Courseiva

CCNA Development with AWS Services Questions

75 of 388 questions · Page 2/6 · Development with AWS Services · Answers revealed

76
MCQmedium

A company is using AWS Lambda functions behind an Amazon API Gateway REST API. Users report intermittent 503 errors. The Lambda function code appears correct. Which action is MOST likely to resolve the issue?

A.Increase the Lambda function memory allocation.
B.Increase the Lambda function timeout.
C.Request a service quota increase for Lambda concurrent executions.
D.Increase the API Gateway throttling limits.
AnswerC

A 503 Service Unavailable error from Lambda indicates that the service is currently unable to handle the request, most commonly because the account's or function's concurrent execution quota has been reached. Each AWS account has a default regional concurrency limit for Lambda functions, and exceeding this limit causes subsequent invocation attempts to be throttled. Requesting a service quota increase directly addresses this bottleneck, allowing more Lambda instances to run in parallel and process incoming API Gateway requests.

Why this answer

Intermittent 503 errors from API Gateway often indicate that Lambda concurrent execution limits have been reached. When the number of simultaneous invocations exceeds the account-level or function-level reserved concurrency, API Gateway returns a 503 'Service Unavailable' response. Increasing the Lambda concurrent executions quota allows more invocations to be processed without throttling.

Exam trap

The trap here is that candidates confuse API Gateway throttling limits (which return 429 errors) with Lambda concurrency limits (which return 503 errors), leading them to incorrectly choose option D.

How to eliminate wrong answers

Option A is wrong because increasing memory allocation improves CPU performance and execution speed, but does not resolve throttling due to concurrency limits. Option B is wrong because increasing the timeout only allows the function to run longer, but does not prevent new invocations from being rejected when concurrency is exhausted. Option D is wrong because API Gateway throttling limits (e.g., 10,000 requests per second by default) are typically much higher than Lambda concurrency limits, and the 503 error is caused by Lambda throttling, not API Gateway throttling.

77
MCQhard

A developer is using AWS X-Ray to trace a serverless application. The application uses an AWS Lambda function to query a DynamoDB table. The trace shows that the DynamoDB subsegment takes a significant portion of the total response time. The developer wants to reduce the DynamoDB query latency. Which service should the developer integrate with the Lambda function to achieve the lowest latency for repeated read queries?

A.DynamoDB Accelerator (DAX)
B.Amazon ElastiCache for Redis
C.DynamoDB Global Tables
D.DynamoDB Streams
AnswerA

DynamoDB Accelerator (DAX) is a fully managed, in-memory cache specifically designed to sit in front of DynamoDB tables. It provides microsecond response times for read-heavy workloads by caching frequently accessed data, significantly improving performance for serverless applications. DAX is API-compatible with DynamoDB, requiring minimal application code changes to integrate and benefit from its high-performance caching capabilities, making it ideal for reducing read latency.

Why this answer

DynamoDB Accelerator (DAX) is a fully managed, highly available, in-memory cache for DynamoDB that delivers up to 10x read performance improvement by reducing response times from milliseconds to microseconds for repeated read queries. By integrating DAX with the Lambda function, the developer can cache the results of frequent DynamoDB queries directly in memory, bypassing the read capacity units and the underlying storage engine, which directly addresses the latency bottleneck shown in the X-Ray trace.

Exam trap

The trap here is that candidates often choose ElastiCache for Redis because it is a well-known caching solution, but they overlook that DAX is purpose-built for DynamoDB and provides lower latency with zero application-level cache management, making it the correct choice for reducing DynamoDB query latency in a serverless application.

How to eliminate wrong answers

Option B (Amazon ElastiCache for Redis) is wrong because it is a general-purpose caching solution that requires the developer to manually manage cache invalidation, data synchronization, and application-level logic to keep the cache consistent with DynamoDB, adding complexity and potential latency overhead compared to DAX's native DynamoDB integration. Option C (DynamoDB Global Tables) is wrong because it is designed for multi-region replication and disaster recovery, not for reducing read latency within a single region; it actually increases write latency due to cross-region replication and does not cache repeated read queries. Option D (DynamoDB Streams) is wrong because it captures a time-ordered sequence of item-level changes in a DynamoDB table for event-driven processing (e.g., triggering Lambda functions), but it does not provide any caching or read acceleration functionality.

78
MCQmedium

A developer is building a serverless application using AWS Lambda to process events from an Amazon SQS queue. The Lambda function is CPU-bound and currently experiences timeouts. What is the MOST cost-effective way to reduce execution time?

A.Increase the SQS batch window size
B.Switch the Lambda runtime from Python to Node.js
C.Increase the Lambda function's memory allocation
D.Enable Provisioned Concurrency for the function
AnswerC

Increasing a Lambda function's memory allocation is the most direct and effective way to improve performance for CPU-bound tasks. AWS Lambda provisions CPU power proportionally to the configured memory. Therefore, allocating more memory provides the function with a larger share of CPU resources, enabling it to complete computationally intensive operations faster and reduce overall execution time.

Why this answer

Increasing the Lambda function's memory allocation is the most cost-effective way to reduce execution time for a CPU-bound function because Lambda allocates CPU proportionally to memory. More memory means more vCPU capacity, which directly speeds up CPU-bound processing. This reduces the function's duration, and since Lambda billing is based on compute time (GB-seconds), the total cost can decrease even if the per-GB-second rate is higher.

Exam trap

The trap here is that candidates assume increasing memory only helps memory-bound workloads, but AWS Lambda's CPU allocation scales with memory, making it the primary lever for CPU-bound performance improvements.

How to eliminate wrong answers

Option A is wrong because increasing the SQS batch window size only delays event retrieval, it does not reduce the Lambda function's execution time or address CPU-bound timeouts. Option B is wrong because switching the runtime from Python to Node.js does not guarantee a performance improvement for CPU-bound tasks; the bottleneck is CPU capacity, not language overhead, and this change introduces migration risk without a cost-effective guarantee. Option D is wrong because Provisioned Concurrency keeps functions initialized and ready to handle bursts of traffic, but it does not reduce the execution time of a single invocation; it adds cost for pre-warmed instances without addressing the CPU-bound timeout issue.

79
MCQmedium

A development team is using AWS CodeBuild to compile and test their code. They want to store build artifacts in an Amazon S3 bucket. The buildspec.yml file includes an artifacts section. Which configuration correctly specifies the output artifacts?

A.artifacts: files: - '**/*' discard-paths: no
B.artifacts: base-directory: 'build' files: '**/*'
C.artifacts: file: '**/*' discard-paths: no
D.artifacts: path: '**/*' discard-paths: false
AnswerA

This configuration correctly specifies that all files and directories from the build output directory should be included as artifacts. The `files` key expects a YAML list of glob patterns, where `**/*` matches everything recursively from the `base-directory` (or root of the build output if not specified). Setting `discard-paths: no` ensures that the original directory structure of the collected files is preserved within the generated artifact archive, which is crucial for maintaining file organization during deployments.

Why this answer

It uses the correct `files` key with a glob pattern `'**/*'` to include all files, and `discard-paths: no` preserves the directory structure in the S3 bucket. In CodeBuild, the `artifacts` section requires `files` (not `file` or `path`) to specify which files to output, and `discard-paths` controls whether the relative path is kept.

Exam trap

The trap here is confusing the `files` key (plural, required) with `file` (singular, invalid) or `path` (used in other AWS services like CodePipeline), leading candidates to select options with incorrect key names.

How to eliminate wrong answers

Option B is wrong because `files` must be a list (e.g., `['**/*']`), not a string `'**/*'`; CodeBuild expects a sequence of file patterns, and a single string will cause a validation error. Option C is wrong because it uses `file:` instead of `files:`; the correct key is `files` (plural), and `file` is not a valid artifact configuration key. Option D is wrong because it uses `path:` instead of `files:`; `path` is not a valid key in the artifacts section—the correct key is `files` to define the file patterns to include.

80
MCQhard

A developer is building a serverless application using AWS Lambda and Amazon API Gateway. The developer wants to enable caching for API responses to reduce latency and cost. Which step is REQUIRED to enable caching?

A.Enable caching in the Lambda function code
B.Set the TTL in the API Gateway method request integration
C.Create a cache cluster in API Gateway for the stage
D.Use Amazon ElastiCache and modify the Lambda function to check cache
AnswerC

This is the correct approach for reducing latency by caching API responses directly within API Gateway. To enable caching, a cache cluster must be provisioned and associated with a specific API Gateway stage, where you define its capacity (e.g., 0.5 GB to 237 GB) and the default Time-To-Live (TTL) for cached responses. Once enabled, API Gateway intercepts requests, serves cached responses if available and valid, and only invokes the backend Lambda function when a cache miss occurs or the cache entry expires.

Why this answer

API Gateway caching requires a dedicated cache cluster to be enabled and configured at the stage level. This cluster stores API responses and serves them directly from the cache for identical requests, reducing the number of calls to the backend Lambda function and lowering latency. Without creating and enabling this cache cluster in the API Gateway stage settings, caching cannot function.

Exam trap

The trap here is that candidates often confuse API Gateway's built-in caching with external caching solutions like ElastiCache or assume that caching can be enabled solely by modifying Lambda code or integration settings, when in fact a dedicated cache cluster must be explicitly created and enabled at the API Gateway stage level.

How to eliminate wrong answers

Option A is wrong because caching is not implemented within the Lambda function code; Lambda functions are stateless and do not natively cache API responses. Option B is wrong because the TTL (time-to-live) for API Gateway caching is configured in the stage settings or per-method cache settings, not in the method request integration. Option D is wrong because while Amazon ElastiCache could be used for custom caching logic, it is not a required step for enabling API Gateway's built-in caching; the question asks for the required step to enable caching in API Gateway, which is to create a cache cluster in API Gateway for the stage.

81
MCQeasy

A developer is building a serverless application using AWS Lambda and Amazon DynamoDB. The Lambda function needs to read and write items to a DynamoDB table. What is the BEST way to securely provide the Lambda function with the necessary AWS credentials?

A.Store the AWS access key and secret key in the Lambda environment variables.
B.Create an IAM role with DynamoDB permissions and attach it to the Lambda function.
C.Create an IAM user with programmatic access and store the credentials in the Lambda code.
D.Use the Lambda function's default full admin access provided by AWS.
AnswerB

Creating an IAM role with specific DynamoDB permissions and attaching it to the Lambda function is the AWS-recommended and most secure approach. When the Lambda function executes, it automatically assumes this IAM role, which provides temporary, short-lived credentials to interact with DynamoDB. This method adheres to the principle of least privilege by granting only necessary permissions and eliminates the need to manage static credentials within the function code or configuration, significantly enhancing security.

Why this answer

The best practice for granting AWS Lambda functions access to DynamoDB is to create an IAM role with the necessary DynamoDB permissions (e.g., dynamodb:GetItem, dynamodb:PutItem) and attach that role to the Lambda function. This follows the principle of least privilege and leverages AWS Identity and Access Management (IAM) roles, which provide temporary, automatically rotated credentials via the AWS Security Token Service (STS). This approach eliminates the need to manage long-term access keys and ensures secure, auditable access.

Exam trap

The trap here is that candidates may think environment variables (Option A) are a secure storage mechanism because they are not in the code, but they fail to recognize that long-term access keys are still exposed and violate the IAM roles best practice for serverless applications.

How to eliminate wrong answers

Option A is wrong because storing AWS access keys and secret keys in Lambda environment variables is insecure and violates best practices; environment variables can be exposed in logs or through the Lambda console, and long-term credentials increase the risk of compromise. Option C is wrong because creating an IAM user with programmatic access and embedding the credentials in Lambda code is a security anti-pattern; it requires manual credential rotation, exposes secrets in code, and bypasses the automatic credential management provided by IAM roles. Option D is wrong because AWS does not provide 'default full admin access' to Lambda functions; the Lambda function must have an explicit IAM role attached, and granting full admin access would violate the principle of least privilege and create a severe security risk.

82
MCQhard

A developer is building a real-time chat application using Amazon API Gateway WebSockets and AWS Lambda. The developer notices that messages are sometimes delivered out of order. What should the developer do to ensure ordered message delivery?

A.Increase the Lambda function's memory allocation
B.Use API Gateway's built-in message ordering feature
C.Set the 'sequenceNumber' property in the WebSocket message
D.Use an Amazon SQS FIFO queue to buffer messages before processing
AnswerD

An Amazon SQS FIFO (First-In, First-Out) queue is specifically designed to guarantee the exact order in which messages are sent and received. By buffering chat messages in an SQS FIFO queue before they are processed by a Lambda function, the application ensures that messages from a specific message group (e.g., a chat room or user conversation) are delivered to the Lambda function strictly in the order they were sent. This mechanism prevents race conditions and ensures sequential processing, which is crucial for maintaining the integrity of a real-time chat conversation.

Why this answer

WebSocket connections run over TCP, which guarantees in-order delivery of frames from the client to Amazon API Gateway. However, when API Gateway routes these messages to AWS Lambda, Lambda executes concurrently. This concurrent execution can lead to messages being processed, written to a database, or broadcasted to other clients out of order.

To guarantee ordered processing, messages can be buffered using an Amazon SQS FIFO (First-In-First-Out) queue before being processed by Lambda, ensuring they are handled in the exact order they were received.

Exam trap

Candidates often mistake TCP/WebSocket transport guarantees for application-level processing guarantees. While the network protocol ensures packets arrive at API Gateway in order, the downstream serverless backend (Lambda) processes them concurrently, destroying that order unless a sequencing mechanism like SQS FIFO is introduced.

How to eliminate wrong answers

Option A is wrong because increasing Lambda memory allocation improves compute performance but does not affect the order in which WebSocket messages are received or processed; ordering is a network and queuing concern, not a resource allocation one. Option B is wrong because API Gateway WebSockets does not have a built-in message ordering feature; the WebSocket protocol (RFC 6455) does not guarantee ordering, and API Gateway does not add such a feature. Option C is wrong because setting a 'sequenceNumber' property in the WebSocket message is a client-side or application-level metadata field that does not enforce ordering at the infrastructure level; the Lambda function would still need to reorder messages manually, and without a FIFO mechanism, concurrent processing can still cause out-of-order delivery.

83
MCQmedium

A company uses AWS CloudFormation to deploy infrastructure. The developer needs to pass a list of security group IDs to an EC2 instance launch configuration. The security groups are created in another stack. How should the developer obtain the security group IDs?

A.Use Fn::GetAtt to retrieve the IDs from the other stack's resources.
B.Use Fn::ImportValue to import the exported outputs from the other stack.
C.Use a nested stack to include the security group resources in the same template.
D.Use Fn::Ref to reference the security group IDs directly.
AnswerB

The Fn::ImportValue intrinsic function is the correct mechanism for referencing outputs from other CloudFormation stacks. It allows a stack to consume values that have been explicitly exported by another stack using the Fn::Export function in its `Outputs` section, referencing the unique name provided during export. This design pattern promotes modularity and enables decoupled infrastructure deployments by facilitating secure and managed cross-stack communication.

Why this answer

Fn::ImportValue is designed to retrieve exported outputs from another CloudFormation stack. When security groups are created in a separate stack, the developer must export their IDs using the Export field in the Outputs section of that stack, and then use Fn::ImportValue in the current stack to reference those exported values. This is the standard cross-stack reference mechanism in CloudFormation, enabling decoupled infrastructure management.

Exam trap

The trap here is that candidates often confuse Fn::GetAtt and Fn::ImportValue, mistakenly thinking that GetAtt can retrieve attributes across stacks, when in fact it is strictly intra-stack, while ImportValue is the only native CloudFormation function for cross-stack references.

How to eliminate wrong answers

Option A is wrong because Fn::GetAtt retrieves attributes of resources within the same stack, not from another stack; it cannot reference resources across stack boundaries. Option C is wrong because using a nested stack would require restructuring the template and embedding the security group resources, which contradicts the requirement that they are created in another stack and does not solve the cross-stack reference problem. Option D is wrong because Fn::Ref returns the logical ID or physical ID of a resource only within the same template; it cannot resolve values from a different stack.

84
MCQmedium

A developer is creating a REST API using Amazon API Gateway and multiple AWS Lambda functions for different endpoints. The API must support CORS for a web application hosted on a different domain. The developer is using Lambda proxy integration. Which configuration is required to enable CORS?

A.Enable CORS in API Gateway and configure the Lambda functions to return the required CORS headers.
B.Configure API Gateway to return CORS headers and Lambda functions can ignore CORS.
C.Configure Lambda functions to return CORS headers and API Gateway will pass them through automatically.
D.Use a Lambda@Edge function at Amazon CloudFront to add CORS headers.
AnswerA

Enabling CORS in API Gateway generates an OPTIONS method and configures headers for non-proxy integrations, but for proxy integrations, the Lambda must also return the headers. Both steps are needed to ensure full CORS support.

Why this answer

With Lambda proxy integration in API Gateway, the entire request and response are passed through to the Lambda function, which must return the HTTP response including status code, headers, and body. To enable CORS, the Lambda function must include the required CORS headers (e.g., Access-Control-Allow-Origin) in its response. While API Gateway can be configured to add CORS headers for non-proxy integrations, with proxy integration the Lambda function is solely responsible for returning all headers.

