configurable setting, a function can access more scratch space than the default 512 MB, which is essential for processing larger files or datasets locally. This directly fulfills the requirement for a larger temporary scratch space within the Lambda execution environment.

Why this answer

Lambda functions have a default /tmp storage of 512 MB, which is insufficient for large image processing tasks. Adjusting the ephemeral storage size (up to 10,240 MB) provides the necessary scratch space for temporary files, such as intermediate image buffers or resized outputs, without requiring external storage like EFS.

Exam trap

The trap here is that candidates confuse ephemeral storage with memory allocation or external storage services, assuming that increasing the function's memory or using S3 will solve the scratch space issue, when the /tmp directory is the only directly configurable scratch space within the Lambda execution environment.

How to eliminate wrong answers

Option A is wrong because reserved concurrency controls the maximum number of concurrent executions for a function, not storage capacity. Option C is wrong because the function URL auth type (e.g., AWS_IAM or NONE) determines authentication for HTTP invocations, not storage. Option D is wrong because a dead-letter queue target (e.g., SQS or SNS) is used for capturing failed asynchronous invocations, not for providing scratch space.

582
MCQhard

A company uses AWS CodePipeline to automate deployments. The pipeline source stage uses Amazon S3. The developer wants to automatically trigger the pipeline when a new version of the source file is uploaded. The developer has configured S3 event notifications to invoke a Lambda function that starts the pipeline. However, the pipeline is not triggering. What is the most likely cause?

A.S3 versioning is not enabled on the bucket.
B.The pipeline execution role does not have permission to read from the S3 bucket.
C.The Lambda function does not have permission to start the pipeline.
D.The S3 bucket does not have a bucket policy that allows S3 to invoke Lambda.
AnswerC

This would cause an error, but the question says the pipeline is not triggering, implying no invocation.

Why this answer

The most likely cause is that the Lambda function does not have permission to start the pipeline. S3 event notifications can invoke Lambda regardless of whether S3 versioning is enabled, so versioning is not required. For the pipeline to start, the Lambda function's execution role must have permission to call codepipeline:StartPipelineExecution on the target pipeline.

If that permission is missing, the S3 event will invoke Lambda but the pipeline will not start. (Note: the S3 bucket must also allow S3 to invoke the Lambda function; however, among the provided options, the missing Lambda permission to start the pipeline is the most likely cause.)

Exam trap

The trap is assuming that S3 versioning is required for S3 event notifications or CodePipeline S3 source actions. S3 event notifications work without versioning, and CodePipeline can use S3 sources without requiring versioning. Focus on the IAM permissions needed for the Lambda function to start the pipeline.

How to eliminate wrong answers

Option B is wrong because the pipeline execution role's permission to read from the S3 bucket is not the issue; the pipeline is not triggering at all, which points to the detection mechanism, not read permissions. Option C is wrong because the Lambda function's permission to start the pipeline is a separate concern; if the function is invoked but fails to start the pipeline, you would see invocation errors, but the question states the pipeline is not triggering, implying the event notification itself is failing. Option D is wrong because S3 does not require a bucket policy to invoke Lambda; instead, the Lambda function's resource-based policy must grant S3 permission to invoke it, and the question does not indicate that the Lambda function is not being invoked.

583
Multi-Selectmedium

A developer is deploying an application using AWS CloudFormation. The stack includes an Amazon RDS DB instance. To ensure secure credential management, which TWO actions should the developer take? (Choose TWO.)

Select 2 answers
A.Use AWS Systems Manager Parameter Store with a SecureString parameter for the password.
B.Use AWS Secrets Manager to store the master password and reference it dynamically.
C.Hardcode the master password in the CloudFormation template.
D.Use IAM database authentication to manage credentials.
E.Leave the master password empty so that CloudFormation generates a random password.
AnswersA, B

Using AWS Systems Manager Parameter Store with a SecureString parameter is a robust solution for storing sensitive data like passwords. SecureString parameters are encrypted at rest using AWS Key Management Service (KMS) and can be securely referenced within CloudFormation templates using dynamic references or `Fn::Sub` functions. This method ensures the password is never exposed in plain text within the template or CloudFormation console, adhering to security best practices for non-rotating secrets.

Why this answer

AWS Systems Manager Parameter Store with a SecureString parameter is correct because it allows you to securely store the RDS master password as an encrypted parameter and reference it in the CloudFormation template using the `resolve:ssm` or `resolve:ssm-secure` dynamic reference. This avoids hardcoding the password in the template or exposing it in plaintext, while still enabling automated deployment.