Exam trap

The trap here is that candidates assume API Gateway's CORS configuration works universally, but with Lambda proxy integration, the Lambda function has full control over the response headers, making API Gateway's CORS settings ineffective.

How to eliminate wrong answers

Option B is wrong because with Lambda proxy integration, API Gateway cannot independently add CORS headers; the Lambda function controls the entire response. Option C is wrong because API Gateway does not automatically pass through headers from the Lambda function; the Lambda function must explicitly return them in the response object. Option D is wrong because Lambda@Edge is used with CloudFront for edge processing, not for API Gateway CORS configuration, and it would add unnecessary complexity and latency.

85
MCQeasy

A developer is building a serverless web application using AWS Lambda and Amazon DynamoDB. The application needs to perform complex aggregations on data stored in DynamoDB. Which AWS service should the developer use to perform these aggregations efficiently without reading all the data into Lambda?

A.AWS Glue
B.Amazon EMR
C.DynamoDB Streams with AWS Lambda
D.Amazon Redshift
AnswerC

DynamoDB Streams capture a time-ordered sequence of item-level modifications (inserts, updates, and deletes) in a DynamoDB table, providing a near real-time data feed. AWS Lambda functions can subscribe to these streams, processing batches of records as they become available. This serverless pattern allows for efficient, event-driven aggregation updates, such as maintaining counters or summary tables, without requiring expensive full table scans, making it the ideal solution for responsive data insights in a serverless web application.

Why this answer

DynamoDB Streams captures item-level changes in near real-time and can trigger a Lambda function to perform incremental aggregations without scanning the entire table. This pattern avoids reading all data into Lambda, making it efficient for continuous aggregation workloads.

Exam trap

The trap here is that candidates may choose AWS Glue or Amazon EMR because they associate 'complex aggregations' with big data tools, overlooking that DynamoDB Streams with Lambda provides a serverless, incremental aggregation pattern that avoids full table scans.

How to eliminate wrong answers

Option A is wrong because AWS Glue is a serverless ETL service designed for batch data processing and cataloging, not for real-time aggregations triggered by DynamoDB changes. Option B is wrong because Amazon EMR is a big data platform for running Apache Spark, Hadoop, or Hive clusters, which is overkill and not serverless for simple aggregations on DynamoDB data. Option D is wrong because Amazon Redshift is a petabyte-scale data warehouse for SQL analytics, not a service for performing aggregations directly on DynamoDB data without moving it first.

86
MCQmedium

A developer is building a serverless application using AWS Lambda to process files uploaded to an S3 bucket. The files are encrypted with S3 server-side encryption using AWS KMS (SSE-KMS). The Lambda function needs to read the files and store metadata in DynamoDB. Which IAM policy statement should be attached to the Lambda execution role to allow it to decrypt the objects?

A.{"Effect":"Allow","Action":["kms:Encrypt"],"Resource":"*"}
B.{"Effect":"Allow","Action":["kms:Decrypt"],"Resource":"arn:aws:kms:us-east-1:123456789012:key/1234abcd-12ab-34cd-56ef-1234567890ab"}
C.{"Effect":"Allow","Action":["kms:GenerateDataKey"],"Resource":"*"}
D.{"Effect":"Allow","Action":["s3:GetObject"],"Resource":"arn:aws:s3:::my-bucket/*"}
AnswerB

When an object is stored in Amazon S3 using Server-Side Encryption with AWS KMS keys (SSE-KMS), the S3 service encrypts the object data using a unique data key, which is then encrypted by the specified KMS customer master key (CMK). To retrieve and read this object, the calling entity (e.g., a Lambda function) must have explicit `kms:Decrypt` permission on the specific KMS key used for encryption. This allows S3 to use the caller's permissions to request decryption of the data key, enabling the object's content to be returned in plaintext.

Why this answer

The Lambda function needs to decrypt objects encrypted with SSE-KMS. The kms:Decrypt action on the specific KMS key ARN grants the necessary permission to decrypt the S3 object data using AWS KMS. Without this, the Lambda function will receive an access denied error when trying to read the encrypted file.

Exam trap

The trap here is that candidates often assume s3:GetObject alone is sufficient for reading encrypted objects, forgetting that SSE-KMS requires explicit kms:Decrypt permission on the specific KMS key, not just a wildcard or unrelated KMS actions.

How to eliminate wrong answers

Option A is wrong because kms:Encrypt is used to encrypt data, not decrypt it, and the resource wildcard is overly permissive and unnecessary for this use case. Option C is wrong because kms:GenerateDataKey is used to generate a data key for client-side encryption, not to decrypt existing objects; it does not fulfill the requirement to read and decrypt SSE-KMS encrypted files. Option D is wrong because s3:GetObject alone is insufficient; while it allows reading the object, the Lambda function also needs explicit kms:Decrypt permission on the KMS key to decrypt the SSE-KMS encrypted content.

87
MCQmedium

Refer to the exhibit. A developer runs the AWS CLI command to invoke a Lambda function. The output shows StatusCode 200 and no FunctionError. However, the application that depends on this function's output is not working correctly. What should the developer check next?

A.Check the Lambda function's CloudWatch Logs for any errors or unexpected output.
B.Check the IAM role attached to the Lambda function for insufficient permissions.
C.Check the payload format against the function's expected input.
D.Check the Lambda function's memory and timeout configuration.
AnswerA

If the Lambda function executed successfully (no FunctionError), but the result is not as expected, the primary place to investigate the function's internal logic and output is CloudWatch Logs. The function's console.log (or equivalent in other runtimes) statements, along with any unhandled exceptions or specific return values, are all captured here, providing crucial insights into its runtime behavior and what it actually returned.

Why this answer

A StatusCode 200 with no FunctionError indicates the Lambda function executed and completed without a runtime or invocation error. However, the application may still fail if the function returns incorrect data or has logical errors. Checking CloudWatch Logs is the standard next step to inspect the actual execution logs, print statements, or handled logic errors that would reveal why the output is incorrect.

Exam trap

The trap here is that candidates assume a 200 status code guarantees correct application behavior, but Lambda's success response only indicates the function ran to completion, not that its business logic or output is correct for the caller.

How to eliminate wrong answers

Option B is wrong because insufficient IAM permissions would typically cause an access denied error (e.g., 403) or a FunctionError, not a successful 200 response. Option C is wrong because a payload format mismatch would likely cause a runtime error (e.g., JSON parsing failure) that would appear as a FunctionError or in CloudWatch Logs, not a clean 200. Option D is wrong because memory or timeout issues would result in a timeout error (e.g., Task timed out) or out-of-memory error, both of which would produce a FunctionError or a non-200 status code.

88
Multi-Selecteasy

Which TWO AWS services can be used to decouple microservices in a distributed application? (Choose TWO.)

Select 2 answers
A.Amazon CloudWatch
B.Elastic Load Balancer (ELB)
C.Amazon Simple Notification Service (SNS)
D.Amazon Simple Queue Service (SQS)
E.Amazon Route 53
AnswersC, D

Amazon SNS is a fully managed publish/subscribe messaging service that effectively decouples microservices by allowing publishers to send messages to a central topic. This topic then fans out those messages to multiple subscribed endpoints or services asynchronously, ensuring that the publisher does not need to know about or directly interact with the consumers. This pattern promotes loose coupling, independent scaling, and fault tolerance across the system.

Why this answer

Amazon Simple Notification Service (SNS) is a fully managed pub/sub messaging service that enables microservices to communicate asynchronously by broadcasting messages to multiple subscribers (e.g., SQS queues, Lambda functions, HTTP endpoints). This decouples the producer from the consumers, allowing each microservice to scale and fail independently without blocking the sender.

Exam trap

The trap here is that candidates confuse Elastic Load Balancer (ELB) with a message broker, but ELB operates at the transport layer (TCP/HTTP) for synchronous load balancing, not for asynchronous decoupling via queues or pub/sub messaging.

89
MCQeasy

A developer is building a RESTful API using Amazon API Gateway. The API experiences high traffic spikes, and many requests are for the same data (e.g., a product catalog). The developer wants to reduce the load on the backend Lambda functions and improve response times for repeated requests. Which feature should the developer enable?

A.Enable API Gateway caching and set a TTL.
B.Use CloudFront with the API Gateway as an origin.
C.Enable throttling on the API Gateway usage plan.
D.Use a DynamoDB Accelerator (DAX) cluster for the backend database.
AnswerA

Enabling API Gateway caching directly addresses the problem by storing responses for a specified Time-To-Live (TTL). When subsequent identical requests arrive within the TTL, API Gateway serves the response from its managed cache, completely bypassing the backend Lambda function. This significantly reduces the load on the Lambda function, lowers invocation costs, and improves API response times for repeated requests.

Why this answer

API Gateway caching stores responses from backend Lambda functions for a configurable time-to-live (TTL). When a request for the same data (e.g., a product catalog) arrives within the TTL period, API Gateway serves the cached response directly, reducing the number of invocations to the Lambda function and improving response latency. This directly addresses the need to reduce load on the backend and improve response times for repeated requests.

Exam trap

The trap here is that candidates often confuse API Gateway caching with CloudFront caching, thinking that CloudFront alone reduces backend load, but CloudFront caches at the edge and still forwards cache misses to API Gateway, which then invokes Lambda; only API Gateway caching directly reduces Lambda invocations for repeated requests.

How to eliminate wrong answers

Option B is wrong because CloudFront with API Gateway as an origin adds a CDN layer that caches responses at edge locations, but it does not reduce the load on the backend Lambda functions for repeated requests to the same API endpoint; it primarily improves latency for geographically distributed users and can still forward requests to API Gateway, which then invokes Lambda. Option C is wrong because enabling throttling on the API Gateway usage plan limits the rate of requests to protect the backend from being overwhelmed, but it does not cache responses or improve response times for repeated requests; it may actually reject or delay requests. Option D is wrong because using a DynamoDB Accelerator (DAX) cluster caches database queries at the data layer, but the problem is about reducing load on Lambda functions and improving response times for API requests, not about optimizing database access; DAX does not cache API responses or reduce Lambda invocations.

90
MCQmedium

A company is using AWS CodePipeline to automate its CI/CD pipeline. The pipeline has a build stage that uses AWS CodeBuild. The developer wants to run unit tests and only proceed to the deploy stage if the tests pass. Which configuration should the developer use to achieve this?

A.Configure a manual approval step before the deploy stage.
B.Configure Amazon CloudWatch alarms to stop the pipeline if tests fail.
C.Configure the build stage to run tests and fail the build if tests fail; CodePipeline will automatically stop.
D.Configure AWS Lambda to invoke a function that checks test results and manually stops the pipeline.
AnswerC

The AWS CodeBuild action within a CodePipeline build stage is specifically designed to execute build commands and tests. If any command within the CodeBuild `buildspec.yml` exits with a non-zero status, CodeBuild reports a failure to CodePipeline. CodePipeline then automatically recognizes this failed action, stops the current pipeline execution, and prevents any subsequent stages, such as deployment, from being initiated, ensuring a 'fail fast' approach.

Why this answer

AWS CodeBuild can be configured to run unit tests as part of the build phase. If any test fails, CodeBuild exits with a non-zero status, causing the build to fail. CodePipeline automatically stops the pipeline execution when a stage fails, preventing the deploy stage from running.

This is the native and simplest way to gate deployment on test success.

Exam trap

The trap here is that candidates may over-engineer a solution (like Lambda or manual approval) when the native failure propagation in CodePipeline already handles the requirement automatically.

How to eliminate wrong answers

Option A is wrong because a manual approval step requires human intervention to proceed, but it does not automatically check test results; tests could fail and the pipeline would still wait for approval, which is not the desired automated behavior. Option B is wrong because Amazon CloudWatch alarms monitor metrics and can trigger notifications or actions, but they cannot directly stop a CodePipeline execution; they are not integrated to halt pipeline stages based on test failures. Option D is wrong because invoking a Lambda function to manually stop the pipeline adds unnecessary complexity and latency; CodePipeline already has built-in failure handling that stops the pipeline when a stage fails, making a custom Lambda solution redundant and less reliable.

91
MCQmedium

The developer runs a scan on the DynamoDB table 'orders' with a filter expression to find items with order_status equal to 'SHIPPED'. The output shows ScannedCount of 10000 but Count of 0. Which statement is correct?

A.The scan retrieved 10,000 items from the table, but none matched the filter condition.
B.The scan only returned items that matched the filter, so there are no items with status SHIPPED.
C.The filter expression syntax is incorrect, causing the scan to return zero items.
D.The scan applied the filter before reading items, so only matching items were scanned.
AnswerA

The `ScannedCount` metric in DynamoDB represents the total number of items read from the table before any `FilterExpression` is applied. If the `ScannedCount` is 10,000 and the `Count` (number of items returned after filtering) is 0, it indicates that all 10,000 items were successfully retrieved from the table, but none of them met the criteria specified in the `FilterExpression`. This is a common scenario when the filter condition is very specific or no matching data exists.

Why this answer

In DynamoDB, a Scan operation retrieves all items in the table or index up to the 1 MB limit, then applies any filter expression client-side. The ScannedCount of 10,000 indicates that 10,000 items were read from the table, but the Count of 0 means none of those items satisfied the filter condition (order_status = 'SHIPPED'). This is the expected behavior: filters are applied after the data is read, not before.

Exam trap

The trap here is that candidates often confuse ScannedCount with Count, assuming that the filter is applied before reading (like a SQL WHERE clause), when in fact DynamoDB scans all items first and then filters, so ScannedCount reflects total items read and Count reflects matches only.

How to eliminate wrong answers

Option B is wrong because it incorrectly states that the scan only returned items that matched the filter; in reality, the scan returns all items up to the limit, and the filter is applied afterward, so Count reflects only matches. Option C is wrong because if the filter expression syntax were incorrect, DynamoDB would return a validation error (e.g., ValidationException), not a Count of 0 with a valid ScannedCount. Option D is wrong because it claims the filter is applied before reading items; DynamoDB always reads items first and then applies the filter, which is why ScannedCount can be larger than Count.

92
MCQmedium

A developer is deploying an application using AWS Elastic Beanstalk. The application reads and writes data to an Amazon RDS database. The developer wants to ensure that database credentials are not stored in the application code or configuration files. What should the developer do?

A.Store the credentials as environment properties in the Elastic Beanstalk environment configuration.
B.Encrypt the credentials and store them in an Amazon S3 bucket. Have the application download them at startup.
C.Use AWS Secrets Manager to store the credentials and retrieve them in the application code.
D.Store the credentials in a separate configuration file and include it in the application source bundle.
AnswerC

Secrets Manager stores credentials securely and retrieves them via API calls, but the question requires that credentials are never stored in application code or configuration files. The correct approach uses IAM database authentication with RDS, eliminating static credentials entirely by granting the Elastic Beanstalk environment’s IAM role direct access to the database. Secrets Manager is tempting because it is designed for secure credential storage and rotation, and would be correct if the application needed static credentials that could not be eliminated, such as when RDS does not support IAM authentication.

Why this answer

AWS Secrets Manager is specifically designed to protect secrets (such as database credentials, API keys, and OAuth tokens) needed to access applications, services, and IT resources. It enables you to easily rotate, manage, and retrieve database credentials throughout their lifecycle. Storing credentials in Elastic Beanstalk environment properties (Option A) is a security risk because they are stored in plaintext within the environment configuration, can be exposed via the AWS Console/API to users with Beanstalk permissions, and do not support automatic rotation.

Exam trap

Candidates often choose Elastic Beanstalk environment properties (Option A) because it is a built-in feature of Elastic Beanstalk. However, AWS security best practices dictate using AWS Secrets Manager or Systems Manager Parameter Store (SecureString) for sensitive data like database credentials to ensure encryption at rest and support credential rotation.

How to eliminate wrong answers

Option B is wrong because storing encrypted credentials in an S3 bucket and downloading them at startup introduces complexity and potential security risks, such as exposing the S3 bucket or requiring the application to manage decryption keys, which violates the principle of not storing credentials in the application. Option C is wrong because while AWS Secrets Manager is a secure service for storing credentials, the question specifically asks for a solution within Elastic Beanstalk's native capabilities, and using Secrets Manager would require additional SDK calls and IAM permissions, which is not the simplest or most direct approach for this scenario. Option D is wrong because including a separate configuration file in the application source bundle still stores credentials in the deployment artifact, which defeats the purpose of keeping them out of the code and configuration files.

93
MCQeasy

A developer invokes a Lambda function using the AWS CLI. The response shows StatusCode 200 and FunctionError: Unhandled. What does this indicate?

A.The Lambda function threw an exception that was not caught by the code.
B.The Lambda function timed out before completing.
C.The Lambda function executed successfully without errors.
D.The AWS CLI failed to invoke the function due to permissions.
AnswerA

The presence of the `X-Amz-Function-Error` header in the response, along with a `StatusCode: 200`, is the definitive indicator that the Lambda service successfully received and attempted to execute the function, but the function's code itself encountered an unhandled exception. This means an error occurred within the function's runtime environment that was not caught by a `try-catch` block or equivalent error handling mechanism. Consequently, the Lambda service reported the internal function error back to the invoker.