Exam trap

The trap here is that candidates may confuse IAM database authentication (which handles user-level access) with master password management, or assume CloudFormation can auto-generate passwords for RDS, but neither is correct for securely setting the initial master password.

584
MCQhard

A company runs a microservices architecture on Amazon ECS with Fargate. Each service exposes an HTTP API and needs to be accessible only from the company's internal network via a VPN. The services are deployed in private subnets. What is the MOST secure and scalable way to expose these services?

A.Create a VPC Endpoint service powered by PrivateLink and a Network Load Balancer in front of the services.
B.Place an Application Load Balancer in public subnets and point to the services' target groups.
C.Use a NAT Gateway to allow inbound traffic from the VPN to the services.
D.Use an Internet Gateway and route traffic from the VPN to the services.
AnswerA

A VPC Endpoint service, powered by AWS PrivateLink, enables secure, private connectivity from other VPCs or on-premises networks (via VPN/Direct Connect) to services hosted within your VPC. By placing a Network Load Balancer (NLB) in front of the ECS services, the PrivateLink endpoint can expose these services securely. This setup ensures traffic remains entirely within the AWS network and your private network, bypassing the public internet and maintaining strict security for internal-only access.

Why this answer

AWS PrivateLink with a VPC Endpoint service and a Network Load Balancer (NLB) allows you to expose services running in private subnets to other VPCs or on-premises networks via VPN without traversing the public internet. The NLB handles TCP traffic at Layer 4, and the VPC Endpoint service provides secure, scalable connectivity by creating elastic network interfaces in the consumer VPC, ensuring traffic stays within the AWS network. This approach is both secure (no public exposure) and scalable (NLB handles high throughput and availability).

Exam trap

The trap here is that candidates often confuse NAT Gateway (outbound only) with a solution for inbound traffic, or they assume an ALB in public subnets is acceptable because it can be restricted via security groups, but that still exposes the services to the internet at the network layer.

How to eliminate wrong answers

Option B is wrong because placing an Application Load Balancer in public subnets would expose the services to the internet, violating the requirement that services be accessible only from the internal network via VPN. Option C is wrong because a NAT Gateway is used for outbound traffic from private subnets to the internet, not for inbound traffic from a VPN; it cannot accept inbound connections initiated from outside the VPC. Option D is wrong because an Internet Gateway is designed for direct internet access, and routing VPN traffic through it would expose services to the public internet, defeating the purpose of private subnets and internal-only access.

585
MCQhard

Refer to the exhibit. A developer is troubleshooting a failed CodeDeploy deployment to an EC2 Auto Scaling group. The instance logs show that the 'BeforeInstall' script failed with exit code 1. What should the developer do to resolve the issue?

A.Review the BeforeInstall script for errors and fix them.
B.Ensure the CodeDeploy agent is installed and running on the instance.
C.Verify that the scripts location in the AppSpec file is correct.
D.Check that the instance's IAM role has permissions to download the revision.
AnswerA

An exit code of 1 from a CodeDeploy lifecycle hook script, such as `BeforeInstall`, explicitly indicates that the script itself encountered an error and terminated abnormally. This typically means there's a syntax error, a command failed, or a logical condition within the script was not met, preventing successful execution of its intended tasks. Troubleshooting should involve reviewing the script's contents, checking logs on the instance for specific error messages, and ensuring all commands within it are valid and executable in the target environment.

Why this answer

The 'BeforeInstall' script failed with exit code 1, which is a generic error indicating the script itself encountered an issue during execution. The developer should review the script for errors, such as syntax mistakes, missing dependencies, or incorrect commands, and fix them. This is the most direct and appropriate action because the failure is explicitly tied to the script's execution, not to infrastructure or permissions.

Exam trap

The trap here is that candidates may assume a script failure is always due to permissions or agent issues, but the exit code 1 specifically points to a script-level error, not infrastructure or configuration problems.

How to eliminate wrong answers

Option B is wrong because the CodeDeploy agent is already running (the instance logs show the script executed, which requires the agent), so reinstalling or checking the agent is unnecessary. Option C is wrong because if the script location in the AppSpec file were incorrect, the script would not have run at all, but the logs confirm it executed and failed. Option D is wrong because the instance successfully downloaded the revision (the script ran), so the IAM role permissions are sufficient; a permissions issue would prevent the download, not cause a script exit code 1.

586
MCQeasy

A developer needs to allow an EC2 instance to access a DynamoDB table. Which IAM entity should be attached to the EC2 instance?

A.IAM group
B.IAM role
C.IAM user
D.Resource-based policy on the DynamoDB table
AnswerB

An IAM role is an identity that can assume permissions, designed for AWS services, federated users, or EC2 instances. When an IAM role is attached to an EC2 instance via an instance profile, the instance can assume the role, obtaining temporary security credentials that grant it the permissions defined in the role's policies. This mechanism allows the EC2 instance to securely access other AWS services like DynamoDB without storing long-term credentials on the instance itself, adhering to the principle of least privilege and enhancing security.

Why this answer

An IAM role is the correct entity to attach to an EC2 instance because it provides temporary security credentials via the AWS Security Token Service (STS) that the instance can assume. This allows the EC2 instance to securely access the DynamoDB table without embedding long-term access keys in the instance. The role is attached to the instance profile, which the EC2 instance metadata service (IMDS) uses to retrieve credentials automatically.

Exam trap

The trap here is that candidates often confuse IAM roles with IAM users, thinking a user can be attached to an EC2 instance, but AWS does not allow attaching a user to a resource—only roles can be assumed by AWS services like EC2.

How to eliminate wrong answers

Option A is wrong because an IAM group is a collection of IAM users and cannot be directly attached to an EC2 instance; groups are used to manage permissions for users, not for AWS resources. Option C is wrong because an IAM user has long-term credentials (access key ID and secret access key) that would need to be stored on the EC2 instance, which is a security risk and not a best practice for granting permissions to an AWS service. Option D is wrong because a resource-based policy on the DynamoDB table can grant access to principals (like IAM roles or users) but cannot be attached to an EC2 instance; the EC2 instance itself must have an identity (role) to authenticate against the policy.

587
MCQmedium

A developer is using AWS CodeDeploy to deploy a new version of a web application to an Auto Scaling group of Amazon EC2 instances. The deployment must install dependencies and run a script to start the application after the new revision is copied to the instance. The developer has created an appspec.yml file with the necessary hooks. Which of the following must the developer ensure to allow CodeDeploy to execute the scripts on the instances?

A.The developer must store the application revision in an Amazon S3 bucket and grant the EC2 instances direct read access to that bucket so they can download and execute the scripts.
B.The instances must be associated with a security group that allows inbound traffic on port 22 from the CodeDeploy service IP range so that CodeDeploy can SSH into the instances and run the scripts.
C.The CodeDeploy agent must be installed and running on the instances, and the instances must have an IAM instance profile that allows them to access the CodeDeploy service.
D.The developer must attach an IAM role to the CodeDeploy service role that allows it to execute scripts on the instances via AWS Systems Manager Run Command.
AnswerC

The CodeDeploy agent is required on each EC2 instance to receive deployment commands, copy the revision, and run lifecycle event hooks. The instance profile grants permissions to communicate with CodeDeploy and retrieve deployment artifacts, which is essential for successful deployments in an Auto Scaling group.

Why this answer

For CodeDeploy to deploy to EC2 instances, the CodeDeploy agent must be installed and running on each instance. The instances also need an IAM instance profile that grants permissions to communicate with CodeDeploy and retrieve deployment artifacts. This setup allows CodeDeploy to orchestrate the deployment and run lifecycle hooks defined in appspec.yml.

Exam trap

The trap here is assuming that CodeDeploy uses SSH or Systems Manager to execute scripts, when it actually relies on an agent installed on the instances.

588
MCQhard

A company has a requirement that all API calls to AWS must be logged and monitored for suspicious activity. They want to receive alerts when root account activity is detected. Which AWS service and configuration should they use?

A.Enable AWS CloudTrail and configure SNS notifications for root account events.
B.Enable AWS CloudTrail and create a CloudWatch Events rule to match root account API calls and trigger a Lambda function.
C.Use VPC Flow Logs to capture API calls and analyze with Athena.
D.Use AWS Config rules to detect root account usage.
AnswerB

This option correctly outlines the standard and most effective architecture for real-time alerting on specific AWS API calls, such as root account usage. AWS CloudTrail captures all API activity, which can then be streamed to CloudWatch Logs. A CloudWatch Events rule (now often referred to as Amazon EventBridge) can be configured to filter these log events for specific patterns, like API calls made by the root user. Upon a match, the rule can reliably trigger an AWS Lambda function, which can then perform custom actions such as sending detailed alerts, enriching data, or initiating automated remediation.

Why this answer

AWS CloudTrail captures all API calls, including those made by the root account. By creating a CloudWatch Events (now Amazon EventBridge) rule that matches the `userIdentity.type` field set to `Root` and the `eventSource` set to `signin.amazonaws.com`, you can trigger a Lambda function to send alerts or perform remediation. This provides real-time monitoring and notification for suspicious root account activity.

Exam trap

The trap here is confusing CloudTrail's logging capability with direct notification configuration—candidates often think SNS can be attached directly to CloudTrail, but CloudTrail requires an intermediary like CloudWatch Events to filter and route events to SNS or Lambda.