Why this answer

A is correct because a StatusCode 200 from an AWS Lambda invocation via the AWS CLI indicates that the invocation request itself was accepted and processed by the Lambda service, but the presence of FunctionError: Unhandled means the function code threw an exception that was not caught by any try-catch block or error handler. This results in the Lambda service returning a 200 HTTP status for the invocation request while signaling the error via the FunctionError field in the response payload.

Exam trap

The trap here is that candidates often assume a 200 HTTP status code always means success, but AWS Lambda uses 200 for all synchronous invocations that reach the service, and the actual error state is indicated by the FunctionError field in the response body, not the HTTP status code.

How to eliminate wrong answers

Option B is wrong because a Lambda timeout would return a StatusCode 200 with FunctionError: Unhandled only if the timeout exception itself is unhandled, but the specific error for a timeout is 'Task timed out' and would be caught by the runtime as a handled error if the function has a catch-all; however, the question's FunctionError: Unhandled specifically indicates an unhandled exception, not a timeout. Option C is wrong because a successful execution without errors would return StatusCode 200 with no FunctionError field or FunctionError: None, not FunctionError: Unhandled. Option D is wrong because an AWS CLI permissions failure would result in an HTTP 403 (Forbidden) or 400 (Bad Request) status code, not a 200, and the invocation would not reach the function code at all.

94
MCQhard

A developer is building a REST API using Amazon API Gateway with a Lambda integration. The API must validate that the 'Authorization' header contains a valid JWT token before invoking the backend. Which approach provides the LOWEST latency for token validation?

A.Use a VPC Link to connect to a private server for validation.
B.Validate the token inside the Lambda function integrated with the API.
C.Use API Gateway request validation to check the header format.
D.Use a Lambda authorizer (formerly custom authorizer) on the API Gateway.
AnswerD

A Lambda authorizer, previously known as a custom authorizer, is a dedicated Lambda function invoked by API Gateway *before* the request reaches the backend integration. This authorizer receives the incoming token, performs custom validation logic (e.g., JWT signature verification, expiration checks), and returns an IAM policy that either permits or denies access to the requested API resource. Crucially, API Gateway can cache the policy generated by the authorizer, significantly reducing latency and computational overhead for subsequent requests with the same valid token.

Why this answer

A Lambda authorizer (formerly custom authorizer) runs before the backend Lambda invocation, caching the JWT validation result for a configurable TTL (default 300 seconds). This avoids re-validating the token on every request, providing the lowest latency for token validation compared to validating inside the backend Lambda.

Exam trap

It is a common misconception that API Gateway request validation can handle JWT token validation, but it only validates structural format (e.g., header presence), not cryptographic signature verification.

How to eliminate wrong answers

Option A is wrong because a VPC Link connects to a private server inside a VPC, which adds network latency and complexity without any caching or pre-invocation validation benefit. Option B is wrong because validating the token inside the integrated Lambda function requires the backend to run on every request, even for invalid tokens, increasing latency and cost. Option C is wrong because API Gateway request validation only checks header presence and format (e.g., regex), not the cryptographic validity of a JWT token.

95
MCQeasy

A developer needs to access a DynamoDB table from a Lambda function. The Lambda function is in the same AWS account as the DynamoDB table. What is the most secure way to grant the Lambda function access to the DynamoDB table?

A.Use the AWS account root user credentials.
B.Store the AWS access key and secret access key in the Lambda environment variables.
C.Create an IAM role with a policy that grants DynamoDB access and assign it as the Lambda execution role.
D.Use a resource-based policy on the DynamoDB table to allow the Lambda function.
AnswerC

Creating an IAM role with a policy that grants specific DynamoDB access and assigning it as the Lambda execution role is the secure and recommended AWS best practice. This approach provides the Lambda function with temporary, automatically rotated credentials, adhering to the principle of least privilege by allowing access only to the necessary DynamoDB actions and resources without ever exposing static, long-lived credentials.

Why this answer

The most secure and standard way to grant a Lambda function access to DynamoDB is to create an IAM role with a policy that grants the necessary DynamoDB actions (e.g., dynamodb:GetItem, dynamodb:PutItem) and assign that role as the Lambda execution role. This follows the principle of least privilege and avoids hardcoding credentials, as Lambda automatically assumes this role and manages temporary security credentials. While DynamoDB supports resource-based policies, the Lambda execution role (identity-based policy) remains the standard and recommended approach for granting a Lambda function access to resources within the same account.

Exam trap

Candidates might be tempted by resource-based policies (Option D). While DynamoDB does support resource-based policies, they are primarily used for cross-account access or specific administrative controls. For a Lambda function in the same account, the standard, most secure, and recommended practice is to use the Lambda execution role (identity-based policy).

How to eliminate wrong answers

Option A is wrong because using the AWS account root user credentials is a severe security risk; root credentials have unrestricted access and should never be used for programmatic access, especially in Lambda functions. Option B is wrong because storing AWS access keys and secret access keys in Lambda environment variables exposes long-term credentials that could be leaked through logs or function output, and they lack automatic rotation. Option D is wrong because resource-based policies on DynamoDB tables do not support granting access to Lambda functions directly; DynamoDB resource-based policies only allow cross-account access or service principal grants, not individual Lambda function ARNs, and Lambda functions must assume an IAM role to access DynamoDB.

96
MCQmedium

A company runs a containerized web application on Amazon ECS using Fargate. The application needs to store files in Amazon S3. The developer wants to follow the principle of least privilege for the ECS task IAM role. Which IAM policy should be attached to the task role?

A.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:*","Resource":"*"}]}
B.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:*","Resource":"arn:aws:s3:::example-bucket/*"}]}
C.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"s3:PutObject","Resource":"arn:aws:s3:::example-bucket/*"}]}
D.{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":["s3:GetObject","s3:PutObject"],"Resource":"arn:aws:s3:::example-bucket/*"}]}
AnswerC

This policy precisely adheres to the principle of least privilege, granting only the `s3:PutObject` action, which is the exact permission required for the web application to upload files to Amazon S3. The resource is correctly scoped to `arn:aws:s3:::example-bucket/*`, ensuring the application can only write objects into the specified bucket and not affect other S3 resources or perform any other S3 operations. This minimal permission set significantly enhances security by limiting potential damage if the task's credentials were ever compromised.

Why this answer

It grants only the s3:PutObject action on the specific S3 bucket, which is the minimum permission required for the application to store files. This adheres to the principle of least privilege by not including unnecessary read or list actions. The task role should be scoped to the exact resource and action needed.

Exam trap

The trap here is that candidates often choose Option D thinking both read and write are needed for storing files, but the question explicitly states 'store files' which implies write-only, making the read permission unnecessary and a violation of least privilege.

How to eliminate wrong answers

Option A is wrong because it grants full s3:* access to all S3 resources, which violates least privilege by allowing any S3 operation on any bucket. Option B is wrong because it grants all s3:* actions on the specified bucket, which includes read, delete, and administrative actions not needed for storing files. Option D is wrong because it includes s3:GetObject, which is unnecessary for a write-only use case and violates least privilege by granting read access.

97
MCQmedium

A developer is building a system that reads messages from an Amazon SQS queue, processes them, and stores results in an Amazon DynamoDB table. The developer wants to use a managed service to coordinate the processing steps, including error handling and retry logic, without provisioning any servers. Which AWS service should the developer use?

A.AWS Step Functions
B.Amazon Simple Workflow Service (SWF)
C.AWS Glue
D.Amazon MQ
AnswerA

AWS Step Functions is a serverless workflow service that enables developers to build resilient, distributed applications using visual state machines. It excels at orchestrating complex, multi-step processes, integrating seamlessly with Amazon SQS to consume messages and coordinate subsequent actions across various AWS services. Step Functions provides built-in state management, error handling, and retry policies, making it ideal for creating reliable, fault-tolerant workflows initiated by SQS messages.

Why this answer

AWS Step Functions is a serverless orchestration service that lets you coordinate multiple AWS services into a workflow. It directly supports error handling, retry logic, and conditional branching, making it ideal for managing the processing steps of messages from SQS through to DynamoDB without provisioning any servers.

Exam trap

The trap here is that candidates confuse Amazon MQ (a message broker) with a workflow orchestrator, or mistakenly think SWF is the correct choice because it was historically used for workflow coordination, but Step Functions is the modern, serverless, and fully managed alternative that directly integrates with SQS and DynamoDB.

How to eliminate wrong answers

Option B is wrong because Amazon Simple Workflow Service (SWF) is a legacy workflow service that requires you to manage workers (deciders and activity workers) and does not natively integrate with SQS or DynamoDB as seamlessly as Step Functions; it also lacks the built-in retry and error-handling patterns of Step Functions. Option C is wrong because AWS Glue is a serverless ETL service designed for data preparation and transformation, not for orchestrating message processing workflows with SQS and DynamoDB. Option D is wrong because Amazon MQ is a managed message broker service for Apache ActiveMQ and RabbitMQ, not a workflow orchestration service; it provides message queuing but does not handle coordination, error handling, or retry logic across processing steps.

98
Multi-Selecteasy

A developer is using Amazon API Gateway to expose a Lambda function as a REST API. The API should only be accessible from a specific VPC. Which TWO steps are required to achieve this? (Choose TWO.)

Select 2 answers
A.Create a VPC endpoint for API Gateway.
B.Attach a resource policy to the API Gateway API that denies access unless the request originates from the VPC.
C.Use an API key that is only known within the VPC.
D.Configure the Lambda function to be VPC-enabled.
E.Create a VPC endpoint for Lambda.
AnswersA, B

Creating an interface VPC endpoint for API Gateway establishes a private connection from your VPC to the API Gateway service using AWS PrivateLink. This allows clients within your VPC to access the API Gateway endpoint without traversing the public internet, ensuring that all traffic remains within the AWS network and is restricted to the specified VPC.

Why this answer

Creating a VPC endpoint for API Gateway (of type `execute-api`) allows API Gateway to be accessed privately from within a specific VPC without traversing the public internet. This endpoint uses AWS PrivateLink to provide a private IP address within the VPC, ensuring traffic stays within the AWS network.

Exam trap

The trap here is that candidates often think enabling the Lambda function to be VPC-enabled (Option D) is sufficient to restrict API access, but this only affects the Lambda's outbound connectivity, not the inbound API Gateway endpoint.

99
MCQeasy

A developer is writing an AWS Lambda function that needs to read a secret from AWS Secrets Manager. The function is written in Python. What is the BEST practice for retrieving the secret?

A.Use AWS Systems Manager Parameter Store to store the secret.
B.Retrieve the secret inside the handler function every time it is invoked.
C.Store the secret in an environment variable.
D.Retrieve the secret outside the handler function and cache it in a global variable.
AnswerD

Retrieving secrets outside the handler function, typically during the Lambda function's initialization phase, and caching them in a global variable is an optimal strategy for performance and cost efficiency. This approach ensures the secret is fetched only once per execution environment (during a cold start) and then reused for subsequent invocations (warm starts), significantly reducing latency and API call costs associated with repeated secret retrieval.

Why this answer

The best practice because retrieving the secret outside the handler function (at initialization time) and caching it in a global variable avoids making a Secrets Manager API call on every invocation. This reduces latency, cost, and the risk of hitting API rate limits. The cached value persists across warm starts within the same execution environment, aligning with AWS Lambda's lifecycle best practices.

Exam trap

The trap here is that candidates may think retrieving the secret inside the handler (Option B) is simpler or more reliable, but they overlook the performance and cost implications of repeated API calls, as well as the Lambda execution environment reuse model that makes caching outside the handler both safe and efficient.

How to eliminate wrong answers

Option A is wrong because it suggests using AWS Systems Manager Parameter Store instead of Secrets Manager, which does not address the requirement of reading a secret from Secrets Manager; Parameter Store is a different service with different features (e.g., no automatic rotation). Option B is wrong because retrieving the secret inside the handler function on every invocation leads to unnecessary API calls, increased latency, and potential throttling, especially under high concurrency. Option C is wrong because storing secrets in environment variables is insecure; environment variables are visible in the Lambda console, logs, and can be exposed through function configuration, violating security best practices.

100
MCQmedium

A developer is running a web application on multiple Amazon EC2 instances behind an Application Load Balancer (ALB). The application needs to store user session state that must be available across all instances. The session data is small and temporary but must survive individual instance failures. Which AWS service should the developer use to store this session state?

A.Store session state in an Amazon ElastiCache cluster
B.Store session state in the /tmp directory of each EC2 instance
C.Use an Amazon SQS queue to persist session data
D.Store session state in an Amazon S3 bucket
AnswerA

Amazon ElastiCache provides a fully managed, in-memory caching service, making it an excellent choice for storing web application session state. By centralizing session data in an ElastiCache Redis or Memcached cluster, all EC2 instances can access and update the same session information, ensuring session stickiness and persistence even if a user's subsequent request is routed to a different instance. Its low-latency access and high availability features, including replication and automatic failover, are critical for responsive and resilient user experiences in distributed environments.

Why this answer

Amazon ElastiCache (e.g., using Redis or Memcached) provides a centralized, in-memory data store that is external to the EC2 instances. This allows all instances behind the ALB to read and write the same session state, ensuring consistency across the fleet. Because the data is stored in a managed cluster, it survives individual instance failures and is ideal for small, temporary session data that requires low-latency access.

Exam trap

The trap here is that candidates often confuse 'survive instance failures' with 'persistent storage' and choose S3 or SQS, overlooking that session state requires low-latency, in-memory access with automatic expiry, which only ElastiCache provides among the options.

How to eliminate wrong answers

Option B is wrong because storing session state in the /tmp directory of each EC2 instance is ephemeral—data is lost if the instance terminates or fails, and it is not shared across instances, breaking the requirement for cross-instance availability. Option C is wrong because Amazon SQS is a message queue service designed for decoupling and asynchronous communication, not for storing session state; it lacks the low-latency, key-value lookup capabilities needed for session management. Option D is wrong because Amazon S3 is an object storage service with higher latency and no built-in support for fast, atomic read/write operations on small session data, making it unsuitable for real-time session state storage.

101
Matchingmedium

Match each AWS security feature to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Temporary permissions for services

Stateful firewall for EC2

Web application firewall

DDoS protection

SSL/TLS certificate management

Why these pairings

The correct matches are IAM with access control, Security Groups with EC2 firewall, KMS with encryption key management, and CloudTrail with API auditing. Common confusions include mistaking IAM for CloudTrail and Security Groups for NACLs.

102
Multi-Selectmedium

Which TWO actions can improve the performance of an Amazon DynamoDB table that experiences frequent throttling due to hot partitions? (Choose TWO.)

Select 2 answers
A.Disable auto scaling to provision fixed capacity
B.Enable DynamoDB Accelerator (DAX) for caching
C.Increase the read capacity units (RCUs) of the table
D.Add a random suffix to the partition key values
E.Use a global secondary index (GSI) with a different partition key
AnswersB, D

Enabling DynamoDB Accelerator (DAX) significantly improves read performance by providing an in-memory cache for frequently accessed data. DAX intercepts read requests before they reach the DynamoDB table, serving cached items with microsecond latency. This drastically reduces the read load on the underlying DynamoDB table, effectively mitigating read-related throttling issues and enhancing application responsiveness for read-intensive workloads.

Why this answer

DynamoDB Accelerator (DAX) is an in-memory cache that reduces the number of read requests hitting the underlying table, thereby alleviating pressure on hot partitions. By serving frequently accessed items from DAX, the table experiences fewer throttled read requests, improving overall performance without changing the data model.

Exam trap

The trap here is that candidates often assume increasing provisioned capacity (RCUs/WCUs) will solve throttling, but they overlook the partition-level throughput limit that makes hot partitions a distribution problem, not a capacity problem.

103
Multi-Selecthard

A developer is deploying a serverless application using the AWS Serverless Application Model (SAM). The application includes an API Gateway REST API and a Lambda function. The developer wants to enable access logging for the API Gateway. Which THREE resources or configurations are required? (Choose THREE.)

Select 3 answers
A.A stage with access logging enabled in the API Gateway.
B.A Lambda function that processes the access logs.
C.An IAM role that grants API Gateway permission to write to CloudWatch Logs.
D.An Amazon CloudWatch Logs log group.
E.An IAM role for the Lambda function with logs:PutLogEvents permission.
AnswersA, C, D

Enabling access logging on a specific API Gateway stage is a fundamental configuration step for capturing API traffic. This setting dictates that API Gateway will generate detailed information about every request and response passing through that stage, including caller IP, request latency, and response status. Without this explicit enablement on the stage, no access logs will be generated, regardless of other logging infrastructure being in place. Therefore, it is a prerequisite for any access logging functionality.

Why this answer

API Gateway access logging is configured at the stage level. The developer must enable access logging on a specific stage (e.g., prod, dev) and specify a destination CloudWatch Logs log group and a logging format (e.g., JSON or CLF). Without enabling it on the stage, no access logs are generated regardless of other configurations.

Exam trap

The trap here is that candidates often confuse the IAM role needed for API Gateway to write logs (Option C) with the Lambda execution role (Option E), or incorrectly think a Lambda function must process the logs (Option B) when API Gateway writes them directly to CloudWatch Logs.

104
MCQmedium

A developer is writing a Lambda function that processes events from an Amazon S3 bucket. The function needs to access a DynamoDB table to store metadata about the S3 objects. Which of the following is the MOST efficient way to initialize the DynamoDB client in the Lambda function?

A.Store the DynamoDB table name as a global variable and create the client inside the handler.
B.Use a static variable inside the handler to cache the DynamoDB client.
C.Create the DynamoDB client inside the Lambda handler function every invocation.
D.Create the DynamoDB client outside the Lambda handler function, in the global scope.
AnswerD

Creating the DynamoDB client outside the Lambda handler function, in the global scope, is the recommended best practice for optimizing Lambda performance. This ensures the client is initialized only once when the Lambda execution environment is first created during a cold start. For subsequent 'warm' invocations within the same execution environment, the pre-initialized client is reused, significantly reducing latency by avoiding repeated client setup overhead and connection establishment.

Why this answer

Initializing the DynamoDB client outside the Lambda handler (in global scope) allows the client to be reused across multiple invocations within the same execution environment. This avoids the overhead of creating a new client on every invocation, which reduces latency and conserves resources. AWS Lambda reuses the global scope for subsequent invocations after the first, making this the most efficient approach.

Exam trap

The trap here is that candidates may think creating the client inside the handler is safer for avoiding stale connections, but AWS Lambda's execution environment reuse makes global initialization both safe and more efficient.

How to eliminate wrong answers

Option A is wrong because storing the table name as a global variable is acceptable, but creating the client inside the handler on every invocation still incurs unnecessary initialization overhead. Option B is wrong because using a static variable inside the handler does not prevent the client from being recreated on each invocation; static variables in Python are effectively global but the client creation inside the handler still runs on every call. Option C is wrong because creating the DynamoDB client inside the handler on every invocation wastes time and resources, as the client could be reused across invocations in the same execution environment.

105
Multi-Selecteasy

A developer is designing a serverless application using AWS Lambda. The function needs to process messages from an Amazon SQS queue. The developer wants to configure the Lambda function to be triggered by the SQS queue. Which TWO actions are required? (Choose TWO.)

Select 2 answers
A.Attach an IAM execution role to Lambda with permission to receive messages from SQS.
B.Configure a resource-based policy on the SQS queue to allow Lambda invocation.
C.Create an event source mapping in Lambda to poll the SQS queue.
D.Set up a dead-letter queue for failed messages.
E.Place the Lambda function in a VPC to access the SQS queue.
AnswersA, C

The Lambda function's IAM execution role must include permissions such as sqs:ReceiveMessage, sqs:DeleteMessage, and sqs:GetQueueAttributes. These permissions are essential for the Lambda service, acting on behalf of the function, to successfully poll the SQS queue, retrieve messages, and then delete them after successful processing. Without these explicit permissions, the Lambda function would be unable to interact with the SQS queue as an event source, preventing message consumption.

Why this answer

Option A is correct because the Lambda function's IAM execution role must grant permissions such as sqs:ReceiveMessage, sqs:DeleteMessage, and sqs:GetQueueAttributes so the service can poll and consume messages from the SQS queue on the function's behalf. Option C is correct because SQS is a pull-based source, so you must create an event source mapping that tells the Lambda service to poll the queue, batch records, and invoke the function with those messages. Option B is not required because SQS integration uses the execution role for polling rather than a resource-based policy invoking Lambda directly, as would be the case for push-based sources like S3 or SNS.

Option D is not required, though a dead-letter queue or Lambda destinations can optionally handle failed messages. Option E is not required because Lambda can reach SQS over the AWS network without being placed in a VPC.

Exam trap

Candidates often confuse the integration pattern of SQS with push-based services like S3 or SNS. For S3 or SNS, you must configure a resource-based policy on the Lambda function to allow the service to invoke it. For SQS, Lambda uses an Event Source Mapping (polling model) where the Lambda service polls SQS using the Lambda function's execution role, meaning no resource-based policies are needed on either side.

106
Multi-Selecthard

A developer is using AWS Secrets Manager to rotate database credentials. The rotation Lambda function fails with an error. Which THREE steps should the developer take to troubleshoot? (Choose THREE.)

Select 3 answers
A.Check VPC Flow Logs for the Lambda function's ENI.
B.Verify that the Lambda function has network access to the database.
C.Ensure the KMS key used to encrypt the secret is rotated.
D.Verify that the Lambda function's IAM role has permission to update the secret.
E.Check the CloudWatch Logs for the Lambda function.
AnswersB, D, E

For the Lambda function to successfully rotate database credentials, it must establish a network connection to the database instance. If the database resides within a VPC, the Lambda function must be configured to execute within that same VPC or a peered VPC, with appropriate security groups and network ACLs allowing outbound connections to the database's port and inbound connections from the Lambda's Elastic Network Interface (ENI). Lack of network reachability is a common cause of rotation failures.

Why this answer

The Lambda function must have network access to the database to perform the rotation (e.g., connecting to the database to change the password). Without network connectivity, the rotation cannot complete. Option D is correct because the Lambda function's IAM role needs permission to call `secretsmanager:PutSecretValue` and `secretsmanager:GetSecretValue` to update the secret in Secrets Manager.

Option E is correct because CloudWatch Logs capture the Lambda function's execution output, including any error messages, stack traces, or logs from the rotation logic, which are essential for diagnosing failures.

Exam trap

The trap here is that candidates often confuse VPC Flow Logs (which show network traffic) with CloudWatch Logs (which show application logs), and they may think that rotating the KMS key is necessary for secret rotation, when in fact KMS key rotation is automatic and unrelated to the rotation process.

107
MCQhard

A developer is designing a serverless application that processes images uploaded to an S3 bucket. Each image must be resized and then stored in a different S3 bucket. The process must be asynchronous and fault-tolerant. Which AWS service should trigger the Lambda function?

A.Amazon S3 Event Notifications
B.Amazon SQS
C.Amazon API Gateway
D.AWS Step Functions
AnswerA

Amazon S3 Event Notifications are the native mechanism for S3 buckets to publish events, such as object creation (s3:ObjectCreated:*), to various destinations. These notifications can directly invoke AWS Lambda functions asynchronously, providing a highly scalable and decoupled way to trigger serverless processing whenever new data arrives in an S3 bucket. This direct integration eliminates the need for intermediary services for simple object-triggered workflows, making it the most suitable and efficient choice for this scenario.

Why this answer

Amazon S3 Event Notifications are the correct trigger because they natively support event-driven architectures where S3 object creation events (e.g., s3:ObjectCreated:Put) can directly invoke a Lambda function. This enables asynchronous processing of uploaded images without any intermediate polling or custom integration, ensuring fault tolerance through Lambda's built-in retry mechanism and dead-letter queue (DLQ) support.

Exam trap

The trap here is that candidates often confuse the service that triggers the Lambda (S3 Event Notifications) with the service that stores or routes the event data (SQS or Step Functions), leading them to pick an option that adds unnecessary complexity or is designed for a different use case.

How to eliminate wrong answers

Option B (Amazon SQS) is wrong because SQS is a message queue service that requires a separate producer to send messages; while S3 can publish events to SQS, the question asks for the service that triggers the Lambda function, and SQS itself does not trigger Lambda unless configured as an event source mapping, which adds unnecessary complexity for a direct S3-to-Lambda use case. Option C (Amazon API Gateway) is wrong because API Gateway is designed for creating RESTful or WebSocket APIs to handle synchronous HTTP requests, not for reacting to S3 object creation events asynchronously. Option D (AWS Step Functions) is wrong because Step Functions is a workflow orchestration service that coordinates multiple AWS services, not a direct trigger for Lambda; using it here would introduce an unnecessary orchestration layer when a simple S3 event notification suffices.

108
MCQmedium

A developer is deploying a web application using AWS Elastic Beanstalk. The application needs to store session state. The developer wants to ensure that session data is not lost if an EC2 instance is terminated. Which solution should the developer implement?

A.Store session data in an Amazon EBS volume.
B.Store session data in an Amazon S3 bucket.
C.Store session data in the instance store.
D.Store session data in an Amazon ElastiCache cluster.
AnswerD

Amazon ElastiCache, particularly when configured with Redis, provides a highly scalable, in-memory data store offering extremely low-latency read and write access essential for responsive session management. It supports high availability through replication and automatic failover, ensuring session data persistence and resilience against node failures. This centralized caching layer allows multiple web servers to efficiently share and access session state, enabling stateless application design crucial for scalability and seamless user experience across instances.

Why this answer

Amazon ElastiCache provides a managed, highly available, and durable in-memory cache that can store session state externally from EC2 instances. By using ElastiCache (e.g., Redis with replication and persistence), session data survives instance termination because it is stored in a separate, resilient service, not on the local instance.

Exam trap

The trap here is that candidates often confuse persistent storage (EBS) with shared, low-latency session storage, failing to recognize that EBS volumes are instance-attached and not designed for cross-instance session sharing, while ElastiCache provides the necessary distributed, in-memory session store.

How to eliminate wrong answers

Option A is wrong because an Amazon EBS volume is tied to a single Availability Zone and, while persistent, it is attached to a specific EC2 instance; if the instance is terminated, the EBS volume may be detached but the session data is not automatically shared across instances and requires manual reattachment, making it unsuitable for stateless session management. Option B is wrong because Amazon S3 is an object storage service designed for large, static objects and high-latency access; it is not optimized for low-latency session state reads/writes and incurs significant overhead per request, making it impractical for real-time session handling. Option C is wrong because the instance store provides temporary, block-level storage that is physically attached to the host computer; data is lost when the instance is stopped, terminated, or fails, directly contradicting the requirement to preserve session data after instance termination.

109
MCQhard

A developer is using Amazon DynamoDB to store session data for a web application. The application reads and writes a single item per user session. The traffic pattern shows occasional spikes. The developer wants to minimize read and write costs. Which DynamoDB capacity mode should the developer choose?

A.Reserved capacity
B.On-demand capacity
C.Provisioned capacity with manual scaling
D.Provisioned capacity with auto scaling
AnswerB

DynamoDB On-demand capacity mode is specifically designed for workloads with unpredictable traffic patterns and sudden, sharp spikes. It operates on a pay-per-request model, automatically scaling throughput up or down instantly to accommodate actual traffic volume without requiring any capacity planning. This eliminates the risk of throttling during peak loads and avoids over-provisioning during quiet periods, making it ideal for highly variable session data.

Why this answer

On-demand capacity mode is ideal for unpredictable traffic patterns with occasional spikes because it automatically scales read and write throughput based on actual usage, charging only for consumed operations. Since the application reads and writes a single item per session and experiences spikes, on-demand eliminates the need to provision for peak capacity, minimizing costs compared to over-provisioning.

Exam trap

The trap here is that candidates may confuse 'Reserved capacity' with a valid DynamoDB option or assume that auto scaling (Option D) is always the cheapest for variable traffic, but on-demand is specifically designed for unpredictable spikes to avoid over-provisioning costs and throttling.

How to eliminate wrong answers

Option A is wrong because DynamoDB does not offer a 'Reserved capacity' pricing model; that concept applies to services like Amazon EC2 or RDS, not DynamoDB. Option C is wrong because provisioned capacity with manual scaling requires you to predict and manually adjust capacity for spikes, which risks either throttling during spikes or over-provisioning and higher costs during low traffic. Option D is wrong because provisioned capacity with auto scaling still requires you to set a minimum and maximum capacity, and during sudden spikes, auto scaling may lag behind, causing throttling or requiring over-provisioning to avoid it, whereas on-demand handles spikes instantly without configuration.

110
MCQmedium

A developer is using Amazon DynamoDB as the data store for a web application. The application experiences frequent throttling errors. Which action can reduce throttling without changing the application code?

A.Add a secondary index
B.Decrease the provisioned write capacity
C.Enable DynamoDB Auto Scaling
D.Increase the provisioned read capacity only
AnswerC

Enabling DynamoDB Auto Scaling, powered by AWS Application Auto Scaling, is the most effective solution for preventing throttling due to fluctuating workloads. Auto Scaling dynamically adjusts the table's provisioned read and write capacity units (RCUs/WCUs) up or down in response to actual traffic patterns and utilization metrics. By automatically increasing capacity during peak demand and decreasing it during lulls, it ensures sufficient throughput to avoid throttling while optimizing costs.

Why this answer

DynamoDB Auto Scaling automatically adjusts the provisioned throughput capacity based on actual traffic patterns, using the AWS Application Auto Scaling service. This prevents throttling by increasing capacity during demand spikes and reduces costs by scaling down during low traffic, all without requiring any code changes.

Exam trap

The trap here is that candidates often assume throttling can only be fixed by manually increasing capacity (Option D) or by optimizing queries (Option A), but they overlook the managed scaling solution that requires no code changes.

How to eliminate wrong answers

Option A is wrong because adding a secondary index does not directly increase the base read/write capacity of the table; it only provides alternative query patterns and can even increase consumed capacity if not designed carefully. Option B is wrong because decreasing provisioned write capacity would worsen throttling by reducing the available throughput, directly contradicting the goal of reducing throttling. Option D is wrong because increasing only read capacity does not address write throttling, and the question describes 'frequent throttling errors' without specifying read or write, so a balanced solution is needed.

111
MCQhard

A Step Functions workflow calls three independent Lambda functions and should continue only after all results are available. Which state pattern should be used?

A.Choice state
B.Wait state
C.Parallel state
D.Fail state
AnswerC

The Parallel state is specifically designed to execute multiple independent branches of a workflow concurrently. Each branch within a Parallel state runs simultaneously, allowing for the efficient, parallel invocation of services like AWS Lambda functions. The state completes only when all its branches have finished their execution, aggregating their outputs into a single result, which perfectly addresses the requirement of calling three independent Lambda functions at the same time.

Why this answer

The Parallel state in AWS Step Functions is designed to execute multiple branches of work concurrently and then aggregate their outputs into a single array. This is exactly what is needed when three independent Lambda functions must all complete before the workflow continues, as the Parallel state waits for all branches to finish before proceeding to the next state.

Exam trap

The trap here is that candidates may confuse the Parallel state with the Map state, but the Map state is for processing items in an array with the same logic, not for running distinct independent tasks.

How to eliminate wrong answers

Option A is wrong because a Choice state is used for conditional branching based on input data, not for executing multiple tasks concurrently. Option B is wrong because a Wait state only introduces a delay in the workflow and does not execute or coordinate multiple Lambda functions. Option D is wrong because a Fail state is used to stop the execution and mark it as failed, not to run parallel tasks.

112
MCQmedium

A developer is building a REST API using Amazon API Gateway and AWS Lambda. The API must support request validation, request throttling, and API keys. Which API Gateway feature should the developer use to enforce a daily request limit for each API key?

A.Usage plans
B.API keys
C.Throttling settings at the method level
D.AWS WAF
AnswerA

Usage plans in Amazon API Gateway are the definitive mechanism for enforcing per-client quotas and throttling limits. They allow you to associate specific API keys with defined request rates (e.g., requests per second) and burst capacities, as well as total request quotas over a given period. This ensures that individual API consumers adhere to their subscribed service tiers, preventing any single client from monopolizing API resources and providing granular control over API consumption.

Why this answer

Usage plans in API Gateway allow you to set throttling and quota limits per API key, enabling daily request limits for each key. This feature is specifically designed to control usage by associating API keys with a plan that defines rate limits and quotas, such as a daily request cap. Option A is correct because it directly addresses the requirement to enforce a daily request limit per API key.

Exam trap

The trap here is that candidates often confuse API keys with usage plans, thinking that simply enabling API keys automatically enforces throttling or quotas, but API keys alone provide no rate limiting without a usage plan.

How to eliminate wrong answers

Option B is wrong because API keys alone are just identifiers used to authenticate requests; they do not enforce any throttling or quota limits. Option C is wrong because throttling settings at the method level apply globally to all requests for that method, not per API key, and cannot enforce a daily limit per key. Option D is wrong because AWS WAF is a web application firewall that protects against common web exploits, not a feature for managing API usage quotas or throttling per API key.

113
Multi-Selectmedium

A company is using Amazon S3 to store sensitive documents. They must encrypt all objects at rest. Which TWO methods can be used to enforce server-side encryption? (Choose TWO.)

Select 2 answers
A.Set a bucket policy that denies PutObject if x-amz-server-side-encryption header is not present.
B.Enable default encryption on the S3 bucket.
C.Attach an IAM policy that denies all S3 actions unless encryption is specified.
D.Configure an SQS queue policy to require encryption.
E.Use client-side encryption before uploading objects.
AnswersA, B

Setting a bucket policy allows you to define granular permissions and conditions for all principals interacting with the S3 bucket. By using a `Deny` statement with a condition that checks for the absence of the `s3:x-amz-server-side-encryption` header during a `s3:PutObject` action, you can effectively enforce that all new objects uploaded to the bucket must be encrypted at rest using server-side encryption. This ensures compliance across all uploads, regardless of the uploader's individual IAM permissions.