How to eliminate wrong answers

Option A is wrong because while CloudTrail logs root account events, SNS notifications cannot be directly configured on CloudTrail; you need a CloudWatch Events rule to filter and route the events to an SNS topic. Option C is wrong because VPC Flow Logs capture network traffic metadata (IP addresses, ports, protocols) at layer 3/4, not API call details; they cannot log or monitor AWS API calls. Option D is wrong because AWS Config rules evaluate resource configuration compliance (e.g., whether an S3 bucket is public), not user activity or API call patterns; they cannot detect root account usage.

589
MCQeasy

A developer is troubleshooting a web application that intermittently returns HTTP 504 errors. The application runs on EC2 instances behind an Application Load Balancer. What is the most likely cause of these errors?

A.The target group is using an HTTPS health check but the instances only support HTTP.
B.The load balancer's cross-zone load balancing is disabled.
C.The load balancer idle timeout is set too low, and the application takes longer than the timeout to respond.
D.The security group for the EC2 instances is missing an inbound rule for the load balancer.
AnswerC

The load balancer idle timeout specifies the maximum duration the load balancer will wait for a response from a registered target before closing the connection. If the backend application takes longer to process a request and send a response than this configured timeout, the load balancer will terminate the connection. This action directly results in an HTTP 504 Gateway Timeout error being returned to the client, indicating a lack of timely response.

Why this answer

HTTP 504 (Gateway Timeout) errors from an Application Load Balancer indicate that the load balancer successfully connected to the target (EC2 instance) but the target did not respond within the configured idle timeout period. The default idle timeout is 60 seconds, and if the application's processing time exceeds this value, the load balancer terminates the connection and returns a 504. Option C directly addresses this mismatch between the load balancer timeout and the application response time.

Exam trap

The trap here is that candidates often confuse HTTP 504 (Gateway Timeout) with HTTP 502 (Bad Gateway) or health check failures, leading them to select options related to security groups or health check mismatches instead of the correct idle timeout configuration.

How to eliminate wrong answers

Option A is wrong because HTTPS health checks require the target to support HTTPS; if the instances only support HTTP, the health check would fail and the instances would be marked unhealthy, leading to 503 errors (not 504). Option B is wrong because disabling cross-zone load balancing affects traffic distribution across Availability Zones, not the timeout behavior that causes 504 errors. Option D is wrong because a missing inbound security group rule for the load balancer would prevent the load balancer from establishing connections to the instances, resulting in 502 errors or health check failures, not intermittent 504 timeouts.

590
Multi-Selectmedium

Which THREE are best practices for deploying applications with AWS Elastic Beanstalk? (Choose THREE.)

Select 3 answers
A.Manually update EC2 instances in the environment.
B.Use environment configuration files (.ebextensions) to manage settings.
C.Use a blue/green deployment to minimize downtime.
D.Deploy to a staging environment before production.
E.Always use the default Elastic Beanstalk domain for production.
AnswersB, C, D

Utilizing `.ebextensions` configuration files is a fundamental best practice for Elastic Beanstalk deployments. These YAML or JSON files allow developers to customize and extend the environment by defining custom resources, installing packages, modifying server configurations, and running scripts. This declarative approach ensures that every deployment consistently applies the desired settings and infrastructure modifications, promoting repeatability and reducing configuration drift across environments.

Why this answer

Ebextensions configuration files allow you to define environment settings, software configurations, and custom resources declaratively, ensuring consistent and repeatable deployments without manual intervention. This aligns with the best practice of infrastructure as code, as Elastic Beanstalk automatically applies these settings during environment creation and updates.

Exam trap

The trap here is that candidates may think manual EC2 updates (Option A) are acceptable for quick fixes, but Elastic Beanstalk's managed updates and immutable deployments are designed to prevent configuration drift and ensure environment consistency.

591
MCQeasy

A developer is using AWS CodeBuild to compile and package a Java application. The build process takes longer than expected. The developer wants to speed up the build by reusing dependencies that have not changed between builds. Which feature should the developer enable?

A.Configure the build project to run builds concurrently
B.Enable build artifacts in the CodeBuild project
C.Enable caching for the CodeBuild project by specifying an S3 bucket for cache storage
D.Store the build's output artifacts in an S3 bucket
AnswerC

Enabling caching for the CodeBuild project by specifying an S3 bucket for cache storage is the intended solution: CodeBuild downloads a cache archive from the given S3 bucket before the build and uploads it again afterward. This lets package managers like Maven, Gradle, npm, or pip reuse previously downloaded dependencies, dramatically reducing build time and network traffic for untouched dependencies. You can configure cache paths in the buildspec to collect and restore the correct directories. This is the standard, documented way to cache dependencies in CodeBuild.

Why this answer

AWS CodeBuild caching allows you to persist dependencies (e.g., Maven .m2 repository, Gradle caches) between builds. By specifying an S3 bucket as the cache storage, CodeBuild uploads the cache after a successful build and downloads it at the start of subsequent builds, avoiding re-downloading unchanged dependencies. This significantly reduces build time for Java applications.

Exam trap

DVA-C02 often tests the confusion between caching (for dependencies) and artifacts (for build outputs), leading candidates to choose artifact-related options when asked about speeding up builds by reusing dependencies.

How to eliminate wrong answers

Option A is wrong because running builds concurrently increases throughput but does not reduce the time of an individual build; it may even increase resource contention. Option B is wrong because build artifacts are the output of the build (e.g., JAR files) and do not affect dependency resolution speed. Option D is wrong because storing output artifacts in S3 is for post-build storage and distribution, not for caching dependencies to speed up builds.

592
Multi-Selecteasy

A developer is using an Amazon SQS queue with a Lambda function as a consumer. Messages are being sent to the queue but the Lambda function is not processing them. Which THREE of the following are possible causes?

Select 3 answers
A.The SQS queue has a dead-letter queue configured.
B.The SQS queue policy denies access to the Lambda function.
C.The Lambda function's execution role does not have sqs:ReceiveMessage permission.
D.The SQS queue has a rate limit that prevents Lambda from polling.
E.The event source mapping between SQS and Lambda is disabled.
AnswersB, C, E

An SQS queue policy is a resource-based policy that defines who can access the queue and what actions they can perform. If this policy contains an explicit Deny statement for the sqs:ReceiveMessage action (or other relevant polling actions) for the Lambda function's execution role, the Lambda service will be unable to poll messages from the queue. This explicit denial takes precedence over any Allow statements in the Lambda's IAM role, effectively blocking access.

Why this answer

The SQS queue policy is a resource-based policy that controls which principals (like Lambda's execution role) can perform actions on the queue. If the policy explicitly denies the Lambda function's access, the function will not be able to poll or delete messages from the queue, even if its own execution role grants those permissions.

Exam trap

The trap here is that candidates often overlook resource-based policies (like SQS queue policies) and focus only on the Lambda execution role, assuming that if the role has permissions, the integration will work, but the queue policy can independently deny access.

593
MCQeasy

A developer is deploying a serverless application using AWS CloudFormation. The stack creation fails with the error 'The following resource(s) failed to create: [MyLambdaFunction]'. The developer checks the CloudWatch logs but finds no logs for the Lambda function. What is the most likely reason?

A.The Lambda function code has a syntax error that prevents creation.
B.The Lambda function was never invoked.
C.The Lambda function's IAM role does not have permission to write to CloudWatch Logs.
D.The CloudFormation template has a syntax error.
AnswerD

A syntax error in the CloudFormation template, such as a missing required property for the Lambda resource, can cause creation failure. The error message and lack of logs are consistent with this.

Why this answer

A CloudFormation template syntax error, such as a missing required property (e.g., 'Handler' or 'Runtime'), can cause the Lambda function resource to fail creation. The error message indicates the specific resource failed, and the absence of CloudWatch logs is expected because the function was never created. Option A is incorrect because code syntax errors do not prevent resource creation; they affect invocation.

Option B is incorrect because the function not being invoked is a consequence, not the cause. Option C is incorrect because missing CloudWatch Logs permissions do not prevent creation; they only affect logging during invocation.

Exam trap

The key trap is that candidates may assume the absence of logs means the function was never invoked or that a code error existed. However, the error explicitly states the resource failed to create, so the function was never deployed. The missing logs are a direct consequence of the creation failure, not a separate issue.

The root cause is often a CloudFormation template error, such as a missing required property (e.g., 'Handler' or 'Runtime'), which causes the Lambda resource to fail creation.

How to eliminate wrong answers

Option A is wrong because a syntax error in the Lambda function code would not prevent the resource from being created; CloudFormation would still create the function, but invocation would fail, and logs would appear (if permissions allow). Option B is wrong because the error message states the resource failed to create, meaning the function was never successfully created, so it cannot be invoked; the absence of logs is not due to lack of invocation but due to creation failure. Option D is wrong because a CloudFormation template syntax error would cause a different error (e.g., 'Template validation error') and would prevent the entire stack from being parsed, not just a single resource creation failure.