Why this answer

Option A is correct because a bucket policy can include a Deny statement on s3:PutObject with a condition such as StringNotEquals on s3:x-amz-server-side-encryption (or its absence via Null), which blocks any upload that does not request server-side encryption with the required algorithm (for example, AES256 or aws:kms). Option B is correct because enabling default bucket encryption (SSE-S3, SSE-KMS, or DSSE-KMS) causes Amazon S3 to automatically encrypt every object at rest on upload, even when the request does not include the x-amz-server-side-encryption header, thereby enforcing encryption at rest. Option C is not appropriate because an IAM policy denying all S3 actions unless encryption is specified is overly broad and does not itself enforce encryption on PutObject in the precise, header-based way a bucket policy condition does.

Option D is wrong because an SQS queue policy governs access to an SQS queue, not to S3 objects, and has no effect on S3 server-side encryption. Option E is wrong because client-side encryption encrypts data before it reaches S3 and is not a server-side encryption enforcement method.

Exam trap

Candidates often confuse client-side encryption (Option E) with server-side encryption. Additionally, while IAM policies (Option C) can restrict user actions, denying 'all S3 actions' unless encryption is specified is incorrect because read actions (like GetObject) or metadata actions (like ListBucket) do not require encryption headers.

114
MCQeasy

A developer is creating a CloudFormation template to deploy an Amazon S3 bucket. The developer wants the bucket to be deleted automatically when the CloudFormation stack is deleted. What should the developer specify in the template?

A.Set the DeletionPolicy attribute to Delete.
B.Specify a unique bucket name to avoid conflicts.
C.Use the DependsOn attribute to specify the bucket depends on the stack.
D.Set the DeletionPolicy attribute to Retain.
AnswerA

When a CloudFormation stack is deleted, resources with DeletionPolicy: Delete are removed from the AWS account. For an S3 bucket, applying DeletionPolicy: Delete ensures that the bucket and all its contents are permanently deleted when the associated CloudFormation stack is terminated. This is the correct approach to ensure the bucket's lifecycle is tied directly to the stack's lifecycle, preventing orphaned resources. This attribute explicitly instructs CloudFormation to remove the resource.

Why this answer

The `DeletionPolicy` attribute in AWS CloudFormation controls what happens to a resource when its stack is deleted. By setting `DeletionPolicy: Delete` on the S3 bucket resource, the developer ensures that the bucket is automatically deleted when the stack is deleted. This is the default behavior for most resources, but explicitly setting it confirms the intent and overrides any other policy like `Retain`.

Exam trap

The trap here is that candidates often confuse `DeletionPolicy` with `UpdatePolicy` or assume that `Retain` is the default, leading them to choose Option D, when in fact `Delete` is the default and correct choice for automatic deletion.

How to eliminate wrong answers

Option B is wrong because specifying a unique bucket name avoids naming conflicts but does not control deletion behavior; CloudFormation can still delete the bucket regardless of its name. Option C is wrong because the `DependsOn` attribute only establishes resource creation order within the stack, not deletion behavior; it does not affect whether the bucket is deleted when the stack is removed. Option D is wrong because setting `DeletionPolicy` to `Retain` explicitly prevents the bucket from being deleted when the stack is deleted, which is the opposite of what the developer wants.

115
MCQeasy

A developer is using AWS Lambda to process events from an Amazon Kinesis stream. The function has been failing with 'ProvisionedThroughputExceededException' errors when writing to a DynamoDB table. What should the developer do to resolve this issue?

A.Decrease the batch size of the Kinesis event source mapping.
B.Implement retry logic with exponential backoff in the Lambda function.
C.Increase the number of shards in the Kinesis stream.
D.Increase the memory allocated to the Lambda function.
AnswerB

Implementing retry logic with exponential backoff in the Lambda function is the standard and most effective approach for handling `ProvisionedThroughputExceededException`. This exception indicates a temporary throttling by DynamoDB when its provisioned capacity is exceeded. Exponential backoff allows the Lambda function to automatically reattempt failed writes after increasing delays, giving DynamoDB time to recover capacity and successfully process the request, thereby smoothing out write spikes and preventing data loss.

Why this answer

The 'ProvisionedThroughputExceededException' error indicates that the Lambda function is exceeding the write capacity units (WCUs) provisioned for the DynamoDB table. Implementing retry logic with exponential backoff in the Lambda function allows it to handle throttling gracefully by pausing and retrying failed writes, which is the standard AWS-recommended pattern for managing DynamoDB throttling.

Exam trap

The trap here is that candidates often confuse scaling the source (Kinesis shards) or the compute (Lambda memory) with managing the downstream resource's capacity limits, leading them to choose options that increase parallelism rather than implementing proper retry and backoff logic.

How to eliminate wrong answers

Option A is wrong because decreasing the batch size of the Kinesis event source mapping reduces the number of records per invocation but does not address the root cause of exceeding DynamoDB's provisioned throughput; it may only reduce the burst of writes but not prevent throttling if the table's capacity is insufficient. Option C is wrong because increasing the number of shards in the Kinesis stream increases the parallelism of Lambda invocations, which can actually exacerbate the throttling issue by sending more concurrent write requests to DynamoDB. Option D is wrong because increasing the memory allocated to the Lambda function only affects CPU and network performance, not the rate at which it writes to DynamoDB; it does not resolve throughput limit errors.

116
MCQeasy

A developer is deploying a web application using AWS Elastic Beanstalk. The application requires a relational database. The developer wants the database to be automatically created and configured as part of the Elastic Beanstalk environment. Which approach should they use?

A.Use Amazon DynamoDB as the database and configure it in the Elastic Beanstalk environment.
B.Create an RDS database manually and configure the application to connect to it using environment properties.
C.Embed a SQLite database file in the application deployment package.
D.Configure the Elastic Beanstalk environment to include an RDS database instance.
AnswerD

Elastic Beanstalk provides direct, integrated support for provisioning and managing an Amazon RDS database instance as part of the environment. When configured this way, Elastic Beanstalk automatically creates, manages, and injects the necessary database connection details (such as endpoint, username, and password) as environment variables for the application. This significantly simplifies deployment, scaling, and the overall lifecycle management of the database alongside the application.

Why this answer

The correct approach is to configure the Elastic Beanstalk environment to include an RDS database instance. Elastic Beanstalk allows you to provision an RDS database as part of the environment, automatically handling creation, configuration, and connection details. This integrates the database lifecycle with the environment, simplifying management.

Exam trap

DVA-C02 often tests the difference between integrated and manually configured resources, and candidates may incorrectly assume that manual creation is required for production or that DynamoDB is a relational database.

How to eliminate wrong answers

Option A is wrong because DynamoDB is a NoSQL database, not relational, and Elastic Beanstalk does not natively provision DynamoDB as part of the environment. Option B is wrong because creating an RDS database manually does not automatically configure it as part of the Elastic Beanstalk environment; it requires manual setup and connection configuration. Option C is wrong because embedding a SQLite database file is not suitable for a scalable web application and does not provide a managed relational database service.

117
Multi-Selecteasy

A developer is building a serverless application using AWS Lambda. The Lambda function needs to access a VPC to connect to an RDS database. Which TWO resources must the developer configure to allow the Lambda function to access the VPC?

Select 2 answers
A.A NAT gateway in the VPC.
B.A security group that allows inbound/outbound traffic to the RDS database.
C.VPC subnet IDs for the Lambda function.
D.An IAM role with permissions to access RDS.
E.An internet gateway attached to the VPC.
AnswersB, C

A security group acts as a virtual firewall for your RDS database instance, controlling both inbound and outbound traffic at the instance level. To allow a Lambda function to connect to RDS, the RDS security group must have an inbound rule permitting traffic on the database port (e.g., 3306 for MySQL) from the security group associated with the Lambda function's ENI. This ensures network-level access is granted for the serverless application.

Why this answer

A security group acts as a virtual firewall for the Lambda function, controlling inbound and outbound traffic. To connect to an RDS database in a VPC, the Lambda function's security group must allow outbound traffic to the RDS database's security group on the database port (e.g., 3306 for MySQL), and the RDS security group must allow inbound traffic from the Lambda security group. This two-way rule ensures the Lambda function can establish a TCP connection to the database.

Exam trap

The trap here is that candidates often confuse the resources needed for VPC access (subnet IDs and security groups) with network infrastructure components (NAT gateway, internet gateway) or database-level permissions (IAM role), but the question specifically asks for the two resources that enable the Lambda function to connect to the VPC network layer, not the database service itself.

118
MCQeasy

A developer is building an AWS Lambda function that needs to retrieve a database password securely. The password is stored in AWS Secrets Manager and is rotated every 30 days. The function must minimize the number of API calls to Secrets Manager. Which approach should the developer use?

A.Store the database password as an encrypted environment variable in the Lambda function.
B.Call Secrets Manager on every invocation to get the latest secret.
C.Retrieve the secret from Secrets Manager once outside the handler function, cache it in a global variable, and refresh the cache if the secret fails.
D.Use AWS Systems Manager Parameter Store SecureString instead of Secrets Manager.
AnswerC

Retrieving the secret from Secrets Manager once outside the handler function and caching it in a global variable is an optimal pattern for Lambda. This approach leverages the execution environment's persistence, significantly reducing latency and cost by minimizing `GetSecretValue` API calls across warm invocations. If the secret is rotated, the cached value will eventually fail authentication, triggering a refresh from Secrets Manager to retrieve the latest version, ensuring both efficiency and up-to-date security.

Why this answer

It retrieves the secret once during the Lambda cold start (outside the handler), caches it in a global variable, and only refreshes the cache if the secret fails (e.g., due to rotation). This minimizes API calls to Secrets Manager while still handling secret rotation gracefully, as the cached secret remains valid until a failure occurs.

Exam trap

The trap here is that candidates assume 'minimize API calls' means never calling Secrets Manager again, but the correct approach allows a single call per cold start with a fallback refresh on failure, not zero calls forever.

How to eliminate wrong answers

Option A is wrong because storing the password as an encrypted environment variable does not support automatic rotation—the value is static until the function is redeployed, violating the requirement that the password is rotated every 30 days. Option B is wrong because calling Secrets Manager on every invocation maximizes API calls, incurring unnecessary cost and latency, and contradicts the requirement to minimize API calls. Option D is wrong because switching to Systems Manager Parameter Store does not inherently reduce API calls; the same caching strategy would still be needed, and the question specifically asks about Secrets Manager, not an alternative service.

119
MCQhard

A company runs a containerized application on Amazon ECS with Fargate. The application writes logs to stdout. The operations team wants to send these logs to a centralized log management tool that requires logs in JSON format. What is the BEST way to achieve this without modifying application code?

A.Use the FireLens log driver to route logs to Fluent Bit and then to the tool
B.Use the awslogs log driver and configure a JSON output format
C.Install the CloudWatch Logs agent on the container
D.Modify the application to output logs in JSON format
AnswerA

The FireLens log driver is the appropriate solution for routing and transforming container logs on Amazon ECS, especially when running on AWS Fargate. It integrates seamlessly with Fluent Bit or Fluentd as a sidecar container, enabling powerful log processing capabilities like parsing unstructured logs into JSON, filtering, and routing them to various destinations beyond CloudWatch Logs. This approach centralizes log management without requiring modifications to the application code itself, aligning with best practices for containerized environments.

Why this answer

FireLens is an ECS log driver that integrates with Fluent Bit or Fluentd to route, filter, and transform container logs without modifying application code. By using FireLens with Fluent Bit, you can configure a JSON parser to convert stdout logs into JSON format before forwarding them to the centralized log management tool, meeting the requirement exactly.

Exam trap

The trap here is that candidates assume the awslogs log driver can format logs as JSON (it cannot) or that installing an agent on Fargate containers is possible (it is not), leading them to overlook FireLens as the only serverless-compatible, code-free option for log transformation and routing.

How to eliminate wrong answers

Option B is wrong because the awslogs log driver sends logs to Amazon CloudWatch Logs in plain text, not JSON, and it does not support configuring a JSON output format; it is designed for direct CloudWatch ingestion, not third-party tools. Option C is wrong because installing the CloudWatch Logs agent on a container is not supported in Fargate (which is serverless and does not allow host-level agents), and even if it were, it would not transform logs to JSON. Option D is wrong because it requires modifying application code, which the question explicitly prohibits.

120
MCQeasy

A developer is building a serverless application using AWS Lambda and Amazon DynamoDB. The Lambda function reads from a DynamoDB table. The function fails with a timeout error when processing large items. What is the MOST efficient solution?

A.Increase the Lambda function memory.
B.Increase the Lambda function timeout.
C.Enable Lambda provisioned concurrency.
D.Increase the DynamoDB read capacity units.
AnswerA

Increasing Lambda function memory allocates more CPU and network bandwidth, which can accelerate execution for CPU-bound or network-intensive tasks. However, if the function's processing time inherently exceeds its configured timeout, simply adding more memory will not prevent termination. The function will still be stopped once the timeout limit is reached, regardless of its available resources, making this an indirect and often insufficient solution for a timeout issue.

Why this answer

In AWS Lambda, CPU power is allocated proportionally to the configured memory. When a Lambda function times out while processing large items or files, it is typically due to CPU bottlenecks (such as serialization, deserialization, or processing overhead). Increasing the memory (Option A) automatically increases the CPU power, which speeds up execution and resolves the timeout.

Simply increasing the timeout (Option B) allows the function to run longer but does not address the performance bottleneck and can lead to higher latency and costs.

Exam trap

Candidates often think that a timeout error should always be fixed by increasing the timeout limit (Option B). However, for resource-intensive tasks like processing large items, increasing the memory (Option A) is the most efficient solution because it scales CPU power, reducing execution time and often lowering overall costs.

How to eliminate wrong answers

Option A is wrong because increasing memory also increases CPU and network throughput, but the issue is time, not resource constraints; the function may still timeout if the processing duration exceeds the new timeout. Option C is wrong because provisioned concurrency keeps functions initialized to reduce cold starts, but does not extend the maximum execution duration for a single invocation. Option D is wrong because the error is a Lambda timeout, not a DynamoDB throttling issue; increasing read capacity units would not affect how long the Lambda function takes to process items.

121
MCQhard

A developer is building a multi-region application using Amazon DynamoDB global tables. The application needs to read data from a replica table in a different region shortly after a write in the primary region. The developer notices that reads sometimes return stale data. Which of the following explains this behavior?

A.Global tables use asynchronous replication, introducing unavoidable replication lag.
B.The developer must use DynamoDB Streams to capture changes and replicate them separately.
C.The developer must enable strong consistency reads on the replica table.
D.The global table must be configured with write forwarding.
AnswerA

DynamoDB Global Tables are built upon an asynchronous, multi-master replication model, which inherently leads to eventual consistency across regions. This design means there will always be an unavoidable, albeit typically brief, replication lag between regions. Data written to one region is propagated to other replica regions with a small delay, ensuring high availability and low latency writes globally but not immediate read consistency across regions.

Why this answer

Amazon DynamoDB global tables use asynchronous replication to propagate writes from one region to all other replica tables. This means that after a write in the primary region, there is an inherent replication lag (typically sub-second but can be higher under load or network issues) before the change is visible in other regions. The developer observes stale reads because the read is hitting a replica that has not yet received the update, which is expected behavior for eventually consistent reads on global tables.

Exam trap

The trap here is that candidates often assume DynamoDB global tables provide immediate consistency across regions (like synchronous replication) or that they can simply switch to strong consistency reads on replicas, but the exam tests the understanding that global tables are eventually consistent and that strong consistency is not available on replica tables.

How to eliminate wrong answers

Option B is wrong because DynamoDB Streams are used to capture item-level changes for custom processing (e.g., triggering Lambda functions), but they are not required for replication in global tables—global tables handle replication internally using the DynamoDB replication protocol. Option C is wrong because strong consistency reads are not supported on replica tables in a global table setup; only eventually consistent reads are available on replicas, so enabling strong consistency reads is not an option. Option D is wrong because write forwarding is a feature that allows a write request to a replica to be forwarded to the primary region for execution, but it does not affect the read consistency or replication lag when reading from a replica after a write in the primary region.

122
MCQmedium

A developer is deploying a web application using AWS Elastic Beanstalk. The application uses a MySQL database. During deployment, the developer needs to apply database schema migrations. Which approach should the developer use to run database migrations as part of the Elastic Beanstalk deployment?

A.Use an .ebextensions configuration file to run a migration script during deployment.
B.Configure an RDS event subscription to trigger a Lambda function that runs migrations.
C.Run the migration script as a scheduled task using CloudWatch Events.
D.Use AWS CodeDeploy's AppSpec file to run the migration script.
AnswerA

Using an .ebextensions configuration file is the correct approach because Elastic Beanstalk processes these files during deployment, allowing developers to execute custom commands on the EC2 instances. Specifically, `container_commands` or `commands` within these YAML files can run database migration scripts at a specific point in the application deployment lifecycle. This ensures the database schema is updated in sync with the new application code before it starts serving traffic.