594
MCQeasy

A developer needs to deploy a containerized application on AWS. The application requires persistent storage for stateful data. Which AWS compute service should the developer choose?

A.Amazon ECS with Fargate
B.AWS Elastic Beanstalk
C.Amazon EKS with Fargate
D.AWS Lambda
AnswerA

This combination is ideal for deploying containerized applications requiring persistent storage because Amazon ECS provides robust container orchestration, while Fargate eliminates the need to manage underlying EC2 instances. For stateful applications, ECS tasks running on Fargate can seamlessly integrate with Amazon EFS for shared file system access or utilize bind mounts to local ephemeral storage (though EFS is preferred for true persistence across task restarts). This offers a fully managed, scalable, and highly available solution for stateful container workloads without server management overhead.

Why this answer

Amazon ECS with Fargate is the best choice for deploying a containerized application with persistent storage. Fargate supports persistent storage by integrating with Amazon EFS. While Amazon EKS with Fargate also supports persistent storage, ECS with Fargate offers simpler management and is often preferred for stateful containers.

AWS Elastic Beanstalk can run containers but is more opinionated and less flexible for stateful configurations. AWS Lambda is stateless and ephemeral, not suitable for persistent storage.

595
MCQmedium

A company is building a serverless application using AWS Lambda to process user uploads to Amazon S3. The Lambda function needs to access a DynamoDB table to store metadata. What is the MOST secure way to grant the Lambda function access to DynamoDB?

A.Store IAM user access keys in the Lambda function's environment variables.
B.Use a resource-based policy on the DynamoDB table to allow the Lambda function's ARN.
C.Create an IAM role with a policy that grants DynamoDB access and attach it to the Lambda function.
D.Hardcode the DynamoDB credentials in the Lambda function code.
AnswerC

An IAM role attached to the Lambda function supplies temporary credentials via the execution environment, so no long-term keys are stored in code or environment variables. This satisfies least-privilege access to DynamoDB without embedding static credentials.

Why this answer

AWS Lambda uses an IAM role (execution role) to obtain temporary credentials via the AWS Security Token Service (STS). Attaching a policy that grants DynamoDB access to this role follows the principle of least privilege and avoids long-term credentials. This is the standard, secure pattern for granting Lambda functions access to other AWS services.

Exam trap

The trap here is that candidates confuse resource-based policies (which work for services like S3 and SQS) with the need for an execution role for Lambda, leading them to incorrectly select Option B, even though DynamoDB does not support resource-based policies for granting access to Lambda functions.

How to eliminate wrong answers

Option A is wrong because storing IAM user access keys in environment variables introduces long-term credentials that can be leaked, and it violates the AWS best practice of using temporary credentials via IAM roles. Option B is wrong because resource-based policies on DynamoDB tables cannot grant access to a Lambda function directly; DynamoDB does not support resource-based policies for Lambda invocation, and the Lambda function still needs an execution role to assume permissions. Option D is wrong because hardcoding credentials in code is insecure, makes rotation difficult, and violates the principle of never embedding secrets in application code.

596
MCQeasy

A developer is deploying a serverless application using AWS SAM. The application includes an API Gateway REST API and a Lambda function. The developer wants to set up a custom domain name for the API in the production stage. Which resource should the developer define in the SAM template to achieve this with minimal effort?

A.AWS::ApiGateway::DomainName
B.AWS::Serverless::Api
C.AWS::ApiGateway::BasePathMapping
D.AWS::Route53::RecordSet
AnswerB

The AWS::Serverless::Api resource in AWS SAM provides a high-level abstraction for defining an Amazon API Gateway REST API, including its custom domain configuration. By utilizing its `Domain` property, developers can specify a custom domain name, a certificate ARN from AWS Certificate Manager (ACM), and base path mappings directly within the SAM template. SAM then automatically provisions the underlying `AWS::ApiGateway::DomainName` and `AWS::ApiGateway::BasePathMapping` CloudFormation resources, simplifying the setup of custom domains for serverless APIs.

Why this answer

The AWS::Serverless::Api resource in an AWS SAM template provides a high-level abstraction that simplifies the configuration of API Gateway REST APIs, including the ability to set up a custom domain name via the Domain property. This approach requires minimal effort because SAM automatically creates the underlying AWS::ApiGateway::DomainName and AWS::ApiGateway::BasePathMapping resources, handles the TLS certificate association, and manages the stage deployment. Defining a raw AWS::ApiGateway::DomainName would require additional manual configuration for base path mapping and stage integration, making the Serverless::Api the most efficient choice.

Exam trap

The trap here is that candidates often think they must define the low-level AWS::ApiGateway::DomainName resource directly, overlooking that AWS SAM's AWS::Serverless::Api provides a built-in Domain property that automates the entire custom domain setup with minimal code.

How to eliminate wrong answers

Option A is wrong because AWS::ApiGateway::DomainName only defines the custom domain name and its TLS certificate; it does not automatically create the base path mapping or integrate with the API stage, so additional resources and manual wiring are needed. Option C is wrong because AWS::ApiGateway::BasePathMapping maps a base path to an API stage but does not create the custom domain name itself; it must be used in conjunction with a DomainName resource, increasing complexity. Option D is wrong because AWS::Route53::RecordSet creates a DNS record (e.g., CNAME or A alias) to point a custom domain to the API Gateway endpoint, but it does not configure the API Gateway custom domain name or TLS termination; it is a DNS-only resource and cannot replace the DomainName configuration.

597
MCQhard

A company has an IAM policy that allows access to an S3 bucket only if the request comes from a specific VPC endpoint. The developer notices that requests from an EC2 instance in that VPC are being denied. What is the most likely cause?

A.The VPC endpoint policy does not allow the required S3 action for the principal
B.The bucket policy does not have a condition checking aws:SourceVpce
C.The route table does not have a route to the S3 endpoint
D.The security group does not allow outbound HTTPS traffic
AnswerA

A VPC endpoint policy acts as an explicit access control layer for requests originating from within your VPC to AWS services like S3. If this policy does not explicitly permit the required S3 action, such as 's3:GetObject', for the requesting principal, it will override any permissions granted by the IAM user/role policy or the S3 bucket policy. This results in an 'Access Denied' error because the request is blocked at the endpoint before reaching the S3 bucket's own policy evaluation.

Why this answer

The VPC endpoint policy is an additional layer of access control that can explicitly deny actions even if the bucket policy allows them. If the endpoint policy does not grant the required S3 action (e.g., s3:GetObject) for the IAM principal (the EC2 instance's role), requests will be denied regardless of the bucket policy. This is a common misconfiguration where developers focus only on the bucket policy and overlook the endpoint policy.

Exam trap

The trap here is that candidates assume the bucket policy is the only control point and overlook the VPC endpoint policy, which acts as a separate authorization layer that can silently deny requests even when the bucket policy appears correct.

How to eliminate wrong answers

Option B is wrong because the bucket policy condition checking aws:SourceVpce is necessary to restrict access to the VPC endpoint, but the question states the policy already allows access only from a specific VPC endpoint; the issue is that requests are denied, so the condition is likely present but the endpoint policy is blocking. Option C is wrong because the route table does not need a route to the S3 endpoint; VPC endpoints use prefix lists and route tables direct traffic to the endpoint via a gateway or interface endpoint, but missing routes would cause a timeout or connection failure, not an IAM denial. Option D is wrong because security groups do not apply to VPC endpoint traffic; S3 uses a gateway endpoint which is not associated with security groups, and outbound HTTPS traffic from the EC2 instance is allowed by default in the VPC.

598
Multi-Selecteasy

A company is deploying a web application on AWS Elastic Beanstalk. The application uses an Amazon RDS database. The company wants to ensure that database credentials are not exposed in the application code or environment variables. Which TWO methods are secure ways to manage credentials? (Choose TWO.)

Select 2 answers
A.Store credentials in AWS Secrets Manager and retrieve them at runtime.
B.Store credentials in an Amazon S3 bucket with server-side encryption.
C.Hardcode credentials in the application configuration file.
D.Store credentials in AWS Systems Manager Parameter Store with SecureString parameter type.
E.Store credentials as environment variables in the Elastic Beanstalk environment.
AnswersA, D

AWS Secrets Manager encrypts secrets with KMS keys and provides a dedicated GetSecretValue API for runtime retrieval, so application code never contains or resolves the secret itself. It also supports automatic rotation of database credentials via Lambda, fine-grained IAM policies, and cross-account access, making it the most built-for-purpose option for dynamically fetching secrets in an Elastic Beanstalk environment.

Why this answer

Option A is correct because AWS Secrets Manager is purpose-built for storing and rotating secrets such as RDS database credentials, and the application can retrieve them at runtime via the AWS SDK using IAM permissions, so the credentials never appear in code or environment variables. Option D is correct because AWS Systems Manager Parameter Store supports the SecureString parameter type, which encrypts values with AWS KMS and allows retrieval at runtime through IAM-controlled API calls, keeping credentials out of the application code and environment variables. Option B is not appropriate because an S3 object, even with server-side encryption, is not a dedicated secrets-management service and would still require custom retrieval logic and careful access controls to avoid exposure.