Why this answer

Elastic Beanstalk supports .ebextensions configuration files that can execute custom commands or scripts during deployment. By placing a migration script (e.g., a shell script that runs `mysql` commands or a framework migration tool) in the `.ebextensions` directory and using the `commands` or `container_commands` key, the developer can ensure the migration runs automatically after the application is deployed but before the new environment serves traffic. This approach integrates the migration into the deployment lifecycle without external dependencies.

Exam trap

The trap here is that candidates often confuse the deployment lifecycle hooks of different AWS services (e.g., CodeDeploy's AppSpec vs. Elastic Beanstalk's .ebextensions) and assume any migration script can be plugged into any deployment tool, ignoring that Elastic Beanstalk has its own proprietary configuration mechanism.

How to eliminate wrong answers

Option B is wrong because RDS event subscriptions notify about database events (e.g., failover, backup completion) but do not trigger Lambda functions directly; while you could use EventBridge to route RDS events to Lambda, this approach is asynchronous and unrelated to the deployment lifecycle, so it cannot guarantee migrations run exactly during an Elastic Beanstalk deployment. Option C is wrong because running migrations as a scheduled task using CloudWatch Events would execute at fixed times, not in sync with the deployment process, leading to potential schema mismatches or race conditions. Option D is wrong because AWS CodeDeploy's AppSpec file is used for deployments managed by CodeDeploy, not Elastic Beanstalk; Elastic Beanstalk has its own deployment mechanism and does not read or execute AppSpec files.

123
MCQmedium

A developer needs an S3 upload workflow where clients upload large files directly to S3 without exposing AWS credentials through the browser. What should the backend generate?

A.Pre-signed URLs with appropriate expiration and object restrictions
B.Long-lived IAM access keys for each client
C.A public-read bucket policy
D.An S3 Inventory report
AnswerA

Pre-signed URLs grant temporary, time-limited access to specific S3 objects or prefixes without requiring AWS credentials directly from the client. They are generated by an AWS credential holder and can be configured with specific permissions (e.g., PutObject), an expiration time, and even conditions on the upload like content type or size. This approach securely delegates upload capability to unauthenticated clients for a defined period, aligning perfectly with the requirement for client uploads without exposing long-term credentials.

Why this answer

Pre-signed URLs allow the backend to generate time-limited, permission-restricted URLs that clients can use to upload objects directly to S3 without exposing AWS credentials. The backend signs the URL with IAM credentials, and the client uses the URL to perform the PUT operation, ensuring secure, credential-free uploads.

Exam trap

The trap here is that candidates may confuse pre-signed URLs with public bucket policies or long-lived keys, thinking that any form of direct access requires exposing credentials, when in fact pre-signed URLs provide temporary, scoped access without credential leakage.

How to eliminate wrong answers

Option B is wrong because long-lived IAM access keys would expose permanent credentials in the browser, violating the requirement to avoid credential exposure and creating a severe security risk. Option C is wrong because a public-read bucket policy allows anyone to read objects but does not provide a secure, controlled upload mechanism; it would also expose the bucket to unauthorized writes if not carefully restricted. Option D is wrong because an S3 Inventory report is a listing of objects for auditing or lifecycle management, not a mechanism for uploading files.

124
MCQeasy

A developer is using Amazon DynamoDB to store session data for a web application. The application experiences read-heavy traffic and the developer wants to reduce latency. Which feature should be used to improve read performance?

A.DynamoDB Global Tables
B.DynamoDB Streams
C.DynamoDB Accelerator (DAX)
D.DynamoDB Time to Live (TTL)
AnswerC

DynamoDB Accelerator (DAX) is a fully managed, highly available, in-memory cache specifically designed for DynamoDB. It provides microsecond response times for read-heavy workloads by caching frequently accessed data, significantly reducing the load on the underlying DynamoDB table. DAX is API-compatible with DynamoDB, allowing developers to integrate it with minimal application code changes to achieve substantial read performance improvements.

Why this answer

DynamoDB Accelerator (DAX) is a fully managed, in-memory cache that delivers up to 10x read performance improvement by reducing response times from milliseconds to microseconds. For read-heavy workloads like session data, DAX offloads read traffic from the DynamoDB table, reducing latency and providing a seamless caching layer without application code changes.

Exam trap

The trap here is that candidates confuse DynamoDB Global Tables (which reduce latency for cross-region reads) with a single-region read cache, but Global Tables do not improve read performance within the same region — DAX is the correct service for that purpose.

How to eliminate wrong answers

Option A is wrong because DynamoDB Global Tables provide multi-region replication for disaster recovery and low-latency writes across regions, but they do not improve read performance within a single region. Option B is wrong because DynamoDB Streams capture item-level changes for event-driven processing or replication, but they do not cache data or reduce read latency. Option D is wrong because DynamoDB Time to Live (TTL) automatically expires old session data to manage storage costs, but it has no impact on read performance or latency.

125
MCQmedium

A developer has an AWS Lambda function that processes messages from an Amazon SQS standard queue. The function is idempotent and currently has a batch size of 10. The developer wants to increase throughput and increases the batch size to 100. After the change, CloudWatch metrics show a significant increase in throttles and the queue backlog is growing. The function's reserved concurrency is set to 10. What is the most effective action to resolve the throttling and improve throughput?

A.Increase the reserved concurrency of the Lambda function
B.Increase the memory allocation of the Lambda function
C.Switch the SQS queue to a FIFO queue
D.Decrease the batch size back to 10
AnswerA

Increasing reserved concurrency directly allocates a dedicated maximum number of simultaneous executions for this specific Lambda function. This prevents the function from being throttled by the account's unreserved concurrency limit or other functions consuming available capacity. By ensuring more invocations can run in parallel, the function can effectively process larger SQS batch sizes without messages backing up, significantly improving overall message consumption rate and throughput.

Why this answer

Increasing the reserved concurrency from 10 to a higher value directly addresses the root cause of throttling. With a batch size of 100, each invocation processes more messages, but the function's reserved concurrency of 10 limits the maximum number of concurrent executions to 10. This means the Lambda service can only invoke the function 10 times at once, regardless of how many messages are in the queue.

By raising reserved concurrency, you allow more concurrent invocations to handle the larger batches, reducing throttling and improving throughput.

Exam trap

The trap here is that candidates often assume throttling is due to function performance (memory or CPU) and choose to increase memory, when in fact the issue is a concurrency limit that prevents the function from scaling to handle the larger batch size.

How to eliminate wrong answers

Option B is wrong because increasing memory allocation improves CPU and network performance per invocation but does not increase the number of concurrent executions allowed, so it cannot resolve throttling caused by hitting the reserved concurrency limit. Option C is wrong because switching to a FIFO queue would reduce throughput due to its strict message ordering and limited concurrency (FIFO queues support a maximum of 300 transactions per second with batching), which is counterproductive when trying to increase throughput. Option D is wrong because decreasing the batch size back to 10 would reduce the number of messages processed per invocation, lowering throughput and failing to address the underlying concurrency bottleneck.

126
MCQmedium

A developer is creating a REST API using Amazon API Gateway with Lambda proxy integration. The API needs to accept and return binary data such as images or PDF files. The developer has configured the API to use the Lambda proxy integration. What additional configuration is required to support binary data?

A.Set the Content-Type header to application/octet-stream in the Lambda response.
B.In API Gateway, add the binary media types to the API settings, e.g., image/png, application/pdf.
C.Use an API Gateway custom domain with an SSL certificate.
D.Enable API caching with binary support.
AnswerB

This is the correct and essential step for API Gateway to properly handle binary data from a Lambda integration. By explicitly listing media types like `image/png` or `application/pdf` in the API Gateway's binary media types settings, you instruct API Gateway to treat incoming and outgoing payloads of these types as raw binary data. This ensures that API Gateway correctly base64-encodes binary responses from Lambda before sending them to the client and decodes binary requests before passing them to Lambda, preventing data corruption.

Why this answer

With Lambda proxy integration, API Gateway passes the client request as-is to Lambda and returns the Lambda response as-is to the client. To handle binary data, you must explicitly declare the binary media types (e.g., image/png, application/pdf) in the API Gateway REST API settings. This tells API Gateway to base64-encode the binary payload before sending it to Lambda and to decode the base64-encoded response from Lambda back to binary for the client.

Without this configuration, API Gateway treats all payloads as text and will corrupt binary data.

Exam trap

The trap here is that candidates assume Lambda proxy integration automatically handles binary data because it passes everything through, but in reality, API Gateway requires explicit binary media type configuration to avoid corrupting binary payloads during base64 encoding/decoding.

How to eliminate wrong answers

Option A is wrong because setting the Content-Type header to application/octet-stream in the Lambda response alone does not enable API Gateway to handle binary data; API Gateway must be explicitly configured with the binary media types in the API settings, and the Lambda response must also include the correct isBase64Encoded flag set to true. Option C is wrong because using a custom domain with an SSL certificate is related to HTTPS endpoint configuration and custom domain names, not to enabling binary data support in API Gateway. Option D is wrong because API caching is a performance optimization feature that caches responses; it does not provide or enable binary data handling, and there is no 'binary support' toggle in API caching.

127
MCQeasy

A developer is using Amazon API Gateway to create a REST API. The API must support CORS (Cross-Origin Resource Sharing) to allow requests from a web application hosted on a different domain. What must the developer do to enable CORS?

A.Use Amazon CloudFront to proxy the API and add CORS headers.
B.Enable CORS in the API Gateway settings and configure the required headers.
C.Nothing; API Gateway automatically handles CORS.
D.Add CORS headers in the Lambda function code.
AnswerB

API Gateway provides a dedicated feature to enable Cross-Origin Resource Sharing (CORS) directly within its console or via infrastructure as code. This involves configuring the `OPTIONS` method for resources, specifying allowed origins, methods, and headers, and ensuring the necessary `Access-Control-Allow-*` headers are automatically included in responses. This native capability simplifies CORS management, allowing the API Gateway to handle preflight requests and inject the required headers without custom backend logic.

Why this answer

Enabling CORS in API Gateway requires explicit configuration: you must enable CORS on the API Gateway resource, which automatically generates an OPTIONS method and adds the necessary CORS headers (Access-Control-Allow-Origin, Access-Control-Allow-Methods, Access-Control-Allow-Headers) to responses. This is done through the API Gateway console or API configuration, not by the backend Lambda function or CloudFront.

Exam trap

The trap here is that candidates assume API Gateway automatically handles CORS (Option C) or that adding headers only in the Lambda function is sufficient (Option D), forgetting that the browser's preflight OPTIONS request must be handled by API Gateway itself.

How to eliminate wrong answers

Option A is wrong because Amazon CloudFront does not automatically add CORS headers for API Gateway; it can only forward or modify headers if configured, but the CORS headers must originate from the API Gateway or backend. Option C is wrong because API Gateway does not automatically handle CORS; it requires explicit enabling and configuration of CORS headers and the OPTIONS preflight response. Option D is wrong because while you can add CORS headers in the Lambda function code, this only works for non-preflight requests; API Gateway must still handle the OPTIONS preflight request and return the appropriate CORS headers, which is why enabling CORS in API Gateway is the recommended approach.

128
MCQmedium

A developer is using AWS Elastic Beanstalk to deploy a web application. The application writes logs to the local file system. The developer wants to ensure that logs are automatically rotated and retained for 30 days. What should the developer do?

A.Modify the application code to write logs directly to an S3 bucket with lifecycle policies.
B.Add a cron job to the EC2 instances that compresses and deletes old logs.
C.Configure the Elastic Beanstalk environment to enable log rotation and set retention period to 30 days.
D.Install the CloudWatch Logs agent on the EC2 instances and configure it to stream logs to CloudWatch Logs with a 30-day retention.
AnswerC

Elastic Beanstalk provides built-in environment properties to manage log rotation and retention directly, making it the most appropriate and integrated solution for this requirement. Developers can configure settings like `LogRotationPeriod` and `LogRotationSizeThreshold` through the Elastic Beanstalk console, CLI, or configuration files. This ensures local log files are automatically rotated and old logs are removed, preventing disk space issues without requiring custom code or manual scripts.

Why this answer

Elastic Beanstalk provides a built-in configuration for log rotation and retention directly in the environment settings. By enabling log rotation and setting the retention period to 30 days, the developer can automatically manage logs without modifying application code or adding external agents. This leverages the Elastic Beanstalk health agent, which handles log rotation on the EC2 instances and stores rotated logs in Amazon S3 with lifecycle policies to enforce the retention period.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing CloudWatch Logs (Option D) because it is a common logging service, but the question specifically asks for automatic rotation and retention on the local file system, which Elastic Beanstalk's built-in feature handles directly without additional services.

How to eliminate wrong answers

Option A is wrong because writing logs directly to S3 from application code bypasses the local file system requirement and introduces unnecessary complexity, such as managing S3 permissions and handling network latency, while Elastic Beanstalk already provides a simpler built-in log rotation mechanism. Option B is wrong because adding a cron job to EC2 instances is a manual, non-scalable approach that does not integrate with Elastic Beanstalk's managed environment; it also lacks centralized retention control and can be lost during instance replacements. Option D is wrong because while CloudWatch Logs agent can stream logs with a 30-day retention, this requires additional setup and costs, and it does not perform local log rotation on the file system; Elastic Beanstalk's native log rotation is more straightforward for this specific requirement.

129
MCQeasy

A developer wants to store application configuration data that can be accessed by multiple microservices. The data is sensitive and should be encrypted at rest. Which AWS service should be used to meet these requirements?

A.Amazon S3
B.AWS Identity and Access Management (IAM)
C.Amazon DynamoDB
D.AWS Systems Manager Parameter Store
AnswerD

AWS Systems Manager Parameter Store is a highly scalable, secure, and easy-to-use service for storing and managing configuration data and secrets. It supports hierarchical organization, versioning, and secure string types, allowing sensitive data like database credentials or API keys to be encrypted at rest using AWS KMS. Applications can securely retrieve parameters at runtime, making it the ideal solution for centralized application configuration management.

Why this answer

AWS Systems Manager Parameter Store provides a secure, hierarchical store for configuration data and secrets. It supports encryption at rest using AWS KMS, integrates with AWS IAM for fine-grained access control, and is designed for use by multiple microservices via the AWS SDK or CLI. This makes it the ideal choice for storing sensitive application configuration that must be encrypted at rest and accessed by distributed services.

Exam trap

The trap here is that candidates often choose Amazon S3 because they think of storing configuration files (e.g., JSON or YAML) in buckets, but they overlook that Parameter Store is purpose-built for secure, encrypted configuration management with native IAM integration and no need to manage file access or encryption manually.

How to eliminate wrong answers

Option A is wrong because Amazon S3 is an object storage service, not a configuration store; while it supports encryption at rest, it lacks native hierarchical parameter management, versioning of configuration values, and seamless integration with AWS SDKs for parameter retrieval without custom code. Option B is wrong because AWS Identity and Access Management (IAM) is an access management service for controlling permissions, not a data store; it cannot store application configuration data or secrets. Option C is wrong because Amazon DynamoDB is a NoSQL database designed for high-performance, scalable data storage, but it does not provide built-in encryption at rest by default (requires additional configuration with AWS KMS), and it lacks native parameter store features like tiered pricing, automatic rotation, or simple key-value retrieval without provisioning read/write capacity units.

130
Multi-Selectmedium

A company is using Amazon RDS for MySQL with Multi-AZ deployment. The application writes to the database using the primary endpoint. The company wants to improve read performance and offload read traffic from the primary instance. Which TWO actions should the company take? (Choose TWO.)

Select 2 answers
A.Create an Amazon RDS read replica in the same region.
B.Add another primary instance and configure replication.
C.Modify the application to use the read replica endpoint for SELECT queries.
D.Use the Multi-AZ secondary instance endpoint for read queries.
E.Enable Amazon RDS Proxy to distribute read queries across instances.
AnswersA, C

Creating an Amazon RDS read replica in the same region provides an asynchronously replicated copy of the primary database instance. This replica is specifically designed to handle read-only queries, such as SELECT statements, thereby offloading the read workload from the primary instance. By distributing read traffic, the primary instance's CPU, I/O, and connection utilization are significantly reduced, allowing it to dedicate resources to write operations and maintain optimal performance for critical transactions.

Why this answer

Amazon RDS read replicas are designed to offload read traffic from the primary DB instance. A read replica is an asynchronous copy of the primary that can serve SELECT queries, improving read performance without impacting write operations on the primary. Option C is correct because the application must explicitly use the read replica's endpoint for read queries; the replica does not automatically balance traffic.

Together, creating a read replica and modifying the application to direct SELECT queries to its endpoint achieves the goal of improving read performance and offloading the primary.

Exam trap

The trap here is confusing Multi-AZ standby instances with read replicas—candidates often think the standby can serve reads, but it is a passive replica that only becomes active during failover and has no accessible endpoint for read queries.

131
MCQeasy

A developer needs to store session state data for a web application running on multiple EC2 instances. The data must be highly available and durable. Which AWS service should be used?