Option C is wrong because hardcoding credentials in a configuration file directly exposes them in source control and deployment artifacts. Option E is wrong because Elastic Beanstalk environment variables are visible in the console and configuration and are explicitly what the scenario wants to avoid.

Exam trap

DVA-C02 often tests whether candidates recognize that environment variables and S3-stored secrets are not secure credential stores, luring them toward 'encrypted S3' as if encryption alone made it a secrets manager.

599
MCQhard

A developer attaches the following IAM policy: ```json { "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": "ec2:RunInstances", "Resource": "*" }, { "Effect": "Deny", "Action": "ec2:RunInstances", "Resource": "*", "Condition": { "StringNotEquals": { "ec2:InstanceType": "t2.micro" } } } ] } ``` What happens when the developer attempts to launch a t2.micro instance?

A.The action is denied because ec2:RunInstances requires additional permissions.
B.The action is allowed because the Allow statement applies and the Deny condition excludes t2.micro.
C.The action is denied because the Deny statement overrides the Allow.
D.The action is allowed only if the user has ec2:DescribeInstances as well.
AnswerB

Correct. In IAM, a request is implicitly denied if no Allow matches, but here the Allow for ec2:RunInstances matches the action and applies to the principal. The Deny statement includes a condition that evaluates to false for t2.micro, so it does not apply. Because there is no applicable Deny and at least one applicable Allow, the launch proceeds successfully.

Why this answer

AWS IAM evaluates all applicable statements, and an explicit Deny always overrides an Allow — but only when the Deny's condition evaluates to true. Here the Deny uses StringNotEquals on ec2:InstanceType with value t2.micro, so for a t2.micro launch the condition is false and the Deny does not apply. The Allow on ec2:RunInstances with Resource '*' therefore takes effect and the launch is permitted.

Exam trap

DVA-C02 often tests the misconception that 'Deny always overrides Allow' unconditionally — the real rule is that a Deny only overrides when its condition evaluates true, so candidates who ignore the StringNotEquals condition pick option C.

How to eliminate wrong answers

Option A is wrong because ec2:RunInstances does not require additional permissions to succeed on its own — the policy already grants it, and no dependent action like iam:PassRole is needed for a simple instance launch without an instance profile. Option C is wrong because while Deny normally overrides Allow, that only holds when the Deny statement's condition is satisfied; here StringNotEquals evaluates false for t2.micro, so the Deny is inert. Option D is wrong because ec2:DescribeInstances is a separate read permission not required to call RunInstances; IAM does not implicitly require describe permissions for launch.

600
MCQeasy

A developer needs to send large files (up to 5 GB) from a web application to Amazon S3. The application runs on EC2 instances. Which approach is MOST efficient and reliable?

A.Save the file to EC2 instance store and then copy to S3.
B.Upload the file as a single S3 PutObject operation.
C.Use S3 multipart upload to upload the file in parts.
D.Use S3 Transfer Acceleration to upload the file.
AnswerC

S3 multipart upload is the recommended and most efficient method for uploading large objects, especially those exceeding 100 MB, and is required for objects larger than 5 GB. This method breaks the file into smaller, independent parts, which can be uploaded concurrently, significantly improving throughput and resilience. If a part fails, only that specific part needs to be re-uploaded, rather than the entire file, ensuring greater reliability and faster recovery from network issues.

Why this answer

S3 multipart upload is the most efficient and reliable approach for uploading large files (up to 5 GB) because it allows the file to be split into smaller parts that can be uploaded in parallel, improving throughput and resilience. If a part fails, only that part needs to be retried, not the entire file, and the upload can be paused and resumed. This is the recommended AWS method for objects larger than 100 MB and is required for objects over 5 GB.

Exam trap

The trap here is that candidates may think S3 Transfer Acceleration (Option D) is the best choice for large files because it speeds up transfers, but they overlook that multipart upload is the fundamental mechanism for reliability and efficiency with large objects, while Transfer Acceleration is an optional performance enhancement that can be used on top of multipart upload.

How to eliminate wrong answers

Option A is wrong because saving to EC2 instance store is ephemeral (data is lost on instance stop/termination) and adds an unnecessary intermediate step with no benefit for reliability or efficiency. Option B is wrong because a single PutObject operation for a 5 GB file is prone to network interruptions, requires the entire upload to restart on failure, and has a hard limit of 5 GB (the maximum object size in a single PUT is 5 GB, but multipart is still recommended for files over 100 MB). Option D is wrong because S3 Transfer Acceleration optimizes network path and speed for long-distance transfers but does not provide the reliability benefits of parallel uploads or retry granularity; it can be combined with multipart upload but is not the primary solution for reliability.

Page 7

Page 8 of 16

Page 9