A.Amazon ElastiCache
B.Amazon S3
C.Amazon EBS
D.Amazon CloudFront
AnswerA

Amazon ElastiCache provides managed in-memory data stores, such as Redis or Memcached, which offer extremely low-latency access and high throughput. This makes it an ideal choice for storing frequently accessed, transient session state data for web applications. By centralizing session state in ElastiCache, application servers can remain stateless, allowing for seamless horizontal scaling and high availability across multiple instances without losing user sessions.

Why this answer

Amazon ElastiCache is the correct choice because it provides a managed, in-memory caching service that is ideal for storing session state data with high availability and durability. By using ElastiCache for Redis or Memcached, session data is stored outside of individual EC2 instances, ensuring that if an instance fails, the session state is preserved and can be accessed by other instances in the application tier. ElastiCache supports replication and automatic failover, meeting the requirements for high availability and durability.

Exam trap

The trap here is that candidates often confuse Amazon ElastiCache with Amazon DynamoDB or Amazon S3 for session storage, but the question specifically requires a highly available and durable in-memory solution, and ElastiCache is the only option that provides low-latency, shared session state across multiple EC2 instances with built-in replication and failover.

How to eliminate wrong answers

Option B (Amazon S3) is wrong because S3 is an object storage service designed for large-scale data storage and retrieval, not for low-latency session state access; its eventual consistency model and higher latency make it unsuitable for real-time session management. Option C (Amazon EBS) is wrong because EBS provides block-level storage volumes attached to a single EC2 instance, so session data stored on an EBS volume is not shared across multiple instances and becomes unavailable if the instance fails, violating the high availability requirement. Option D (Amazon CloudFront) is wrong because CloudFront is a content delivery network (CDN) that caches static and dynamic content at edge locations; it does not provide a storage mechanism for session state data and is not designed for transactional, stateful data persistence.

132
Multi-Selectmedium

A developer is designing a mobile application that needs to upload files to Amazon S3. The developer wants to use temporary credentials to avoid storing long-term AWS credentials on the device. Which TWO services should the developer use together?

Select 2 answers
A.AWS Security Token Service (STS)
B.Amazon Cognito
C.Amazon S3 Transfer Acceleration
D.AWS Identity and Access Management (IAM)
E.AWS Key Management Service (KMS)
AnswersA, B

AWS Security Token Service (STS) is fundamental for granting temporary, limited-privilege credentials to users or services that don't have long-term IAM credentials. For mobile applications, STS is often used indirectly via services like Amazon Cognito, which federates identities and then calls STS to issue session tokens. Developers can also directly use STS API operations, such as AssumeRoleWithWebIdentity, to exchange tokens from external identity providers for temporary AWS access keys, enabling secure, time-bound access to AWS resources.

Why this answer

AWS Security Token Service (STS) is used to generate temporary, limited-privilege credentials for accessing AWS resources, such as S3 buckets. Amazon Cognito provides identity pools that can automatically obtain and refresh STS tokens for authenticated users, eliminating the need to store long-term AWS credentials on the mobile device. Together, they enable secure, temporary credential management for file uploads.

Exam trap

The trap here is that candidates often confuse IAM (which manages long-term credentials) with STS (which issues temporary credentials), or they mistakenly think S3 Transfer Acceleration or KMS can handle authentication, when in fact only STS and Cognito together solve the temporary credential requirement for mobile apps.

133
MCQeasy

A developer is creating an API with Amazon API Gateway that needs to accept binary data (e.g., images) and store them directly in an S3 bucket. The developer wants to minimize backend complexity. Which integration type should be used?

A.AWS service integration with S3
B.Lambda proxy integration
C.HTTP integration
D.Mock integration
AnswerA

AWS service integration enables API Gateway to directly invoke actions on other AWS services, such as S3, without requiring an intermediate compute layer like Lambda. For storing objects, this integration type allows API Gateway to map incoming request bodies directly to S3 PUT object operations. This approach significantly minimizes backend complexity and latency by leveraging S3's native capabilities for object storage, making it the most efficient solution for directly accepting and storing data.

Why this answer

AWS service integration with S3 allows API Gateway to directly proxy binary data (e.g., images) to an S3 bucket without invoking a Lambda function or other backend. This minimizes backend complexity because the API Gateway handles the request transformation and passes the payload directly to S3 via the PutObject API action, eliminating the need for custom code.

Exam trap

The trap here is that candidates often default to Lambda proxy integration for any data processing task, overlooking that direct AWS service integration can handle binary uploads to S3 without any compute layer, which is the simplest and most cost-effective approach.

How to eliminate wrong answers

Option B (Lambda proxy integration) is wrong because it introduces unnecessary backend complexity by requiring a Lambda function to receive the binary data and then upload it to S3, adding compute cost and latency. Option C (HTTP integration) is wrong because it would require a separate HTTP endpoint (e.g., on EC2 or on-premises) to receive the data and then forward it to S3, defeating the goal of minimizing backend complexity. Option D (Mock integration) is wrong because it only returns static responses from API Gateway without actually storing any data in S3, so it cannot fulfill the requirement of persisting binary data.

134
MCQeasy

A developer is creating an AWS Lambda function that processes messages from an Amazon SQS queue. The function should process each message only once. Which SQS queue type should the developer use?

A.Amazon SQS does not support exactly-once processing.
B.Dead-letter queue
C.FIFO queue
D.Standard queue
AnswerC

An Amazon SQS FIFO queue is the correct choice for scenarios requiring exactly-once processing and strict message ordering. It achieves this by preventing duplicate messages from being sent to the queue using a deduplication ID or content-based deduplication, and by ensuring that a message is delivered to a consumer, processed, and deleted before the next message in its message group is delivered. This guarantee is critical for applications where message order and uniqueness are paramount, such as financial transactions or order processing systems.

Why this answer

Amazon SQS FIFO (First-In-First-Out) queues guarantee exactly-once processing within a message group. They use a deduplication ID (either content-based or explicitly provided) to prevent duplicate message delivery, ensuring that each message is processed only once by the consumer.

Exam trap

The trap here is that candidates often assume Standard queues are sufficient because they are the default, but they overlook the fact that Standard queues provide at-least-once delivery, not exactly-once, which directly contradicts the requirement to process each message only once.

How to eliminate wrong answers

Option A is wrong because Amazon SQS does support exactly-once processing through FIFO queues, which provide deduplication and ordered delivery. Option B is wrong because a dead-letter queue is a secondary queue used to capture messages that fail processing after a specified number of attempts; it does not itself provide exactly-once processing guarantees. Option D is wrong because Standard queues offer at-least-once delivery, meaning the same message can be delivered multiple times, which violates the requirement for exactly-once processing.

135
MCQmedium

A developer is using AWS SAM to deploy a serverless application. The template includes a Lambda function that connects to an RDS MySQL database. The function works correctly in the developer's account but fails with a timeout when deployed to a production account. What is the MOST likely cause?

A.The Lambda function timeout is set too low for the database query.
B.The Lambda function is not attached to the same VPC as the RDS instance.
C.The SAM template does not support RDS as an event source.
D.The Lambda function uses a runtime that is not compatible with the MySQL client.
AnswerB

For a Lambda function to securely and privately access an Amazon RDS instance, it must be configured to operate within the same Virtual Private Cloud (VPC) as the database. RDS instances are typically deployed into private subnets without public internet access, requiring the Lambda function to be placed within that VPC to establish a private network connection. If the Lambda is not attached to the correct VPC, it will be unable to resolve the private IP address or reach the RDS endpoint, leading to connection failures.

Why this answer

The most likely cause is that the Lambda function is not attached to the same VPC as the RDS instance. Lambda functions run in a VPC by default only if explicitly configured; without VPC attachment, the function cannot reach the RDS database's private IP address, leading to a connection timeout. The developer's account may have had the RDS instance publicly accessible or the Lambda function was inadvertently in the same VPC, but the production account likely uses a private RDS instance in a VPC that the Lambda function is not connected to.

Exam trap

The trap here is that candidates often assume a Lambda function can always reach an RDS database by default, overlooking the critical VPC configuration requirement for private resources.

How to eliminate wrong answers

Option A is wrong because a low Lambda function timeout would cause a timeout error, but the symptom is a connection timeout (the function fails to connect at all), not a query execution timeout; the core issue is network connectivity, not the timeout value. Option C is wrong because SAM templates do not need to define RDS as an event source; Lambda connects to RDS via the database client library in the function code, not through an event source mapping. Option D is wrong because the Lambda function works correctly in the developer's account, proving the runtime is compatible with the MySQL client; the failure is environment-specific, not runtime-related.

136
MCQeasy

A developer needs to store temporary session data for a web application running on Amazon EC2 behind an Application Load Balancer. The data must be accessible across multiple EC2 instances. Which AWS service should the developer use?

A.Amazon ElastiCache
B.Amazon EBS
C.Amazon DynamoDB
D.Amazon S3
AnswerA

Amazon ElastiCache, offering managed Redis or Memcached, is the optimal choice for storing temporary session data. Its in-memory nature provides sub-millisecond latency and high throughput, crucial for frequently accessed session information. By externalizing session state from individual web servers, ElastiCache enables horizontal scaling of application instances and ensures session continuity even if an instance fails, preventing the need for sticky sessions.

Why this answer

Amazon ElastiCache is the correct choice because it provides a managed, in-memory caching service (e.g., Redis or Memcached) that can store temporary session data with sub-millisecond latency. Since the data must be accessible across multiple EC2 instances behind an Application Load Balancer, ElastiCache offers a centralized, highly available data store that all instances can read from and write to, ensuring session persistence regardless of which instance handles a request.

Exam trap

The trap here is that candidates often confuse 'temporary session data' with 'persistent user data' and choose DynamoDB for its scalability, overlooking that ElastiCache is purpose-built for low-latency, ephemeral storage with automatic eviction policies.

How to eliminate wrong answers

Option B (Amazon EBS) is wrong because EBS volumes are block-level storage attached to a single EC2 instance in a specific Availability Zone; they cannot be shared across multiple instances for concurrent read/write access. Option C (Amazon DynamoDB) is wrong because while it is a fully managed NoSQL database that can store session data, it is a persistent, disk-based database with higher latency than an in-memory cache, and it is overkill for temporary session data that does not require durability. Option D (Amazon S3) is wrong because S3 is an object storage service designed for high-durability, long-term storage with eventual consistency (unless using S3 Select or versioning), and its higher latency and lack of native sub-millisecond access make it unsuitable for real-time session data that must be read and written on every request.

137
MCQmedium

A developer is building a chat application using WebSockets. The application runs on multiple EC2 instances and needs to broadcast messages to all connected clients. Which AWS service can handle the WebSocket connections and route messages?

A.Amazon SQS with long polling
B.Application Load Balancer with WebSocket support
C.Amazon CloudFront with WebSocket support
D.Amazon API Gateway WebSocket API
AnswerD

Amazon API Gateway WebSocket API is purpose-built for managing persistent, bidirectional communication channels required by real-time applications like chat. It natively handles WebSocket connection management, including connection establishment and termination, and provides robust mechanisms to send messages to specific clients or broadcast messages to all connected clients, often integrating with backend services like AWS Lambda for message processing.

Why this answer

Amazon API Gateway WebSocket API is the correct choice because it natively manages WebSocket connections, maintains persistent bidirectional communication, and can broadcast messages to all connected clients using callback URLs. It handles connection lifecycle (connect, disconnect, default) and integrates with AWS Lambda or other backends to route messages efficiently.

Exam trap

The trap here is that candidates confuse Application Load Balancer's WebSocket support (which only proxies connections to a single target) with the need for a managed service that can broadcast to multiple clients, leading them to choose ALB over API Gateway.

How to eliminate wrong answers

Option A is wrong because Amazon SQS is a message queue service that uses polling (long or short) and does not support WebSocket connections or real-time bidirectional communication. Option B is wrong because Application Load Balancer supports WebSocket connections but only for routing traffic to backend targets; it cannot broadcast messages to all connected clients or manage the WebSocket protocol's pub/sub patterns. Option C is wrong because Amazon CloudFront does not natively support WebSocket connections; it is a CDN optimized for HTTP/HTTPS and cannot maintain persistent WebSocket state or route messages.

138
MCQhard

A Lambda function connects to an RDS database and causes too many database connections during traffic spikes. Which service should be introduced?

A.AWS Glue Data Catalog
B.Amazon RDS Proxy
C.Amazon Route 53 Resolver
D.AWS WAF
AnswerB

Amazon RDS Proxy is a fully managed, highly available database proxy that significantly improves application resilience and scalability for RDS databases. It establishes and maintains a pool of database connections, reusing them efficiently for new application connections from services like Lambda. This reduces the overhead of establishing new connections, prevents Lambda's concurrent invocations from overwhelming the RDS database with too many open connections, and handles credential management securely.

Why this answer

Amazon RDS Proxy sits between your Lambda function and the RDS database, managing a pool of established database connections. During traffic spikes, Lambda can rapidly scale up concurrent executions, each potentially opening a new database connection, which can exhaust the database's maximum connections. RDS Proxy reuses connections from the pool, reducing the number of open connections and preventing database overload, while also improving connection handling efficiency for serverless applications.

Exam trap

The trap here is that candidates might confuse AWS WAF (a web firewall) or Route 53 (DNS) with database connection management, or incorrectly think that Glue Data Catalog can somehow cache or pool database connections, when in fact only RDS Proxy directly addresses the connection scaling issue for Lambda and RDS.

How to eliminate wrong answers

Option A is wrong because AWS Glue Data Catalog is a metadata repository for data assets in AWS Glue and Athena, not a connection pooling or proxy service for RDS databases. Option C is wrong because Amazon Route 53 Resolver is a DNS service for resolving domain names within VPCs, and it does not manage database connections or connection pooling. Option D is wrong because AWS WAF is a web application firewall that protects against common web exploits like SQL injection and cross-site scripting, but it does not handle database connection management or pooling.

139
MCQhard

Refer to the exhibit. A developer runs the AWS CLI command to invoke a Lambda function. The command succeeds, but the function returns an error. The developer wants to see the error message and logs from the function execution. What should the developer add to the command?

A.--client-context string
B.--qualifier alias
C.--invocation-type Event
D.--log-type Tail
AnswerD

The --log-type Tail parameter is specifically designed to retrieve the last 4 KB of log data generated by a synchronous Lambda function invocation. When used with RequestResponse invocation type, this option includes the base64-encoded log output in the LogResult field of the CLI response. This provides immediate access to recent execution logs directly within the terminal, which is invaluable for debugging and quick verification of function behavior.

Why this answer

The `--log-type Tail` parameter instructs the AWS CLI to retrieve the last 4 KB of log data from the function's execution and base64-encode it in the response. This allows the developer to see the error message and logs directly without needing to query CloudWatch Logs separately. The command must also use `--invocation-type RequestResponse` (the default) to get a synchronous response containing the logs.

Exam trap

The trap here is that candidates often confuse `--invocation-type Event` (async) with the ability to retrieve logs, not realizing that only synchronous invocations (`RequestResponse`) return execution results and logs via `--log-type Tail`.

How to eliminate wrong answers

Option A is wrong because `--client-context string` passes arbitrary JSON data to the Lambda function as part of the invocation request, but it does not retrieve or display any logs or error messages from the execution. Option B is wrong because `--qualifier alias` specifies a version or alias of the function to invoke, which controls which code runs but does not affect log retrieval. Option C is wrong because `--invocation-type Event` triggers an asynchronous invocation, which returns a 202 response immediately without any function output or logs, making it impossible to see error messages in the response.

140
Multi-Selecteasy

Which TWO AWS services can be used to deploy and manage containerized applications? (Choose two.)

Select 2 answers
A.Amazon EC2
B.Amazon ECS
C.Amazon RDS
D.AWS Lambda
E.Amazon EKS
AnswersB, E

Amazon Elastic Container Service (ECS) is a fully managed container orchestration service that allows you to easily deploy, manage, and scale Docker containers on AWS. It provides robust capabilities for defining tasks, services, and clusters, abstracting away the underlying infrastructure management. You can choose between the serverless AWS Fargate launch type, where AWS manages the compute capacity, or the EC2 launch type, giving you more control over the underlying instances.

Why this answer

Amazon ECS (Elastic Container Service) is a fully managed container orchestration service that allows you to run Docker containers at scale. It integrates with AWS Fargate for serverless compute or EC2 for more control, and it handles cluster management, scheduling, and scaling of containerized applications.

Exam trap

The trap here is that candidates may confuse Amazon EC2 (a compute instance) with a container management service, or think AWS Lambda can manage containers long-term, but Lambda is designed for short-lived, event-driven functions, not persistent container orchestration.

141
MCQmedium

A Lambda function must share reusable validation code across several functions without packaging the same library into every deployment artifact. What should be used?

A.Lambda layer
B.API Gateway usage plan
C.S3 multipart upload
D.CloudWatch metric filter
AnswerA

A Lambda layer is a ZIP archive containing supplementary code or data, such as libraries, custom runtimes, or common utility functions. By packaging reusable validation logic into a layer, multiple Lambda functions can reference it, significantly reducing deployment package sizes and promoting code consistency. This mechanism directly addresses the need to share common code across various serverless functions efficiently.

Why this answer

Lambda layers allow you to centrally manage reusable code (e.g., validation libraries) and share it across multiple Lambda functions without packaging it into each deployment artifact. When you attach a layer to a function, the layer's content is extracted into the /opt directory, making it available at runtime. This avoids duplication and simplifies updates, as you only need to update the layer version rather than every function's deployment package.

Exam trap

The trap here is that candidates may confuse Lambda layers with other AWS services that handle 'sharing' (like API Gateway usage plans for sharing API access) or 'packaging' (like S3 multipart upload for large files), but only Lambda layers are designed to share code and dependencies across functions without repackaging.

How to eliminate wrong answers

Option B is wrong because API Gateway usage plans are used to throttle and quota API requests, not to share code across Lambda functions. Option C is wrong because S3 multipart upload is a mechanism for uploading large objects in parts, not for distributing reusable code to Lambda functions. Option D is wrong because CloudWatch metric filters are used to extract metric data from log streams, not to share or package code for Lambda.

142
MCQeasy

A developer is writing a Lambda function that processes images uploaded to an S3 bucket. The function needs to extract metadata from the image. Which S3 feature can be used to automatically trigger the Lambda function?

A.S3 Events
B.S3 Inventory
C.S3 Transfer Acceleration
D.S3 Batch Operations
AnswerA

S3 Event Notifications are the correct mechanism for triggering real-time actions in response to object changes within an S3 bucket. When an image is uploaded, S3 can publish an event to a configured destination, such as an AWS Lambda function. This allows for immediate, automated processing like image resizing, watermarking, or metadata extraction as soon as the object creation event occurs.

Why this answer

Amazon S3 Events can be configured to send a notification when an object is created (e.g., via PutObject) in an S3 bucket. This event can directly invoke an AWS Lambda function, making it the correct service to automatically trigger the function upon image upload. The developer simply needs to set up an S3 event notification with the Lambda function as the destination.

Exam trap

The trap here is that candidates may confuse S3 Batch Operations (which can invoke Lambda functions for batch processing) with real-time event triggers, but Batch Operations require a manual job initiation and do not automatically fire on each upload.

How to eliminate wrong answers

Option B (S3 Inventory) is wrong because it is used to generate a list of objects and their metadata for auditing or compliance, not to trigger real-time event-driven actions. Option C (S3 Transfer Acceleration) is wrong because it only speeds up uploads over long distances using edge locations, it has no mechanism to invoke Lambda functions. Option D (S3 Batch Operations) is wrong because it performs bulk actions (like copying or tagging) on existing objects via a job, not real-time event triggering upon object creation.

143
MCQeasy

A developer is designing a microservices architecture where each service runs in its own Amazon ECS container. Services need to communicate with each other. The developer wants to simplify service discovery and load balancing. Which AWS service should the developer use?

A.AWS Cloud Map
B.Elastic Load Balancing
C.Amazon ECS service discovery
D.Amazon Route 53
AnswerA

AWS Cloud Map provides a robust service discovery solution by registering dynamically changing microservices with custom names, allowing other services to discover them via API calls or DNS queries. It integrates seamlessly with Amazon ECS, enabling tasks to register and deregister automatically as they scale or become unhealthy. This dynamic registration is crucial for ephemeral microservices, ensuring services can find each other reliably without hardcoding network locations.

Why this answer

AWS Cloud Map is the correct choice because it provides a fully managed service discovery solution that allows microservices to dynamically discover each other using DNS or HTTP API calls. It integrates natively with Amazon ECS, enabling services to register themselves and resolve other services by logical names, which simplifies service discovery and load balancing across containers.

Exam trap

The trap here is that candidates often confuse the ECS service discovery feature (which is just a configuration option) with a standalone AWS service, leading them to pick option C instead of recognizing that AWS Cloud Map is the underlying service that actually provides the discovery mechanism.

How to eliminate wrong answers

Option B is wrong because Elastic Load Balancing (ELB) is a load balancer that distributes traffic to targets, but it does not provide service discovery; it requires manual configuration of target groups and does not automatically register/deregister ECS services as they scale. Option C is wrong because Amazon ECS service discovery is not a standalone AWS service; it is a feature that leverages AWS Cloud Map under the hood, so the correct service to use is Cloud Map itself. Option D is wrong because Amazon Route 53 is a DNS service primarily for domain name resolution and routing internet traffic, not designed for dynamic service discovery of ephemeral containers in ECS; it lacks native integration with ECS task registration and health checks for service discovery.

144
MCQmedium

A company is using AWS Lambda functions to process events from Amazon S3. The functions are writing logs to CloudWatch Logs. Recently, they noticed that some logs are missing and the functions are experiencing throttling errors. What is the MOST likely cause?

A.The CloudWatch Logs log group retention policy is set too low.
B.The Lambda function's reserved concurrency is set to a low value.
C.The Lambda function's IAM role lacks permissions to write to CloudWatch Logs.
D.The S3 bucket is sending too many event notifications.
AnswerB

Reserved concurrency explicitly caps the maximum number of simultaneous executions for a specific Lambda function. When the rate of incoming events or requests attempts to invoke the function beyond this configured limit, subsequent invocation requests are immediately throttled. This mechanism ensures that the function does not consume more concurrency than allocated, preventing it from impacting other functions or exceeding account-level limits, directly resulting in throttling errors for excess requests.

Why this answer

The most likely cause of throttling errors is that the Lambda function's reserved concurrency is set too low. When a Lambda function's reserved concurrency limit is reached, additional invocation requests are throttled, resulting in missing logs. Option A is incorrect because log group retention affects log storage, not Lambda throttling.

Option C is incorrect because IAM permissions affect the ability to write logs, not throttling. Option D is incorrect because while S3 can send many events, Lambda's concurrency limit is the direct cause of throttling.

145
Multi-Selecteasy

A developer needs to monitor the performance of an Amazon RDS for MySQL database. Which TWO metrics should the developer monitor to detect a potential CPU bottleneck?

Select 2 answers
A.FreeStorageSpace
B.DatabaseConnections
C.CPUUtilization
D.NetworkThroughput
E.ReadLatency
AnswersB, C

DatabaseConnections measures the number of client connections currently established with the database instance. A consistently high or rapidly increasing number of database connections can significantly contribute to CPU contention, as each connection consumes resources and requires the CPU to manage session overhead, execute queries, and handle context switching. While not a direct CPU usage percentage, monitoring this metric is crucial because an excessive connection count is a common cause of elevated CPU utilization and performance degradation.

Why this answer

High CPUUtilization (Option C) directly indicates the CPU is under heavy load, which is the primary symptom of a CPU bottleneck. DatabaseConnections (Option B) is correct because an excessive number of concurrent connections can overwhelm the CPU as each connection requires context switching and query processing, leading to CPU saturation. Monitoring both metrics together helps distinguish between a CPU bottleneck caused by high query load versus one caused by connection overhead.

Exam trap

The trap here is that candidates often focus solely on CPUUtilization and overlook DatabaseConnections, not realizing that a high number of connections can itself be the root cause of CPU saturation, especially in bursty connection scenarios.

146
MCQeasy

A developer is building a serverless REST API using Amazon API Gateway and AWS Lambda. The API should return JSON responses to client requests. The developer is using the Lambda proxy integration. What is the simplest way to return a JSON response from the Lambda function?

A.Return a string from the Lambda handler.
B.Return a dictionary containing 'statusCode', 'headers', and 'body' with 'body' as a JSON string.
C.Use API Gateway integration response and mapping templates to transform the Lambda output.
D.Return a JSON object from Lambda and set a Content-Type header in the API Gateway method response.
AnswerB

This format precisely adheres to the API Gateway Lambda proxy integration contract, where the Lambda function is solely responsible for constructing the entire HTTP response. By returning a dictionary containing `statusCode`, `headers` (as a dictionary of key-value pairs), and a `body` field (which itself must be a string, often a JSON string), the Lambda function provides all necessary information for API Gateway to directly pass through to the client. This ensures the client receives a properly formatted HTTP response with the correct status, custom headers, and a valid JSON payload.

Why this answer

With Lambda proxy integration, API Gateway passes the entire request to the Lambda function and expects the function to return a specific response format. The simplest way to return a JSON response is to return a dictionary (or object) containing 'statusCode', 'headers', and 'body', where 'body' is a JSON string. This format is required by API Gateway to correctly interpret the Lambda output and forward it to the client.

Exam trap

The trap here is that candidates often think returning a JSON object directly from Lambda is sufficient, but they overlook the requirement that the body must be a JSON string and the response must include the exact 'statusCode', 'headers', and 'body' keys for API Gateway proxy integration to work correctly.

How to eliminate wrong answers

Option A is wrong because returning a plain string from the Lambda handler will cause API Gateway to fail or return an unexpected response, as it expects a properly formatted response object. Option C is wrong because using API Gateway integration response and mapping templates adds unnecessary complexity; with proxy integration, the Lambda function itself is responsible for formatting the response, and mapping templates are not used. Option D is wrong because simply returning a JSON object from Lambda without the required 'statusCode', 'headers', and 'body' structure will not be parsed correctly by API Gateway, and setting a Content-Type header in the method response does not address the required Lambda response format.

147
MCQhard

A developer is building a real-time chat application using WebSocket APIs in Amazon API Gateway. The backend is an AWS Lambda function that stores connection IDs in an Amazon DynamoDB table. After a few days, the application stops working for new users. The developer checks CloudWatch Logs and sees that the Lambda function is returning 'AccessDeniedException' when calling DynamoDB. What is the MOST likely cause?

A.The Lambda function code was updated but the IAM role was not reattached.
B.The Lambda function uses an outdated AWS SDK version.
C.The API Gateway route was updated without redeploying the API.
D.The DynamoDB table was recreated and the Lambda function's IAM role still references the old table ARN.
AnswerD

When a DynamoDB table is recreated, it is assigned a completely new Amazon Resource Name (ARN), even if it has the same name. IAM policies grant permissions to specific resources, often identified by their ARN. If the Lambda function's IAM role policy explicitly referenced the old table's ARN, recreating the table invalidates that specific resource permission. Consequently, the Lambda function attempting to access the newly created table (with its new ARN) would correctly receive an AccessDeniedException because its IAM role lacks permission for that specific new resource.

Why this answer

The most likely cause is that the DynamoDB table was recreated, which changes its ARN. The Lambda function's IAM role still references the old table ARN, so when the function attempts to perform DynamoDB operations (e.g., PutItem for storing connection IDs), the request is denied because the role no longer has permissions on the new table. This is a common issue when infrastructure is rebuilt without updating IAM policies.

Exam trap

The trap here is that candidates may confuse 'AccessDeniedException' with a network or API configuration issue (like an outdated SDK or missing redeployment), rather than recognizing it as a classic IAM permissions problem tied to resource ARN changes.

How to eliminate wrong answers

Option A is wrong because IAM roles are attached to Lambda functions at the function level, not to the code; updating code does not detach the role. Option B is wrong because an outdated SDK version would cause errors like 'UnknownOperationException' or 'UnsupportedMediaType', not 'AccessDeniedException', which is an IAM permissions error. Option C is wrong because API Gateway route updates without redeployment would cause 404 or 503 errors at the API level, not an 'AccessDeniedException' from Lambda when calling DynamoDB.

148
MCQmedium

A developer is using AWS CodePipeline to deploy a web application to an Auto Scaling group. The pipeline includes a deploy action that uses CodeDeploy. The deployment fails with the error: 'The overall deployment failed because too many individual instances failed deployment, too few healthy instances are available, or some instances in your deployment group are experiencing problems.' Which of the following is the MOST likely cause?

A.The CodeDeploy agent is not sending logs to CloudWatch.
B.The deployment configuration has a minimum healthy instances setting that is too restrictive.
C.The application's lifecycle hooks are failing during the ApplicationStop event.
D.The instances were launched from an AMI that does not have the CodeDeploy agent installed.
AnswerB

CodeDeploy deployment configurations, such as `CodeDeployDefault.OneAtATime` or custom settings, include a `minimum healthy instances` threshold. If this setting is too restrictive, for example, requiring 100% of instances to remain healthy during a rolling update, the deployment will fail when even a single instance is taken offline for the update. The deployment cannot proceed if the number of healthy instances drops below the specified minimum, leading to a "too few healthy instances" error.

Why this answer

The error message indicates that the deployment failed because too many instances were unhealthy or failed. The most likely cause is that the deployment configuration's minimum healthy hosts setting is too restrictive, meaning it requires a higher percentage of healthy instances during deployment than the environment can sustain, causing CodeDeploy to stop the deployment when the threshold is breached.

Exam trap

The trap here is that candidates often confuse individual instance failures (e.g., missing agent, hook errors) with the deployment group-level threshold error, leading them to pick options that explain why a single instance failed rather than why the entire deployment was aborted.

How to eliminate wrong answers

Option A is wrong because the CodeDeploy agent not sending logs to CloudWatch would cause a lack of monitoring data, but it would not directly cause the deployment to fail with the given error; the deployment would proceed but logs would be missing. Option C is wrong because lifecycle hooks failing during the ApplicationStop event would cause individual instance failures, but the error message specifically points to a global deployment failure due to too few healthy instances, which is a deployment configuration issue, not a hook failure. Option D is wrong because if instances were launched from an AMI without the CodeDeploy agent, the agent would not run and the deployment would fail on each instance individually, but the error message about 'too few healthy instances' is a deployment group-level threshold issue, not a missing agent problem.

149
MCQhard

A developer is building a REST API using API Gateway and Lambda. The API must support multiple HTTP methods and use a custom domain name with an SSL certificate. The developer wants to enable caching for the /products GET endpoint to reduce latency. Which step is essential to enable caching for this specific endpoint?

A.Set the TTL (time-to-live) for the /products GET method to a non-zero value.
B.Enable caching on the /products GET method and specify cache key parameters.
C.Flush the API cache to start fresh.
D.Enable caching on the API stage and set the 'Cache Status' to 'AVAILABLE'.
AnswerB

To implement caching for a specific API Gateway method like /products GET, caching must first be enabled at the API stage level. Subsequently, individual methods can be configured to utilize this cache. This involves explicitly enabling caching for the /products GET method and defining cache key parameters, which dictate how requests are uniquely identified for caching purposes, often including query string parameters, headers, or path parameters. This ensures relevant responses are stored and retrieved efficiently.

Why this answer

Enabling caching on a specific method (e.g., /products GET) in API Gateway allows you to configure cache key parameters, which control how the cache key is generated based on request parameters. This is essential for per-endpoint caching, as it ensures that only responses for the /products GET endpoint are cached, reducing latency for that specific method without affecting other endpoints.

Exam trap

The trap here is that candidates often confuse enabling caching at the stage level (which caches all methods) with enabling it on a specific method, and they overlook the requirement to specify cache key parameters for per-endpoint control.

How to eliminate wrong answers

Option A is wrong because setting a non-zero TTL on the /products GET method is not a step to enable caching; TTL is configured after caching is enabled and controls how long cached responses are retained, not the enabling itself. Option C is wrong because flushing the API cache clears existing cached data but does not enable caching; it is a maintenance action, not an enabling step. Option D is wrong because enabling caching on the API stage caches all methods in the stage by default, not specifically the /products GET endpoint, and the 'Cache Status' to 'AVAILABLE' is a status indicator, not an action to enable per-method caching.

150
Multi-Selectmedium

Which THREE of the following are valid use cases for AWS Lambda? (Choose three.)

Select 3 answers
A.Processing records from a DynamoDB Stream in real time
B.Running a scheduled task every hour to clean up old database records
C.Serving as a web server for a static website
D.Hosting a long-running web application with WebSockets
E.Processing objects uploaded to an S3 bucket
AnswersA, B, E

AWS Lambda is an excellent choice for processing records from a DynamoDB Stream in real time. DynamoDB Streams provide a time-ordered sequence of item-level modifications, which can be configured as an event source for a Lambda function. This allows the function to automatically invoke and process batches of stream records as soon as changes occur in the DynamoDB table, enabling real-time data processing, analytics, or replication.

Why this answer

Option A is correct because DynamoDB Streams can be configured as an event source for Lambda, which then invokes the function in real time with batches of stream records for processing. Option B is correct because Amazon EventBridge (CloudWatch Events) scheduled rules can invoke a Lambda function on a cron or rate expression, such as hourly, making it suitable for periodic cleanup tasks. Option C is incorrect because static websites are served by services like Amazon S3 static website hosting or CloudFront, not by Lambda, which is an event-driven compute service rather than a persistent web server.

Option D is incorrect because long-running applications with persistent WebSocket connections require continuously running compute such as EC2, ECS, or API Gateway WebSocket APIs backed by appropriate compute, whereas Lambda has a maximum execution timeout of 15 minutes and is not designed for persistent connections. Option E is correct because S3 can be configured to send event notifications (e.g., s3:ObjectCreated:*) that invoke a Lambda function to process uploaded objects.

Exam trap

The trap here is that candidates often confuse Lambda's ability to handle HTTP requests via API Gateway with the idea that Lambda itself can serve as a web server, ignoring its stateless nature and execution timeout constraints.

← PreviousPage 2 of 6 · 388 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Development with AWS Services questions.